A smart community access control permission dynamic management method and system and a medium
Patent Information
- Application Number
- CN202611236837.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-08-14
- Publication Date
- 2026-09-29
AI Technical Summary
[0003]现有方法难以确定各次通行所对应的有效权限版本,容易将权限变更前发生的通行事件与变更后的权限状态错误关联,或者将权限变更后发生的通行事件与变更前的权限状态错误关联,进而造成后续门禁错误放行、错误拒绝或人员所在区域状态异常
[0052]通过获取门禁点与门禁区域的连接关系、权限版本切换事件、人员通行事件及本地事件序号,并按照同一门禁控制器内部事件的产生顺序构建本地事件序列,减少事件回传顺序与实际发生顺序不一致造成的权限版本误判;通过将多个本地事件序列中的人员通行事件关联为连续通行链,并将权限版本切换事件映射至连续通行链,识别权限版本切换边界及待归属通行事件;结合前序门禁区域可达性、后序门禁点可通行性及反向约束确定目标权限版本,使实际通行事件与有效权限版本准确对应;依据目标权限版本校正人员所在门禁区域并调整关联后续门禁点权限,减少错误放行、错误拒绝及权限异常延续,保持权限版本、通行事件与人员所在门禁区域之间的时序一致性,提高智慧社区门禁权限动态管理的准确性和可靠性。
Smart Images

Figure CN122842227A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of access control technology, and more specifically, to a method, system, and medium for dynamic management of access control permissions in smart communities. Background Technology
[0002] Existing smart community access control management platforms typically distribute permission change data to the access controllers corresponding to the community entrance, garage, building doors, and elevator access control. Each access controller performs access judgment and records access events based on the locally effective permission version. When the permission version switching process overlaps with the continuous passage of personnel across multiple access control nodes, the actual effective time of permissions, the actual occurrence time of access events, and the time of access event feedback may differ between different access controllers.
[0003] Existing methods make it difficult to determine the valid permission version corresponding to each access, which can easily lead to incorrect association between access events that occurred before the permission change and the permission status after the change, or incorrect association between access events that occurred after the permission change and the permission status before the change, resulting in subsequent incorrect access control, incorrect denial, or abnormal status of the area where the person is located. Summary of the Invention
[0004] In order to overcome the above-mentioned defects of the prior art, embodiments of the present invention provide a method, system and medium for dynamic management of access control permissions in smart communities to solve the problems mentioned in the background art.
[0005] To achieve the above objectives, the present invention provides the following technical solution:
[0006] A method for dynamic management of access control permissions in smart communities includes the following steps:
[0007] S1: Obtain the connection relationship between access control points and access control areas, the permission version switching event of each access control point's corresponding access control controller, personnel access events, and local event sequence numbers;
[0008] S2: Arrange the permission version switching events and personnel access events of the same access controller according to the local event sequence number to form a local event sequence;
[0009] S3: Based on personnel identification, passage direction, and connection relationship, associate personnel passage events in multiple local event sequences into a continuous passage chain;
[0010] S4: Map permission version switching events to a continuous access chain, and define the access events to be assigned and the candidate permission versions that cross the permission version switching boundary;
[0011] S5: Verify the reachability of the access event to be assigned to the preceding access control area and the accessibility of the following access control point under each candidate permission version, and use the unique personnel access event in the access control area in the continuous access chain to perform reverse constraints to determine the target permission version;
[0012] S6: Correct the access control area where the personnel are located based on the target permission version, and adjust the permissions of associated subsequent access control points.
[0013] In a preferred embodiment, S1 specifically refers to:
[0014] Collect the access control point signage, source access control area, target access control area, and direction of passage for each access control point, and establish the connection relationship between access control points and access control areas;
[0015] When the access controller at each access point enables a new permission version to replace the current permission version, a permission version switch event is generated.
[0016] A personnel passage event is generated when a person actually passes through the access control point;
[0017] Based on the order in which permission version switching events and personnel access events are generated in the corresponding access controllers, local event sequence numbers are assigned to permission version switching events and personnel access events.
[0018] In a preferred embodiment, S2 specifically refers to:
[0019] Based on the access control controller identifier, the permission version switching event is assigned to the corresponding access control controller;
[0020] Based on the access control point identifier in the personnel access event, the personnel access event is assigned to the corresponding access control controller;
[0021] Read the local event sequence numbers of permission version switching events and personnel access events within the same access control controller, and merge and arrange them according to the order in which they were generated;
[0022] Determine the position of each person's access event before, between, or after the adjacent permission version switching event to form the local event sequence of the corresponding access controller.
[0023] In a preferred embodiment, S3 specifically refers to:
[0024] Extract personnel access events with the same personnel identifier from each local event sequence;
[0025] Based on the access control point signage, passage direction, and connection relationship between access control points and access control areas in personnel access events, determine the source access control area and target access control area corresponding to each personnel access event;
[0026] Personnel access events whose target access area is the same as the source access area of the previous personnel access event will be sequentially linked together;
[0027] Based on the position of each person's passage event in the corresponding local event sequence, connections that conflict with the order of occurrence are eliminated to form a continuous passage chain.
[0028] In a preferred embodiment, S4 specifically refers to:
[0029] The corresponding access controller is determined based on the access point identifier of personnel passage events in the continuous passage chain;
[0030] In the corresponding local event sequence, find the local event with a local event number less than the personnel access event and the nearest permission version switching event, map it to the continuous access chain, and determine the permission version corresponding to the permission version switching event as the event execution permission version;
[0031] Compare the event execution permission versions of adjacent personnel passage events, and define the positions where the event execution permission versions differ as permission version switching boundaries;
[0032] The passage events of adjacent personnel on both sides of the permission version switching boundary are identified as passage events to be assigned, and the corresponding event execution permission version is identified as the candidate permission version.
[0033] In a preferred embodiment, S5 specifically refers to:
[0034] The candidate permission version is assigned to the access event to be assigned, and the accessibility of the preceding access area is verified based on whether the source access area is connected to the target access area of the previous personnel access event.
[0035] Based on whether the candidate permission version includes the access permission of the access point corresponding to the next personnel access event, verify the accessibility of the subsequent access point;
[0036] Retain candidate permission versions where both the accessibility of the preceding access control area and the passability of the subsequent access control point are true;
[0037] When multiple candidate permission versions exist, starting from the personnel passage event that is unique in both the source and target access control areas, the access control area connection relationship is checked in reverse along the continuous passage chain to eliminate candidate permission versions that cause connection interruption and determine the target permission version.
