Terminal authorization-free access control method and system based on multi-dimensional key algorithm
By employing multi-dimensional key algorithms and anti-duplicate verification strategies, the problems of identity verification difficulties and insufficient security in existing access control systems under offline environments are solved, enabling flexible and secure authorization-free control and improving the stability and security of the access control system.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- SHANGHAI USKY TECH CO LTD
- Filing Date
- 2026-01-16
- Publication Date
- 2026-04-21
Smart Images

Figure CN121904872A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of access control and identity authentication technology, specifically relating to a terminal-based unauthorized access control method and system based on a multi-dimensional key algorithm. Background Technology
[0002] With the development of intelligent buildings, smart parks, and public safety management systems, access control systems have been widely used in offices, residential communities, industrial parks, and key controlled areas to achieve personnel entry and exit identification and access control. Existing access control systems typically rely on access cards, mobile terminals, or biometrics for identity authentication, and their core processes are mostly based on backend authorization verification or fixed key comparison mechanisms.
[0003] In practical applications, existing access control systems generally suffer from a high degree of dependence on central servers or authorization platforms. When network connections are unstable, authorization platforms are unavailable, or systems are offline, access control systems often cannot complete effective identity verification, thus affecting normal passage efficiency. Furthermore, traditional access control authorization mechanisms often employ one-time authorization or long-term authorization methods, making it difficult to flexibly control access based on time periods, passage requirements, or changing scenarios, thus compromising between security and convenience.
[0004] While some existing authorization-free or fast-access access control solutions reduce the number of authorization interactions, they are mostly based on single card number recognition or static keys, making them vulnerable to security risks such as card number duplication, replay attacks, or repeated card swiping within a short period. Furthermore, the internal storage structure and sector access permissions of access control cards typically use fixed configurations, lacking fine-grained control methods that combine terminal device identity and dynamic authorization parameters, making it difficult to achieve multi-layered security protection.
[0005] In unauthorized access control scenarios, there is a general lack of effective mechanisms to constrain repeated authorization behavior. This can easily lead to the same card number being identified and triggering access multiple times within a short period of time, which not only disrupts access control order but also increases security risks. Therefore, how to achieve secure, controllable, and constrained terminal unauthorized access control without relying on real-time authorization in the background remains a pressing technical problem that needs to be solved in this field. Summary of the Invention
[0006] To address the aforementioned problems in the existing technology, this invention provides a terminal-based unauthorized access control method based on a multi-dimensional key algorithm. The objective of this invention can be achieved through the following technical solutions: S1: Obtain identity feature data, construct a setting card mechanism based on the identity feature data to read target sector access data, update the unauthorized data storage sector parameters in conjunction with the authorization verification code, and output an authorization pulse signal; S2: Based on the authorized pulse signal, define a multi-dimensional key data structure in the instruction sector, and compare and parse the timestamp of the authorized key in combination with the time period. If it matches the current time period, mark it as a valid unauthorized card, and set the card identification path autonomous verification terminal unauthorized access card according to the settings.
[0007] S3: Report the terminal unauthorized access control card number information twice in sequence, pre-authorize the card number verification information in advance based on the terminal authorization scheme model, and select the terminal unauthorized mode to execute unauthorized access control according to the current access control requirements; S4: Introduce a duplicate verification strategy, establish a short-term cache queue for unauthorized card numbers, record access control card number information that has completed unauthorized access, and ignore duplicate authorized card numbers in the short term, thereby restricting the unauthorized access mode of the terminal.
[0008] Specifically, the method for obtaining the identity feature data is as follows: when the access control terminal triggers an interaction signal, the device's fixed identity information and the card's physical identity information are retrieved, and the device's fixed identity information and the card's physical identity information are mapped to the authorization key vector space to obtain the identity feature data.
[0009] Specifically, the method for constructing the setting card mechanism is as follows: the setting card is initialized and configured based on the dynamic session key, a sector access control table is established in the setting card, the sector access control table is written into the secure storage area of the setting card, the access method and access range of the access card to the target data sector are limited, and the integrity of the written content is verified to construct the setting card mechanism.
