ACCESS CONTROL SYSTEM WITH RADIO AND FACE RECOGNITION
Patent Information
- Application Number
- DE502018015790
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2017-04-10
- Filing Date
- 2018-03-28
- Publication Date
- 2025-05-28
- Estimated Expiration
- 2038-03-28
AI Technical Summary
Existing access control systems require users to handle their mobile devices or remember access codes, which can be inconvenient and prone to errors, especially in high-traffic situations.
An access control system that uses a combination of radio communication to identify authorized mobile devices and facial recognition to verify users, allowing seamless access to restricted zones without user intervention.
The system provides fast and secure access by limiting user profile checks to only those present, reducing the risk of errors and queue formation, even in high-traffic conditions.
Description
[0001] The technology described here generally relates to an access control system that grants an authorized user access to a restricted area within a building or site. Exemplary embodiments of the technology relate in particular to an access control system with a transmitting and receiving device and a method for operating such an access control system.
[0002] Access control systems can be designed in a variety of ways. US 9,077,716, for example, describes an access control system in which a mobile electronic device communicates with an electronic door lock via a Bluetooth or Wi-Fi connection and with a web server via a WAN (Wide Area Network) connection to open the electronic lock. To do this, the mobile electronic device sends its device identifier and a user-entered identifier for the electronic lock to the web server, which verifies access authorization and sends a response to the mobile device consisting of a lock command, the lock identifier, and a code pattern. The mobile device then sends the lock command and code pattern to the electronic lock. If the lock recognizes the lock command and code pattern as valid, it opens.
[0003] WO 2010 / 112586 A1 describes an access control system in which a mobile phone carried by a user sends an identification code to an access node. If the identification code is recognized as valid, the access node sends an access code to the mobile phone, which displays the access node on a screen. When the user holds the mobile phone up to a camera so that it can capture the displayed access code, the access control system checks whether the captured access code is valid. If it is valid, the user is granted access.
[0004] These access control systems offer a certain degree of user-friendliness because users don't need to carry badges or traditional keys, nor do they have to remember an access code. Instead, the mobile electronic device that many users already carry for communication purposes serves as the badge or key. Despite the use of mobile devices, these access control systems still require users to handle the devices. Therefore, there is a need for a different, even more user-friendly technology.
[0005] US 2015 / 221151 A1 concerns a facial recognition-based access control system and procedure in which localization sensors determine the position of mobile electronic devices in an area adjacent to an access area and at least one camera monitors the area adjacent to the access area.
[0006] One aspect of the present invention relates to a system according to claim 12.
[0007] Another aspect concerns a method according to claim 1.
[0008] The technology described here results in an access control system that requires no handling of the mobile electronic device by the user, particularly when the user is already at or near the access point (e.g., a door). An initial verification of user authorization occurs even when the user is still relatively far from the access point. For example, the user can move towards the entrance to the restricted area, while, in one embodiment, the user's mobile electronic device is already communicating with the access control system's transmitting and receiving unit. The transmitting and receiving unit receives the mobile electronic device's identifier, which, if the user is registered as authorized, is assigned to a stored user profile.Alternatively, the sending and receiving device can receive the identifier via a communication network. When the user then enters the detection range of a camera in the access control system, facial features of the user are determined from a camera image in a second phase. If the determined facial features match facial features stored in a user profile to a defined degree, the user is authorized and access is granted without the user having to handle their mobile electronic device. An authorized user can thus enter the access-restricted zone virtually seamlessly.
[0009] A large number of users (e.g., several hundred or thousands) may be authorized to access a restricted zone in a building or area; user profiles are created accordingly. Nevertheless, the technology described here offers the advantage of rapid verification because it doesn't require checking all user profiles of authorized users, but only those of users actually present. A user present can thus enter the restricted zone without significant delay or congestion. This significantly reduces the risk of queues forming at the entrance, especially during periods of high traffic.
[0010] The technology not only offers faster verification, but it can also be used in situations with high security requirements because, for example, it employs two-factor authentication. Firstly, it uses two different channels: radio for transmitting an identifier and optical facial recognition. The identifier must belong to a registered user in the system, and the facial data analysis must confirm this. Secondly, fewer user profiles need to be searched or verified, thus reducing the frequency of errors (i.e., an authorized user is mistakenly denied access, or an unauthorized user is mistakenly granted access).
[0011] Depending on traffic volume, a large number of mobile electronic devices may be present in the public zone. In such a situation, the transmitting and receiving device receives numerous identifiers, which are stored in the storage device. For each stored identifier, it can be determined whether the received identifier is associated with a reference template in the database. If such associations exist, it is checked whether the real-time template matches one of these reference templates; if there is a match, the system grants the user access to the restricted zone, and if there is a mismatch, it denies the user access. The aforementioned advantage of rapid verification is thus guaranteed even during periods of high traffic, because the match check is limited to a restricted (relatively small) number of user profiles.
