Method for configuring an access control system

The method uses a graphical user interface and a two-dimensional matrix to simplify and clarify the configuration of access control systems by differentiating user and access control unit permissions, reducing errors and enhancing management efficiency.

EP4068229B1Active Publication Date: 2025-11-19ABUS SECURITY CENT
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
EP2022163638
Authority / Receiving Office
EP · EP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2021-03-31
Filing Date
2022-03-22
Publication Date
2025-11-19
Estimated Expiration
2042-03-22

AI Technical Summary

Technical Problem

Existing access control systems become complex and prone to errors as they manage multiple users and access control units with varying permissions, making it difficult to configure and modify authorizations clearly and unambiguously.

Method used

A method using a graphical user interface to configure an access control system by differentiating user and access control unit permissions through multiple attributes, allowing selective visualization and modification of authorizations via a two-dimensional matrix.

Benefits of technology

Simplifies the configuration process, reduces errors, and provides a clear overview of authorization settings, ensuring accurate and efficient management of user permissions across multiple access control units.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure IMGF0001
    Figure IMGF0001
  • Figure IMGF0002
    Figure IMGF0002
  • Figure IMGF0003
    Figure IMGF0003
Patent Text Reader

Abstract

A method for configuring an access control system, where different users have different permissions at different access control units, via a graphical user interface, comprises the following steps: providing a database in which each user is assigned entries with the permissions of the respective user at the various access control units and / or each access control unit is assigned entries with the permissions of the various users at the respective access control unit according to various permission attributes; receiving a selected permission attribute from the various permission attributes via the graphical user interface; filtering the entries according to the selected permission attribute;Visualization of the different authorizations by displaying a two-dimensional matrix on the graphical user interface, wherein the two-dimensional matrix contains respective matrix elements ordered according to the different users on the one hand and the different access control units on the other, wherein the respective matrix element, as a result of filtering, represents the entry which corresponds to the authorization of the respective user at the respective access control unit according to the selected authorization attribute; Receiving a selection command via the graphical user interface, wherein the selection command determines a selection of at least one of the displayed matrix elements; Receiving a change command via the graphical user interface, wherein the change command determines the creation of a new entry or a change to at least one existing entry;and creating or modifying the entry that the selected at least one matrix element represents.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The invention relates to a method for configuring an access control system in which different users have different authorizations at different access control units, via a graphical user interface.

[0002] If, in a location such as a building, which is frequented by many different people (hereinafter referred to as users), certain areas of the location are to be accessible only to certain users, it is advisable to control access to the areas and to grant access to a respective area only to those users who are authorized to do so.

[0003] Access to an area can be easily restricted by an access barrier, which can be designed, for example, as a door with an electrically controlled lock, door handle or door fitting, as a gate, as a turnstile, or in a similar manner. Access control can then be achieved by ensuring that the access barrier can only be passed using a locking medium that opens the barrier. In this respect, such an access barrier, which may include, for example, a locking mechanism, an actuator, and / or an evaluation and control circuit, can generally be described as an access control point. One or more such access control points, which should always be treated uniformly for the sake of clarity or for technical reasons, can constitute an access control unit.The locking medium can be, for example, a classic mechanical key, an RFID or NFC transponder in the form of a key card or key fob, a device designed to transmit a signal via Bluetooth, a code to be entered, a biometric feature, or similar. A user who is authorized to access a specific area through an access barrier and therefore possesses access authorization at the corresponding access control unit can then be granted access by assigning or issuing a suitable locking medium.

[0004] In a location frequented by numerous different users and encompassing many different areas, at least some of which should only be accessible to certain users or groups of users, it would not be practical to issue each user a separate access token for every access control unit to which they have authorization. Not only would a user potentially have to carry a multitude of different access tokens, but changing permissions would also be a considerable undertaking, particularly involving the exchange or reconfiguration of numerous access tokens, potentially affecting many users.

[0005] If multiple access control units exist and numerous users have different permissions at these units (which can be the case in a commercial property, but also in a private home), then using an access control system can be advantageous. This system treats the various users and access control units as a unified system. In particular, such a system allows users to be added and removed, additional access control units to be added and removed, and it can track which access credentials have been issued to which users and which access credential allows access to each unit.

[0006] In particular, such an access control system can also allow the setting or modification of the permissions that a user has at a specific access control unit. This can include not only the traceable documentation within the access control system of who has which permissions and where, but also, and especially, the transmission of this information to the individual access control units. Depending on the design of the access control system, the verification of whether a person is granted access at an access control unit can be carried out centrally, and the result is communicated to the relevant access control unit. With decentralized verification, it can be provided that the permissions configured in the access control system are transferred to, and / or stored in, and / or queried by the respective access control units and / or locking media.

[0007] The complexity of an access control system increases with the number of users and access control units. This is especially true if the system offers a high degree of flexibility in its configuration options. For example, permissions can be set not only for individual users and access control units, but also for groups of users and / or groups of access control units. Furthermore, permissions can extend beyond simply granting general access to a specific user at a particular access control unit. They can also include additional aspects, such as restrictions to a specific access medium, time limitations, and / or supplementary permissions for the user at that specific access control unit, which may not necessarily relate to access itself.

[0008] As the complexity of an access control system increases, configuring it also becomes more complex, making it not only less convenient but also more difficult and, above all, more prone to errors. Since access control systems are generally security-relevant, avoiding errors is particularly important. A clear and unambiguous configuration process is especially helpful in preventing errors.

[0009] US Patent 2015 / 0235497 A1 discloses a method for configuring small locking systems in which keys and locks are assigned to each other using a two-dimensional matrix. Furthermore, US Patent 2016 / 0148449 A1 describes an access system for a vehicle with centralized rights management, access control devices, and portable identification media, whereby authorization changes can be transferred between the access control devices using the identification media. Finally, US Patent 6,449,643 B1 discloses an access control system that also manages alarm acknowledgment authorizations.

[0010] It is an object of the invention to provide a method for configuring an access control system in which different users have different authorizations at different access control units, enabling particularly simple, clear, and unambiguous setting or modification of authorizations. In particular, it should also be possible to configure the access control system selectively with respect to various authorization attributes easily and clearly in order to avoid incorrect entries and to easily identify incorrect settings.

[0011] The problem is solved by a method having the features of claim 1. Advantageous further developments of the invention are evident from the dependent claims, the present description and the figures.

[0012] According to the invention, the access control system is configured via a graphical user interface. This configuration can include, in particular, entering, defining, and modifying permissions that a user may have at each access control unit according to several different permission attributes. The configuration and corresponding visualization can be performed selectively according to one of the various permission attributes.

[0013] In this context, the term "user" refers to one or more persons who are to be treated uniformly at all times, even if this is only implemented at the database level (without mandatory visualization) as an organizational unit. The term "access control unit" refers to one or more access barriers or access control points that are to be treated uniformly at all times. The access control points of an access control unit can be located close to each other or far apart. Combining multiple access barriers or access control points allows for more precise control.Access control points within an access control unit can be particularly useful in large facilities for reasons of clarity or for technical reasons, such as the limited storage space available at each access control point or on each locking medium, which is required for storing the respective authorizations. However, an access control unit can also comprise only a single access control point and be implemented solely as an organizational unit at the database level (without mandatory visualization).

[0014] The aforementioned authorizations can be, in particular, individual authorizations assigned to at least some, and especially all, users and / or at least some, and especially all, access control units as an individual combination. This does not preclude the possibility of defining groups of one or more users and / or groups of one or more access control units at the visualization and / or database level. This allows for the simplification of configuration or, due to technical constraints, the joint granting or revocation of authorizations, or the setting or removal of restrictions on authorizations, to the users or access control units of a respective group. Even in this case, the individual users or access control units of a respective group can be visualized and selected according to the chosen authorization attribute.In some implementations, configuring the access control system with individual authorizations may include defining exceptions to such formed groups, namely by setting (granting or withdrawing) individual authorizations for a user or access control unit of a respective group that differ from the authorizations set jointly for the users or access control units of the group.

