A linkage control system based on access control state applied in an automated warehouse

By introducing a multi-level linkage control system into the automated warehouse, and utilizing the dynamic calculations of sensors and controllers, accurate identification and rapid response to access control status are achieved. This solves the problems of insufficient security response and poor adaptability in existing technologies, and improves the reliability and operational efficiency of the system.

CN122172629APending Publication Date: 2026-06-09GUANGDONG SAIFEIER LOGISTICS TECH CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
GUANGDONG SAIFEIER LOGISTICS TECH CO LTD
Filing Date
2026-03-17
Publication Date
2026-06-09

AI Technical Summary

Technical Problem

Existing automated warehouse systems based on access control status suffer from problems such as insufficient accuracy in security response, limited environmental adaptability, high dependence on operation and maintenance, susceptibility to data inconsistency, and lack of adaptability to emergency recovery and scenario changes.

Method used

The system adopts a multi-layered structure consisting of a perception layer, a control layer, and an execution layer. It includes access control status sensors, personnel detection radar, equipment status monitors, emergency button modules, safety linkage controllers, equipment braking modules, status indicator panels, and alarm notification modules. It calculates the safety response level through dynamic coefficients and combines real-time data processing and rapid command generation to ensure accurate identification, rapid response, and reliable execution of the system.

Benefits of technology

It enables precise and secure responses to automated warehouses, reduces misjudgment and misoperation rates, improves the system's environmental adaptability and operational efficiency, and ensures the reliability of emergency recovery and adaptability to scenario changes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122172629A_ABST
    Figure CN122172629A_ABST
Patent Text Reader

Abstract

The application provides a linkage control system based on access control state applied to an automatic warehouse, comprising a perception layer for data acquisition, a control layer for core control decision and an action output layer for releasing control instructions, wherein the perception layer comprises an access control state sensor for collecting access control opening and closing signals in real time, compared with the prior art, the system has the beneficial effects as follows: in actual use, in the aspect of the perception layer, the double detector configuration of the access control state sensor is combined with high-frequency acquisition, environment adaptive installation and accurate calibration, so that the access control state recognition is ensured without missing judgment, and reliable data basis is provided for safety response; the X-shaped cross deployment of the personnel detection radar and the intelligent identification function eliminate the monitoring blind area, effectively filter the goods carrying false triggering, reduce the system misoperation rate, the direct connection design of the equipment state monitor and the fault diagnosis capability capture equipment abnormalities in real time, and supplement key basis for risk assessment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention is a linkage control system based on access control status applied in automated warehouses, belonging to the field of industrial safety control system technology. Background Technology

[0002] Existing automated warehouse systems using access control status-based linkage control suffer from several key drawbacks: insufficient accuracy in security response, limited environmental adaptability, high reliance on maintenance, and susceptibility to data inconsistencies. Furthermore, they lack adaptability to emergency recovery and scenario changes. These shortcomings stem from multiple factors: sensor deployment is susceptible to signal deviations due to environmental factors such as warehouse dust, vibration, and low temperatures; personnel detection radar, despite having filtering parameters, may still trigger false alarms in scenarios involving cargo handling; fixed weights in the security response model make it difficult to adapt to differences in equipment layout and operational intensity across different warehouses; during initialization and routine maintenance, sensor calibration and parameter settings rely on manual operation, and communication link failures or asynchronous parameter changes can easily lead to data loss or errors; in emergency recovery processes, the tiered recovery equipment startup verification lacks intelligent judgment, and the manual cost of parameter modification and linkage testing after temporary scenario changes is high. Conventional solutions include periodically manually calibrating sensors, manually verifying data consistency, fixing model weights and relying on manual testing of new scenario linkage functions, and manually checking equipment status during recovery. These methods have significant drawbacks: manual calibration and verification are inefficient, prone to omissions, and difficult to respond to dynamic environmental changes in real time; fixed-weight models cannot flexibly match the safety requirements of different operational scenarios, which may lead to over- or under-response; manual testing of new scenario linkage functions is time-consuming and prone to leaving security vulnerabilities due to operational errors; manual recovery verification cycles are long, affecting warehouse operation efficiency and making it difficult to completely avoid secondary risks. Therefore, there is an urgent need for a linkage control system based on access control status applied in automated warehouses to solve the above problems. Summary of the Invention

[0003] In view of the shortcomings of the existing technology, the purpose of this invention is to provide a linkage control system based on access control status for use in automated warehouses, so as to solve the problems mentioned in the background technology.

[0004] The technical solution of the present invention is implemented as follows: a linkage control system based on access control status applied in an automated warehouse, including a perception layer for data acquisition, a control layer for core control decision making, and an action output layer for releasing control commands, wherein the perception layer includes access control status sensors for real-time acquisition of access control opening and closing signals. Personnel detection radar used to accurately identify whether people have entered automated areas; Equipment status monitor used to obtain the real-time operating status of hoists and AGV equipment; An emergency button module for on-site personnel to trigger emergency safety commands; The access control status sensor and personnel detection radar should be installed in locations that cover all access control entrances and the working areas of automated equipment. The equipment status monitor and the control connection of the hoist and AGV equipment should maintain signal communication. The emergency button module should be installed in a fixed location that is easy for personnel to reach and should have a structure to prevent accidental touch. The control layer includes a safety linkage controller for receiving data from the perception layer and executing linkage control logic. A device braking algorithm based on a safety response model that calculates and outputs device control commands; A security level assessment module used to determine the security response level based on data collected from the acquisition layer; A real-time response engine to ensure the rapid transmission and execution of control commands; The control layer maintains a smooth communication link with the perception layer and the execution layer. The control layer pre-stores device type, working range, and safety threshold parameters according to the actual situation. The execution layer includes an emergency braking module for receiving control commands and executing equipment stop operations. An installation status indicator panel used to display the current security level of the system and the status of the equipment; An alarm and notification module used to trigger audible and visual alarms and push security notifications when a security incident occurs; A reset and recovery control module used to detect the installation status and initiate the equipment recovery process after the warehouse door is closed; The equipment emergency braking module receives control commands from the control layer and executes the equipment stop operation. The installation status indicator and alarm and notification module are installed in a prominent position in the warehouse and are directly observable by personnel. The reset and recovery control module has preset safety data verification conditions for equipment restart.

[0005] As a preferred implementation, access control status sensors are installed at the entrances of all automated areas, such as fences, automatic doors, and maintenance doors. Each access control system corresponds to at least one set of sensors. At the same time, each set of access control status sensors is synchronously set with a set of door opening signal detectors and a set of door closing detectors to ensure accurate capture of the three states of door open, door closed, and door not fully closed. The data collection frequency is set to refresh the data once every 10ms to avoid missed judgments due to signal delay. During installation, avoid areas with high dust concentration and severe vibration in the warehouse. At the same time, take waterproof and moisture-proof measures. For cold chain warehouses with a low temperature environment of -25℃, select a low temperature resistant model. After installation, calibrate by simulating door opening and closing actions to ensure that the signal recognition error is ≤1% and that the status data can be transmitted to the control layer in real time through the communication line. Personnel detection radars are deployed in an X-shaped, cross-coverage pattern around the working areas of the hoist and AGV four-way vehicle. The detection range of the personnel detection radars covers an area with a radius of 1.5 times the operating trajectory of the equipment, avoiding any blind spots in monitoring. The personnel detection radar has the intelligent identification function to distinguish between personnel, goods, and equipment, and filters false alarms by setting parameters such as target volume and moving speed, reducing false triggers caused by goods handling. During operation, the radar transmits personnel location data to the control layer every 5ms. If personnel are detected entering a dangerous area, the radar immediately marks the personnel intrusion signal and triggers the early warning mechanism simultaneously.

