System for controlling access to buildings, building complexes and / or site installations
A decentralized access control system using cellular modems simplifies installation and maintenance, enhancing flexibility and security in environments without continuous network infrastructure.
Patent Information
- Application Number
- DE202025106616
- Authority / Receiving Office
- DE · DE
- Patent Type
- Utility models
- Current Assignee / Owner
- Filing Date
- 2025-10-31
- Publication Date
- 2026-01-22
- Estimated Expiration
- 2035-10-31
AI Technical Summary
Common access control systems for larger facilities are inflexible and difficult to retrofit due to their integration with the building's IT infrastructure, limiting flexibility and scalability.
A decentralized access control system utilizing cellular modems for communication between control units and an administrator unit, eliminating the need for on-site IT infrastructure and enabling modular, scalable, and fault-tolerant operation.
Facilitates easy installation and maintenance, reduces security risks, and allows operation in environments without continuous network infrastructure, providing flexible and secure access control.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
State of the art
[0001] The invention relates to a system according to the preamble of claim 1 and a building, a building complex and / or a terrain installation according to the preamble of claim 12.
[0002] Common access control systems for larger facilities such as buildings, which manage multiple entrances and areas, are always firmly embedded in the building infrastructure, especially the building's IT infrastructure. This makes these systems inflexible and difficult to retrofit.
[0003] The object of the invention is, in particular, to provide a generic device with advantageous flexibility characteristics. This object is achieved according to the invention by the features of claims 1 and 12, while advantageous embodiments and further developments of the invention can be found in the dependent claims. Advantages of the invention
[0004] The invention relates to a system for controlling access to areas of a building, a building complex and / or a site installation by means of blocking and releasing access control devices, for example doors, gates, barriers, turnstiles, etc., in response to access requests, comprising a plurality of control units, each assigned to one of the access blocking devices and designed to control at least one function of the access blocking device, for example a locking state of the access blocking device or an access blockage state of the access blocking device, and comprising an administrator unit designed separately from the control units and located remotely from the access blocking devices, at least for sending / transmitting control instructions based on the access requests to the control units for controlling the at least one function of the access blocking device.
[0005] It is proposed that each of the system's control units be equipped with a cellular modem, with all operational communication between the control units and the administrator unit taking place via these cellular modems. This eliminates the need for on-site IT infrastructure, particularly network cabling, local servers, or wireless LAN connections. This significantly simplifies installation and commissioning, as no network cables need to be laid and no network components or network security systems need to be configured. Furthermore, the full use of cellular communication advantageously enables location-independent, scalable, and modular system expansion.Additional access control devices can now be put into operation, for example, by simply adding more control units, without requiring any changes to a central network topology. Since each control unit has its own cellular modem, a fault-tolerant communication architecture can also be created, particularly because the failure of a single control unit cannot affect the operation of the other control units. The system is especially suitable for distributed site installations or building complexes where a continuous network infrastructure is not economically or technically feasible, for example, in parks or industrial facilities, factory premises, solar parks, port terminals, or security-relevant outdoor areas.Furthermore, the elimination of a local IT connection reduces the security risk posed by a centralized cyberattack, particularly since all data transmission occurs via secure mobile communication channels. Overall, the system according to the invention advantageously enables autonomous, flexible, and low-maintenance operation of an access control system with minimal infrastructure requirements.
[0006] The system, as used here, refers in particular to an assembly of several control units and at least one administrator unit that work together to control access to areas of the building, building complex, or site installation. A passage blocking device is, in particular, any device that controls or prevents the physical passage of persons or vehicles. A "control unit" is understood to be, in particular, a unit with an information input, information processing, and information output. Advantageously, the control unit includes at least a processor, memory, input and output interfaces, other electrical components, an operating program, control routines, and / or calculation routines.Preferably, the components of the control unit are arranged on a common circuit board or several interconnected circuit boards and / or advantageously in a common housing. "Provided for" is understood to mean, in particular, specifically programmed, designed, and / or equipped. The fact that an object is intended for a specific function is understood to mean, in particular, that the object fulfills and / or performs this specific function in at least one application and / or operating state. The administrator unit is, in particular, arranged separately from and / or remotely from the building, the building complex, and / or the site installation with the access control devices. The control units are, in particular, each (portable) physical electronic unit, preferably each comprising at least a processor, a memory, data communication interfaces, and a physical housing.The control units can be battery-powered and / or have a mains power connection option. Solar power or similar is also conceivable. The control units can each be integrated into an ID card reader or can themselves function as an ID card reader.