[0038] In a preferred embodiment, S6 specifically refers to:
[0039] Based on the source access control area, target access control area, and direction of passage corresponding to the passage event to be assigned, update the access control area where the person is located to the target access control area;
[0040] Based on the access control area where the person is located and the connection relationship between the access control point and the access control area, determine the associated subsequent access control points with the access control area where the person is located as the source access control area;
[0041] Compare the associated access permissions of the target permission version with the access permissions currently enabled by the corresponding access controller;
[0042] Based on the comparison results, permission adjustment data including personnel identifier, access control point identifier, permission version identifier, and permission adjustment type is generated and sent to the corresponding access control controller.
[0043] On the other hand, the present invention provides a smart community access control dynamic management system, comprising:
[0044] Information Acquisition Module: Acquires the connection relationship between access control points and access control areas, the permission version switching events of the access control controllers corresponding to each access control point, personnel access events, and local event sequence numbers;
[0045] Event sorting module: Sorts permission version switching events and personnel access events of the same access controller according to local event sequence number, forming a local event sequence;
[0046] Access Association Module: Based on personnel identification, access direction, and connection relationship, it associates personnel access events in multiple local event sequences into a continuous access chain;
[0047] Version mapping module: Maps permission version switching events to a continuous access chain, and defines the access events to be assigned and the candidate permission versions that cross the permission version switching boundary;
[0048] Version determination module: Verifies the reachability of the access event to be assigned to the preceding access control area and the accessibility of the subsequent access control point under each candidate permission version, and uses the unique personnel access event in the access control area in the continuous access chain to perform reverse constraints to determine the target permission version;
[0049] Permission adjustment module: Corrects the access control area where the personnel are located based on the target permission version, and adjusts the permissions of associated subsequent access control points.
[0050] On the other hand, the present invention provides a storage medium containing computer-executable instructions, which, when executed by a computer processor, are used to perform the aforementioned method for dynamic management of access control permissions in a smart community.
[0051] The technical effects and advantages of the present invention, a method, system, and medium for dynamic management of access control permissions in smart communities, are as follows:
[0052] By acquiring the connection relationship between access control points and access control areas, permission version switching events, personnel access events, and local event sequence numbers, and constructing local event sequences according to the generation order of events within the same access control controller, the system reduces misjudgments of permission versions caused by inconsistencies between the event feedback order and the actual occurrence order. By associating personnel access events in multiple local event sequences into a continuous access chain and mapping permission version switching events to this chain, the system identifies permission version switching boundaries and access events to be assigned. The system combines the accessibility of preceding access control areas, the accessibility of subsequent access control points, and reverse constraints to determine the target permission version, ensuring accurate correspondence between actual access events and valid permission versions. Based on the target permission version, the system corrects the access control area where the personnel are located and adjusts the permissions of associated subsequent access control points, reducing erroneous granting, erroneous denial, and abnormal permission continuation. This maintains temporal consistency between permission versions, access events, and the access control area where the personnel are located, improving the accuracy and reliability of dynamic access control management in smart communities. Attached Figure Description
[0053] Figure 1 This is a schematic diagram of a smart community access control dynamic management method according to the present invention;
[0054] Figure 2 This is a schematic diagram of the structure of a smart community access control and dynamic management system according to the present invention. Detailed Implementation
[0055] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of the present invention.
[0056] Example 1
[0057] Figure 1 This invention presents a method for dynamic management of access control permissions in smart communities, comprising the following steps:
[0058] S1: Obtain the connection relationship between access control points and access control areas, the permission version switching event of each access control point's corresponding access control controller, personnel access events, and local event sequence numbers;
[0059] S2: Arrange the permission version switching events and personnel access events of the same access controller according to the local event sequence number to form a local event sequence;
[0060] S3: Based on personnel identification, passage direction, and connection relationship, associate personnel passage events in multiple local event sequences into a continuous passage chain;
[0061] S4: Map permission version switching events to a continuous access chain, and define the access events to be assigned and the candidate permission versions that cross the permission version switching boundary;
[0062] S5: Verify the reachability of the access event to be assigned to the preceding access control area and the accessibility of the following access control point under each candidate permission version, and use the unique personnel access event in the access control area in the continuous access chain to perform reverse constraints to determine the target permission version;
[0063] S6: Correct the access control area where the personnel are located based on the target permission version, and adjust the permissions of associated subsequent access control points.
[0064] S1: Obtain the connection relationship between access control points and access control areas, the permission version switching events of the access control controllers corresponding to each access control point, personnel access events, and local event sequence numbers, including:
[0065] In one implementation, an access control point represents a controlled passage location traversed by a person when entering another access control area. An access control area represents a spatial range separated by access control points that allows for the determination of a person's entry or exit status. Access control point identifiers are generated using unique characters, integers, or combinations of characters and integers within the smart community. The source access control area represents the access control area where the person was before passing through the access control point according to the direction of travel. The target access control area represents the access control area the person arrives at after passing through the access control point according to the direction of travel. The direction of travel is indicated by a directional marker pointing from the source access control area to the target access control area. The access control point identifier, source access control area, target access control area, and direction of travel are collected for each access control point. These information are then written into the same connection relationship record. Multiple connection relationship records together constitute the access control point and... The connection relationships of access control areas are defined as follows: For access control points that allow bidirectional access, two connection relationship records with opposite directions are established. The two connection relationship records use the same access control point identifier and exchange the source access control area and the target access control area respectively. After the connection relationship record is written, it is checked whether the source access control area and the target access control area in each connection relationship record are different, and whether the same access control point identifier and the same passage direction correspond to only one set of source access control area and target access control area. Connection relationship records that meet the check conditions are retained. Each access control controller is configured with a unique access control controller identifier within the smart community. A correspondence between access control point identifiers and access control controller identifiers is established, and the valid start point and valid end point of the correspondence are recorded, so that within any valid period, one access control point identifier corresponds to only one access control controller identifier responsible for generating permission version switching events and personnel access events.
[0066] A permission version represents the set of all access permissions associated with the same permission version identifier formed by a single permission adjustment. The permission version identifier is generated using characters, integers, or a combination of characters and integers that can distinguish between previous and current permission configuration states. The entire department's access permission set and the permission version identifier are jointly stored as a permission version record. The entire department's access permission set must at least record the personnel identifier, access point identifier, passage direction, valid permission start point, valid permission end point, and permitted passage status. The valid permission start point indicates the time when the corresponding access permission begins to participate in the access judgment; the valid permission end point indicates the time when the corresponding access permission stops participating in the access judgment; and the permitted passage status indicates that the corresponding personnel are allowed to pass through the corresponding access point in the corresponding passage direction between the valid permission start point and the valid permission end point. Each access point's corresponding access controller stores the local permission record associated with the corresponding access point in the entire department's access permission set, and stores a permission version identifier consistent with the permission version record, enabling the permission version identifier to associate with different access permissions involved in the same permission adjustment. After receiving a new permission version, the controller writes the local permission record associated with the corresponding access point in the new permission version to the local storage. It checks whether the personnel identifier, access point identifier, passage direction, valid permission start point, valid permission end point, and allowed passage status can be completely read. After the check passes, the access controller enters the serial switching process and pauses receiving new access judgments. It replaces the currently enabled permission version identifier with the new permission version identifier, generates a permission version switching event containing the access controller identifier and the new permission version identifier, assigns a local event sequence number to the permission version switching event, and writes the permission version switching event and the local event sequence number together into the local event record. After the permission version identifier replacement, permission version switching event generation, local event sequence number assignment, and local event record writing are all completed, it resumes receiving new access judgments. Personnel access events established before the start of the serial switching process obtain local event sequence numbers before the permission version switching event. Personnel access events established after the resumption of receiving new access judgments obtain local event sequence numbers after the permission version switching event.