[0015] According to the invention, the method comprises at least the steps listed and explained individually below.

[0016] The method according to the invention comprises, as one of its steps, providing a database in which entries with the authorizations of the respective user at the various access control units and / or entries with the authorizations of the various users at the respective access control unit are assigned to each user, wherein the entries are assigned to the respective user or the respective access control unit according to the following different authorization attributes: access authorization of the respective user at the respective access control unit; available locking media of the respective user at the respective access control unit; and time restrictions of the access authorization of the respective user at the respective access control unit.

[0017] In other words, the database contains entries for each user with their respective permissions at the various access control units, according to the aforementioned permission attributes, and / or entries for each access control unit with the permissions of the various users at that access control unit, according to the aforementioned permission attributes. The entries assigned to a particular user can be considered a permission record associated with that user, containing those entries. Similarly, the entries assigned to a particular access control unit can be considered a permission record associated with that access control unit, containing those entries. In both cases, the permissions for the user and the access control unit can be retrieved according to the various permission attributes.

[0018] Information about a user's authorizations at a particular access control unit can therefore be assigned to the respective user and / or access control unit in the database, or at least be considered to be assigned to the respective user and / or access control unit. For example, the respective user can correspond to the primary key for an authorization record containing the individual entries assigned to them, or be uniquely assigned to such a primary key. Alternatively, the respective access control unit can correspond to the primary key for an authorization record containing the individual entries assigned to it, or be uniquely assigned to such a primary key.

[0019] The database contains entries with authorizations assigned to users or access control units. These entries thus contain information about the authorizations of a respective user (i.e., one or more persons treated uniformly) at a respective access control unit (i.e., at one or more access control points treated uniformly). The authorizations that a respective user possesses or can potentially possess at a respective access control unit can be differentiated according to the various authorization attributes that characterize each authorization. According to the invention, entries corresponding to at least three authorization attributes are assigned to each user and / or each access control unit.

[0020] The first of these authorization attributes is the access authorization of the respective user at the respective access control unit, i.e., the general authorization of the respective user to gain access at the respective access control unit (i.e., at one or more uniformly treated access control points). The implementation of this access authorization can consist, in particular, of issuing the respective user at least one access medium with which they can gain access at the respective access control unit, or at least of activating one of the access media in the possession of the respective user so that it can be used to gain access at the respective access control unit.Conversely, the lack of access authorization can be implemented in particular by blocking or confiscating all locking media in the possession of the respective user and by means of which access to the respective access control unit can be gained for this access control unit.

[0021] The second authorization attribute relates to the access media available to the respective user at the respective access control unit. The fact that a particular access medium is available at a particular access control unit does not merely mean that the user possesses the respective access medium, but that they can actually use it to gain access to the respective access control unit. In this respect, this authorization attribute restricts the general access authorization to one or more specific access media that can be used for access. This can, in particular, include a restriction to a specific type of access medium.For example, a user may be generally authorized to access a given access control unit, but only by means of a locking medium of a specific type, such as a particularly secure type, while they may not be authorized to gain access using a locking medium of a different type.

[0022] The restriction to one or more specific locking media can also arise from the type of the respective access control unit, in particular a lock provided on the respective access control unit and operated by means of the locking medium. For example, the respective access control unit may be equipped with a lock that can only be opened using a biometric feature. However, it is conceivable that a lock provided on the respective access control unit could, in principle, be operated by locking media of different types, e.g.which can be activated both by means of a key card and by means of an app, but that in the access control system for one or more respective users the authorization according to the second authorization attribute is restricted to the fact that these users can only actually gain access to the respective access control unit by means of a locking medium of a certain type.

[0023] The third authorization attribute relates to time restrictions on the general access authorization of the respective user at the respective access control unit. A time restriction on access authorization could, for example, mean that the respective user is only authorized to access a particular access control unit on certain days of the week and / or only within specific time periods. If no such time restriction exists, then a respective user's access authorization is valid without time restrictions, i.e., in principle at any time. This does not, of course, preclude the possibility that a user's access authorization can be revoked and / or that the access authorization can be subsequently restricted to a specific time period.

[0024] If a user does not have access authorization at a particular access control unit, the database preferably contains an explicit corresponding entry according to the aforementioned first authorization attribute, which is assigned to the respective user and / or the respective access control unit. However, the lack of access authorization can also be reflected in the database simply by the absence of any authorization entry, or at least no entry regarding access authorization, for the respective user at the respective access control unit.Therefore, the database always shows for each user and each access control unit whether the respective user has authorization for the respective access control unit (namely if a corresponding positive entry exists according to at least the first authorization attribute mentioned above) or not (namely if either a corresponding negative entry exists according to at least the first authorization attribute mentioned above or if no such entry exists for this user for this access control unit).

[0025] In particular, with regard to the third authorization attribute mentioned above, the opposite is preferable, since this authorization attribute restricts the general access authorization: If, for a respective user at a respective access control unit, there is indeed an entry that corresponds to the access authorization of the respective user at the respective access control unit according to the first authorization attribute, but with regard to the third authorization attribute there is no explicit entry, the absence of such an entry can implicitly correspond to an entry which defines that the access authorization is not restricted in time.

[0026] Therefore, the database also allows for the unambiguous determination at any time, with regard to the third authorization attribute, of whether a corresponding restriction of any existing access authorization of the respective user at the respective access control unit exists (namely if a corresponding positive entry according to the third authorization attribute is present) or not (namely if either a corresponding negative entry according to the third authorization attribute is present or no entry exists in this regard).

[0027] Regarding the second authorization attribute, the absence of a corresponding entry can be interpreted either as meaning that there is no restriction to a specific locking medium, or as meaning that no locking medium is provided that would grant the respective user access to the respective access control unit. Preferably, however, if an entry exists for a respective user and a respective locking medium according to the first authorization attribute (access authorization), an entry according to the second authorization attribute (locking medium) is also present, which specifies at least one locking medium by means of which the respective user can gain access to the respective access control unit.

[0028] The entries are not limited to the three authorization attributes mentioned; users or access control units may have further entries with authorizations according to additional authorization attributes. For these additional authorization attributes, particularly if they involve further restrictions on possible access authorization, the same principles apply as explained above for the second and third authorization attributes. However, additional authorization attributes may also relate to authorizations other than access authorization, such as the authorization to arm or disarm an alarm system, as explained below.

[0029] The method according to the invention further comprises, as one of its steps, receiving a selected authorization attribute from among the various authorization attributes via the graphical user interface. In other words, it is possible via the graphical user interface to select a specific authorization attribute from at least some, preferably all, of the authorization attributes according to which entries in the database are assigned to a respective user or access control unit. This selection serves to specify one of the authorization attributes as the authoritative authorization attribute for subsequent process steps, in particular for the subsequent filtering step.Therefore, the aforementioned receiving of a selected authorization attribute can also correspond to receiving a filter command via the graphical user interface, where the filter command determines a selection of one of the various authorization attributes.

[0030] In principle, the present process step can involve receiving not only one, but also several selected authorization attributes, or the filter command can determine a selection of not only one, but also several of the various authorization attributes. Preferably, however, only exactly one authorization attribute can be selected at any given time. This allows, in particular, a simple overview of individual authorizations in the visualization explained below by displaying a two-dimensional matrix.