[0006] As a preferred implementation, the equipment status monitor directly interfaces with the control system of automated equipment such as hoists and AGVs. It collects equipment operating parameters in real time through a data interface, including the hoist's lifting speed, load weight, and running position, and the AGV's travel speed, navigation status, and battery level. The collected parameters include three core types of information: whether the equipment is running, whether it is running normally, and whether it is in a high-risk working condition. The monitor has a fault diagnosis function. If it finds that the equipment parameters exceed the safety threshold, such as the hoist load exceeding the rated value by 10%, it immediately sends an equipment abnormality signal to the control layer, providing a basis for equipment risk assessment for safety evaluation. The safety linkage controller has multi-channel data receiving capability, and can simultaneously process input data from four types of devices: access control status sensors, personnel radar, equipment status monitors, and emergency button modules. The data receiving delay is ≤5ms. The controller has a preset data verification mechanism to check the integrity and validity of each set of received data, and to determine whether the access control status data is one of three valid values: open, closed, or not closed properly, and whether the personnel location data is within the preset automation area. If data abnormality, missing data, or incorrect format is found, a data retransmission command is immediately sent to the perception layer, and the most recent valid data is used as a temporary substitute to avoid decision interruption due to data abnormality. The equipment braking algorithm is the core software module of the control layer. Its core is to calculate the risk value R based on the safety response model. The model formula is R=(T*Wt) plus (P*Wp) plus (E*We). The access control opening time coefficient (T) is dynamically adjusted according to the access control opening time: T=0.3 for 0-10s, T=0.6 for 10-30s, and T=1.0 for more than 30s. P (personnel location hazard factor) is determined based on the distance between personnel and equipment. When the distance is ≥5m, P=0.2; when the distance is 3-5m, P=0.5; and when the distance is <3m, P=1.0. E (equipment operating status coefficient) is set according to the equipment operating conditions. When the equipment is stopped, E=0; when it is running normally, E=0.5; and when it is running under high load / high speed, E=1.0. Wt (time weight), Wp (location weight), and We (device weight) are fixed at 0.4, 0.4, and 0.2 respectively to ensure the stability of the algorithm logic; The algorithm calculates the R value every 2ms and determines the security level based on the R value range: R < 0.5 is L1 (normal level), 0.5 ≤ R < 0.8 is L2 (emergency level), and R ≥ 0.8 is L3 (special level). The security level assessment module performs secondary verification by combining the algorithm calculation results with the actual triggering scenario to avoid misjudgment caused by a single data point. When the access control is activated and triggers Level 1, the module checks whether the personnel radar has detected personnel entering. If no personnel are detected, the response level is downgraded to a warning state, which only prompts the equipment to slow down rather than stop immediately. If the emergency button module triggers Level 2, the module checks whether the button has been reset. If it has been reset and there is no risk to personnel, the device lockout state can be terminated in advance. The evaluation module also has pre-set special scenario processing logic. For example, when the access control status sensor in a cold chain warehouse is delayed due to low temperature, the data acquisition time window is automatically extended to avoid the sensor delay from misjudging that the door is not closed properly. The real-time response engine ensures the rapid generation and transmission of control commands. After determining the safety response level, it generates the corresponding device control commands within ≤10ms. The L1 level instruction is to "stop the hoist and AGV-related equipment, while keeping auxiliary equipment such as conveyor belts running"; The L2 level command is "Stop all automated equipment, lock equipment control permissions, and prohibit manual start-up"; The L3 level command is to "stop all equipment in the entire area and cut off the power supply to all equipment except emergency lighting"; After the instruction is generated, the engine transmits it to the execution layer through a dedicated communication channel, and at the same time sends an instruction log to the control terminal to record information such as the instruction generation time, level, and involved devices, so as to facilitate subsequent traceability. The control layer also has a command feedback receiving function. If the execution layer fails to provide a signal indicating that the command has been executed within the specified time (L1≤20ms, L2≤15ms, L3≤10ms), the command will be automatically resent and an alarm will be triggered to ensure that the command is executed properly. In actual use, in terms of the perception layer, the dual detector configuration and high-frequency acquisition of the access control status sensor, combined with environmentally adapted installation and precise calibration, ensure that the access control status identification has no missed judgments and an error of ≤1%, providing a reliable data foundation for security response. The X-shaped cross deployment and intelligent identification function of the personnel detection radar not only eliminates monitoring blind spots but also effectively filters out accidental triggering during cargo handling, reducing the system's misoperation rate. The direct connection design and fault diagnosis capability of the equipment status monitor capture equipment anomalies in real time, providing key evidence for risk assessment. The multi-channel controller in the control layer and the ≤5ms data reception delay ensure synchronous processing of multi-source data, while data verification and temporary replacement mechanisms prevent decision interruption. The safety response model scientifically calculates risk values ​​through dynamic coefficients and fixed weights, and achieves accurate risk classification through high-frequency calculations every 2ms and a three-level classification standard. The secondary verification logic and special scenario adaptation design further reduce misjudgments and make the response more in line with the actual scenario. The real-time response engine's fast instruction generation (≤10ms), hierarchical instruction design, and feedback retransmission mechanism ensure timely and effective instruction execution and avoid response delays or failures.

[0007] As a preferred implementation, the equipment emergency braking module is designed with a dedicated braking scheme for different types of AGV equipment to ensure that the braking effect matches the characteristics of the equipment. For the hoist, the equipment emergency braking module triggers both mechanical braking and electrical braking at the same time: the mechanical braking clamps the hoist guide rail with brake pads to prevent the car from falling. The electric brake cuts off the motor power supply to prevent the motor from continuing to run. The braking response time is ≤30ms. After braking, the AGV's related equipment will lock the car in its current position, prohibiting free movement. For AGV four-way vehicles, the equipment emergency braking module adopts an emergency stop and position locking mode: immediately cut off the AGV drive power, fix the vehicle position through the wheel locking mechanism to prevent the AGV from sliding due to inertia, and send an emergency stop signal to the AGV navigation system to prevent other AGVs from approaching the area. The equipment emergency braking module has a manual trigger function. When the control layer command fails, the equipment operator can perform an emergency stop through the manual brake switch on the equipment to ensure dual safety protection. The system status indicator panels are installed at the warehouse access control entrance, equipment operation area, and monitoring room, and use a combination of lights and screens to intuitively display the system status. The indicator lights distinguish safety levels by color: green indicates normal status (L0), yellow indicates warning status, i.e., the door is open but there are no people, and red indicates safety event status (L1, L2, L3). Among them, the L1 level is a flashing red light with a flashing frequency of 1 time / second, the L2 level is a solid red light, and the L3 level is a red light with a buzzer sound, with a frequency of 2 times / second. The display screen shows the current security level, trigger cause, involved equipment, response time and other information in real time, so that on-site personnel can quickly understand the situation. The indicator panel also has a power failure backup function, which can maintain operation for at least 30 minutes when the warehouse loses power, so as to ensure that the status information is not interrupted in an emergency.

[0008] As a preferred implementation, the alarm and notification module provides dual coverage of on-site alarm and remote notification. On-site alarm is issued by an audible and visual alarm. Several sets of audible and visual alarms are installed in various areas of the warehouse. When the audible and visual alarm is triggered, the volume is ≥85dB and the light visibility distance is ≥50m. Different safety levels correspond to different alarm modes: Level L1 is a short beep plus a flashing yellow light, Level L2 is a long beep plus a solid red light, and Level L3 is a continuous long beep plus a flashing red light plus a live broadcast, the broadcast content of which is a pre-recorded message: "Emergency, do not enter the automated area, evacuate to the safe area immediately." Remote notifications send alarm information to the mobile apps or work terminals of warehouse managers, equipment maintenance personnel, and on-site safety officers through the system. The information includes the event time, location, level, triggering reason, and handling suggestions. The notification sending delay is ≤15 seconds to ensure that relevant personnel respond in a timely manner. The recovery control mechanism is a key auxiliary function of the execution layer. It is responsible for restoring equipment operation in an orderly manner according to the instructions of the control layer after a safety event is resolved, so as to avoid secondary risks caused by blind recovery. The recovery process follows the principle of hierarchical recovery and verification one by one: after the L1 level event is resolved, auxiliary equipment such as conveyor belts are restored first, and then core equipment such as elevators and AGVs are restored. Each piece of equipment runs for 10 seconds after startup, and the next one is restored only after confirming that there are no abnormalities. When an L2 or L3 level event is resolved, the equipment maintenance personnel first manually check the braking status and operating parameters of each piece of equipment. After confirming that there are no faults, they send a recovery permission command to the execution layer through the control terminal. The execution layer then starts the equipment in the order from non-core equipment to core equipment. During the recovery process, the execution layer provides real-time feedback on the equipment startup status to the control layer. For example, AGV1 has started and is running normally, while hoist 2 failed to start with error code E03. If a device fails to start, the recovery process is immediately stopped and restarted after the fault is cleared. Once the recovery is complete, the execution layer sends a recovery completion signal to the control layer and switches the safety status indicator to green, ending the alarm notification and ensuring that the system returns to normal operation. In actual use, the equipment emergency braking module is designed with a special solution for the characteristics of the hoist and the AGV four-way vehicle. The mechanical and electrical dual braking ensures that the hoist locks the car within ≤30ms. The AGV's drive power cut-off and wheel lock combined with navigation isolation effectively avoid the risk of inertial slippage. The manual trigger function provides redundant safety protection and greatly reduces the probability of equipment loss of control. The status indicator panel uses a combination of lights and a screen to intuitively distinguish safety levels through color and frequency. The display screen presents event details in real time and has a 30-minute power outage endurance capability to ensure information transparency in emergency situations and facilitate rapid response by on-site personnel. The dual coverage mechanism of the alarm and notification module, combined with the on-site audible and visual alarm (volume ≥85dB, visibility distance ≥50m) and hierarchical mode, remotely notifies relevant personnel within 15 seconds and provides handling suggestions, achieving seamless connection between on-site warning and remote response. The execution layer significantly improves the system's security and reliability through precise actions, transparent status, and collaborative response.

