The invention relates to a security system for monitoring and/or controlling subsections in a monitoring area having at least one control device which is designed for the input and/or output of information and/or signals in one of the subsections, and having a communication network which is designed for the communication connection of the at least one control device, wherein the control device has a first Ethernet port for the communication with the communication network.
Entry control systems, for example in buildings, have the task of checking the authorization of a person who wishes to enter or leave the building or subsections thereof. While many installations involve only one entrance control, it is customary, particularly in the case of security-relevant areas, to define areas with different entry authorizations. It is also possible for buildings on a site to be provided with different entry authorizations. While a simple entrance control may have the entry control system positioned locally at the entrance, an entry control system having a plurality of subsections and having different authorizations requires distributed verification devices to be positioned in a decentralized manner. In order to be able to control said verification devices centrally, they are connected via a data network which can be used to initialize or update authorizations and to transmit verifications which have been performed.
By way of example, laid-open specification DE 100 012 53 A1 discloses an apparatus for the input and/or output of information, which apparatus is used for one of the following fields of application: time management, entry control, security engineering or building services. The apparatus is in the form of an installable unit and has a communication module which sets up the connection to a communication network. The communication takes place via an RS485 network or an LSN (local security network), for example.
The invention proposes a security system for monitoring and/or controlling subsections in a monitoring area.
The security system is preferably suitable and/or designed for implementing time management, entry control, security engineering and/or building services. The monitoring area may be in the form of a building, a plurality of buildings or a building complex, a space and/or another local environment. The subsections are preferably in the form of lock sections, which are embodied as turnstiles, doors, singularization devices or the like, for example.
The security system has at least one control device, preferably a plurality of such control devices, which is/are designed for the input and/or output of information and/or signals in one of the subsections. By way of example, the information may be authorization information which is transmitted to the control device for the purpose of verification and/or authorization checking. In particular, the information may be authorization information, such as the information on an authorization card, badge, etc. that has been read, an input authorization information item, such as a code, and/or a captured authorization information item, such as biometric data, for example. By way of example, the signals may be in the form of status signals and may relate particularly to the status of the lock (e.g. open/closed/impaired) and/or the activity of the lock (e.g. active/passive). With particular preference, the signals comprise control signals for opening and closing the lock.
The security system comprises a communication network which is designed for the communication connection of the at least one control device, particularly by means of the interchange of communication signals, so that the control device can interchange the information and/or the signals or other data via the communication network. The communication signals are preferably in the form of Ethernet data transmission blocks and/or in the form of digital signals.
The control device has a first Ethernet port for the communication with the communication network. The Ethernet port is preferably implemented as a 10 Mbit/s, 100 Mbit/s, 1 gigabit/s or 10 gigabit/s Ethernet port, particularly as a fast Ethernet port. Preferably, the Ethernet port is defined by means of the IEEE 802.3 standard.
The invention proposes that the control device has at least one second Ethernet port for the communication with the communication network. The second Ethernet port is preferably implemented under the same standard as the first Ethernet port and/or using the same design and/or the same functions.
One possible advantage of the invention is that the doubled Ethernet port can be used for redundant connection of the control device to the communication network. In particular, both the first and the second Ethernet port can be operated independently of the operational status of the respective other Ethernet port. The effect of the modification according to the invention is that the control device remains ready for operation even if a supply line to one of the two Ethernet ports is interrupted or impaired. In this context, it can be regarded as particularly advantageous that both network ports may be based on the same standard, which means that only the characteristics of a single standard, for example in respect of free cable length, shielding, etc., need to be considered during planning, assembly and startup.
In the most general embodiment, it is conceivable for the control device to be supplied locally with a supply voltage, e.g. via a dedicated power supply unit or a supply line. In one particularly preferred development of the invention, however, the first and/or the second Ethernet port is designed such that besides the communication signals a supply voltage for supplying the control device can be transmitted. In many embodiments, this type of transmission of the supply voltage can also be referred to as PoE (Power over Ethernet). The advantage of this addition is that the control device needs to have neither an autonomous supply voltage nor additional cables for providing a supply voltage.
In one particularly preferred development of the invention, a preferably analog supplementary signal can be transmitted in the first and/or in the second Ethernet port besides the communication signals of the Ethernet. Similarly to in the case of the supply voltage, this also exhibits the advantage that an additional signal can be transmitted without additional cabling complexity.
With particular preference, the supplementary signal is in the form of an alarm signal, particularly in the form of a fire alarm signal. For security reasons, many countries do not permit alarm signals, particularly fire alarm signals, to be transmitted by software in the normal communication data stream. Instead, it is prescribed for the alarm signal to be transmitted as a separate, preferably analog, signal. The fact that the first and/or second Ethernet port is/are designed for transmitting the supplementary signal means that the already available cables of the Ethernet can also be used for transmitting the supplementary signals.