[0010] Specifically, the method for outputting the authorization pulse signal is as follows: based on the update result of the unauthorized data storage sector parameters and combined with the verification status of the setting card mechanism, the authorization triggering condition is determined, and when the authorization triggering condition meets the preset requirements, the corresponding authorization pulse signal is generated.
[0011] Specifically, the definition method of the multidimensional key data structure is as follows: Based on the preset key encoding rules, the data of each dimension in the multidimensional key data structure is encoded and arranged. According to the security level and data length requirements of each dimension, the corresponding fields are assigned fixed or variable bit widths and the field boundaries are marked to obtain the key body data. The data of each dimension is divided into bit segments and a check bit is embedded to form a structured key unit. The structured key unit is written into the instruction sector, and the integrity and consistency of the writing result are checked to define a multi-dimensional key data structure.
[0012] Specifically, the verification method for the terminal's unauthorized access control card is as follows: based on the card setting mechanism, the corresponding card recognition path is determined; the multi-dimensional key data structure in the access control card instruction sector is read; the parsed timestamp information is compared with the current system time for a time period; if the timestamp falls within a preset valid time period, the time verification is deemed successful; and if the time verification is successful, the parsed identity feature data is matched and verified with the identity feature data generated locally by the access control terminal; if the match is successful, the terminal's unauthorized access control card verification is deemed successful.
[0013] Specifically, the method for pre-authorization determination using the card number verification information is as follows: After receiving two reports of the terminal's unauthorized access control card number information, the system performs consistency verification and timing validity verification on the two reported access control card number information, generates a basic card number credibility identifier, and maps the basic card number credibility identifier to a preset pre-authorization judgment threshold range. When the pre-authorization determination result falls within the allowed unauthorization range, the access card number is marked as an unauthorization candidate card number, and pre-authorization identification information for terminal unauthorization mode selection is output; when the pre-authorization determination result does not fall within the allowed unauthorization range, a non-unauthorization determination result is output, blocking subsequent unauthorization access control processes.
[0014] Specifically, the method for selecting the terminal's unlicensed mode is as follows: After completing the pre-authorization determination of the access card number information, the pre-authorization determination result is input into the unauthorized mode adaptive decision function to calculate the unauthorized risk assessment value, and interval determination is performed between the unauthorized risk assessment value and the preset multi-level risk threshold interval. The corresponding terminal unauthorized mode is dynamically selected based on the interval determination result. In the selected terminal unauthorized mode, the access control instruction set and verification strength parameters corresponding to the unauthorized risk assessment value are dynamically loaded, and differentiated unauthorized access control is executed. During the unauthorized access control release process, the historical unauthorized release density parameters are updated in real time to adaptively adjust subsequent unauthorized modes.
[0015] Specifically, the method for implementing the anti-duplicate verification strategy to allow the terminal in unauthorized mode is as follows: A short-term cache queue is established based on the unauthorized access card number. When a new terminal unauthorized request is detected, the corresponding access card number information is extracted, and a time correlation comparison operation is performed in the short-term cache queue to determine whether the unauthorized access card number has an associated release record within a preset time window. When an unauthorized access card number is detected to have an associated release record within the time window, it is determined whether the terminal's unauthorized request is a repeatable release request. If it is determined to be a non-repeatable release request, the current unauthorized triggering behavior is suppressed, and a release constraint is applied to the terminal's unauthorized mode to block repeated unauthorized releases of the same card number within a short period of time. If it is determined to be a repeatable release request, the release timestamp in the short-term cache queue is updated, and the terminal's unauthorized process is allowed to continue.
[0016] Specifically, the method for establishing the sector access control table is as follows: based on the storage structure of the access card, the data sectors in the access card are logically divided, the target sector identification parameters are confirmed, and the target sector identification parameters are encrypted using a multi-dimensional key algorithm and written into the secure storage area of the setting card or access card to establish the sector access control table.