[0009] As a preferred implementation, this system is operated in an environment where the warehouse power supply voltage fluctuation is ≤±5% and the backup power supply UPS power is ≥90%, and the sensing layer, control layer, and execution layer equipment are free from physical damage and the installation location is unobstructed. The equipment maintenance personnel close the circuit in the order of main switch, backup power supply, and sub-equipment power supply to avoid current surges that could cause hardware damage. After closing the circuit, observe the power indicator lights of each device. No tripping or abnormal noise is normal. If a tripping occurs, immediately check for short circuits in the line, eliminate the problem, and then close the circuit again. Next, the system administrator sequentially activates the access control status sensor, personnel detection radar, and emergency button module in the perception layer, the safety linkage controller and real-time response engine in the control layer, and the equipment emergency braking module and alarm and notification module in the execution layer on the control terminal, and waits for each module to complete its self-test. Subsequently, the equipment maintenance personnel performed precise calibration on the sensing equipment: simulating the opening and closing actions of the access control system to confirm that the signals collected by the access control status sensors were consistent with the actual status, with an error of ≤1%. The test target is a metal frame simulating the human body moving at different positions in an automated area. The test target is 1.2m*0.5m*0.3m (simulating the outline of a human body) with a volume ≥85dB and a light visibility distance ≥50m when the audible and visual alarm is triggered. The material is aluminum alloy. The personnel detection radar is calibrated to ensure that the position recognition deviation is ≤0.5m. If the calibration deviation is too large, clean the equipment probe or adjust the installation angle and retest. The system administrator should enter the equipment operating parameters for the day, including the AGV working route and the load threshold of the elevator. At the same time, confirm the weights of the safety response model, where the time weight Wt=0.4, the location weight Wp=0.4, and the equipment weight We=0.2 are correct data. After saving the parameters, check whether they are synchronized with the warehouse WCS system to avoid data inconsistency that may cause linkage failure. Finally, the equipment maintenance personnel and the on-site safety officer jointly tested the linkage function: simulated the L1 scenario and opened the regular access control, and observed whether the hoist and AGV stopped within ≤100ms; Simulate pressing the emergency button module in an L2 scenario and confirm that all devices stop and lock within ≤50ms; Simulate an L3 scenario by triggering an intruder with a test target, and check whether all devices in the area stop urgently within ≤30ms. After all tests are passed, the system administrator confirms on the control terminal that the system is ready to run. The status indicator light turns green, and the initialization process is completed. The acquisition accuracy of the access control sensor (error ≤1%) and the personnel detection radar (position deviation ≤0.5m) is verified through simulated scenarios. Calibration measures such as cleaning the probe and adjusting the angle are carried out to provide reliable data support for subsequent risk assessment. When configuring parameters, the weights of equipment operating parameters and safety response models are clearly defined and synchronously checked with the warehouse WCS system to avoid linkage failure caused by data inconsistency and ensure the accurate implementation of control logic. The final joint testing covered all scenarios of L1, L2, and L3, rigorously verifying the time thresholds (≤100ms / 50ms / 30ms) and device actions of different response levels. This ensured that the system could respond as expected in actual security events. The entire process was progressive and interconnected, reducing human error through standardized operations and ensuring system readiness through comprehensive verification, laying a solid foundation for the safe and efficient operation of automated warehouses.

[0010] As a preferred implementation method, the real-time monitoring process runs through the entire warehouse operation. It is executed in an environment where the equipment is running according to the preset process, the sensing layer components are continuously powered and there are no fault alarms. The core is to identify safety risks in a timely manner through real-time data collection and analysis, and provide a basis for linkage control. After the process is started, the on-site safety officer checks the control terminal monitoring interface every 5 minutes and focuses on three core data points: Check the access control status to see if there are any abnormalities or unauthorized access control openings. If any abnormalities are found, immediately contact on-site personnel to verify and rule out misoperation or unauthorized entry. Monitor the equipment operating status, including parameters such as the speed and load of the hoist and AGV, and ensure they are within preset thresholds. If any parameters exceed the limits, notify the equipment maintenance personnel to adjust the equipment operating parameters to avoid overload risks. Safety response level: Under normal circumstances, the system should be at L0 (no risk). If a level jump occurs, the on-site safety officer should wait to confirm the triggering cause. The system administrator exports real-time data every hour. Access control switch records include opening time, opening location, and closing time. Equipment start-stop records include the reason for triggering the stop and the stop duration. Response time data includes the actual response time for each linkage. Warehouse operation logs include personnel inspection plans and equipment scheduling records for verification to ensure that system data is consistent with actual operations and that there is no missing or incorrect data. If data inconsistency is found, check the communication link between the control layer and the perception layer to see if there is signal transmission delay or loss. After supplementing the missing data, mark the cause of the anomaly to facilitate subsequent maintenance and analysis. If the warehouse operation scenario changes temporarily, such as increasing the number of AGVs or adjusting the operating range of the hoist, the system administrator should promptly modify the corresponding equipment parameters on the control terminal, synchronize the changes to the WCS system, and test the equipment linkage function under the new parameters to confirm that the AGVs and hoists can still respond normally according to the access control status. This avoids security vulnerabilities caused by parameter changes. In actual use, the system administrator exports and verifies multi-dimensional data and warehouse operation logs every hour to ensure data authenticity and completeness. The mechanism for troubleshooting and supplementing data when communication links are abnormal not only ensures data traceability but also provides a clear basis for subsequent maintenance. For temporary changes in the operation scenario, parameters are promptly modified and synchronized to the WCS system, and the effectiveness of the response is verified through linkage testing to avoid security vulnerabilities caused by parameter adjustments.

[0011] As a preferred implementation, the system administrator confirms the shutdown by first checking the equipment status through the control terminal to ensure that all equipment, such as the hoist and AGV, is displayed as stopped and that no equipment is running or malfunctioning. The automated area is scanned by personnel detection radar to confirm that no personnel remain. If personnel are found, evacuation is immediately arranged. Check the system data backup status for the day to confirm that the system has automatically backed up the content, including security event records, device start-up and shutdown records, and response time data. At the same time, manually export the data archive to the warehouse server to avoid data loss. The equipment maintenance personnel shut down system components in the order of execution layer, control layer, and perception layer: first, shut down the equipment emergency braking module and alarm and notification module at the execution layer to ensure that the equipment has no power output; Then shut down the safety linkage controller and real-time response engine in the control layer. Before shutting down, confirm that there are no unfinished instructions to avoid data transmission interruption. Finally, turn off the access control status sensor, personnel detection radar, and emergency button module in the perception layer. During the shutdown process, observe the indicator lights of each device to ensure that they are turned off normally without any error messages. After the components are shut down, the equipment maintenance personnel cut off the power in the order of sub-equipment power supply, backup power supply, and main switch. Before cutting off the main switch, they check whether all equipment power switches are reset to avoid current surge when the switches are turned on the next day. The system administrator strictly verifies the shutdown prerequisites and confirms through the control terminal that all equipment is in a stopped state and there are no residual faults. The personnel detection radar ensures that no personnel are left in the automated area, thus eliminating the risk of equipment accidental start-up or personnel being trapped from the source. Simultaneously, data security is protected by two safeguards: both the system automatically backs up all operational data and manually exports and archives it to the server, completely preventing the loss of critical operational and security data and ensuring data traceability and subsequent analysis capabilities. Equipment maintenance personnel should shut down system components in reverse order of execution layer, control layer, and perception layer. Before shutting down, they should confirm that there are no incomplete instructions, ensure that the equipment has no power output and that data transmission is uninterrupted, and avoid hardware conflicts or data corruption caused by improper component shutdown order. The power outage process follows the standard procedure for the main switch of the sub-equipment power supply and backup power supply, and the reset status of the power switch is checked before the main switch is cut off, which effectively avoids the damage to the hardware caused by the current surge when the switch is closed the next day. The entire shutdown process is designed with a closed loop, including pre-screening, data preservation, orderly shutdown, and standardized power outage. This not only strengthens the safety management of the shutdown process but also achieves dual protection for equipment and data.

[0012] After adopting the above technical solutions, the beneficial effects of this system are as follows: In actual use, at the perception layer, the dual-detector configuration and high-frequency acquisition of the access control status sensor, combined with environmentally adapted installation and precise calibration, ensure that access control status recognition has no missed judgments and an error of ≤1%, providing a reliable data foundation for security response; the X-shaped cross deployment and intelligent recognition function of the personnel detection radar not only eliminate monitoring blind spots but also effectively filter out accidental triggering during cargo handling, reducing the system's misoperation rate; the direct connection design and fault diagnosis capability of the equipment status monitor capture equipment anomalies in real time, providing key evidence for risk assessment. The multi-channel controller in the control layer and the ≤5ms data reception delay ensure synchronous processing of multi-source data, while data verification and temporary replacement mechanisms prevent decision interruptions. The safety response model scientifically calculates risk values ​​through dynamic coefficients and fixed weights, and high-frequency calculations every 2ms and a three-level classification standard achieve accurate risk classification. Secondary verification logic and special scenario adaptation design further reduce misjudgments and make the response more in line with the actual scenario. The real-time response engine's fast instruction generation (≤10ms), hierarchical instruction design, and feedback retransmission mechanism ensure timely and effective instruction execution and avoid response delays or failures. In practical use, the equipment emergency braking module is designed with a special solution for the characteristics of the hoist and the AGV four-way vehicle. The mechanical and electrical dual braking ensures that the hoist locks the car within ≤30ms. The AGV's drive power is cut off and the wheel lock is combined with navigation isolation to effectively avoid the risk of inertial slippage. The manual trigger function provides redundant safety protection and greatly reduces the probability of equipment loss of control. The status indicator panel uses a combination of lights and a screen to intuitively distinguish safety levels through color and frequency. The display screen presents event details in real time and has a 30-minute power outage endurance capability to ensure information transparency in emergency situations and facilitate rapid response by on-site personnel. The dual coverage mechanism of alarm and notification modules, combined with on-site audible and visual alarms (volume ≥85dB, visibility distance ≥50m) and a hierarchical mode, allows for remote notifications to reach relevant personnel within 15 seconds with handling suggestions, achieving seamless integration of on-site warnings and remote responses. The execution layer significantly improves the system's security and reliability through precise actions, transparent status, and collaborative responses. In practical use, system administrators export and verify multi-dimensional data and warehouse operation logs every hour to ensure data authenticity and completeness. The mechanism for troubleshooting and supplementing data when communication links are abnormal not only ensures data traceability but also provides a clear basis for subsequent maintenance. For temporary changes in operational scenarios, parameters are modified in a timely manner and synchronized with the WCS system. Furthermore, the effectiveness of the response is verified through linkage testing to avoid security vulnerabilities caused by parameter adjustments. Attached Figure Description