With particular preference, the control device is connected to the communication network via the Ethernet ports by means of multicore, in particular eight-core, network cables. These network cables preferably have four twisted-pair cables with a total of eight cores, only four or six cores being used for the transmission of the Ethernet communication. The remaining four or two cores can, by contrast, be used for transmitting the supply voltage and/or the alarm signal. This means that commercially available, cheap and high-quality network cables can be used for the cabling of the communication device and it is nevertheless possible to transmit the supply voltage and the supplementary signal at the same time.
With particular preference, the Ethernet ports have sockets which are designed for eight-terminal (8P8C) modular connectors, particularly “RJ-45”. The modular connectors may be in unshielded, but preferably shielded, form.
In one possible development of the invention, provision is made for the control device to be designed to transmit the supplementary signal and/or the supply voltage in cores of the network cables which are used for the Ethernet communication. This modification has the possible advantage that both the supply voltage and the supplementary signal can be transmitted in a single network cable. Preferably, both network cables connected to the two Ethernet ports have this functionality. In this manner, a completely redundant system is formed, with the Ethernet communication, the supply voltage and the supplementary signal being transmitted redundantly.
The topology of the communication network may optionally have provision for two different network areas to be formed which work independently of one another, with the respective network area being associated with one of the Ethernet ports. In this embodiment, not only are the network cables made in redundant or semiredundant form, but also entire network areas are implemented in duplicate or redundant form in order to ensure that the security system functions even if a network area fails.
In particular, the communication network has a first master controller and a second, redundant master controller, the master controller and/or the second, redundant master controller both being designed for the communication with the control device. From the point of view of the network architecture, the master controller and the redundant master controller may be arranged in a common network area or else in two mutually independent network areas.
In one advantageous development of the invention, the control device is in the form of a lock and/or door control device which performs authorization control for these entry areas.
In one possible implementation of the invention, the control device comprises an operation control element for the input of a signal for opening the lock or the door, particularly a touch sensor and/or identification mark reader and/or interfaces for signal-related interconnection to the or a further operator control element or identification mark reader.
Further features, advantages and effects of the invention can be found in the description below of preferred exemplary embodiments of the invention and in the appended figures, in which:
The control devices 2 are in the form of local devices which are arranged in proximity to the door or lock that is to be controlled. For the purpose of communication with the communication network 3, the control device 2 has two separate Ethernet ports 4 which are connected to the communication network 3 via Ethernet cables 5. The control device 2 is designed such that the Ethernet cables 5 are used redundantly, so that in the event of damage or impairment to one of the two Ethernet cables 5, communication between a control device 2 and a communication network 3 is maintained.
A: Network communication and supply voltage
B: Network communication and supplementary signal
C: Network communication and supplementary signal and supply voltage
Depending on the desired configuration, the two Ethernet ports 4 may be of completely redundant design by virtue of the them both being designed on the basis of option A or B or else C. In case B, the supply voltage would be provided by means of an autonomous supply voltage for the control device 2, for example. Alternatively, hybrid operation is also possible, with, for example, the first Ethernet port 4 being operated on the basis of option A and the second Ethernet port 4 being operated on the basis of option B. In principle, it is also possible for further Ethernet ports 4 to be integrated into the control device 2.
In a second layer II, one or more main entry control devices 7 (Main Access Controller) are implemented which communicate with the control devices 2 and receive information about the position of persons in the monitoring area, for example. The main entry control devices may be designed to supply 64 control devices 2 with communication signals, for example.
Such a security system 1 may contain a plurality of main entry control devices 7, with one such main entry control device 7 being provided for each building to be monitored or for each more complex area to be monitored, for example. In addition, the layer II may contain a signal supply device 8 which feeds the supply voltage and/or the supplementary signal into the Ethernet cables 5. Optionally, the signal supply device 8 or the layer II generally has an uninterruptable power supply 9 for safeguarding the supply voltage.
A third layer III accommodates the control devices 2, which comprise a plurality of inputs and outputs for the monitoring and control of the doors and possibly devices for reading identification marks, such as identification cards. In the case of the architecture shown in
By contrast,
In a further architecture, which is indicated in
Through the use of two Ethernet ports 4 per control device 2, preferably each with PoE capability, the invention permits inexpensive implementation of a security system 1 which can be designed with complete redundancy, which meets the requirements of security applications and which can optionally transmit a fire alarm signal in accordance with the regulations.
Number | Date | Country | Kind |
---|---|---|---|
10 2009 001 177.3 | Feb 2009 | DE | national |
Filing Document | Filing Date | Country | Kind | 371c Date |
---|---|---|---|---|
PCT/EP10/52150 | 2/19/2010 | WO | 00 | 11/4/2011 |