<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE ep-patent-document PUBLIC "-//EPO//EP PATENT DOCUMENT 1.4//EN" "ep-patent-document-v1-4.dtd">
<ep-patent-document id="EP13150935B1" file="EP13150935NWB1.xml" lang="en" country="EP" doc-number="2581888" kind="B1" date-publ="20140319" status="n" dtd-version="ep-patent-document-v1-4">
<SDOBI lang="en"><B000><eptags><B001EP>ATBECHDEDKESFRGBGRITLILUNLSEMCPTIESILTLVFIRO..CY..TRBGCZEEHUPLSK....IS..MT..........................</B001EP><B005EP>J</B005EP><B007EP>DIM360 Ver 2.40 (30 Jan 2013) -  2100000/0</B007EP></eptags></B000><B100><B110>2581888</B110><B120><B121>EUROPEAN PATENT SPECIFICATION</B121></B120><B130>B1</B130><B140><date>20140319</date></B140><B190>EP</B190></B100><B200><B210>13150935.8</B210><B220><date>20070510</date></B220><B240><B241><date>20130520</date></B241></B240><B250>en</B250><B251EP>en</B251EP><B260>en</B260></B200><B300><B310>446523</B310><B320><date>20060602</date></B320><B330><ctry>US</ctry></B330><B310>446570</B310><B320><date>20060602</date></B320><B330><ctry>US</ctry></B330></B300><B400><B405><date>20140319</date><bnum>201412</bnum></B405><B430><date>20130417</date><bnum>201316</bnum></B430><B450><date>20140319</date><bnum>201412</bnum></B450><B452EP><date>20130920</date></B452EP></B400><B500><B510EP><classification-ipcr sequence="1"><text>G08B  13/196       20060101AFI20130605BHEP        </text></classification-ipcr></B510EP><B540><B541>de</B541><B542>Systeme und Verfahren zur verteilten Überwachung entfernter Orte</B542><B541>en</B541><B542>Systems and methods for distributed monitoring of remote sites</B542><B541>fr</B541><B542>Systèmes et procédés pour la surveillance répartie de sites à distance</B542></B540><B560><B561><text>US-A1- 2002 110 264</text></B561><B561><text>US-A1- 2005 162 515</text></B561></B560></B500><B600><B620><parent><pdoc><dnum><anum>07794745.5</anum><pnum>2030180</pnum></dnum><date>20070510</date></pdoc></parent></B620></B600><B700><B720><B721><snm>Buehler, Christopher J.</snm><adr><str>84 Clifton Street</str><city>Cambridge MA 02140</city><ctry>US</ctry></adr></B721></B720><B730><B731><snm>Sensormatic Electronics, LLC</snm><iid>101426755</iid><irf>PB140262EPA</irf><adr><str>1501 Yamato Road</str><city>Boca Raton, FL 33431</city><ctry>US</ctry></adr></B731></B730><B740><B741><snm>Hackett, Sean James</snm><iid>101030768</iid><adr><str>Marks &amp; Clerk LLP 
Alpha Tower 
Suffolk Street Queensway</str><city>Birmingham B1 1TT</city><ctry>GB</ctry></adr></B741></B740></B700><B800><B840><ctry>AT</ctry><ctry>BE</ctry><ctry>BG</ctry><ctry>CH</ctry><ctry>CY</ctry><ctry>CZ</ctry><ctry>DE</ctry><ctry>DK</ctry><ctry>EE</ctry><ctry>ES</ctry><ctry>FI</ctry><ctry>FR</ctry><ctry>GB</ctry><ctry>GR</ctry><ctry>HU</ctry><ctry>IE</ctry><ctry>IS</ctry><ctry>IT</ctry><ctry>LI</ctry><ctry>LT</ctry><ctry>LU</ctry><ctry>LV</ctry><ctry>MC</ctry><ctry>MT</ctry><ctry>NL</ctry><ctry>PL</ctry><ctry>PT</ctry><ctry>RO</ctry><ctry>SE</ctry><ctry>SI</ctry><ctry>SK</ctry><ctry>TR</ctry></B840><B880><date>20130417</date><bnum>201316</bnum></B880></B800></SDOBI>
<description id="desc" lang="en"><!-- EPO <DP n="1"> -->
<heading id="h0001"><b><u>Technical Field</u></b></heading>
<p id="p0001" num="0001">This invention relates to computer-based methods and systems for monitoring activities, and more specifically to a computer-aided surveillance system capable of detecting events occurring at multiple sites.</p>
<heading id="h0002"><b><u>Background Information</u></b></heading>
<p id="p0002" num="0002">The current heightened sense of security and declining cost of monitoring equipment have resulted in increased use of surveillance systems using technologies such as closed-circuit television (CCTV). Such systems have the potential to reduce crime, prevent accidents, and generally increase security in a wide variety of environments. Video surveillance systems typically include a series of cameras placed in various locations about an area of interest (e.g., a warehouse, a retail establishment, an office building, an airport, for example). The cameras transmit video feeds back to a central viewing stations (or multiple stations), typically manned by a security officer. The various surveillance feeds are displayed on a series of screens, which are monitored for suspicious activities.</p>
<p id="p0003" num="0003">In addition to using CCTV systems at individual locations, there is great interest in using video surveillance and analysis systems to collect data about the behavior of people across multiple locations. For example, a national retail store chain might be interested in the<!-- EPO <DP n="2"> --> behavior of shoppers in its various stores. While data collected from a single site is useful, the full value of the data is only realized when comparing data from different sites, such as providing insights into how to optimally deploy resources across multiple locations at or within a site to achieve specific goals.</p>
<p id="p0004" num="0004">In order to be useful, however, the data from one location should be comparable to data collected at other similar locations. That is, the same events (e.g., "person paused in front of display") should have a consistent meaning at each location. However, because of non-standard floor-plans, variable camera configurations, and other site differences, the occurrence of an event can appear quite different (from the point-of-view of a surveillance system) at each location. Such differences make it difficult for a single person (e.g., a chief security officer or corporate marketing analyst) to specify an event at the level of detail needed in order to reliably detect the event at multiple disparate locations.</p>
<p id="p0005" num="0005">One approach to dealing with the problem of non-uniform locations is to have a global operator interact with a surveillance system at each individual site to define events of interest. While this approach has the advantage that events can be centrally controlled and managed, time and resource constraints prohibit the scalability across many sites. Another approach requires that similar locations across all sites be identical, both in floor-plan and sensor placement. Although this approach allows a global operator to centrally define events of interest and replicate the events across all locations, requiring all locations to be identical is not practical. A third approach places the responsibility of event definition in the hands of local site operators, but such an approach relinquishes any element of centralized control and significantly reduces data consistency across sites.</p>
<p id="p0006" num="0006">Unfortunately, none of these approaches is sufficient. What is needed, therefore, is a technique for centrally defining and managing events at a global level while allowing<!-- EPO <DP n="3"> --> variability among location layouts and camera configurations.</p>
<p id="p0007" num="0007"><patcit id="pcit0001" dnum="US2005016525A1"><text>US Patent Publication 2005/016525 A1</text></patcit> describes a video surveillance system which can undertake a response, such as an alarm, based on extracted event occurrences.</p>
<heading id="h0003"><b><u>Summary</u></b></heading>
<p id="p0008" num="0008">In accordance with the invention, rules are applied to surveillance data (e.g., video surveillance data, point-of-sale ("POS") data, radio frequency identification ("RFID") data, electronic article surveillance ("EAS") data, personnel identification data such as proximity card data and/or biometrics, etc.) to detect the occurrence (or non-occurrence) of an event. To facilitate both centralized control and localization simultaneously, event definition is separated into multiple components, with certain components being defined globally, and other components defined locally. The global components of an event can describe, for example, the aspects of the event that are identical (or nearly identical) across all (or some large set) of locations. The local components describe aspects of the event that can be customized for each location.</p>
<p id="p0009" num="0009">For example, using the systems and techniques described below, a central security authority can create an event definition "template" that includes global, concrete information about some event of interest (e.g., theft, vandalism, purchase, etc.) as well as "placeholders" for localized event information to be completed by operators at remote sites, who typically will have greater knowledge about product placement, camera placement, floor-plans, etc. The template is provided to the sites and implemented as part of the site's surveillance system. The local system operator completes the template, and an acknowledgment is sent to the central authority indicating that the event has been fully defined and being used for ongoing surveillance.</p>
<p id="p0010" num="0010">Accordingly, in a first aspect, the invention provides a method for facilitating monitoring multiple disparate sites that includes providing a set of rules describing events of<!-- EPO <DP n="4"> --> interest. The rules have multiple components, some of which are site-specific components, whereas other components are site-independent. The site-independent components are defined globally and the rules are then distribute at the multiple sites, thereby facilitating the definition of the site-specific components and the monitoring of the site using the rules.</p>
<p id="p0011" num="0011">The site-specific components can specify locations about the sites, floor-plan data, sensor identification data (e.g., camera IDs, RFID sensor IDs, POS sensor IDs, and/or EAS sensor IDs), or any combination thereof. The site independent components can specify actions occurring at the sites, objects placed about the sites and/or people interacting with objects about the site.</p>
<p id="p0012" num="0012">In some embodiments, alerts indicating the occurrence of events at the sites are received from the sites. The alerts can be aggregated to facilitate, for example, statistical analysis of the alerts such as determining an average number of alerts received from certain sites during a predefined time period. Specific analysis can, for example, determine if the site-specific components of the rules are suboptimal and/or if inconsistently applied across the sites. In some cases, changes to the site-specific components suggest by the analysis can be distributed to the sites at which inconsistencies are observed. Secondary alerts can also be generated (either centrally or remotely) and transmitted to a remote site, which can be a site from which one or more of the initial alerts was generated, or a different site. In some instances, the different site can be identified based on an inferred relationship among the events and/or sites from which the alerts were received. The site-specific components can also be sent to a central authority for approval and/or publication.</p>
