CN104240342A - Access control method and device - Google Patents

Access control method and device Download PDF

Info

Publication number
CN104240342A
CN104240342A CN201410422030.1A CN201410422030A CN104240342A CN 104240342 A CN104240342 A CN 104240342A CN 201410422030 A CN201410422030 A CN 201410422030A CN 104240342 A CN104240342 A CN 104240342A
Authority
CN
China
Prior art keywords
gate inhibition
identify label
access control
management system
request
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
CN201410422030.1A
Other languages
Chinese (zh)
Other versions
CN104240342B (en
Inventor
许飚
张京松
刘洋
田东海
吴亚楠
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Beijing spaceflight morning letter Technology Co., Ltd.
Original Assignee
China Aerospace Ke Gong Group 4th Research Institute's Command Automation Technical Research And Application Center
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by China Aerospace Ke Gong Group 4th Research Institute's Command Automation Technical Research And Application Center filed Critical China Aerospace Ke Gong Group 4th Research Institute's Command Automation Technical Research And Application Center
Priority to CN201410422030.1A priority Critical patent/CN104240342B/en
Publication of CN104240342A publication Critical patent/CN104240342A/en
Application granted granted Critical
Publication of CN104240342B publication Critical patent/CN104240342B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Abstract

The embodiment of the invention provides an access control method and device. The access control device is associated with a preset on-line management system and comprises an information acquisition module, an identity identifying module and an access control opening module, wherein the information acquisition module is used for acquiring identity information of a target requesting for passing through an access control at present; the identity identifying module is used for judging whether an identity mark matched with a first identity mark is stored in a first preset database, and can be used for obtaining a second identity mark and sending the second identity mark to the on-line management system if the identity mark matched with the first identity mark is stored in the first preset database; the access control opening module is used for opening the access control according to a legal verification result which is information generated after the identity mark as same as the second identity mark is found in a second preset database after the second identity mark is received by the on-line management system. By virtue of the access control method and device, the workload of an enterprise management department can be reduced, the management efficiency can be improved and the enterprise management safety can be improved.