[0007] Functions of the access control device are, in particular, technical actions or changes in the operating state of the respective access control device brought about by the control unit. Examples of such functions include, in particular: a) locking or unlocking a door, gate, or barrier; b) triggering an opening movement of a motorized door, turnstile, or barrier; c) blocking or releasing access by mechanical blocking or unlocking; d) controlling a signaling unit, for example, activating a visual indicator (illuminated field "Access allowed" / "Access denied") or an acoustic signal; e) detecting a state of the access control device, such as an opening angle, a lock status, or a blockage detection by a sensor; or f) triggering an alarm message when an unauthorized access attempt is detected.In some embodiments, a control unit can perform or coordinate several functions simultaneously, for example, unlocking a door and simultaneously providing a visual indication of access authorization.
[0008] An access request is, in particular, an (electronic or data-based) request generated by an authentication or identification unit of a control unit when a person or object seeks access to an area. The access request can be triggered by the following events: a) presenting an ID card or RFID tag to a card reader, b) entering a PIN code on a keypad or touch input device, c) capturing a biometric characteristic, such as a fingerprint or facial pattern, or e) the approach of an authorized object (e.g., a vehicle with a transponder) to a sensor area. For example, a person holds an authorized RFID card to a card reader of a door control unit. The control unit then generates an access request, which is transmitted to the administrator unit via the cellular modem.This request contains, for example, a card ID, a timestamp, and the identifier of the relevant control unit. The administrator unit uses this information to determine a control instruction corresponding to the person's authorization and transmits it to the cellular modem of the control unit that originally sent the access request. A control instruction is, in particular, a data message generated by the administrator unit and transmitted via the cellular network to a control unit, which triggers or controls a specific function of the access control device.The control instruction can include, in particular: a) a command to unlock or lock the respective access control device, b) a release or blocking decision depending on the verification of access rights, c) parameters for activating a signaling unit, for example, the display "Access Allowed," or d) instructions for logging or transmitting status data to the administrator unit. For example, after verifying the received access request, the administrator unit recognizes that the presented card is authorized. It then generates a control instruction with the command "Unlock" and sends it via a mobile network to the mobile modem of the relevant control unit. The control unit executes the control instruction by actuating a locking actuator of the door and, if necessary, simultaneously activating a green signal indicator.
[0009] The term "operational communication" refers specifically to all data transmissions necessary for the proper operation of the system. Operational communication can include, for example: a) transmitting access requests from the control units to the administrator unit, b) transmitting control instructions from the administrator unit to the control units, c) synchronizing system parameters and authorization data, d) transmitting status and diagnostic data from the control units, e) performing software or firmware updates, and / or f) transmitting log and event data for central storage. Operational communication thus relates specifically to the functional operation of the access control system and preferably includes local communication processes within a control unit (e.g.,...).(Internal signal lines between a microcontroller and an actuator) are explicitly excluded. Within the scope of the invention, all operational communication takes place exclusively via the cellular modems of the control units. This advantageously ensures that neither a wired nor a local wireless IT infrastructure is required. A cellular modem is, in particular, an electronic communication unit designed for the bidirectional transmission of data via a cellular network. The cellular modem is a component of each control unit of the system and serves to establish a wireless data connection between the respective control unit and the administrator unit. The connection is preferably established via a public or private cellular network, for example, according to the cellular standards GSM, UMTS, LTE, 5G, or 6G.The cellular modem could be implemented as an integrated communication module within the control unit, as a radio module mounted on a circuit board, or as a replaceable plug-in module (e.g., M.2 or Mini PCIe card). For authentication on the cellular network, the cellular modem can utilize a SIM card, an eSIM, or a software-based authentication routine. In preferred embodiments, the cellular modem supports encryption and authentication methods in accordance with common mobile network security standards to ensure the integrity and confidentiality of the transmitted data. In one specific configuration, each control unit incorporates an LTE modem that communicates with a cloud-based administration unit. The connection is established automatically upon system startup and enables continuous data exchange for access control processes and status monitoring.