<p id="p0013" num="0013">In addition to (or instead of) receiving alerts, surveillance data can be received from the different sites. In such cases, the rules are applied against the surveillance data in order to detect the occurrence (or non-occurrence) of events of interest, thus generating alerts that can<!-- EPO <DP n="5"> --> be aggregated and/or analyzed as described above.</p>
<p id="p0014" num="0014">In another aspect, the invention provides a system for monitoring multiple disparate sites including a rule-definition module and a transmission module. The rule-definition module facilitates the creation of rules that describe various events that may (or may not) occur at the sites. The rules include both site-specific components (e.g., floor-plan data, locations, camera position information, etc.) and site-independent components (such as actions occurring at the site, objects at the site, and people interacting with objects at the monitored site, for example). The transmission module transmits the rules to the monitored sites, where the environment-specific locational components can be defined.</p>
<p id="p0015" num="0015">In some embodiments, a web server can be used to provide remotely located clients, each associated with (and usually located at) a particular site, with access to the rule-definition module. In some cases the web server governs access granted to the remote clients, restricting them, for example, such that they can only modify site-specific components or access a subset of the components. The transmission module can also receive data (e.g., from the monitored environments) such as alerts that indicate the occurrence of an event at a location as well as sensor data such as video, RFID data, EAS data and POS data. The system can also, in some embodiments, include an analysis module for determining the accuracy and consistency of the environment-specific components by, for example, aggregating the received data for statistical analysis, comparing the number of alerts received from the monitored locations, and identifying inconsistencies within the received alerts and/or surveillance data. Based on the identified-inconsistencies, modifications can be made to the rules (using, for example, the rule-definition module), and in some cases redistributed to the remote sites via the transmission module. The system can also include a data storage module for storing video surveillance data, the rules, the results of analyses performed by the analysis module, as well<!-- EPO <DP n="6"> --> as other application-specific data.</p>
<p id="p0016" num="0016">In another aspect, the invention provides a method for monitoring sites that includes providing a canonical site layout that specifies an element or elements that are common to some number of the sites. Events are assigned to the elements without regard to the actual layout of the sites, resulting in an annotated canonical site layout. The annotated layout is then transmitted to a user who is familiar with the site to which the layout was sent, and the user can then modify the canonical site layout (using, for example, a downloadable applet such as an AJAX applet) such that it is consistent with the actual site layout, and can be used to monitor the site.</p>
<p id="p0017" num="0017">The elements can specify locations about the sites such floor plan data. The events assigned to the canonical floor plan can be site-specific (e.g., sensor identification data such as camera IDs, RFID sensor IDs, POS sensor IDs, and/or EAS sensor IDs) and/or site independent, such as a location (exit, aisle way, etc.) or an interaction between a person and an element (e.g., a customer stopping at a product display).</p>
<p id="p0018" num="0018">In some embodiments, the modified layout can be used within a surveillance system (at one or more of the sites, for example) as a basis for generating alerts based on the occurrence of the events. The alerts can be analyzed to determine, for example, the accuracy of the events and/or floor plan.</p>
<p id="p0019" num="0019">In another aspect, the invention provides a system for monitoring sites including a user interface and a modification module. The user interface includes a canonical site layout pane in which site-independent elements are associated with the canonical site layout, and a pane in which an actual, site-specific layout is presented to the user. The modification module facilitates the association of site-independent elements with site-specific elements of the actual site layout.<!-- EPO <DP n="7"> --></p>
<p id="p0020" num="0020">In some embodiments, the modification module comprises an asynchronous java script applet. The system can also include a web server for providing the applet to users and for processing data requests from the applet, using, for example, XML. A data storage module can also be used to fulfill data requests made by modification module and submitted via the web server.</p>
<heading id="h0004"><b><u>Brief Description of the Drawings</u></b></heading>
<p id="p0021" num="0021">In the drawings, like reference characters generally refer to the same parts throughout the different views. Also, the drawings are not necessarily to scale, emphasis instead generally being placed upon illustrating the principles of the invention.
<ul id="ul0001" list-style="none" compact="compact">
<li><figref idref="f0001">FIG. 1</figref> is a block diagram of a surveillance system incorporating data from multiple sensor networks according to one embodiment of the invention.</li>
<li><figref idref="f0002">FIG. 2</figref> is a block diagram of an embodiment of a surveillance system having both centralized and remote processing capabilities according to one embodiments of the invention.</li>
<li><figref idref="f0003">FIG. 3</figref> is an illustration of various components used to define events within a surveillance system according to one embodiment of the invention.</li>
<li><figref idref="f0004">FIG. 4</figref> is a flow chart depicting a method for implementing a surveillance system according to one embodiment of the invention.</li>
<li><figref idref="f0005">FIG. 5</figref> is a flow chart depicting additional steps of a method for implementing a surveillance system according to one embodiment of the invention.</li>
<li><figref idref="f0006">FIG. 6</figref> is a flow chart depicting additional steps of a method for implementing a surveillance system according to one embodiment of the invention.</li>
<li><figref idref="f0007">FIG. 7</figref> is a screen capture of a user interface for implementing a surveillance system according to one embodiment of the invention.<!-- EPO <DP n="8"> --></li>
<li><figref idref="f0008">FIG. 8</figref> is a representation of a user interface for defining floor-plan templates for a surveillance system according to one embodiment of the invention.</li>
<li><figref idref="f0009">FIG. 9</figref> is a screen capture of a user interface for defining location components of an event within a surveillance system according to one embodiment of the invention.</li>
<li><figref idref="f0010">FIG. 10</figref> is a screen capture of a user interface for defining events within a surveillance system according to one embodiment of the invention.</li>
<li><figref idref="f0011">FIG. 11</figref> is a screen capture of a user interface for modifying events within a surveillance system according to one embodiment of the invention.</li>
<li><figref idref="f0012">FIG. 12</figref> is representation of a user interface for attributing site-specific components to events within a surveillance system according to one embodiment of the invention.</li>
<li><figref idref="f0013">FIG. 13</figref> is representation of a user interface for customizing a site-specific floor-plan using a floor-plan template within a surveillance system according to one embodiment of the invention.</li>
</ul></p>
<heading id="h0005"><b><u>Detailed Description</u></b></heading>
<p id="p0022" num="0022">Although described herein with reference to tracking patrons and products within retail establishments, and as useful when implemented with regard to detecting theft and measuring various merchandising and operational aspects of stores, the systems and techniques described below are equally applicable to any environment being monitored, such as airports, casinos, schools, amusement parks, entertainment venues, and office buildings for a wide range of purposes.</p>
<p id="p0023" num="0023"><figref idref="f0001">FIG. 1</figref> illustrates an integrated video surveillance and sensor network system <b>100</b> in accordance with various embodiments of the invention. The system <b>100</b> captures surveillance data from any number of monitoring devices within one or more monitored sites, the data thus<!-- EPO <DP n="9"> --> being available for analysis and/or processing locally (at each monitoring device, at a local processor or both), at a single centralized location and/or at any number of intermediate data processing locations. In some embodiments, the processing and analysis techniques described below can be allocated among remote, intermediate and centralized sites according to bandwidth, processing capacities, and other parameters. Data from the monitoring devices can be processed according to one or more rules in order to detect the occurrence (or in some cases non-occurrence) of an event or events at the monitored sites. The system broadly includes an intelligent video surveillance system <b>105</b> and optionally one or more external sensor networks <b>110</b>. The intelligent video surveillance system <b>105</b> includes a video processing module <b>115</b> and an alert/search processing module <b>120</b>. The video processing module <b>115</b> analyzes video streams, producing compressed video and video meta-data as outputs. In some embodiments, the alert/search processing module <b>120</b> includes a tracking module <b>130</b>, an alert module <b>135</b> and a transmission module <b>140</b> and scans video metadata for patterns that match a set of predefined rules, producing alerts (or search results, in the case of prerecorded metadata) when pattern matches are found which can then be transmitted to one or more output devices <b>145</b> (described in greater detail below). Examples of metadata used by the alert module when processing the rules include object IDs, object type (e.g., person, product, etc.) date/time stamps, current camera location, previous camera locations, directional data, product cost, product shrinkage, as well as others.</p>
<p id="p0024" num="0024">One example of an intelligent video surveillance system <b>105</b> is described in commonly-owned, co-pending <patcit id="pcit0002" dnum="US706850A" dnum-type="L"><text>U.S. Patent Application Serial No. 10/706,850</text></patcit>, "Method And System For Tracking And Behavioral Monitoring Of Multiple Objects Moving Through Multiple Fields-Of-View,". In certain implementations, the alert/search processing module <b>120</b> is augmented with additional<!-- EPO <DP n="10"> --> inputs for receiving data from external sensor networks <b>110</b> using various forms of tracking and data capture, such as point-of-sale ("POS") systems, radio frequency identification ("RFID") systems, and/or electronic article surveillance ("EAS") systems, as described in commonly-owned, co-pending <patcit id="pcit0003" dnum="US44350006A" dnum-type="L"><text>U.S. Patent Application Serial No. 11/443,500</text></patcit>, "Object Tracking and Alerts," filed on May 30, 2006.</p>