[0013] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0014] Figure 1 This is a flowchart illustrating the overall system architecture of a linkage control system based on access control status applied in an automated warehouse, according to the present invention. Figure 2 This invention provides a flowchart of the personnel detection radar process in a linkage control system based on access control status in an automated warehouse. Figure 3 This is a flowchart illustrating the equipment braking algorithm logic of a linkage control system based on access control status in an automated warehouse, according to the present invention. Figure 4 This invention provides a flowchart of the emergency braking execution process for equipment in a linkage control system based on access control status in an automated warehouse. Figure 5 This is a system initialization flowchart of a linkage control system based on access control status applied in an automated warehouse according to the present invention; Figure 6 This is a flowchart of an equipment recovery control system based on access control status in an automated warehouse, according to the present invention. Detailed Implementation

[0015] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0016] A linkage control system based on access control status applied in an automated warehouse includes a perception layer for data acquisition, a control layer for core control decisions, and an action output layer for releasing control commands. The perception layer includes access control status sensors for real-time acquisition of access control opening and closing signals. Personnel detection radar used to accurately identify whether people have entered automated areas; Equipment status monitor used to obtain the real-time operating status of hoists and AGV equipment; An emergency button module for on-site personnel to trigger emergency safety commands; The access control status sensor and personnel detection radar should be installed in locations that cover all access control entrances and the working areas of automated equipment. The equipment status monitor and the control connection of the hoist and AGV equipment should maintain signal communication. The emergency button module should be installed in a fixed location that is easy for personnel to reach and should have a structure to prevent accidental touch. The control layer includes a safety linkage controller for receiving data from the perception layer and executing linkage control logic. A device braking algorithm based on a safety response model that calculates and outputs device control commands; A security level assessment module used to determine the security response level based on data collected from the acquisition layer; A real-time response engine to ensure the rapid transmission and execution of control commands; The control layer maintains a smooth communication link with the perception layer and the execution layer. The control layer pre-stores device type, working range, and safety threshold parameters according to the actual situation. The execution layer includes an emergency braking module for receiving control commands and executing equipment stop operations. An installation status indicator panel used to display the current security level of the system and the status of the equipment; An alarm and notification module used to trigger audible and visual alarms and push security notifications when a security incident occurs; A reset and recovery control module used to detect the installation status and initiate the equipment recovery process after the warehouse door is closed; The equipment emergency braking module receives control commands from the control layer and executes the equipment stop operation. The installation status indicator and alarm and notification module are installed in a prominent position in the warehouse and are directly observable by personnel. The reset and recovery control module has preset safety data verification conditions for equipment restart.

[0017] Please see Figures 1-3 As the first embodiment of the present invention: access control status sensors are installed at the entrances of automatic gates, maintenance gates, etc. in all automated areas. Each access control corresponds to at least one set of sensors. At the same time, each set of access control status sensors is synchronously set with a set of door opening signal detectors and a set of door closing detectors to ensure accurate capture of the three states of door opening, door closing, and door not closed tightly. The data collection frequency is set to refresh the data once every 10ms to avoid missed judgments due to signal delay. During installation, avoid areas with high dust concentration and severe vibration in the warehouse. At the same time, take waterproof and moisture-proof measures. For cold chain warehouses with a low temperature environment of -25℃, select a low temperature resistant model. After installation, calibrate by simulating door opening and closing actions to ensure that the signal recognition error is ≤1% and that the status data can be transmitted to the control layer in real time through the communication line. Personnel detection radars are deployed in an X-shaped, cross-coverage pattern around the working areas of the hoist and AGV four-way vehicle. The detection range of the personnel detection radars covers an area with a radius of 1.5 times the operating trajectory of the equipment, avoiding any blind spots in monitoring. The personnel detection radar has the intelligent identification function to distinguish between personnel, goods, and equipment, and filters false alarms by setting parameters such as target volume and moving speed, reducing false triggers caused by goods handling. During operation, the radar transmits personnel location data to the control layer every 5ms. If personnel are detected entering a dangerous area, the radar immediately marks the personnel intrusion signal and triggers the early warning mechanism simultaneously.

[0018] The equipment status monitor directly interfaces with the control systems of automated equipment such as hoists and AGVs. It collects equipment operating parameters in real time through data interfaces, including the hoist's lifting speed, load weight, and running position, and the AGV's travel speed, navigation status, and battery level. The collected parameters include three core types of information: whether the equipment is running, whether it is running normally, and whether it is in a high-risk working condition. The monitor has a fault diagnosis function. If it finds that the equipment parameters exceed the safety threshold, such as the hoist load exceeding the rated value by 10%, it immediately sends an equipment abnormality signal to the control layer, providing a basis for equipment risk assessment for safety evaluation. The safety linkage controller has multi-channel data receiving capability, and can simultaneously process input data from four types of devices: access control status sensors, personnel radar, equipment status monitors, and emergency button modules. The data receiving delay is ≤5ms. The controller has a preset data verification mechanism to check the integrity and validity of each set of received data, and to determine whether the access control status data is one of three valid values: open, closed, or not closed properly, and whether the personnel location data is within the preset automation area. If data abnormality, missing data, or incorrect format is found, a data retransmission command is immediately sent to the perception layer, and the most recent valid data is used as a temporary substitute to avoid decision interruption due to data abnormality. The equipment braking algorithm is the core software module of the control layer. Its core is to calculate the risk value R based on the safety response model. The model formula is R=(T*Wt) plus (P*Wp) plus (E*We). The access control opening time coefficient (T) is dynamically adjusted according to the access control opening time: T=0.3 for 0-10s, T=0.6 for 10-30s, and T=1.0 for more than 30s. P (personnel location hazard factor) is determined based on the distance between personnel and equipment. When the distance is ≥5m, P=0.2; when the distance is 3-5m, P=0.5; and when the distance is <3m, P=1.0. E (equipment operating status coefficient) is set according to the equipment operating conditions. When the equipment is stopped, E=0; when it is running normally, E=0.5; and when it is running under high load / high speed, E=1.0. Wt (time weight), Wp (location weight), and We (device weight) are fixed at 0.4, 0.4, and 0.2 respectively to ensure the stability of the algorithm logic; The algorithm calculates the R value every 2ms and determines the security level based on the R value range: R < 0.5 is L1 (normal level), 0.5 ≤ R < 0.8 is L2 (emergency level), and R ≥ 0.8 is L3 (special level). The security level assessment module performs secondary verification by combining the algorithm calculation results with the actual triggering scenario to avoid misjudgment caused by a single data point. When the access control is activated and triggers Level 1, the module checks whether the personnel radar has detected personnel entering. If no personnel are detected, the response level is downgraded to a warning state, which only prompts the equipment to slow down rather than stop immediately. If the emergency button module triggers Level 2, the module checks whether the button has been reset. If it has been reset and there is no risk to personnel, the device lockout state can be terminated in advance. The evaluation module also has pre-set special scenario processing logic. For example, when the access control status sensor in a cold chain warehouse is delayed due to low temperature, the data acquisition time window is automatically extended to avoid the sensor delay from misjudging that the door is not closed properly. The real-time response engine ensures the rapid generation and transmission of control commands. After determining the safety response level, it generates the corresponding device control commands within ≤10ms. The L1 level instruction is to "stop the hoist and AGV-related equipment, while keeping auxiliary equipment such as conveyor belts running"; The L2 level command is "Stop all automated equipment, lock equipment control permissions, and prohibit manual start-up"; The L3 level command is to "stop all equipment in the entire area and cut off the power supply to all equipment except emergency lighting"; After the instruction is generated, the engine transmits it to the execution layer through a dedicated communication channel, and at the same time sends an instruction log to the control terminal to record information such as the instruction generation time, level, and involved devices, so as to facilitate subsequent traceability. The control layer also has a command feedback receiving function. If the execution layer fails to provide a signal indicating that the command has been executed within the specified time (L1≤20ms, L2≤15ms, L3≤10ms), the command will be automatically resent and an alarm will be triggered to ensure that the command is executed properly. In actual use, in terms of the perception layer, the dual detector configuration and high-frequency acquisition of the access control status sensor, combined with environmentally adapted installation and precise calibration, ensure that the access control status identification has no missed judgments and an error of ≤1%, providing a reliable data foundation for security response. The X-shaped cross deployment and intelligent identification function of the personnel detection radar not only eliminates monitoring blind spots but also effectively filters out accidental triggering during cargo handling, reducing the system's misoperation rate. The direct connection design and fault diagnosis capability of the equipment status monitor capture equipment anomalies in real time, providing key evidence for risk assessment. The multi-channel controller in the control layer and the ≤5ms data reception delay ensure synchronous processing of multi-source data, while data verification and temporary replacement mechanisms prevent decision interruption. The safety response model scientifically calculates risk values ​​through dynamic coefficients and fixed weights, and achieves accurate risk classification through high-frequency calculations every 2ms and a three-level classification standard. The secondary verification logic and special scenario adaptation design further reduce misjudgments and make the response more in line with the actual scenario. The real-time response engine's fast instruction generation (≤10ms), hierarchical instruction design, and feedback retransmission mechanism ensure timely and effective instruction execution and avoid response delays or failures.