Description

A kind of access control method and access control device
Technical field
The present invention relates to information checking technical field, particularly relate to a kind of access control method and a kind of access control device.
Background technology
Along with the development of Information technology and the raising of enterprise security consciousness, particularly recent years is along with contactless card technology, the development of biological identification technology, gate inhibition's technology obtains rapid development, gate inhibition's technology has surmounted simple gateway and key management already, it has developed into the access management system of complete set gradually, and gate inhibition's technology plays huge effect in the Administrations such as work circumstances safe, personnel attendance management.
Traditional access control equipment generally carries out off line identification, its principle of work is: identifying information is entered in access control equipment in advance, when there being personnel to pass in and out gate inhibition, access control equipment directly mates according to the personal information collected in identifying information, the match is successful then opening gate.But above-mentioned principle of work needs human resources to carry out the regular typing of identifying information, labor intensive cost, reduces the work efficiency of personnel.And, if the identifying information in access control equipment upgrades not in time, probably cause for the previous period there is right of access but the personnel that current time does not have right of access enter gate inhibition smoothly, concerning the enterprise that particularly the strict controllers of safety-security area is come in and gone out of enterprise, reduce the security of enterprise.
Therefore, the technical matters needing those skilled in the art urgently to solve at present is exactly: provide a kind of access control mechanism, in order to reduce the workload of department of enterprise organization, improves the efficiency of management and improves enterprise security.
Summary of the invention
Embodiment of the present invention technical matters to be solved is to provide a kind of access control method, in order to reduce the workload of department of enterprise organization, improves the efficiency of management, and improves business administration security.
Accordingly, the embodiment of the present invention additionally provides a kind of access control device, in order to ensure the implementation and application of said method.
In order to solve the problem, the invention discloses a kind of access control device, described access control device associates with the online management system preset, and described access control device comprises:
Information acquisition module, for gathering the identity information of current request by the object of gate inhibition, described identity information comprises the first identify label;
Identification module, for judging, in the first database of presetting, whether there is the identify label of mating with described first identify label, if, then obtain the second identify label, and described second identify label is sent to described online management system in real time, the incidence relation of the first identify label and the second identify label described in described first database purchase;
Gate inhibition's opening module, for after receiving the checking valid result that described online management system returns, opening gate; Described checking valid result be described online management system after receiving described second identify label, from the second database preset, find information identify with described second identify label common identity and generate afterwards.
Preferably, described device also comprises:
Traffic information transmits module, for generating traffic information, and described traffic information is passed to described online management system.
Preferably, described traffic information transmission module comprises:
Monitoring submodule, for monitoring described gate inhibition's opening module;
Data acquisition submodule, for when monitoring described gate inhibition's opening module opening gate, obtains the second identify label of the current object by gate inhibition from described identification module;
Time record sub module, for recording the time of the current object by gate inhibition by gate inhibition;
Information generates submodule, for organizing the second identify label of the described current object by gate inhibition and the described current object by gate inhibition by the time of gate inhibition, generates traffic information;
Transmit submodule, for described traffic information is passed to described online management system.
Preferably, described access control device has gate inhibition's mark, and described identification module is also for being sent to described online management system by described gate inhibition's mark, and described online management system is used for verifying described second identify label in conjunction with described gate inhibition's mark.
Preferably, described current request comprises at least one of the vehicle of asking the personnel that go out and request to be gone out by the object of gate inhibition.
Present invention also offers a kind of access control method, described access control method is applied in access control device, and described access control device associates with the online management system preset, and described method comprises:
Access control device gathers the identity information of current request by the object of gate inhibition, and described identity information comprises the first identify label;
Access control device judges whether have the identify label of mating with described first identify label in the first database preset, if, then obtain the second identify label, and described second identify label is sent to described online management system in real time, the incidence relation of the first identify label and the second identify label described in described first database purchase;
Access control device after receiving the checking valid result that described online management system returns, opening gate; Described checking valid result be described online management system after receiving described second identify label, from the second database preset, find information identify with described second identify label common identity and generate afterwards.
Preferably, described method also comprises:
Access control device generates traffic information, and described traffic information is passed to described online management system.
Preferably, described access control device generates traffic information, and the step described traffic information being passed to described online management system comprises:
When monitoring gate inhibition and opening, record the time of the current object by gate inhibition by gate inhibition;
Organize the second identify label of the current object by gate inhibition and the described current object by gate inhibition by the time of gate inhibition, generate traffic information;
Described traffic information is passed to described online management system.
Preferably, described access control device has gate inhibition's mark, and described method also comprises:
Described gate inhibition's mark is sent to described online management system.
Preferably, described current request comprises at least one of the vehicle of asking the personnel that go out and request to be gone out by the object of gate inhibition.
Compared with background technology, the embodiment of the present invention comprises following advantage:
The embodiment of the present invention innovatively proposes a kind of online access control device, the online management system of this access control device and enterprise is interconnected online, by the identity information of Real-time Collection request by the object of gate inhibition, be sent to online management system after the identity information of this collection is identified and carry out authentication, the unlatching of real-time access control when receiving the checking valid result that online management system sends, thus realize the data syn-chronization of online management system and access control device, avoid and for the previous period there is right of access but the situation that the personnel that current time does not have a right of access enter gate inhibition occurs, improve business administration security, and decrease the workload of enterprise administrator, improve the efficiency of management, meet the demand of modern management.
Accompanying drawing explanation
Fig. 1 is the structured flowchart of a kind of access control device embodiment of the present invention;
Fig. 2 is the interactive step process flow diagram of the access control device of the embodiment of the present invention;
Fig. 3 is the flow chart of steps of a kind of access control method embodiment of the present invention.
Embodiment
For enabling above-mentioned purpose of the present invention, feature and advantage become apparent more, and below in conjunction with the drawings and specific embodiments, the present invention is further detailed explanation.
With reference to Fig. 1, show the structured flowchart of a kind of access control device embodiment of the present invention, wherein, described access control device associates with the online management system preset, and described access control device can comprise as lower module:
Information acquisition module 101, for gathering the identity information of current request by the object of gate inhibition, described identity information comprises the first identify label;
As a kind of preferred exemplary of the present embodiment, current request can comprise at least one of the vehicle of asking the personnel that go out and request to be gone out by the object of gate inhibition.
Identification module 102, for judging whether have the identify label of mating with described first identify label in the first database of presetting, if so, then obtaining the second identify label, and described second identify label is sent to described online management system in real time;
Gate inhibition's opening module 103, for after receiving the checking valid result that described online management system returns, opening gate; Described checking valid result be described online management system after receiving described second identify label, from the second database preset, find information identify with described second identify label common identity and generate afterwards.
In a kind of preferred embodiment of the embodiment of the present invention, described device can also comprise:
Traffic information transmits module, for generating traffic information, and described traffic information is passed to described online management system.
In a kind of preferred embodiment of the embodiment of the present invention, described traffic information is transmitted module and be may further include following submodule:
Monitoring submodule, for monitoring described gate inhibition's opening module;
Data acquisition submodule, for when monitoring described gate inhibition's opening module opening gate, obtains the second identify label of the current object by gate inhibition from described identification module;
Time record sub module, for recording the time of the current object by gate inhibition by gate inhibition;
Information generates submodule, for organizing the second identify label of the described current object by gate inhibition and the described current object by gate inhibition by the time of gate inhibition, generates traffic information;
Transmit submodule, for described traffic information is passed to described online management system.
In a kind of preferred embodiment of the embodiment of the present invention, described access control device has gate inhibition's mark, described identification module can also be used for described gate inhibition's mark to be sent to described online management system, and described online management system is used for verifying described second identify label in conjunction with described gate inhibition's mark.
The embodiment of the present invention innovatively proposes a kind of online access control device, the online management system of this access control device and enterprise is interconnected online, by the identity information of Real-time Collection request by the object of gate inhibition, be sent to online management system after the identity information of this collection is identified and carry out authentication, the unlatching of real-time access control when receiving the checking valid result that online management system sends, thus realize the data syn-chronization of online management system and access control device, avoid and for the previous period there is right of access but the situation that the personnel that current time does not have a right of access enter gate inhibition occurs, improve business administration security, and decrease the workload of enterprise administrator, improve the efficiency of management, meet the demand of modern management.