[0067] Personnel identification represents a unique identifier for a person's identity record within the smart community. Each access pass uniquely corresponds to one personnel identification, and one personnel identification can correspond to one or more access passes. Access passes include, but are not limited to, access cards, mobile terminal credentials, QR code credentials, or biometric credentials. After successful access pass verification, the personnel identification corresponding to the access pass is read. Based on the source access control area corresponding to the access pass verification location, the access control point identifier and passage direction are read from the connection relationship between the access control point and the access control area, and a pending confirmation access record is generated, containing the personnel identification, access control point identifier, passage direction, and verification completion order. Infrared beam detection, pressure detection, or channel counting methods are used on both sides of the access control point to generate source access control area side detection signals and target access control area side detection signals, respectively. The access control point is determined to be in a prohibited or permitted state by the door lock status record or the turnstile position record. From the moment the access control point changes from a prohibited to a permitted state, the source access control area side detection signal appears first, followed by the target access control area side detection signal. The sequence forms a complete direction detection process, and the passage direction corresponding to the complete direction detection process is determined based on the connection relationship between the access control point and the access control area. The passage records to be confirmed are arranged in the order of verification completion. The complete direction detection process is associated with the passage record to be confirmed that is listed first and has the same access control point identifier and passage direction. Only one passage record to be confirmed is associated with the same complete direction detection process. When the detection signal on the target access control area side appears, it is determined that the person has actually passed through the access control point. At the time when the detection signal on the target access control area side appears, a person passage event containing the person identifier, access control point identifier and passage direction is generated, and the person passage event enters the local event sequence number allocation process. The access control point restoring the prohibition state is only used as the end condition of the current passage process, not as the time point for the generation of the person passage event. If a complete direction detection process has not been formed before the access control point restores the prohibition state, the corresponding passage record to be confirmed is canceled and no person passage event is generated. If a complete direction detection process is formed but there is no passage record to be confirmed that can be associated, no person passage event containing the person identifier is generated.
[0068] The local event sequence number indicates the unified generation order of permission version switching events and personnel access events within the same access control controller. The permission version switching event is established when the permission version identifier is replaced during the serial switching process. The personnel access event is established when a detection signal appears on the target access control area side. After both events are established, they enter the same serial sequencing process. The access control controller shares a continuously increasing local counter value for both permission version switching and personnel access events. The next event can only read the local counter value after one event has completed the local event sequence number allocation. When allocating a local event sequence number, the sequence number of the most recently successfully written local event is read and set as the local event record. The recorded local event sequence number is incremented and used as the local event sequence number of the current event. During an indivisible local write process, the current event, the local event sequence number, and the incremented local count value are written together to the local storage. If the local write is not completed, the local count value update is not confirmed, and the joint write of the current event, the local event sequence number, and the local count value is re-executed. After the access controller restarts, it reads the local event sequence number of the most recently successfully written local event record and continues to allocate data from the incremented local event sequence number. The permission version switching event ultimately includes the access controller identifier, the permission version identifier, and the local event sequence number. The personnel access event ultimately includes the personnel identifier, the access point identifier, the access direction, and the local event sequence number.
[0069] S2: Arrange the permission version switching events and personnel access events of the same access control controller according to the local event sequence number to form a local event sequence, including:
[0070] In one implementation, when the access control controller first activates the initial permission version, it generates an initial permission version switching event containing the access control controller identifier, the permission version identifier corresponding to the initial permission version, and the local event sequence number, according to the generation method of the permission version switching event. After the initial permission version switching event completes the local event record writing, it begins to receive personnel access judgment. The permission version switching event and personnel access event newly written since the last local event sequence update are identified as pending events. Initially, the existing permission version switching event and personnel access event in the local event record are identified as pending events. The access control controller that generates at least one pending event is identified as the pending access control controller. The range of pending events is determined by the minimum local event sequence number and the maximum local event sequence number in the pending events corresponding to each pending access control controller.
[0071] For each access control controller to be processed, the access control controller identifier, permission version identifier, and local event sequence number contained in the permission version switching event are read. The access control controller identifier contained in the permission version switching event is used as the classification basis. Permission version switching events whose access control controller identifier matches the access control controller identifier of the access control controller to be processed are classified into the event set of the access control controller to be processed. Before being classified into the event set, it is checked whether the permission version identifier contained in the permission version switching event can be associated with the permission version record, whether the local event sequence number can locate a unique event in the local event record of the access control controller to be processed, and whether the unique event located has the same access control controller identifier and permission version identifier as the permission version switching event to be classified. All permission version switching events with consistent check results are retained in the event set.
[0072] The system reads the personnel identifier, access control point identifier, passage direction, and local event sequence number from the personnel access event. It also retrieves the access control controller identifier that generated the personnel access event from the storage source of the local event record. The system uses the access control point identifier to query the correspondence between the access control point identifier and the access control controller identifier. Each correspondence record includes the access control point identifier, access control controller identifier, valid start point, and valid end point. The valid start point and valid end point are represented by the local event sequence number of the corresponding access control controller when the correspondence begins and ends, respectively. The valid end point is recorded as long as the correspondence remains valid. The status is not terminated. When the local event sequence number of a personnel access event is greater than or equal to the valid start point and less than or equal to the valid end point, or the valid end point is not terminated, the corresponding relationship record is determined as a valid corresponding relationship. Check whether the access controller identifier in the valid corresponding relationship is consistent with the access controller identifier corresponding to the storage source of the local event record where the personnel access event is located. Check whether the access point identifier and the passage direction can locate a unique connection relationship record in the connection relationship between the access point and the access area. All personnel access events with consistent check results are included in the event set of the corresponding access controller to be processed.