[0019] Please see Figures 1-4 As a second embodiment of the present invention: based on the description in Embodiment 1, the equipment emergency braking module is further designed with a dedicated braking scheme for different types of AGV equipment to ensure that the braking effect matches the characteristics of the equipment. For the hoist, the equipment emergency braking module triggers both mechanical braking and electrical braking at the same time: the mechanical braking clamps the hoist guide rail with brake pads to prevent the car from falling. The electric brake cuts off the motor power supply to prevent the motor from continuing to run. The braking response time is ≤30ms. After braking, the AGV's related equipment will lock the car in its current position, prohibiting free movement. For AGV four-way vehicles, the equipment emergency braking module adopts an emergency stop and position locking mode: immediately cut off the AGV drive power, fix the vehicle position through the wheel locking mechanism to prevent the AGV from sliding due to inertia, and send an emergency stop signal to the AGV navigation system to prevent other AGVs from approaching the area. The equipment emergency braking module has a manual trigger function. When the control layer command fails, the equipment operator can perform an emergency stop through the manual brake switch on the equipment to ensure dual safety protection. The system status indicator panels are installed at the warehouse access control entrance, equipment operation area, and monitoring room, and use a combination of lights and screens to intuitively display the system status. The indicator lights distinguish safety levels by color: green indicates normal status (L0), yellow indicates warning status, i.e., the door is open but there are no people, and red indicates safety event status (L1, L2, L3). Among them, the L1 level is a flashing red light with a flashing frequency of 1 time / second, the L2 level is a solid red light, and the L3 level is a red light with a buzzer sound, with a frequency of 2 times / second. The display screen shows the current security level, trigger cause, involved equipment, response time and other information in real time, so that on-site personnel can quickly understand the situation. The indicator panel also has a power failure backup function, which can maintain operation for at least 30 minutes when the warehouse loses power, so as to ensure that the status information is not interrupted in an emergency.

[0020] The alarm and notification module provides dual coverage of on-site alarms and remote notifications. On-site alarms are issued through audible and visual alarms. Several sets of audible and visual alarms are installed in various areas of the warehouse. When the audible and visual alarms are triggered, the volume is ≥85dB and the light visibility distance is ≥50m. Different safety levels correspond to different alarm modes: Level L1 is a short beep plus a flashing yellow light, Level L2 is a long beep plus a solid red light, and Level L3 is a continuous long beep plus a flashing red light plus a live broadcast, the broadcast content of which is a pre-recorded message: "Emergency, do not enter the automated area, evacuate to the safe area immediately." Remote notifications send alarm information to the mobile apps or work terminals of warehouse managers, equipment maintenance personnel, and on-site safety officers through the system. The information includes the event time, location, level, triggering reason, and handling suggestions. The notification sending delay is ≤15 seconds to ensure that relevant personnel respond in a timely manner. The recovery control mechanism is a key auxiliary function of the execution layer. It is responsible for restoring equipment operation in an orderly manner according to the instructions of the control layer after a safety event is resolved, so as to avoid secondary risks caused by blind recovery. The recovery process follows the principle of hierarchical recovery and verification one by one: after the L1 level event is resolved, auxiliary equipment such as conveyor belts are restored first, and then core equipment such as elevators and AGVs are restored. Each piece of equipment runs for 10 seconds after startup, and the next one is restored only after confirming that there are no abnormalities. When an L2 or L3 level event is resolved, the equipment maintenance personnel first manually check the braking status and operating parameters of each piece of equipment. After confirming that there are no faults, they send a recovery permission command to the execution layer through the control terminal. The execution layer then starts the equipment in the order from non-core equipment to core equipment. During the recovery process, the execution layer provides real-time feedback on the equipment startup status to the control layer. For example, AGV1 has started and is running normally, while hoist 2 failed to start with error code E03. If a device fails to start, the recovery process is immediately stopped and restarted after the fault is cleared. Once the recovery is complete, the execution layer sends a recovery completion signal to the control layer and switches the safety status indicator to green, ending the alarm notification and ensuring that the system returns to normal operation. In actual use, the equipment emergency braking module is designed with a special solution for the characteristics of the hoist and the AGV four-way vehicle. The mechanical and electrical dual braking ensures that the hoist locks the car within ≤30ms. The AGV's drive power cut-off and wheel lock combined with navigation isolation effectively avoid the risk of inertial slippage. The manual trigger function provides redundant safety protection and greatly reduces the probability of equipment loss of control. The status indicator panel uses a combination of lights and a screen to intuitively distinguish safety levels through color and frequency. The display screen presents event details in real time and has a 30-minute power outage endurance capability to ensure information transparency in emergency situations and facilitate rapid response by on-site personnel. The dual coverage mechanism of the alarm and notification module, combined with the on-site audible and visual alarm (volume ≥85dB, visibility distance ≥50m) and hierarchical mode, remotely notifies relevant personnel within 15 seconds and provides handling suggestions, achieving seamless connection between on-site warning and remote response. The execution layer significantly improves the system's security and reliability through precise actions, transparent status, and collaborative response.

[0021] This system operates under conditions where the warehouse power supply voltage fluctuation is ≤±5% and the backup power supply UPS power is ≥90%. The sensing layer, control layer, and execution layer equipment must be free of physical damage and unobstructed installation locations. The equipment maintenance personnel should close the circuit in the order of main switch, backup power supply, and sub-equipment power supply to avoid current surges that could damage the hardware. After closing the circuit, observe the power indicator lights of each device. No tripping or abnormal noise is normal. If a tripping occurs, immediately check for short circuits in the lines, resolve the issue, and then close the circuit again. Next, the system administrator sequentially activates the access control status sensor, personnel detection radar, and emergency button module in the perception layer, the safety linkage controller and real-time response engine in the control layer, and the equipment emergency braking module and alarm and notification module in the execution layer on the control terminal, and waits for each module to complete its self-test. Subsequently, the equipment maintenance personnel performed precise calibration on the sensing equipment: simulating the opening and closing actions of the access control system to confirm that the signals collected by the access control status sensors were consistent with the actual status, with an error of ≤1%. The test target is a metal frame simulating the human body moving at different positions in an automated area. The test target is 1.2m*0.5m*0.3m (simulating the outline of a human body) with a volume ≥85dB and a light visibility distance ≥50m when the audible and visual alarm is triggered. The material is aluminum alloy. The personnel detection radar is calibrated to ensure that the position recognition deviation is ≤0.5m. If the calibration deviation is too large, clean the equipment probe or adjust the installation angle and retest. The system administrator should enter the equipment operating parameters for the day, including the AGV working route and the load threshold of the elevator. At the same time, confirm the weights of the safety response model, where the time weight Wt=0.4, the location weight Wp=0.4, and the equipment weight We=0.2 are correct data. After saving the parameters, check whether they are synchronized with the warehouse WCS system to avoid data inconsistency that may cause linkage failure. Finally, the equipment maintenance personnel and the on-site safety officer jointly tested the linkage function: simulated the L1 scenario and opened the regular access control, and observed whether the hoist and AGV stopped within ≤100ms; Simulate pressing the emergency button module in an L2 scenario and confirm that all devices stop and lock within ≤50ms; Simulate an L3 scenario by triggering an intruder with a test target, and check whether all devices in the area stop urgently within ≤30ms. After all tests are passed, the system administrator confirms on the control terminal that the system is ready to run. The status indicator light turns green, and the initialization process is completed. The acquisition accuracy of the access control sensor (error ≤1%) and the personnel detection radar (position deviation ≤0.5m) is verified through simulated scenarios. Calibration measures such as cleaning the probe and adjusting the angle are carried out to provide reliable data support for subsequent risk assessment. When configuring parameters, the weights of equipment operating parameters and safety response models are clearly defined and synchronously checked with the warehouse WCS system to avoid linkage failure caused by data inconsistency and ensure the accurate implementation of control logic. The final joint testing covered all scenarios of L1, L2, and L3, rigorously verifying the time thresholds (≤100ms / 50ms / 30ms) and device actions of different response levels. This ensured that the system could respond as expected in actual security events. The entire process was progressive and interconnected, reducing human error through standardized operations and ensuring system readiness through comprehensive verification, laying a solid foundation for the safe and efficient operation of automated warehouses.