<p id="p0025" num="0025">The video surveillance system <b>105</b> includes multiple input sensors <b>125</b> that capture data depicting the interaction of people and things in a monitored environment The sensors <b>125</b> can include both cameras (e.g., optical sensors, infrared detectors, still cameras, analog video cameras, digital video cameras, or any device that can generate image data of sufficient quality to support the methods described below) and non-video based sensors (e.g,, RFID base stations, POS scanners and inventory control systems). The sensors can also include smoke, fire and carbon monoxide detectors, door and window access detectors, glass break detectors, motion detectors, audio detectors, infrared detectors, computer network monitors, voice identification devices, video cameras, still cameras, microphones and/or fingerprint, facial, retinal, or other biometric identification devices. In some instances, the sensors can include conventional panic buttons, global positioning satellite (GPS) locators, other geographic locators, medical indicators, and vehicle information systems. The sensors can also be integrated with other existing information systems, such as inventory control systems, accounting systems, or the like.</p>
<p id="p0026" num="0026">In instances in which additional external sensor networks <b>110</b> are implemented in conjunction with the video surveillance system <b>105</b>, external sensor networks <b>110</b> collect and route signals representing the sensor outputs to the alert/search processing module <b>120</b> of the video surveillance system <b>105</b> via one or more standard data transmission techniques. The<!-- EPO <DP n="11"> --> signals can be transmitted over a LAN and/or a WAN (e.g., TI, T3, 56kb, X.25), broadband connections (ISDN, Frame Relay, ATM), wireless links (802.11, Bluetooth, etc.), and so on. In some embodiments, the video signals may be encrypted using, for example, trusted key-pair encryption. Different sensor systems may transmit information using different communication pathways such as Ethernet or wireless networks, direct serial or parallel connections, USB, firewire, Bluetooth, or proprietary interfaces. The system <b>100</b> can be configured as a "star-shaped network" in which each sensor <b>125</b> is individually connected to the alert/search module <b>120</b>, or in some cases, the sensor network <b>110</b> may have a more generic topology including switches, routers, and other components commonly found in computer networks. In some embodiments, the sensors <b>125</b> are capable of two-way communication, and thus can receive signals (to power up, sound an alert, move, change settings, etc.) from the video surveillance system <b>105</b>.</p>
<p id="p0027" num="0027">In some embodiments, the system <b>100</b> includes a video storage module <b>150</b> and a rules/metadata storage module <b>155</b>. The video storage module <b>150</b> stores video captured from the video surveillance system <b>105</b>. The video storage module <b>150</b> can include VCRs, DVRs, RAID arrays, USB hard drives, optical disk recorders, flash storage devices, image analysis devices, general purpose computers, video enhancement devices, de-interlacers, scalers, and/or other video or data processing and storage elements for storing and/or processing video. The video signals can be captured and stored in various analog and/or digital formats, including, as examples only, Nation Television System Committee (NTSC), Phase Alternating Line (PAL), and Sequential Color with Memory (SECAM), uncompressed digital signals using DVI or HDMI connections, and/or compressed digital signals based on a common codec format (e.g., MPEG, MPEG2, MPEG4, or H.264).<!-- EPO <DP n="12"> --></p>
<p id="p0028" num="0028">The rules/metadata storage module <b>150</b> stores metadata captured from the video surveillance system <b>105</b> and the external sensor networks <b>110</b> as well as rules against which the metadata is compared to determine if alerts should be triggered. The rules/metadata storage module <b>155</b> can be implemented on a server class computer that includes application instructions for storing and providing alert rules to the alert/search processing module <b>120</b>. Examples of database applications that can be used to implement the video storage module <b>150</b> and/or the rules/metadata storage module <b>155</b> the storage include MySQL Database Server by MySQL AB of Uppsala, Sweden, the PostgreSQL Database Server by the PostgreSQL Global Development Group of Berkeley, CA, or the ORACLE Database Server offered by ORACLE Corp. of Redwood Shores, CA. In some embodiments, the video storage module <b>150</b> and the rules/metadata storage module <b>155</b> can be implemented on one server using, for example, multiple partitions and/or instances such that the desired system performance is obtained.</p>
<p id="p0029" num="0029">A variety of external sensor networks <b>110</b> can provide data to the system <b>100</b>. For example, POS networks involve of a number of stations (e.g., cash registers, scanners, etc.) connected to a network and when activated, sensors in the stations transmit a customer's transaction information (product, price, customer ID, etc.) as well as the status of the cash drawer (e.g., open.or closed) to the network. Similarly, EAS networks typically include a number of pedestals situated near the exits of a retail store that sense the presence of activated EAS tags placed on high-value (or in some cases all) products. When the presence of a tag is detected, the pedestal transmits information over the network to a central location. Many commercial buildings also employ security systems that sense the opening and closing of doors and use "card-swipe" systems that require employees to swipe or present identification cards when entering or leaving the facility. In accordance with the present invention, some or all of these sensor-based monitoring systems <b>110</b> are integrated with the video surveillance<!-- EPO <DP n="13"> --> system <b>105</b> to enhance its capabilities and accuracy. Of course, the above list of sensor types is not exhaustive, and merely provides examples of the types of sensor networks <b>110</b> that can be accommodated.</p>
<p id="p0030" num="0030">In one non-limiting example, the sensor network <b>110</b> includes an RFID subsystem that itself includes transmitters (also referred to as "base stations" or "stations") that interact with transponders placed on objects being tracked by the surveillance system 100. The stations intermittently (every <i>n<sup>th</sup></i> millisecond, for example, where <i>n</i> is a selected integer) transmit RF energy within some effective radius of the station. When a transponder enters this effective radius, the RF energy "wakes up" the transponder, which then interacts therewith to impart an identification signal to the station. The signal typically includes various information about the object to which the transponder is attached, such as a SKU code, a source code, a quantity code, etc. This data is augmented with information from the transmitter (e.g., a transmitter ID and date/timestamp), and can be saved as a unique record. By placing multiple transmitters about an area (throughout a store or warehouse, for example), the RFID subsystem can be used to determine the location and path of an object carrying the RFID tag using the coordinates of the transmitters and the times they interacted with the transponder.</p>
<p id="p0031" num="0031">In some embodiments, the alerts created by the alert/search processing module <b>120</b> can be transmitted to output devices <b>145</b> such as smart or dumb terminals, network computers, wireless devices (e.g., hand-held PDAs), wireless telephones, information appliances, workstations, minicomputers, mainframe computers, or other computing devices that can be operated as a general purpose computer, or a special purpose hardware device used solely for serving as an output devices <b>145</b> in the system <b>100</b>. In one example, security officers are provided wireless output devices <b>145</b> with text, messaging, and video capabilities as they patrol a monitored environment. As alerts are generated, messages are transmitted to the output<!-- EPO <DP n="14"> --> devices <b>145</b>, directing the officers to a particular location. In some embodiments, video can be included in the messages, providing the patrol officers with visual confirmation of the person or object of interest.</p>
<p id="p0032" num="0032">In some embodiments, the output devices <b>145</b> can also include geographic information services (GIS) data. In such implementations, maps and/or floor-plans (either actual photographs or graphical repreesntations thereof) are combined with iconic and textual information describing the environment and objects within the environment. For example, security personnel working at a large retail store can be provided with wireless, hand-held devices (such as the SAMSUNG SCH i730 wireless telephone) which are capable of rendering still and/or video graphics that include a floor-plan and/or parking areas near the store. Using GPS coordinates obtained via similar devices (or, in some cases, RFID base stations located throughout the store), the locations of various displays, personnel, vendors, or groups can be determined and displayed as a map of the store. In this way, features common to all sites but possibly situated in different locations can be mapped with respect to each site.</p>
<p id="p0033" num="0033">As the system <b>100</b> analyzes movements of customers and other objects, the alert/search processing module <b>120</b> uses metadata received from the video surveillance system <b>115</b> and the external sensor networks <b>110</b> to determine if one or more rules are met, and if so, generates alerts. As one example, an object ID associated with a customer and a product ID associated with a product of interest can be linked using manual association and/or automatic techniques (based, for example, on repeated detection of the two objects in close proximity). If the product and the customer are determined to be co-located (either repeatedly, continuously, or at some defined interval), an alert can be generated indicating the customer has placed the product in her shopping cart. A subsequent indication that the product was sensed at an RFID station at the exit of the store, and the absense of an indication that the product was scanned at<!-- EPO <DP n="15"> --> a POS station, may indiciate a shoplifting event. The alert can then transmitted to the security personnel, who, using the GIS-enabled devices, can see the location of the product and the customer on the store floor-plan.</p>