[0017] Specifically, the method for establishing the unauthorized card number short-term cache queue is as follows: when the access control terminal is initialized or the unauthorized mode is activated, a cache storage space for unauthorized anti-duplicate verification is allocated, a structured field is defined for each cache unit in the cache storage space, and a maximum queue length threshold is set according to the terminal's unauthorized mode and access control requirements. Each time unauthorized access is granted, the corresponding access card number information and its associated unauthorized mode identifier and release timestamp are written into the short-term cache queue.
[0018] Specifically, a terminal-based authorization-free access control system based on a multi-dimensional key algorithm includes: Identity feature setting card control module: acquires identity feature data, constructs a setting card mechanism based on the identity feature data to read target sector access data, updates unauthorized data storage sector parameters in conjunction with the authorization verification code, and outputs an authorization pulse signal; Multi-dimensional key unauthorized verification module: Based on the authorized pulse signal, a multi-dimensional key data structure is defined in the instruction sector. The timestamp of the authorized key is compared and parsed with the time period. If it matches the current time period, it is marked as a valid unauthorized card. The unauthorized access control card of the autonomous verification terminal is then verified according to the set card identification path.
[0019] Pre-authorization judgment and control management module: It sequentially reports the terminal unauthorized access control card number information twice, performs pre-authorization judgment on the card number verification information in conjunction with the terminal authorization scheme model, and selects the terminal unauthorized mode to execute unauthorized access control based on the current access control requirements; Anti-duplicate verification release module: Introduces anti-duplicate verification strategy, establishes a short-term cache queue of unauthorized card numbers, records access control card number information that has completed unauthorized access, and ignores duplicate authorized card numbers in a short period of time, thereby restricting the release of terminals in unauthorized access mode.
[0020] The beneficial effects of this invention are as follows: By acquiring identity feature data and constructing a setting card mechanism, fine-grained access control of the access control card data sector is achieved. This eliminates the reliance on a single card number or fixed key for unauthorized access control, fundamentally improving the security and controllability of the access control system. By defining a multi-dimensional key data structure in the instruction sector and comparing it with the timestamp of the authorization key over a specific time period, the security risks associated with long-term valid authorizations are effectively avoided, giving unauthorized access control both timeliness and dynamic constraint capabilities.
[0021] A pre-authorization determination mechanism is introduced on the terminal side. By double-reporting and verifying the consistency of access card number information, and combining it with the terminal authorization scheme model, pre-authorization determination is performed. Reliable access control can be completed without relying on real-time authorization in the backend, improving access control efficiency in offline or weak network environments. At the same time, the terminal authorization-free mode is dynamically selected according to actual access needs, making the access control policy more flexible and adaptable to the security requirements of different scenarios.
[0022] A short-term cache queue for unauthorized card numbers is established and a deduplication prevention strategy is introduced. Time-related constraints are applied to card numbers that have completed unauthorized access, which effectively prevents the same card number from being repeatedly triggered for access within a short period of time. This reduces the risk of replay attacks and false triggers, and improves the stability and security of the access control system in high-frequency access scenarios.
[0023] In summary, this invention achieves multi-level security control and dynamic constraints while ensuring unauthorized passage efficiency, taking into account security, flexibility and practicality, and has good application value and promotion prospects. Attached Figure Description
[0024] To facilitate understanding by those skilled in the art, the present invention will be further described below with reference to the accompanying drawings.
[0025] Figure 1 This is a schematic diagram of the framework of a terminal-based unauthorized access control method and system based on a multi-dimensional key algorithm according to the present invention.
[0026] Figure 2 This is a schematic diagram of a terminal-based unauthorized access control method and system based on a multi-dimensional key algorithm, according to the present invention. Detailed Implementation
[0027] To further illustrate the technical means and effects adopted by the present invention to achieve the intended purpose, the following detailed description of the specific implementation methods, structures, features and effects of the present invention, in conjunction with the accompanying drawings and preferred embodiments, is provided.
[0028] Please see Figure 1 A terminal-based authorization-free access control method based on a multi-dimensional key algorithm: S1: Obtain identity feature data, construct a setting card mechanism based on the identity feature data to read target sector access data, update the unauthorized data storage sector parameters in conjunction with the authorization verification code, and output an authorization pulse signal; S2: Based on the authorized pulse signal, define a multi-dimensional key data structure in the instruction sector, and compare and parse the timestamp of the authorized key in combination with the time period. If it matches the current time period, mark it as a valid unauthorized card, and set the card identification path autonomous verification terminal unauthorized access card according to the settings.