[0031] The method according to the invention also includes, as one of its steps, filtering the entries according to the selected authorization attribute. This means, in particular, that from the entries in the database containing the authorizations of a respective user at a respective access control unit, those entries are identified, read, and used for the subsequent steps that correspond to the selected authorization attribute. The remaining information, especially the information relating to the other authorization attributes, is not deleted, discarded, or altered in any way by the filtering; rather, the filtering merely results in this remaining information being disregarded or only considered secondarily in the subsequent steps. The filtering step enables a visualization of individual authorizations specific to the selected authorization attribute.

[0032] The method according to the invention further comprises, as one of its steps, visualizing the different authorizations by displaying a two-dimensional matrix on the graphical user interface. This two-dimensional matrix contains respective matrix elements, ordered according to the different users on the one hand and the different access control units on the other. As a result of filtering, each matrix element represents the entry that corresponds to the authorization of the respective user at the respective access control unit according to the selected authorization attribute. As already explained, each access control unit can comprise several access control points or only a single access control point.

[0033] The matrix elements of the two-dimensional matrix can be arranged in rows and columns. In this respect, the matrix can also be viewed as a table with the matrix elements as the table cells. The matrix elements can also be considered matrix fields. Each row of the two-dimensional matrix can correspond to a user, and each column can correspond to an access control unit; or conversely, each row can correspond to an access control unit, and each column to a user. In both cases, each matrix element can be uniquely assigned to a user and an access control unit (i.e., one or more uniformly treated access control points) based on its position (row and column) within the two-dimensional matrix.Furthermore, each matrix element can be uniquely assigned, based on the selected authorization attribute, to the entry with the authorization of that respective user at that respective access control unit, which refers to the selected authorization attribute - provided such an entry exists.

[0034] In some implementations—particularly when user groups or access control unit groups are defined, as explained below—rows and / or columns of the displayed matrix can be selectively collapsed and expanded to switch between different views that correspond to the same selected authorization attribute. Collapsing one or more rows or columns means that the display of the row(s) or column(s) in question is suppressed, which can be indicated graphically (e.g., by highlighting, color, or a warning symbol), resulting in a clearer visualization. Expanding one or more rows or columns means that the original (complete) display of that row(s) or column(s) is restored, resulting in a more detailed visualization.

[0035] The visualization involves each matrix element representing its respective entry. This can mean, in particular, that each matrix element displays information corresponding to the entry, for example, by using symbols or presenting it in a visually easily understandable way. If an entry corresponding to the respective matrix element, according to its position within the two-dimensional matrix and the selected authorization attribute, is not present, this absence can still represent unambiguous information, as explained above, which can also be displayed. Therefore, each matrix element can also represent a missing entry.

[0036] The absence of an entry for an authorization for a particular user at a particular access control unit, according to the respective selected authorization attribute, can be visualized, for example, by a matrix element displayed as an empty field or by a symbol representing the absence of an entry corresponding to the selected authorization attribute. Preferably, the absence of general access authorization (according to the first authorization attribute) is represented by an empty field, while in the case of the absence of a time restriction on access authorization (according to the third authorization attribute), a specific symbol for this is preferably displayed in the respective matrix element.With regard to the locking media (according to the second authorization attribute), preferably each locking medium available at the respective access control unit of the respective user is displayed in the respective matrix element with a character symbolizing the respective available locking medium.

[0037] Visualizing different authorization levels by displaying a two-dimensional matrix with filtered representation of each authorization level as matrix elements allows for a particularly clear overview of the configuration status or settings, making it easy and reliable to identify any incorrect settings compared to the desired configuration. The filtered representation of each authorization level as matrix elements can include displaying only the authorization of the respective user at the respective access control unit according to the selected authorization attribute, or visually highlighting the authorization level according to the selected attribute compared to other authorization attributes.

[0038] The method according to the invention further comprises, as additional steps, receiving a selection command via the graphical user interface, wherein the selection command determines the selection of at least one of the displayed matrix elements; receiving a change command via the graphical user interface, wherein the change command determines the creation of at least one new entry or the modification of at least one existing entry; and creating or modifying the entry represented by the selected at least one matrix element. Whether the respective entry is created or modified depends on whether it already exists or not.

[0039] In other words, the graphical user interface allows you to select one or more matrix elements of the displayed two-dimensional matrix and trigger the creation and / or modification of one or more database entries. The selected matrix elements determine which entries are created or modified, and the modification command specifies the content of these entries. These entries represent the permissions of a specific user at a specific access control unit, according to one of the respective permission attributes. The specific user and access control unit are determined by the selected matrix element, and the respective permission attribute is determined by the selected permission attribute.

[0040] Changing or creating the entry represented by the selected at least one matrix element means, in particular, that the entry is changed or that such an entry is created which contains the authorization of the user corresponding to the selected at least one matrix element at the access control unit corresponding to the selected at least one matrix element, according to the respective selected authorization attribute.

[0041] It is understood that if the selection command determines a selection of several of the displayed matrix elements, i.e., more than one matrix element has been selected, the aforementioned creation or modification of the entry represented by the selected matrix element includes that several entries, namely all those entries that are each represented by one of the selected matrix elements, are modified or created accordingly.

[0042] The creation or modification step is based on the preceding steps of receiving the selection command or the modification command, insofar as, firstly, the received selection command determines the one or more matrix elements and thus—via the connection that each matrix element represents a respective entry (cf. the visualization step)—the one or more entries that are to be created or modified; and secondly, the received modification command determines that and how these respective entries are to be created or modified. The modification command can, in particular, specify the content that the entries are to contain after creation or modification. Preferably, if several matrix elements have been selected, the modification or modification process...The process generates all entries represented by these matrix elements according to the change command, ensuring that these entries subsequently match in content. The change command entered via the graphical user interface when executing the procedure can therefore be applied simultaneously to multiple combinations of a given user with a given access control unit.

[0043] A key feature of the method according to the invention is that authorizations are differentiated with respect to several different authorization attributes, one of which is selected within the process. This selection then forms the basis for the subsequent steps. In particular, the entries containing the authorizations are filtered with regard to the respective selected authorization attribute. The matrix shown is based on this filtering and thus preferably displays only the information corresponding to the respective selected authorization attribute. This significantly simplifies the representation of authorizations, even in a very extensive and complex access control system.

[0044] Above all, selective configuration of the access control system is simplified. This simplification arises primarily from the fact that the creation or modification step (which itself is based on the selection and modification commands received in the preceding steps) is also based on the selected authorization attribute. In this way, the access control system configuration can be focused on a specific authorization attribute, allowing corresponding authorization to be set individually (for a single user at a single access control unit) and essentially independently of the other authorization attributes. Without reducing the complexity of the access control system itself, this approach effectively eliminates some of the complexity involved in its configuration.

[0045] The aforementioned focus of the configuration on a specific authorization attribute does not preclude the possibility that setting or changing an individual authorization with respect to the selected authorization attribute may also result in an adjustment of the authorization with respect to another authorization attribute. For example, setting a user's access medium available at the respective access control unit may automatically grant that user general access authorization at that access control unit, as specifying the available access medium would otherwise be meaningless.

[0046] A further advantage of the method according to the invention, in some embodiments, lies in the limitation to individual authorizations. This advantage arises particularly from the fact that the database can contain entries for each user with the authorizations of the respective user at the various access control units, and / or entries for each access control unit can contain the authorizations of the various users at the respective access control unit. For each individual combination of a respective user with a respective access control unit, the authorizations relating to this individual combination can thus be looked up directly in the database for the respective user and / or directly for the respective access control unit.In particular, it is not necessarily required to resolve any group assignments and hierarchies as well as possible contradictions between authorizations granted at different levels of order, although this is not fundamentally excluded and may be quite expedient due to system requirements, especially for access control units.

