Building people and vehicle permission cross-station point unified management system and method
Patent Information
- Application Number
- CN202611068913.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-17
- Publication Date
- 2026-09-22
AI Technical Summary
[0004]然而,上述现有技术方案在实际应用中暴露出若干技术缺陷
[0060]本发明通过部署在局点边缘的异构协议转换模块,深度扫描并获取各厂商门禁机、车闸、访客机等终端的私有通信协议与SDK,将其精准映射并封装为统一设备抽象接口。在此基础上,通过为各异构硬件分配包含唯一标识、局点归属标签和功能类型标签的统一终端标识列表,打破了传统安防系统对特定硬件厂商的强依赖,降低了多局点异构硬件接入的技术门槛与改造成本,实现了对不同物理局点、不同厂商设备的高效无差别统一接入与标准化全生命周期管理。
Smart Images

Figure CN122802542A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of computer data processing technology, and in particular to a unified management system and method for cross-site access control of people and vehicles in buildings. Background Technology
[0002] As businesses expand and park management becomes more sophisticated, modern buildings and parks commonly deploy pedestrian and vehicular access control systems. These systems automatically control access control and gate systems by identifying and verifying the identities and permissions of personnel and vehicles. They are crucial information infrastructure for ensuring area security and improving management efficiency. At their core lies a complex data processing logic used to manage personnel information, vehicle data, access policies, and massive amounts of access event records.
[0003] In existing technologies, access control management is often challenging for large enterprises with multiple geographically dispersed office areas or factory sites. One common approach is to deploy an independent access control system for each site, with each system operating independently and data processing and device control handled by a local server. Another approach is to use a centralized management platform from a single vendor, attempting to connect all devices at all sites to a unified central server, where all data processing and authentication decisions are centrally handled.
[0004] However, the aforementioned existing technical solutions have revealed several technical shortcomings in practical applications. When different locations use equipment from different vendors, the incompatibility of their communication protocols and data formats leads to information silos between systems, making it impossible to achieve a unified global view and policy control. Even with a centralized management solution, there is a strong dependence on the central server and network connection. If the network link between a remote location and the central server fails, the access authentication function of that location may be paralyzed. Furthermore, the management of basic data such as personnel and vehicles is fragmented from the management of access control policy data, resulting in rigid processes when handling temporary access requests such as visitors, making it difficult to adapt to the flexible and dynamic management requirements of modern enterprises. Summary of the Invention
[0005] To address the aforementioned issues, this invention provides a unified management system and method for pedestrian and vehicle access permissions across different physical locations. It employs data processing technologies such as heterogeneous protocol conversion, edge computing, and dynamic permission generation to achieve unified, reliable, and dynamic management of pedestrian and vehicle access permissions across physical locations and equipment manufacturers.
[0006] The above objectives can be achieved through the following approach:
[0007] The unified management system for building personnel and vehicle access across different physical locations includes: an edge access adaptation layer deployed at each physical location, a central management backend integrating a dynamic business flow control engine, and heterogeneous hardware terminals distributed across these physical locations.
[0008] The device abstraction and terminal identification generation module is used to obtain the device attribute information and communication protocol of heterogeneous hardware terminals deployed at various physical sites, establish a device abstraction interface through heterogeneous protocol conversion, and generate a unified terminal identification list containing the unique identifier of each terminal, site affiliation label and function type label. The function types cover access control terminals, vehicle gate terminals and visitor integrated machine terminals.
[0009] The global unified data hub construction module is used to acquire organizational structure data, personnel multimodal characteristic data and vehicle information data, build a global unified data hub, and generate a set of personnel and vehicle data associated with global role tags;
[0010] The initial spatiotemporal permission matrix calculation module is used to calculate and generate an initial spatiotemporal permission matrix based on the unified terminal identifier list and personnel and vehicle data set, combined with preset site access rules. The initial spatiotemporal permission matrix includes personnel identifiers, vehicle identifiers, permitted sites, permitted time periods, and corresponding hardware terminal lists.
[0011] The matrix splitting and edge asynchronous distribution module is used to split the initial spatiotemporal permission matrix into a subset of site permissions corresponding to each site, asynchronously distribute it to the edge access adaptation layer of each site, and store it in the local cache of each site, supporting offline authentication.
[0012] The cross-site access request receiving module is used to receive cross-site access request initiated by users. The access request includes the access subject identifier, the target site, and the access time window.
[0013] The dynamic flow control and temporary permission distribution module is used to extract the corresponding site permission subset of the distribution based on the target site, submit the site permission subset and the access application request together to the dynamic business flow control engine, drive the approval process, trigger policy security verification in response to approval, generate a temporary spatiotemporal permission object, and distribute the temporary spatiotemporal permission object to the activated terminal of the target site with the function type of visitor all-in-one machine. The temporary spatiotemporal permission object includes the target site, hardware terminal identification code, activation time window and expiration time window;
[0014] The on-site activation and permission injection release module is used to receive the on-site verification pass signal fed back by the activation terminal, generate an activation command, and according to the activation command, send and inject the permission data contained in the temporary spatiotemporal permission object into the selected edge hardware terminal within the target site in real time, so that the edge hardware terminal performs the release operation for the actual personnel or vehicles corresponding to the access subject identifier within the activation time window.
[0015] Optionally, the device abstraction and terminal identifier generation module includes:
[0016] The device scanning and protocol acquisition unit is used to scan the access control machines, vehicle gates and visitor integrated machines connected in each site, and acquire their respective device SDKs and private communication protocols;
[0017] A heterogeneous protocol conversion unit is used to map the private communication protocol into a unified device abstraction interface by deploying heterogeneous protocol conversion at the edge of the local site;
[0018] The unified identifier generation unit is used to assign a unique identifier to each terminal based on the unified device abstraction interface, and bind the site label and function type label to generate a unified terminal identifier list.
[0019] Optionally, the heterogeneous protocol conversion unit includes:
[0020] The protocol text parsing subunit is used to parse the private communication protocol and extract the device control field, event reporting field, and status polling field from it.
[0021] The control primitive mapping subunit is used to establish a bidirectional data mapping relationship between the device control field, event reporting field, and status polling field and the preset standard control primitives in the unified device abstraction interface.
[0022] The communication message conversion subunit is used to convert the private communication messages of the heterogeneous hardware terminal into standard communication messages that conform to the unified device abstraction interface in real time according to the bidirectional data mapping relationship, so as to realize transparent communication between the management backend and the heterogeneous hardware terminal.
[0023] Optionally, the global unified data hub construction module includes:
[0024] The organizational structure management unit is used to obtain organizational structure data from multiple human resources systems and build an organizational structure tree library.
[0025] The multimodal feature acquisition unit is used to collect facial and fingerprint features to build a multimodal feature database of personnel.
[0026] The vehicle information integration unit is used to collect information on vehicles and related personnel to build a vehicle information database;
[0027] The global role tag association unit is used to associate the organizational structure tree library, personnel multimodal feature library, and vehicle information library based on the unique identifier of the personnel, and to assign global role tags according to the role of the personnel in the organizational structure, thereby generating a personnel and vehicle data set.
[0028] Optionally, the initial spatiotemporal authority matrix calculation module includes:
[0029] The access rule configuration unit is used to obtain predefined access rules for each site, wherein the access rules specify the permitted time periods and permitted device types for different roles at each site;
[0030] The permission matching processing unit is used to match each subject in the personnel and vehicle data set with the access rules based on the global role tags, and determine the authorized location, authorized time period and corresponding hardware terminal list for each subject respectively.