[0029] S3: Report the terminal unauthorized access control card number information twice in sequence, pre-authorize the card number verification information in advance based on the terminal authorization scheme model, and select the terminal unauthorized mode to execute unauthorized access control according to the current access control requirements; S4: Introduce a duplicate verification strategy, establish a short-term cache queue for unauthorized card numbers, record access control card number information that has completed unauthorized access, and ignore duplicate authorized card numbers in the short term, thereby restricting the unauthorized access mode of the terminal.
[0030] In this embodiment, the method for obtaining the identity feature data is as follows: when the access control terminal triggers an interaction signal, the device's fixed identity information and the card's physical identity information are retrieved, and the device's fixed identity information and the card's physical identity information are mapped to the authorized key vector space to obtain the identity feature data.
[0031] In this embodiment, the method for constructing the setting card mechanism is as follows: the setting card is initialized and configured based on the dynamic session key, a sector access control table is established in the setting card, the sector access control table is written into the secure storage area of the setting card, the access method and access range of the access card to the target data sector are limited, and the integrity of the written content is verified to construct the setting card mechanism.
[0032] In this embodiment, the method for outputting the authorization pulse signal is as follows: based on the update result of the unauthorized data storage sector parameters and combined with the verification status of the setting card mechanism, the authorization triggering condition is determined, and when the authorization triggering condition meets the preset requirements, the corresponding authorization pulse signal is generated.
[0033] In this embodiment, the method for defining the multidimensional key data structure is as follows: Based on the preset key encoding rules, the data of each dimension in the multidimensional key data structure is encoded and arranged. According to the security level and data length requirements of each dimension, the corresponding fields are assigned fixed or variable bit widths and the field boundaries are marked to obtain the key body data. The data of each dimension is divided into bit segments and a check bit is embedded to form a structured key unit. The structured key unit is written into the instruction sector, and the integrity and consistency of the writing result are checked to define a multi-dimensional key data structure.
[0034] In this embodiment, as Figure 2 In addition to Flash memory and a microprocessor, the terminal access control card reader shown mainly includes an RFID card reader module, a Wiegand / 485 communication interface, a pulse / level signal interface, and a power input interface.
[0035] The Flash memory is used to store the card reader's operating program and configuration parameters. The configuration parameters of the operating program include: terminal unauthorized mode identifier (ordinary card reader mode or terminal unauthorized card reader mode), trigger door opening method identifier (specific card number or pulse, level signal), terminal unauthorized data storage sector number, card sector password, access control terminal single-user key, and other information.
[0036] The RFID card reader module is used to perform card search, anti-collision, card selection, and card reading operations under the instructions of the running program, that is, to obtain the physical card number of the access control card and the data information of the designated sector of the access control card within the RFID sensing area.
[0037] The Wiegand / 485 communication interface is used to report the currently read physical card number data to the host computer (usually the access control controller).
[0038] The pulse / level signal interface is used to send a cardless access request to the host computer (usually the access control controller).
[0039] Main functions of terminal-based unauthorized access control card readers Based on the running program and configuration parameters stored in the Flash memory, the corresponding operations are executed; the RFID card reader module is continuously powered on, reset, searched for cards, and read from the cache in a loop to explore the high-frequency RFID card status within the sensing area; when a high-frequency RFID card is sensed in the area, the card data is read, different card data types are identified, and corresponding operations are executed: Setting Card: The setting data in the card is read, saved to the configuration parameter address in the Flash memory of the device, and then the running program and configuration parameters are reloaded (i.e., hot restart); Terminal Unauthorized Card: According to the configuration parameters, "card reader pulse signal to open the door" or "card reader reports a specific card number to open the door" is executed; Ordinary Card: Access control card number reporting is executed.
