Instant access control equipment combining trusted digital identity and security chip
The instant access control device, which combines trusted digital identity with a security chip, solves the problem of poor communication in weak network environments by generating ciphertext and decrypting it with the security chip, thus enabling normal passage and identity authentication in weak network environments.
Patent Information
- Application Number
- CN202423289703.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Utility models(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-30
- Publication Date
- 2025-11-28
- Estimated Expiration
- 2034-12-30
AI Technical Summary
Traditional access control devices suffer from poor communication in weak network environments, resulting in delayed authorization and impeded passage. Furthermore, device performance and power supply strategies can prevent the devices from uploading communication records in a timely manner.
The device employs an instant access control system that combines trusted digital identity with a security chip. It generates encrypted data through the access control platform and decrypts it using the security chip. It combines multiple communication methods for identity authentication and permission verification, ensuring normal access even in weak network environments.
It enables normal passage even in weak network environments, ensuring the real-time nature and security of identity authentication, and solving the problem of passage obstacles caused by network instability.
Smart Images

Figure CN223611954U_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The utility model relates to access control security technology field, concretely is a kind of open type access control equipment in combination with trusted digital identity and security chip. BACKGROUND
[0002] Traditional access control equipment is embedded with communication module such as wifi / lan / 4g / veegan, usually uses the way of preset personnel access right to issue to terminal equipment, and personnel access is carried out through various verification methods such as two-dimensional code, face, fingerprint, password login mode to verify personnel right and access judgment.
[0003] For example, the patent announcement No.CN211979737U discloses "a door access control system based on two-dimensional code", including server, access control device and mobile terminal, access control device and mobile terminal are connected by transmitting two-dimensional code information, the key before two-dimensional code coding is encrypted by first encryption unit, after mobile terminal receives information, it is decrypted by first decryption unit again, to verify the security of two-dimensional code, server key is encrypted by key encryption unit before transmission, after server receives the key in the string of mobile terminal, it is decrypted by decryption unit again and then checked;
[0004] However, in weak network environment, due to the incoherent communication, it may cause access obstacles due to no timely issuance of real-time right, and it may cause no timely uploading of communication record due to device performance and power supply strategy and network reasons. The communication environment of the device itself is required to be higher, in some weak network areas, it often causes management platform to display device offline due to abnormal device networking, right cannot be issued, access record cannot be uploaded in time and so on. UTILITY MODEL CONTENT
[0005] The utility model aims at providing a kind of open type access control equipment in combination with trusted digital identity and security chip to solve the problems raised in the above background.
[0006] To achieve the above object, the utility model provides the following technical scheme:
[0007] A kind of open type access control equipment in combination with trusted digital identity and security chip, comprising:
[0008] Access control platform end, including key encryption unit and first communication unit;
[0009] Access control mobile terminal, including processor, and the second communication unit, two-dimensional code generation unit, bluetooth unit, NFC unit connected with processor;
[0010] Access control device, including MCU unit, and the code scanning submodule, bluetooth submodule, NFC submodule, security chip, sound-light unit and electric control unit connected with MCU unit.
[0011] The first communication unit and the second communication unit are wirelessly connected, the security chip is used for analyzing the ciphertext and feeding back the analysis result to the MCU unit, and the MCU unit controls the sound and light unit and the electric control unit to perform corresponding actions.
[0012] Preferably, the access control mobile terminal further comprises an identity authentication unit connected with the processor, and the access control platform terminal further comprises an identity recognition unit, which stores registered personnel information and is used for comparing the identity information sent by the identity authentication unit to determine the personnel identity.
[0013] Preferably, the security chip is built-in with a secret key consistent with the key encryption unit.
[0014] Preferably, the access control platform terminal and the access control device both comprise a dynamic password generation module with the same structure, and the access control device further comprises an input module.
[0015] Preferably, the access control device comprises a shell, the MCU unit, the code scanning sub-module, the Bluetooth sub-module, the NFC sub-module, the security chip, the dynamic password generation module and the input module are arranged on the shell, a recess for accommodating the input module is formed in the lower side wall of the shell, a reset tension spring is connected between the recess and the input module, and the reset tension spring drives the input module to normally extend into the recess.