[0031] The permission matrix aggregation unit, connected to the permission matching processing unit, is used to aggregate the permission data of all subjects to form an initial spatiotemporal permission matrix.
[0032] Optionally, the matrix splitting and edge asynchronous distribution module includes:
[0033] The permission subset extraction unit is used to extract permission records belonging to the same local point from the initial spatiotemporal permission matrix, taking the local point identifier as the dimension, to form a local point permission subset corresponding to each local point.
[0034] An asynchronous message push unit is used to asynchronously push the local access permission subset to the edge access adaptation layer using a message middleware;
[0035] A local data persistence unit, deployed in the edge access adaptation layer, is used to write a subset of the received site permissions into the local persistence cache of the edge access adaptation layer.
[0036] The offline authentication control unit is used to control the edge access adaptation layer to switch to offline mode when the network connection with the data hub is detected to be interrupted, and to make authentication decisions for heterogeneous hardware terminals at the local site based only on a subset of site permissions in the local persistent cache.
[0037] Optionally, the offline authentication control unit includes:
[0038] The network status monitoring subunit is used to monitor the communication link status between the edge access adaptation layer and the data hub in real time, and to trigger an offline switching control signal when the communication link status is determined to be interrupted.
[0039] The local cache retrieval subunit is used to respond to the offline switching control signal, obtain the real-time authentication request triggered on the heterogeneous hardware terminal side, and retrieve the local persistent cache corresponding to the local permission subset of the real-time authentication request.
[0040] The offline authentication decision subunit is used to perform spatiotemporal matching verification between the current timestamp, terminal identification code, and personnel and vehicle identifier in the real-time authentication request and the retrieved local permission subset, and control the corresponding heterogeneous hardware terminal to execute a local release decision when the matching is successful.
[0041] Optionally, when the cross-site access request is a visitor request, the access subject identifier carries information about the person or vehicle being the visitor, and the dynamic flow control and temporary permission distribution module includes:
[0042] The workflow approval unit is used to obtain the cross-site access application request, match the target employee corresponding to the visitor in the global unified data hub construction module, use the approval account corresponding to the target employee as the approval node to drive the approval process, and obtain the corresponding approval signal.
[0043] A multimodal feature extraction unit is used to trigger a policy security check when the approval signal is received, and to extract the visitor's real-time facial image data and real-time vehicle license plate data from the cross-site access application request.
[0044] The temporary permission object generation unit is used to call the global unified data hub construction module to convert the real-time face image data and the real-time vehicle license plate data into visitor feature templates corresponding to the personnel multimodal feature data and license plate recognition fields corresponding to the vehicle information data, respectively, and calculate and generate the temporary spatiotemporal permission object in combination with the hardware terminal list specified in the corresponding local permission subset.
[0045] The permission object targeted distribution unit is used to target and distribute the temporary spatiotemporal permission object to the activated terminal with the function type of visitor all-in-one machine within the target site.
[0046] Optionally, the on-site activation and permission injection grant module includes:
[0047] The on-site verification receiving unit is used to acquire the on-site verification pass signal fed back by the activated terminal of the visitor all-in-one machine after successfully verifying the identity of the visiting subject;
[0048] An activation instruction generation unit is used to dynamically calculate and generate an activation instruction to activate the temporary spatiotemporal permission object locally in response to receiving the on-site verification pass signal.
[0049] The real-time permission injection unit is used to extract the permission data contained in the temporary spatiotemporal permission object according to the activation instruction, and to send and inject the permission data in real time into the selected edge hardware terminal in the target site.
[0050] The terminal control release unit is deployed on the edge hardware terminal and is used to control the edge hardware terminal to perform release operations on the actual personnel or vehicles corresponding to the access subject identifier within the activation time window.
[0051] Based on the same inventive concept, this invention also provides a method for unified management of building access permissions across different locations, the method comprising:
[0052] Obtain device attribute information and communication protocols of heterogeneous hardware terminals deployed at various physical sites, establish device abstraction interfaces through heterogeneous protocol conversion, and generate a unified terminal identifier list containing unique identifiers of each terminal, site affiliation tags, and function type tags. The function types cover access control terminals, vehicle gate terminals, and visitor integrated terminals.
[0053] Acquire organizational structure data, personnel multimodal characteristic data, and vehicle information data to build a globally unified data hub and generate a set of personnel and vehicle data associated with global role tags;
[0054] Based on the unified terminal identifier list and personnel and vehicle data set, and combined with the preset site access rules, an initial spatiotemporal permission matrix is calculated and generated. The initial spatiotemporal permission matrix includes personnel identifiers, vehicle identifiers, permitted sites, permitted time periods, and corresponding hardware terminal lists.
[0055] The initial spatiotemporal permission matrix is split into a subset of permissions corresponding to each local station, asynchronously distributed to the edge access adaptation layer of each local station, and stored in the local cache of each local station to support offline authentication.
[0056] Receive cross-site access request initiated by the user, wherein the access request includes the access subject identifier, the target site and the access time window;
[0057] Based on the target site, extract the corresponding site permission subset distributed to the site, submit the site permission subset and the access request together to the dynamic business flow control engine to drive the approval process. In response to the approval, trigger the policy security verification, generate a temporary spatiotemporal permission object, and distribute the temporary spatiotemporal permission object to the activated terminal of the target site with the function type of visitor all-in-one machine. The temporary spatiotemporal permission object includes the target site, hardware terminal identification code, activation time window and expiration time window.
[0058] Upon receiving the on-site verification pass signal from the activation terminal, an activation command is generated. Based on the activation command, the permission data contained in the temporary spatiotemporal permission object is sent and injected into the selected edge hardware terminal within the target site in real time, so that the edge hardware terminal can perform a release operation on the actual personnel or vehicles corresponding to the access subject identifier within the activation time window.
[0059] Compared with the prior art, the present invention has the following advantages:
[0060] This invention utilizes a heterogeneous protocol conversion module deployed at the edge of a site to deeply scan and acquire the proprietary communication protocols and SDKs of various manufacturers' access control machines, vehicle gates, visitor machines, and other terminals. These protocols are then precisely mapped and encapsulated into a unified device abstraction interface. Based on this, a unified terminal identifier list, containing unique identifiers, site affiliation tags, and function type tags, is assigned to each heterogeneous hardware device. This breaks the strong dependence of traditional security systems on specific hardware manufacturers, reduces the technical barriers and transformation costs for multi-site heterogeneous hardware access, and achieves efficient, undifferentiated, unified access and standardized full lifecycle management for different physical sites and devices from different manufacturers.
[0061] This invention constructs a globally unified data hub, deeply associating previously scattered organizational structure tree data, collected multimodal feature data such as facial and fingerprint data, and dynamically collected vehicle and associated personnel data based on unique personnel identifiers at the underlying data level. Simultaneously, it creatively introduces a global role tagging mechanism to generate strongly correlated and highly cohesive personnel and vehicle data sets. This enables the system to break down "data silos," providing highly complete and consistent global data support for subsequent refined, multi-dimensional composite permission calculations and high-concurrency real-time retrieval of spatiotemporal permission matrices.