[0040] Workflow of Terminal Unauthorized Access Control Card Reader 1. After the program is loaded, the configuration parameters stored in the Flash module are loaded immediately, including: terminal unauthorized mode identifier, door opening method identifier, unauthorized data card sector code and sector password, single-user key of the access control unauthorized system, and pulse signal duration parameter; 2. When the terminal's unlicensed mode is identified as 0xaa, the terminal will be executed according to the unlicensed mode (the workflow for other modes is not described here). 3. When no card is detected, continuously execute the cycle of powering on, resetting, searching for the card, and powering off the RFID module. The time of each cycle is controlled between 0.25 seconds and 0.5 seconds to ensure an instant card swiping experience. 4. Upon card detection, the card number is stored in the cache, and the corresponding sector data (Block 0 to Block 2) is read according to the unauthorized card sector code and sector password parameters: a. When sector data reading fails, indicate that the current card is neither a terminal-unauthorized access control card nor a terminal-unauthorized setting card, and report the card number as a regular access control card; b. When sector data is successfully read, read each data block according to the data sequence and data length identifier of the terminal's unlicensed card, and calculate the key for the data area according to the multi-dimensional key decryption algorithm of the terminal's unlicensed card; c. Decrypt the encrypted data from the terminal's unlicensed card using the data area key, and calculate the checksum according to the data area verification method: i. If the verification code does not match, report the card number as a regular access card; ii. If the verification code matches, perform the corresponding operation according to the terminal's unauthorized terminal card structure: If the card structure matches the terminal's unauthorized access control card, the access control card structure is parsed accordingly. If the authorization time period (No. 7 / 9) matches, the access control card sends opening information to the host computer according to the currently configured opening mode (pulse / level / specific card number). If the time period does not match, the card number is reported as a regular access control card (in scenarios such as centralized activation of access control terminals for new university students, staggered application of terminal authorization time periods is used). If the card structure matches the terminal's unauthorized setting card, the terminal's unauthorized mode (regular card reader mode / terminal unauthorized card reader mode), opening method (pulse / level / specific card number), unauthorized data storage sector, card sector password, access control terminal single-user key, pulse duration, and other parameters are read according to the setting data structure and written to the card reader's Flash memory. After writing the parameters, the program and configuration parameters stored in the Flash module are reloaded and run according to the new parameter configuration mode.
[0041] In this embodiment, the verification method for the terminal's unauthorized access control card is as follows: based on the card setting mechanism, the corresponding card recognition path is determined; the multi-dimensional key data structure in the access control card instruction sector is read; the parsed timestamp information is compared with the current system time for a time period; if the timestamp falls within a preset valid time period, the time verification is deemed successful; and if the time verification is successful, the parsed identity feature data is matched and verified with the identity feature data generated locally by the access control terminal; if the match is successful, the terminal's unauthorized access control card verification is deemed successful.
[0042] In this embodiment, the method for pre-authorization determination using the card number verification information is as follows: After receiving two reports of the terminal's unauthorized access control card number information, the system performs consistency verification and timing validity verification on the two reported access control card number information, generates a basic card number credibility identifier, and maps the basic card number credibility identifier to a preset pre-authorization judgment threshold range. When the pre-authorization determination result falls within the allowed unauthorization range, the access card number is marked as an unauthorization candidate card number, and pre-authorization identification information for terminal unauthorization mode selection is output; when the pre-authorization determination result does not fall within the allowed unauthorization range, a non-unauthorization determination result is output, blocking subsequent unauthorization access control processes.
[0043] In this embodiment, the method for selecting the terminal's unlicensed mode is as follows: After completing the pre-authorization determination of the access card number information, the pre-authorization determination result is input into the unauthorized mode adaptive decision function to calculate the unauthorized risk assessment value, and interval determination is performed between the unauthorized risk assessment value and the preset multi-level risk threshold interval. The corresponding terminal unauthorized mode is dynamically selected based on the interval determination result. In the selected terminal unauthorized mode, the access control instruction set and verification strength parameters corresponding to the unauthorized risk assessment value are dynamically loaded, and differentiated unauthorized access control is executed. During the unauthorized access control release process, the historical unauthorized release density parameters are updated in real time to adaptively adjust subsequent unauthorized modes.