It should be noted that, in order to access control device is combined with online management system, realize online intercommunication, the environment building both online intercommunications of embodiment of the present invention needs, such as build computer network and (can IP network be comprised, the network of RS485 bus and other form) and switching equipment, server, database server, gate inhibition's access device, and supporting bottom working procedure and communications protocol, as: in central machine room configure application server, stored data base, the network switching equipment, transmitted by comprehensive wiring system, with the gate control system equipment being distributed in each gateway, management systems etc. interconnect, realize the said equipment 24 hours round-the-clock on-line operations, ensure real-time request for data and check and write off data upload, the needs that real-time discrepancy is current.Build this set of environments, need to decide according to the quantity of the user demand of user and required terminal, room entry/exit management terminal, and carry out the construction of civil engineering, strong and weak electricity, installation etc.
In order to be described access control device of the present invention better, below online management system is illustrated:
Described online management system comprises:
Data management module, for obtaining the request for data examined and pass through; And, when finding the request for data mated with described traffic information in the request for data that described examination & approval are passed through, according to preset rules, process is checked and write off to the request for data of described coupling;
Authentication module, for obtaining the request for data that described examination & approval are passed through from described data management module, and, verify in the identify label of request for data that described examination & approval are passed through there is the second identify label of passing through the object of gate inhibition with described current request consistent request for data time, generate checking valid result, and described checking valid result is sent to gate inhibition's opening module.
In one embodiment, described data management module can comprise following submodule:
Online application submodule, for receiving the request for data filled in online;
Online examination & approval submodule, for examining online described request for data, and is sent to sub module stored by examining the request for data passed through;
Sub module stored, for storing the request for data that described examination & approval are passed through.
In one embodiment, described request for data also comprises the time period of applying for going out, and described data management module comprises following submodule:
State checks submodule, during for finding the request for data mated with the identify label of the described current object by gate inhibition in the request for data that passes through in described examination & approval, checks in the request msg of described coupling whether have specific markers;
Mark adds submodule, during for not having specific markers in the request msg of described coupling, is that the request msg of described coupling adds specific markers;
Check and write off process submodule, for having specific markers in the request msg of described coupling, and the described current object by gate inhibition is by when time of gate inhibition is in the scope of the time period that described application is gone out, and checks and writes off process to the request for data of described coupling.
In one embodiment, described data management module also comprises:
First records interpolation submodule in violation of rules and regulations, for there is specific markers in the request msg of described coupling, and the described current object by gate inhibition is by when time of gate inhibition is not in the scope of the time period that described application is gone out, and the request msg of described coupling is added in default violation record list;
Second records interpolation submodule in violation of rules and regulations, detects the described request for data with described specific markers for regular, is added in default violation record list by the request for data exceeded outside the preset time period of applying for the time period of going out.
In one embodiment, described online management system also comprises:
Enquiry module, for receiving the querying condition of input, obtains the request for data mated with described querying condition from described data management module;
Output module, for exporting the described request for data mated with described querying condition.
In one embodiment, described authentication module also for verify in the request for data that passes through of described examination & approval not exist with described current request by identify label that the identify label of the object of gate inhibition is consistent time, generate the illegal result of checking, and illegal for described checking result is sent to gate inhibition's opening module;
Then described gate inhibition's opening module is also for when receiving the illegal result of checking that described authentication module sends, not opening gate.
In one embodiment, the request for data that described examination & approval are passed through also comprises capability identification, and described access control device stores the right of way limit scope of current gate inhibition, and described authentication module comprises:
Authority obtains submodule, for verify in the request for data that passes through of described examination & approval there is the identify label of passing through the object of gate inhibition with described current request consistent identify label time, from the request for data that described examination & approval are passed through, obtain the capability identification of current request by the object of gate inhibition;
Judge submodule, for judging described current request by the capability identification of the object of gate inhibition whether within the scope of described right of access;
Result generates submodule, for when judging that the capability identification of described current request by the object of gate inhibition is within the scope of described right of access, generates checking valid result;
Result transmits submodule, for described checking valid result is passed to described gate inhibition's opening module.
Show the access control device of the embodiment of the present invention and the interactive step process flow diagram of online management system with reference to figure 2, can comprise the steps:
Step 301, data management module obtains the request for data examined and pass through;
In one preferred embodiment of the invention, step 301 can comprise following sub-step:
Sub-step S11, data management module receives the request for data filled in online;
In practice, if application personnel have the authority operating in wire management system, then can fill in request for data by application personnel online by online management system, to do the application of being correlated with; Or if application personnel do not operate in the authority of wire management system, then apply for that personnel can be filed an application to administrative authority by written form, the related management personnel of administrative authority fill in request for data online by online management system again.
As a kind of example, request for data can for request for data, the application request for data of field personnel and at least one of vehicle request for utilization data of asking for leave, the request for data of the personnel of application field personnel can be thought, the request for data of the personnel of application field personnel and vehicle request for utilization data, the request for data etc. of the personnel of asking for leave, such as, the personnel of request field personnel can fill in field personnel request for data and vehicle request for utilization data, or only fill in field personnel request for data.
Request for data can comprise the time period of applying for going out, the information such as identify label, vehicles identifications, capability identification, reason for the request of applying for personnel, wherein, application personnel identify label can be applicant person ID or application personnel title, is the foundation identifying application personnel; Capability identification, for identifying the right of access of the vehicle of application personnel or application, can be the grade encoding of the vehicle of applicant person or application, and encode transitable region and number of times of different stage is different.
Sub-step S12, data management module is examined online to described request for data, obtains examining the request for data passed through;
In specific implementation, after data management module receives the request for data of application, automatically can examine it according to preset rules, such as identify capability identification whether within the scope of the capability identification preset, if so, then examination & approval are passed through, otherwise examination & approval are not passed through.
Certainly, also manually can be examined the request for data of application by the related personnel of administrative authority, detailed process can be, after the related personnel of administrative authority logs in wire management system, online management system shows that request for data is to these personnel, these personnel by click examination & approval in online management system by or examination & approval not by waiting function button submit to examination & approval by result or examine and do not pass through result.It should be noted that, when there being the request for data of submission, online management system can the related personnel of real-time reminding administrative authority be examined in real time, online management system also can remind administrative authority related personnel batch processing request for data every preset time period, or, online management system also can not be reminded, initiatively check when department related personnel to be managed logs in wire management system request for data and do examination & approval process, the embodiment of the present invention to this without the need to being limited.
Sub-step S13, data management module stores the request for data that described examination & approval are passed through.
After obtaining examining the request for data that passes through, data management module can store with the form of list or database (the second database) or file the request for data that described examination & approval pass through, and uses and follow-up maintenance for other follow-up modules.
In fact, all can preserve for all request for data online management systems, this all request for data can be a list, and the request for data that examination & approval are passed through can be another part of list; Or, examine the request for data passed through and examine in the list of described all request for data by mark.
It should be noted that, the request for data that the examination & approval that data management module stores are passed through has storage period, and the request for data exceeding storage period can carry out Automatic clearance, or reminds administrative authority's cleaning.
In another preferred embodiment of the invention, administrative authority also can upload by online management system batch the request for data examined and pass through, after data management module receives the request for data uploaded, store with the form of list or database or file the request for data that described examination & approval pass through.
Step 302, information acquisition module Real-time Collection current request is by the identity information of the object of gate inhibition, and described identity information comprises the first identify label;
Specifically, access control device is equipment exit and entrance being carried out to control, and it develops on traditional door lock basis.Access control device in the embodiment of the present invention can comprise at least one of the porte-cochere lock of entrance guard device that personnel pass through and vehicle pass-through, then described current request can comprise at least one of the vehicle of asking the personnel that go out and request to be gone out by the object of gate inhibition, and ask the personnel gone out can comprise the personnel of asking for leave, the personnel etc. of request field personnel.
