A Community Security Early Warning Method and System Based on Multi-Source Alarm Merging
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-16
- Publication Date
- 2026-08-14
AI Technical Summary
若缺少对真实通行链路的约束,容易将无关告警误归并;若只按设备类型分别处理,又会造成重复上报
[0021]本发明的有益效果在于:本发明通过建立分层防区拓扑包和通行链路表,将社区内各类安防点位统一到由外向内的空间链路中,使多源告警能够按照真实通行路径进行锚定和比较。通过链路邻接判定和父子告警吸附处理,将门禁、视频、对讲、户内探测、设备防拆和线路异常等分散告警归并为同一归并事件骨架,减少同一事件被重复上报的情况。通过授权闭环度和未授权度的确定,将住户确认、远程开门、临时授权和物业维护工单纳入预警判定,降低正常通行被误判为异常事件的概率。通过链路连续度、源异构度、防区深入度和篡改附加量确定归并事件预警值,并结合事件类型生成预警母包,使预警结果具备路径、等级、类型和闭环状态,便于中心控制台及对应终端进行跟踪处理。
Smart Images

Figure CN122575010A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of security alarm technology, specifically relating to a community security early warning method and system based on multi-source alarm merging. Background Technology
[0002] With the widespread adoption of community security equipment, systems such as access control, intercoms, video surveillance, perimeter detection, indoor detection, anti-tampering devices, and line monitoring are typically deployed separately and report alarms independently. In actual operation, the same abnormal entry behavior often triggers multiple alarms consecutively at different locations. For example, an access control refusal may occur first, followed by a corridor video anomaly, and then a resident's door detection alarm. Current handling methods mostly report alarms as a single unit or simply merge alarms by time and location, making it difficult to determine whether these alarms belong to the same event on the same access path.
[0003] Community scenarios exhibit distinct spatial hierarchies, with pedestrian traffic typically proceeding sequentially through the community entrance, building entrance, unit access control, public passageways, resident doors, and interior areas. Even if different buildings, units, and residents are geographically close, they may not have actual communication paths. Without constraints on the actual traffic flow, irrelevant alarms can easily be mistakenly merged; processing alarms solely based on device type can lead to duplicate reporting. Furthermore, communities also involve normal traffic scenarios such as resident authorization, temporary visitor authorization, remote door opening, property maintenance, and disarming. The same alarm sequence may correspond to completely different event types under different authorization states. Therefore, how to uniformly process multi-source alarms, traffic paths, and authorization states to generate clear and traceable community security early warning results is a problem that needs to be solved in community security alarm systems. Summary of the Invention
[0004] This invention provides a community security early warning method and system based on multi-source alarm merging, which solves the technical problems in the background art.
[0005] This invention provides a community security early warning method based on multi-source alarm merging, comprising the following steps:
[0006] Step 1: Obtain the basic security configuration data and raw multi-source alarm data of the target community; establish a hierarchical defense zone topology package and access link table based on the basic security configuration data of the community, and establish a standardized alarm atomic package based on the raw multi-source alarm data;
[0007] Step 2: Based on the access link table and standardized alarm atomic packets, determine the link sequence position of each standardized alarm atomic packet in the access link table, and determine the link adjacency determination result between standardized alarm atomic packets;
[0008] Step 3: Based on the standardized alarm atomic packets and link adjacency determination results, perform parent-child alarm adsorption processing to obtain the merged event skeleton;
[0009] Step 4: Obtain the authorization class data corresponding to the merge event skeleton, and determine the authorization closure degree and unauthorized degree corresponding to the merge event skeleton based on the merge event skeleton and the authorization class data;
[0010] Step 5: Based on the merged event skeleton, determine the link continuity, source heterogeneity, defense zone depth, and tampering addition corresponding to the merged event skeleton;
[0011] Step 6: Based on link continuity, source heterogeneity, defense zone depth, unauthorized access level, and tampering addition, determine the merge event warning value corresponding to the merge event skeleton; determine the warning level based on the merge event warning value; and determine the event type based on the merge event skeleton, authorized closed loop, defense zone depth, and tampering addition.
[0012] Step 7: Generate a master warning packet based on the warning level and event type, and perform warning sending, status update and event reset based on the master warning packet.
[0013] This invention also provides a community security early warning system based on multi-source alarm merging, comprising:
[0014] The data construction module is used to acquire basic community security configuration data and raw multi-source alarm data of the target community; based on the basic community security configuration data, it establishes hierarchical defense zone topology packages and access link tables, and based on the raw multi-source alarm data, it establishes standardized alarm atomic packages;
[0015] The link determination module is used to determine the link sequence position of each standardized alarm atomic packet in the access link table based on the access link table and the standardized alarm atomic packets, and to determine the link adjacency determination result between the standardized alarm atomic packets.
[0016] The alarm merging module is used to perform parent-child alarm adsorption processing based on standardized alarm atomic packets and link adjacency determination results to obtain the merged event skeleton.
[0017] The authorization verification module is used to obtain the authorization class data corresponding to the merged event skeleton, and determine the authorization closure degree and unauthorized degree corresponding to the merged event skeleton based on the merged event skeleton and the authorization class data.
[0018] The structural quantity calculation module is used to determine the link continuity, source heterogeneity, defense zone depth, and tampering addition quantity corresponding to the merged event skeleton based on the merged event skeleton;
[0019] The early warning determination module is used to determine the early warning value of the merged event corresponding to the merged event skeleton based on link continuity, source heterogeneity, defense zone depth, unauthorized access level, and tampering addition; determine the early warning level based on the merged event early warning value; and determine the event type based on the merged event skeleton, authorized closure degree, defense zone depth, and tampering addition.
[0020] The closed-loop management module is used to generate a master warning package based on the warning level and event type, and to perform warning sending, status update and event reset based on the master warning package.
[0021] The beneficial effects of this invention are as follows: By establishing a hierarchical defense zone topology package and a access link table, this invention unifies various security points within the community into a spatial link from the outside in, enabling multi-source alarms to be anchored and compared according to the actual access path. Through link adjacency determination and parent-child alarm aggregation processing, scattered alarms such as access control, video, intercom, indoor detection, equipment tampering, and line anomalies are merged into a single merged event skeleton, reducing the occurrence of duplicate reporting of the same event. By determining the degree of authorization closure and unauthorized access, resident confirmation, remote door opening, temporary authorization, and property maintenance work orders are included in the early warning judgment, reducing the probability of normal access being misjudged as abnormal events. By determining the early warning value of the merged event through link continuity, source heterogeneity, defense zone depth, and tampering addition, and combining it with the event type to generate an early warning master package, the early warning result has path, level, type, and closed-loop status, facilitating tracking and processing by the central control console and corresponding terminals. Attached Figure Description
[0022] Figure 1 This is a flowchart of a community security early warning method based on multi-source alarm merging according to the present invention;
[0023] Figure 2 This is a flowchart illustrating the process of determining the link adjacency determination results between standardized alarm atomic packets according to the present invention.
[0024] Figure 3 This is a schematic diagram of a community security early warning system based on multi-source alarm merging according to the present invention. Detailed Implementation
[0025] The subject matter described herein will now be discussed with reference to exemplary embodiments. It should be understood that these embodiments are discussed only to enable those skilled in the art to better understand and implement the subject matter described herein, and changes may be made to the function and arrangement of the elements discussed without departing from the scope of this specification. Various processes or components may be omitted, substituted, or added as needed in the examples. Furthermore, features described in some examples may be combined in other examples.
[0026] It should be noted that, unless otherwise defined, the technical or scientific terms used in one or more embodiments of the present invention should have the ordinary meaning understood by one of ordinary skill in the art to which this invention pertains. The terms "first," "second," and similar terms used in one or more embodiments of the present invention do not indicate any order, quantity, or importance, but are merely used to distinguish different components. Terms such as "comprising" or "including" mean that the element or object preceding the word encompasses the elements or objects listed after the word and their equivalents, without excluding other elements or objects. Terms such as "connected" or "linked" are not limited to physical or mechanical connections, but can include electrical connections, whether direct or indirect. Terms such as "upper," "lower," "left," and "right" are used only to indicate relative positional relationships; when the absolute position of the described object changes, the relative positional relationship may also change accordingly.