[0047] The access control system can also define groups (as explained in more detail below), particularly to display and / or set the permissions of multiple users at a single access control unit and / or of a single user at multiple access control units collectively, i.e., for the same content for all users or access control units. However, this primarily serves to further simplify configuration by allowing multiple entries to be changed or created at once. Preferably, the individual permissions, especially those relating to a single user and, if applicable, those relating to a single access control unit, are ultimately decisive in the access control system.

[0048] In some embodiments, it may also be useful to define groups of users and / or access control units at the database level for easier processing of the authorization records, with some groups comprising only a single user and / or a single access control unit.

[0049] The access control system mentioned in connection with the invention can generally comprise several access control units of the type mentioned, as well as a control unit for controlling the access control units according to the configured settings. The control unit can include a processing unit and the database mentioned for the entries containing the authorizations. The processing unit can be a central processing unit of the access control system (e.g., a central control unit, a personal computer). The processing unit need not be located locally, but can also be hosted in the cloud. The database can be integrated into the processing unit or contained in an electronic storage device that is directly or indirectly connected to the processing unit (e.g., via a network). In particular, at least the database can be hosted in the cloud.It may be provided that not only the control unit but also the individual access control units can access the database. The control unit may also include the aforementioned graphical user interface or be connectable to it. The graphical user interface may be part of the processing unit or it may be a separate unit that can be connected to the processing unit directly or indirectly. In particular, the graphical user interface may be an electronic visual interface, such as a computer monitor whose image content is directly controlled by the processing unit, or the screen of a computer separate from the processing unit, including, in particular, a tablet or smartphone that has its own operating system and communicates with the processing unit.The content of the graphical user interface can be generated by software running on the computer, which receives the necessary data from the processing unit. The graphical user interface can provide an input method, for example, by using a touch-sensitive monitor or by allowing graphical elements to be selected using an electronic pointer (cursor, moved and operated by a computer mouse).

[0050] According to an advantageous embodiment of the method, it is further provided that the various authorization attributes, according to which entries are assigned to the users and / or access control units in the database, additionally include an alarm switching authorization of the respective user at the respective access control unit, i.e. the authorization of the respective user to arm and / or disarm an alarm system at the respective access control unit.

[0051] The authorization attribute for alarm activation does not necessarily correspond to the authorization attribute for access authorization or the authorization attribute for possible locking media. This is because alarm activation authorization may refer to an alarm system to which some access barriers (e.g., door locks) are assigned, but not necessarily all access barriers for which the user has access authorization. Depending on the design of the access control system and the alarm system, there may also be access barriers installed that technically do not allow the arming and / or disarming of the alarm system at all; this can therefore be configured individually.The additional authorization attribute of the alarm switching authorization allows the authorization to arm and / or disarm the alarm system to be selectively granted and visualized for a respective user on those access control units that are assigned to the alarm system and that are also technically usable or intended to be used for this purpose.

[0052] The alarm system can be integrated into the access control system or linked to the access control system to form a combined access control and alarm system. This can include the following: provided the relevant authorization exists according to the corresponding authorization attribute, opening a door or other access barrier of a respective access control unit simultaneously disarms the alarm system, and / or conversely, locking the door or barrier simultaneously arms the alarm system. The alarm system can also be configured to check the arming capability and, if necessary, confirm it to the access control system.

[0053] Providing alarm switching authorization or any other additional authorization attribute advantageously expands the configuration options and thus the flexibility of the access control system, but does not affect the fundamental process of the method according to the invention. While it is then possible, in the step of receiving a selected authorization attribute, to choose not only from the three aforementioned authorization attributes, but also, if necessary, from further authorization attributes, the steps of filtering, visualizing, and creating or modifying the selected authorization attribute are executed accordingly, regardless of whether the selected authorization attribute is one of the three aforementioned authorization attributes or one of potentially further authorization attributes, such as the aforementioned alarm switching authorization.

[0054] If a user at a particular access control unit does not have authorization to activate the alarm system, this can be configured in the access control system either through an explicit entry or by the absence of an entry related to this authorization attribute in the database. The existence of alarm activation authorization for a user at a particular access control unit is preferably configured through an explicit entry in the database, in which case several scenarios can be distinguished. For example, alarm activation authorization can be limited to arming the alarm system, to disarming the alarm system, or it can include both. Furthermore, the alarm system can comprise various subsystems, which, for example,Different spatial areas are monitored, and the alarm switching authorization can then either be restricted to one or more of the subsystems or be unrestricted in this respect.

[0055] For each of these cases, the entry, according to the further authorization attribute of an alarm switching authorization, can contain corresponding content that is uniquely assignable to the respective case. When visualizing the different authorizations, the various cases can also be distinguished by the fact that the matrix elements, provided the selected authorization attribute is the alarm switching authorization, represent the corresponding entry of the respective user at the respective access control unit in different ways for the different cases, e.g., through different symbols.

[0056] In some embodiments, at least some users in the database can be assigned group membership information about their membership in one, in particular at most one, of one or more user groups, wherein those entries in the database that correspond to an authorization of the users belonging to the respective user group at a respective access control unit can only be created or changed uniformly with respect to at least one of the aforementioned different authorization attributes.In other embodiments, at least some access control units in the database can be assigned group membership information about their membership in one, in particular at most one, of one or more access control unit groups, wherein those entries in the database that correspond to a user's authorization to the access control units belonging to the respective access control unit group can only be created or changed uniformly with respect to at least one of the aforementioned different authorization attributes.

[0057] In this embodiment, group memberships can be predefined, particularly due to technical limitations or to reduce the complexity of the access control system and its configuration. For example, depending on the design of the access control system, authorizations may be stored on the access media, which, however, have a limited storage capacity that is insufficient for large buildings. In such cases, user groups or access control unit groups can be created, particularly in an upstream step, so that the membership in specific user groups or access control unit groups is stored in the database. These memberships (together with the different authorizations or the two-dimensional matrix) can be visualized in the graphical user interface.Membership in a user group means that, via the graphical user interface, the authorization of the various users within that user group can only be set uniformly for each access control unit, specifically (depending on the implementation) for one, several, or all of the various authorization attributes. Similarly, membership in an access control unit group means that, via the graphical user interface, a user's authorization for the various access control units within that group can only be set uniformly, specifically (depending on the implementation) for one, several, or all of the various authorization attributes.

[0058] According to a further advantageous embodiment of the method, it is further provided that the database contains group membership information for at least some users, in particular for each user, indicating their possible membership in one, and in particular at most one, of one or more user groups, and that each user group is assigned entries with the respective user group's authorizations at the various access control units according to the aforementioned various authorization attributes. In other words, in this embodiment, the database records for each user whether or not they belong to a user group. The absence of such an entry can also be considered group membership information, namely, group membership information indicating that the respective user does not belong to any user group.

[0059] Preferably, each user can belong to only one user group. If multiple user groups are provided, they are preferably disjoint. Since user groups primarily serve to allow multiple users to be processed together, each user group preferably contains several users. However, a user group can also, in principle, contain only a single user.

[0060] Similar to users, each user group in the database can also be assigned permissions for the various access control units according to their respective user group and various authorization attributes. However, these permissions are only virtual in that the access rights of a given user to a specific access control unit are not determined by the permissions of the user group to which the user may belong, but rather by the individual permissions of the respective user at that specific access control unit. In particular, the permissions of a given user at a specific access control unit may differ from the permissions of the user group to which the respective user may belong at that access control unit.The permissions assigned to a particular user group in the database therefore have no immediate real-world impact.