<p id="p0034" num="0034">In some embodiments, additional data can be added to the display, such as coloring to represent crowd density or a preferred path, to further facilitate quick movement of security personnel to a particular locations. Color enhancements can also be added to indicate the speed at which an object is moving, or the degree of threat the object poses to the monitored environment. In some cases, updates can be transmitted to the display to provide a real-time (or near-real-time) representation of the events and objects being monitored.</p>
<p id="p0035" num="0035"><figref idref="f0002">FIG. 2</figref> illustrates an exemplary implementation 200 of the invention in which multiple video surveillance and sensor network systems <b>100</b> are deployed in a distributed fashion to facilitate monitoring multiple sites. As illustrated, the distributed video surveillance and sensor network system <b>100</b> includes at least one centralized site <b>205</b>, and at multiple remote sites <b>210</b>, <b>210</b>', <b>210</b>" (generally, <b>210</b>) that communicate over a network <b>215</b>. As shown, the system includes three remote sites, but this is only for exemplary purposes, and infact there can be any number of sites <b>210</b>. Each remote site can include one or more components <b>220</b>, <b>220</b>', <b>220</b>" (generally, <b>220</b>) of the video surveillance and sensor network system <b>100</b> such as local client software <b>225</b> and/or one or more sensor networks <b>230</b> for monitoring the remote site. In some implementations, a complete implementation of the intelligent video surveillance system <b>105</b> can reside at each (or some) of the remote sites <b>210</b>. For example, certain remote sites (e.g., warehouses, stores located in large metropolitan areas, etc.) may be large enough to warrant a complete implementation of the system, whereas implementations at other, typically smaller sites may be limited to the sensor devices which transmit captured data to the central site <b>205</b>. In some implementations, multiple remote sites <b>210</b> provide video<!-- EPO <DP n="16"> --> and/or sensor network data to some number (typically greater than one, and less than the number of remote sites) of intermediate sites for processing, analysis and/or storage.</p>
<p id="p0036" num="0036">The local client software <b>225</b> can facilitate remote connections to a server at the central site <b>205</b>. In such embodiments, the local client software <b>225</b> can include a web browser, client software, or both. The web browser allows users at a remote site <b>210</b> to request web pages or other downloadable programs, applets, or documents (e.g., from the central site <b>205</b> and/or other remote sites <b>210</b>) with a web-page request. One example of a web page is a data file that includes computer-executable or interpretable information, graphics, sound, text, and/or video, that can be displayed, executed, played, processed, streamed, and/or stored and that can contain links, or pointers, to other web pages. In one embodiment, a user of the local client software <b>225</b> manually requests a web page from the central site <b>205</b>. Alternatively, the local client software <b>225</b> can automatically make requests with the web browser. Examples of commercially available web browser software include INTERNET EXPLORER, offered by Microsoft Corporation, NETSCAPE NAVIGATOR, offered by AOL/Time Warner, or FIREFOX offered the Mozilla Foundation.</p>
<p id="p0037" num="0037">The local client software <b>225</b> can also include one or more applications that allow a user to manage components of the sensor network <b>230</b> and/or the rules relating to the monitoring of that particular site <b>210</b>. The applications may be implemented in various forms, for example, in the form of a Java applet that is downloaded to the client and runs in conjunction with a web browser, or the application may be in the form of a standalone application, implemented in a multi-platform language such as Java, visual basic, or C, or in native processor-executable code. In one embodiment, if executing on a client at a remote site <b>210</b>, the application opens a network connection to a server at the central site <b>205</b> over the communications network <b>215</b> and communicates via that connection to the server. In one<!-- EPO <DP n="17"> --> particular example, the application may be implemented as an information screen within a separate application using, for example, asynchronous JavaScript and XML ("AJAX") such that many of the user-initiated actions are processed at the remote site. In such cases, data may be exchanged with the central site <b>205</b> behind the scenes and any web pages being viewed by users at the remote sites need not be reloaded each time a change is made, thus increasing the interactivity, speed, and usability of the application.</p>
<p id="p0038" num="0038">For example, the remote sites <b>210</b> can implement the local software <b>225</b> on a personal computer (e.g., a PC with an INTEL processor or an APPLE MACINTOSH) capable of running such operating systems as the MICROSOFT WINDOWS family of operating systems from Microsoft Corporation of Redmond, Washington, the MACINTOSH operating system from Apple Computer of Cupertino, California, and various varieties of Unix, such as SUN SOLARIS from SUN MICROSYSTEMS of Santa Clara, California, and GNU/Linux from RED HAT, INC. of Durham, North Carolina (and others). The local software <b>225</b> can also be implemented on such hardware as a smart or dumb terminal, networks computer, wireless device, wireless telephone, information appliance, workstation, minicomputer, mainframe computer, or other computing device that is operated as a general purpose computer or a special purpose hardware device used solely for serving as a client in the surveillance system.</p>
<p id="p0039" num="0039">The central site <b>205</b> interacts with the systems at each of the remote sites <b>210</b>. In one embodiment, portions of the video surveillance and sensor network system <b>100</b> such as the intelligent video surveillance system <b>105</b> are implemented on a server <b>240</b> at the central site <b>205</b>. In such instances, the server <b>240</b> is preferably implemented on one or more server-class computers that have sufficient memory, data storage, and processing power and that run a server class operating system (e.g., SUN Solaris, GNU/Linux, and the MICROSOFT WINDOWS family of operating systems). System hardware and software other than that<!-- EPO <DP n="18"> --> described herein may also be used, depending on the capacity of the device and the number of sites and the volume of data being received and analyzed. For example, the server <b>240</b> may be or may be part of a logical group of one or more servers such as a server farm or server network. As another example, there can be multiple servers that may be associated or connected with each other, or multiple servers can operate independently, but with shared data. In a further embodiment and as is typical in large-scale systems, application software can be implemented in components, with different components running on different server computers, on the same server, or some combination. In some embodiments, the server <b>240</b> may be implemented at and operated by a service bureau or hosting service on behalf of different, sometimes unrelated entities who wish to outsource such services.</p>
<p id="p0040" num="0040">The communications network <b>215</b> connects the remote implementations with the server <b>240</b> using a transmission module <b>245</b> at the central site <b>205</b>. Non-limiting examples of applications capable of performing the functions of the transmission module include the APACHE Web Server and the WINDOWS -INTERNET INFORMATION SERVER The communication may take place via any media and protocols such as those described above with respect to <figref idref="f0001">FIG. 1</figref>. Preferably, the network <b>215</b> can carry TCP/IP protocol communications, and HTTP/HTTPS requests made by the local software and/or the server and the connection between the local software <b>225</b> and the server <b>240</b> can be communicated over such TCP/IP networks. The type of network is not a limitation, however, and any suitable network may be used. Non-limiting examples of networks that can serve as or be part of the communications network <b>215</b> include a wireless or wired Ethernet-based intranet, a local or wide-area network (LAN or WAN), and/or the global communications network known as the Internet, which may accommodate many different communications media and protocols.</p>
<p id="p0041" num="0041">In embodiments in which some or all of the processing and analysis is performed at the<!-- EPO <DP n="19"> --> central site <b>205</b>, the server <b>240</b> can also include various application modules for the definition, storage and analysis of data and rules relating to the monitoring of the remote sites <b>210</b>. For example, a definition module <b>250</b> facilitates the definition of rules relating to events of interest that may occur at the remote sites and floor-plans for attributing the rules to sites (either in general or at specific sites), as described in greater detail below.</p>
<p id="p0042" num="0042">The server <b>240</b> can also include a central storage modules <b>255</b>, such as a database system which stores data received from the remote sites <b>205</b>, rules related to the events of interest, user permissions, industry data, and the like in one or more databases. The database typically provides data to other modules residing on the server <b>240</b> and the local software <b>225</b> at the remote sites <b>205</b>. For instance, the database can provide information to an analysis module <b>260</b> that compares video data with defined rules to determine if a particular event has occurred. In some embodiments, the analysis module reviews historical data, attempting to identify peculiarities within the data, such as high instances of a particular event at certain sites as compared to other sites. The central storage module <b>255</b> may also contain separate databases for video, non-video sensor data, rule components, historical analysis, user permissions, etc. Examples of database servers that can be configured to perform these and other similar functions include those described with respect to the storage module of <figref idref="f0001">FIG. 1</figref>.</p>
<p id="p0043" num="0043">The server <b>240</b> can also act as a mass memory device for storing application instructions and data for comnunicating with the remote sites <b>210</b> and for processing the surveillance data. More specifically, the server <b>240</b> can be configured to store an event-detection and surveillance application in accordance with the present invention for obtaining surveillance data from a variety of devices at the remote sites <b>210</b> and for manipulating the data at the central site <b>205</b>. The event-detection and surveillance application comprises computer-executable instructions which, when executed by the server <b>240</b> and/or the local software <b>225</b><!-- EPO <DP n="20"> --> obtains, analyzes and transmits surveillance data as will be explained below in greater detail. The event detection and surveillance application can be stored on any computer-readable medium and loaded into the memory of the server <b>240</b> using a derive mechanism associated with the computer-readable medium, such as a floppy, CD-ROM, DVD-ROM drive, or network drive.</p>
