Reverse identification technology with three-tier architecture
The three-level architecture with a cloud platform and local access switches using QR, NFC, or Bluetooth tags addresses security and reliability issues in access control systems, enhancing protection and reducing hardware complexity.
Patent Information
- Application Number
- PCT/RU2024/000030
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-25
- Filing Date
- 2024-02-02
- Publication Date
- 2025-07-03
AI Technical Summary
Current access control systems for protected facilities are inadequate in terms of security and reliability, particularly in environments requiring high protection levels.
A three-level architecture involving a cloud platform, local access switches, and access points with QR, NFC, or Bluetooth tags for user identification, ensuring secure and reliable access management through synchronized access caches and reduced hardware complexity.
Enhances security and fault tolerance by providing robust access control with reduced hardware requirements and improved reliability in access management systems.
Smart Images

Figure 00000011_0000 
Figure 00000012_0000 
Figure 00000013_0000
Abstract
Description
[0001] REVERSE IDENTIFICATION TECHNOLOGY WITH THREE-LEVEL ARCHITECTURE
[0002] AREA OF TECHNOLOGY
[0003] This technical solution relates to the field of computer technology, in particular to methods of access control and management.
[0004] LEVEL OF TECHNOLOGY
[0005] The prior art discloses a solution selected as the closest analogue, RU2756701C1, 10 / 04 / 2021. This solution relates to the field of computing, namely to a method for providing access and protecting an object. The method for providing access and protecting an object is based on a scoring system in which access to the protected object is provided by the user gaining a predetermined required number of points, while, for each of the above options for providing access, the user, upon positive identification, is assigned a predetermined certain number of points through the scoring system.
[0006] The proposed solution is aimed at eliminating the shortcomings of the current level of technology and differs from known solutions in that the proposed solution ensures increased security of the protected facility, as well as an increased level of fault tolerance and reliability in terms of providing and controlling access to the premises of the facility.
[0007] ESSENCE OF THE INVENTION
[0008] The technical problem, which the claimed solution is aimed at solving, is the creation of a method for access control and management. Additional embodiments of the present invention are presented in the dependent claims of the invention.
[0009] The technical result consists in increasing the security of the protected object.
[0010] The claimed technical result is achieved by implementing a method for access control and management, including the following stages: on a cloud server, local access switches of an object with controllers and access points connected to it are configured; access levels of subjects are configured on the side of the cloud part and are synchronized in the form of an access cache with the local access switches of the object; wherein the local access switch provides the following functionality for interaction with the executive devices of the access points: broadcasting commands received from outside to the executive devices of the access points; storing the local access cache and synchronizing it with the data of the cloud platform; wherein the process of passing through the access points of an object is possible only for an authorized subject and is carried out by means of the computing device of the authorized user, by reading the identifier of the access point;the received access point identifier together with the authorized user identifier is transmitted from the user's computing device to the local switch for execution; the local switch performs the operation authorization by checking the local access cache for the presence of permissions; if the user is successfully authorized, the local switch sends an opening signal to the access point actuator where the tag read by the user was installed.
[0011] In a particular embodiment of the described method, the process of obtaining an access point identifier is performed by reading a QR code with a camera of a computing device.
[0012] In another particular embodiment of the described method, the process of obtaining the access point identifier is performed by reading the NFC tag data.
[0013] In another particular embodiment of the described method, the process of obtaining the access point identifier is performed by reading the data of the Bluetooth tag.
[0014] In another particular embodiment of the described method, the process of obtaining the access point identifier is performed by recognizing the audio-sound identifier of the tag.
[0015] In another particular embodiment of the described method, the local access cache is a database containing current information about the user's powers, and the power data contains the following attributes: user identifier, access point identifier, and power validity period; in this case, based on the data in the database for the pair "user identifier" and "access point identifier", the authorization of the access request is performed, and in the absence of data, the access request is rejected.
[0016] DESCRIPTION OF DRAWINGS
[0017] The implementation of the invention will be described further in accordance with the attached drawings, which are presented to explain the essence of the invention and in no way limit the scope of the invention. The following drawings are attached to the application:
[0018] Fig. 1 illustrates the general scheme of the proposed technical solution.