When object requests having been detected by gate inhibition, information acquisition module can by be positioned at the equipment such as radio-frequency card card-reading apparatus, fingerprint instrument equipment, portrait recognition device of gate inhibition gateway wherein a kind of come Real-time Collection current request by the identity information of the object of gate inhibition.
In specific implementation, identity information is the information of unique identification personnel or testing vehicle register, the first identify label can be comprised, first identify label can comprise the perfect instrument number of object, the biometric feature information of object, various card images that can represent personnel identity etc., such as, for the personnel asking to go out, first identify label can comprise at least one of following information: the ID (identity number) card No. of personnel, the fingerprint feature information of personnel, the iris feature information of personnel, the face feature information of personnel, the skeleton character information of personnel, the voice characteristics information of personnel, the IC-card of personnel identity can be represented, the ID card etc. of personnel identity can be represented, for asking for the vehicle of going out, the first identify label can comprise at least one of following information: the number-plate number, containing car plate ground form the number-plate number, can represent testing vehicle register IC-card, can represent testing vehicle register ID card, the bluetooth card of testing vehicle register can be represented, the microwave card etc. of testing vehicle register can be represented.
Information acquisition module is passed to identification module after collecting the identity information of current request by the object of gate inhibition, to carry out identification.
Step 303, identification module judges whether have second identify label of mating with described first identify label in the first database preset, if so, then obtain described second identify label, and described second identify label is sent to described authentication module in real time;
After identification module receives the first identify label, from the first database preset, search the identify label identical with described first identify label, in the first database, obtain the second identify label of this mark correspondence.Wherein, the incidence relation that can store the first identify label and the second identify label in the first database, the data in the first database can for the data prestored, or the data obtained from online management system.
After identification module identifies the second identify label, this second identify label is sent to authentication module, carries out authentication for authentication module.
Such as, application personnel enter gate inhibition by the mode request of brush finger line, after information acquisition module collects the finger print information of this application personnel, finger print data is passed to identification module, then identification module mates this finger print information in the first database, if match, then obtain corresponding application personnel title or ID, and application personnel title or ID are sent to authentication module.
Step 304, after authentication module receives second identify label of current request by the object of gate inhibition, the request for data that described examination & approval are passed through is obtained from described data management module, and, verify in the identify label of request for data that described examination & approval are passed through to exist with described current request by request for data that the second identify label of the object of gate inhibition is consistent time, generate and verify valid result;
Specifically, after authentication module receives second identify label of current request by the object of gate inhibition that identification module sends, checking current request is by the legitimacy of the object identity of gate inhibition, verification method can be, after authentication module obtains the request for data that described examination & approval pass through from data management module, verify in the request for data that these examination & approval are passed through and whether exist with current request by the identical request for data of the second identify label of the object of gate inhibition, if exist, it is legal then to verify, generates checking valid result.Correspondingly, when not exist with described current request by request for data that the second identify label of the object of gate inhibition is consistent if verify in the identify label of the request for data that described examination & approval are passed through, the illegal result of checking is generated.
Further, the right of way limit scope of current gate inhibition is stored in access control device, this right of way limit scope defines the object of which authority by current gate inhibition, then authentication module can also verify the identity legitimacy of current request by the object of gate inhibition in conjunction with right of access scope, be specifically as follows: while the second identify label is sent to authentication module by identification module, the right of access scope obtaining current gate inhibition is sent to authentication module, authentication module verify in the identify label of request for data that described examination & approval are passed through there is the second identify label of passing through the object of gate inhibition with described current request consistent request for data time, the capability identification of current request by the object of gate inhibition is obtained from the request for data that described examination & approval are passed through, judge described current request by the capability identification of the object of gate inhibition whether within the scope of described right of access, if so, then generate checking valid result, otherwise, generate the illegal result of checking.
Step 305, described checking valid result is passed to gate inhibition's opening module by authentication module;
Concrete, authentication module generates checking valid result or after verifying illegal result, by this checking valid result or can verify that illegal result is all sent to gate inhibition's opening module.
In actual applications, authentication module generates checking valid result or after verifying illegal result, also directly illegal for checking result can be filtered, only checking valid result is sent to gate inhibition's opening module, to reduce the pressure of data transmission.
Step 306, gate inhibition's opening module receive described authentication module send checking valid result time, opening gate;
Concrete, gate inhibition's opening module after receiving checking valid result, opening gate, the object of this request by gate inhibition of letting pass.On the other hand, if gate inhibition's opening module does not receive checking valid result or receives the illegal result of checking, then do not do the process of opening gate, now, gate inhibition's opening module can be generated prompting message and remind current request not made the reason of opening by the current gate inhibition of the object of gate inhibition.
Step 307, traffic information transmits CMOS macro cell traffic information, and described traffic information is sent to data management module;
Traffic information can comprise the current object by gate inhibition identity information and by the time of gate inhibition and the channel information etc. of current gate inhibition.Specifically, traffic information is transmitted module and is monitored gate inhibition's opening module in real time, when monitoring gate inhibition's opening module opening gate, the second identify label of the current object by gate inhibition is obtained from identification module, and record the time of the current object by gate inhibition by gate inhibition, organize the second identify label of the described current object by gate inhibition and the described current object by gate inhibition by the time of gate inhibition, generate traffic information, and traffic information is passed to data management module.
Step 308, after data management module receives traffic information, when finding the request for data mated with the identify label of described traffic information in the request for data that described examination & approval are passed through, checks and writes off process to the request for data of described coupling according to preset rules;
Be applied to the embodiment of the present invention, data management module can also carry out checking and writing off process.In one preferred embodiment of the invention, the concrete processing procedure of checking and writing off can be: after data management module receives traffic information, the request for data passed through in the examination & approval stored in advance mates the request for data consistent with the identify label of traffic information, if match, then illustrate this pass through gate inhibition to as if for submitting request for data to and request for data audits the object passed through, then in this request for data matched, record this traffic information, and check whether this request for data matched has specific markers, if there is specific markers, then illustrate that this object by gate inhibition is that request is gone out, now request returns the object entering gate inhibition, if there is no specific markers, then illustrate that this object by gate inhibition is the object of asking to go out.As a kind of example, described specific markers can be mark of going out.
If this request for data matched is the request for data not having specific markers, then data management module is the request for data interpolation specific markers of this coupling, to indicate this object for do well, and record the time of the current object by gate inhibition by gate inhibition in this request for data as the time of going out outward.
If this request for data matched is the request for data having specific markers, then data management module judges the current object by gate inhibition further by time of gate inhibition whether in the scope of the time period that described application is gone out, if applying within the scope of the time period of going out, then illustrate that this object normally returns within the time of agreement, then data management module can check and write off process normally to this application data, the means of checking and writing off process can comprise at least one in following means: the capability identification deleting the request for data of this coupling, request for data for this coupling adds " checking and writing off " mark etc.Further, in this request for data, the time of the current object by gate inhibition by gate inhibition is recorded as time of return.
On the other hand, if this request for data matched is the request for data having specific markers, but the described current object by gate inhibition is by when time of gate inhibition is not in the scope of the time period that described application is gone out, then illustrate that this object does not return within the time of agreement, the i.e. object of overtime return, then data management module can check and write off process not in accordance with checking and writing off normally flow process to this application data, now, the request msg of this coupling can be added in default violation record list by data management module, checked and write off by administrative authority's laggard pedestrian's work of going and finding out what's going on, and by violation situation remarks, in violation of rules and regulations situation can comprise the time of the current object by gate inhibition by gate inhibition, reason etc. in violation of rules and regulations.
In addition, a kind of situation is in addition, application object and/or vehicle exceed after going out in the Preset Time of time period applying for going out and also do not return (i.e. overtime situation of not returning), now, data management module does not receive traffic information, for this situation, data management module in the embodiment of the present invention regularly can carry out cleaning detection to examining in the request for data that passes through with the request for data of specific markers, the request for data exceeded outside the preset time period of applying for the time period of going out is added in default violation record list, inquire that concrete condition does concrete process by administrative authority.
The embodiment of the present invention reminds administrative authority to carry out going out the management of object in violation of rules and regulations by violation of rules and regulations record list, improves the work efficiency of administrative authority and has ensured enterprise security.