<p id="p0044" num="0044">In many implementations, the remote sites <b>210</b> can be homogeneous in function and/or design; however, in many instances one or more of the sites <b>210</b> will differ from the others. For example, a department-store chain may implement a system in accordance with the present invention across some or all of its warehouses, distribution centers and retail stores, such that the floor-plans, activities and operational schedules for the various sites are different. In some instances, certain sites may be quite similar (e.g., similarly designed storefronts) but may benefit from different surveillance strategies due to environmental differences such as the neighborhood in which the stores are located and/or promotional events that are unique to a particular store. In such instances, it is difficult to define a global ruleset describing the various aspects of events of interest at each location without having a significant impact on accuracy or overburdening staff at each site.</p>
<p id="p0045" num="0045"><figref idref="f0003">FIG. 3</figref> illustrates a multi-component event construct that balances the need for centralized rule definition and scalable implementation with the desirability of localized input and customization at the remote sites. Generally, the construct of the present invention combines multiple components, some of which are global in nature - i.e., characteristics not specific to any particular site with components that are site-specific - to form events <b>305</b>. The occurrence (or non-occurrence) of events <b>305</b> can then be detected based on the detection of each component as defined in the event. For example, one component of an event can be a location <b>310</b> such as a point-of-sale counter, an exit, a hallway, doorway or other physically-identifiable<!-- EPO <DP n="21"> --> place. Components of events <b>305</b> can also include objects <b>315</b>, such as a particular item in a retail store, and actions <b>320</b> such as the selection and/or purchase of the obj ect <b>315</b> or movement of a person about the site.</p>
<p id="p0046" num="0046">The events can be implemented as rules that are used to test for the occurrence or non-occurrence of the events at one or more sites. One possible form for the rules uses Boolean logic. Using a fraudulent employee return event as an example, a rule can be expressed as "if ((RETURN PROCESSED on POS #XXX) and (not (OBJECT #YYY PRESENT in camera view #ZZZ))) then ALERT." Here "XXX" refers to a unique ID number assigned to each POS station, "YYY" refers to a specific product, and "ZZZ" refers to a unique ID number assigned to a camera that has a field-of-view corresponding to the POS station. The definition of the rule, and hence the association of the POS station ID with the region ID, can be formulated manually by a user of the system at the site who has knowledge about the particular POS station and the camera locations, whereas the product information may be defined globally by a user who lacks site-specific knowledge, but knows that that particular item is often stolen or fraudulently returned.</p>
<p id="p0047" num="0047">In general, an alert rule combines events and components of the events together using Boolean logic (for example, AND, OR, and NOT operators) that can be detected on a given sensor network. For example, POS events can include "RETURN PROCESSED," "CASH DRAWER OPEN," "ITEM ZZZ PURCHASED," etc. Video system events can include OBJECT PRESENT," "OBJECT MOVING," "NUM OBJECTS &gt; N," etc. Security system events can include "CARD #123456 SWIPED," "DOOR OPEN," "MOTION DETECTED," etc.</p>
<p id="p0048" num="0048">The events can be combined together with Boolean logic to generate alert expressions, which can be arbitrarily complex. A rule may consist of one or more alert expressions. If the<!-- EPO <DP n="22"> --> entire expression evaluates to "true," then an alert is generated, For example, consider an alert to detect if two people leave a store when an electronic article surveillance (EAS) event is detected. The event components are "TAG DETECTED" and "NUM OBJECTS &gt; 2." If both are true, then the event has occurred and the alert fires. The compound expression is thus "(TAG DETECTED on EAS # 123) and (NUM OBJECTS &gt; 2 in region #456)." As before, unique ID numbers are used to relate the particular EAS pedestal to a region of interest on the appropriate camera,</p>
<p id="p0049" num="0049">As another example, an alert can be triggered based on detecting two people entering a restricted access door using one credential (commonly referred to as "piggybacking"). The alert rule is similar to the above EAS alert rule: "if ((DOOR OPENED on DOOR #834) and (NUM OBJECTS &gt; 2 in region #532)) then ALBERT." Other alerts can be based on movements of objects such as hazardous materials, automobiles and merchandise that determine if the object is moving into a restricted area, is moving too quickly, or moving at a time when no activity should be detected.</p>
<p id="p0050" num="0050">Similar to detecting employee return fraud, it is often useful to know when the cash drawer of a POS station is opened and a customer is not present Such event is often indicative of employee theft. As an example of a more complex rule, detection of this event can be combined with the employee return fraud rule so that both cases can be detected with one rule: "if (((RETURN PROCESSED on pos #XXX) or (CASH DRAWER OPENED on pos #XXX)) and (not (OBJECT PRESENT in region #YYY))) then ALERT."</p>
<p id="p0051" num="0051">Together, each component provides a piece of the event, such as an item being selected by a customer and brought to a cash register. Although such an event can be defined in the abstract - i.e., without reference to any particular register, the monitoring device <b>325</b> being used to oversee the register, or the operational area <b>330</b> of the device (e.g., a field-of-view of a<!-- EPO <DP n="23"> --> camera or operational radius of an RFID sensor) - the event is not completely accurate until such information is added to the event. Therefore, the ability to distribute the definition of individual event components to personnel uniquely familiar with the physical attributes of individual sites allows the general purpose of the events to remain consistent among the sites while permitting the necessary customization of the events to account for different physical characteristics of the sites.</p>
<p id="p0052" num="0052">In many cases, each of the remote sites will share certain characteristics (e.g., they all have aisle ways, doors, dressing rooms, displays, etc.) but the specific configuration characteristics will differ. As an example, a convenience store chain may have a self-serve food area, refrigerated cases, and restrooms in each store, but because of the different floor-plans, the physical relationship among these areas will differ. More specifically, the refrigerated case in one store may be along a back wall and the check-out counter located along the same wall as the exit, whereas in another store the refrigerated case is in an aisle in the middle of the store and the check-out counter is opposite from the exit.</p>
<p id="p0053" num="0053">To further ease the implementation of the defined events as they relate to a particular store, a generic site template (or series of templates) can be defined that represents a "canonical form" of the site floor-plans from each remote site. For example, the canonical floor-plan may define any number of generic attributes and physical characteristics of a site (e.g., walls, exits, aisles, rooms, etc.) that are common among the sites, and in some cases associate events with one or more elements of the floor-plan, as described in further detail below. In some embodiments, the canonical floor-plan can include a combination of generic characteristics and site-specific elements if, for example, the user has some knowledge of a particular set of site layouts.<!-- EPO <DP n="24"> --></p>
<p id="p0054" num="0054"><figref idref="f0004 f0005 f0006">FIGS. 4-6</figref> illustrate various embodiments of a technique for implementing a rule-based surveillance system across multiple disparate sites. The process can be generally divided into three distinct phases: a definition phase (generally illustrated in <figref idref="f0004">FIG. 4</figref>), during which global attributes of events are defined and a generic site floor-plan can be developed at the central site; a customization and monitoring phase (generally illustrated in <figref idref="f0005">FIG. 5</figref>), during which the events and/or floor-plans can be tailored to the individual sites and used to monitor the activities at the sites; and an alert and analysis phase (generally illustrated in <figref idref="f0006">FIG. 6</figref>), during which alerts and sensor data are received at the central site and analyzed to identify trends and anomalies in the data.</p>
<p id="p0055" num="0055">In describing the various tasks of the technique, two user roles are referred to throughout the text below. First, a "central user" is responsible for performing the tasks attributed to the central site that, in general, are global in nature - i.e., are applicable to some set (in some cases all) of the remote sites. Second, a "remote user" is responsible for tasks attributed to the remote sites that, in general, are specific to a particular (or some small group) of remote sites. Typically, such tasks are delegated to the remote user because the central user lacks the site-specific knowledge to perform the task (e.g., assigning a particular camera to an event) or the volume of tasks is such that the distribution of the work across a larger number of users is more efficient,</p>
<p id="p0056" num="0056">Referring to <figref idref="f0004">FIG. 4</figref>, a central user of the system performs various tasks that define site-independent components of the events, as well as one or more generic floor-plans that can be used as starting points for site-specific floor-plans. More specifically, the central user defines an event construct (<b>STEP 405</b>) by identifying the various components of the events. As described above, the components can be site-independent or site-specific. Examples of site-independent event components include actions (e.g., item selection, movement, purchase, etc.)<!-- EPO <DP n="25"> --> and objects (e.g., people, products, cars, money, etc.). Examples of site-specific components include monitoring sensors such as cameras, point-of-sale stations, RFID transmitters, proximity-card readers and other devices disposed about the sites for the purpose of receiving surveillance data.</p>