[0010] In this context, it is proposed that the cellular modem be an LTE modem. This allows for a sufficiently high transmission speed and low latency, enabling control instructions from the administrator unit to be transmitted to the control units almost in real time. This facilitates dynamic access management, even with a large number of access control devices. Furthermore, the use of an LTE network offers the advantage of comprehensive network coverage, allowing operation in virtually any geographical environment without the need for a local network or WLAN infrastructure. This makes the system particularly well-suited for distributed or difficult-to-access installation locations, such as outdoor facilities, industrial parks, or construction sites.The LTE modem preferably supports standardized security and encryption protocols, thus ensuring enhanced data protection during the transmission of access data. Furthermore, LTE advantageously allows the establishment of private or virtual mobile networks (APN-based connections), enabling the system to adapt to the security requirements of different operator environments. An LTE modem is specifically a mobile communication modem designed for data transmission according to the Long Term Evolution (LTE) mobile communication standard. It preferably enables packet-switched data communication with typical data rates of at least 10 Mbit / s.
[0011] Furthermore, it is proposed that the administrator unit be configured using a cloud server infrastructure, preferably running administrator software. This advantageously shifts system administration to a virtualized, scalable, and / or geographically independent server environment. A cloud server infrastructure allows for the (functionally centralized) processing, storage, and provision of access data, user profiles, and system parameters without requiring local server installations. This significantly reduces hardware and maintenance costs. A cloud server infrastructure specifically refers to a distributed computing and storage environment accessible via the internet and / or a mobile network, providing virtual server resources. The cloud server infrastructure can consist of one or more server instances operated in a data center or distributed across multiple locations.It offers, in particular, data processing, storage, and communication functions for the access control system. Administrator software, in this context, is specifically a software application running on the cloud server infrastructure that enables centralized system management. The administrator software serves, in particular, for rights management, recording and evaluating access requests, generating control instructions, and / or monitoring and / or configuring the control units.
[0012] Furthermore, it is proposed that the system include at least one central administrator terminal, providing access to the administrator unit via an internet connection. This advantageously enables location-independent and convenient control and monitoring of the entire access control system. An operator can access the administrator unit from any location without being physically connected to the system. The central administrator terminal could be used, among other things, to: a) grant, modify, or revoke access rights; b) view system logs and event data; c) diagnose or reconfigure control units; and / or d) initiate firmware or software updates to the control units.Since the administrator terminal communicates with the cloud-based administration unit via an internet connection, the need for local administration hardware is advantageously eliminated. An administrator terminal is preferably a control device configured for interaction with the administration unit. The administrator terminal can be a computer, laptop, tablet, or other electronic device with display and input capabilities. It serves primarily for configuring, monitoring, and controlling the system via a graphical user interface or a web application. Access via the administrator terminal is preferably via an encrypted internet connection, for example, using an HTTPS or VPN connection.
[0013] If the central administrator terminal provides access to the control units via the administrator unit, a secure, logically separated communication structure can be advantageously created. For example, the administrator terminal does not have direct access to the control units in the field, but rather sends all commands and requests via the administrator unit as a central intermediary and control instance.
[0014] It is further proposed that each control unit include a local authentication or identification unit, in particular an ID card reader, a PIN entry unit, and / or a biometric reader. This advantageously enables reliable access control. An ID card reader is, in particular, an electronic component for reading an identification card, such as an RFID, NFC, or chip card, either with or without contact. A PIN entry unit is, in particular, a keypad or touchscreen control unit via which a user enters a personal identification number. A biometric reader is, in particular, a sensor for capturing individual biometric characteristics, such as a fingerprint, facial image, or iris pattern, and for digitally converting these characteristics into authentication data.The authentication or identification unit is preferably directly connected to or integrated into the respective control unit.