[0061] In the present embodiment, the two-dimensional matrix is ​​further provided to contain additional matrix elements, ordered according to the respective user group on the one hand and the various access control units on the other. Each additional matrix element, as a result of filtering, represents the entry that corresponds to the authorization of the respective user group at the respective access control unit according to the selected authorization attribute. Thus, the user groups are treated similarly to individual users during visualization. If a respective column or row of the matrix corresponds to a respective user, the additional matrix elements can form additional columns or rows of the matrix that correspond to a respective user group. A column or row corresponding to a respective user group can, in particular, be adjacent to the columns or rows of the user group.The rows should be arranged according to the users belonging to the respective user group.

[0062] Since the matrix in this embodiment includes the additional matrix elements, in the step of receiving a selection command, the matrix elements shown, from which at least one is selected, include not only the aforementioned matrix elements (representing a respective entry with the authorizations of a respective user at a respective access control unit according to the selected authorization attribute) but also the additional matrix elements (representing a respective entry with the authorizations of a respective user group at a respective access control unit according to the selected authorization attribute).

[0063] In the present embodiment, it is further provided that, in the step of creating or modifying the entry represented by the selected at least one matrix element, in those cases where the selected at least one matrix element is one of the additional matrix elements, all such entries are additionally created or modified that correspond to an authorization of the users belonging to the respective user group at the respective access control unit according to the selected authorization attribute. In these cases, therefore, on the one hand, the entries assigned to the respective user group are modified or created (which essentially serves to record and, if necessary, display the virtual authorizations of the user group, but has no direct real effect), and on the other hand, the entries of each user belonging to the respective user group are also modified or modified.generated in a manner that corresponds to the content (which then has real effects as individual permissions of a respective user at a respective access control unit).

[0064] In other words, the graphical user interface offers a way to treat all entries corresponding to the authorization of a user group at a specific access control unit, according to the selected authorization attribute, as if the matrix elements representing these entries had been selected and the change command entered. This is achieved by selecting at least one of the additional matrix elements—that is, a matrix element representing an entry corresponding to the authorization of a user group at a specific access control unit according to the selected authorization attribute—and entering a change command. Therefore, the change or creation does not need to be triggered individually for each user belonging to a specific user group, but can be performed for all users at once.The entries can be generated simultaneously or sequentially, but in any case, they are triggered together.

[0065] The aforementioned additional matrix elements serve as shortcuts for systematically selecting multiple matrix elements related to different individual users and for collaboratively modifying or creating all entries represented by these multiple matrix elements. Each of these collaboratively modified or created entries, corresponding to the authorization of an individual user, can subsequently be further modified individually, thus potentially differing from the entries of other users belonging to the same user group. Such a deviation of an entry assigned to a specific user from the corresponding entry assigned to the user group to which that user belongs can be highlighted in the matrix display by a special indicator.This can further contribute to a better overview and thus at least indirectly support the configuration of the access control system.

[0066] According to a further advantageous embodiment of the method, it is (alternatively or additionally) further provided that the database contains group membership information for at least some access control units, in particular for each access control unit, indicating a possible membership in one, in particular at most one, of one or more access control unit groups, and that each access control unit group contains entries with authorizations of the various users at the respective access control unit group according to the aforementioned various authorization attributes. In other words, in this embodiment, the database records for each access control unit (i.e., for one or more uniformly treated access control points) whether it belongs to an access control unit group or not.The absence of a corresponding entry can also be considered group membership information, namely group membership information indicating that the respective access control unit does not belong to any access control unit group.

[0067] Preferably, each access control unit can belong to at most one access control unit group. If multiple access control unit groups are provided, they are therefore preferably disjoint. Since access control unit groups primarily serve to allow several access control units to be handled jointly, each access control unit group preferably contains several access control units. In principle, however, each access control unit group can also comprise only a single access control unit. Nevertheless, assigning access control units to access control unit groups can be useful and advantageous for technical reasons.

[0068] Similar to access control units, the database can also assign permissions to each access control unit group for different users, based on various permission attributes. However, these permissions are only virtual in that the access rights of a particular user to a specific access control unit are not determined by the permissions of the access control unit group to which the unit may belong, but rather by the individual permissions of that user at that specific access control unit. In particular, the permissions of a particular user at that specific access control unit may differ from the permissions of that user at the access control unit group to which the unit may belong.The authorizations assigned in the database of a respective access control unit group therefore do not necessarily have any immediate real-world effects.

[0069] In the present embodiment, the two-dimensional matrix is ​​further provided to contain additional matrix elements, ordered according to the various users on the one hand and the respective access control unit group on the other. Each additional matrix element, as a result of filtering, represents the entry that corresponds to the authorization of the respective user for the respective access control unit group according to the selected authorization attribute. Thus, the access control unit groups are treated similarly to individual access control units during visualization. If a respective column or row of the matrix corresponds to a respective access control unit, the additional matrix elements can form additional columns or rows of the matrix that correspond to a respective access control unit group. A column or row corresponding to a respective access control unit group...The row can be arranged particularly adjacent to the columns or rows that correspond to the access control units belonging to the respective access control unit group.

[0070] Since the matrix in this embodiment contains the additional matrix elements, in the step of receiving a selection command, the matrix elements shown, from which at least one is selected, include, in addition to the aforementioned matrix elements (representing a respective entry with the authorizations of a respective user at a respective access control unit according to the selected authorization attribute), the additional matrix elements (representing a respective entry with the authorizations of a respective user at a respective access control unit group according to the selected authorization attribute).

[0071] In the present embodiment, it is further provided that in the step of creating or modifying the entry represented by the selected at least one matrix element, in those cases where the selected at least one matrix element is one of the additional matrix elements, all such entries are additionally created or modified that correspond to an authorization of a respective user for the access control units belonging to the respective access control unit group according to the selected authorization attribute. In these cases, therefore, the entries assigned to the respective access control unit group are modified or modified.generated (which essentially serves to record and, if necessary, display the virtual authorizations of the access control unit group, but has no immediate real effect) and, on the other hand, also changes or creates the entries for each access control unit belonging to the respective access control unit group in a corresponding manner (which then has real effects as individual authorizations of a respective user at a respective access control unit).

[0072] In other words, the graphical user interface offers a way to treat all entries corresponding to a user's authorization at a particular access control unit group, according to the selected authorization attribute, as if the matrix elements representing these entries had been selected and the change command entered, by selecting at least one of the additional matrix elements—that is, a matrix element representing an entry corresponding to a user's authorization at a particular access control unit group according to the selected authorization attribute—and entering a change command. The modification or...Therefore, it is advantageous that the creation process does not need to be triggered individually for each access control unit belonging to a given access control unit group, but can be carried out for all access control units at once. The modification or creation of entries can be performed simultaneously or sequentially, but is always triggered together.

[0073] The aforementioned additional matrix elements serve as shortcuts for systematically selecting multiple matrix elements related to different individual access control units and for jointly modifying or creating all entries represented by these multiple matrix elements. Each of these jointly modified or created entries, corresponding to an authorization at a single access control unit, can subsequently be modified individually, and thus also deviating from the entries of the other access control units belonging to the respective access control unit group.Such a discrepancy between an entry assigned to a specific access control unit and the corresponding entry assigned to the respective access control unit group to which that unit belongs can be highlighted in the matrix display by a special indicator. This can further improve clarity and thus, at least indirectly, also support the configuration of the access control system.