[0022] Please see Figures 1-4 As a third embodiment of the present invention: based on the description in Embodiment 2, the real-time monitoring process runs through the entire warehouse operation process and is executed in an environment where the equipment is running according to the preset process, the sensing layer components are continuously powered and there are no fault alarms. The core is to identify safety risks in a timely manner through real-time data collection and analysis, and provide a basis for linkage control. After the process is started, the on-site safety officer checks the control terminal monitoring interface every 5 minutes and focuses on three core data points: Check the access control status to see if there are any abnormalities or unauthorized access control openings. If any abnormalities are found, immediately contact on-site personnel to verify and rule out misoperation or unauthorized entry. Monitor the equipment operating status, including parameters such as the speed and load of the hoist and AGV, and ensure they are within preset thresholds. If any parameters exceed the limits, notify the equipment maintenance personnel to adjust the equipment operating parameters to avoid overload risks. Safety response level: Under normal circumstances, the system should be at L0 (no risk). If a level jump occurs, the on-site safety officer should wait to confirm the triggering cause. The system administrator exports real-time data every hour. Access control switch records include opening time, opening location, and closing time. Equipment start-stop records include the reason for triggering the stop and the stop duration. Response time data includes the actual response time for each linkage. Warehouse operation logs include personnel inspection plans and equipment scheduling records for verification to ensure that system data is consistent with actual operations and that there is no missing or incorrect data. If data inconsistency is found, check the communication link between the control layer and the perception layer to see if there is signal transmission delay or loss. After supplementing the missing data, mark the cause of the anomaly to facilitate subsequent maintenance and analysis. If the warehouse operation scenario changes temporarily, such as increasing the number of AGVs or adjusting the operating range of the hoist, the system administrator should promptly modify the corresponding equipment parameters on the control terminal, synchronize the changes to the WCS system, and test the equipment linkage function under the new parameters to confirm that the AGVs and hoists can still respond normally according to the access control status. This avoids security vulnerabilities caused by parameter changes. In actual use, the system administrator exports and verifies multi-dimensional data and warehouse operation logs every hour to ensure data authenticity and completeness. The mechanism for troubleshooting and supplementing data when communication links are abnormal not only ensures data traceability but also provides a clear basis for subsequent maintenance. For temporary changes in the operation scenario, parameters are promptly modified and synchronized to the WCS system, and the effectiveness of the response is verified through linkage testing to avoid security vulnerabilities caused by parameter adjustments.

[0023] Please see Figures 1-6 As a fourth embodiment of the present invention: based on the description in embodiments one to three, the system administrator confirms the shutdown by first checking the equipment status through the control terminal to ensure that all equipment such as the hoist and AGV are displayed as stopped and no equipment is running or malfunctioning; The automated area is scanned by personnel detection radar to confirm that no personnel remain. If personnel are found, evacuation is immediately arranged. Check the system data backup status for the day to confirm that the system has automatically backed up the content, including security event records, device start-up and shutdown records, and response time data. At the same time, manually export the data archive to the warehouse server to avoid data loss. The equipment maintenance personnel shut down system components in the order of execution layer, control layer, and perception layer: first, shut down the equipment emergency braking module and alarm and notification module at the execution layer to ensure that the equipment has no power output; Then shut down the safety linkage controller and real-time response engine in the control layer. Before shutting down, confirm that there are no unfinished instructions to avoid data transmission interruption. Finally, turn off the access control status sensor, personnel detection radar, and emergency button module in the perception layer. During the shutdown process, observe the indicator lights of each device to ensure that they are turned off normally without any error messages. After the components are shut down, the equipment maintenance personnel cut off the power in the order of sub-equipment power supply, backup power supply, and main switch. Before cutting off the main switch, they check whether all equipment power switches are reset to avoid current surge when the switches are turned on the next day. The system administrator strictly verifies the shutdown prerequisites and confirms through the control terminal that all equipment is in a stopped state and there are no residual faults. The personnel detection radar ensures that no personnel are left in the automated area, thus eliminating the risk of equipment accidental start-up or personnel being trapped from the source. Simultaneously, data security is protected by two safeguards: both the system automatically backs up all operational data and manually exports and archives it to the server, completely preventing the loss of critical operational and security data and ensuring data traceability and subsequent analysis capabilities. Equipment maintenance personnel should shut down system components in reverse order of execution layer, control layer, and perception layer. Before shutting down, they should confirm that there are no incomplete instructions, ensure that the equipment has no power output and that data transmission is uninterrupted, and avoid hardware conflicts or data corruption caused by improper component shutdown order. The power outage process follows the standard procedure for the main switch of the sub-equipment power supply and backup power supply, and the reset status of the power switch is checked before the main switch is cut off, which effectively avoids the damage to the hardware caused by the current surge when the switch is closed the next day. The entire shutdown process is designed with a closed loop, including pre-screening, data preservation, orderly shutdown, and standardized power outage. This not only strengthens the safety management of the shutdown process but also achieves dual protection for equipment and data.

[0024] To address the aforementioned technical solution, we designed four types of experiments with different dimensions. Experimental data was used to validate the system performance. All experiments were aligned with the technical specifications and logic outlined in the documentation, and the experimental data and results are presented in tabular form. I. Accuracy Verification Experiment of Sensing Layer Devices Experimental objective: To verify the data acquisition accuracy of the access control status sensor and personnel detection radar, and to ensure data reliability. Where: State recognition error = (Total number of tests - Number of correct recognitions) / Total number of tests * 100% Position identification deviation = (measured target position a - actual target position b) / 2; The experimental results show that the access control status sensor had only 0.2 recognition errors in 50 tests, with an error value as low as 0.4%, far exceeding the theoretical accuracy requirement of ≤1%. The data acquisition delay was 8.2ms in 30 tests, meeting the standard of ≤10ms. The personnel detection radar also performed well. In the position recognition deviation test at different distances of 3m, 5m, and 10m, the average deviation was only 0.32m in 40 tests, lower than the requirement of ≤0.5m. In the case of goods movement, there were only 0.8 false triggers in 100 tests, with a false trigger rate of 0.8%, meeting the accuracy standard of ≤1%. The average data transmission delay was 3.7ms, meeting the requirement of ≤5ms. This experiment fully demonstrates that the perception layer devices have extremely high acquisition accuracy and data reliability. The access control status sensor can accurately capture the three states of the door, and the high-frequency acquisition and low-latency characteristics can avoid signal omission. The personnel detection radar effectively distinguishes between personnel and goods through intelligent recognition technology. The cross-deployment design eliminates monitoring blind spots. The low false trigger rate and accurate location detection capability provide the control layer with real and effective raw data, ensuring the accuracy of system security decisions from the data source.

[0025] II. System Response Time Test Experiment Experimental objective: To verify the system's full-process response time from triggering to device braking under different safety levels; The response time is calculated as follows: Total system response time = Perception layer data acquisition delay + Control layer data processing delay + Command transmission delay + Execution layer braking response delay. Experimental data shows that the system response time is better than the theoretical requirement under different security levels. In a standard L1 scenario, the average response time across 20 tests was 85.3ms, lower than the standard of ≤100ms. The average response time for L2 emergency scenarios is 38.7ms, which meets the requirement of ≤50ms. The average response time in L3 high-level scenarios is 24.1ms, which is far below the upper limit of ≤30ms; the average latency for command retransmission response is 7.8ms, which also meets the requirement of ≤10ms. Compared with industry norms, the response speed of L1 level is 43.2% faster than the industry average of 150-200ms, L2 level is 51.6% faster than 80-120ms, L3 level is 60.7% faster than 60-80ms, and command retransmission response is 61.0% faster than 20-30ms. In conclusion, the system demonstrates rapid response capabilities across different security levels. Through the coordinated efforts of rapid data acquisition at the perception layer, efficient processing at the control layer, high-speed command transmission, and swift braking at the execution layer, it achieves low-latency response throughout the entire process. In particular, in the highest-risk L3 scenario, the response speed is improved by over 60%, enabling emergency braking of equipment to be triggered in a very short time, significantly reducing the risk of personnel injury and equipment damage. Compared to traditional systems, the system exhibits a significant advantage in the timeliness of security protection.

[0026] III. Risk Value Calculation and Rating Experiment Experimental objective: To verify the accuracy of risk value calculation and the rationality of risk classification in the safety response model; The formula for calculating the risk value R is: R = T * 0.4 + P * 0.4 + E * 0.2; Comparative analysis (with traditional fixed-value triggering method): In five different test scenarios, the system's risk value calculation and classification performed perfectly. In scenario 1, the access control was open for 8 seconds, the person was 6 meters away from the device, and the device was stopped. According to the formula, R=0.20, the theoretical classification was L0, and the actual classification was consistent. Scenario 2: Access control opens for 15 seconds, personnel are 4m away from the equipment and the equipment is operating normally, R=0.54, and the theoretical and experimental levels are both L2; Scenario 3: Access control opens for 35 seconds, personnel are 2.5m away from the device, and the device is operating under high load. R=1.00, and the classification is L3. Scenario 4 and Scenario 5 calculated R=0.42, and were both classified as L1. The classification accuracy was 100% in 200 tests. Compared with the traditional fixed-value triggering system, this system has upgraded from a single-dimensional evaluation to a three-dimensional evaluation of time, location and device status. The misclassification rate has been reduced from 8-12% to 0%, and it supports dynamic adjustment for special scenarios. This demonstrates that the system's safety response model accurately calculates risk values, has reasonable classification logic, and its dynamic risk value calculation method comprehensively considers various safety influencing factors. It avoids the problems of equipment shutdown or risk omission caused by mis-triggered single conditions in traditional systems. The 100% classification accuracy and flexible scenario adaptability ensure that the system can make the most reasonable safety response based on the actual risk situation in complex warehouse environments, balancing warehouse operation efficiency and security protection needs.