[0015] Furthermore, it is proposed that each of the control units has a wired or wireless local communication interface for local communication with at least one electrotechnical unit associated with the access blocking device and performing the function of the access blocking device. This advantageously creates a robust and / or modular system architecture in which each control unit can interact independently with its access blocking device. The local communication interface is preferably a hardware and / or software interface through which the control unit can directly exchange data with an electrotechnical unit located in close proximity. The interface can be wired (e.g., RS-485, CAN bus, Ethernet) or wireless (e.g., Bluetooth, WLAN, Zigbee, proprietary radio protocol). The local communication interface is separate from the cellular modem.The local communication interface uses a communication technology different from a long-distance radio connection. The electrotechnical unit is, in particular, a component connected to the control unit or integrated into the access blocking device, which receives or sends electrical signals to perform a function of the access blocking device or to detect its status.
[0016] If the electrotechnical unit is an actuator, in particular an electronic or electromechanical actuator, for example a lock actuator or an actuator for automatically opening the access control device, a local actuator function can advantageously be controlled by the system. Advantageously, the control unit can directly trigger a physical action at the associated access control device, such as locking, unlocking, or opening. An actuator is, in particular, a component that converts electrical or electronic control signals into a mechanical movement or another physical effect. An electronic actuator is preferably an actuator that performs electronic switching or control functions, e.g., by means of a semiconductor switching element or a relay module.An electromechanical actuator is preferably an actuator that converts electrical energy into mechanical motion, for example, by means of motor, magnetic, linear, or servo drives. A lock actuator is, in particular, an actuator that performs a locking or unlocking movement in a door, gate, or barrier mechanism.
[0017] Examples of suitable actors include, but are not limited to: a) Door and gate drives, such as a motor lock with integrated unlocking mechanism that is opened or locked by an electrical signal, an electromechanical door opener with swing arm or linear drive for revolving doors, a door magnetic drive or magnetic holder, a bolt motor or rod drive for multi-point locking of doors, a garage or hall door drive; b) Barrier and gate drives, such as linear actuators or electric spindle drives for raising and lowering a barrier pole, servomotor rotary drives for opening and closing gates or turnstiles, hydraulically or pneumatically assisted electromagnetic actuators, electromagnetic bolt actuators that extend or retract a locking bolt when activated; or c) Locking and locking elements, such as electromagnetic bolts, solenoid drives that briefly generate a linear movement to actuate a lock, clamping actuators for blocking a mechanical axis (e.g.Rotation lock in a turnstile), piezomechanical actuators, d) signal and auxiliary actuators, such as acoustic buzzers or electronic signal transmitters, vibration actuators or tactile feedback devices for user interaction, light signal transmitters (e.g. light bars, status LEDs or flashing lights).
[0018] It is further proposed that the electrotechnical unit be an electronic sensor, for example, a sensor for detecting the open state of the access control device. This advantageously enables continuous condition monitoring. A sensor for detecting the open state of the access control device, e.g., a reed contact sensor or a magnetic switch, detects, in particular, whether a door, gate, or similar control device is open or closed. This can be achieved through magnetic, optical, inductive, capacitive, or mechanical principles. The electronic sensor can also be a sensor for detecting the rotation angle of a door or similar access control device. The electronic sensor can also be a sensor for detecting the presence of a person, such as an infrared sensor or a light barrier. Vibration and / or acceleration sensors are also conceivable.The sensor can be, in particular, a position, motion, proximity, force, current, temperature, vibration, light, humidity, pressure, shock, gas or combination sensor.