In the embodiment of the present invention, data management module can also be gathered the situation that object application is gone out, can comprise and ask virtual degree, outer outdegree, normal recycle time, in violation of rules and regulations recycle time etc., with the department of strengthening management to any personnel who go out or the management of vehicle of going out.
Step 309, enquiry module initiates the inquiry request to described data management module, obtains the request for data mated with querying condition and is also represented.
In the embodiment of the present invention, traffic information is with the addition of when examining the request for data passed through, after checking and writing off the information such as mark, summary information, administrative authority can also input inquiry condition to inquire about the request for data passed through of examining safeguarded in data management module, querying condition can for apply for go out time period, the second identify label, place etc. of going out.The described request for data mated with querying condition represents after obtaining the request for data mated with querying condition by enquiry module.
It should be noted that, the embodiment of the present invention, for the vehicle of turnover gate inhibition, can also be carried out the real-time display of car two information, comprise turnover time, license board information etc.
In order to make art technology object understand the embodiment of the present invention better, with an embody rule scene, the embodiment of the present invention is illustrated below:
1) certain unit personnel first needs to ask for leave and be on home leave, and goes out, return when 9 day afternoon 17 during its plan 2 day the morning 8, then proposes to ask for leave application on 1st to second (department ask for leave managerial personnel);
2) second is by ask for leave information reporting registration (be herein considered as identify label that access control device comprised first) of online management system by first, Human Resources Department supervisor third carried out batch and to ask for leave management 1 day 17 time, have approved asking for leave of first, this approval of jurisdiction is carried out upload process by online management system;
3) if first punctual brush finger line in 2 day the morning 8 time is gone out, after gate inhibition obtains the finger print information of first, this finger print information is mated from the first database preset, if match, then obtain in the first database the name of the first corresponding with finger print information stored, and the name of first is sent to online management system;
4) online management system searches the name of first in examination & approval data, if find, then returns checking valid result;
5) access control device receive checking valid result after opening gate.
In embodiments of the present invention, by a device that access control device and online management system are permeated, the centralized management of record and the synchronous of authentication are checked and write off in the application achieving application personnel, namely can verify current after reaching the approval of application personnel instant request for data at once, application personnel or vehicle return rear effect of automatically checking and writing off process, meet the demand of modern management.
With reference to Fig. 3, show the flow chart of steps of a kind of access control method embodiment of the present invention, described access control method is applied in access control device, and described access control device associates with the online management system preset, and described method specifically can comprise the steps:
Step 401, access control device gathers the identity information of current request by the object of gate inhibition, and described identity information comprises the first identify label;
Step 402, access control device judges whether have the identify label of mating with described first identify label in the first database preset, if, then obtain the second identify label, and described second identify label is sent to described online management system in real time, the incidence relation of the first identify label and the second identify label described in described first database purchase;
Step 403, access control device after receiving the checking valid result that described online management system returns, opening gate; Described checking valid result be described online management system after receiving described second identify label, from the second database preset, find information identify with described second identify label common identity and generate afterwards.
In one preferred embodiment of the invention, described method can also comprise:
Access control device generates traffic information, and described traffic information is passed to described online management system.
In one preferred embodiment of the invention, described access control device generates traffic information, and the step described traffic information being passed to described online management system comprises:
When monitoring gate inhibition and opening, record the time of the current object by gate inhibition by gate inhibition;
Organize the second identify label of the current object by gate inhibition and the described current object by gate inhibition by the time of gate inhibition, generate traffic information;
Described traffic information is passed to described online management system.
In one preferred embodiment of the invention, described access control device has gate inhibition's mark, and described method also comprises:
Described gate inhibition's mark is sent to described online management system.
As a kind of preferred exemplary of the embodiment of the present invention, described current request comprises at least one of the vehicle of asking the personnel that go out and request to be gone out by the object of gate inhibition.It should be noted that, for embodiment of the method, in order to simple description, therefore it is all expressed as a series of combination of actions, but art technology object should be known, the embodiment of the present invention is not by the restriction of described sequence of movement, because according to the embodiment of the present invention, some step can adopt other orders or carry out simultaneously.Secondly, art technology object also should be known, the embodiment described in instructions all belongs to preferred embodiment, and involved action might not be that the embodiment of the present invention is necessary.
For the embodiment of the method described in Fig. 3, due to itself and said apparatus embodiment basic simlarity, so description is fairly simple, relevant part illustrates see the part of embodiment of the method.
Each embodiment in this instructions all adopts the mode of going forward one by one to describe, and what each embodiment stressed is the difference with other embodiments, between each embodiment identical similar part mutually see.
Technical object in this area should be understood, the embodiment of the embodiment of the present invention can be provided as method, device or computer program.Therefore, the embodiment of the present invention can adopt the form of complete hardware embodiment, completely software implementation or the embodiment in conjunction with software and hardware aspect.And the embodiment of the present invention can adopt in one or more form wherein including the upper computer program implemented of computer-usable storage medium (including but not limited to magnetic disk memory, CD-ROM, optical memory etc.) of computer usable program code.
In one typically configuration, described computer equipment comprises one or more processor (CPU), input/output interface, network interface and internal memory.Internal memory may comprise the volatile memory in computer-readable medium, and the forms such as random access memory (RAM) and/or Nonvolatile memory, as ROM (read-only memory) (ROM) or flash memory (flash RAM).Internal memory is the example of computer-readable medium.Computer-readable medium comprises permanent and impermanency, removable and non-removable media can be stored to realize information by any method or technology.Information can be computer-readable instruction, data structure, the module of program or other data.The example of the storage medium of computing machine comprises, but be not limited to phase transition internal memory (PRAM), static RAM (SRAM), dynamic RAM (DRAM), the random access memory (RAM) of other types, ROM (read-only memory) (ROM), Electrically Erasable Read Only Memory (EEPROM), fast flash memory bank or other memory techniques, read-only optical disc ROM (read-only memory) (CD-ROM), digital versatile disc (DVD) or other optical memory, magnetic magnetic tape cassette, tape magnetic rigid disk stores or other magnetic storage apparatus or any other non-transmitting medium, can be used for storing the information can accessed by computing equipment.According to defining herein, computer-readable medium does not comprise the computer readable media (transitory media) of non-standing, as data-signal and the carrier wave of modulation.
The embodiment of the present invention describes with reference to according to the process flow diagram of the method for the embodiment of the present invention, terminal device (system) and computer program and/or block scheme.Should understand can by the combination of the flow process in each flow process in computer program instructions realization flow figure and/or block scheme and/or square frame and process flow diagram and/or block scheme and/or square frame.These computer program instructions can being provided to the processor of multi-purpose computer, special purpose computer, Embedded Processor or other programmable data processing terminal equipment to produce a machine, making the instruction performed by the processor of computing machine or other programmable data processing terminal equipment produce device for realizing the function of specifying in process flow diagram flow process or multiple flow process and/or block scheme square frame or multiple square frame.
These computer program instructions also can be stored in can in the computer-readable memory that works in a specific way of vectoring computer or other programmable data processing terminal equipment, the instruction making to be stored in this computer-readable memory produces the manufacture comprising command device, and this command device realizes the function of specifying in process flow diagram flow process or multiple flow process and/or block scheme square frame or multiple square frame.
These computer program instructions also can be loaded on computing machine or other programmable data processing terminal equipment, make to perform sequence of operations step to produce computer implemented process on computing machine or other programmable terminal equipment, thus the instruction performed on computing machine or other programmable terminal equipment is provided for the step realizing the function of specifying in process flow diagram flow process or multiple flow process and/or block scheme square frame or multiple square frame.
Although described the preferred embodiment of the embodiment of the present invention, the technical object in this area once obtain the basic creative concept of cicada, then can make other change and amendment to these embodiments.So claims are intended to be interpreted as comprising preferred embodiment and falling into all changes and the amendment of embodiment of the present invention scope.
Finally, also it should be noted that, in this article, the such as relational terms of first and second grades and so on is only used for an entity or operation to separate with another entity or operational zone, and not necessarily requires or imply the relation that there is any this reality between these entities or operation or sequentially.And, term " comprises ", " comprising " or its any other variant are intended to contain comprising of nonexcludability, thus make to comprise the process of a series of key element, method, article or terminal device and not only comprise those key elements, but also comprise other key elements clearly do not listed, or also comprise by the intrinsic key element of this process, method, article or terminal device.When not more restrictions, the key element limited by statement " comprising ... ", and be not precluded within process, method, article or the terminal device comprising described key element and also there is other identical element.
Above to a kind of access control method provided by the present invention and a kind of access control device, be described in detail, apply specific case herein to set forth principle of the present invention and embodiment, the explanation of above embodiment just understands method of the present invention and core concept thereof for helping; Meanwhile, for one of ordinary skill in the art, according to thought of the present invention, all will change in specific embodiments and applications, in sum, this description should not be construed as limitation of the present invention.