[0062] This invention employs a distributed architecture design of "centralized computing, asynchronous distribution, and local storage." Through a message middleware, the initial spatiotemporal permission matrix is split into permission subsets based on the site identifier, and these subsets are asynchronously pushed to the edge access adaptation layer of each physical site and written to a local persistent cache. When the edge access adaptation layer detects an anomaly or interruption in the network link with the central data hub, it can seamlessly switch to offline authentication mode within milliseconds, autonomously completing on-site authentication decisions solely relying on the local persistent cache. This reduces the system's strong dependence on backbone network bandwidth and stability, ensuring the continuous, uninterrupted, and robust operation of core personnel and vehicle access functions at each site under extreme disaster recovery scenarios such as network paralysis.
[0063] To address the management of high-risk, highly mobile cross-site temporary visitors, this invention pioneers a triple security barrier mechanism: dynamic flow control engine workflow, policy security verification, and on-site secondary verification activation. After a visitor's application is approved via a custom workflow engine driving the visitor's node, the system does not directly issue access permissions. Instead, it first generates temporary spatiotemporal permission objects with strong time-sensitivity and device limitations, and distributes them to the visitor's all-in-one machine at the target site. Only when the visitor successfully completes multimodal identity verification on-site through the visitor machine will a real-time activation command be triggered, instantly injecting the permission data into the edge hardware terminal. This closed-loop mechanism of "person arrival, verification successful, and instant on-demand permission injection" not only simplifies the workflow approval process for cross-site access but also avoids security vulnerabilities such as theft of temporary permissions, premature unauthorization, or long-term residency.
[0064] Other features and advantages of the invention will be set forth in the description which follows, and will be apparent in part from the description, or may be learned by practicing the invention. The objects and other advantages of the invention may be realized and obtained by means of the structures pointed out in the description, claims, and drawings. Attached Figure Description
[0065] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0066] Figure 1 This is a schematic diagram of the unified management system for building personnel and vehicle access across different locations, according to an embodiment of the present invention.
[0067] Figure 2 This is a graph showing the relationship between the time consumed by bidirectional conversion of heterogeneous protocol messages and the number of protocols in an embodiment of the present invention.
[0068] Figure 3 This is a heatmap of the frequency of authorization and concurrent flow control for each physical location under different passage periods in an embodiment of the present invention.
[0069] Figure 4 This is a flowchart illustrating the unified management method for building personnel and vehicle access across different locations, according to an embodiment of the present invention. Detailed Implementation
[0070] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0071] Reference Figure 1 One embodiment of the present invention proposes a unified management system and method for pedestrian and vehicle access permissions across physical locations. It adopts data processing technologies such as heterogeneous protocol conversion, edge computing and dynamic permission generation to achieve unified, reliable and dynamic management of pedestrian and vehicle access permissions across physical locations and equipment manufacturers.
[0072] The system described in this embodiment specifically includes:
[0073] The system consists of an edge access adaptation layer deployed at each physical location, a central management backend integrating a dynamic service flow control engine, and heterogeneous hardware terminals distributed across these physical locations.
[0074] The device abstraction and terminal identification generation module is used to obtain the device attribute information and communication protocol of heterogeneous hardware terminals deployed at various physical sites, establish a device abstraction interface through heterogeneous protocol conversion, and generate a unified terminal identification list containing the unique identifier of each terminal, site affiliation label and function type label. The function types cover access control terminals, vehicle gate terminals and visitor integrated machine terminals.
[0075] The global unified data hub construction module is used to acquire organizational structure data, personnel multimodal characteristic data and vehicle information data, build a global unified data hub, and generate a set of personnel and vehicle data associated with global role tags;
[0076] The initial spatiotemporal permission matrix calculation module is used to calculate and generate an initial spatiotemporal permission matrix based on the unified terminal identifier list and personnel and vehicle data set, combined with preset site access rules. The initial spatiotemporal permission matrix includes personnel identifiers, vehicle identifiers, permitted sites, permitted time periods, and corresponding hardware terminal lists.
[0077] The matrix splitting and edge asynchronous distribution module is used to split the initial spatiotemporal permission matrix into a subset of site permissions corresponding to each site, asynchronously distribute it to the edge access adaptation layer of each site, and store it in the local cache of each site, supporting offline authentication.
[0078] The cross-site access request receiving module is used to receive cross-site access request initiated by users. The access request includes the access subject identifier, the target site, and the access time window.
[0079] The dynamic flow control and temporary permission distribution module is used to extract the corresponding site permission subset of the distribution based on the target site, submit the site permission subset and the access application request together to the dynamic business flow control engine, drive the approval process, trigger policy security verification in response to approval, generate a temporary spatiotemporal permission object, and distribute the temporary spatiotemporal permission object to the activated terminal of the target site with the function type of visitor all-in-one machine. The temporary spatiotemporal permission object includes the target site, hardware terminal identification code, activation time window and expiration time window;
[0080] The on-site activation and permission injection release module is used to receive the on-site verification pass signal fed back by the activation terminal, generate an activation command, and according to the activation command, send and inject the permission data contained in the temporary spatiotemporal permission object into the selected edge hardware terminal within the target site in real time, so that the edge hardware terminal performs the release operation for the actual personnel or vehicles corresponding to the access subject identifier within the activation time window.
[0081] Optionally, the device abstraction and terminal identifier generation module includes:
[0082] The device scanning and protocol acquisition unit is used to scan the access control machines, vehicle gates and visitor integrated machines connected in each site, and acquire their respective device SDKs and private communication protocols;
[0083] A heterogeneous protocol conversion unit is used to map the private communication protocol into a unified device abstraction interface by deploying heterogeneous protocol conversion at the edge of the local site;
[0084] The unified identifier generation unit is used to assign a unique identifier to each terminal based on the unified device abstraction interface, and bind the site label and function type label to generate a unified terminal identifier list.
[0085] Specifically, this step aims to address the challenge of unified management of hardware terminals from different manufacturers and models due to varying communication protocols. The device scanning and protocol acquisition unit uses network detection technology at geographically dispersed physical locations to discover all online heterogeneous hardware terminals, including access control terminals, vehicle gate terminals, and visitor terminal units. Based on network response characteristics, it matches and loads the corresponding device SDK and private communication protocol from a pre-built device driver library. A heterogeneous protocol conversion unit deployed on the edge computing nodes of each location converts the private communication protocol into a standardized device abstraction interface (DAPI). A unified identifier generation unit generates a globally unique identity credential for each terminal based on the DAPI, thereby generating a unified terminal identifier list containing a unique identifier, location affiliation label, and function type label. To ensure the unique identifier is unique and tamper-proof throughout the system, its generation process uses the following formula:
[0086] ;
[0087] in, The unique identifier generated is a fixed-length string; The standard cryptographic hash function, in this embodiment, is the Secure Hash Algorithm 256 (SHA-256), which is used to convert input information of arbitrary length into a fixed-length digest to achieve collision prevention. The physical address of the network interface representing the heterogeneous hardware terminal, namely the MAC address, is unique globally and is based on the inherent hardware attributes derived from the analysis of 200 sets of measured data from industrial sensors. Represents the precise timestamp when the generation operation was performed, typically in UNIX timestamp format. Timestamps were introduced to prevent MAC address reuse conflicts in extremely rare cases. The symbols represent string concatenation operations. Information from each terminal is constructed into a data tuple. And compile them into a unified terminal identifier list. , can be represented as:
[0088] ;
[0089] in, , This represents a unified terminal identifier list containing all terminal information. The first in the list Information tuples of each terminal This is the first A unique identifier calculated by each terminal It is the first The local area affiliation tag for each terminal is set based on the physical local area network where the device was discovered. It is the first The function type label for each terminal can be selected from access control terminal, vehicle gate terminal, and visitor integrated terminal based on the device model and function.