<p id="p0057" num="0057">Components such as locations can be both site-independent and site-specific. For example, the central user may define locations in a general nature - e.g., exits, point-of-sale counters, dressing rooms, parking lots and/or product-specific aisles or displays - in cases where such locations are known to exist at each (or some number of) the remote sites. These locations can them be customized by remote users by converting the abstract locations defined at the central site into actual locations at the remote site.</p>
<p id="p0058" num="0058">With the various components of the events defined, the central user can specify the information for some or all of the global components (<b>STEP 410</b>). For example, the central user can specify that an event be based on an action (e.g., a selection) attributed to two objects (e.g., a customer and a particular product). In some embodiments, the events can include combinations of multiple actions, multiple objects and multiple locations, and non-occurrences of each. Each component can have one or more thresholds associated with it, such as date/time parameters, and counts, and in some cases these parameters can be set by the central user, the remote users, or both. The parameters can also be reset manually and/or automatically based on meeting a threshold and/or the occurrence or non-occurrence of an event. By attributing time-based parameters'to the actions, the thresholds of the events can be adjusted in a manner that permits the event to be accurately detected while minimizing false positives. For example, an event directed to detecting shoplifting may include three action components such as an item selection, an exit, and the absence of a sale, two item components such as a person and an particular item of merchandise, and two location components, a point-of-sale counter and an<!-- EPO <DP n="26"> --> exit. Once defined, the events can be distributed (<b>STEP 415</b>) to the remote sites for further customization and implementation.</p>
<p id="p0059" num="0059">In some embodiments, the central user also defines one or more canonical floor-plans (<b>STEP 420</b>) that can be used as templates for the remote locations. In some cases, one canonical floor-plan can be used for all remote sites; however, in many cases multiple canonical floor-plans can be designed as templates for subsets of remote sites that share numerous features. For example, a large retail chain may have numerous warehouses and distribution centers as well as a number of different branded stores, such as stores targeting teenagers, stores targeting parents of infants, and stores targeting professionals. In such a case, the central user can defile a canonical floor-plan for each type of site. In some instances, a canonical floor-plan for one type of site (e.g., the teen-focused stores) can be used as a template for the canonical floor-plan (with minor modifications possibly) for other sites, such as the stores targeting professionals. The number of different canonical floor-plans that can be created is virtually unlimited, but generally will be determined by the degree of similarity among the sites and the availability of the central user to design the floor-plans. The canonical floor-plans can also be annotated with one or more events (<b>STEP 425</b>) and distributed to the remote sites (<b>STEP 430</b>). The remote users are thus provided with a starting set of events and a generic floor-plan from which they can build a site-specific floor-plan and complete the event definitions by adding the site-specific components.</p>
<p id="p0060" num="0060">Each of the event constructs, events, floor-plan templates, and combinations thereof can be stored, for example, in the central storage module <b>255</b> of the server <b>240</b> at the central site.</p>
<p id="p0061" num="0061">Referring to <figref idref="f0005">FIG. 5</figref>, the remote users receive the events and/or floor-plans (<b>STEP 505</b>) and, using the local software and systems described herein, customize the events and/or floor-plans to meet the individual needs of each remote site, or, in some cases, groups of remote<!-- EPO <DP n="27"> --> sites. The remote users can, for example, define site-specific components of the events (<b>STEP 510</b>) that were initiated by the central user by adding or modifying location components that are unique to a particular site. For example, remote user may assign one or more surveillance sensors to a location, such that a "select item from beverage display" event is associated with a camera having a field-of-view that includes the display, an RFID sensor that has an operational radius that includes the display, and/or other sensors used to track the location or movement of objects in the display. In implementations where the field-of-view of a camera (or other sensor) is subdivided into multiple sub-regions, the remote user can assign both a camera ID and a sub-region ID to the event by selecting an area of the floor-plan and sub-region using an interactive graphical interface.</p>
<p id="p0062" num="0062">In some embodiments, remotely-defined events and/or the components that make up the events can be re-used at individual sites, as well as by the central user, such that the central user can take advantage of the remote user's knowledge of the site in building subsequent events and floor-plan templates. For example, the central user can defined a location component such as "makeup endcap" for inclusion on a retail store floor-plan, and have certain parameters (height, time periods, sensor ID numbers) associated with it based on a location defined by a remote user.</p>
<p id="p0063" num="0063">The remote users can also set parameters associated with the events. For example, certain stores may keep different hours than others, or have particular times that requires additional security, and thus the time parameters that govern the events may differ from store to store. As another example, the allowable time-span between two events (e.g., a shopper selecting an item and exiting a store) may need to be greater in stores having a larger footprint than smaller stores.<!-- EPO <DP n="28"> --></p>
<p id="p0064" num="0064">In embodiments where a canonical floor-plan is received at a remote site, the remote user can customize the floor-plan (<b>STEP 515</b>) to meet the needs of the particular site, For examples, the central user may have provided a generic layout having four aisles, two point-of sale positions, and one exit. However, if the remote site has six aisles, three point-of-sale positions, and two exits, the remote user can add the necessary elements so the floor-plan more accurately represents the actual layout of the site. Furthermore, the central user may have arranged the elements in a general manner, without regard to the relationships among the elements and/or the surrounding walls. Again, the remote user can manipulate the floor-plan (using, for example, the local software 225 described above and in additional detail below) so that it mirrors (or closely resembles) the actual site.</p>
<p id="p0065" num="0065">In some instances, the central user may have defined an event and associated it with an element of the canonical floor-plan, such as associating a customer selection of an item of merchandise with a specific aisle, based on his belief that such an association is common across many sites. However, in cases where such an association is not accurate (e.g., the product is not carried at a particular store, or it is kept behind the counter), the remote user can break the association, redefine the event, associate it with a different element of the floor-plan, or any combination of the foregoing. In certain instances, the remote user can delete a centrally defined event or event component if it does not match the remote site. By providing remote users with the building blocks of an event-driven surveillance system that maintains certain consistencies across many sites, yet allowing the events to be customized at the site level, the system balances the need for data commonality and site variability such that the central site will receive comparable data from the disparate sites.</p>
<p id="p0066" num="0066">Once the events and/or the floor-plan is customized for the site, events are implemented in the surveillance system (<b>STEP 250</b>). In some embodiments, the implementation includes<!-- EPO <DP n="29"> --> saving the customized events and/or floor-plan to the central storage module at the server. In other embodiments in which the surveillance system (or portions thereof) are implemented at the remote sites, local storage <b>525</b> can be used to store the events and floor-plans, as well as the application code used by the system to monitor the site (<b>STEP 530</b>) for activities that implicate the events.</p>
<p id="p0067" num="0067">While (or even after) the system monitors the site, information can be transmitted (either programmatically, manually, or both) to the central site. For example, implementations in which the alert/search processing module (<b>120</b> of <figref idref="f0001">FIG. 1</figref>) is located at remover sites, alerts are generated upon the occurrence of the events, and in addition to being dispatched to local security personnel, the alerts can also be transmitted (<b>STEP 535</b>) to the central site for analysis and comparison across multiple sites. In other embodiments, video data can also be transmitted (<b>STEP 540</b>) to the central site, either in real-time for event processing and alert generation, or periodically to provide central storage and analysis of the video and the associated metadata across sites. In some cases, the video data can be sent in batch mode (e.g., once nightly) during off-peak times to avoid congestion and overloading of data processing resources. Likewise, sensor data from other sensors (RFID, POS, etc.) can also be transmitted (<b>STEP 545</b>) to the central site for similar purposes.</p>
<p id="p0068" num="0068">Referring to <figref idref="f0006">FIG. 6</figref>, the alerts, video and/or sensor data is received (<b>STEPS 605, 610, and 615</b>) at the central site, where it can be stored (in the central storage module <b>255</b>, for example) and processed. In some embodiments, the data is aggregated (<b>STEP 620</b>) and analyzed (<b>STEP 625</b>). The alerts can be aggregated and analyzed according to time, site (or sites), and/or objects specified within the events that triggered the alerts. For example, if personnel at the central site wish to compare shoplifting events related to a particular item (e.g., razors, baby formula, etc.) across multiple sites, all alerts based on events having those<!-- EPO <DP n="30"> --> items can be selected and grouped by site. In some instances, the video and/or sensor data captured during the event can be further analyzed (<b>STEP 630</b>) to determine if the event was a false positive, or to ascertain if other actions or objects were present during the event that should be considered when modifying the events. The analysis can be performed, for example, using the central analysis module <b>260</b> residing on the server <b>240</b>.</p>