Claims (10)

1. an access control device, is characterized in that, described access control device associates with the online management system preset, and described access control device comprises:
Information acquisition module, for gathering the identity information of current request by the object of gate inhibition, described identity information comprises the first identify label;
Identification module, for judging, in the first database of presetting, whether there is the identify label of mating with described first identify label, if, then obtain the second identify label, and described second identify label is sent to described online management system in real time, the incidence relation of the first identify label and the second identify label described in described first database purchase;
Gate inhibition's opening module, for after receiving the checking valid result that described online management system returns, opening gate; Described checking valid result be described online management system after receiving described second identify label, from the second database preset, find information identify with described second identify label common identity and generate afterwards.
2. device according to claim 1, is characterized in that, also comprises:
Traffic information transmits module, for generating traffic information, and described traffic information is passed to described online management system.
3. device according to claim 2, is characterized in that, described traffic information is transmitted module and comprised:
Monitoring submodule, for monitoring described gate inhibition's opening module;
Data acquisition submodule, for when monitoring described gate inhibition's opening module opening gate, obtains the second identify label of the current object by gate inhibition from described identification module;
Time record sub module, for recording the time of the current object by gate inhibition by gate inhibition;
Information generates submodule, for organizing the second identify label of the described current object by gate inhibition and the described current object by gate inhibition by the time of gate inhibition, generates traffic information;
Transmit submodule, for described traffic information is passed to described online management system.
4. device according to claim 1, it is characterized in that, described access control device has gate inhibition's mark, described identification module is also for being sent to described online management system by described gate inhibition's mark, and described online management system is used for verifying described second identify label in conjunction with described gate inhibition's mark.
5. the device according to claim 1 or 2 or 3 or 4, is characterized in that, described current request comprises at least one of the vehicle of asking the personnel that go out and request to be gone out by the object of gate inhibition.
6. an access control method, is characterized in that, described access control method is applied in access control device, and described access control device associates with the online management system preset, and described method comprises:
Access control device gathers the identity information of current request by the object of gate inhibition, and described identity information comprises the first identify label;
Access control device judges whether have the identify label of mating with described first identify label in the first database preset, if, then obtain the second identify label, and described second identify label is sent to described online management system in real time, the incidence relation of the first identify label and the second identify label described in described first database purchase;
Access control device after receiving the checking valid result that described online management system returns, opening gate; Described checking valid result be described online management system after receiving described second identify label, from the second database preset, find information identify with described second identify label common identity and generate afterwards.
7. method according to claim 6, is characterized in that, also comprises:
Access control device generates traffic information, and described traffic information is passed to described online management system.
8. method according to claim 7, is characterized in that, described access control device generates traffic information, and the step described traffic information being passed to described online management system comprises:
When monitoring gate inhibition and opening, record the time of the current object by gate inhibition by gate inhibition;
Organize the second identify label of the current object by gate inhibition and the described current object by gate inhibition by the time of gate inhibition, generate traffic information;
Described traffic information is passed to described online management system.
9. method according to claim 6, is characterized in that, described access control device has gate inhibition's mark, and described method also comprises:
Described gate inhibition's mark is sent to described online management system.
10. the method according to any one of claim 6-9, is characterized in that, described current request comprises at least one of the vehicle of asking the personnel that go out and request to be gone out by the object of gate inhibition.
CN201410422030.1A 2014-08-25 2014-08-25 Access control method and device based on identity authentication Active CN104240342B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201410422030.1A CN104240342B (en) 2014-08-25 2014-08-25 Access control method and device based on identity authentication