[0090] For example, consider two access control terminals: the first and the second. The first terminal's LAN scan discovers an access control terminal from vendor A with IP address 192.168.1.100 and MAC address "0A1B2C3D4E5F". It loads the corresponding SDK and obtains the protocol. The second terminal's LAN scan discovers a gate terminal from vendor B with IP address 192.168.2.200 and MAC address "F0E9D8C7B6A5". Its protocol is also obtained. The heterogeneous protocol conversion unit establishes mappings between the two devices and a unified device abstraction interface. The unified identifier generation unit generates identifiers for the terminals at preset timestamps 1678886400 and 1678886460. (The timestamps of the access control terminals are shown in the original text.) The given value is "1678886400". When concatenated, it becomes "0A1B2C3D4E5F1678886400". Calculate... The unique identifier obtained is "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855", which is then bound to the site tag. "First Set Point" and Function Tags "Access control terminal", forming tuples Timestamp of the gate terminal The given value is "1678886460", which, when concatenated, becomes "F0E9D8C7B6A51678886460". Calculate... The unique identifier obtained is "a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2", which is then bound to the site tag. "Second Set Point" and Function Tags "Gate terminal", forming a tuple Finally, a unified terminal identifier list containing the above records is generated. This provides a standardized device object foundation for subsequent permission calculation and distribution.
[0091] Optionally, the heterogeneous protocol conversion unit includes:
[0092] The protocol text parsing subunit is used to parse the private communication protocol and extract the device control field, event reporting field, and status polling field from it.
[0093] The control primitive mapping subunit is used to establish a bidirectional data mapping relationship between the device control field, event reporting field, and status polling field and the preset standard control primitives in the unified device abstraction interface.
[0094] The communication message conversion subunit is used to convert the private communication messages of the heterogeneous hardware terminal into standard communication messages that conform to the unified device abstraction interface in real time according to the bidirectional data mapping relationship, so as to realize transparent communication between the management backend and the heterogeneous hardware terminal.
[0095] Specifically, this step aims to achieve transparent communication between the central management backend and heterogeneous hardware terminals at various physical sites through heterogeneous protocol conversion. The protocol text parsing subunit deeply analyzes each acquired private communication protocol, accurately identifying and extracting device control fields, event reporting fields, and status polling fields through syntactic and semantic analysis. The control primitive mapping subunit establishes a bidirectional data mapping relationship, associating the extracted private fields with the pre-defined standard control primitives in the unified device abstraction interface. Based on this bidirectional data mapping relationship, the communication message conversion subunit performs real-time bidirectional message conversion along the communication path between the central management backend and the heterogeneous hardware terminals. This bidirectional data mapping relationship... For the A heterogeneous hardware terminal can be formally represented as a pair of transformation functions:
[0096] ;
[0097] in, Representative regarding the first A two-way data mapping relationship is established between the terminals; For the decoding function, the first... Private communication messages of each terminal Convert to standard communication messages , is represented as: ; This is an encoding function responsible for encoding standard communication messages. Convert to the first Private communication messages of each terminal , is represented as: For a specific control command, the conversion process can be represented as follows: , here This represents the converted private control instruction section; This represents the original standard control command section; Representative regarding the first The specific field encoding mapping rules for each terminal map standard instruction names, parameters, etc., to corresponding fields of private instructions. These mapping rules are established based on data analysis of over 50 pre-set protocols from mainstream security equipment manufacturers. For example... Figure 2 The diagram illustrates the relationship between the bidirectional conversion time and the number of protocols handled by the heterogeneous protocol conversion unit when processing different numbers of proprietary protocols. As the number of access protocols increases, the encoding / decoding conversion time exhibits a linear growth trend. Due to the algorithm's high efficiency, the total latency remains stable within 4 milliseconds, demonstrating the mechanism's high real-time performance.
[0098] For example, taking the access control terminal at the first site and the vehicle gate terminal at the second site as examples, the protocol text parsing subunit parses the access control command at the first site as JSON format {"command_name":"open"}, with the event field being {"event_type":"swipe"}; and parses the vehicle gate command at the second site as XML format. <control> <action> lift_gate< / action> < / control> The control primitive mapping subunit maps the preset standard command "command":"OPEN" to the access control's "command_name":"open" and the vehicle gate's "command_name":"open" respectively. <action> lift_gate< / action> When sending standard control messages At that time, the communication message conversion subunit uses the encoding function to calculate the private message. And issue; when the access control reports a private event message. At that time, the calculation is converted into a standard communication message through a decoding function. Reporting enables transparent communication.
[0099] Optionally, the global unified data hub construction module includes:
[0100] The organizational structure management unit is used to obtain organizational structure data from multiple human resources systems and build an organizational structure tree library.
[0101] The multimodal feature acquisition unit is used to collect facial and fingerprint features to build a multimodal feature database of personnel.
[0102] The vehicle information integration unit is used to collect information on vehicles and related personnel to build a vehicle information database;
[0103] The global role tag association unit is used to associate the organizational structure tree library, personnel multimodal feature library, and vehicle information library based on the unique identifier of the personnel, and to assign global role tags according to the role of the personnel in the organizational structure, thereby generating a personnel and vehicle data set.
[0104] Specifically, this step aims to build a globally unified data hub, providing a complete data foundation for refined permission calculations. The organizational structure management unit acquires organizational structure data from multi-source human resources systems, establishes a hierarchical organizational structure tree library, and assigns a globally unique identifier to each employee. The multimodal feature acquisition unit collects facial and fingerprint features of employees, converting them into numerical vectors through feature extraction algorithms to construct a multimodal feature library. The vehicle information integration unit collects vehicle information and associates it with the corresponding unique employee identifier to construct a vehicle information library. The global role tag association unit uses the unique employee identifier as a hub to aggregate and associate data from the organizational structure tree library, the multimodal feature library, and the vehicle information library, assigning global role tags based on the employee's role in the organizational structure, ultimately generating a personnel and vehicle data set. Data objects from multiple individuals The composition can be represented as:
[0105] ;
[0106] in, On this basis, Represents a complete set of personnel and vehicle data; Represents the set about the first Personal data objects; It is the first An individual's unique identifier across all personnel; It is the first Individual node information in the organizational structure tree database; It is the first An individual's multimodal feature data set, i.e. ,in The representative feature vector is based on highly accurate basic data obtained by model training and analysis of 30,000 face images collected from more than 10,000 employees under different lighting and poses. It is the first A collection of vehicle information associated with an individual; It is to give the first An individual's global role tag is generated by a mapping function. definition, The function is based on the input organizational structure information. Query the preset job and role mapping table and output the corresponding global role tags.
[0107] For example, consider the first employee and the second employee. The organizational structure management unit records the unique identifier of the first employee. "E1" indicates organizational structure information. Engineer in the R&D department; unique identifier for the second employee. "M1" refers to organizational structure information. The position is for the Marketing Department Manager. The multimodal feature acquisition unit extracts and generates a set of facial feature vectors for the first employee. Extract and generate a set of facial and fingerprint feature vectors for the second employee. The vehicle information integration unit records the vehicle information set of the first employee. The second employee's vehicle information set empty set The global role tag association unit is based on a preset mapping function. The rules are used for calculation, specifying that R&D engineers are mapped to the label "R1" and marketing managers to the label "M1". Based on this, the first employee's global role label is calculated. The first employee data object that is ultimately generated ; Calculate the global role label of the second employee The final generated second employee data object This results in a combined set of personnel and vehicle data. It achieves full-dimensional correlation of multi-source heterogeneous data, providing highly comprehensive data support for the accurate calculation of subsequent spatiotemporal permissions.