[0027] IV. Low Temperature Environment Adaptability Experiment Experimental objective: To verify the stability and functional effectiveness of the system in a cold chain warehouse at a low temperature of -25℃; Low-temperature performance degradation rate formula: Performance degradation rate = (Low-temperature environment data - Normal temperature environment data) / Normal temperature environment data * 100%; Under a test environment of -25℃ for 48 hours, the access control status sensor had a status recognition error of 0.7%, which is slightly higher than the 0.4% at room temperature, but still lower than the theoretical requirement of ≤1.5%. The data acquisition delay was 11.3ms, which meets the ≤15ms standard. The personnel detection radar position recognition deviation is 0.51m, which is lower than the ≤0.8m requirement; the data transmission delay is 6.2ms, which meets the ≤8ms requirement; the L2 level system response time is 45.8ms, which is lower than the theoretical value of ≤60ms. Although the performance of each device is somewhat reduced at room temperature, such as the access control sensor recognition error attenuation rate of 75%, the data after attenuation is still far better than the industry's 3-5% error standard at low temperature. Experimental results demonstrate that the system exhibits excellent adaptability to low-temperature environments. The low-temperature resistant equipment selected for cold chain warehouses, after special protective treatment, can still operate stably in extreme low-temperature environments, with key performance indicators meeting safety requirements. This overcomes the limitations of traditional automated warehouse systems, which are prone to equipment failure, inaccurate data acquisition, and response delays in low-temperature environments. It ensures that the system's safety protection functions remain effective during normal operation of the cold chain warehouse, providing a reliable guarantee for the safe operation of automated warehouses in the cold chain industry.

[0028] Overall, the four experiments verified the high reliability, efficiency, and environmental adaptability of the automated warehouse access control system from four core dimensions: data source, response speed, decision logic, and environmental adaptability. Its comprehensive performance is significantly better than that of traditional systems, and it can provide comprehensive, accurate, and rapid security protection for automated warehouses. It is especially suitable for the warehouse security operation needs in special environments such as conventional and cold chain environments.

[0029] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.

Claims

1. A linkage control system based on access control status applied in an automated warehouse, comprising a sensing layer for data acquisition, a control layer for core control decisions, and an action output layer for releasing control commands, characterized in that, The perception layer includes access control status sensors used to collect access control opening and closing signals in real time; Personnel detection radar used to accurately identify whether people have entered automated areas; Equipment status monitor used to obtain the real-time operating status of hoists and AGV equipment; An emergency button module for on-site personnel to trigger emergency safety commands; The access control status sensor and personnel detection radar should be installed in locations that cover all access control entrances and the working areas of automated equipment. The equipment status monitor and the control connection of the hoist and AGV equipment should maintain signal communication. The emergency button module should be installed in a fixed location that is easy for personnel to reach and should have a structure to prevent accidental touch. The control layer includes a safety linkage controller for receiving data from the perception layer and executing linkage control logic. A device braking algorithm based on a safety response model that calculates and outputs device control commands; A security level assessment module used to determine the security response level based on data collected from the acquisition layer; A real-time response engine to ensure the rapid transmission and execution of control commands; The control layer maintains a smooth communication link with the perception layer and the execution layer. The control layer pre-stores device type, working range, and safety threshold parameters according to the actual situation. The execution layer includes an emergency braking module for receiving control commands and executing equipment stop operations. An installation status indicator panel used to display the current security level of the system and the status of the equipment; An alarm and notification module used to trigger audible and visual alarms and push security notifications when a security incident occurs; A reset and recovery control module used to detect the installation status and initiate the equipment recovery process after the warehouse door is closed; The equipment emergency braking module receives control commands from the control layer and executes the equipment stop operation. The installation status indicator and alarm and notification module are installed in a prominent position in the warehouse and are directly observable by personnel. The reset and recovery control module has preset safety data verification conditions for equipment restart.

2. The linkage control system based on access control status applied in an automated warehouse according to claim 1, characterized in that: Access control status sensors are installed at the entrances of all automated areas, such as fences, automatic doors, and maintenance doors. Each access control system corresponds to at least one set of sensors. At the same time, each set of access control status sensors is synchronously set with a set of door opening signal detectors and a set of door closing detectors to ensure accurate capture of the three states of door open, door closed, and door not fully closed. The data collection frequency is set to refresh the data once every 10ms to avoid missed judgments due to signal delay. During installation, avoid areas with high dust concentration and severe vibration in the warehouse. At the same time, take waterproof and moisture-proof measures. For cold chain warehouses with a low temperature environment of -25℃, select a low temperature resistant model. After installation, calibrate by simulating door opening and closing actions to ensure that the signal recognition error is ≤1% and that the status data can be transmitted to the control layer in real time through the communication line. Personnel detection radars are deployed in an X-shaped, cross-coverage pattern around the working areas of the hoist and AGV four-way vehicle. The detection range of the personnel detection radars covers an area with a radius of 1.5 times the operating trajectory of the equipment, avoiding any blind spots in monitoring. The personnel detection radar has the intelligent identification function to distinguish between personnel, goods, and equipment, and filters false alarms by setting parameters such as target volume and moving speed, reducing false triggers caused by goods handling. During operation, the radar transmits personnel location data to the control layer every 5ms. If personnel are detected entering a dangerous area, the radar immediately marks the personnel intrusion signal and triggers the early warning mechanism simultaneously.

3. A linkage control system based on access control status applied in an automated warehouse according to claim 2, characterized in that: The equipment status monitor directly interfaces with the control systems of automated equipment such as hoists and AGVs. It collects equipment operating parameters in real time through data interfaces, including the hoist's lifting speed, load weight, and running position, and the AGV's travel speed, navigation status, and battery level. The collected parameters include three core types of information: whether the equipment is running, whether it is running normally, and whether it is in a high-risk working condition. The monitor has a fault diagnosis function. If it finds that the equipment parameters exceed the safety threshold, such as the hoist load exceeding the rated value by 10%, it immediately sends an equipment abnormality signal to the control layer, providing a basis for equipment risk assessment for safety evaluation. The safety linkage controller has multi-channel data receiving capability, and can simultaneously process input data from four types of devices: access control status sensors, personnel radar, equipment status monitors, and emergency button modules. The data receiving delay is ≤5ms. The controller has a preset data verification mechanism to check the integrity and validity of each set of received data, and to determine whether the access control status data is one of three valid values: open, closed, or not closed properly, and whether the personnel location data is within the preset automation area. If data abnormality, missing data, or incorrect format is found, a data retransmission command is immediately sent to the perception layer, and the most recent valid data is used as a temporary substitute to avoid decision interruption due to data abnormality. The equipment braking algorithm is the core software module of the control layer. Its core is to calculate the risk value R based on the safety response model. The model formula is R=(T*Wt) plus (P*Wp) plus (E*We). The access control opening time coefficient (T) is dynamically adjusted according to the access control opening time: T=0.3 for 0-10s, T=0.6 for 10-30s, and T=1.0 for more than 30s. P (personnel location hazard factor) is determined based on the distance between personnel and equipment. When the distance is ≥5m, P=0.2; when the distance is 3-5m, P=0.5; and when the distance is <3m, P=1.

0. E (equipment operating status coefficient) is set according to the equipment operating conditions. When the equipment is stopped, E=0; when it is running normally, E=0.5; and when it is running under high load / high speed, E=1.

0. Wt (time weight), Wp (location weight), and We (device weight) are fixed at 0.4, 0.4, and 0.2 respectively to ensure the stability of the algorithm logic; The algorithm calculates the R value every 2ms and determines the security level based on the R value range: R < 0.5 is L1 (normal level), 0.5 ≤ R < 0.8 is L2 (emergency level), and R ≥ 0.8 is L3 (special level). The security level assessment module performs secondary verification by combining the algorithm calculation results with the actual triggering scenario to avoid misjudgment caused by a single data point. When the access control is activated and triggers Level 1, the module checks whether the personnel radar has detected personnel entering. If no personnel are detected, the response level is downgraded to a warning state, which only prompts the equipment to slow down rather than stop immediately. If the emergency button module triggers Level 2, the module checks whether the button has been reset. If it has been reset and there is no risk to personnel, the device lockout state can be terminated in advance. The evaluation module also has pre-set special scenario processing logic. For example, when the access control status sensor in a cold chain warehouse is delayed due to low temperature, the data acquisition time window is automatically extended to avoid the sensor delay from misjudging that the door is not closed properly. The real-time response engine ensures the rapid generation and transmission of control commands. After determining the safety response level, it generates the corresponding device control commands within ≤10ms. The L1 level instruction is "Stop the elevator and AGV-related equipment, but keep auxiliary equipment such as conveyors running"; The L2 level command is "Stop all automated equipment, lock equipment control permissions, and prohibit manual start-up"; The L3 level command is to "stop all equipment in the entire area and cut off the power supply to all equipment except emergency lighting"; After the instruction is generated, the engine transmits it to the execution layer through a dedicated communication channel, and at the same time sends an instruction log to the control terminal to record information such as the instruction generation time, level, and involved devices, so as to facilitate subsequent traceability. The control layer also has an instruction feedback receiving function. If the execution layer fails to provide a signal that the instruction has been executed within the specified time L1≤20ms, L2≤15ms, L3≤10ms, the instruction will be automatically resent and an alarm will be triggered to ensure that the instruction is executed properly.