[0019] Fig. 2 illustrates the description of the parameters.
[0020] Fig. 3 illustrates a structural diagram of an example of implementation of the invention.
[0021] DETAILED DESCRIPTION OF THE INVENTION
[0022] In the following detailed description of the embodiment of the invention, numerous implementation details are set forth in order to provide a clear understanding of the present invention. However, it will be apparent to one skilled in the art how the present invention may be used with or without these implementation details. In other instances, well-known methods, procedures, and components have not been described in detail in order not to unnecessarily obscure the features of the present invention.
[0023] In addition, it will be clear from the above description that the invention is not limited to the embodiment shown. Numerous possible modifications, changes, variations and substitutions, preserving the essence and form of the present invention, will be obvious to those skilled in the art.
[0024] This technical solution relates to the field of computer technology, in particular to the method of access control and management. The proposed solution ensures increased security of the protected object, as well as an increase in the level of fault tolerance and reliability in terms of providing and controlling access to the premises of the object.
[0025] Currently, access to various objects (for example: objects requiring a high level of protection, office buildings, apartment buildings, etc.) is provided by means of primitive and insufficiently secure object protection systems. The proposed method is aimed at solving the above problems. In this technical solution, an access point is understood as a certain object - a physical barrier equipped with a blocking device (door, barrier, turnstile, etc.), an actuator (locks, latches, drives), a reader, and sensors.
[0026] Technical means implementing this technical solution (object security circuit).
[0027] Cloud platform - a system that provides functions for configuring end devices (switches, access controllers) at an object, issuing access point identifiers, forming and updating the object's access cache. The access cache is understood as a set of subject permissions to the object-passage points. By updating the access cache, the security of the protected object is significantly increased.
[0028] The local access cache can be a database containing up-to-date information about user permissions. The permission data contains the following attributes: user ID, access point ID, permission period. The presence of data in the database for the user ID + access point ID pair allows authorization of the access request. If the data is missing, the access request is rejected.
[0029] Local switch - a subsystem in the infrastructure of the object that ensures storage and updating of the local access cache, receipt, authorization and transmission of access requests to the executive devices of access points. Due to the reduction in the number and complexity of the functions performed, the requirements for hardware are significantly reduced, allowing it to be placed on devices of the single-board microcomputer class.
[0030] The switch can be a hardware and software complex based on single-board microcomputers with the following minimum characteristics: 2 GB RAM, 32 GB ROM.
[0031] Interaction between the cloud, switch and controller occurs via a secure protocol (SSL).
[0032] Figure 1 illustrates the general scheme of the proposed technical solution.
[0033] The local switch stores the configuration of controllers and access points required for interaction with the device. In general, several access points can be connected to one controller. The configuration of controllers connected to the switch comes from the cloud server. The solution can use any network access controllers with an open interface for exchanging data and management commands. Examples of controllers from different suppliers: Iron Logic Model: Z-5R (mod. Web), Dahua DHI- ASC2202C-D. The configuration itself is locally stored on the switch and contains additional parameters of the controller and access point required for interaction via the controller API. The description of the configuration parameters is illustrated in Figure 2.
[0034] The switch provides:
[0035] • the ability to interact with access controllers from various suppliers via API;
[0036] • interface (m2m) for receiving commands for interaction with access points (doors, barriers, turnstiles). Basic commands: opening an access point, receiving the current mode of an access point, changing the mode of an access point;
[0037] • local storage of the access cache with the ability to synchronize it with the cloud server;
[0038] • local storage of settings for connected controllers and access points.
[0039] An access controller is a device that provides interaction with final actuators (electromechanical locks, barriers, etc.).
[0040] To identify access requests, reverse identification technology is used, in which a unique identifier in the form of a QR, NFC, or Bluetooth tag is issued for each access point (door, barrier, etc.). The user scans the tag using a mobile application with the application installed. The mobile application transmits an access request containing the subject and object identifier to the access switch for execution. This approach eliminates the need for additional actuators to identify the access subject (access card readers, fingerprint scanners, etc.).