[0044] In this embodiment, the method for the anti-duplicate verification strategy to restrict the terminal's unauthorized mode is as follows: A short-term cache queue is established based on the unauthorized access card number. When a new terminal unauthorized request is detected, the corresponding access card number information is extracted, and a time correlation comparison operation is performed in the short-term cache queue to determine whether the unauthorized access card number has an associated release record within a preset time window. When an unauthorized access card number is detected to have an associated release record within the time window, it is determined whether the terminal's unauthorized request is a repeatable release request. If it is determined to be a non-repeatable release request, the current unauthorized triggering behavior is suppressed, and a release constraint is applied to the terminal's unauthorized mode to block repeated unauthorized releases of the same card number within a short period of time. If it is determined to be a repeatable release request, the release timestamp in the short-term cache queue is updated, and the terminal's unauthorized process is allowed to continue.
[0045] In this embodiment, the construction of the authorized key vector space makes the unauthorized access control verification no longer dependent on a single static key, realizing multi-dimensional security constraints related to time, terminal, and card, effectively improving the security and reliability of unauthorized access control scenarios.
[0046] A multidimensional key algorithm is defined as a composite mapping that combines the effects of an identity feature space, a temporal perturbation space, and a key encoding space. , Where K is the multidimensional authorization key vector, F t F is the identity feature vector of the terminal device. c Let P be the physical identity feature vector of the access card, and let P be the preset key encoding rule parameter set.
[0047] After the setting card completes the update of the target sector access parameters and the unauthorized data storage sector parameters, the access control terminal outputs an authorization pulse signal according to the generation status of the authorization key vector, which is used to trigger the writing operation of the multi-dimensional key data structure of the instruction sector. The multi-dimensional key data structure includes at least: key vector index, timestamp parameter, valid time period identifier and unauthorized flag bit.
[0048] The formula for determining unauthorized matching is: , Where D is the matching distance value between the authorized key vectors. To perform an accumulation calculation on all key components from the 1st dimension to the mth dimension in the authorized key vector, where m is the number of dimensions of the authorized key vector, wi is the weight coefficient corresponding to the i-th dimension key component, (k i read -k i calc ) 2 Let ε(τ) be the squared difference between the i-th key components. When D ≤ ε(τ), the authorization-free verification is considered successful. ε(τ) is an adaptive threshold that varies with the time period.
[0049] In this embodiment, the method for establishing the sector access control table is as follows: based on the storage structure of the access card, the data sectors in the access card are logically divided, the target sector identification parameters are confirmed, and the target sector identification parameters are encrypted using a multi-dimensional key algorithm, written into the secure storage area of the setting card or access card, and a sector access control table is established.
[0050] In this embodiment, the method for establishing the unauthorized card number short-term cache queue is as follows: when the access control terminal is initialized or the unauthorized mode is activated, a cache storage space for unauthorized anti-duplicate verification is allocated, a structured field is defined for each cache unit in the cache storage space, and a maximum queue length threshold is set according to the terminal's unauthorized mode and access control requirements. Each time unauthorized access is granted, the corresponding access card number information and its associated unauthorized mode identifier and release timestamp are written into the short-term cache queue.
[0051] This invention also provides a terminal-based authorization-free access control system based on a multi-dimensional key algorithm, specifically including: Identity feature setting card control module: acquires identity feature data, constructs a setting card mechanism based on the identity feature data to read target sector access data, updates unauthorized data storage sector parameters in conjunction with the authorization verification code, and outputs an authorization pulse signal; Multi-dimensional key unauthorized verification module: Based on the authorized pulse signal, a multi-dimensional key data structure is defined in the instruction sector. The timestamp of the authorized key is compared and parsed with the time period. If it matches the current time period, it is marked as a valid unauthorized card. The unauthorized access control card of the autonomous verification terminal is then verified according to the set card identification path.
[0052] Pre-authorization judgment and control management module: It sequentially reports the terminal unauthorized access control card number information twice, performs pre-authorization judgment on the card number verification information in conjunction with the terminal authorization scheme model, and selects the terminal unauthorized mode to execute unauthorized access control based on the current access control requirements; Anti-duplicate verification release module: Introduces anti-duplicate verification strategy, establishes a short-term cache queue of unauthorized card numbers, records access control card number information that has completed unauthorized access, and ignores duplicate authorized card numbers in a short period of time, thereby restricting the release of terminals in unauthorized access mode.