[0027] like Figure 1 As shown, a community security early warning method based on multi-source alarm merging includes the following steps:
[0028] Step 1: Obtain the basic security configuration data and raw multi-source alarm data of the target community; establish a hierarchical defense zone topology package and access link table based on the basic security configuration data of the community, and establish a standardized alarm atomic package based on the raw multi-source alarm data;
[0029] Step 2: Based on the access link table and standardized alarm atomic packets, determine the link sequence position of each standardized alarm atomic packet in the access link table, and determine the link adjacency determination result between standardized alarm atomic packets;
[0030] Step 3: Based on the standardized alarm atomic packets and link adjacency determination results, perform parent-child alarm adsorption processing to obtain the merged event skeleton;
[0031] Step 4: Obtain the authorization class data corresponding to the merge event skeleton, and determine the authorization closure degree and unauthorized degree corresponding to the merge event skeleton based on the merge event skeleton and the authorization class data;
[0032] Step 5: Based on the merged event skeleton, determine the link continuity, source heterogeneity, defense zone depth, and tampering addition corresponding to the merged event skeleton;
[0033] Step 6: Based on link continuity, source heterogeneity, defense zone depth, unauthorized access level, and tampering addition, determine the merge event warning value corresponding to the merge event skeleton; determine the warning level based on the merge event warning value; and determine the event type based on the merge event skeleton, authorized closed loop, defense zone depth, and tampering addition.
[0034] Step 7: Generate a master warning packet based on the warning level and event type, and perform warning sending, status update and event reset based on the master warning packet.
[0035] In one embodiment of the present invention, basic community security configuration data and raw multi-source alarm data of the target community are acquired. A hierarchical defense zone topology package and a access link table are established based on the basic community security configuration data, and standardized alarm atomic packages are established based on the raw multi-source alarm data. The basic community security configuration data refers to the basic data related to the deployment, spatial affiliation, and access relationships of security points within the target community. The raw multi-source alarm data refers to the original alarm records generated by different security subsystems such as access control, building intercom, video surveillance, perimeter detection, indoor detection, equipment tamper protection, and line monitoring.
[0036] Specifically, information on security points within the target community is first collected. This information includes community entrance points, vehicle entrance points, building entrance points, unit access control points, public corridor points, elevator lobby points, resident door points, indoor detection points, perimeter detection points, building intercom points, video surveillance points, equipment tamper protection points, and line monitoring points. Each security point is associated with community identification, building identification, unit identification, floor identification, resident identification, point type, upstream point, downstream point, and the corresponding defense zone level. Community identifiers are used to distinguish different communities. Building identifiers, unit identifiers, floor identifiers, and resident identifiers are used to define the spatial affiliation of security points. Point type is used to distinguish point categories such as access control, video, intercom, detection, anti-tamper, and line monitoring. Upstream and downstream points are used to represent the connection relationship of the security point in the passage path. The security zone level is used to represent whether the security point is located in the community entrance / exit security zone, building unit security zone, public passage security zone, resident door security zone, or related security zone inside the household.
[0037] After obtaining information on each security point, a hierarchical topology package is established based on the hierarchical and attribution relationships of this information. The hierarchical topology package is a data set obtained by structuring security points according to community identifiers, building identifiers, unit identifiers, floor identifiers, resident identifiers, and point types. Specifically, during generation, the community identifier, building identifier, unit identifier, floor identifier, resident identifier, and point type corresponding to the same security point are combined according to a preset field order to obtain the hierarchical topology unit corresponding to that security point. Then, all hierarchical topology units within the target community are aggregated to obtain the hierarchical topology package. Each hierarchical topology unit corresponds one-to-one with a security point, ensuring that each subsequent alarm can be anchored to a specific spatial hierarchy. For example, the hierarchical topology unit corresponding to the camera in front of apartment 501 on the 5th floor of Unit 2, Building 1, can be jointly determined by the video surveillance points in front of the apartment, including Community A, Building 1, Unit 2, 5th floor, apartment 501, and the apartment's front door.
[0038] Furthermore, a access link table is established based on the actual passable sequence of each security point information. The actual passable sequence refers to the order in which personnel, vehicles, or visitors can pass through the target community according to the actual entrance, access control, passageway, and resident's door location, excluding jumps across enclosed areas, unconnected floors, or between different households. When establishing the access link table, direct connections are first determined based on the upstream and downstream points in each security point information. Then, continuous points are connected in the direction from the community perimeter to the resident's associated area to form at least one access link. Each access link includes several consecutive nodes from the community entrance, building entrance, unit access control, public passageway, resident's door location, and resident's interior. For example, from the east gate entrance point, the building 1 entrance point, the unit 2 access control point, the 5th floor corridor point, the 501 household's door location, to the 501 household's interior detection point, a corresponding access link for 501 household can be formed.
[0039] After establishing the hierarchical zone topology packets and access link tables, the system receives raw multi-source alarm data and converts it into standardized alarm atomic packets. A standardized alarm atomic packet is the smallest alarm data unit formed by unifying the fields of raw alarm records from different security subsystems. During the conversion, the source device information in the raw alarm records is first read and identified as the device identifier. Then, the corresponding hierarchical zone topology unit is located based on the device identifier, and the code corresponding to that topology unit is identified as the zone anchor code. Next, the alarm type is determined based on the trigger content in the raw alarm records, the trigger time is determined based on the occurrence time in the raw alarm records, and the identity verification result, intercom response result, image capture index, work order number, temporary authorization number, and line status flag are written into the supplementary information. Therefore, each standardized alarm atomic packet includes five items: device identifier, zone anchor code, alarm type, trigger time, and supplementary information. For example, when the access control unit 2 generates an identity verification failure record at 08:31:20, it can be converted into a standardized alarm atomic package containing the access control device identifier of unit 2, the corresponding zone anchor code of unit 2 access control, entrance alarm, 08:31:20 and identity verification failure information.
[0040] Meanwhile, the alarm types in the standardized alarm atomic packages are categorized into entry alarms, visual confirmation alarms, intrusion alarms, indoor alarms, device tampering alarms, and line fault alarms. Entry alarms include alarms related to entry actions, such as access control triggers, access control denials, and perimeter entry triggers; visual confirmation alarms include alarms that provide visual confirmation information, such as building intercom, video capture, corridor video anomalies, and resident door video anomalies; intrusion alarms include perimeter triggers, abnormal entry detection, and passageway anomaly triggers; indoor alarms include indoor detector triggers and abnormal door opening alarms; device tampering alarms include alarms for device disassembly, obstruction, and disconnection; and line fault alarms include records of disconnection, open circuits, and abnormal states of access control lines, video lines, intercom lines, and detection lines. After uniformly classifying alarm types, original alarms reported by different subsystems can participate in subsequent link adjacency determination and parent-child alarm absorption according to the same type system.
[0041] Through the above processing, the spatial hierarchy of security points, actual traversable paths, and multi-source alarm records of the target community are uniformly organized into hierarchical defense zone topology packages, access link tables, and standardized alarm atomic packages. This processing enables subsequent community security early warnings to be merged based on alarm location, alarm source, and access path, rather than being reported independently based on the trigger result of a single device. This provides a clear data foundation for subsequent determination of whether multiple alarms belong to the same abnormal entry event chain and reduces the erroneous merging of alarms across buildings, units, and households.
[0042] In one embodiment of the present invention, such as Figure 2 As shown, based on the access link table and standardized alarm atomic packets, the link sequence position of each standardized alarm atomic packet in the access link table is determined, and the link adjacency determination result between standardized alarm atomic packets is determined. This step is performed on the basis of the aforementioned hierarchical defense zone topology packet, access link table, and standardized alarm atomic packets, and is used to determine whether different standardized alarm atomic packets can be included in the same access event chain. The link sequence position refers to the sequential number of the link node corresponding to the standardized alarm atomic packet in the access link table, and the link adjacency determination result refers to the determination result of whether any two standardized alarm atomic packets meet the continuous merging conditions in terms of spatial link, access direction, and trigger time.