[0073] The permission version switching event and personnel access event in the event set are converted into records to be arranged, each containing an event type, event fields, and a local event sequence number. The event fields for the permission version switching event include the access controller identifier and the permission version identifier, while the event fields for the personnel access event include the personnel identifier, the access point identifier, and the direction of passage. Only one of the duplicate records to be arranged with the same local event sequence number and completely identical event type and event fields is retained. If the local event sequence number is the same but the event type or event fields are different, the event type and event fields are reread from the local event record of the access controller to be processed according to the local event sequence number, and the conflicting record to be arranged is replaced with the local event record. If there is a local event sequence number between the minimum and maximum local event sequence numbers that cannot be located for the record to be arranged, the local event record is reread according to the missing local event sequence number. The permission version switching event or personnel access event obtained after the reread is added to the event set. If the complete event fields still cannot be obtained after the reread, the missing local event sequence number is marked as the location of the event to be recovered.
[0074] When no event location exists, select the record with the smallest local event number from the unsorted records that have not yet been written into the sorting result and write it into the sorting result. Repeat this selection and writing until all unsorted records in the event set are sorted. Starting from the smallest local event number in the range of events to be processed, read the nearest permission version switching event in the direction of decreasing local event number and add the nearest permission version switching event to the sorting result. If no permission version switching event is read, mark the local event record corresponding to the initial permission version switching event as the location of the event to be restored and pause the formation of the local event sequence of the access control controller to be processed. Starting from the largest local event number in the range of events to be processed, read the nearest permission version switching event that has been written into the local event record in the direction of increasing local event number and add it to the sorting result when a permission version switching event is read. After the addition is completed, sort all the unsorted records again in ascending order of local event number so that each personnel access event can establish a positional relationship with the adjacent permission version switching event in the access control controller to be processed.
[0075] Select personnel access events sequentially from the sorted results. Starting from the local event number corresponding to the personnel access event, search for the nearest permission version change event in decreasing order of local event number. This nearest permission version change event is identified as the preceding adjacent permission version change event. Then, search for the nearest permission version change event in increasing order of local event number and identify the following adjacent permission version change event. If the local event number of the personnel access event is less than the local event number of the first permission version change event in the sorted results, record the personnel access event's position as preceding the permission version change event, preceding the preceding adjacent permission version change event, and following the following adjacent permission version change event. When all permission version switching events exist, the personnel access event is recorded as being located between adjacent permission version switching events. When a forward adjacent permission version switching event exists but a backward adjacent permission version switching event does not exist, the personnel access event is recorded as being located after the permission version switching event. The access controller identifier, the permission version switching events and personnel access events arranged according to local event sequence number, the arrangement position of each personnel access event, the forward adjacent permission version switching events, and the backward adjacent permission version switching events are collectively saved as the local event sequence of the corresponding access controller. The local event sequence numbers of different access controllers are only compared within their respective local event sequences.
[0076] S3: Based on personnel identification, passage direction, and connection relationships, associate personnel passage events from multiple local event sequences into a continuous passage chain, including:
[0077] In one implementation, when a personnel access event is generated, the local clock value corresponding to the occurrence of the detection signal on the target access control area side is recorded synchronously. A unified reference clock provides a reference time to each access controller according to the calibration cycle. When sending a calibration request, the access controller records the requested local clock value. When receiving a calibration response containing the reference time, it records the received local clock value. The intermediate time between the requested local clock value and the received local clock value is used as the local time corresponding to the reference time. The difference between the reference time and the intermediate time is saved as a time correction value. The local clock value corresponding to the occurrence of the detection signal on the target access control area side is compared with the most recent time correction. The values are added together to generate a unified passage occurrence time for the corresponding personnel passage event; the calibration period is determined based on the maximum offset rate measured by the access controller's local clock during continuous calibration and the shortest actual passage time between different access points that can be continuously passed. The cumulative time deviation caused by the maximum offset rate within the calibration period is less than half of the shortest actual passage time; the sum of half of the request round-trip time corresponding to the time correction value and the cumulative time deviation within the calibration period is determined as the unified time error upper limit; for example, the maximum offset rate can be obtained by executing the calibration request multiple times, and the shortest actual passage time can be obtained by the test record of personnel continuously passing through adjacent access points according to the allowed passage path.
[0078] The system reads personnel access events from each local event sequence. The read content includes personnel identification, access control point identification, passage direction, local event sequence number, access control controller identification, unified access occurrence time, and unified time error upper limit. Personnel access events with identical personnel identifications are written into the same personnel event set, and the combination of the access control controller identification and the local event sequence number is used as the unique identifier for each personnel access event. Duplicate personnel access events with identical unique identifiers and identical event content are retained only once. If the unique identifiers are identical but the event content is different, the corresponding local event record is reread according to the access control controller identification and the local event sequence number, and a reread is performed. Replace conflicting personnel access events with new ones; for each personnel access event, use both access point identifier and direction of travel to query the connection relationship between the access point and the access control area, and read the source access control area and the target access control area from the connection relationship records where both the access point identifier and direction of travel are consistent; if no connection relationship record is found or multiple connection relationship records where the source access control area and the target access control area are inconsistent are found, mark the corresponding personnel access event as a personnel access event to be completed; when a unique connection relationship record is found, write the source access control area and the target access control area into the corresponding personnel access event, and determine the personnel access event as a personnel access event to be connected.
[0079] For personnel access events to be connected within the same personnel event set, they are arranged from earliest to latest according to the unified access occurrence time. When the time ranges corresponding to two personnel access events to be connected do not overlap, the time ranges are formed by extending the unified access occurrence time forward and backward by the unified time error upper limit, with the personnel access event whose overall time range is earlier arranged before the personnel access event whose overall time range is later. When two personnel access events to be connected correspond to the same access controller and their time ranges overlap, the arrangement order is determined by the local event sequence number from smallest to largest. When two personnel access events to be connected correspond to different access controllers and their time ranges overlap, the first access controller is checked separately. Whether the target access control area of the pending personnel passage event is the same as the source access control area of the second pending personnel passage event, and whether the target access control area of the second pending personnel passage event is the same as the source access control area of the first pending personnel passage event, if only the first check is true, the first pending personnel passage event will be placed before the second pending personnel passage event; if only the second check is true, the second pending personnel passage event will be placed before the first pending personnel passage event. If both checks are true or false, the two pending personnel passage events will be marked as personnel passage events with uncertain timing, and each of the two personnel passage events with uncertain timing will be used as the starting point of a different continuous passage chain.
[0080] A continuous access chain is established starting with the first access event to be connected that has been arranged and is not marked as a time-determined access event. The first access event to be connected is written into the continuous access chain and designated as the current end access event. Then, the next access event to be connected is read sequentially according to the arrangement order. If the target access control area of the current end access event is the same as the source access control area of the next access event to be connected, a connection relationship is established from the current end access event to the next access event to be connected. The current end access event is designated as the previous access event, and the next access event to be connected is designated as the next access event to be connected. The next access event to be connected is written into the continuous access chain. If the target access control area of the current end access event is different from the source access control area of the next access event to be connected, the current continuous access chain ends, and a new continuous access chain is established for the next access event to be connected. Continuous access chains are allowed to pass through the same access control area multiple times. The access event corresponding to the unique identifier of the same event is written only once in the same continuous access chain.