[0012] The technology described here limits the matching process to a limited set of user profiles. Furthermore, this limited set includes only authorized users, because the mobile device identifier is only assigned to a stored user profile if the user has access. For the image processing system, this means that the requirements for the implemented image processing algorithm are relatively low, for example, regarding recognition accuracy. In contrast to an image processing algorithm tasked with identifying a person based on a relatively large number of facial features with high recognition accuracy (i.e., the degree of match must be relatively high, for example, greater than approximately 90%), the technology described here only requires assigning a relatively small number of facial features to one of the authorized users.Furthermore, the degree of agreement can be set, for example, between approximately 60% and approximately 90%. Therefore, a cost-effective image processing algorithm can be used while still ensuring compliance with safety requirements.
[0013] In one embodiment, the compliance check includes generating a result signal. A compliance signal indicates that the user has access to the restricted zone, while a non-compliance signal indicates that the user does not have access. As a function of the result signal, a control signal can be generated in one embodiment to release a (physical) barrier (e.g., gate, door, or turnstile). A barrier that is not released remains blocked. In another embodiment, the control signal activates an information device when access is denied. The information device can be used, for example, in conjunction with an access point without a physical barrier. If an unauthorized user is detected at the access point, the information device can, in one case, generate an alarm that is perceptible (audible and / or visual) at the access point.In another case, the control signal can alert a security service, which then checks the user identified as not having access.
[0014] In one embodiment, the radio connection between the transmitting and receiving device and a user's mobile electronic device is established according to a Bluetooth or WLAN / WiFi standard. This is advantageous because commercially available mobile phones or smartphones are already equipped with technology according to one of these standards, thus eliminating the need for special devices.
[0015] The technology described here also allows for flexibility regarding the identifier of a mobile device. For example, the identifier of a mobile device can include a device identification number permanently assigned to the device or a telephone number assigned to the mobile device. In one embodiment, each mobile device is equipped with application-specific software that generates a unique and time-invariant identifier for that mobile device. This identifier (regardless of whether it comprises a device identification number or a telephone number, or is generated by software) enables the unambiguous identification of a mobile device.
[0016] In one embodiment, the image processing device has a modular design; an image processing module generates the real-time template from a camera image, and an evaluation module, connected to the image processing module and the storage device, generates a result signal indicating whether the real-time template matches this reference template. Such modularity allows for efficient adaptation of the modules to different requirements (e.g., implementation of a cost-effective image processing algorithm in the evaluation module).
[0017] In one embodiment, modularity is also present with respect to a processor connected to the image processing unit. Depending on the result signal, the processor generates a control signal to control the access control system so that the user is granted or denied access.
[0018] A key advantage of the technology described here is that its application is not limited to the design of access to the restricted area. Access can include a physical barrier, such as a gate, door, revolving door, or turnstile, which can either be opened or closed. Alternatively, access can be designed without such a physical barrier (i.e., as essentially barrier-free access). If an unauthorized user is detected at the access point (with or without a physical barrier) using the technology described here, an alarm can be generated and / or a security service can be alerted.
[0019] In one embodiment, the technology described here can be used in conjunction with an elevator system. For each authorized user, a target floor can be defined, for example, where their workplace or apartment is located. When access is granted, a destination call can be generated for the user in question, whereupon the elevator system's control unit moves an elevator car first to a boarding floor and then to the target floor. This improves user-friendliness because the user can go directly to an assigned elevator car without having to initiate an elevator call themselves.
[0020] The following section explains various aspects of the improved technology in more detail using exemplary embodiments in conjunction with the figures. In the figures, identical elements have the same reference numerals. They show: Fig. 1 a schematic representation of an application example of an access control system in connection with a building; Fig. 2 a schematic representation of an embodiment of an access control system; Fig. 3 a flowchart of an embodiment of an access control procedure as one aspect of a method for operating the access control system; and Fig. 4 an exemplary signal diagram to represent an embodiment of a visitor registration procedure as one aspect of a method for operating the access control system.
[0021] Fig. 1 This is a schematic representation of an application example of an access control system 1 in connection with a situation in a building, of which, for illustrative purposes, only some walls, rooms 4 and zones 8, 10 are shown. The rooms 4 can be, for example, offices, apartments, halls and / or elevator cars of an elevator system. In the Fig. 1 In the application of access control system 1 shown, several users 2 are located in zone 10, carrying mobile electronic devices 6 (hereinafter also referred to as mobile device 6). In this example, zone 10 is not subject to any access restrictions and is hereinafter also referred to as public zone 10. Public zone 10 can be an area inside or outside the building. An access point 12 separates public zone 10 from zone 8, which is subject to access restrictions and adjoins rooms 4. A person skilled in the art will recognize that access control system 1 is not limited to applications within a building, but can also be used analogously to control access to an access-restricted zone on a site. In this description, the term "building" includes, for example, residential buildings, commercial buildings, sports arenas, shopping centers, and also ships.
[0022] The access control system 1 monitors access 12 so that only authorized users 2 can enter zone 8, for example by blocking or releasing a door, barrier, turnstile, or other physical barrier, by activating an information device 38 in the case of access without a physical barrier when an unauthorized user 2 is detected, or by combining these measures. The information device 38 can, for example, trigger a visual and / or audible alarm or initiate notification of a security service. Fig. 1 For illustrative purposes, the access control system 1 is shown arranged in entrance 12; a turnstile 36 is also indicated as an exemplary physical barrier. However, the person skilled in the art recognizes that in a concrete implementation, the access control system 1 or its components can be arranged in various ways.