[0043] Specifically, the system first matches the corresponding link node in the access link table based on the zone anchor code in the standardized alarm atomic packet. The zone anchor code corresponds to the hierarchical zone topology unit in the aforementioned hierarchical zone topology packet, thus determining which security point the standardized alarm atomic packet originates from. The system then searches the access link table for the access link containing that security point and reads the node order of that security point in the access link, determining this node order as the link sequence position of the standardized alarm atomic packet. For example, if a certain access link sequentially includes the east gate of the community, the entrance of Building 1, the access control of Unit 2, the corridor on the 5th floor, and the door of Unit 501, and if the zone anchor code of a standardized alarm atomic packet corresponds to the access control of Unit 2, then the link sequence position of that standardized alarm atomic packet is the third node position in that access link.
[0044] After determining the link sequence location, link attribution is determined for any two standardized alarm atomic packets. First, it's determined whether the two standardized alarm atomic packets belong to the same access link; if they don't belong to the same access link, then it's determined whether they belong to adjacent access links. Adjacent access links refer to two access links that share a common upstream node, a common downstream node, or a direct transfer node in the access link table. Links located in the same building but belonging to different units, floors, or households without a direct access relationship are excluded. This limitation avoids misclassifying alarms that are spatially close but have discontinuous access paths as mergeable alarms. For example, although the alarm points in front of household 501 and household 502 are on the same floor, they correspond to different household links. If there is no direct access node between them, they are not considered adjacent access links.
[0045] For two standardized alarm atomic packets belonging to the same or adjacent links, the link order and time interval are further determined. Specifically, the trigger times of the two standardized alarm atomic packets are first compared, and the standardized alarm atomic packet with the earlier trigger time is designated as the preceding trigger alarm, and the standardized alarm atomic packet with the later trigger time is designated as the following trigger alarm. Then, the link sequence positions corresponding to the preceding and following trigger alarms are compared. If the link sequence position corresponding to the following trigger alarm is not earlier than the link sequence position corresponding to the preceding trigger alarm, the link order condition from the outside to the inside is satisfied. If the link sequence position corresponding to the following trigger alarm is earlier than the link sequence position corresponding to the preceding trigger alarm, it is determined to be a reverse jump, and the link adjacency condition is not satisfied.
[0046] Simultaneously, based on the alarm types in the two standardized alarm atomic packets, the maximum allowable time interval for the corresponding alarm type combination is read. This maximum allowable time interval is a pre-set time threshold for different alarm type combinations, used to limit whether two alarms belong to the same consecutive passage event in time. When determining the time interval, the trigger time of the later-triggered alarm is subtracted from the trigger time of the earlier-triggered alarm to obtain the trigger time interval. If the trigger time interval is greater than zero and does not exceed the maximum allowable time interval for the corresponding alarm type combination, the time continuity condition is met; if the trigger time interval is less than or equal to zero, or exceeds the maximum allowable time interval for the corresponding alarm type combination, the time continuity condition is not met. For example, the maximum allowable time interval between an access control rejection alarm and a subsequent corridor video anomaly alarm on the same link can be set to 120 seconds. If the access control rejection alarm occurs at 08:31:20 and the corridor video anomaly alarm occurs at 08:32:10, the trigger time interval between the two is 50 seconds, which meets the time continuity condition.
[0047] After determining link ownership, link order, and time interval, it is necessary to exclude cases involving crossing impassable nodes and reverse jumps. Crossing an impassable node refers to situations where two standardized alarm atomic packets, although having sequential node positions in the access link table, are separated by intermediate nodes such as closed access gates, restricted passages, different resident boundaries, or lack of configured direct access relationships. A reverse jump refers to a situation where a later-triggered alarm returns to an outermost defense zone relative to a previously triggered alarm, and is not within the scope of subsequent valid backtracking link determination. For two standardized alarm atomic packets that cross impassable nodes or involve reverse jumps, even if their trigger time interval meets the requirements, the link adjacency determination result is determined to be invalid.
[0048] When two standardized alarm atomic packets simultaneously meet the conditions of the same or adjacent access links, the link sequence position corresponding to the later-triggered alarm is not earlier than the link sequence position corresponding to the earlier-triggered alarm, the triggering time interval does not exceed the maximum allowable time interval of the corresponding alarm type combination, and there is no crossing of impassable nodes or reverse jump, the link adjacency determination result of the two is determined to be valid; otherwise, the link adjacency determination result of the two is determined to be invalid.
[0049] Through the above processing, the adjacency relationship between standardized alarm atomic packets is no longer determined solely by time proximity or location proximity, but is simultaneously constrained by the passageway, passage direction, and trigger time. This provides a clear and verifiable basis for subsequent parent-child alarm adsorption and merging event skeleton generation, reducing the erroneous merging of alarms across households, units, and non-continuous paths.
[0050] In one embodiment of the present invention, based on standardized alarm atomic packets and link adjacency determination results, a parent-child alarm adsorption process is performed to obtain a merged event skeleton. This step is performed based on the previously determined link adjacency determination results between standardized alarm atomic packets, and is used to organize scattered multi-source alarms into a merged event skeleton with an event start point, a path, and subsequent alarm expansion relationships. The parent-child alarm adsorption process refers to using standardized alarm atomic packets that can characterize the event start state as parent alarm candidates, and using standardized alarm atomic packets that can characterize subsequent spatial advancement, on-site confirmation, indoor triggering, and equipment anomaly as child alarm candidates. When the link adjacency relationship and alarm type correspondence are satisfied, the child alarm is attached to the event unit where the parent alarm is located.
[0051] Specifically, a parent-child alarm type correspondence is first established. This correspondence is a type matching relationship established according to the triggering sequence of community security events, used to define which alarm types can serve as the starting point of an event and which can serve as signals for the subsequent development of the event. Entrance alarms, perimeter alarms, and intercom anomaly alarms are determined as parent alarm candidates based on the aforementioned alarm type classification results. Perimeter alarms include alarms triggered by community boundaries, fences, and external detection of entrances and exits. Intercom anomaly alarms include alarms related to visitor access confirmation, such as missed calls, abnormally frequent calls, and resident refusal to confirm. Video anomaly alarms, resident door anomaly alarms, indoor trigger alarms, equipment tampering alarms, and line anomaly alarms are identified as sub-alarm candidates. Among them, video anomaly alarms and resident door anomaly alarms are alarms that confirm the status of the on-site video. Indoor trigger alarms indicate that the event is triggered by detection after entering the resident's associated space. Equipment tampering alarms and line anomaly alarms indicate that the event is accompanied by abnormal system states such as equipment damage, disconnection, or loss of connection.
[0052] After establishing the parent-child alarm type correspondence, standardized alarm atomic packets that meet the parent-child alarm absorption conditions are determined based on the link adjacency determination results and the parent-child alarm type correspondence. Specifically, the link adjacency determination results between two standardized alarm atomic packets are first read. If the link adjacency determination result is valid, the alarm types of the preceding and following alarms are read, and a valid correspondence is checked in the parent-child alarm type correspondence. If the link adjacency determination result is valid, and the preceding alarm is a parent alarm candidate and the following alarm is a child alarm candidate corresponding to that parent alarm candidate, the following alarm is determined to meet the parent-child alarm absorption conditions. If the link adjacency determination result is invalid, or the alarm types do not match the parent-child alarm type correspondence, the following alarm is determined not to meet the parent-child alarm absorption conditions. This calculation process is equivalent to simultaneously satisfying both the link validity and type validity conditions before determining the absorption determination result as valid; if either condition is not met, the absorption determination result is invalid.
[0053] After identifying standardized alarm atomic packets that meet the parent-child alarm adsorption conditions, the earliest parent alarm meeting these conditions is designated as the event starting point. The earliest parent alarm refers to the standardized alarm atomic packet with the earliest trigger time within the same merging range that conforms to the parent alarm candidate type. After determining the event starting point, subsequent child alarms are adsorbed sequentially from the outside in according to their link sequence position, and the adsorbed child alarms are attached to the event unit where the event starting point is located. For multiple child alarms with the same link sequence position, they can be arranged according to the order of their trigger times; for multiple child alarms with the same trigger time, they can be arranged according to a preset priority order of alarm types. For example, if the access control system in Unit 2 generates an access denial alarm at 08:31:20, the video anomaly alarm in the corridor on the 5th floor generates a video anomaly alarm at 08:32:10, and the detection point in front of Unit 501 generates a resident door anomaly alarm at 08:32:40, and all three belong to the same access link and meet the corresponding time interval requirements, the access denial alarm can be used as the starting point of the event, and the subsequent video anomaly alarm and resident door anomaly alarm can be sequentially absorbed into the same event unit.