[0081] After each person access event is written to the continuous access chain, the personnel access events generated by the same access controller in the continuous access chain are extracted according to the access controller identifier, and the corresponding local event sequence number is read according to the arrangement order in the continuous access chain. When the local event sequence number corresponding to the same access controller keeps strictly increasing, the most recently established connection relationship is retained. When the local event sequence number corresponding to the same access controller does not keep increasing, the most recently established connection relationship is determined to be a connection relationship that conflicts with the order of generation, the connection relationship that conflicts with the order of generation is deleted, the continuous access chain before the deletion position is ended, and a new continuous access chain is established for the next personnel access event. The local event sequence numbers of different access controllers are not compared in value. The order of personnel access events generated by different access controllers in the continuous access chain is determined only based on the unified access occurrence time, the unified time error limit, and the access control area connection relationship.
[0082] After processing all pending personnel access events, the personnel identifier corresponding to each continuous access chain, the personnel access events arranged in the connection order, the access control point identifier corresponding to each personnel access event, the access direction, the source access control area, the target access control area, the access control controller identifier, the local event sequence number, the unified access occurrence time, and the corresponding position in the local event sequence are all saved together. Adjacent personnel access events in a continuous access chain satisfy the following conditions: the target access control area of the previous personnel access event is the same as the source access control area of the next personnel access event, and the order of personnel access events generated by the same access control controller in the continuous access chain is consistent with the order of their generation in the corresponding local event sequence.
[0083] S4: Map permission version switching events to a continuous access chain, defining the access events to be assigned and candidate permission versions that cross the permission version switching boundary, including:
[0084] In one implementation, personnel access events in a continuous access chain are read sequentially. The correspondence between access control point identifiers and access controller identifiers is queried using access control point identifiers. Records matching the access control point identifier in the personnel access event, matching the access controller identifier stored in the continuous access chain, and whose local event number falls within the valid start-to-end period are selected. If the valid end-to-end is not terminated, local event numbers greater than or equal to the valid start-to-end are considered to fall within the valid period. If only one matching record is found, the access controller identifier in that record is identified as the access controller corresponding to the personnel access event. If no matching record is found, or multiple matching records are found, the personnel access event is marked as a personnel access event requiring control verification.
[0085] For each personnel access event for a given access controller, the access controller identifier and local event sequence number are used to locate the personnel access event in the local event sequence of the corresponding access controller. The personnel identifier, access point identifier, and passage direction in the located personnel access event are checked to ensure they match those stored in the continuous access chain. If they match, permission version switching events are searched for from the position of the personnel access event along the decreasing direction of the local event sequence number. The permission version switching event with the largest local event sequence number (less than the personnel access event's local event sequence number) is identified as the event execution permission version switching event. The search continues along the increasing direction of the local event sequence number to find the nearest permission version switching event with a local event sequence number greater than the personnel access event's local event sequence number. If the nearest permission version switching event exists, the local event sequence number of the personnel access event is checked to ensure it is within the event execution permission range. If there is no nearest permission version change event between the local event number of the limited version change event and the local event number of the nearest permission version change event, check if the local event number of the personnel access event is greater than the local event number of the event execution permission version change event. If the check passes, map the event execution permission version change event to the corresponding position of the personnel access event in the continuous access chain, and read the permission version record based on the permission version identifier contained in the event execution permission version change event. The read permission version is determined as the event execution permission version of the personnel access event. The event execution permission version indicates the permission version that the access controller has been enabled and used for access judgment when the personnel actually passes through the access point. The personnel access event, access controller identifier, local event number, local event number of the event execution permission version change event, permission version identifier, and event execution permission version are saved together as an event execution permission version mapping record.
[0086] Adjacent personnel access events are selected sequentially according to the connection order in the continuous access chain. The personnel access event that appears first is designated as the preceding personnel access event, and the personnel access event that appears last is designated as the following personnel access event. The event execution permission version mapping records corresponding to the preceding and following personnel access events are read. If the permission version identifiers corresponding to the preceding and following personnel access events are the same, no permission version switching boundary is defined between the preceding and following personnel access events. If the permission version identifiers corresponding to the preceding and following personnel access events are different, the connection position between the preceding and following personnel access events is defined as the permission version switching boundary. When an event and a subsequent personnel access event are generated by the same access controller, it checks whether there is a permission version switching event between the local event number of the previous personnel access event and the local event number of the subsequent personnel access event. It also checks whether the permission version identifier contained in the last permission version switching event is consistent with the permission version identifier corresponding to the subsequent personnel access event. If the check passes, the permission version switching boundary is preserved. If the check fails, the previous personnel access event and the subsequent personnel access event are marked as boundary personnel access events to be restored. When the previous personnel access event and the subsequent personnel access event are generated by different access controllers, the permission version mapping record is executed according to the respective events of the previous personnel access event and the subsequent personnel access event to preserve the permission version switching boundary.
[0087] The preceding and following personnel passage events on both sides of the permission version switching boundary are identified as passage events to be assigned. These events represent adjacent personnel passage events whose respective event execution permission versions have been determined, but the target permission version to be used in the continuous passage process needs to be determined in subsequent processing. The event execution permission version corresponding to the preceding personnel passage event is identified as the pre-boundary candidate permission version, and the event execution permission version corresponding to the following personnel passage event is identified as the post-boundary candidate permission version. The pre-boundary and post-boundary candidate permission versions together constitute the candidate permission versions. For continuous passage chains, [further details are needed]. Each permission version switching boundary stores the previous personnel access event, the next personnel access event, the common access control area, the access controller identifier corresponding to the previous personnel access event, the access controller identifier corresponding to the next personnel access event, the event execution permission version mapping record, and the candidate permission version. When the event execution permission version switching event is missing, the permission version identifier cannot be associated with the permission version record, there is a pending event position in the local event sequence, or the personnel access event field is inconsistent, the corresponding personnel access event is marked as a boundary pending personnel access event, and the candidate permission version is not generated using the boundary pending personnel access event.