[0023] In another embodiment, the access control system 1 is arranged at an access point 18 to at least one room 4, possibly at each access point 18. Depending on the type of room 4, the access point 18 may be, for example, an office door, a floor door, an apartment door, or an elevator door, each of which then constitutes a physical barrier. In this embodiment, each room 4 corresponds to an access-restricted zone 8, and the area in front of an access point 18 corresponds to the public zone 10. The access control system 1 unlocks, for example, an electronic lock on an office or apartment door. In an application involving an elevator, the access control system 1 can, for example, prevent an elevator car from departing if an unauthorized user 2 enters or attempts to enter the car.
[0024] As in Fig. 1 As indicated, the access control system 1 comprises a transmitting and receiving device 14 (in Fig. 1 (shown as TX / RX) and a camera 16 as part of an image processing unit; further components of the access control system 1 are in Fig. 2 As shown. In one embodiment described here, the transmitting and receiving device is designed to receive radio signals and is therefore referred to as transceiver 14 in the following. The transceiver 14 communicates with the mobile electronic devices 6 when they are within radio range of the transceiver 14, i.e., a radio signal transmitted by a mobile device 6 has a signal strength at the location of the transceiver 14 (expressed by an RSSI value (Received Signal Strength Indicator)) that is greater than a threshold value defined for reliable reception. Communication takes place, for example, via a near-field radio network such as a Bluetooth network, WLAN / WiFi, or a ZigBee network. Bluetooth is a standard according to IEEE 802.15.1, WLAN / WiFi is a standard according to IEEE 802.11, and ZigBee is a standard according to IEEE 802.15.4. Such radio networks according to these standards serve for the wireless networking of devices over a short distance of approximately...a few meters to approximately one hundred meters. The radio network forms the interface through which the mobile electronic device 6 and the transceiver 14 can communicate with each other.
[0025] In another embodiment, the transmitting and receiving device 14 is communicatively coupled to a communication network 38. In this embodiment, the transmitting and receiving device 14 can receive the device-specific identifier of a mobile device 6 via the communication network 38. The mobile device 6 can determine its current location using a positioning function installed on it, for example, based on GPS (Global Positioning System). By means of an internet connection established via a mobile communication system (e.g., 4G) (including the communication network 38) and possibly application-specific software, the mobile device 6 can transmit its location together with its identifier to the transmitting and receiving device 14.
[0026] The following describes exemplary implementations of the technology using the transceiver 14. As described above, the transceiver 14 receives an identifier transmitted by a mobile electronic device 6 via (near-field) radio communication.
[0027] The camera 16 generates a camera image of a user 2 (in particular, their face) who is within the camera 16's detection range when the user 2 attempts to enter the access-restricted zone 8 at access point 12. In one embodiment, the camera 16 generates a digital camera image (also referred to as a digital image). The transceiver 14 and the camera 16 (including other components of the image processing device) can be housed in an enclosure, such as the one shown in [reference to relevant document]. Fig. 1 The transceiver 14 and the camera 16 (including other components of the image processing device) can be arranged as shown in access point 12. Alternatively, the transceiver 14 and the camera 16 (including other components of the image processing device) can also be arranged separately as separate units, for example, spatially separated from each other in an area around access point 12, with the camera 16 being arranged in such a way that essentially only the user 2 who actually wishes to access the access point is captured.
[0028] In the Fig. 1 In the situation shown, the technology described here can be advantageously applied to operate the access control system 1 with the lowest possible complexity and to grant user 2 convenient access to the restricted zone 8. In short, and by way of example, the operation of the access control system 1 according to an embodiment is as follows: As soon as a user 2 is within radio range of the transceiver 14, their mobile device 6 automatically communicates with the transceiver 14, and the mobile device 6 transmits its identifier to the transceiver 14. In the situation shown Fig. 1 The transceiver 14 receives a multitude of identifiers. The access control system 1 therefore "knows" how many mobile devices 6 are within radio range at a given time and, if their users 2 are registered users 2, to which users 2 the mobile devices 6 belong. These users 2 can be grouped together as a group of present users 2. If one of the present users 2 now wants access to the restricted zone 8, the access control system 1 uses an image processing or facial recognition procedure to determine a data record with facial features of this user 2 and compares this determined data record with stored (facial feature) data records assigned to the present users 2. This comparison is thus limited to the group of present users 2; only data records of this group are searched to see if the determined data record matches one of the stored data records.Because not all data records stored in access control system 1 need to be searched, the facial recognition process runs faster, and it can be decided more quickly whether user 2 is authorized to access or not.
[0029] Fig. 1 Figure 38 also shows the communication network 38, which in one embodiment is communicatively connected to a host system 36 and the access control system 1. It is also indicated that a user 2 can communicate via the communication network 38 using a communication link 40, for example with the host system 36 or a web portal. Exemplary functions of the communication network 38 and the host system 36 are shown in conjunction with... Fig. 4 described.