[0054] During the process of absorbing subsequent sub-alarms, alarms of the same type that are repeatedly triggered by the same device within a preset compression time window are compressed. The preset compression time window is a time range set for repeated alarms, such as 30 seconds to 120 seconds. During compression, the absorbed alarm set is first sorted according to device identifier, alarm type, and trigger time. When multiple standardized alarm atomic packets generated by the same device have the same alarm type, and the time difference between the later alarm and the first alarm does not exceed the preset compression time window, only the first alarm is retained as a valid alarm, and the remaining alarms are no longer used as new path nodes in the event skeleton generation, but are accumulated in the repeated trigger count. If the time difference between the later alarm and the first alarm exceeds the preset compression time window, the later alarm is treated as a new valid alarm and re-participated in the subsequent absorption judgment. This process can prevent the same event from being repeatedly split due to device vibration, continuous obstruction, or continuous card swiping failures in access control. For example, if the same access control device generates 5 access denial alarms within 60 seconds, the first access denial alarm is retained, and the remaining 4 alarms are counted in the duplicate trigger count.
[0055] After completing parent-child alarm adsorption and duplicate alarm compression, a merged event skeleton is generated. The merged event skeleton is fixed as an event structure containing the event origin, path node sequence, adsorbed alarm set, deepest reaching zone, covered source type set, and duplicate trigger count. The event origin is determined by the earliest parent alarm; the path node sequence is obtained by arranging the link nodes of the adsorbed alarm in the access link table according to their link sequence positions; the adsorbed alarm set consists of the event origin and all valid child alarms; the deepest reaching zone is determined by the link node with the deepest zone level in the path node sequence; the covered source type set is obtained by deduplicating different alarm source types within the merged event skeleton; and the duplicate trigger count is determined by the number of duplicate alarms merged during the compression process. When a new alarm cannot meet the parent-child alarm adsorption conditions of the existing merged event skeleton, it is not forcibly attached to the existing merged event skeleton. Instead, the new alarm is used as a new candidate event origin or alarm to be adsorbed for subsequent processing.
[0056] Through the above processing, the previously scattered standardized alarm atomic packets from access control, intercom, video, resident door front, indoor detection, equipment tampering, and line anomalies are organized into a merged event skeleton with a clear event origin, passage path, alarm unfolding order, and repeated triggering status. This merged event skeleton can accommodate the aforementioned link adjacency determination results and provide a unified event carrier for subsequent authorized closed-loop verification, structural quantity calculation, and warning level determination, thereby reducing the multiple reporting of the same abnormal passage process and preventing alarms from different resident links and different entry paths from being incorrectly absorbed into the same event.
[0057] In one embodiment of the present invention, authorization-related data corresponding to the merged event skeleton is obtained, and based on the merged event skeleton and the authorization-related data, the authorization closure degree and the degree of non-authorization corresponding to the merged event skeleton are determined. This step is performed on the basis of the previously generated merged event skeleton and is used to determine whether the passage process corresponding to the merged event skeleton has complete authorization support. The authorization-related data refers to data that can prove that the passage behavior has a legal source, legal confirmation, legal destination, or legal operating basis. The authorization closure degree is used to characterize the completeness of the authorization chain corresponding to the merged event skeleton, and the degree of non-authorization is used to characterize the degree of authorization deficiency corresponding to the merged event skeleton.
[0058] Specifically, first, obtain the authorization data corresponding to the merged event skeleton. Authorization data includes access control release records, valid card swipe records, resident intercom confirmation records, remote door opening records, temporary visitor authorization records, property maintenance work order records, and disarming records. Access control release records are access records generated after successful identity verification by the access control device. Valid card swipe records are records matching the cardholder with the corresponding resident, building unit, or authorized area. Resident intercom confirmation records are records of resident confirmation of visitor calls. Remote door opening records are records generated after a resident, property management, or authorized terminal initiates a door opening operation. Temporary visitor authorization records are authorization records configured for specific visitors, time periods, and destinations. Property maintenance work order records are task bases generated for equipment maintenance, in-home repairs, or inspection operations. Disarming records are records of the corresponding defense zone being disarmed within a preset time period.
[0059] After acquiring the authorized data, it is matched one by one with the path nodes in the merged event skeleton. Path nodes are nodes arranged according to the access route table in the merged event skeleton, including community entrances, building entrances, unit access control points, public passages, and locations in front of or inside residents' homes. During matching, the target access route, target time range, and target destination corresponding to the merged event skeleton are first determined based on the event start point, path node sequence, deepest reached defense zone, and set of absorbed alarms in the merged event skeleton. Then, records in the authorized data that match the target access route, target time range, and target destination are filtered. The target time range can be determined based on the trigger time of the event start point, the trigger time of the last absorbed alarm, and the preset before and after extension time. For example, if the event start point occurs at 08:31:20, the last absorbed alarm occurs at 08:33:00, and the preset before and after extension time is 60 seconds, then the matching time range for the authorized data can be set to 08:30:20 to 08:34:00.
[0060] After completing path node matching, the following criteria are determined: access control identity consistency, intercom confirmation validity, remote door opening validity, temporary authorization matching, property maintenance work order matching, and authorized destination coverage. Access control identity consistency means that the identity object in the access control release record or legitimate card swipe record matches the target destination, target resident, or target authorized area corresponding to the merged event skeleton. Intercom confirmation validity means that the confirmation object, confirmation time, and corresponding path node in the resident intercom confirmation record match the path nodes and target time range in the merged event skeleton. Remote door opening validity means that the initiating entity, opening device, and opening time of the remote door opening record match the corresponding access control node and target time range in the merged event skeleton. Temporary authorization matching means that the visitor identity, authorization period, and authorized destination in the temporary visitor authorization record match the alarm ancillary information, trigger time, and deepest reaching zone in the merged event skeleton. Property maintenance work order matching means that the work area, work period, and work object in the property maintenance work order record match the path nodes and deepest reaching zone in the merged event skeleton. Authorized destination coverage refers to the fact that authorized data is allowed to reach a defense zone level no shallower than the deepest reaching defense zone of the merged event skeleton.
[0061] All six judgment results above adopt a binary judgment method of being true or false. When determining the authorization closure degree, first count the number of items that are true among access control identity consistency, intercom confirmation validity, remote door opening validity, temporary authorization matching, property maintenance work order matching, and authorization destination coverage; then use the number of items that are true as the numerator, and the total number of the six judgment items as the denominator, and the ratio of the numerator to the denominator to obtain the authorization closure degree. The authorization closure degree ranges from 0 to 1; if all six judgment items are true, the authorization closure degree is 1; if none of the six judgment items are true, the authorization closure degree is 0.
[0062] After obtaining the authorization closure degree, the unauthorized degree is determined based on the authorization closure degree. Specifically, the unauthorized degree is obtained by subtracting the authorization closure degree from the preset baseline value of 1. The unauthorized degree ranges from 0 to 1; the higher the authorization closure degree, the lower the unauthorized degree; the lower the authorization closure degree, the higher the unauthorized degree.
[0063] Furthermore, if the merged event skeleton contains access control rejection, resident refusal to confirm, or missing authorization data corresponding to path nodes, and the deepest reachable zone corresponding to the merged event skeleton is deeper than the zone level corresponding to the preceding path node, then the authorization loop is deemed invalid. Access control rejection refers to the result of the access control device failing to verify the identity and refusing passage; resident refusal to confirm refers to the result of the resident's intercom or remote confirmation terminal explicitly refusing passage; missing authorization data corresponding to path nodes means that the critical path nodes in the merged event skeleton do not match access control release records, resident intercom confirmation records, remote door opening records, temporary visitor authorization records, property maintenance work order records, or disarming records. This additional rule is used to handle situations where a single front-end action is insufficient to cover subsequent in-depth behaviors. For example, if a visitor has an intercom call record at the building entrance, but the resident refuses to confirm, and the merged event skeleton still extends to the resident's door zone, then the authorization loop is not considered valid.