[0074] If, according to a combination of the two preceding embodiments, both user groups and access control unit groups are provided, the additional matrix elements can be conceptually distinguished as first group matrix elements, each representing an entry corresponding to the authorization of the respective user group at the respective access control unit according to the selected authorization attribute, and second group matrix elements, each representing an entry corresponding to the authorization of the respective user at the respective access control unit group according to the selected authorization attribute.Furthermore, the two-dimensional matrix, ordered according to the different user groups on the one hand and the different access control unit groups on the other, can also contain combined group matrix elements that refer to both a specific user group and a specific access control unit group. As a result of the filtering, each combined group matrix element represents the entry that corresponds to the authorization of the respective user group for the respective access control unit group according to the selected authorization attribute.In the step of creating or changing the entry that the selected at least one matrix element represents, in those cases where the selected at least one matrix element is one of the combined group matrix elements, all such entries are additionally created or changed that correspond to an authorization of a user belonging to the respective user group at an access control unit belonging to the respective access control unit group according to the selected authorization attribute.

[0075] If, as explained above, additional matrix elements for user groups and / or access control unit groups are provided and displayed, some embodiments may allow rows and / or columns of the displayed matrix to be selectively collapsed and expanded following a corresponding command (e.g., via a graphical user interface). In particular, it may be possible to selectively collapse and expand those rows and / or columns corresponding to the users of the respective user group. Similarly, it may be possible to selectively collapse and expand those rows and / or columns corresponding to the access control units of the respective access control unit group. This allows a user to switch between a detailed display and a particularly clear display.

[0076] The invention further relates to a computer program product comprising commands which, when executed by a computer, cause the computer to execute the described method for configuring an access control system.

[0077] The invention also relates to a control unit for controlling access control units of an access control system, wherein the control unit comprises a computing unit and a database for entries with authorizations, and wherein the control unit includes a graphical user interface or is connectable to a graphical user interface. The computing unit is configured to execute the described method for configuring the access control system in conjunction with the database and the graphical user interface.

[0078] The invention will be further explained below by way of example only, with reference to the figures. Fig. 1 schematically illustrates the process of the method according to the invention. Fig. 2 shows a matrix for visualizing individual authorizations according to a first embodiment of the method according to the invention, wherein a first authorization attribute is selected. Fig. 3 shows a matrix for visualizing individual authorizations according to the first embodiment of the method according to the invention, wherein a second authorization attribute is selected. Fig. 4 shows a matrix for visualizing individual authorizations according to the first embodiment of the method according to the invention, wherein a third authorization attribute is selected. Fig. 5 shows a matrix for visualizing individual authorizations according to the first embodiment of the method according to the invention, wherein a fourth authorization attribute is selected.Figure 6 shows the representation of a matrix for visualizing individual authorizations according to a third embodiment of the method according to the invention, wherein a first authorization attribute is selected.

[0079] The Fig. 1 The sequence of the individual steps of the method according to the invention is illustrated by individual blocks, which are connected by arrows according to the sequence of the method. Block 11 represents the process step of providing a database. Block 13 represents the process step of receiving a selected authorization attribute via the graphical user interface 15, which is located in Fig. 1 This is symbolized by an elongated vertical block arranged laterally to the blocks containing the process steps. The fact that the selected authorization attribute is received from the graphical user interface 15 in block 13 is symbolized by an arrow with a dashed line pointing from user interface 15 to block 13.

[0080] Block 17 represents the process step of filtering the entries. Block 19 represents the process step of visualizing the different authorizations by displaying a two-dimensional matrix on the graphical user interface 15. The fact that the graphical user interface 15 is thus affected in this step is symbolized by an arrow with a dashed line from block 19 to the user interface 15.

[0081] Block 21 represents the process step of receiving a selection command, and block 23 represents the process step of receiving a change command. Both the selection command and the change command are received via the graphical user interface 15, which is symbolized by a dashed arrow pointing from the user interface 15 to the respective block 21 or 23.

[0082] Finally, block 25 represents the process step of creating or modifying the entry that the selected matrix element represents. Creating or modifying this entry configures the access control system. The configuration can then generally be considered complete. If further entries are to be created or modified during the configuration process, the procedure can be repeated. Subsequent iterations of the procedure preferably begin either at block 13 (the process step of receiving a selected authorization attribute) or, if the previously selected authorization attribute is to be retained, at block 21 (the process step of receiving a selection command), each symbolized by a dotted-line arrow.

[0083] In Fig. 2 Figure 15 shows, by way of example and in simplified form, a possible content displayed on the graphical user interface 15 during the execution of the method according to a first embodiment. This content includes, in particular, a matrix 27, which is displayed in the process step of visualizing the different authorizations (block 19 in Figure 15). Fig. 1 ) is represented. Matrix 27 contains a large number of matrix elements 29, of which only a few are marked with their own reference symbol for better clarity.

[0084] The matrix elements 29 are arranged in rows and columns, with each column corresponding to one of the various users U1-U9 of the access control system (i.e., one or more uniformly treated persons) and each row corresponding to one of the various access control units D1-D9 (i.e., one or more uniformly treated access control points) of the access control system. Thus, each matrix element 29 can be assigned to both a respective user Ux and a respective access control unit Dx.

[0085] The graphical user interface 15 also includes a selection input field 31, via which one of several different authorization attributes 33, for example four, can be selected. Fig. 2 The first of these four authorization attributes 33 is selected, which is indicated by a selection frame in the form of an additional border around the selected authorization attribute 33. This first authorization attribute is the access authorization of the respective user U. x at the respective access control unit Dx. As a result of selecting the authorization attribute 33', the database containing the entries with the authorizations of the various users U1-U9 at the various access control units D1-D9 is filtered according to the selected authorization attribute 33', so that for each combination of a respective user U x and a respective access control unit D x the access authorization of the respective user U x at the respective access control unit D x is read out and displayed in the matrix.

[0086] Each matrix element 29, according to its position (row and column) within matrix 27, represents the entry which corresponds to the access authorization of the respective user U corresponding to the position (column). x at the respective access control unit D corresponding to the position (row) x This corresponds to the following: The presence of access authorization is symbolized by an X in the example shown, whereas the absence of access authorization is symbolized by an empty field. The further entries in the database containing the permissions of a respective user U x at a respective access control unit D x According to each of the three other, unselected authorization attributes 33, the results are not displayed due to the filtering by the selected authorization attribute 33'.

[0087] The Fig. 3 , 4 and 5 correspond to Fig. 2 each largely, but with the difference that a different authorization attribute 33 is selected in each case (see the respective position of the selection frame).

[0088] In Fig. 3 The second authorization attribute 33 is selected, according to which the access control unit D is activated. x available locking media of a respective user U x are defined. In the example shown, there are a total of three different types of locking media: a locking medium in the form of a key fob, a locking medium in the form of a key card, and a locking medium in the form of an app that runs on a smartphone, which is connected to the respective access control unit D, for example, via Bluetooth. xcan communicate. As a result of the filtering according to the selected authorization attribute 33', symbols of all those locking media corresponding to the access control unit D of the respective matrix element 29 are displayed in all matrix elements 29. x can be used by the user Ux corresponding to the respective matrix element 29 to gain access.

[0089] Basically, for each combination of a respective user U x with a respective access control unit D x The available locking media can be arbitrarily determined. However, it is also possible that a respective access control unit D x e.g., for technical reasons, only by means of a specific locking medium, in Fig. 3 For example, access to the D2 access control unit can only be granted using a key card. This can be taken into account in the display on the graphical user interface 15 and in the interaction with the graphical user interface 15 by storing the corresponding information in the database as a mandatory condition.

[0090] In Fig. 4 The third authorization attribute 33 is selected, according to which the general access authorization (according to the first authorization attribute 33) of a respective user U is determined. x at a respective access control unit D x a time restriction may apply. In the example shown, an entry indicating that no time restriction exists is symbolized by an infinity symbol, which is located at the respective user Ux and access control unit D. xThe corresponding matrix element 29 is displayed.