[0030] Fig. 2 Figure 1 shows a schematic representation of an embodiment of the access control system 1. In one embodiment, the access control system 1 has a modular design and includes an image processing unit which, in addition to the camera 16, contains an image processing module 22 (image processing in Fig. 2 ) and an evaluation module 24 (evaluation in Fig. 2 ) comprises. In addition, the access control system 1 includes, besides the transceiver 14, a processor 20, a storage device 26 (memory in Fig. 2 ) and an intermediate storage device 28 (intermediate storage in Fig. 2 The person skilled in the art recognizes that at least one of the storage devices 26, 28 can also be assigned to the image processing device, or that the function of the intermediate storage device 28 can be performed by the storage device 26, and thus the intermediate storage device 28 can be omitted in an embodiment. The processor 20 has an output 32 for a control signal and an input 30 for a result signal generated by the evaluation module 24. Depending on the result signal, the processor 20 controls the access control system 1 so that access is granted or denied to the user 2. For example, if a physical barrier (e.g., turnstile 36 in Fig. 1 For zones 8 and 10, the control signal either releases or blocks the barrier. If, however, the zone separation occurs without a physical barrier, the control signal, in the case of an unauthorized user 2, triggers, for example, the information device 38 to generate an alarm or alerts a security service. The information device 38 can also be activated, in conjunction with a barrier, to indicate to user 2 or a security service that the barrier has been released or blocked.
[0031] In one embodiment, camera 16 comprises a digital camera with selectable and / or adjustable properties; in this embodiment, camera images are thus available as digital data sets. The properties of the digital camera, for example, resolution (e.g., specified in megapixels), exposure, and focal length, are selected or set such that a camera image (digital image) is evaluable and the face of the user 2 is recognizable in the digital image with evaluable quality. The digital image is available, for example, in JPEG format, but it can also be in another format, such as BMP or JPEG2000. Camera 16 can be equipped with a sensor module or connected to a separate sensor module that activates camera 16 when it detects the presence of a user 2 within the camera 16's detection range.The sensor module can, for example, include a proximity sensor, which can be designed as an ultrasonic sensor, an infrared sensor, or an optical sensor (e.g., a light barrier, a brightness sensor). Alternatively, in one embodiment, the presence of a user 2 within the detection range of the camera 16 can be detected by detecting changes within the detection range. For example, if the user 2 enters the detection range and the camera 16 is continuously in an active state, the camera 16 records changes against a substantially static background; these changes are interpreted as presence.
[0032] The evaluation module 24 is shown for illustrative purposes as a separate unit connected to the image processing module 22, the processor 20, and the buffer storage device 28. In one embodiment, the evaluation module 24 and the image processing module form a single unit. The storage devices 26 and 28 are also shown for illustrative purposes as separate units; depending on the configuration, they may be combined in a single storage device, where, for example, they occupy separate memory areas. Regardless, the storage devices 26 and 28 may, for example, comprise a hard disk drive (HDD) or CD / DVD drive, a solid-state drive (SSD), or combinations thereof, or other storage devices for digital data.
[0033] The aforementioned unit, consisting of evaluation module 24 and image processing module 22, comprises at least one processor unit that executes a computer-aided image processing method. Image processing methods are known, for example, from US 8,494,231 B2. A basic description of image processing for the purpose of facial recognition is provided in the publication "Facial Recognition" by the German Federal Office for Information Security (available under the topic of biometrics at www.bsi.bund.de). This publication distinguishes between three main steps: "creating a template," "generating a reference dataset," and "comparing facial images." To make the comparison of two facial images as simple and quick as possible, the features of a face are determined and stored in the form of a feature dataset referred to as a "template."Once a user's face has been identified and normalized in an image, additional features beyond the eyes, nose, and mouth / chin area are identified, measured, and correlated. These extracted features are coded, compressed, and stored as a feature set (template). To determine the similarity of templates for two face images, they are combined using a mathematical algorithm. This results in a degree of similarity between the templates. If the result falls within certain tolerance limits, the two templates, and thus the underlying face images, are classified as identical.
[0034] According to the technology described here, a template is generated for each user 2 upon registration as an authorized user and stored in a user profile of user 2. The template can be generated from a digital image showing the face of user 2. This template is referred to below as the reference template. It is advantageous if, during registration, the face of user 2 is exposed to similar lighting conditions as those on-site in the vicinity of camera 16. This facilitates the comparison of templates, i.e., the comparison of the reference template with a real-time template that is generated when a user 2 requests access to the access-restricted zone 8.
[0035] In the Fig. 1 In the situation shown, several users 2 are present in public zone 10; some of them may wish to access restricted zone 8, some may be coming from zone 8 and heading towards a building exit, and others may be on their way to another part of the building. This means that, in the situation shown, not every user 2 present in public zone 10 actually wants to enter zone 8. From the perspective of access control system 1, however, all users 2 present are potential users 2 who might wish to access zone 8 sooner or later.