[0064] When authorization loop closure is not established, the authorization loop closure degree can be corrected to 0, or the unauthorized degree can be corrected to 1, and the corrected unauthorized degree can be used in the calculation of subsequent merged event warning values. For merged event skeletons with disarming records, if the defense zone range, disarming time period, and disarming object of the disarming record all cover the path nodes in the merged event skeleton, then the authorization loop closure degree is calculated according to the authorization data; if the disarming record only covers part of the shallow defense zone, while the merged event skeleton has extended to the deeper defense zone that has not been disarmed, then the authorization destination coverage is not considered to be established.
[0065] Through the above processing, the merged event skeleton no longer directly enters the warning judgment based solely on the number or type of alarms. Instead, it first undergoes closed-loop verification of access control, intercom, remote door opening, visitor authorization, property work orders, and disarming status. This processing can distinguish between normal resident access, authorized visitor access, property maintenance access, and abnormal entry events, avoiding misjudging access processes with complete authorization chains as security warnings. At the same time, it can form a clear unauthorized degree for merged event skeletons that lack authorization and continue to penetrate into resident-related spaces, providing a definite data foundation for subsequent warning value calculation and event type determination.
[0066] In one embodiment of the present invention, based on the merged event skeleton, the link continuity, source heterogeneity, zone depth, and tampering addition corresponding to the merged event skeleton are determined. This step is performed after the aforementioned merged event skeleton has been generated and the authorized closure degree and unauthorized degree have been determined, and is used to perform structured quantification of the same merged event skeleton from four aspects: travel path, alarm source, zone level, and device status. The link continuity, source heterogeneity, zone depth, and tampering addition are all used as input parameters for subsequent merged event warning values.
[0067] Specifically, link continuity is first determined based on the path node sequence and the set of adsorbed alarms in the merged event skeleton. The path node sequence refers to the set of nodes arranged according to the link sequence position in the access link table in the merged event skeleton, and the set of adsorbed alarms refers to the set of valid standardized alarm atomic packets adsorbed into the same merged event skeleton. When determining link continuity, the total number of adjacent node pairs in the path node sequence is first counted, which is the number of path nodes minus one; then, it is determined whether each pair of adjacent nodes has a corresponding adsorbed alarm. If both adjacent nodes have corresponding adsorbed alarms, the adjacent node pair is recorded as a continuous node pair; finally, the link continuity is obtained by dividing the number of continuous node pairs by the total number of adjacent node pairs.
[0068] The link continuity can be expressed as: ,in, Represents the skeleton of the merge event The corresponding link continuity, Represents the skeleton of the merge event The number of path nodes in the data. Indicates the first The path node and the first The determination result of consecutive node pairs between path nodes; when the... The path node and the first When all path nodes have corresponding adsorption alarms The value is 1 if it is set to 1, otherwise it is 0. (This refers to merging event skeletons.) If the number of path nodes is less than or equal to 1, the link continuity is set to 0 to avoid the inability to calculate when the total number of adjacent node pairs is 0.
[0069] Furthermore, the source heterogeneity is determined based on the set of covered source types in the merged event skeleton and the preset total number of system-accessible source types. The set of covered source types is the set obtained by deduplicating each source type that has been adsorbed in the merged event skeleton. Source types include access control sources, building intercom sources, video surveillance sources, perimeter detection sources, indoor detection sources, equipment tamper protection sources, and line monitoring sources. The preset total number of system-accessible source types is the number of source types that can participate in the merging pre-configured by the target community security system, and it is a positive integer. When determining the source heterogeneity, the number of source types in the set of covered source types is first counted. Then, this number of source types is used as the numerator, and the preset total number of system-accessible source types is used as the denominator. The ratio of the two is used to obtain the source heterogeneity.
[0070] The source isomerism can be expressed as: ,in, Represents the skeleton of the merge event The corresponding source heterogeneity, Represents the skeleton of the merge event The collection of source types already covered in the data. This indicates the number of different source types in the source type set that have been covered. This indicates the total number of preset system access source types. Source heterogeneity is used to characterize the degree to which different security subsystems jointly form alarm support within the same merged event skeleton.
[0071] Furthermore, the depth of a defense zone is determined based on the deepest reach defense zone in the merged event skeleton and the preset weight values for each defense zone level. The deepest reach defense zone refers to the defense zone corresponding to the node whose defense zone level is closest to the resident's associated space in the path node sequence of the merged event skeleton. The preset weight values for each defense zone level are positive numbers pre-set according to the hierarchical depth of the community entrance / exit defense zone, building unit defense zone, public passage defense zone, resident door front defense zone, and household associated defense zone, and the deeper the defense zone is into the resident's associated space, the larger its corresponding weight value. When determining the depth of a defense zone, first read the preset weight value corresponding to the deepest reach defense zone, then read the maximum weight value among all defense zone hierarchical weight values; then use the preset weight value corresponding to the deepest reach defense zone as the numerator, and use the maximum weight value among all defense zone hierarchical weight values as the denominator, and the ratio of the two gives the depth of the defense zone.
[0072] The depth of the defense zone can be expressed as: ,in, Represents the skeleton of the merge event Corresponding defense zone depth, Represents the skeleton of the merge event The deepest point reached the defense zone. This represents the preset defense zone level weight value corresponding to the deepest defense zone reached. This represents the maximum weight value among all defense zone level weight values. The preset weight values for each defense zone level are set in ascending order of level depth: community entrance / exit defense zone, building unit defense zone, public passage defense zone, resident door defense zone, and related defense zone within the household.
[0073] Furthermore, based on the set of adsorbed alarms in the merged event skeleton, the tampering additional quantity is determined. Device tamper alarms refer to alarms generated when security equipment is disassembled, obstructed, disconnected, has its casing opened, or is in an abnormal installation state; line abnormality alarms refer to alarms generated when access control lines, video lines, intercom lines, detection lines, or communication lines experience disconnection, open circuit, short circuit, communication interruption, or abnormal status. When determining the tampering additional quantity, the set of adsorbed alarms in the merged event skeleton is traversed; if a device tamper alarm or line abnormality alarm exists in the set of adsorbed alarms, the tampering additional quantity is determined to be valid; if neither a device tamper alarm nor a line abnormality alarm exists in the set of adsorbed alarms, the tampering additional quantity is determined to be invalid. To facilitate subsequent calculation of the merged event warning value, a valid tampering additional quantity can be calculated as a value of one, and an invalid tampering additional quantity can be calculated as a value of zero.
[0074] Through the above processing, the merged event skeleton is converted into four types of deterministic parameters: link continuity, source heterogeneity, zone depth, and tampering addition. This processing avoids directly outputting warnings based solely on a single alarm or a single device status, enabling subsequent merged event warning values to simultaneously reflect path continuity, the degree of confirmation of multi-source alarms, zone depth, and abnormal device line status, providing a clear and verifiable quantitative basis for subsequent warning level and event type determination.
[0075] In one embodiment of the present invention, a merge event warning value corresponding to the merge event skeleton is determined based on link continuity, source heterogeneity, zone depth, unauthorized access level, and tampering addition. A warning level is determined based on the merge event warning value, and the event type is determined based on the merge event skeleton, authorized loop closure, zone depth, and tampering addition. This step is performed based on the previously obtained link continuity, source heterogeneity, zone depth, unauthorized access level, and tampering addition, and is used to uniformly transform multiple structured parameters corresponding to the merge event skeleton into comparable warning judgment results. The merge event warning value is a comprehensive risk quantification result for the same merge event skeleton; the warning level is a level result determined based on the threshold range into which the merge event warning value falls; and the event type is a security event category determined based on the alarm composition and status characteristics of the merge event skeleton.
[0076] Specifically, the link continuity, source heterogeneity, defense zone depth, unauthorized access, and tampering addition are first multiplied by their respective preset weight coefficients, and the results are summed to obtain the merge event warning value. The preset weight coefficients include the link continuity weight coefficient, source heterogeneity weight coefficient, defense zone depth weight coefficient, unauthorized access weight coefficient, and tampering addition weight coefficient. Each preset weight coefficient is a non-negative number, and the sum of the five preset weight coefficients is one. During calculation, the link continuity is first multiplied by the link continuity weight coefficient to obtain the link continuity contribution value; the source heterogeneity is multiplied by the source heterogeneity weight coefficient to obtain the source heterogeneity contribution value; the defense zone depth is multiplied by the defense zone depth weight coefficient to obtain the defense zone depth contribution value; the unauthorized access is multiplied by the unauthorized access weight coefficient to obtain the unauthorized access contribution value; and the tampering addition is multiplied by the tampering addition weight coefficient to obtain the tampering addition contribution value. Finally, the above five contribution values are summed to obtain the merge event warning value.