[0108] Optionally, the initial spatiotemporal authority matrix calculation module includes:
[0109] The access rule configuration unit is used to obtain predefined access rules for each site, wherein the access rules specify the permitted time periods and permitted device types for different roles at each site;
[0110] The permission matching processing unit is used to match each subject in the personnel and vehicle data set with the access rules based on the global role tags, and determine the authorized location, authorized time period and corresponding hardware terminal list for each subject respectively.
[0111] The permission matrix aggregation unit, connected to the permission matching processing unit, is used to aggregate the permission data of all subjects to form an initial spatiotemporal permission matrix.
[0112] Specifically, this step aims to transform abstract identities and roles into concrete, executable access permissions. The access rule configuration unit obtains predefined access rules for each location, specifying the permitted time periods and device types for different roles at each location. The permission matching processing unit matches each entity in the personnel and vehicle dataset with the access rules based on global role tags, determining the permitted location and permitted time period for each entity, and then searches and filters the unified terminal identifier list to form a corresponding hardware terminal list. The permission matrix aggregation unit aggregates the permission data of all entities, forming an initial spatiotemporal permission matrix containing personnel identifiers, vehicle identifiers, permitted locations, permitted time periods, and corresponding hardware terminal lists. (One permission entry) During the generation process, the local access rule tuple is represented as:
[0113] ;
[0114] in, It is the global role tag to which the rules apply; It is a site affiliation label; It refers to the permitted time period; This is the function type label for the hardware terminal. When the main role meets... At that time, the corresponding hardware terminal list Calculate according to the formula:
[0115] ;
[0116] Indicates a unified terminal identifier list Searching for local tags With the rules of the game Same and functional type labels With regular device types Same terminal unique identifier The set of matching and retrieval data is derived from the standard list generated in the previous steps, thus ensuring computational efficiency. The final generated permission entries are represented as follows: Initial spatiotemporal permission matrix This is a collection of all permission entries. For example... Figure 3 The image shows a heatmap illustrating the frequency of concurrent flow control and authorization at various physical locations during different time periods. The concurrent traffic at each physical location exhibits a spatiotemporal imbalance, with the first location reaching a peak of 92 transactions per minute during peak commuting hours. Matrix splitting and on-site matching significantly alleviated the computational pressure on the central backend.
[0117] For example, consider the equipment and main data of the first and second sites. Unified Terminal Identifier List Includes access control terminals Personnel and vehicle data set Includes the first subject Personnel identification "E1", vehicle assembly Character "R1" and the second main body Personnel identification "M1", vehicle assembly The role is "M1". The access rule configuration unit obtains preset rule 1 ("R1", "First Site", "Time Period 1", "Access Control Terminal") and rule 2 ("M1", "First Site", "Time Period 2", "Access Control Terminal"). The permission matching processing unit performs calculations, and the first subject... Matched with rule 1, in The system retrieves devices belonging to the "first site" and designated as "access control terminals" and obtains a unique identifier "ID1". The terminal list is then calculated. Generate permission entries Second subject If rule 2 is matched, the terminal list can be calculated similarly. Generate permission entries The permission matrix aggregation unit aggregates the generated permission entries into an initial spatiotemporal permission matrix. This provides a complete static permission base for subsequent asynchronous edge distribution.
[0118] Optionally, the matrix splitting and edge asynchronous distribution module includes:
[0119] The permission subset extraction unit is used to extract permission records belonging to the same local point from the initial spatiotemporal permission matrix, taking the local point identifier as the dimension, to form a local point permission subset corresponding to each local point.
[0120] An asynchronous message push unit is used to asynchronously push the local access permission subset to the edge access adaptation layer using a message middleware;
[0121] A local data persistence unit, deployed in the edge access adaptation layer, is used to write a subset of the received site permissions into the local persistence cache of the edge access adaptation layer.
[0122] The offline authentication control unit is used to control the edge access adaptation layer to switch to offline mode when the network connection with the data hub is detected to be interrupted, and to make authentication decisions for heterogeneous hardware terminals at the local site based only on a subset of site permissions in the local persistent cache.
[0123] Specifically, this step aims to transform centralized permission data into distributed permission copies that support local decision-making, thereby improving the reliability and throughput of data distribution. The permission subset extraction unit segments the initial spatiotemporal permission matrix using the site identifier as the basic operational dimension, aggregating permission records with the same permitted site field to form site permission subsets for each site. The asynchronous message push unit uses a message middleware to asynchronously push the site permission subsets to the edge access adaptation layer of the corresponding site. The local data persistence unit, deployed in the edge access adaptation layer, writes the received site permission subsets into the local persistent cache of the edge computing nodes in real time. The offline authentication control unit controls the edge access adaptation layer to switch to offline mode when a network connection interruption is detected, making offline authentication decisions for heterogeneous hardware terminals at the site based entirely on the site permission subsets in the local persistent cache. The formula for the site permission subset extraction process is:
[0124] ;
[0125] in, Representatives and specific points The corresponding subset of site permissions; Represents the initial spatiotemporal authority matrix The permission record in the matrix data comes from the complete set generated by the previous steps. This refers to the permitted location field in the permissions record; These are specific preset location identifiers. This formula, through logical filtering, transforms the complex global matrix into a smaller set of local permissions based on the physical space dimension, providing precise data support for on-site offline authentication.
[0126] For example, the initial spatiotemporal permission matrix Includes permission entries and The permission subset extraction unit is calculated using the preset "first game point" and "second game point" identifiers as dimensions, traversing... Discover and The permission location field is always "first location", thus the permission subset of the first location is calculated and generated. However, no records belonging to the second game point were found, therefore the permission subset of the second game point is... The asynchronous message push unit will The package is published to the first topic corresponding to the message middleware. The edge access adaptation layer of the first site subscribes to this topic through the local data persistence unit, receives the data, and writes it to the local persistent cache. When the offline authentication and control unit detects a network link interruption with the data hub, the first subject requests passage in "Time Period 1" and directly matches it in the local persistent cache. Records are kept, allowing for independent on-site clearance decisions without needing to connect to a central server.
[0127] Optionally, the offline authentication control unit includes:
[0128] The network status monitoring subunit is used to monitor the communication link status between the edge access adaptation layer and the data hub in real time, and to trigger an offline switching control signal when the communication link status is determined to be interrupted.
[0129] The local cache retrieval subunit is used to respond to the offline switching control signal, obtain the real-time authentication request triggered on the heterogeneous hardware terminal side, and retrieve the local persistent cache corresponding to the local permission subset of the real-time authentication request.
[0130] The offline authentication decision subunit is used to perform spatiotemporal matching verification between the current timestamp, terminal identification code, and personnel and vehicle identifier in the real-time authentication request and the retrieved local permission subset, and control the corresponding heterogeneous hardware terminal to execute a local release decision when the matching is successful.