[0019] Furthermore, it is proposed that the electrotechnical unit be an optical and / or acoustic output unit. This allows for the advantageous on-site output of statuses, events, or operational information, thus improving ease of use, security, and / or transparency of the access control system. An optical output unit can be a device that indicates statuses, events, or warnings through visible light signals. It can consist, in particular, of one or more light-emitting diodes (LEDs), a light panel, a display, a signal lamp, or a projection device. An acoustic output unit can be a device that generates sound or audio signals to communicate information or warnings audibly, e.g., by means of a buzzer, loudspeaker, or horn. In particular, the optical and / or acoustic output unit serves as a human-machine feedback and information interface.
[0020] Furthermore, it is proposed that the system can operate independently of the building's existing IT infrastructure, the building complex, and the site's installations. This eliminates the need to integrate existing local networks, server structures, or data interfaces into the access control system. This architecture offers several significant technical and operational advantages. The system can be installed without interfering with existing building cabling or IT systems, greatly simplifying installation, particularly in existing buildings. Disruptions or maintenance work on the building's IT infrastructure do not affect the access control system. There is also no network connection between the access control system and internal company or administrative networks, significantly reducing the risk of cyberattacks.Thanks to autonomous mobile communication and, if necessary, battery-backed control units, the system can remain functional even in the event of local network failures. The system can be advantageously operated at any location or distributed across multiple buildings without requiring a shared IT infrastructure. The operator is not dependent on administrator rights or building management resources, but can control the system entirely via the cloud-based administration unit and the administrator terminal. Overall, this design enables autonomous, secure, and location-independent operation of the access control system.The building's IT infrastructure refers specifically to all network and communication systems permanently installed within the building, such as local area networks (LANs), internet connections, server hardware, routers, switches, firewalls, and cabling systems, which typically serve building automation or management. In particular, all communication, control, and data processing operations required for access control can be carried out without the use, connection, or support of a building's IT infrastructure (if one exists at all).
[0021] Furthermore, the building, building complex, and / or site installation is proposed to be equipped with a plurality of access control devices, each with one or more associated electrotechnical units, and with a plurality of control units of a previously described system, wherein each access control device is associated with at least one of these control units. This control architecture offers several technical and organizational advantages, such as good scalability, ease of retrofitting, and / or flexible expandability. The building could be, among other things, an office or administrative building, an industrial plant, a warehouse, an airport, a factory site, a power plant, or a construction site. The plurality can be greater than 5, greater than 10, greater than 15, or greater than 20.
[0022] If all control units of the system are free of internal cabling and cabling to the system's administration unit, a self-contained system architecture can be advantageously created, offering significant technical and economic benefits such as minimized installation effort, high flexibility, reduced construction costs, and ease of maintenance. The term "free of cabling" specifically describes a state in which no signal-carrying or data-carrying cable connections exist, excluding local electrical supply lines or connectors within a unit.
[0023] Furthermore, if the building, building complex and / or site installation has a design that is free from on-site IT infrastructure for controlling access to areas of the building, building complex and / or site installation, a simple and / or cost-effective construction can be advantageously achieved.
[0024] The system, building, building complex, and building installation according to the invention are not limited to the application and embodiment described above. In particular, the system, building, building complex, and building installation according to the invention may, to achieve a functionality described herein, comprise a different number of individual elements, components, and units than that specified herein. Drawings
[0025] Further advantages will become apparent from the following description of the drawings. The drawings illustrate an embodiment of the invention. The drawings, the description, and the claims contain numerous features in combination. A person skilled in the art will expediently consider the features individually and combine them into meaningful further combinations.
[0026] They show: Fig. 1 a schematic representation of a site installation comprising a system for access control with a passage blocking device, to which control units of the system are assigned, and Fig. 2 A schematic representation of the system with an administrator unit and with the several control units, each assigned to one of the passage-blocking devices. Description of the exemplary embodiment
[0027] The Fig. Figure 1 schematically shows a site installation 14. The site installation 14 is enclosed by a fence 52. The site installation 14 includes, for example, a building complex 12 with several buildings 10. The building 10, the building complex 12, and the site installation 14 are free of any on-site IT infrastructure. The fence 52 and the buildings 10 have access control devices 16. All access control devices 16 are monitored by an access control system. Alternatively, only some of the access control devices 16 could be monitored by the access control system, e.g., those that delimit sensitive areas. Each of the access control devices 16 belonging to the access control system is at least one electrotechnical unit 40, 42, 44 (see Figure 1). Fig. 2) assigned. Site installation 14 includes electrotechnical units 40, 42, and 44. Site installation 14 includes a system 28. System 28 is designed to control access to areas of building 10, building complex 12, and / or site installation 14 by means of blocking and releasing the access control devices 16 in response to access requests.