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201410422030.1A CN104240342B (en) 2014-08-25 2014-08-25 Access control method and device based on identity authentication

Publications (2)

Publication Number Publication Date
CN104240342A true CN104240342A (en) 2014-12-24
CN104240342B CN104240342B (en) 2017-01-11

Family

ID=52228339

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201410422030.1A Active CN104240342B (en) 2014-08-25 2014-08-25 Access control method and device based on identity authentication

Country Status (1)

Country Link
CN (1) CN104240342B (en)

Cited By (19)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105825642A (en) * 2016-05-25 2016-08-03 安徽远东网络科技有限公司 Community security information processing system
CN106373228A (en) * 2016-08-29 2017-02-01 杭州巴玺电子科技有限公司 Intelligent safe passive lockset system and unlocking method thereof
CN106453220A (en) * 2016-06-17 2017-02-22 四川师范大学 Butt joint type safety protection identification method
CN106487762A (en) * 2015-08-31 2017-03-08 腾讯科技(深圳)有限公司 The recognition methodss of user identity, identification applications client and server
WO2017101385A1 (en) * 2015-12-14 2017-06-22 乐视控股(北京)有限公司 Access control identification method, device, system and terminal
CN106981119A (en) * 2017-05-05 2017-07-25 江苏速度信息科技股份有限公司 Entrance guard management system and method based on body shape
CN107045684A (en) * 2016-02-06 2017-08-15 戴见霖 Identification system and its recognition methods
CN107330601A (en) * 2017-06-23 2017-11-07 深圳市盛路物联通讯技术有限公司 A kind of intelligent gun management method and device
CN108022334A (en) * 2016-11-04 2018-05-11 法乐第(北京)网络科技有限公司 Garage access control system and garage door control method
CN108021851A (en) * 2016-11-04 2018-05-11 法乐第(北京)网络科技有限公司 Garage door control system and garage fingerprint base update method
CN108335387A (en) * 2018-01-23 2018-07-27 阿里巴巴集团控股有限公司 Face recognition door control system and access control method
CN109360301A (en) * 2018-09-05 2019-02-19 深圳中兴力维技术有限公司 Access control system and its control method
CN109712290A (en) * 2018-12-26 2019-05-03 广东中安金狮科创有限公司 Security system
CN109791714A (en) * 2016-09-30 2019-05-21 亚萨合莱有限公司 The access to physical space is controlled using fingerprint sensor
CN110021088A (en) * 2018-10-29 2019-07-16 深圳市微开互联科技有限公司 It is distributed the page control open-door system and method for authorization architecture
CN110580754A (en) * 2018-06-11 2019-12-17 杭州海康威视系统技术有限公司 Face authentication method, device and system
CN112489282A (en) * 2020-12-02 2021-03-12 杭州国辰机器人科技有限公司 Entrance guard attendance checking method, system, computer equipment and storage medium
CN113132106A (en) * 2019-12-30 2021-07-16 中国移动通信集团山西有限公司 User identity recognition system
CN114724292A (en) * 2022-03-31 2022-07-08 合肥指南针电子科技有限责任公司 Prison management method

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101114338A (en) * 2007-08-21 2008-01-30 深圳市杰特电信控股有限公司 Work attendance method based on finger print mobile phones
US20080041943A1 (en) * 2006-08-16 2008-02-21 Michael Radicella Method and system for controlling access to an enclosed area
CN101587607A (en) * 2008-05-23 2009-11-25 上海科识通信息科技有限公司 Opening type radio frequency automatic identification gate control system
CN101661586A (en) * 2009-09-29 2010-03-03 金蝶软件(中国)有限公司 Method of optimized data processing procedure and device thereof
CN103986772A (en) * 2014-05-23 2014-08-13 南京洛尧智慧信息技术有限公司 Army management system based on internet of things and cloud computing

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20080041943A1 (en) * 2006-08-16 2008-02-21 Michael Radicella Method and system for controlling access to an enclosed area
CN101114338A (en) * 2007-08-21 2008-01-30 深圳市杰特电信控股有限公司 Work attendance method based on finger print mobile phones
CN101587607A (en) * 2008-05-23 2009-11-25 上海科识通信息科技有限公司 Opening type radio frequency automatic identification gate control system
CN101661586A (en) * 2009-09-29 2010-03-03 金蝶软件(中国)有限公司 Method of optimized data processing procedure and device thereof
CN103986772A (en) * 2014-05-23 2014-08-13 南京洛尧智慧信息技术有限公司 Army management system based on internet of things and cloud computing