[0131] Specifically, this step details the execution process of the offline authentication mechanism. The network status monitoring subunit monitors the communication link status between the edge access adaptation layer and the data hub in real time, and triggers an offline handover control signal when the communication link is determined to be interrupted. The local cache retrieval subunit responds to the offline handover control signal by obtaining the real-time authentication request triggered on the heterogeneous hardware terminal side, and directly retrieves the site permission subset corresponding to the personnel and vehicle identifiers from the local persistent cache. The offline authentication decision subunit performs spatiotemporal matching verification between the current timestamp, terminal identification code, and personnel / vehicle identifiers in the real-time authentication request and the retrieved site permission subset, and controls the corresponding heterogeneous hardware terminal to execute a local release decision when a match is successful. Its offline authentication decision logic... Defined by the formula: when When satisfied, To allow passage, otherwise To reject. In this formula, This represents the final offline authentication decision. It is the personnel and vehicle identification obtained from the real-time authentication request; It is a terminal identification code; It is the current timestamp; It is the permission record in the local permission subset retrieved from the local persistent cache. The local permission subset data comes from the local cache copy asynchronously issued by the previous steps when the network was not interrupted. Represents a logical OR operation; Represents the logical AND operation; It is a Boolean function used to determine whether the current timestamp is within the permitted time period. The algorithm logic of this function is based on the inductive modeling of more than 100 common enterprise access time strategies, which ensures the accuracy of the verification.
[0132] For example, the network status monitoring subunit determines that the link with the central data center is interrupted, triggering an offline handover control signal. At this time, the first entity is the personnel identifier. For "E1" at the preset timestamp The terminal identification code at the first access control terminal represents the morning of a certain workday. The request to "ID1" was approved. The local cache retrieval subunit received the request and successfully retrieved the site permission record issued in the previous steps from the local persistent cache using "E1" as the index. The permitted period is during working days. The offline authentication decision subunit performs spatiotemporal matching verification based on the decision formula: First, the requested personnel identifier "E1" matches the personnel identifier in the record, and the identity verification passes; second, the requested terminal identification code "ID1" exists in the corresponding hardware terminal list in the record, and the spatial verification passes; finally, it calls... The function determines that the current timestamp falls within the permitted time frame for a weekday, and the time verification passes. Since all logical verification results are true, the decision result calculated by the formula is valid. To allow passage, the system sends an opening command to the access control terminal, and completes the safe passage decision by relying on local calculation even when the network is disconnected.
[0133] Optionally, when the cross-site access request is a visitor request, the access subject identifier carries information about the person or vehicle being the visitor, and the dynamic flow control and temporary permission distribution module includes:
[0134] The workflow approval unit is used to obtain the cross-site access application request, match the target employee corresponding to the visitor in the global unified data hub construction module, use the approval account corresponding to the target employee as the approval node to drive the approval process, and obtain the corresponding approval signal.
[0135] A multimodal feature extraction unit is used to trigger a policy security check when the approval signal is received, and to extract the visitor's real-time facial image data and real-time vehicle license plate data from the cross-site access application request.
[0136] The temporary permission object generation unit is used to call the global unified data hub construction module to convert the real-time face image data and the real-time vehicle license plate data into visitor feature templates corresponding to the personnel multimodal feature data and license plate recognition fields corresponding to the vehicle information data, respectively, and calculate and generate the temporary spatiotemporal permission object in combination with the hardware terminal list specified in the corresponding local permission subset.
[0137] The permission object targeted distribution unit is used to target and distribute the temporary spatiotemporal permission object to the activated terminal with the function type of visitor all-in-one machine within the target site.
[0138] Specifically, this step details the dynamic flow control and temporary permission distribution mechanism for temporary permissions such as those for visitors. The workflow approval unit obtains cross-site access requests and matches the target employee corresponding to the visitor in the global unified data hub construction module. The approval process is driven by the approval account corresponding to the target employee, resulting in an approval signal. Upon receiving the approval signal, the multimodal feature extraction unit triggers a policy security check and extracts the visitor's real-time facial image data and real-time vehicle license plate data from the cross-site access request. The temporary permission object generation unit calls the global unified data hub construction module to convert the real-time facial image data and real-time vehicle license plate data into visitor feature templates corresponding to personnel multimodal feature data and license plate recognition fields corresponding to vehicle information data, respectively. Combined with the available device list specified in the corresponding site permission subset, a temporary spatiotemporal permission object is calculated and generated. The permission object targeted distribution unit targets and distributes the temporary spatiotemporal permission object to the activated terminal with the visitor all-in-one machine function type within the target site. The generated temporary spatiotemporal permission object is formally represented by the formula:
[0139] ;
[0140] in, This represents the generated temporary spacetime permission object; It is a temporary access subject identifier for visitors, represented as a template containing visitor characteristics. and license plate recognition fields The set, i.e. ; It is the target location that the visitor requests to access; It is the hardware terminal identification code of the activation terminal used for on-site activation permissions within the target site, and its function type is visitor all-in-one terminal. It is the activation time window, which represents the time interval during which visitors are allowed to perform on-site verification and activate their permissions at the activation terminal; This is the expiration time window, representing the point in time when the temporary spacetime permission object completely expires. The above activation and expiration time window settings are based on the maximum convenience data derived from historical statistical analysis of over 300 preset visitor reception processes.
[0141] For example, visitor Wang submits a cross-site access request, including a selfie of his face, license plate number "License Plate 1", target site set as "First Site", and target employee "E1". After receiving the request, the workflow approval unit finds the approval account corresponding to "E1" and drives the approval process. Upon receiving an approval signal from employee "E1" clicking "agree", the multimodal feature extraction unit responds to the signal and uses a feature extraction algorithm to convert the face image into a numerical visitor feature template. The license plate is then converted into the license plate recognition field "License Plate 1". The temporary permission object generation unit begins calculation: First, the visitor identifier... identified as Secondly, the target point The system identifies the "first site" as the location of the "Visitor All-in-One Terminal" and queries the unified terminal identifier list. The system then matches the device hardware terminal identification code "ID_ACT" within the "first site" whose function type is "Visitor All-in-One Terminal." Finally, the system calculates the activation time window based on preset rules. The expiration time window is defined as [00:00:00 on the same day, 23:59:59 on the same day]. The timeframe is 23:59:59 on that day. The final formula generates a temporary spatiotemporal permission object. The permission object targeted distribution unit targets and distributes the object to the activated terminal with the hardware terminal identification code "ID_ACT", causing the terminal to enter the verification and activation state.
[0142] Optionally, the on-site activation and permission injection grant module includes:
[0143] The on-site verification receiving unit is used to acquire the on-site verification pass signal fed back by the activated terminal of the visitor all-in-one machine after successfully verifying the identity of the visiting subject;
[0144] An activation instruction generation unit is used to dynamically calculate and generate an activation instruction to activate the temporary spatiotemporal permission object locally in response to receiving the on-site verification pass signal.
[0145] The real-time permission injection unit is used to extract the permission data contained in the temporary spatiotemporal permission object according to the activation instruction, and to send and inject the permission data in real time into the selected edge hardware terminal in the target site.
[0146] The terminal control release unit is deployed on the edge hardware terminal and is used to control the edge hardware terminal to perform release operations on the actual personnel or vehicles corresponding to the access subject identifier within the activation time window.