[0053] The above description is merely a preferred embodiment of the present invention and is not intended to limit the present invention in any way. Although the present invention has been disclosed above with reference to preferred embodiments, it is not intended to limit the present invention. Any person skilled in the art can make some modifications or alterations to the above-disclosed technical content to create equivalent embodiments without departing from the scope of the present invention. Any simple modifications, equivalent changes and alterations made to the above embodiments based on the technical essence of the present invention without departing from the scope of the present invention shall still fall within the scope of the present invention.
Claims
1. A terminal-based authorization-free access control method based on a multi-dimensional key algorithm, characterized in that, include: S1: Obtain identity feature data, construct a setting card mechanism based on the identity feature data to read target sector access data, update the unauthorized data storage sector parameters in conjunction with the authorization verification code, and output an authorization pulse signal; S2: Based on the authorized pulse signal, define a multi-dimensional key data structure in the instruction sector, and combine the time period to parse the timestamp of the authorized key. If it matches the current time period, mark it as a valid unauthorized card, and verify the unauthorized access card of the autonomous verification terminal according to the set card identification path. S3: Report the terminal unauthorized access control card number information twice in sequence, pre-authorize the card number verification information in advance based on the terminal authorization scheme model, and select the terminal unauthorized mode to execute unauthorized access control according to the current access control requirements; S4: Introduce a duplicate verification strategy, establish a short-term cache queue for unauthorized card numbers, record access control card number information that has completed unauthorized access, and ignore duplicate authorized card numbers in the short term, thereby restricting the unauthorized access mode of the terminal.
2. The method according to claim 1, characterized in that, The method for obtaining the identity feature data is as follows: when the access control terminal triggers an interaction signal, the device's fixed identity information and the card's physical identity information are retrieved, and the device's fixed identity information and the card's physical identity information are mapped to the authorization key vector space to obtain the identity feature data.
3. The method according to claim 1, characterized in that, The method for constructing the setting card mechanism is as follows: the setting card is initialized and configured based on the dynamic session key, a sector access control table is established in the setting card, the sector access control table is written into the secure storage area of the setting card, the access method and access range of the access card to the target data sector are limited, and the integrity of the written content is verified to construct the setting card mechanism.
4. The method according to claim 1, characterized in that, The method for outputting the authorization pulse signal is as follows: based on the update result of the unauthorized data storage sector parameters and combined with the verification status of the setting card mechanism, the authorization trigger condition is determined, and when the authorization trigger condition meets the preset requirements, the corresponding authorization pulse signal is generated.
5. The method according to claim 2, characterized in that, The method for defining the multidimensional key data structure is as follows: Based on the preset key encoding rules, the data of each dimension in the multidimensional key data structure is encoded and arranged. According to the security level and data length requirements of each dimension, the corresponding fields are assigned fixed or variable bit widths and the field boundaries are marked to obtain the key body data. The data of each dimension is divided into bit segments and a check bit is embedded to form a structured key unit. The structured key unit is written into the instruction sector, and the integrity and consistency of the writing result are checked to define a multi-dimensional key data structure.
6. The method according to claim 5, characterized in that, The verification method for the terminal's unauthorized access control card is as follows: Based on the card setting mechanism, the corresponding card recognition path is determined; the multi-dimensional key data structure in the access control card instruction sector is read; the parsed timestamp information is compared with the current system time for a time period; if the timestamp falls within a preset valid time period, the time verification is deemed successful; and if the time verification is successful, the parsed identity feature data is matched and verified with the identity feature data generated locally by the access control terminal; if the match is successful, the terminal's unauthorized access control card verification is deemed successful.