[0088] S5: Verify the reachability of the access event to be assigned to the preceding access control area and the accessibility of the subsequent access control point under each candidate permission version, and use the unique personnel access event in the access control area of the continuous access chain for reverse constraint to determine the target permission version, including:
[0089] In one implementation, the preceding personnel passage event before the permission version switching boundary and the following personnel passage event after the permission version switching boundary are read according to the connection order in the continuous passage chain. The preceding personnel passage event is identified as the passage event to be verified before the boundary, and the following personnel passage event is identified as the passage event to be verified after the boundary. A correspondence is established between the candidate permission version before the boundary and the passage event to be verified before the boundary, as well as between the candidate permission version after the boundary and the passage event to be verified after the boundary. The permission version records corresponding to the candidate permission version before the boundary and the candidate permission version after the boundary are read respectively. The effective start and end points of the permission in the permission version record are represented by the same unified reference clock and time precision as the unified passage occurrence time. The effective period of the permission is a time interval that includes the effective start point of the permission but does not include the effective end point of the permission. The candidate permission version identifier, the permission version switching boundary, the passage event to be verified before the boundary, the passage event to be verified after the boundary, and the corresponding permission version record are written together into the candidate permission version verification record.
[0090] For each candidate permission version verification record, read the nearest personnel access event before the access event to be verified before the boundary in the continuous access chain. If there is a personnel access event before the access event to be verified before the boundary, compare the target access control area of the nearest personnel access event with the source access control area of the access event to be verified before the boundary, and compare the target access control area of the access event to be verified before the boundary with the source access control area of the access event to be verified after the boundary. If both comparison results are the same, the accessibility of the preceding access control area is recorded as successful; if either comparison result is different, the accessibility of the preceding access control area is recorded as unsuccessful. When a pass event to be verified before the boundary is located at the beginning of a continuous pass chain, the source access control area of the pass event to be verified before the boundary is determined as the starting access control area of the continuous pass chain. If the target access control area of the pass event to be verified before the boundary is the same as the source access control area of the pass event to be verified after the boundary, the accessibility of the preceding access control area is recorded as established. The accessibility of the preceding access control area is only used to verify whether the personnel pass events that have occurred can be continuously connected between physical access control areas. It does not take whether the candidate permission version contains the access permission corresponding to the personnel pass event that occurred before the permission version switching boundary as a judgment condition.
[0091] For candidate permission versions whose accessibility records for the preceding access control area are valid, the access permissions are queried from the set of access permissions for all departments corresponding to the candidate permission version, based on the personnel identifier, access control point identifier, and passage direction in the passage event to be verified after the boundary. If a unique access permission is found, and the unified passage occurrence time of the passage event to be verified after the boundary is greater than or equal to the valid start point of the permission, less than the valid end point of the permission, and the allowed passage status is allowed, the accessibility of the subsequent access control point is recorded as valid. If no access permission is found, multiple access permissions with inconsistent content are found, the unified passage occurrence time does not fall within the valid period of the permission, or the allowed passage status is not allowed, the accessibility of the subsequent access control point is recorded as invalid. Only candidate permission versions whose accessibility records for both the preceding access control area and the subsequent access control point are valid are retained, and the retained candidate permission versions are written into the set of candidate permission versions to be reverse-checked. When the set of candidate permission versions to be reverse-checked is empty, the permission version switching boundary is marked as the boundary to be restored for the target permission version.
[0092] When the set of candidate permission versions to be reverse-verified contains multiple candidate permission versions, the last personnel passage event in the continuous passage chain from the boundary to the next permission version switching boundary is determined as the reverse-verification range. When there is no next permission version switching boundary, the range from the boundary to the end of the continuous passage chain is determined as the reverse-verification range. Personnel passage events are read sequentially from the end of the reverse-verification range towards the permission version switching boundary. The access control point identifier and passage direction correspond to only one set of source access control area and target access control area in the connection relationship between access control point and access control area, and correspond to only one item in the continuous passage chain that can be connected with the source access control area. Personnel access events with complete preceding personnel access events and event execution permission version mapping records are identified as personnel access events unique in both the source and target access control areas. For each candidate permission version to be reverse-checked, starting from personnel access events unique in both the source and target access control areas, personnel access events are read one by one along the continuous access chain towards the permission version switching boundary. According to personnel identifier, access point identifier, access direction, and unified access occurrence time, it is checked whether the candidate permission version to be reverse-checked contains the corresponding allowed access permission that is in the permission validity period. Personnel access events that pass the check are written into the candidate permission version supported access chain in sequence.
[0093] When writing the current personnel access event to the candidate permission version support access chain along the reverse verification direction, the target access control area of the current personnel access event is compared with the source access control area of the next personnel access event already written to the candidate permission version support access chain. If the comparison results are the same, the current personnel access event is written to the candidate permission version support access chain and reading continues in the permission version switching boundary direction. If the comparison results are different, the candidate permission version to be reverse verified lacks the access permission corresponding to the current personnel access event, the corresponding access permission is not in the validity period of the permission or the allowed access status is not allowed, the writing of the current personnel access event to the candidate permission version support access chain is stopped. If the candidate permission version support access chain can be continuously extended to the boundary after the access event to be verified, the corresponding candidate permission version to be reverse verified is retained. If the candidate permission version support access chain cannot be continuously extended to the boundary after the access event to be verified, the corresponding candidate permission version to be reverse verified is identified as the candidate permission version that caused the connection interruption and is excluded.
[0094] If only one candidate permission version is retained after the reverse verification, the retained candidate permission version is determined as the target permission version. If multiple candidate permission versions are still retained after the reverse verification, the event execution permission version mapping record corresponding to the personnel access event that is unique in both the source access control area and the target access control area is read, and the candidate permission version whose permission version identifier matches the permission version identifier in the event execution permission version mapping record is determined as the target permission version. If a unique matching permission version cannot be located from the retained candidate permission versions, the permission version switching boundary is marked as the target permission version to be restored boundary, and the permission adjustment based on the target permission version to be restored boundary is stopped.
[0095] S6: Correct the access control area where the personnel are located based on the target permission version, and adjust the permissions of associated subsequent access control points, including:
[0096] In one implementation, the access control area record for a person includes at least a person identifier, the access control area where the person is located, a unique identifier of the most recently processed event, the area status update time, and the permission version identifier corresponding to the target permission version. When the access control area record for a person is first established, the source access control area of the first person passage event in the continuous access chain is written into the access control area where the person is located, and the unprocessed status is written into the unique identifier of the most recently processed event. Upon subsequent execution, processing begins from the first person passage event in the continuous access chain that is after the unique identifier of the most recently processed event. Personnel passage events whose unique event identifier is the same as or precedes the unique identifier of the most recently processed event are not processed again. Unprocessed events are read sequentially according to the connection order in the continuous access chain. For personnel access events, the connection relationship between the access control point and the access control area is queried using the access control point identifier and the direction of passage. It checks whether the source access control area in the unique connection relationship record is consistent with the access control area where the person is located, and whether the target access control area in the unique connection relationship record is consistent with the target access control area in the personnel access event. If both checks pass, in the same indivisible write process, the access control area where the person is located is updated to the target access control area, the unique identifier of the most recently processed event is updated to the unique identifier of the event corresponding to the personnel access event, and the area status update time is updated to the unified access occurrence time corresponding to the personnel access event. If either check fails, the personnel access event is marked as an access event with an area status pending recovery, and the processing of personnel access events after the area status pending recovery event is stopped.