[0091] The existence of a time restriction can be indicated in a given matrix element 29 either by a specific symbol or by a particularly abbreviated and / or easily understandable coded indication of the time periods to which access authorization is restricted. Fig. 4 A two-line entry is used in each case, with the first line specifying the days of the week as numbers to which access is restricted, and the second line specifying the time period on those days of the week during which access is restricted. The example shown provides only a rough overview. The way in which the time periods are specified can be more detailed. Furthermore, it can be provided that additional information can be retrieved from the graphical user interface 15 for each matrix element 29, in particular a complete list of potentially several precisely specified time periods to which the respective access is restricted.

[0092] In Fig. 5 The fourth authorization attribute, 33, is selected, which is an alarm switching authorization, according to which a respective user U xat a respective access control unit D x The user has the authorization to activate an alarm system, particularly one integrated into or linked to the access control system. If such alarm activation authorization exists, it may include the authorization to arm the alarm system, symbolized by a closed padlock, and / or the authorization to disarm the alarm system, symbolized by an open padlock. Depending on whether a particular user has U x at a respective access control unit D x; If the user has none, one, the other or both of the alarm switching authorizations, the corresponding matrix element 29 displays an empty field, the closed padlock, the open padlock or both padlocks.

[0093] In the Fig. 5 In the example shown, matrix elements 29, corresponding to access control units D4 and D9, are shown hatched. Such highlighting can serve to identify access control units D4 and D9. x to indicate where, regardless of granted permissions, switching the alarm system is not possible at all, e.g. for technical reasons.

[0094] Regardless of which authorization attribute 33 is selected, one or more matrix elements 29 can be selected via the graphical user interface within matrix 27. This corresponds to the process step of receiving a selection command, whereupon, for example, an input window may open or another input option may be offered to enter a desired access authorization. This corresponds to the process step of receiving the change command. Subsequently, for example, triggered by pressing a corresponding confirmation button, changes can be made for those combinations of a respective user U. x with a respective access control unit D xEntries corresponding to the selected authorization attribute are created or existing entries are modified accordingly, which corresponds to the process step of creating or modifying entries. Thus, the method according to the invention enables a particularly simple and clear setting of authorizations.

[0095] In the Fig. 2 bis 5 Users U8 and U9 are identified by a bracket as belonging to user group UG1, and access control units D7-D9 are identified by another bracket as belonging to access control unit group DG1. However, in this embodiment, the group memberships have no direct effect. In particular, the permissions of each user U x at a respective access control unit D xindependent of any possible group affiliation, and can also be configured essentially completely individually regardless of that.

[0096] In a second embodiment, however, group memberships can be predefined or predetermined at the database level, particularly due to technical limitations or to reduce the complexity of the access control system and its configuration. For example, it may be possible to store authorizations on the locking media, which, however, have only a limited storage capacity that is insufficient for large buildings.

[0097] In such cases, user groups UG1 or access control unit groups DG1 are created, which can occur at a deeper level of configuration (not shown) or in a preceding step, so that membership in specific user groups UG1 or access control unit groups DG1 can be stored in the database as a mandatory condition. These memberships can thus be visualized as predefined group memberships on the graphical user interface 15, for example, by the elements shown in the Fig. 2 bis 5 The brackets shown, or by a border around several rows or columns, indicate group memberships. Such group memberships result in the authorization of the various users being displayed on the graphical user interface 15. x A user group UG1 can only be configured uniformly at a respective access control unit Dx, or the authorization of a user U xat the various access control units D x The access control unit group DG1 can only be set uniformly. This uniform setting can refer to a single authorization attribute, several authorization attributes, or all of the aforementioned authorization attributes 33. If a matrix element 29 is selected within matrix 27 via the graphical user interface and, as explained above, a desired access authorization or a change command is entered and confirmed, the entries of the entire user group UG1 or access control unit group DG1 are set or changed uniformly, and this setting can subsequently only be changed uniformly. The uniformly set entries are visualized accordingly in the graphical user interface 15, as shown, for example, in Fig. 2 and in Fig. 4 As shown. In this embodiment, it is preferred if either only user groups UG1 or only access control unit groups DG1 are specified or can be specified in order to avoid contradictions.

[0098] One way to use group memberships at the visualization level to further simplify the configuration of the access control system is described in Fig. 6 This illustrates an exemplary third embodiment of the method according to the invention. In this embodiment, the matrix 27 shown in the visualization step has additional matrix elements 35 (of which not all, but only some, are marked with their own reference numeral), namely the matrix elements 35 of an additional column corresponding to the user group UG1, and the matrix elements 35 of an additional row corresponding to the access control unit group DG1 (see the respective column heading UG1 and row heading DG1). Otherwise, the representation corresponds to that of the Fig. 2 , especially in Fig. 6 The first authorization attribute 33 is also selected, which determines the access authorization of a respective user U. x at a respective access control unit D x indicates.

[0099] However, in the Fig. 6 The illustrated third embodiment not only benefits every user U x or each access control unit D x such access authorizations are assigned not only to the user group UG1 but also to the access control unit group DG1. The presence or absence of an access authorization for user group UG1 at a respective access control unit D x or of a respective user U x At the access control unit group DG1, the respective additional matrix element 35 is displayed in the same way as the other matrix elements 29, namely by an X or by an empty field. However, an authorization assigned to a group UG1, DG1 has no direct effect on whether a user U belonging to group UG1 x at a respective access control unit D x or a respective user Ux at an access control unit D belonging to group DG1 xThis authorization is granted because only individual authorizations are relevant.

[0100] However, the additional matrix elements 35 offer the advantage that they can be used to jointly modify or create entries for all users belonging to group UG1. x or all access control units Dx belonging to group DG1. Selecting one of the additional matrix elements 35 in column UG1 and subsequently entering a change command advantageously leads not only to changing or creating the corresponding entry assigned to group UG1, but also to a corresponding change or creation of all those entries that relate to the authorization (according to the selected authorization attribute) of the users U belonging to group UG1. x at the respective access control unit D x refer (in Fig. 6 This is the row section, or these are the two matrix elements 29 to the right of the relevant additional matrix element 35). Similarly, selecting one of the additional matrix elements 35 of row DG1 and subsequently entering a change command advantageously leads not only to changing or creating the corresponding entry assigned to group DG1, but also to a corresponding change or creation of all those entries that relate to the authorization (according to the selected authorization attribute) of the respective user U. x at the access control units belonging to group DG1 D x refer (in Fig. 6 This is the column section, or these are the three matrix elements 29 below the relevant additional matrix element 35). Thus, permissions of multiple users U x at a respective access control unit D x or permissions of a respective user Ux at several access control units D x They can be changed or set particularly conveniently.

[0101] Through the additional matrix element 35, where the additional column for user group UG1 and the additional row for access control unit group DG1 intersect, even all entries belonging to the authorization of a user U belonging to user group UG1 can be viewed. x at one of the access control unit groups DG1 belonging to access control unit D x according to the selected authorization attribute, they can be changed or created all at once.

[0102] Another advantage of the additional matrix elements 35 is that the permissions displayed on these matrix elements 35, assigned to a respective group, serve as a kind of basic permission setting for the users U belonging to the respective group. x or access control units D xThese can be considered even if the actual relevant individual entitlements may deviate from this requirement. Examples of such deviations are provided in Fig. 6 This represents matrix element 29 corresponding to user U4 and access control unit D7, as well as matrix element 29 corresponding to user U9 and access control unit D2. It may be provided that such matrix elements 29, which contain an entry with an individual authorization for a respective user U, x at a respective access control unit D x represent which of a permission requirement for a group UG1, DG1, which of these users U x or this access control unit D x Any deviation from the above will be marked as an exception in the representation of matrix 27. In the case of the Fig. 6 In the example shown, this marking is achieved by hatching the respective matrix element 29. However, the marking could also be achieved through color highlighting and / or an additional symbol, such as a red dot or the symbol of a warning triangle, or similar. Displaying the group permissions and highlighting the differing individual permissions further contributes to an improved overview of the permissions set in the access control system and thus also to an improvement in the configuration of the access control system.