[0028] System 28 comprises a plurality of control units 18, 20, 22, 24. Each of the passage-blocking devices 16 is assigned at least one of these control units 18, 20, 22, 24. The control units 18, 20, 22, 24 are each designed to control at least one function of the passage-blocking device 16, for example, a locking state of the passage-blocking device 16 or a passage-blocking state of the passage-blocking device 16. The control units 18, 20, 22, 24 could be configured according to the devices described in German patent application no. 10 2024 116 684.3. The content of German patent application no. 10 2024 116 684.3 is hereby incorporated in its entirety into this disclosure. All control units 18, 20, 22, 24 of system 28 are free of any wiring between them.All control units 18, 20, 22, 24 of system 28 are free of cabling to an administrator unit 26 of system 28.
[0029] System 28 includes the administrator unit 26. The administrator unit 26 is configured separately from the control units 18, 20, 22, and 24. The administrator unit 26 is located remotely from the access control devices 16. The administrator unit 26 is located remotely from the site installation 14. The administrator unit 26 is configured via a cloud server infrastructure. This cloud server infrastructure runs administrator software. The administrator unit 26 is designed to send control instructions to the control units 18, 20, 22, and 24 to control at least the functions of the access control device 16. These control instructions are based on evaluations of access requests by the administrator unit 26.
[0030] The Fig. Figure 2 shows a schematic representation of System 28 with the multiple control units 18, 20, 22, 24, each assigned to one of the access control devices 16. System 28 can be operated independently of the existing IT infrastructure of Building 10, Building Complex 12, and the site installation 14, should any such infrastructure exist. Each of the control units 18, 20, 22, 24 of System 28 has its own cellular modem 30. The administrator unit 26 also has a cellular modem 30. The cellular modems 30 are all LTE modems. All operational communication within System 28 between the control units 18, 20, 22, 24 and the administrator unit 26 takes place via the cellular modems 30. All operational communication within System 28 among the control units 18, 20, 22, 24 takes place via the cellular modems 30. Each control unit 18, 20, 22, 24 includes a local authentication or identification unit 36.This is designed as an ID card reader, but could also be a PIN entry unit (PIN reader) or a biometric reader.
[0031] Each of the control units 18, 20, 22, 24 has a local communication interface 38, which is provided for local communication with at least one of the electrotechnical units 40, 42, 44 of the passage-blocking devices 16. The local communication interface 38 is located in the Fig. 2 is shown as an example of a wired connection, but could alternatively be wireless, e.g. via a short-range radio interface such as BLE or NFC.
[0032] An electrotechnical unit 40 of the electrotechnical units 40, 42, 44 is an actuator 46. Actuator 46 is, for example, an electromechanical actuator, more precisely a lock actuator for the automatic locking and unlocking of the associated access blocking device 16. Another electrotechnical unit 42 of the electrotechnical units 40, 42, 44 is an electronic sensor 48. The electronic sensor 48 is, for example, a sensor for detecting the open state of the associated access blocking device 16. Another electrotechnical unit 44 of the electrotechnical units 40, 42, 44 is an optical and / or acoustic output unit 50. For example, the optical and / or acoustic output unit 50 is a status display with an acoustic module.