<p id="p0069" num="0069">Based on the analysis, outliers may be identified (<b>STEP 635</b>) that indicate one or more events are defined improperly. By way of illustration, if an event was distributed to a large number of sites, the mean number of alerts received from each store may indicate a "typical" event rate for sites of that type. However, receiving a significantly higher or lower number of events (greater than two standard deviations from the mean, for example) from a particular site may indicate that the event is improperly defined at that site or that other parameters of the site are in fact different from those sites to which it is being compared, For example, the location-specific component of the event may be inaccurate (e.g., the wrong aisle was attributed to a product, or the wrong camera was assigned to an area), a sensor may be non-functional, or a remote user may have sabotaged the system to bide employee-based theft. In such cases, the central user can suggest modifications to the events, or in some cases make the modifications herself (<b>STEP 640</b>) and redistribute the events to the affected sites (<b>STEP 650</b>).</p>
<p id="p0070" num="0070">Inferred relationships among the sites, locations, events and objects within the sites can also be used to generate additional alerts, which can be distributed to the sites. For example, alerts received from two different sites at a certain interval comparable to the travel time between the two sites that indicate that the same (or a related) item of merchandise has been stolen may imply that the same person is responsible for both thefts. Once such a link has been identified, the central site can transmit a secondary alert (including, for example, text, video and/or both) to sites within some radius of the sites from which the items were stolen<!-- EPO <DP n="31"> --> warning the sites to be aware of potential thefts, The identification of the remote sites can be based on manual selection of sites, or in some cases performed automatically based on historical data stored at the central site. In instances where the relationships among sites is distributed to the sites, secondary alerts can be generated at a first remote site and transmitted to those site or sites determined to be "related" to the first site, either by geography, product line, or other historical data.</p>
<p id="p0071" num="0071">In instances in which both the alerts and some or all of the sensor data is received at the central site, additional rules can be applied to the sensor data. For example, additional rules can be more complex in nature (determining, for example, patterns or trends in the data) and/or confirmatory (e.g., duplicates of rules distributed to remote sites to confirm the rules are returning the proper number of alerts). The sensor data can also be combined with actual alert data (both accurate and inaccurate) an used as input into a training algorithm in which the system can effectively "learn" to more accurately identify events of interest.</p>
<p id="p0072" num="0072">In addition to use with regard to security events, the data can also be used for marketing and operational purposes. For example, events can be defined to monitor sales activities during sales, new product introductions, customer traffic, or periods of interest. Alerts based on the occurrence of such events can be aggregated to compare overall customer experiences across multiple stores and at different times to determine the effectiveness of promotions, pricing and other merchandise-related occurrences.</p>
<p id="p0073" num="0073">Referring to <figref idref="f0007">FIG. 7</figref>, an example of an application screen includes a menu-driven user interface <b>700</b> for implementing the system and techniques described above. The interface <b>700</b> includes four main functions - template definition <b>705</b>, location definition <b>710</b>, event definition <b>715</b>, and event/location display <b>720</b>. The template-definition function <b>705</b> facilitates the definition, and modification of the canonical floor-plans that can be used as<!-- EPO <DP n="32"> --> starting points for site-specific layouts. The location definition function <b>710</b> facilitates the definition of as generic location at which one or more actions take place and objects interact, The specificity of the locations can range from the most generic - e.g., a door, to a specific location, such as loading dock #3 at warehouse #2. The event definition function <b>715</b> allows the user to define the events as combinations of one or more event components and also to associate attributes or parameters with the events, as described above and in more detail below with respect to <figref idref="f0010">FIG. 10</figref>. The event/location display <b>720</b> allows a user to review the locations and events that have been defined in the system, and the sites to which they have been assigned.</p>
<p id="p0074" num="0074">Referring to <figref idref="f0008">FIG. 8</figref>, an example of an application screen includes a template-design user interface <b>800</b> for creating canonical floor-plans and templates. The user interface includes a site template <b>805</b>, a template parameter selection area <b>810</b>, and a template action area <b>815</b>. The template <b>805</b> is implemented as an interactive interface that allows users to select, edit, add, delete and move elements of the floor-plan. In some embodiments, the elements are represented as application objects having attributes such as size and height, thus allowing the user to specify the relative size of an object with respect to other objects (e.g., in units, pixels, etc.) and in absolute terms (e.g., inches, feet, etc.). The template <b>805</b> can respond to "drag-and-drop" user/screen interactions based on keystrokes and/or commands entered using a pointing device such as a mouse or optical pen. In embodiments in which the user interface <b>800</b> is provided to the user via a browser application, the objects can be represented as objects within a Flash-based window, or an AJAX applet such that the user-initiated commands for editing and moving the template objects are processed largley on the client machine and requires minimal data transmission to and from a server.<!-- EPO <DP n="33"> --></p>
<p id="p0075" num="0075">The template parameter area <b>810</b> provides fields for entering and viewing parameters associated with to the template. More specifically, the user can specify the template type (e.g., warehouse, retail, two-story, suburban, generic, etc.) the date the template was created, and the site or sites to which the template has been assigned. The template actions area <b>815</b> provides actionable objects (such as hyperlinks, control buttons, combo-boxes and the like) that, when selected by a user, assign the template to a particular site (or group of sites), publish the template (e.g., to remote users), and copy the template to initiate the creation of a new template, for example.</p>
<p id="p0076" num="0076">The user interlace <b>800</b> also includes libraries of template elements that can be used to create events, attribute elements to templates or both. Specifically, the user interface <b>800</b> can include an object library <b>820</b>, a location library <b>825</b>, an action library <b>830</b>, and an event library <b>840</b>. Each library provides a listing of the respective elements available to the user to either combine into an event (as described above) and/or position within the template. Each template library further provides the ability to add elements to the library as needed.</p>
<p id="p0077" num="0077">A user can annotate the templates with events and/or event components from the libraries by selecting a component and dragging the components into place on the template <b>805</b>. For example, the user may wish to create a template with two fixed walls <b>845</b>, an aisle 850, a checkout counter <b>855</b> and a merchandise display <b>860</b>. In many cases, the floor-plan represented in the template will not actually describe any particular site, but can be used as a starting point by the remote users for customization (as described further below with reference to <figref idref="f0012">FIGS. 12</figref> and <figref idref="f0013">13</figref>).</p>
<p id="p0078" num="0078">In some embodiments, the user interface <b>800</b> can also include a sensor library (not shown) that provides a listing of the available sensors of the various sensor networks and video surveillance systems, thus allowing the user to add the locations of generic sensors (e.g.,<!-- EPO <DP n="34"> --> video camera) and/or specific sensors (e.g., camera #321) to the template. In instances where the template is being defined by a central user, the templates are stored at the central site and can be "published" to remote users when completed.</p>
<p id="p0079" num="0079">Referring to <figref idref="f0009">FIG. 9</figref>, an example of an application screen includes a location definition user interface <b>900</b> for defining locations within the location library, and that can be used to annotate floor-plans and/or create events. The user interface <b>900</b> includes fields <b>905</b> and <b>910</b> into which users can enter a full name (e.g., blue jeans table at front of store) and a short name (blue jeans table), respectively. A location type text box <b>915</b> provides the user with a field in which to specify the type of location (e.g., table, door, counter, restroom, parking structure, etc.) being defined. A description field <b>920</b> allows the user to enter a longer textual description of the location that can include, for example, coordinates of the location, instructions on implementing the location, and other relevant features of the location. A contact field <b>925</b> captures an attribute of the user creating the location such as an email address, user name, employee number or role. A submit button <b>930</b> saves the location and its attributes to the central storage module, the remote storage modules, or both, depending, for example on the user creating the location, the architectural implementation of the system, or other system-based parameters.</p>