[0036] The access control system 1 identifies the users 2 present by means of communication between the mobile devices 6 and the transceiver 14. Each mobile device 6 has an activated radio module, for example, a Bluetooth module, to communicate with the transceiver 14 as soon as it is within radio range. Depending on the design of the mobile device 6 and its radio module, an application-specific software application (also referred to as an app) may also be activated. In one embodiment, the application-specific software application is used in conjunction with access control and the use of elevators. In this embodiment, the application-specific software also generates a unique and time-invariant identifier for the mobile device. Such a software-generated identifier represents an alternative to the aforementioned device identification number and a telephone number.
[0037] During communication, the mobile device 6 sends its identifier to the transceiver 14; the access control system 1 then updates a database containing the identifiers of all currently present mobile devices 6. These can be mobile devices 6 whose users 2 are registered as authorized users 2 in the access control system 1, as well as mobile devices 6 whose users 2 are not registered. In one embodiment, the database storing the identifiers of the present users 2 is located in the buffer 28.
[0038] For each registered user 2, a user profile is created in the access control system 1, i.e., it is stored as a data record in a database 34. In one embodiment, the database 34 is set up in the storage device 26. The user profile includes personal data of user 2 (e.g., name, reason for access (resident, employee, external service provider), and facial features in the form of a template), access permissions (e.g., specific rooms 4 and floors), and possibly time-based access restrictions (e.g., access from Monday to Friday, from 7:00 to 20:00). At least one mobile device 6 is also assigned to user 2 in the user profile.
[0039] As an alternative to creating the user profile in the access control system 1, the user profile can be created in a database of a building management system, whereby the access control system 1 can access this database via a communication network.
[0040] If one of the users present (2) wishes to access the restricted zone (8), they move through the public zone (10), for example, coming from a main building entrance, towards access point (12). When user 2 enters the detection range of the camera (16) located there, the camera (16) generates one or more digital images or a video recording, each of which is stored as a digital data set and temporarily saved for further processing. The image processing module (22) determines the real-time template from the data set, as described elsewhere in this document.
[0041] Once the real-time template has been determined, the evaluation module 24 starts a search algorithm to check whether the determined real-time template can be assigned to a registered user 2. Instead of searching all stored user profiles in the storage device 26, the search algorithm only searches the user profiles of the currently present user 2. The group of currently present user 2 is stored in the temporary storage 28, as described above. If the determined facial features match the facial features stored in the user profile of user 2 to a defined degree, the evaluation module 24 generates a result signal indicating that user 2 is authorized to access the system. If, however, there is no such match, the result signal generated by the evaluation module 24 indicates that user 2 is not authorized to access the system.
[0042] The mobile device 6 can be, for example, a mobile phone, a smartphone, a tablet PC, or a smartwatch, these devices typically being equipped with hardware that enables communication via a near-field radio network. However, the mobile device 6 can also be glasses with a miniature computer or another wearable computer device, provided these devices are designed for near-field communication. Depending on its design, the mobile device 6 may, for example, have a graphical user interface (GUI) to selectively activate and deactivate the mobile device 6 and its functions.
[0043] With an understanding of the fundamental system components and their functionalities described above, the following will take place in conjunction with Fig. 3 a description of an exemplary access control procedure as one aspect of a procedure for operating the access control system 1 (another aspect is one in connection with Fig. 4 (described registration procedure for a visitor). The description refers to a user 2 who wishes to enter access-restricted zone 8 at entrance 12, for example, to use an elevator. User 2 carries mobile device 2 and has its radio module (e.g., for Bluetooth communication) and possibly an associated software application activated. The procedure begins in step S1 and ends in step S10.
[0044] If user 2 is in public zone 10 with their mobile device 6 and within radio range of transceiver 14, transceiver 14 receives an identifier transmitted by the mobile device 6 in step S2. Transceiver 14 and mobile device 6 communicate according to the same communication standard, in this embodiment via a Bluetooth radio connection. The received identifier is stored in step S3; for example, in the buffer device 28.
[0045] Steps S2 and S3 are executed for each mobile device 6 that is within radio range of the transceiver 14 and operates according to the same communication standard as the transceiver 14. Depending on the number of users 2 in the public zone 10, a multitude of identifiers, corresponding to a group of users 2 present, can be stored in the buffer device 28 at any given time. It is understood that the buffer device 28 is updated when a mobile device 6 is no longer within radio range, for example, because the associated user 2 has left the public zone 10 without intending to access the restricted zone 8, or because the associated user 2 has already entered the restricted zone 8. The buffer device 28 thus stores the identifiers of the mobile devices 6 whose users 2 are present in the public zone 10 at any given time.
[0046] In step S4, it is determined whether one of the users present, 2, wishes to access the restricted zone 8. According to one embodiment, the access control system 1 recognizes this request using the aforementioned sensor module or by detecting background changes. For example, the sensor module detects when user 2 enters the detection range of camera 16, whereupon camera 16 is activated. If an access request is detected, the process proceeds along the "yes" branch to step S5. Otherwise, the process remains in a loop along the "no" branch.
[0047] In step S5, the activated camera 16 generates a digital image that depicts at least the face of the detected user 2, and the image processing module generates a real-time template from the digital image, as described elsewhere in this description.