[0033] System 28 has a central administrator terminal 32. The central administrator terminal 32 is located in the Fig.Figure 2 is an example of an internet-enabled desktop PC. The central administrator terminal 32 provides a user with access to the administrator unit 26 via an internet connection 34. The central administrator terminal 32 also provides internet access to the control units 18, 20, 22, and 24, mediated via the administrator unit 26. Reference sign 10 buildings 12 building complex 14 Site installation 16 Passage blocking device 18 Control unit 20 Control unit 22 Control unit 24 control unit 26 Administrator unit 28 System 30 mobile modem 32 Administrator Terminal 34 Internet connection 36 Authentication or identification unit 38 Local communication interface 40 Electrical Engineering Unit 42 Electrical Engineering Unit 44 Electrotechnical Unit 46 Actuator 48 Sensor 50 output units 52 Fencing
Claims
[1] System (28) for controlling access to areas of a building (10), a building complex (12) and / or a site installation (14) by means of blocking and releasing access control devices (16), for example doors, gates, barriers, turnstiles, etc., in response to access requests, comprising a plurality of control units (18, 20, 22, 24), each of which is assigned to one of the access blocking devices (16) and which are intended to control at least one function of the access blocking device (16), for example a locking state of the access blocking device (16) or an access blocking state of the access blocking device (16), and comprising an administrator unit (26) designed separately from the control units (18, 20, 22, 24) and arranged remotely from the access blocking devices (16) for at least sending / transmitting control instructions based on the access requests to control the at least one function of the access blocking device (16) to the control units (18, 20, 22, 24). characterized by, that each of the control units (18, 20, 22, 24) of the system (28) has a mobile communication modem (30), and that all operational communication between the control units (18, 20, 22, 24) and the administrator unit (26) takes place via the mobile communication modems (30). [2] System (28) according to claim 1, characterized by , that the mobile modem (30) is an LTE modem. [3] System (28) according to claim 1 or 2, characterized by , that the administrator unit (26) is trained by a cloud server infrastructure which preferably runs administrator software. [4] System (28) according to any one of the preceding claims, characterized by at least one central administrator terminal (32) which provides access to the administrator unit (26) via an internet connection (34). [5] System (28) according to claim 4, characterized by, that the central administrator terminal (32) provides access to the control units (18, 20, 22, 24) via the administrator unit (26). [6] System (28) according to any one of the preceding claims, characterized by , that each control unit (18, 20, 22, 24) includes a local authentication or identification unit (36), in particular an ID card reader, a PIN entry unit and / or a biometric reader. [7] System (28) according to any one of the preceding claims, characterized by , that each of the control units (18, 20, 22, 24) has a wired or wireless local communication interface (38) for local communication with at least one of the electrotechnical units (40, 42, 44) associated with the passage blocking device (16) and performing the function of the passage blocking device (16). [8] System (28) according to claim 7, characterized by, that the electrotechnical unit (40) is an actuator (46), in particular an electronic or electromechanical actuator, for example a lock actuator or an actuator for automatically opening the passage blocking device (16). [9] System (28) according to claim 7 or 8, characterized by , that the electrotechnical unit (42) is an electronic sensor (48), for example a sensor for detecting an open state of the passage blocking device (16). [10] System (28) according to any one of claims 7 to 9, characterized by , that the electrotechnical unit (44) is an optical and / or acoustic output unit (50). [11] System (28) according to any of the preceding claims, characterized by , that the system (28) can be operated independently of any on-site IT infrastructure of the building (10), the building complex (12) and the site installation (14). [12] Building (10), building complex (12) and / or site installation (14) with a plurality of passage blocking devices (16), each comprising one or more associated electrotechnical units (40, 42, 44), characterized by a plurality of control units (18, 20, 22, 24) of a system (28) according to one of the preceding claims, wherein each of the passage blocking devices (16) is assigned at least one of these control units (18, 20, 22, 24). [13] Building (10), building complex (12) and / or site installation (14) according to claim 12, characterized by , that all control units (18, 20, 22, 24) of the system (28) are free from any cabling between each other and free from any cabling with the administrator unit (26) of the system (28). [14] Building (10), building complex (12) and / or site installation (14) according to claim 12 or 13, characterized bya training course that is independent of any on-site IT infrastructure for controlling access to areas of the building (10), the building complex (12) and / or the site installation (14).