[0077] The merge event warning value can be expressed as: ,in, Represents the skeleton of the merge event The corresponding merge event warning value, Indicates link continuity. Indicates source heterogeneity. Indicates the depth of the defense zone. Indicates unauthorized status. This indicates alteration of the additional quantity. This represents the preset weight coefficient corresponding to the link continuity. This represents the preset weighting coefficient corresponding to the source heterogeneity. This represents the preset weighting coefficient corresponding to the depth of the defense zone. This represents the preset weight coefficient corresponding to the degree of unauthorized access. This represents the preset weighting coefficient corresponding to the altered additional amount; where, , , , and All are non-negative numbers and satisfy: The merged event warning value represents the comprehensive warning amount of the same merged event skeleton based on the continuity of the travel path, the coverage of the source type, the depth of the defense zone, the degree of authorization deficiency, and the abnormal state of the equipment line.
[0078] After obtaining the merged event warning value, it is compared with a preset warning level threshold to determine the warning level. The preset warning level thresholds include a Level 1 warning level threshold, a Level 2 warning level threshold, and a Level 3 warning level threshold, with the Level 1 threshold being lower than the Level 2 threshold, and the Level 2 threshold being lower than the Level 3 threshold. When the merged event warning value is lower than the Level 1 warning level threshold, it is determined as a general event record; when the merged event warning value is not lower than the Level 1 warning level threshold but lower than the Level 2 warning level threshold, it is determined as a level of concern warning; when the merged event warning value is not lower than the Level 2 warning level threshold but lower than the Level 3 warning level threshold, it is determined as a level of handling warning; and when the merged event warning value is not lower than the Level 3 warning level threshold, it is determined as an emergency warning. Therefore, the warning level can be stably output according to the same set of threshold rules, avoiding inconsistencies in warning level definitions caused by independent reporting from different alarm sources.
[0079] Furthermore, the event type is determined based on the merged event skeleton, authorization closure degree, defense zone depth, and tampering addition amount. The event types include at least abnormal entry warning, abnormal loitering warning, and device tampering warning. An abnormal entry warning refers to an event type where the merged event skeleton shows an entry action but lacks sufficient authorization support. Specifically, when the unauthorized degree exceeds a preset unauthorized threshold, the defense zone depth exceeds a preset depth threshold, and the merged event skeleton contains entry-type alarms, as well as at least one of video alarms and intrusion alarms, the event type is determined to be an abnormal entry warning. The entry-type alarm indicates that an entry action has occurred; at least one of the video alarms and intrusion alarms indicates that the entry action has a field confirmation signal or a detection trigger signal; the unauthorized degree and defense zone depth jointly limit the entry action to lacking authorization support and having entered a relatively deep defense zone.
[0080] An abnormal loitering warning refers to an event type where the merged event skeleton has entered a deeper defense zone, but has not formed an authorized closed loop and has not generated evidence of exit or withdrawal within a specified time period. The deeper defense zone can be determined based on a preset depth threshold; when the defense zone depth exceeds the preset depth threshold, the merged event skeleton is considered to have entered a deeper defense zone. The failure to form an authorized closed loop means that the degree of authorized closed loop is lower than the preset authorized closed loop threshold, or that the authorized closed loop has been determined to be invalid according to the aforementioned rules. The effective withdrawal link refers to an alarm sequence in the merged event skeleton that continuously moves from a deeper defense zone node to a shallower defense zone node within a preset detection time limit, and this alarm sequence meets the effective withdrawal direction and time interval requirements in the access link table. When the merged event skeleton enters a deeper defense zone but fails to form an authorized closed loop, and fails to form an effective withdrawal link within the preset detection time limit, the event type is determined to be an abnormal loitering warning.
[0081] Device tampering alert refers to an event type where the aforementioned device tampering alarm or line anomaly alarm exists in the merged event skeleton, accompanied by a device disconnection status in the corresponding security zone. Specifically, when the tampering addition is valid, and the corresponding security zone experiences at least one of the following disconnections within a preset detection window: device disconnection, access control disconnection, video disconnection, and intercom disconnection, the event type is determined to be a device tampering alert. The corresponding security zone refers to the security zone corresponding to the security point where the device tampering alarm or line anomaly alarm is located. The preset detection window is a time range set around the trigger time of the device tampering alarm or line anomaly alarm. Device disconnection, access control disconnection, video disconnection, and intercom disconnection respectively indicate that the corresponding device or subsystem has not returned valid status information, communication connection information, or heartbeat status information within the preset detection window.
[0082] When the same merged event skeleton simultaneously meets the criteria for multiple event types, the primary event type can be determined in the order of device tampering warning, abnormal entry warning, and abnormal loitering warning, and the remaining event types that meet the criteria can be written into the secondary event type information. Through the above processing, the warning level of the merged event skeleton is determined by the merged event warning value, and the event type is jointly determined by alarm composition, authorization loop, defense zone depth, and device status. This ensures that the warning output has both level differentiation and clear event semantics, providing a basis for subsequent warning master packet generation, differentiated transmission, and closed-loop status updates.
[0083] In one embodiment of the present invention, a master warning package is generated based on the warning level and event type, and warning sending, status updates, and event resets are performed based on the master warning package. This step is used to convert the merged event skeleton into a sendable, trackable, and resettable warning data object. The master warning package refers to a unified warning record generated around the same merged event skeleton, used to carry information such as event identity, event path, event category, warning level, sending target, and handling status.
[0084] Specifically, a master warning packet is first generated based on the warning level and event type. The master warning packet includes an event number, event path summary, event type, warning level, destination set, and closed-loop status. The event number is generated according to a preset coding rule based on the event origin, path node sequence, event type, and generation time corresponding to the merged event skeleton, and is used to uniquely identify this merged event. The event path summary is generated from the path node sequence in the merged event skeleton, and includes at least the defense zone where the event origin is located, the deepest defense zone reached, key intermediate nodes, and the corresponding trigger time. The event type follows the judgment results from the aforementioned abnormal entry warning, abnormal loitering warning, and device tampering warning. The warning level follows the judgment results from the aforementioned general event record, attention-level warning, handling-level warning, and emergency-level warning. The destination set is the set of terminals determined according to the event type and warning level, and the closed-loop status refers to the status markers of the master warning packet during the generation, transmission, confirmation, handling, recovery, and reset processes.
[0085] When generating the event path summary, the event origin and path node sequence in the merged event skeleton are first read, and then the critical path nodes are extracted according to the link sequence positions in the access link table. Subsequently, the event origin, the deepest reached defense zone, and the alarm node with the highest warning relevance in the adsorbed alarm set are written into the event path summary. The alarm node with the highest warning relevance refers to the alarm node directly related to the event type determination condition, such as entry-type alarm nodes and video-type alarm nodes in abnormal entry warnings, and device anti-tamper alarm nodes or line abnormality alarm nodes in device tampering warnings.
[0086] Furthermore, based on preset warning transmission rules, the warning master packet is sent to the central control console and the corresponding handling terminal. The preset warning transmission rules refer to the transmission relationship configured according to event type, warning level, and deepest reaching defense zone. The central control console receives all warning master packets, and the corresponding handling terminals include at least one of security terminals, property management terminals, homeowner terminals, and maintenance terminals. For abnormal entry warnings, when the warning level is a handling-level warning or an emergency-level warning, the warning master packet is sent to the central control console and the security terminal; when the deepest reaching defense zone is the resident's door front defense zone or an associated defense zone within the household, it is simultaneously sent to the corresponding homeowner terminal. For abnormal loitering warnings, the warning master packet is sent to the central control console and the property management terminal; when the abnormal loitering warning involves the resident's door front defense zone or an associated defense zone within the household, it is simultaneously sent to the corresponding homeowner terminal. For device tampering warnings, the warning master packet is sent to the central control console, the maintenance terminal, and the security terminal; when the device tampering warning involves access control, intercom, or video equipment, the corresponding device identifier and its location defense zone are marked in the warning master packet.