[0097] After completing all unprocessed personnel passage events in the continuous passage chain, the connection relationship between access control points and access control areas is queried using the personnel's current access control area as the source access control area. The access control point identifier, passage direction, and target access control area in the connection relationship record where the source access control area and the personnel's current access control area are consistent are saved as the associated subsequent access control point record. The correspondence between access control point identifiers and access control controller identifiers is queried using the access control point identifiers in the associated subsequent access control point record. The access control controller identifier in the correspondence record where the valid endpoint is in an unterminated state and there is only one such record is determined as the access control controller identifier corresponding to the associated subsequent access point. The unique identifier of the most recently processed event in the personnel's current access control area record is determined as the unique identifier of the area status baseline event. The personnel identifier, personnel's current access control area, unique identifier of the area status baseline event, access control point identifier, passage direction, target access control area, and access control controller identifier are all written into the associated subsequent access control point record.
[0098] For an access control controller that controls at least one associated subsequent access point, read the currently enabled permission version identifier of the access control controller and check whether the currently enabled permission version identifier of the access control controller is equal to the permission version identifier corresponding to the target permission version, the permission version identifier corresponding to the candidate permission version before the boundary, or the permission version identifier corresponding to the candidate permission version after the boundary. If the currently enabled permission version identifier of the access control controller does not belong to any of the above permission version identifiers, it is determined that a new permission version switch has occurred after the permission version switch boundary is formed, and the corresponding associated subsequent access point record is marked as a record to be re-determined for the target permission version. If the currently enabled permission version identifier of the access control controller belongs to any of the above permission version identifiers, extract all local permission records under the responsibility of the access control controller from the set of access permissions for all departments corresponding to the target permission version, and read all local permission records currently enabled by the access control controller; respectively according to The two sets of local permission records are compared based on the record location conditions consisting of personnel identification, access control point identification, passage direction, valid start point of permission, and valid end point of permission. Local permission records whose target permission version is included but not currently enabled are classified as "additions." Records with the same record location conditions but inconsistent access status are classified as "changes." Records whose current enabled permission version is included but not the target permission version are classified as "revocations." Records with identical content but different permission version identifiers are classified as "version switches." When the access control controller's currently enabled permission version identifier matches the target permission version identifier, but the content of the two sets of local permission records is inconsistent, the corresponding access control controller is marked as an access control controller whose permission data integrity needs to be restored.
[0099] Based on the comparison results, permission adjustment data is generated for each local permission record with discrepancies. This data includes at least the personnel identifier, access point identifier, passage direction, permission version identifier, permission adjustment type, effective start point of permission, effective end point of permission, permitted passage status, and access controller identifier. Permission adjustment data is merged according to the access controller identifier, and a permission adjustment batch identifier is generated based on the personnel identifier, the unique identifier of the area status baseline event, the access controller identifier, the permission version identifier corresponding to the target permission version, and the sending order. Each permission adjustment batch also includes the currently enabled permission version identifier of the access controller read during the comparison, and the identifier belonging to the corresponding door in the target permission version. The total number of local permission records of the access control controller and all local permission records belonging to the corresponding access control controller in the target permission version; before sending the permission adjustment batch, reread the access control area record where the person is located and the access control controller's currently enabled permission version identifier. If the unique identifier of the most recently processed event is inconsistent with the unique identifier of the area status baseline event, or if the access control controller's currently enabled permission version identifier reread is inconsistent with the access control controller's currently enabled permission version identifier read during comparison, cancel the sending of the permission adjustment batch, and re-execute the associated subsequent access control point determination and set comparison based on the updated access control area record where the person is located or the access control controller's currently enabled permission version.
[0100] After receiving a batch of permission adjustments, the access control controller checks whether a confirmation record has been generated for the batch. If a confirmation record has been generated, it returns the record without repeating the permission adjustment. If no confirmation record has been generated, it checks whether the access control controller identifier in the batch matches the access control controller identifier in the receiving batch, whether the currently enabled permission version identifier of the access control controller matches the benchmark permission version identifier recorded in the batch, and whether all local permission records belonging to the corresponding access control controller in the target permission version can be completely read according to the total number of local permission records. After all checks pass, it retrieves all local permission records belonging to the corresponding access control controller in the target permission version. Write to the disabled storage area, verify personnel identification, access control point identification, passage direction, valid start point of permission, valid end point of permission, and allowed passage status, and pause receiving new passage judgments after all local permission records have been verified. Switch the currently enabled local permission records to all local permission records in the disabled storage area, replace the currently enabled permission version identifier of the access control controller with the permission version identifier corresponding to the target permission version, generate a permission version switch event containing the access control controller identifier and the permission version identifier corresponding to the target permission version, assign a local event sequence number to the permission version switch event and write it to the local event record; if any write or verification is not completed, continue to enable the original local permission records and the original permission version identifier, and do not generate a permission version switch event.
[0101] After the permission adjustment is completed, a permission adjustment confirmation record is generated. The permission adjustment confirmation record includes at least the permission adjustment batch identifier, access control controller identifier, permission version identifier corresponding to the target permission version, local event sequence number corresponding to the permission version switch event, completed permission adjustment data, and permission adjustment success status. When the permission adjustment batch identifier, access control controller identifier, permission version identifier corresponding to the target permission version, completed permission adjustment data, and local event sequence number corresponding to the permission version switch event are all consistent with the sent content and local event record, the corresponding permission adjustment batch is recorded as completed. When the permission adjustment confirmation record is missing, the permission version identifier is inconsistent, or the completed permission adjustment data is incomplete, the corresponding permission adjustment batch is recorded as pending recovery and resent using the same permission adjustment batch identifier. After all permission adjustment batches corresponding to subsequent access control points are associated, the unique identifier of the most recently completed event in the access control area record of the personnel is checked again to see if it is equal to the unique identifier of the area status baseline event. If the check results are inconsistent, the records of associated subsequent access control points and permission adjustment batches are regenerated based on the latest access control area of the personnel.
[0102] Example 2
[0103] The difference between Embodiment 2 and Embodiment 1 is that this embodiment introduces a smart community access control dynamic management system.