[0147] Specifically, this step aims to transform digitized, temporary permissions to be activated into actual access rights for visitors in the physical world. The on-site verification receiving unit receives a verification pass signal from the activation terminal (which is a visitor-type all-in-one machine) after successful facial feature vector identity comparison of the visiting subject. In response to the received verification pass signal, the activation command generation unit dynamically calculates and generates an activation command locally to activate the temporary spatiotemporal permission object. The real-time permission injection unit extracts the permission data contained in the temporary spatiotemporal permission object based on the activation command and injects the permission data in real-time into the local authorization list of the selected edge hardware terminal within the target site. The terminal control release unit, deployed on the edge hardware terminal, controls the edge hardware terminal to perform release operations on the actual personnel or vehicles corresponding to the visiting subject's identifier within the activation time window. The identity comparison in the on-site verification receiving unit is determined by a similarity calculation formula:
[0148] ;
[0149] when The comparison was successful. In this formula, The similarity score is a dimensionless value between 0 and 1. It is a visitor feature template vector pre-stored in the temporary spatiotemporal permission object. This data comes from the visitor multimodal features extracted and transformed in the previous steps. It is a feature vector collected and extracted in real time from the activation terminal; Represents the dot product operation of vectors; The Euclidean norm represents a vector; It is a preset similarity threshold, which is set to 0.85. This value is based on data analysis of 10,000 sets of historical face comparison test results under different lighting and angles, and is used to balance the false acceptance rate and the false rejection rate.
[0150] For example, when visitor Wang arrives at the visitor terminal at the first location, the on-site verification receiving unit guides him to have his facial image captured and extracts real-time feature vectors. The terminal reads the visitor feature template vector issued in the previous steps. Calculated according to the similarity formula Because the score is higher than the preset threshold If the value is 0.85, the identity verification is successful, and a live verification pass signal is immediately sent to the edge access adaptation layer. The activation command generation unit generates an activation command based on this, and the real-time permission injection unit responds to the command and extracts the visitor feature template. The license plate recognition field "License Plate 1" is injected into the local authorization lists of the main access control terminal and the gate terminal selected in the first site. Subsequently, when a visitor arrives at the gate by car, the terminal control release unit recognizes "License Plate 1" and determines that the current time is within the preset activation time window. After successful verification, the gate is controlled to open and allow passage. When the visitor enters the main access control, the terminal control release unit successfully recognizes and compares the face locally and determines that the current time is within the activation time window, thereby controlling the access control to open the door. Closed-loop release is completed by relying on local security verification and real-time permission injection.
[0151] Based on the same inventive concept, such as Figure 4 As shown, the present invention also provides a method for unified management of building access permissions across different locations, the method comprising:
[0152] Obtain device attribute information and communication protocols of heterogeneous hardware terminals deployed at various physical sites, establish device abstraction interfaces through heterogeneous protocol conversion, and generate a unified terminal identifier list containing unique identifiers of each terminal, site affiliation tags, and function type tags. The function types cover access control terminals, vehicle gate terminals, and visitor integrated terminals.
[0153] Acquire organizational structure data, personnel multimodal characteristic data, and vehicle information data to build a globally unified data hub and generate a set of personnel and vehicle data associated with global role tags;
[0154] Based on the unified terminal identifier list and personnel and vehicle data set, and combined with the preset site access rules, an initial spatiotemporal permission matrix is calculated and generated. The initial spatiotemporal permission matrix includes personnel identifiers, vehicle identifiers, permitted sites, permitted time periods, and corresponding hardware terminal lists.
[0155] The initial spatiotemporal permission matrix is split into a subset of permissions corresponding to each local station, asynchronously distributed to the edge access adaptation layer of each local station, and stored in the local cache of each local station to support offline authentication.
[0156] Receive cross-site access request initiated by the user, wherein the access request includes the access subject identifier, the target site and the access time window;
[0157] Based on the target site, extract the corresponding site permission subset distributed to the site, submit the site permission subset and the access request together to the dynamic business flow control engine to drive the approval process. In response to the approval, trigger the policy security verification, generate a temporary spatiotemporal permission object, and distribute the temporary spatiotemporal permission object to the activated terminal of the target site with the function type of visitor all-in-one machine. The temporary spatiotemporal permission object includes the target site, hardware terminal identification code, activation time window and expiration time window.
[0158] Upon receiving the on-site verification pass signal from the activation terminal, an activation command is generated. Based on the activation command, the permission data contained in the temporary spatiotemporal permission object is sent and injected into the selected edge hardware terminal within the target site in real time, so that the edge hardware terminal can perform a release operation on the actual personnel or vehicles corresponding to the access subject identifier within the activation time window.
[0159] It should be noted that all equivalent changes and modifications made in accordance with the teachings of this invention are still within the scope of this invention. Those skilled in the art will readily conceive of other embodiments of this invention upon considering the specification and the disclosure of practical truth. This application is intended to cover any variations, uses, or adaptations of this invention that follow the general principles of this invention and include common knowledge or conventional techniques in the art not described herein.
Claims
1. A unified management system for cross-site access control of people and vehicles in buildings, characterized in that: The system includes: an edge access adaptation layer deployed at each physical location, a central management backend integrating a dynamic service flow control engine, and heterogeneous hardware terminals distributed at each physical location. The device abstraction and terminal identification generation module is used to obtain the device attribute information and communication protocol of heterogeneous hardware terminals deployed at various physical sites, establish a device abstraction interface through heterogeneous protocol conversion, and generate a unified terminal identification list containing the unique identifier of each terminal, site affiliation label and function type label. The function types cover access control terminals, vehicle gate terminals and visitor integrated machine terminals. The global unified data hub construction module is used to acquire organizational structure data, personnel multimodal characteristic data and vehicle information data, build a global unified data hub, and generate a set of personnel and vehicle data associated with global role tags; The initial spatiotemporal permission matrix calculation module is used to calculate and generate an initial spatiotemporal permission matrix based on the unified terminal identifier list and personnel and vehicle data set, combined with preset site access rules. The initial spatiotemporal permission matrix includes personnel identifiers, vehicle identifiers, permitted sites, permitted time periods, and corresponding hardware terminal lists. The matrix splitting and edge asynchronous distribution module is used to split the initial spatiotemporal permission matrix into a subset of site permissions corresponding to each site, asynchronously distribute it to the edge access adaptation layer of each site, and store it in the local cache of each site, supporting offline authentication. The cross-site access request receiving module is used to receive cross-site access request initiated by users. The access request includes the access subject identifier, the target site, and the access time window. The dynamic flow control and temporary permission distribution module is used to extract the corresponding site permission subset of the distribution based on the target site, submit the site permission subset and the access application request together to the dynamic business flow control engine, drive the approval process, trigger policy security verification in response to approval, generate a temporary spatiotemporal permission object, and distribute the temporary spatiotemporal permission object to the activated terminal of the target site with the function type of visitor all-in-one machine. The temporary spatiotemporal permission object includes the target site, hardware terminal identification code, activation time window and expiration time window; The on-site activation and permission injection release module is used to receive the on-site verification pass signal fed back by the activation terminal, generate an activation command, and according to the activation command, send and inject the permission data contained in the temporary spatiotemporal permission object into the selected edge hardware terminal within the target site in real time, so that the edge hardware terminal performs the release operation for the actual personnel or vehicles corresponding to the access subject identifier within the activation time window.
2. The unified management system for cross-site access control of people and vehicles in buildings according to claim 1, characterized in that, The device abstraction and terminal identifier generation module includes: The device scanning and protocol acquisition unit is used to scan the access control machines, vehicle gates and visitor integrated machines connected in each site, and acquire their respective device SDKs and private communication protocols; A heterogeneous protocol conversion unit is used to map the private communication protocol into a unified device abstraction interface by deploying heterogeneous protocol conversion at the edge of the local site; The unified identifier generation unit is used to assign a unique identifier to each terminal based on the unified device abstraction interface, and bind the site label and function type label to generate a unified terminal identifier list.