[0087] When sending an early warning, the event number, event path summary, event type, warning level, deepest reaching zone, critical alarm trigger time, and corresponding handling terminal are written into the sending record. If the sending target includes multiple terminals, a sending status is generated for each terminal, including pending sending, sent, received, and sent failed. If any terminal fails to send, the sending failure status of that terminal is retained, and the message is resent according to a preset number of retransmissions. If the number of retransmissions reaches a preset limit and the message is still not successfully sent, the sending status is written into the closed-loop status of the early warning master packet. This process can prevent the unified management of the same event by the central control console from being affected by the sending failure of a single terminal.
[0088] Within the warning hold window, when a new alarm falls within the path range corresponding to the same event number and the event type has not fundamentally changed, the new alarm is added to the original warning master packet and the closed-loop status is updated. The warning hold window refers to the event hold period calculated from the time the warning master packet is generated, for example, 180 seconds to 600 seconds. The path range corresponding to the same event number refers to the range of defense zones covered by the event path summary of the original warning master packet and the path node sequence corresponding to the merged event skeleton. When determining whether a new alarm falls within this path range, first determine its link node based on the defense zone anchor code in the standardized alarm atomic packet corresponding to the new alarm, and then determine whether the link node belongs to the path node sequence of the original merged event skeleton, an adjacent passing link node, or the associated node corresponding to the deepest reaching defense zone. If it belongs to the above range, and the event type corresponding to the new alarm is still the original event type, or only a supplementary alarm with the same event type is added, then it is determined that the event type has not fundamentally changed.
[0089] When a new alarm meets the conditions for overwriting, a new early warning master packet is not regenerated. Instead, the standardized alarm atomic packet corresponding to the new alarm is overwritten into the set of already absorbed alarms in the original early warning master packet. The event path summary, deepest arrival zone, sending destination set, and closed-loop status are updated based on the new alarm's zone anchor code, alarm type, and trigger time. If the new alarm causes the deepest arrival zone to deepen further, the event path summary is recalculated, and the new deepest arrival zone is used to determine whether it is necessary to add a homeowner terminal, maintenance terminal, or other corresponding handling terminal.
[0090] Furthermore, upon receiving records of manual confirmation, resident confirmation, remote reset, line restoration, equipment restoration, or disarming completion, the closed-loop status corresponding to the warning master packet is updated. Manual confirmation refers to records of confirmation of the warning master packet by the central control console, security terminal, or property management terminal; resident confirmation refers to records of confirmation of the warning master packet involving the resident's associated defense zone by the homeowner's terminal; remote reset refers to records of authorized terminals remotely deactivating or resetting the warning event; line restoration and equipment restoration refer to records of line abnormalities, equipment disconnection, and equipment tampering status returning to normal, respectively; disarming completion records refer to records of the corresponding defense zone completing disarming within the allowed time frame. The closed-loop status can be set sequentially to generated, sent, confirmed, in progress, restored, and reset. If multiple confirmation records are received for the same warning master packet simultaneously, the current closed-loop status is determined in the order of reset, restored, in progress, and confirmed.
[0091] At the end of the warning hold window, check if there are still new alarms of the same path and event type. If the warning hold window ends and no more alarms of the same path and event type are received, the corresponding path is restored to the state of being able to receive new events. The state of being able to receive new events means that new alarms that subsequently appear on this path will no longer be added to the original warning parent packet, but will re-participate in link adjacency determination, parent-child alarm absorption, and event skeleton generation. If there are still unconfirmed, unrecovered, or continuously triggered alarms of the same path and event type at the end of the warning hold window, the hold state of the warning parent packet is extended, and the corresponding path continues to be in the event-occupied state until the reset conditions of confirmation, recovery, or no new alarms are met.
[0092] Through the above processing, the early warning master package enables community security early warnings, after being merged from multiple sources, to be sent and tracked according to events, rather than being repeatedly reported as single alarms. This processing can reduce duplicate early warnings under the same path and the same event type, while retaining the supplementary role of subsequent new alarms on the original events, and restoring the path's ability to receive new events after confirmation, recovery, and the end of the window, thus forming a complete closed loop from early warning generation, early warning sending, status update to event reset.
[0093] like Figure 3 As shown, the present invention also provides a community security early warning system based on multi-source alarm merging, comprising:
[0094] The data construction module is used to acquire basic community security configuration data and raw multi-source alarm data of the target community; based on the basic community security configuration data, it establishes hierarchical defense zone topology packages and access link tables, and based on the raw multi-source alarm data, it establishes standardized alarm atomic packages;
[0095] The link determination module is used to determine the link sequence position of each standardized alarm atomic packet in the access link table based on the access link table and the standardized alarm atomic packets, and to determine the link adjacency determination result between the standardized alarm atomic packets.
[0096] The alarm merging module is used to perform parent-child alarm adsorption processing based on standardized alarm atomic packets and link adjacency determination results to obtain the merged event skeleton.
[0097] The authorization verification module is used to obtain the authorization class data corresponding to the merged event skeleton, and determine the authorization closure degree and unauthorized degree corresponding to the merged event skeleton based on the merged event skeleton and the authorization class data.
[0098] The structural quantity calculation module is used to determine the link continuity, source heterogeneity, defense zone depth, and tampering addition quantity corresponding to the merged event skeleton based on the merged event skeleton;
[0099] The early warning determination module is used to determine the early warning value of the merged event corresponding to the merged event skeleton based on link continuity, source heterogeneity, defense zone depth, unauthorized access level, and tampering addition; determine the early warning level based on the merged event early warning value; and determine the event type based on the merged event skeleton, authorized closure degree, defense zone depth, and tampering addition.
[0100] The closed-loop management module is used to generate a master warning package based on the warning level and event type, and to perform warning sending, status update and event reset based on the master warning package.
[0101] The embodiments of the present invention have been described above, but the present invention is not limited to the specific embodiments described above. The specific embodiments described above are merely illustrative and not restrictive. Those skilled in the art can make many other forms based on the guidance of the present embodiments, all of which are within the protection scope of the present embodiments.
Claims
1. A community security early warning method based on multi-source alarm merging, characterized in that, Includes the following steps: Step 1: Obtain basic security configuration data and raw multi-source alarm data for the target community; A hierarchical topology package and access link table are established based on the basic configuration data of community security, and a standardized alarm atomic package is established based on the original multi-source alarm data; Step 2: Based on the access link table and standardized alarm atomic packets, determine the link sequence position of each standardized alarm atomic packet in the access link table, and determine the link adjacency determination result between standardized alarm atomic packets; Step 3: Based on the standardized alarm atomic packets and link adjacency determination results, perform parent-child alarm adsorption processing to obtain the merged event skeleton; Step 4: Obtain the authorization class data corresponding to the merge event skeleton, and determine the authorization closure degree and unauthorized degree corresponding to the merge event skeleton based on the merge event skeleton and the authorization class data; Step 5: Based on the merged event skeleton, determine the link continuity, source heterogeneity, defense zone depth, and tampering addition corresponding to the merged event skeleton; Step 6: Based on link continuity, source heterogeneity, defense zone depth, unauthorized access level, and tampering addition, determine the merge event warning value corresponding to the merge event skeleton; The warning level is determined based on the merged event warning value, and the event type is determined based on the merged event skeleton, authorization closure degree, defense zone depth and tampering addition amount; Step 7: Generate a master warning packet based on the warning level and event type, and perform warning sending, status update and event reset based on the master warning packet.
2. The community security early warning method based on multi-source alarm merging according to claim 1, characterized in that, Obtain basic security configuration data and raw multi-source alarm data for the target community; Based on the community security basic configuration data, a hierarchical defense zone topology package and a access link table are established, and a standardized alarm atomic package is established based on the original multi-source alarm data, including: Step 11: Collect information on each security point within the target community and associate each security point with community identifier, building identifier, unit identifier, floor identifier, resident identifier, point type, upstream point, downstream point, and the level of the defense zone to which it belongs; Step 12: Based on the hierarchical and attribution relationships of each security point information, establish a hierarchical defense zone topology package; Step 13: Based on the actual passable sequence of each security point, establish a passable link table; Step 14: Receive the original multi-source alarm data, convert the original multi-source alarm data into standardized alarm atomic packets, and classify the alarm types in the standardized alarm atomic packets into entry alarms, visual confirmation alarms, intrusion alarms, indoor alarms, equipment tampering alarms, and line fault alarms.