4. A linkage control system based on access control status applied in an automated warehouse according to claim 3, characterized in that: The equipment emergency braking module is designed with a dedicated braking scheme for different types of AGV equipment to ensure that the braking effect matches the characteristics of the equipment. For the hoist, the equipment emergency braking module triggers both mechanical braking and electrical braking at the same time: the mechanical braking clamps the hoist guide rail with brake pads to prevent the car from falling. The electric brake cuts off the motor power supply to prevent the motor from continuing to run. The braking response time is ≤30ms. After braking, the AGV's related equipment will lock the car in its current position, prohibiting free movement. For AGV four-way vehicles, the equipment emergency braking module adopts an emergency stop and position locking mode: immediately cut off the AGV drive power, fix the vehicle position through the wheel locking mechanism to prevent the AGV from sliding due to inertia, and send an emergency stop signal to the AGV navigation system to prevent other AGVs from approaching the area. The equipment emergency braking module has a manual trigger function. When the control layer command fails, the equipment operator can perform an emergency stop through the manual brake switch on the equipment to ensure dual safety protection. The system status indicator panels are installed at the warehouse access control entrance, equipment operation area, and monitoring room, and use a combination of lights and screens to intuitively display the system status. The indicator lights distinguish safety levels by color: green indicates normal status (L0), yellow indicates warning status, i.e., the door is open but there are no people, and red indicates safety event status (L1, L2, L3). Among them, the L1 level is a flashing red light with a flashing frequency of 1 time / second, the L2 level is a solid red light, and the L3 level is a red light with a buzzer sound, with a frequency of 2 times / second. The display screen shows the current security level, trigger cause, involved equipment, response time and other information in real time, so that on-site personnel can quickly understand the situation. The indicator panel also has a power failure backup function, which can maintain operation for at least 30 minutes when the warehouse loses power, so as to ensure that the status information is not interrupted in an emergency.

5. A linkage control system based on access control status applied in an automated warehouse according to claim 1, characterized in that: The alarm and notification module provides dual coverage of on-site alarms and remote notifications. On-site alarms are issued through audible and visual alarms. Several sets of audible and visual alarms are installed in various areas of the warehouse. When the audible and visual alarms are triggered, the volume is ≥85dB and the light visibility distance is ≥50m. Different safety levels correspond to different alarm modes: Level L1 is a short beep and a flashing yellow light; Level L2 is a long beep and a solid red light; Level L3 is a continuous long beep and a flashing red light plus a live broadcast, the broadcast of which is a pre-recorded message: "Emergency situation, do not enter the automated area, evacuate to the safe area immediately." Remote notifications send alarm information to the mobile apps or work terminals of warehouse managers, equipment maintenance personnel, and on-site safety officers through the system. The information includes the event time, location, level, triggering reason, and handling suggestions. The notification sending delay is ≤15 seconds to ensure that relevant personnel respond in a timely manner. The recovery control mechanism is a key auxiliary function of the execution layer. It is responsible for restoring equipment operation in an orderly manner according to the instructions of the control layer after a safety event is resolved, so as to avoid secondary risks caused by blind recovery. The recovery process follows the principle of hierarchical recovery and verification one by one: after the L1 level event is resolved, auxiliary equipment such as conveyor belts are restored first, and then core equipment such as elevators and AGVs are restored. Each piece of equipment runs for 10 seconds after startup, and the next one is restored only after confirming that there are no abnormalities. When an L2 or L3 level event is resolved, the equipment maintenance personnel first manually check the braking status and operating parameters of each piece of equipment. After confirming that there are no faults, they send a recovery permission command to the execution layer through the control terminal. The execution layer then starts the equipment in the order from non-core equipment to core equipment. During the recovery process, the execution layer provides real-time feedback on the equipment startup status to the control layer. For example, AGV1 has started and is running normally, while hoist 2 failed to start with error code E03. If a device fails to start, the recovery process is stopped immediately. After the fault is resolved, the device is restarted. Once the recovery is complete, the execution layer sends a recovery completion signal to the control layer, and the safety status indicator is switched to green to end the alarm notification, ensuring that the system returns to normal operation.

6. A linkage control system based on access control status applied in an automated warehouse according to any one of claims 5, characterized in that: This system operates under conditions where the warehouse power supply voltage fluctuation is ≤±5% and the backup power supply UPS power is ≥90%. The sensing layer, control layer, and execution layer equipment must be free of physical damage and unobstructed installation locations. The equipment maintenance personnel should close the circuit in the order of main switch, backup power supply, and sub-equipment power supply to avoid current surges that could damage the hardware. After closing the circuit, observe the power indicator lights of each device. No tripping or abnormal noise is normal. If a tripping occurs, immediately check for short circuits in the lines, resolve the issue, and then close the circuit again. Next, the system administrator sequentially activates the access control status sensor, personnel detection radar, and emergency button module in the perception layer, the safety linkage controller and real-time response engine in the control layer, and the equipment emergency braking module and alarm and notification module in the execution layer on the control terminal, and waits for each module to complete its self-test. Subsequently, the equipment maintenance personnel performed precise calibration on the sensing equipment: simulating the opening and closing actions of the access control system to confirm that the signals collected by the access control status sensors were consistent with the actual status, with an error of ≤1%. The test target simulates the movement of a human body's metal frame at different positions in an automated area, and the personnel detection radar is calibrated to ensure that the position recognition deviation is ≤0.5m; If the calibration deviation is too large, clean the equipment probe or adjust the installation angle and retest. The system administrator should enter the equipment operating parameters for the day, including the AGV working route and the load threshold of the elevator. At the same time, confirm the weights of the safety response model, where the time weight Wt=0.4, the location weight Wp=0.4, and the equipment weight We=0.2 are correct data. After saving the parameters, check whether they are synchronized with the warehouse WCS system to avoid data inconsistency that may cause linkage failure. Finally, the equipment maintenance personnel and the on-site safety officer jointly tested the linkage function: simulated the L1 scenario and opened the regular access control, and observed whether the hoist and AGV stopped within ≤100ms; Simulate pressing the emergency button module in an L2 scenario and confirm that all devices stop and lock within ≤50ms; Simulate an L3 scenario by triggering an intruder with a test target, and check whether all devices in the area stop urgently within ≤30ms. After all tests are passed, the system administrator confirms on the control terminal that the system is ready to run, the status indicator light turns green, and the initialization process is complete.

7. A linkage control system based on access control status applied in an automated warehouse according to claim 5, characterized in that: The real-time monitoring process runs through the entire warehouse operation. It is executed under the conditions that the equipment is running according to the preset process, the sensing layer components are continuously powered and there are no fault alarms. The core is to identify safety risks in a timely manner through real-time data collection and analysis, and provide a basis for linkage control. After the process is started, the on-site safety officer checks the control terminal monitoring interface every 5 minutes and focuses on three core data points: Check the access control status to see if there are any abnormalities or unauthorized access control openings. If any abnormalities are found, immediately contact on-site personnel to verify and rule out misoperation or unauthorized entry. Monitor the equipment operating status, including parameters such as the speed and load of the hoist and AGV, and ensure they are within preset thresholds. If any parameters exceed the limits, notify the equipment maintenance personnel to adjust the equipment operating parameters to avoid overload risks. Safety response level: Under normal circumstances, the system should be at L0 (no risk). If a level jump occurs, the on-site safety officer should wait to confirm the triggering cause. The system administrator exports real-time data every hour. Access control switch records include opening time, opening location, and closing time. Equipment start-stop records include the reason for triggering the stop and the stop duration. Response time data includes the actual response time for each linkage. Warehouse operation logs include personnel inspection plans and equipment scheduling records for verification to ensure that system data is consistent with actual operations and that there is no missing or incorrect data. If data inconsistency is found, check the communication link between the control layer and the perception layer to see if there is signal transmission delay or loss. After supplementing the missing data, mark the cause of the anomaly to facilitate subsequent maintenance and analysis. If the warehouse operation scenario changes temporarily, such as increasing the number of AGVs or adjusting the operating range of the hoist, the system administrator should promptly modify the corresponding equipment parameters on the control terminal, synchronize the changes to the WCS system, and test the equipment linkage function under the new parameters to confirm that the AGVs and hoists can still respond normally according to the access control status, thus avoiding security vulnerabilities caused by parameter changes.

8. A linkage control system based on access control status applied in an automated warehouse according to claim 5, characterized in that: Before confirming a shutdown, the system administrator should first check the equipment status through the control terminal to ensure that all equipment, such as the hoist and AGV, is displayed as stopped and that no equipment is running or malfunctioning. The automated area is scanned by personnel detection radar to confirm that no personnel remain. If personnel are found, evacuation is immediately arranged. Check the system data backup status for the day to confirm that the system has automatically backed up the content, including security event records, device start-up and shutdown records, and response time data. At the same time, manually export the data archive to the warehouse server to avoid data loss. The equipment maintenance personnel shut down system components in the order of execution layer, control layer, and perception layer: first, shut down the equipment emergency braking module and alarm and notification module at the execution layer to ensure that the equipment has no power output; Then shut down the safety linkage controller and real-time response engine in the control layer. Before shutting down, confirm that there are no unfinished instructions to avoid data transmission interruption. Finally, turn off the access control status sensor, personnel detection radar, and emergency button module in the perception layer. During the shutdown process, observe the indicator lights of each device to ensure that they are turned off normally without any error messages. After the components are shut down, the equipment maintenance personnel disconnect the power in the order of sub-equipment power supply, backup power supply, and main switch. Before disconnecting the main switch, check whether all equipment power switches have been reset to avoid current surge when the switches are turned on the next day.