[0016] Compared with the prior art, the device of the present application has the following advantages: the device uses multiple ways to communicate with the access control device and uses a security chip to verify the communication message and the authority, solves the problem of weak network and terminal device strong security authentication, uses the ciphertext generated by the access control platform terminal for transmission in the communication process, the access control platform side can use a special key encryption unit for ciphertext generation, the security chip used in the access control device is pre-filled with a secret key consistent with the key encryption unit of the access control platform side, so that the access control device calls the corresponding interface of the security chip to decrypt the ciphertext after receiving it, the security chip executes the decryption and verification actions, feeds back the execution result to the MCU unit, the MCU unit judges the result and executes the next door opening action or other prompt to achieve the purpose of passing.
[0017] In the human authentication, the use purpose of real person and real evidence is achieved through the authentication of the trusted digital identity. BRIEF DESCRIPTION OF DRAWINGS
[0018] In order to more clearly illustrate the technical scheme of the embodiments of the present application, the following will briefly introduce the drawings needed to be used in the embodiment description. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can also be obtained by those skilled in the art without creating any creative labor.
[0019] Figure 1 This is a schematic diagram of the structure of this utility model;
[0020] Figure 2 This is a schematic diagram of the cooperative structure of the mobile access control terminal and the access control equipment of this utility model;
[0021] Figure 3 This is a schematic diagram of part of the access control equipment of this utility model.
[0022] 1. Housing; 2. Sunshade; 3. Display screen; 4. Sensing area; 5. Input module; 6. Reset spring. Detailed Implementation
[0023] The technical solutions of the present utility model will be clearly and completely described below with reference to the accompanying drawings of the embodiments. Obviously, the described embodiments are only some embodiments of the present utility model, and not all embodiments. Based on the embodiments of the present utility model, all other embodiments obtained by those skilled in the art without creative effort are within the protection scope of the present utility model.
[0024] Example 1: An instant-opening access control device that combines trusted digital identity with a security chip, such as... Figures 1-2 As shown: This includes access control equipment, mobile access control terminals, and access control platform terminals.
[0025] The mobile access control terminal inputs identity information through the identity authentication unit, which is then transmitted to the identity recognition unit on the access control platform via the first and second communication units. The identity recognition unit stores registered personnel information. By comparing the identity information input into the identity authentication unit with the personnel information stored in the identity recognition unit, the trusted digital identity is verified. After successful verification, the access control platform issues a list of access control devices with corresponding access permissions. The user selects the access control device they need to pass through on the mobile access control terminal and clicks a button to obtain the authorization ciphertext. Once the authorization ciphertext is obtained, it is transmitted to the access control device via a QR code image, Bluetooth, or SuperSIM ciphertext, and then communicates with the scanning submodule, Bluetooth submodule, or NFC submodule in the access control device. The access control device calls its built-in security chip to parse the ciphertext. If the parsing is correct, the ciphertext is fed back to the MCU unit of the access control device. The MCU unit controls the audio-visual unit and the electronic control unit to perform corresponding actions.
[0026] Example 2 includes all the contents of Example 1, except that:
[0027] The access control platform end and the access control device are both provided with dynamic password generation modules with the same structure, a user selects a dynamic password for passing through an access control on the access control mobile end, the dynamic password generation module of the access control platform end generates a corresponding dynamic password and sends it to the access control mobile end, and the user acquires the dynamic password through the access control mobile end and informs a third person on site.
[0028] The third person on site inputs the dynamic password through the input module 5, the dynamic password generation module of the access control device also generates a set of dynamic passwords, the MCU unit compares whether the input dynamic password and the generated dynamic password are consistent, and if consistent, controls the sound and light unit and the electric control unit to perform corresponding actions.
[0029] The time steps of the two sets of dynamic password generation modules of the access control platform end and the access control device are spaced apart by one hour, and the two sets of dynamic password generation modules use the same seed and algorithm.