3. The community security early warning method based on multi-source alarm merging according to claim 1, characterized in that, Based on the access link table and standardized alarm atomic packets, the link sequence position of each standardized alarm atomic packet in the access link table is determined, and the link adjacency determination results between standardized alarm atomic packets are determined, including: Step 21: Based on the zone anchor code in the standardized alarm atomic packet, match the corresponding link node in the access link table to determine the link sequence position of each standardized alarm atomic packet; Step 22: For any two standardized alarm atomic packets, determine whether they belong to the same transmission link; if they do not belong to the same transmission link, further determine whether they belong to adjacent transmission links. Step 23: For the two standardized alarm atomic packets that satisfy Step 22, determine whether the link sequence position corresponding to the later triggered alarm is not earlier than the link sequence position corresponding to the previously triggered alarm, and determine whether the triggering time interval does not exceed the maximum allowable time interval of the corresponding alarm type combination. Step 24: Exclude cases of crossing impassable nodes and reverse jumps, and determine the link adjacency determination result.
4. The community security early warning method based on multi-source alarm merging according to claim 1, characterized in that, Based on the standardized alarm atomic packets and link adjacency determination results, parent-child alarm snapping processing is performed to obtain the merged event skeleton, including: Step 31: Preset the correspondence between parent and child alarm types, and determine entrance alarms, perimeter alarms and intercom anomaly alarms as parent alarm candidates, and determine video anomaly alarms, resident door anomaly alarms, indoor trigger alarms, equipment tampering alarms and line anomaly alarms as child alarm candidates. Step 32: Based on the link adjacency determination results and the correspondence between parent and child alarm types, determine the standardized alarm atom packets that meet the parent-child alarm adsorption conditions; Step 33: Take the earliest parent alarm that meets the parent-child alarm absorption condition as the event starting point, and absorb subsequent child alarms in sequence according to the link sequence position. Step 34: Compress alarms of the same type that are repeatedly triggered by the same device within a preset compression time window to generate a merged event skeleton; Step 35: Fix the merged event skeleton into an event structure that includes the event starting point, path node sequence, set of adsorbed alarms, deepest reached zone, set of covered source types, and repeated trigger count.
5. A community security early warning method based on multi-source alarm merging according to claim 1, characterized in that, Obtain the authorization class data corresponding to the merge event skeleton, and based on the merge event skeleton and authorization class data, determine the authorization closure degree and non-authorization degree corresponding to the merge event skeleton, including: Step 41: Obtain the authorization data corresponding to the merged event skeleton. The authorization data includes access control release records, valid card swipe records, resident intercom confirmation records, remote door opening records, temporary visitor authorization records, property maintenance work order records, and disarming records. Step 42: Match the authorized data with the path nodes in the merged event skeleton one by one to determine the consistency of access control identity, the validity of intercom confirmation, the validity of remote door opening, the matching of temporary authorization, the matching of property maintenance work orders, and the coverage of authorized destinations. Step 43: Determine the authorization closure degree based on the results of the access control identity consistency, intercom confirmation validity, remote door opening validity, temporary authorization matching, property maintenance work order matching, and authorization destination coverage, and determine the unauthorized degree based on the authorization closure degree. Step 44: When there is access control rejection, resident refusal to confirm, or missing corresponding authorization records in the merged event skeleton, and the merged event skeleton is still advancing to a deeper defense zone, it is determined that the authorization loop is not established.
6. A community security early warning method based on multi-source alarm merging according to claim 1, characterized in that, Based on the merged event skeleton, the link continuity, source heterogeneity, defense zone depth, and tampering addition corresponding to the merged event skeleton are determined, including: Step 51: Determine the link continuity based on the path node sequence in the merged event skeleton and the set of adsorbed alarms; Step 52: Determine the source heterogeneity based on the set of covered source types in the merged event skeleton and the preset total number of system-accessible source types; Step 53: Determine the depth of the defense zone based on the deepest reached defense zone in the merged event skeleton and the preset weight values of each defense zone level; Step 54: If there is a device tamper alarm or line abnormality alarm in the merged event skeleton, the tampered additional quantity is determined to be valid; otherwise, the tampered additional quantity is determined to be invalid.
7. A community security early warning method based on multi-source alarm merging according to claim 1, characterized in that, Based on link continuity, source heterogeneity, defense zone depth, unauthorized access, and tampering addition, determine the merge event warning value corresponding to the merge event skeleton; The warning level is determined based on the merged event warning value, and the event type is determined based on the merged event skeleton, authorization closure degree, defense zone depth, and tampering addition amount, including: Step 61: Multiply the link continuity, source heterogeneity, defense zone depth, unauthorized degree, and tampering addition with the corresponding preset weight coefficients respectively, and sum the product results to obtain the merge event warning value; Step 62: Compare the merged event warning value with the preset warning level threshold to determine the warning level; Step 63: When the unauthorized access level exceeds the preset unauthorized access threshold, the zone depth exceeds the preset depth threshold, and the merged event skeleton contains entry alarms, video alarms, or intrusion alarms, the event type is determined to be an abnormal entry warning. Step 64: When the merged event skeleton enters a deeper defense zone but fails to form an authorized closed loop, and fails to form an effective pullback link within the preset detection time limit, the event type is determined to be an abnormal loitering warning. Step 65: When the tampered additional quantity is valid, and the corresponding defense zone has a device disconnection, access control disconnection, video disconnection, or intercom disconnection within the preset detection window, determine the event type as device tampering warning.
8. A community security early warning method based on multi-source alarm merging according to claim 1, characterized in that, A master warning packet is generated based on the warning level and event type, and warning sending, status updates, and event resets are performed based on the master warning packet, including: Step 71: Based on the warning level and event type, generate a warning master packet, which includes event number, event path summary, event type, warning level, set of sending destinations, and closed-loop status; Step 72: Based on the preset warning sending destination rules, send the warning master packet to the central control console and the corresponding processing terminal; Step 73: Within the warning hold window, when a new alarm falls within the path range corresponding to the same event number and the event type has not fundamentally changed, the new alarm is added to the original warning master packet and the closed-loop status is updated. Step 74: Upon receiving records of manual confirmation, resident confirmation, remote reset, line restoration, equipment restoration, or disarming completion, update the closed-loop status corresponding to the early warning master packet. When the early warning holding window ends and no further alarms of the same path and event type are received, restore the corresponding path to a state where new events can be received.
9. A community security early warning system based on multi-source alarm merging, characterized in that, The community security early warning method based on multi-source alarm merging as described in any one of claims 1-8 includes: The data construction module is used to acquire basic community security configuration data and raw multi-source alarm data of the target community; based on the basic community security configuration data, it establishes hierarchical defense zone topology packages and access link tables, and based on the raw multi-source alarm data, it establishes standardized alarm atomic packages; The link determination module is used to determine the link sequence position of each standardized alarm atomic packet in the access link table based on the access link table and the standardized alarm atomic packets, and to determine the link adjacency determination result between the standardized alarm atomic packets. The alarm merging module is used to perform parent-child alarm adsorption processing based on standardized alarm atomic packets and link adjacency determination results to obtain the merged event skeleton. The authorization verification module is used to obtain the authorization class data corresponding to the merged event skeleton, and determine the authorization closure degree and unauthorized degree corresponding to the merged event skeleton based on the merged event skeleton and the authorization class data. The structural quantity calculation module is used to determine the link continuity, source heterogeneity, defense zone depth, and tampering addition quantity corresponding to the merged event skeleton based on the merged event skeleton; The early warning determination module is used to determine the early warning value of the merged event corresponding to the merged event skeleton based on link continuity, source heterogeneity, defense zone depth, unauthorized access level, and tampering addition; determine the early warning level based on the merged event early warning value; and determine the event type based on the merged event skeleton, authorized closure degree, defense zone depth, and tampering addition. The closed-loop management module is used to generate a master warning package based on the warning level and event type, and to perform warning sending, status update and event reset based on the master warning package.