[0048] In step S6, using the real-time template determined in step S5, each user profile in database 34 associated with a received identifier is searched. A user profile is only searched if it is assigned to a present user 2 based on a received identifier. If a registered user 2 requests access, a user profile exists for this user 2 in database 34, in which the identifier of the mobile device 6 is stored. If the access-requesting user 2 is not a registered user 2, no user profile is assigned to the identifier of the mobile device 6.
[0049] During the search according to step S6, step S7 checks whether the real-time template matches a reference template to a defined degree. In one embodiment, the real-time template and the reference templates each comprise a defined number of fixed facial parameters and their values (e.g., interpupillary distance, mouth width, distance between the upper and lower edges of the lips, distance between the nose and lower edges of the lips, etc.). During the search, the parameter values of the real-time template are compared with the parameter values of the reference templates. A match exists if the degree of similarity between the templates is at least equal to the defined degree. The defined degree specifies a percentage of the facial parameters of the real-time template matching the facial parameters of a reference template. Depending on the accuracy requirements, the defined degree can be chosen, for example, between approximately 60% and approximately 90%.
[0050] If there is a match, the procedure proceeds along the "yes" branch to step S9, in which user 2 is granted access. If there is no match, the procedure proceeds along the "no" branch to step S8, and user 2 is denied access.
[0051] From the in connection with Fig. 3 The description of an exemplary procedure for operating the access control system 1 shows that a user 2 does not need to handle their mobile device 6 to gain access to the restricted zone 8. Depending on the design of the access, i.e., with or without a physical barrier, access authorization can be checked without the user 2 noticing anything.
[0052] In one embodiment, the access control system 1 is connected to an elevator system, in particular to an elevator control unit. Communication between the access control system 1 and the elevator control unit can take place via network 38. If access control is carried out, for example, in the building's entrance hall, which users 2 must pass through to reach the elevators, a destination call can be initiated each time access is granted to the user 2 in question. The elevator control unit of the elevator system processes the destination call and assigns an elevator to the user. The elevator assigned to the destination call can be displayed to user 2, for example, via a terminal at entrance 12 and / or communicated by voice. User 2 can thus go directly to the assigned elevator without having to enter an elevator call.
[0053] In connection with Fig. 3 As described above, each user 2 is registered as an authorized user 2 in the access control system, section 1. Depending on the type of building, unregistered users 2 may also request access to the restricted zone 8, for example, visitors. Fig. 4 Figure 1 shows a signal diagram of an exemplary implementation of a method that makes it possible to grant visitors convenient access to the access-restricted Zone 8. To illustrate an exemplary scenario, Figure 2 shows Fig. 4 Schematically, interactions between a host or a host system 36 used by the host, a visitor or their mobile device 6, and the access control system 1, in order to register the visitor in the control system 1 by means of a registration procedure. According to the technology described here, the visitor is thus also a user 2 (reference 2 will be used below to refer to both the visitor and to one or more users).
[0054] In this scenario, the host and visitor 2 agree on a date and time, or a period of time, at which the host expects visitor 2. The host then creates an invitation using the host system (e.g., PC, notebook, tablet PC, smartphone, or other electronic device) and a software application installed on it (e.g., Outlook or similar applications) and sends it to visitor 2, for example, via communication network 38 and communication link 40. Communication link 40 could, for example, be established via a mobile communication system.
[0055] The invitation includes, in addition to the date details, an identification number assigned to the invitation (in Fig. 4 (referred to as "ID") and also information about a communication channel that visitor 2 must use to communicate with the access control system 1 for the purpose of registration. In one embodiment, the communication channel is the internet; the information about the communication channel therefore includes an internet address for a web portal (in Fig. 4 (referred to as a "link"). The internet address can, for example, include a Uniform Resource Locator (URL) that identifies and locates the web portal as a resource via the access method to be used (e.g., a network protocol such as HTTP or FTP) and the location of the resource in a computer network. The web portal is associated with a computer system of the access control system 1. In one embodiment, the invitation is transmitted via the communication network 38 by means of a signal DS1; it can, for example, be sent as a text message to the mobile device 6 of visitor 2 or as an email to visitor 2's email address.
[0056] The host or host system 36 also sends the invitation data to the access control system 1 via a signal DS2, for example, through the communication network 38, essentially simultaneously with sending the invitation or at a later time. Controlled by the processor 20, the access control system 1 creates a visitor profile for the received invitation data. In one embodiment, the invitation data includes, in addition to the appointment details, information about the host, such as name, telephone number, floor, and / or apartment or office number. Furthermore, a time window can be specified within which visitor 2 is to be granted access. The time window can, for example, specify that visitor 2 receives access approximately half an hour before and after the start of the appointment, in case visitor 2 arrives early or is late.The visitor profile can be deleted after the arrival of visitor number 2 or at a later time.