Cited By (28)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN106487762B (en) * 2015-08-31 2019-12-13 腾讯科技(深圳)有限公司 user identity recognition method, identity recognition application client and server
CN106487762A (en) * 2015-08-31 2017-03-08 腾讯科技(深圳)有限公司 The recognition methodss of user identity, identification applications client and server
WO2017101385A1 (en) * 2015-12-14 2017-06-22 乐视控股(北京)有限公司 Access control identification method, device, system and terminal
CN107045684B (en) * 2016-02-06 2022-11-15 戴见霖 Identity recognition system and recognition method thereof
CN107045684A (en) * 2016-02-06 2017-08-15 戴见霖 Identification system and its recognition methods
CN105825642A (en) * 2016-05-25 2016-08-03 安徽远东网络科技有限公司 Community security information processing system
CN106453220A (en) * 2016-06-17 2017-02-22 四川师范大学 Butt joint type safety protection identification method
CN106373228B (en) * 2016-08-29 2019-02-19 杭州巴玺电子科技有限公司 A kind of passive lock system of intelligent and safe and its method for unlocking
CN106373228A (en) * 2016-08-29 2017-02-01 杭州巴玺电子科技有限公司 Intelligent safe passive lockset system and unlocking method thereof
KR102483742B1 (en) * 2016-09-30 2023-01-02 아싸 아브로이 에이비 Control access to physical space using a fingerprint sensor
US11094153B2 (en) 2016-09-30 2021-08-17 Assa Abloy Ab Controlling access to a physical space using a fingerprint sensor
CN109791714A (en) * 2016-09-30 2019-05-21 亚萨合莱有限公司 The access to physical space is controlled using fingerprint sensor
KR20190060790A (en) * 2016-09-30 2019-06-03 아싸 아브로이 에이비 Control access to physical space using fingerprint sensors
CN108022334A (en) * 2016-11-04 2018-05-11 法乐第(北京)网络科技有限公司 Garage access control system and garage door control method
CN108021851A (en) * 2016-11-04 2018-05-11 法乐第(北京)网络科技有限公司 Garage door control system and garage fingerprint base update method
CN106981119A (en) * 2017-05-05 2017-07-25 江苏速度信息科技股份有限公司 Entrance guard management system and method based on body shape
CN107330601A (en) * 2017-06-23 2017-11-07 深圳市盛路物联通讯技术有限公司 A kind of intelligent gun management method and device
CN108335387A (en) * 2018-01-23 2018-07-27 阿里巴巴集团控股有限公司 Face recognition door control system and access control method
CN110580754A (en) * 2018-06-11 2019-12-17 杭州海康威视系统技术有限公司 Face authentication method, device and system
CN109360301A (en) * 2018-09-05 2019-02-19 深圳中兴力维技术有限公司 Access control system and its control method
CN110021088A (en) * 2018-10-29 2019-07-16 深圳市微开互联科技有限公司 It is distributed the page control open-door system and method for authorization architecture
CN110021088B (en) * 2018-10-29 2021-06-29 深圳市微开互联科技有限公司 Page control door opening system and method of distributed authorization architecture
CN109712290A (en) * 2018-12-26 2019-05-03 广东中安金狮科创有限公司 Security system
CN113132106A (en) * 2019-12-30 2021-07-16 中国移动通信集团山西有限公司 User identity recognition system
CN113132106B (en) * 2019-12-30 2023-08-18 中国移动通信集团山西有限公司 User identity recognition system
CN112489282A (en) * 2020-12-02 2021-03-12 杭州国辰机器人科技有限公司 Entrance guard attendance checking method, system, computer equipment and storage medium
CN114724292A (en) * 2022-03-31 2022-07-08 合肥指南针电子科技有限责任公司 Prison management method
CN114724292B (en) * 2022-03-31 2023-08-22 合肥指南针电子科技有限责任公司 Prison management method

Also Published As

Publication number Publication date
CN104240342B (en) 2017-01-11

Similar Documents

Publication Publication Date Title
CN104240342A (en) Access control method and device
CN104240013A (en) Door access control method and door access control platform
US11276131B2 (en) Property management system utilizing a blockchain network
CN104240014A (en) Door access control method and door access control platform
CN105678872B (en) A kind of access control system and its authorization method and access control terminal equipment
CN108961475B (en) Access control deployment method and access control deployment server
CN111553767B (en) Shared house leasing system, method and storage medium based on block chain
CN111402578A (en) Shared vehicle monitoring method and device based on track monitoring and computer equipment
CN105809062A (en) Contract construction and execution methods and apparatuses
CN112398860A (en) Safety control method and device
RU2622883C2 (en) System and method for managing access to personal data
CN109544982B (en) Parking information sharing method and system
CN108351771A (en) Maintain the control for the restricted data during being deployed to cloud computing environment
CN110825776B (en) Air quality detection report processing method and device, computing equipment and storage medium
CN105491102A (en) Intelligent monitoring system based on cloud computing technology and device thereof
CN111932200A (en) Remote bidding evaluation system
CN111654375A (en) Block chain-based edge calculation security encryption method, device and system
CN112949798B (en) Laboratory equipment management method and system based on RFID technology
CN104704521A (en) Multi-factor profile and security fingerprint analysis
CN110097486A (en) A kind of movable police verification core recording system
CN111934881A (en) Data right confirming method and device, storage medium and electronic device
KR101920613B1 (en) Security policy and audit log bi-directional lookup, comparing and tracking system and method thereof
CN111798580A (en) Authority configuration method, device, system, server, terminal and storage medium
CN115640457A (en) Information management method, apparatus, device, medium, and program product
CN112650659B (en) Buried point setting method and device, computer equipment and storage medium

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
GR01 Patent grant
GR01 Patent grant
TR01 Transfer of patent right

Effective date of registration: 20190116

Address after: Room 1101, No. 7 Building, 98 Lianshi Lake West Road, Mentougou District, Beijing 102300

Patentee after: Beijing spaceflight morning letter Technology Co., Ltd.

Address before: 102308 No. 1 Yongan Road, Shilong Economic Development Zone, Mentougou District, Beijing

Patentee before: China Aerospace Ke Gong group the 4th research institute's command automation technical research and application center

TR01 Transfer of patent right