[0103] To illustrate the third embodiment, which also includes user groups UG1 and access control unit groups DG1, only the Fig. 6 shown, in which the first of the four authorization attributes 33, symbolized by an X, namely the access authorization of a respective user U xat a respective access control unit D x , is selected. Of course, in this embodiment, one of the other authorization attributes 33 can also be selected via the selection input field 31 of the graphical user interface 15. The matrix 27 would then largely correspond to the one in Fig. 3 , 4 or 5 shown matrix 27, however with the difference that it contains the additional matrix elements 35 for the authorizations of the user groups UG1 or access control unit groups DG1 according to the respective selected authorization attribute 33'.

[0104] Furthermore, the third embodiment according to Fig. 6 It should be noted that a switching function may also be provided to choose between a detailed display mode according to Fig. 6 and to be able to switch to a more concise display (not shown). For this purpose, the columns belonging to a user group and / or the rows belonging to an access control unit group can be optionally collapsed or expanded. In the example shown, collapsing the columns means that the columns corresponding to users U8 and U9 are no longer displayed (only the additional column corresponding to user group UG1 is shown), and that the rows corresponding to access control units D7 to D9 are no longer displayed (only the additional row corresponding to access control unit group DG1 is shown). Bezugszeichen

[0105] 11. Procedure step of providing a database 13. Procedure step of receiving a selected authorization attribute 15. Graphical user interface 17. Procedure step of filtering the entries 19. Procedure step of visualizing the different authorizations 21. Procedure step of receiving a selection command 23. Procedure step of receiving a change command 25. Procedure step of creating or changing an entry 27. Matrix 29. Matrix element 31. Selection input field 33. Authorization attribute 33. Selected authorization attribute 35. Additional matrix element D1-D9: Access control unit DG1: Access control unit group U1-U9: User UG1: User group

Claims

1. A method of configuring an access control system, in which different users (Ux) have different authorizations at different access control units (Dx) in accordance with a plurality of authorization attributes (33), via a graphical user interface (15), comprising the steps: - providing a database in which each user (Ux) is assigned entries with the authorizations of the respective user (Ux) at the different access control units (Dx) and / or each access control unit (Dx) is assigned entries with the authorizations of the different users (Ux) at the respective access control unit (Dx) in accordance with the following different authorization attributes (33): -- access authorization of the respective user (Ux) at the respective access control unit (Dx); -- available locking media of the respective user (Ux) at the respective access control unit (Dx); and -- time restrictions of the access authorization of the respective user (Ux) at the respective access control unit (Dx); - receiving a selected authorization attribute (33') of the different authorization attributes (33) via the graphical user interface (15); - filtering the entries according to the selected authorization attribute (33'); - visualizing the different authorizations by displaying a two-dimensional matrix (27) at the graphical user interface (15), wherein the two-dimensional matrix (27) contains respective matrix elements (29) arranged according to the different users (Ux), on the one hand, and the different access control units (Dx), on the other hand, wherein, as a result of the filtering, the respective matrix element (29) represents that entry which corresponds to the authorization of the respective user (Ux) at the respective access control unit (Dx) in accordance with the selected authorization attribute (33'); - receiving a selection command via the graphical user interface (15), wherein the selection command determines a selection of at least one of the displayed matrix elements (29); - receiving a modification command via the graphical user interface (15), wherein the modification command determines a creation of at least one new entry or a modification of at least one existing entry; and - creating or modifying that entry which is represented by the selected at least one matrix element (29).

2. A method according to claim 1, wherein the different authorization attributes (33), according to which the users (Ux) and / or access control units (Dx) are assigned entries in the database, additionally comprise: - an alarm controlling authorization of the respective user (Ux) at the respective access control unit (Dx).

3. A method according to claim 1 or 2, wherein, in the database, at least some users (Ux) are assigned group affiliation information about an affiliation to one, in particular at most one, of one or more user groups (UG1), wherein the entries that correspond to an authorization of the users (Ux) belonging to the respective user group (UG1) at a respective access control unit (Dx) can only be uniformly created or modified with respect to at least one of said different authorization attributes (33).

4. A method according to claim 1 or 2, wherein, in the database, at least some access control units (Dx) are assigned group affiliation information about an affiliation to one, in particular at most one, of one or more access control unit groups (DG1), wherein the entries that correspond to an authorization of a user (Ux) at the access control units (Dx) belonging to the respective access control unit group (DG1) can only be uniformly created or modified with respect to at least one of said different authorization attributes (33).

5. A method according to claim 1 or 2, wherein, in the database, furthermore at least some users (Ux) are assigned group affiliation information about a possible affiliation to one, in particular at most one, of one or more user groups (UG1) and each user group (UG1) is assigned entries with authorizations of the respective user group (UG1) at the different access control units (Dx) in accordance with said different authorization attributes (33), wherein the two-dimensional matrix (27) contains additional matrix elements (35) arranged according to the respective user group (UG1), on the one hand, and the different access control units (Dx), on the other hand, wherein, as a result of the filtering, the respective additional matrix element (29) represents that entry which corresponds to the authorization of the respective user (UG1) at the respective access control unit (Dx) in accordance with the selected authorization attribute (33'), and wherein, in the step of creating or modifying that entry which is represented by the selected at least one matrix element (29 or 35), in those cases in which the selected at least one matrix element (29 or 35) is one of the additional matrix elements (35), all those entries are additionally created or modified which correspond to an authorization of the users (Ux) belonging to the respective user group (UG1) at the respective access control unit (Dx) in accordance with the selected authorization attribute (33').

6. A method according to any one of the preceding claims, wherein, in the database, furthermore at least some access control units (Dx) are assigned group affiliation information about a possible affiliation to one, in particular at most one, of one or more access control unit groups (DG1) and each access control point group (DG1) is assigned entries with the authorizations of the different users (Ux) at the respective access control unit group (DG1) in accordance with said different authorization attributes (33), wherein the two-dimensional matrix (27) contains additional matrix elements (35) arranged according to the different users (Ux), on the one hand, and the respective access control unit group (DG1), on the other hand, wherein, as a result of the filtering, the respective additional matrix element (35) represents that entry which corresponds to the authorization of the respective user (Ux) at the respective access control unit group (DG1) in accordance with the selected authorization attribute (33'), and wherein, in the step of creating or modifying that entry which is represented by the selected at least one matrix element (29 or 35), in those cases in which the selected at least one matrix element (29 or 35) is one of the additional matrix elements (35), all those entries are additionally created or modified that correspond to an authorization of the respective user (Ux) at the access control units (Dx) belonging to the respective access control unit group (DG1) in accordance with the selected authorization attribute (33').

7. A computer program product comprising commands which, on execution by a computer, cause it to carry out the method according to any one of the preceding claims.

8. A control device for controlling access control units of an access control system, wherein the control device comprises a computing unit and a database for entries with authorizations, and wherein the control device comprises a graphical user interface or can be connected to a graphical user interface, wherein the computing unit is configured to carry out the method according to any one of the claims 1 to 4 in cooperation with the database and the graphical user interface.

Citation Information

Patent Citations

  • Method and system for the configuration of small locking systems

    US20150235497A1

  • Access system for a vehicle and method for managing access to a vehicle

    US20160148449A1

  • Access control with just-in-time resource discovery

    US6449643B1

  • Access control with just-in-time resource discovery

    EP0957424A2