[0030] Embodiment three contains all the contents of embodiment two, and the difference is that:
[0031] The dynamic password generation module of the access control platform end generates different dynamic passwords according to different user information, the third person on site first inputs corresponding user information through the input module 5, and then inputs the dynamic password provided by the corresponding user; the dynamic password generation module of the access control device generates a corresponding dynamic password according to the input user information, and then performs comparison.
[0032] This setting can record which user's dynamic password the outsider enters according to.
[0033] Embodiment four contains all the contents of embodiment one or three, and the difference is that, as shown in Figure 3 , the dynamic password generation module of the access control platform end generates different dynamic passwords according to different user information, the third person on site first inputs corresponding user information through the input module 5, and then inputs the dynamic password provided by the corresponding user; the dynamic password generation module of the access control device generates a corresponding dynamic password according to the input user information, and then performs comparison.
[0034] The access control device further comprises a shell 1, the MCU unit, the code scanning submodule, the Bluetooth submodule, the NFC submodule, the security chip, the input module 5, and a corresponding set of dynamic password generation modules and are arranged on the shell 1, the upper part of the shell 1 is provided with a display screen 3 for displaying the information input by the input module 5, the upper part of the shell 1 is provided with a sunshade 2 for protecting the display screen 3, the lower part of the shell 1 is set as an induction area 4, and the NFC unit of the access control mobile end is placed in the induction area 4 and used in cooperation with the NFC submodule.
[0035] The bottom wall of the shell 1 is provided with a groove, a reset tension spring 6 is connected between the groove and the input module 5, and the reset tension spring 6 drives the input module 5 to normally extend into the groove to be hidden.
[0036] In the description of the specification, the description of the terms "one embodiment", "an example", "a specific example" and the like means that the specific features, structures, materials or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the utility model. In the specification, the illustrative description of the above terms does not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described can be combined in any one or more embodiments or examples in a suitable manner.
[0037] The preferred embodiments of the utility model disclosed above are only used for helping to explain the utility model. The preferred embodiments do not describe all the details exhaustively, and also do not limit the utility model to only the specific implementation manners described. Obviously, according to the content of the specification, many modifications and changes can be made. The specification selects and specifically describes these embodiments in order to better explain the principles and practical applications of the utility model, so that the persons skilled in the art can well understand and utilize the utility model. The utility model is limited only by the claims and the entire scope and equivalents thereof.
Claims
1. A turnstile access control device that combines trusted digital identity with a secure chip, characterized in that, The application relates to a door access control system. The door access control platform end comprises a key encryption unit and a first communication unit. The door access control mobile end comprises a processor, a second communication unit, a two-dimensional code generation unit, a Bluetooth unit and an NFC unit connected with the processor. The door access control device comprises an MCU unit, a code scanning sub-module, a Bluetooth sub-module, an NFC sub-module, a security chip, a sound and light unit and an electric control unit connected with the MCU unit. The first communication unit and the second communication unit are wirelessly connected, the security chip is used for analyzing the ciphertext and feeding back the analysis result to the MCU unit, and the MCU unit controls the sound and light unit and the electric control unit to perform corresponding actions.
2. The instant access access control device incorporating trusted digital identity and secure chip of claim 1, wherein: The door access control mobile end further comprises an identity authentication unit connected with the processor, and the door access control platform end further comprises an identity recognition unit which stores registered personnel information and is used for comparing the identity information sent by the identity authentication unit to determine the personnel identity.
3. The instant access access control device incorporating trusted digital identity and secure chip of claim 1, wherein: The security chip is built-in with a secret key consistent with the key encryption unit.
4. The instant access access control device incorporating trusted digital identity and secure chip of claim 1, wherein: The door access control platform end and the door access control device both comprise dynamic password generation modules with the same structure, and the door access control device further comprises an input module.
5. The instant access access control device incorporating trusted digital identity and secure chip of claim 4, wherein: The door access control device comprises a shell, and the MCU unit, the code scanning sub-module, the Bluetooth sub-module, the NFC sub-module, the security chip, the dynamic password generation module and the input module are arranged on the shell.
Citation Information
Patent Citations
Access control system based on two-dimensional code
CN211979737U