7. The method according to claim 4, characterized in that, The method for pre-authorization determination based on the card number verification information is as follows: After receiving two reports of the terminal's unauthorized access control card number information, the system performs consistency verification and timing validity verification on the two reported access control card number information, generates a basic card number credibility identifier, and maps the basic card number credibility identifier to a preset pre-authorization judgment threshold range. When the pre-authorization determination result falls within the allowed unauthorization range, the access card number is marked as an unauthorization candidate card number, and pre-authorization identification information for terminal unauthorization mode selection is output; when the pre-authorization determination result does not fall within the allowed unauthorization range, a non-unauthorization determination result is output, blocking subsequent unauthorization access control processes.
8. The method according to claim 2, characterized in that, The method for selecting the terminal's unlicensed mode is as follows: After completing the pre-authorization determination of the access card number information, the pre-authorization determination result is input into the unauthorized mode adaptive decision function to calculate the unauthorized risk assessment value, and interval determination is performed between the unauthorized risk assessment value and the preset multi-level risk threshold interval. The corresponding terminal unauthorized mode is dynamically selected based on the interval determination result. In the selected terminal unauthorized mode, the access control instruction set and verification strength parameters corresponding to the unauthorized risk assessment value are dynamically loaded, and differentiated unauthorized access control is executed. During the unauthorized access control release process, the historical unauthorized release density parameters are updated in real time to adaptively adjust subsequent unauthorized modes.
9. The method according to claim 4, characterized in that, The method for restricting the unauthorized access of terminals under the anti-duplicate verification strategy is as follows: A short-term cache queue is established based on the unauthorized access card number. When a new terminal unauthorized request is detected, the corresponding access card number information is extracted, and a time correlation comparison operation is performed in the short-term cache queue to determine whether the unauthorized access card number has an associated release record within a preset time window. When an unauthorized access card number is detected to have an associated release record within the time window, it is determined whether the terminal's unauthorized request is a repeatable release request. If it is determined to be a non-repeatable release request, the current unauthorized triggering behavior is suppressed, and a release constraint is applied to the terminal's unauthorized mode to block repeated unauthorized releases of the same card number within a short period of time. If it is determined to be a repeatable release request, the release timestamp in the short-term cache queue is updated, and the terminal's unauthorized process is allowed to continue.
10. The method according to claim 2, characterized in that, The method for establishing the sector access control table is as follows: logically divide the data sectors in the access control card based on the storage structure of the access control card, confirm the target sector identification parameters, encrypt the target sector identification parameters using a multi-dimensional key algorithm, write them into the secure storage area of the setting card or access control card, and establish the sector access control table.
11. The method according to claim 9, characterized in that, The method for establishing the unauthorized card number short-term cache queue is as follows: when the access control terminal is initialized or the unauthorized mode is activated, a cache storage space for unauthorized anti-duplicate verification is allocated, a structured field is defined for each cache unit in the cache storage space, and a maximum queue length threshold is set according to the terminal's unauthorized mode and access control requirements. Each time unauthorized access is granted, the corresponding access card number information and its associated unauthorized mode identifier and release timestamp are written into the short-term cache queue.
12. A terminal-based authorization-free access control system based on a multidimensional key algorithm, used to execute the method as described in any one of claims 1-11, characterized in that, include: Identity feature setting card control module: acquires identity feature data, constructs a setting card mechanism based on the identity feature data to read target sector access data, updates unauthorized data storage sector parameters in conjunction with the authorization verification code, and outputs an authorization pulse signal; Multi-dimensional key unauthorized verification module: Based on the authorized pulse signal, a multi-dimensional key data structure is defined in the instruction sector. The timestamp of the authorized key is parsed by comparing the time period. If it matches the current time period, it is marked as a valid unauthorized card. The unauthorized access card of the autonomous verification terminal is verified according to the set card identification path. Pre-authorization judgment and control management module: It sequentially reports the terminal unauthorized access control card number information twice, performs pre-authorization judgment on the card number verification information in conjunction with the terminal authorization scheme model, and selects the terminal unauthorized mode to execute unauthorized access control based on the current access control requirements; Anti-duplicate verification release module: Introduces anti-duplicate verification strategy, establishes a short-term cache queue of unauthorized card numbers, records access control card number information that has completed unauthorized access, and ignores duplicate authorized card numbers in a short period of time, thereby restricting the release of terminals in unauthorized access mode.