[0104] Figure 2 A schematic diagram of the structure of a smart community access control dynamic management system according to the present invention is provided. The smart community access control dynamic management system includes:
[0105] Information Acquisition Module: Acquires the connection relationship between access control points and access control areas, the permission version switching events of the access control controllers corresponding to each access control point, personnel access events, and local event sequence numbers;
[0106] Event sorting module: Sorts permission version switching events and personnel access events of the same access controller according to local event sequence number, forming a local event sequence;
[0107] Access Association Module: Based on personnel identification, access direction, and connection relationship, it associates personnel access events in multiple local event sequences into a continuous access chain;
[0108] Version mapping module: Maps permission version switching events to a continuous access chain, and defines the access events to be assigned and the candidate permission versions that cross the permission version switching boundary;
[0109] Version determination module: Verifies the reachability of the access event to be assigned to the preceding access control area and the accessibility of the subsequent access control point under each candidate permission version, and uses the unique personnel access event in the access control area in the continuous access chain to perform reverse constraints to determine the target permission version;
[0110] Permission adjustment module: Corrects the access control area where the personnel are located based on the target permission version, and adjusts the permissions of associated subsequent access control points.
[0111] Example 3
[0112] This invention discloses a storage medium, characterized in that the storage medium stores an optimized program based on a smart community access control dynamic management method, which, when executed by a processor, implements the steps of the smart community access control dynamic management method described above.
[0113] The above embodiments are only used to illustrate the technical methods of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical methods of the present invention without departing from the spirit and scope of the technical methods of the present invention.
Claims
1. A method for dynamic management of access control permissions in smart communities, characterized in that, Includes the following steps: S1: Obtain the connection relationship between access control points and access control areas, the permission version switching event of each access control point's corresponding access control controller, personnel access events, and local event sequence numbers; S2: Arrange the permission version switching events and personnel access events of the same access controller according to the local event sequence number to form a local event sequence; S3: Based on personnel identification, passage direction, and connection relationship, associate personnel passage events in multiple local event sequences into a continuous passage chain; S4: Map permission version switching events to a continuous access chain, and define the access events to be assigned and the candidate permission versions that cross the permission version switching boundary; S5: Verify the reachability of the access event to be assigned to the preceding access control area and the accessibility of the following access control point under each candidate permission version, and use the unique personnel access event in the access control area in the continuous access chain to perform reverse constraints to determine the target permission version; S6: Correct the access control area where the personnel are located based on the target permission version, and adjust the permissions of associated subsequent access control points.
2. The method for dynamic management of access control permissions in a smart community according to claim 1, characterized in that, S1, specifically: Collect the access control point signage, source access control area, target access control area, and direction of passage for each access control point, and establish the connection relationship between access control points and access control areas; When the access controller at each access point enables a new permission version to replace the current permission version, a permission version switch event is generated. A personnel passage event is generated when a person actually passes through the access control point; Based on the order in which permission version switching events and personnel access events are generated in the corresponding access controllers, local event sequence numbers are assigned to permission version switching events and personnel access events.
3. The method for dynamic management of access control permissions in a smart community according to claim 2, characterized in that, S2, specifically: Based on the access control controller identifier, the permission version switching event is assigned to the corresponding access control controller; Based on the access control point identifier in the personnel access event, the personnel access event is assigned to the corresponding access control controller; Read the local event sequence numbers of permission version switching events and personnel access events within the same access control controller, and merge and arrange them according to the order in which they were generated; Determine the position of each person's access event before, between, or after the adjacent permission version switching event to form the local event sequence of the corresponding access controller.
4. The method for dynamic management of access control permissions in a smart community according to claim 3, characterized in that, S3, specifically: Extract personnel access events with the same personnel identifier from each local event sequence; Based on the access control point signage, passage direction, and connection relationship between access control points and access control areas in personnel access events, determine the source access control area and target access control area corresponding to each personnel access event; Personnel access events whose target access area is the same as the source access area of the previous personnel access event will be sequentially linked together; Based on the position of each person's passage event in the corresponding local event sequence, connections that conflict with the order of occurrence are eliminated to form a continuous passage chain.
5. The method for dynamic management of access control permissions in a smart community according to claim 4, characterized in that, S4, specifically: The corresponding access controller is determined based on the access point identifier of personnel passage events in the continuous passage chain; In the corresponding local event sequence, find the local event with a local event number less than the personnel access event and the nearest permission version switching event, map it to the continuous access chain, and determine the permission version corresponding to the permission version switching event as the event execution permission version; Compare the event execution permission versions of adjacent personnel passage events, and define the positions where the event execution permission versions differ as permission version switching boundaries; The passage events of adjacent personnel on both sides of the permission version switching boundary are identified as passage events to be assigned, and the corresponding event execution permission version is identified as the candidate permission version.
6. The method for dynamic management of access control permissions in a smart community according to claim 5, characterized in that, S5, specifically: The candidate permission version is assigned to the access event to be assigned, and the accessibility of the preceding access area is verified based on whether the source access area is connected to the target access area of the previous personnel access event. Based on whether the candidate permission version includes the access permission of the access point corresponding to the next personnel access event, verify the accessibility of the subsequent access point; Retain candidate permission versions where both the accessibility of the preceding access control area and the passability of the subsequent access control point are true; When multiple candidate permission versions exist, starting from the personnel passage event that is unique in both the source and target access control areas, the access control area connection relationship is checked in reverse along the continuous passage chain to eliminate candidate permission versions that cause connection interruption and determine the target permission version.
7. The method for dynamic management of access control permissions in a smart community according to claim 6, characterized in that, S6, specifically: Based on the source access control area, target access control area, and direction of passage corresponding to the passage event to be assigned, update the access control area where the person is located to the target access control area; Based on the access control area where the person is located and the connection relationship between the access control point and the access control area, determine the associated subsequent access control points with the access control area where the person is located as the source access control area; Compare the associated access permissions of the target permission version with the access permissions currently enabled by the corresponding access controller; Based on the comparison results, permission adjustment data including personnel identifier, access control point identifier, permission version identifier, and permission adjustment type is generated and sent to the corresponding access control controller.
8. A smart community access control dynamic management system, used to implement the smart community access control dynamic management method according to any one of claims 1-7, characterized in that, include: Information Acquisition Module: Acquires the connection relationship between access control points and access control areas, the permission version switching events of the access control controllers corresponding to each access control point, personnel access events, and local event sequence numbers; Event sorting module: Sorts permission version switching events and personnel access events of the same access controller according to local event sequence number, forming a local event sequence; Access Association Module: Based on personnel identification, access direction, and connection relationship, it associates personnel access events in multiple local event sequences into a continuous access chain; Version mapping module: Maps permission version switching events to a continuous access chain, and defines the access events to be assigned and the candidate permission versions that cross the permission version switching boundary; Version determination module: Verifies the reachability of the access event to be assigned to the preceding access control area and the accessibility of the subsequent access control point under each candidate permission version, and uses the unique personnel access event in the access control area in the continuous access chain for reverse constraint to determine the target permission version; Permission adjustment module: Corrects the access control area where the personnel are located based on the target permission version, and adjusts the permissions of associated subsequent access control points.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a program or instructions that cause a computer to execute a smart community access control dynamic management method as described in any one of claims 1 to 7.