3. The unified management system for cross-site access control of people and vehicles in buildings according to claim 2, characterized in that, The heterogeneous protocol conversion unit includes: The protocol text parsing subunit is used to parse the private communication protocol and extract the device control field, event reporting field, and status polling field from it. The control primitive mapping subunit is used to establish a bidirectional data mapping relationship between the device control field, event reporting field, and status polling field and the preset standard control primitives in the unified device abstraction interface. The communication message conversion subunit is used to convert the private communication messages of the heterogeneous hardware terminal into standard communication messages that conform to the unified device abstraction interface in real time according to the bidirectional data mapping relationship, so as to realize transparent communication between the management backend and the heterogeneous hardware terminal.
4. The unified management system for cross-site access control of people and vehicles in buildings according to claim 1, characterized in that, The global unified data hub construction module includes: The organizational structure management unit is used to obtain organizational structure data from multiple human resources systems and build an organizational structure tree library. The multimodal feature acquisition unit is used to collect facial and fingerprint features to build a multimodal feature database of personnel. The vehicle information integration unit is used to collect information on vehicles and related personnel to build a vehicle information database; The global role tag association unit is used to associate the organizational structure tree library, personnel multimodal feature library, and vehicle information library based on the unique identifier of the personnel, and to assign global role tags according to the role of the personnel in the organizational structure, thereby generating a personnel and vehicle data set.
5. The unified management system for cross-site access control of people and vehicles in buildings according to claim 1, characterized in that, The initial spatiotemporal authority matrix calculation module includes: The access rule configuration unit is used to obtain predefined access rules for each site, wherein the access rules specify the permitted time periods and permitted device types for different roles at each site; The permission matching processing unit is used to match each subject in the personnel and vehicle data set with the access rules based on the global role tags, and determine the authorized location, authorized time period and corresponding hardware terminal list for each subject respectively. The permission matrix aggregation unit, connected to the permission matching processing unit, is used to aggregate the permission data of all subjects to form an initial spatiotemporal permission matrix.
6. The unified management system for cross-site access control of people and vehicles in buildings according to claim 1, characterized in that, The matrix splitting and edge asynchronous distribution module includes: The permission subset extraction unit is used to extract permission records belonging to the same local point from the initial spatiotemporal permission matrix, taking the local point identifier as the dimension, to form a local point permission subset corresponding to each local point. An asynchronous message push unit is used to asynchronously push the local access permission subset to the edge access adaptation layer using a message middleware; A local data persistence unit, deployed in the edge access adaptation layer, is used to write a subset of the received site permissions into the local persistence cache of the edge access adaptation layer. The offline authentication control unit is used to control the edge access adaptation layer to switch to offline mode when the network connection with the data hub is detected to be interrupted, and to make authentication decisions for heterogeneous hardware terminals at the local site based only on a subset of site permissions in the local persistent cache.
7. The unified management system for cross-site access control of people and vehicles in buildings according to claim 6, characterized in that, The offline authentication and control unit includes: The network status monitoring subunit is used to monitor the communication link status between the edge access adaptation layer and the data hub in real time, and to trigger an offline switching control signal when the communication link status is determined to be interrupted. The local cache retrieval subunit is used to respond to the offline switching control signal, obtain the real-time authentication request triggered on the heterogeneous hardware terminal side, and retrieve the local persistent cache corresponding to the local permission subset of the real-time authentication request. The offline authentication decision subunit is used to perform spatiotemporal matching verification between the current timestamp, terminal identification code, and personnel and vehicle identifier in the real-time authentication request and the retrieved local permission subset, and control the corresponding heterogeneous hardware terminal to execute a local release decision when the matching is successful.
8. The unified management system for cross-site access control of people and vehicles in buildings according to claim 1, characterized in that, When the cross-site access request is a visitor request, the access subject identifier carries information about the person or vehicle being the visitor. The dynamic flow control and temporary permission distribution module includes: The workflow approval unit is used to obtain the cross-site access application request, match the target employee corresponding to the visitor in the global unified data hub construction module, use the approval account corresponding to the target employee as the approval node to drive the approval process, and obtain the corresponding approval signal. A multimodal feature extraction unit is used to trigger a policy security check when the approval signal is received, and to extract the visitor's real-time facial image data and real-time vehicle license plate data from the cross-site access application request. The temporary permission object generation unit is used to call the global unified data hub construction module to convert the real-time face image data and the real-time vehicle license plate data into visitor feature templates corresponding to the personnel multimodal feature data and license plate recognition fields corresponding to the vehicle information data, respectively, and calculate and generate the temporary spatiotemporal permission object in combination with the hardware terminal list specified in the corresponding local permission subset. The permission object targeted distribution unit is used to target and distribute the temporary spatiotemporal permission object to the activated terminal with the function type of visitor all-in-one machine within the target site.
9. The unified management system for cross-site access control of people and vehicles in buildings according to claim 1, characterized in that, The on-site activation and permission injection granting module includes: The on-site verification receiving unit is used to acquire the on-site verification pass signal fed back by the activated terminal of the visitor all-in-one machine after successfully verifying the identity of the visiting subject; An activation instruction generation unit is used to dynamically calculate and generate an activation instruction to activate the temporary spatiotemporal permission object locally in response to receiving the on-site verification pass signal. The real-time permission injection unit is used to extract the permission data contained in the temporary spatiotemporal permission object according to the activation instruction, and to send and inject the permission data in real time into the selected edge hardware terminal in the target site. The terminal control release unit is deployed on the edge hardware terminal and is used to control the edge hardware terminal to perform release operations on the actual personnel or vehicles corresponding to the access subject identifier within the activation time window.
10. A method for unified management of building access permissions across different locations, characterized in that: The method includes: Obtain device attribute information and communication protocols of heterogeneous hardware terminals deployed at various physical sites, establish device abstraction interfaces through heterogeneous protocol conversion, and generate a unified terminal identifier list containing unique identifiers of each terminal, site affiliation tags, and function type tags. The function types cover access control terminals, vehicle gate terminals, and visitor integrated terminals. Acquire organizational structure data, personnel multimodal characteristic data, and vehicle information data to build a globally unified data hub and generate a set of personnel and vehicle data associated with global role tags; Based on the unified terminal identifier list and personnel and vehicle data set, and combined with the preset site access rules, an initial spatiotemporal permission matrix is calculated and generated. The initial spatiotemporal permission matrix includes personnel identifiers, vehicle identifiers, permitted sites, permitted time periods, and corresponding hardware terminal lists. The initial spatiotemporal permission matrix is split into a subset of permissions corresponding to each local station, asynchronously distributed to the edge access adaptation layer of each local station, and stored in the local cache of each local station to support offline authentication. Receive cross-site access request initiated by the user, wherein the access request includes the access subject identifier, the target site and the access time window; Based on the target site, extract the corresponding site permission subset distributed to the site, submit the site permission subset and the access request together to the dynamic business flow control engine to drive the approval process. In response to the approval, trigger the policy security verification, generate a temporary spatiotemporal permission object, and distribute the temporary spatiotemporal permission object to the activated terminal of the target site with the function type of visitor all-in-one machine. The temporary spatiotemporal permission object includes the target site, hardware terminal identification code, activation time window and expiration time window. Upon receiving the on-site verification pass signal from the activation terminal, an activation command is generated. Based on the activation command, the permission data contained in the temporary spatiotemporal permission object is sent and injected into the selected edge hardware terminal within the target site in real time, so that the edge hardware terminal can perform a release operation on the actual personnel or vehicles corresponding to the access subject identifier within the activation time window.