[0057] The invitation requests that visitor 2 send a digital image, in which visitor 2's face is recognizable, to the access control system 1 via the specified communication channel, for example, the web portal. Visitor 2 can, for instance, take a current self-portrait (also known as a "selfie") with the camera of their mobile device 6 and upload it via the web portal. In another embodiment, visitor 2 can also upload a saved digital image taken at an earlier time. An advantage of the technology described here is that visitor 2 can upload the digital image at a time of their choosing, as long as this occurs before the scheduled appointment. Visitor 2 can be geographically far away from the building or already inside or near the building.
[0058] In conjunction with uploading the digital image, the invitation's identification number is also transmitted so that the access control system 1 can uniquely assign the received digital image to the invitation. Depending on the configuration, the visitor may be prompted to enter the identifier of the mobile device 6 (for example, telephone number or device identification number). If the visitor uploads the digital image using the mobile device 6, the identifier of the mobile device 6 is also transmitted to the access control system 1 in one embodiment, e.g., automatically. If an application-specific software application is installed on the mobile device 6, as described above, it assists the visitor 2 in uploading the digital image. The transmission of the digital image, the identifier, and the invitation's identification number takes place via a signal DS3, for example, via the communication network 38 and the communication link 40.The DS3 signal can be transmitted using a known transmission protocol, such as TCP (Transmission Control Protocol), IP (Internet Protocol), and UDP (User Data Protocol). Access control system 1 stores the received data (digital image, identifier, and invitation identification number) in the visitor profile.
[0059] The technology described here can also utilize other communication channels. As an alternative to using a web portal, the invitation can request that visitor 2 transmit the digital image, the identifier, and the invitation's identification number to a building management company. The building management company can, for example, manage database 34 for the building in question, in which the user profiles of authorized users 2 are stored. The transmission to the building management company can be made, for example, to an email address or telephone number specified in the invitation, such as via SMS or MMS. Building management staff can then initiate the further processing of the received data.
[0060] In one embodiment, the in Fig. 2 The processor 20 shown receives and processes the digital image, the identifier, and the identification number of the invitation. The access control system 1 uses the image processing unit 22 to generate a reference template from the digital image of the visitor 2, as described in conjunction with Fig. 2 The system describes the process and stores the reference template in the visitor profile. According to one embodiment, the visitor profile is thus complete for access control purposes, and the registration process by which visitor 2 is registered in the access control system 1 is finished. The reference template and the invitation data can be read by accessing the visitor profile, for example, using the identifier of visitor 2's mobile device 6.
[0061] Once the visitor profile has been created, visitor 2 can be shown according to the terms associated with Fig. 3 Access will be granted according to the described access control procedure if the visitor arrives at the building at the agreed time. As soon as the visitor enters the reception range of transceiver 14 in public zone 10, transceiver 14 receives the identifier transmitted by mobile device 6. The reception of the identifier from mobile device 6 occurs as described above and is in Fig. 4 The visitor's face is represented by a DS4 signal. If the visitor then enters the detection range of camera 16, camera 16 generates a digital image showing the visitor's face. The generation of the digital image by camera 16 and the subsequent generation of a real-time template occur as described above; in Fig. 4 This is represented by a signal DS 5.
[0062] Access control system 1 checks whether the real-time template matches the reference template to the specified degree. Additionally, access control system 1 checks whether the visitor requests access within the time window defined in the visitor profile. If both conditions are met, the visitor is granted access.
[0063] In one embodiment, the access control system 1 generates and sends a message to the host, informing the host that the visitor has been granted access. The host can thus prepare for the visitor's arrival in a timely manner.
[0064] Depending on the building's design, access control system 1 can communicate with an elevator control system to generate a destination call for visitor 2 upon granting access. The elevator control system assigns an elevator to the destination call, and the assigned elevator can be communicated to visitor 2 in the access area 12 via display or voice prompts. The assigned elevator transports visitor 2 to the floor where the host is located. The host's floor is stored, for example, in the visitor profile in conjunction with the invitation data. Visitor 2, especially if they are visiting the building for the first time, therefore does not need to enter the destination floor. Visitor 2 can also be provided with additional information to help them orient themselves within the building; for example, they can be told in which direction (and possibly how far) they should go after exiting the elevator on the floor.The communication of such wayfinding information can be carried out, for example, by means of the visitor's mobile device 6 and / or displays on the floors or in the elevator car.
Claims
1. Method for operating a system (1) for controlling access to a restricted access zone (8) in a building or a site, wherein the system (1) comprises a transmitting and receiving device (14), a storage device (26, 28) containing a database (34) in which a plurality of user profiles of users (2) authorized to access are stored, a processor (20), and an image processing device (16, 22, 24) which has a camera (16) located at the entrance to the restricted access zone (8), the method comprising: receiving, by the transmitting and receiving device (14), a device-specific identifier of a mobile electronic device (6) of a user (2) when the mobile electronic device (6) is within radio range of the transmitting and receiving device (14) in a public zone (10) from which the user (2) present in the public zone (10) can request access to the restricted access zone (8); storing the received identifier of the mobile electronic device (6) in a further database of the storage device (26, 28) as belonging to a user (2) present, wherein the further database is designed to store identifiers of mobile electronic devices (6) currently present in the public zone (10), wherein such a mobile electronic device (6) is assigned to a user (2) registered or not registered in the access control system (1) and wherein the identifier of a mobile electronic device (6) assigned to a registered user (2) is assigned to a user profile of the registered user (2) stored in the database (34) of the storage device (26, 28); generating, from a camera recording of the user (2) present generated by the camera (16) of the image processing device (16, 22, 24), a real-time template for facial features of a user (2) present when a presence of the user (2) present is recognized in a detection range of the camera (16) when the user (2) present requests access to the restricted access zone (8), wherein the real-time template is generated by the image processing device (16, 22, 24); and searching the user profiles stored in the database (34) for a reference template that matches the real-time template to a specified degree, wherein a user profile is searched only if it is assigned to a user (2) present based on a received identifier stored in the further database, wherein, in case of a match, the system (1) grants the user (2) access to the restricted access zone (8) and denies access if there is no match.