[0041] Configuration of the facility's security circuit devices.
[0042] In the platform application hosted on the cloud server, the configuration of the local access switches of the object with the controllers and access points connected to it is performed. The configuration of the access levels of subjects is performed on the side of the cloud part of the platform and is synchronized in the form of an access cache with the local access switches of the object, due to which the security of the protected object is additionally increased.
[0043] During the local switch configuration process, the following is specified:
[0044] • data on connected access controllers (IP address, MAC address, controller model and supplier, API version); • data on access points connected to the controller (access point number, access point type, access point name).
[0045] The local access switch provides the minimum functionality required to interact with access point actuators:
[0046] • transmission of commands received from outside to the actuators of access points;
[0047] • storing a local access cache and synchronizing it with cloud platform data.
[0048] The process of passing through an object's access points.
[0049] Passage through the object's access points is available to an authorized subject. When using a computing device with the platform application installed, the authorized user reads the access point identifier. Depending on the technical capabilities of the user's device, the process of obtaining the access point identifier can be performed in one of the following ways:
[0050] • reading a QR code with a smartphone camera;
[0051] • reading NFC tag data;
[0052] • reading data from a Bluetooth tag;
[0053] • recognition of the audio-sound identifier of the tag.
[0054] The received access point identifier together with the authorized user identifier is transmitted from the computing device to the local switch for execution. An alternative interaction option is possible, in which the identifiers are transmitted to the cloud server. In the alternative option, the operation is authorized on the cloud server, after which, in the case of a successful verification of the authority, a command is transmitted from the cloud server to the local switch for execution. The local switch performs the operation authorization by checking the presence of the necessary authority in the local access cache. Interaction between the cloud, switch and controller is carried out via a secure protocol (SSL). In the case of successful user authorization, the local switch sends an opening signal to the actuator of the access point where the label read by the user was installed.
[0055] Figure 3 illustrates a structural diagram of an example of implementing the invention.
[0056] The present application materials present a preferred disclosure of the implementation of the claimed technical solution, which should not be used as limiting other, particular embodiments of its implementation that do not go beyond the scope of the requested scope of legal protection and are obvious to specialists in the relevant field of technology.
Claims
Formula 1. A method for access control and management, comprising the following stages: on a cloud server, local access switches of an object with controllers and access points connected to it are configured; access levels of subjects are configured on the cloud side and synchronized in the form of an access cache with the local access switches of the object; wherein the local access switch provides the following functionality for interaction with the executive devices of the access points: transmission of commands received from outside to the executive devices of the access points; storage of the local access cache and its synchronization with the data of the cloud platform; wherein the process of passing through the access points of the object is possible only for an authorized subject and is carried out by means of the computing device of the authorized user, by reading the identifier of the access point;the received access point identifier together with the authorized user identifier is transmitted from the user's computing device to the local switch for execution; the local switch performs the operation authorization by checking the local access cache for permissions; if the user is successfully authorized, the local switch sends an opening signal to the access point actuator where the tag read by the user was installed.
2. The method according to claim 1, wherein the process of obtaining the access point identifier is performed by reading the QR code with a camera of the computing device.
3. The method according to claim 1, wherein the process of obtaining the access point identifier is performed by reading data from the NFC tag.
4. The method according to claim 1, wherein the process of obtaining the access point identifier is performed by reading data from a Bluetooth tag.
5. The method according to claim 1, wherein the process of obtaining the access point identifier is performed by recognizing the audio-sound identifier of the tag.
6. The method according to claim 1, wherein the local access cache is a database containing current information about the user's powers, wherein the power data contains the following attributes: user identifier, access point identifier, and power validity period; wherein, based on the data in the database for the pair of "user identifier" and "access point identifier", the access request is authorized, and if there is no data, the access request is rejected.
Citation Information
Patent Citations
Three-tier architecture based method for optimizing incremental update of system data
CN101931647A
Cloud service server and method for managing cloud service server
EP3203709B1
Method for implementing keyless opening of access control and management systems
RU2756701C1
Authenticating Using Cloud Authentication
US20110099616A1
Orchestrating hybrid cloud services
US20150074279A1