2. Method according to claim 1, in which, when a plurality of mobile electronic devices (6) are located in the public zone (10), - a plurality of received identifiers are stored in the further database of the storage device (26, 28), - for each stored identifier, it is determined whether, in the database (34), the received identifier is assigned to a user profile having a reference template; and, - if such assignments exist, checking to see whether the real-time template matches one of these reference templates to a specified degree, wherein, in the case of a match, the system (1) grants the user (2) access to the restricted access zone (8) and denies access if there is no match.
3. Method according to claim 1 or 2, further comprising generating a result signal, which indicates, in the case of a match, that the user (2) has access to the restricted access zone (8) and, if there is no match, indicates that the user (2) has no access to the restricted access zone (8).
4. Method according to claim 3, further comprising generating a control signal as a function of the result signal to release a barrier (18, 36).
5. Method according to claim 3 or 4, further comprising generating a control signal as a function of the result signal to activate an information device (38) if access is denied.
6. Method according to any of the preceding claims, in which the transmitting and receiving device (14) communicates with a mobile electronic device (6) by means of a radio link, wherein the radio link between the transmitting and receiving device (14) and a mobile electronic device (6) of a user (2) takes place in accordance with a Bluetooth standard or a WLAN / WiFi standard, and wherein the transmitting and receiving device (14) receives the device-specific identifier via the radio link when the mobile electronic device (6) is located within radio range of the transmitting and receiving device (14).
7. Method according to any of claims 1-6, in which the transmitting and receiving device (14) receives the device-specific identifier by means of a communication network (38).
8. Method according to any of the preceding claims, in which the identifier is generated by application-specific software, which is active on the mobile device (6), wherein the identifier does not vary over time.
9. Method according to any of claims 1-7, in which the identifier comprises a device identification number or a telephone number assigned to a mobile device (6).
10. Method according to any of the preceding claims, in which the real-time template and the reference templates each comprise a specified number of specified facial parameters, and in which the specified degree is between 60% and 90%, wherein the specified degree indicates a percentage match of the facial parameters of the real-time template with the facial parameters of a reference template.
11. Method according to any of the preceding claims, further comprising generating a destination call for an elevator system if the user (2) is granted access.
12. System (1) for controlling access to a restricted access zone (8) in a building or a site, wherein the system (1) comprises: a transmitting and receiving device (14), which is designed to receive a device-specific identifier of a mobile electronic device (6) of a user (2); a storage device (26, 28), which is designed to store the identifier of the mobile electronic device (6), received by the transmitting and receiving device (14), as belonging to a user (2) present in a public zone (10) when the mobile electronic device (6) is within radio range of the transmitting and receiving device (14) in a public zone (10) from which the user (2) present in the public zone (10) can request access to the restricted access zone (8), wherein the storage device (26, 28) contains a database (34) in which a plurality of user profiles of users (2) who are authorized to access are created, and which contains a further database which is designed to store identifiers of mobile electronic devices (6) currently present in the public zone (10), wherein such a mobile electronic device (6) can be assigned to a user (2) registered or not registered in the access control system (1) and wherein the identifier of a mobile electronic device (6) associated with a registered user (2) is associated with a user profile of the registered user (2) stored in the database (34) of the storage device (26, 28); and an image processing device (16, 22, 24), - which has a camera (16) located at the entrance to the restricted access zone (8); - which is designed to generate, from a camera recording generated by the camera (16), a real-time template for facial features of the user (2) present when the user (2) present requests access to the restricted access zone (8), - which is designed to search the user profiles stored in the database (34) for a reference template that matches the real-time template to a specified degree, wherein a user profile is searched only if it is assigned to a user present based on a received identifier stored in the further database, wherein in the event of a match the system (1) grants the user (2) access and denies access if there is no match.
13. System (1) according to claim 12, in which the image processing device (16, 22, 24) comprises an image processing module (22), which is designed to generate, from the camera recording, the real-time template, and an evaluation module (24), which is connected to the image processing module (22) and the storage device (26, 28), wherein the evaluation module (24) is designed to generate a result signal which indicates whether the real-time template matches this reference template.
14. System (1) according to claim 13, further comprising a processor (20) which is connected to the image processing device (16, 22, 24) and is designed to generate a control signal depending on the result signal to control the access control system (1) such that the user (2) is granted or denied access.