<p id="p0080" num="0080">Referring to <figref idref="f0010">FIG. 10</figref>, an example of an application screen includes an event definition user interface <b>1000</b> for defining (and, once defined, modifying) an event within the system. As described above, an event can be constructed from one or more event components such as actions, locations and objects, as well as parameters that further describe how and when the event is implemented. Typically, the define event user interface <b>1000</b> is used by the central user to provide the site-independent components of the events, such as time parameters, generic locations, actions, and the like. However, in some embodiments, remote users may be<!-- EPO <DP n="35"> --> given access to the define event functionality in order to create new events that are entirely site-specific. In some cases, a central administrator can grant or deny access to such functionality on a user-by-user basis. The user interface <b>1000</b> includes an event name field <b>1005</b> for capturing a moniker for the event, and to identify the event (uniquely, in some cases) within the data storage module(s). A location field <b>1010</b> provides a listing of available locations that can be associated with the event. Parameter fields <b>1015</b> provide the user with the ability to assign date and/or time boundaries on the event. For example, an event directed to detecting shoppers stopping at display, and selecting an item can be limited to the days and hours that the store is open.</p>
<p id="p0081" num="0081">Action selection items <b>1020</b> and <b>1025</b> facilitate the definition of action-based components of the event. In a retail setting, for example, actions surrounding a particular display may be of interest, such as a shopper stopping at a display, picking up an item, and placing it in a cart. However, accurately determining if such an event occurred may require attributing time-based parameters to certain actions. Specifically, to determine if a user stopped at a display, a "linger time" parameter can be used to detect whether the shopper actually paused at the display long enough (e.g., more than a few seconds) to view the merchandise. Likewise, a long lingering period coupled with a non-action (e.g., not picking up an item) may indicate that, although the display is attractive to the shoppers, the product is not interesting or is priced improperly.</p>
<p id="p0082" num="0082">Such actions can help determine the effectiveness of a display by comparing the number of shoppers who pass by and ignore the display (e.g., no linger time, did not touch an item, but walked up to the display) to the number of shoppers attracted to the display (e.g., a linger time greater than a few seconds and touched an item). In addition, these statistics can be compared to overall sales, based on POS data, for example, and a count of the overall<!-- EPO <DP n="36"> --> number of shoppers entering the store. Detecting and counting specific shopper behaviors as they occur at specific locations, and comparing similar events across otherwise disparate sites, effectively "normalizes" the events by removing site-specific differences and focuses on actions that are directly attributable to the interactions of the shoppers with the products.</p>
<p id="p0083" num="0083">Referring to <figref idref="f0011">FIG. 11</figref>, an example of an application screen includes an event-editing user interface <b>1100</b> for modifying an event and assigning site-specific elements to the event. In some embodiments, data previously entered (by a central user, for example) and displayed on user interface <b>1100</b> to a remote user is read only, whereas in some cases certain elements may be read only (e.g., the name and time-based parameters) and other data elements are editable. In each case, the user interface <b>1100</b> also includes an assign-camera selection box <b>1105</b> and an assign-sensor selection box <b>1110</b>. In instances where a remote user receives instructions to implement the event at their site (or group of sites), the user can select from the available camera and/or sensor identifiers at her particular site. Allowing remote users to review the events and select the appropriate sensors for detecting the event improves the chances that the correct camera, for example, will record the event.</p>
<p id="p0084" num="0084">Referring to <figref idref="f0012">FIG. 12</figref>, an example of an application screen includes a template editing user interface <b>1200</b> for allowing remote users to customize a store floor-plan template provided by a central user. In addition to the functionality and features of the template design user interface <b>800</b>, the template editing user interface <b>1200</b> allows users (either central or remote) to modify the templates such that they better describe a particular site. The object library can include the various video cameras <b>1210</b> and sensors <b>1215</b> (identified by unique ID in some cases) that can be selected and positioned at various locations about the floor-plan. For example, a user may know that a particular camera is affixed to a particular wall and is directed at an aisle, and will therefore place the camera at that location. Similarly, an RFID<!-- EPO <DP n="37"> --> sensor or other similar EAS device may be placed at the store exit. In some instances, the template may include elements added by the central user (walls, aisles, displays, etc.) that are present at the remote sites, but not properly positioned. In such cases, the remote user can select the elements and alter their positioning about the site floor-plan. For example, an aisle 1220 that was positioned perpendicular to a particular wall in the original template can be moved such that it is now parallel to the wall. Likewise, merchandise display <b>1220</b> can be moved such that it remains at the end of the newly placed aisle. Point-of-sale location <b>1430</b> (e.g., a checkout counter) can also be moved to its proper location based on the actual floor-plan of the site. In some cases, additional elements, such as an additional wall <b>1440</b>, can be added to complete the floor-plan. Once the site-specific changes to the floor-plan have been completed, the floor-plan is saved (either to remote storage, central storage, or both) and used as the basis for monitoring the sites. In some cases, the changes are submitted back to a central user for approval prior to implementation and/or use as future templates.</p>
<p id="p0085" num="0085">Referring to <figref idref="f0013">FIG. 13</figref>, an example of an application screen includes a floor plan-mapping user interface <b>1300</b> for mapping elements of a canonical floor-plan to an actual floor-plan at a remote site. Similar to the template editing user interlace <b>1200</b>, the floor plan-mapping user interface <b>1300</b> allows users to build site-specific floor-plans for implementation within the surveillance system described above; however, it provides a visual representation of both the template <b>805</b> an existing site floor-plan <b>1305</b>, thereby allowing the user to annotate and manipulate the site floor-plan <b>1305</b> using the template. In some embodiments, an electronic representation of the floor-plan for a remote site may be available from another source, such as architectural drawings, building layouts, design drawings, and the like, and the user may wish to use the drawings as a starting point for the site-specific floor-plan. For example, the user can indicate on the site floor-plan <b>1305</b> the location of video cameras and/or<!-- EPO <DP n="38"> --> sensors <b>1310</b> and select items from the template <b>805</b> and indicate their true position on the site floor-plan <b>1305</b>. Specifically, elements such as aisles <b>1315</b>, POS devices <b>1320</b>, and merchandise displays <b>1325</b> can be selected on the template <b>805</b>, dragged onto the site floor-plan <b>1305</b> and placed at the correct location. In some instances, elements can be added to the floor-plan <b>1305</b>, such as the entry <b>1330</b>. In some cases, the system requires the user to "place" all the items from the template <b>805</b> on the site floor-plan <b>1305</b> prior to allowing the user to implement it for use in monitoring the site. As a result, a complete and accurate site floor-plan is made available to the system for use in detecting events of interest at the site, without requiring central users to have intimate knowledge of each remote site, but assures that some minimal number of events are implemented at each site.</p>
<p id="p0086" num="0086">In addition to mapping canonical floor-plan elements to the actual floor-plan, actual floor-plan elements can be mapped to canonical floor-plan elements, thus indicating to a central user the elements of the canonical floor-plan to which certain events are assigned. Such an approach further facilitates site-to-site comparisons using a normalized, standard floor-plan, but using data that is captured based on site-specific parameters, For example, to compare traffic totals among numerous (e.g., more than two) stores having different actual floor-plans, event data can be plotted against the canonical floor-plan. As a result, central users can identify the occurance of events or products with exceptionally high shrinkage rates across multiple sites without having to first consider the different site floor-plans.</p>
<p id="p0087" num="0087">For embodiments in which the methods are provided as one or more software programs, the program may be written in any one of a number of high level languages such as FORTRAN, PASCAL, JAVA, C, C<sub>++</sub>, C#, BASIC, various scripting languages, and/or HTML. Data can be transmitted among the various application and storage modules using client/server techniques such as ODBC and direct data access, as well as via web services,<!-- EPO <DP n="39"> --> XML and AJAX technologies. Additionally, the software can be implemented in an assembly language directed to the microprocessor resident on a target computer; for example, the software may be implemented in Intel 80x86 assembly language if it is configured to run on an IBM PC or PC clone. The software may be embodied on an article of manufacture including, but not limited to, a floppy disk, a hard disk, an optical disk, a magnetic tape, a PROM, an EPROM, EEPROM, field-programmable gate array, or a CD-ROM.</p>
<p id="p0088" num="0088">Variations, modifications, and other implementations of what is described herein will occur to those of ordinary skill in the art without departing from the scope of the invention as claimed. Accordingly, the invention is to be defined not by the preceding illustrative description but instead by the scope of the following claims.</p>
</description>
<claims id="claims01" lang="en"><!-- EPO <DP n="40"> -->
<claim id="c-en-01-0001" num="0001">
<claim-text>A method for facilitating monitoring multiple disparate sites, the method comprising
<claim-text>providing a set of rules describing at least one event of interest, the event comprising at least one site-specific event and at least one site-independent event,</claim-text>
<claim-text>defining the site-independent event,</claim-text>
<claim-text>distributing the set of rules to the multiple disparate sites, thereby facilitating definition of the at least one site-specific event at each of the multiples disparate sites and monitoring the sites in accordance with the rules;</claim-text>
<claim-text>receiving alerts from multiple sites indicating the occurrence of one or more of the events of interest at the respective sites; and</claim-text>
<claim-text>analysing the alerts to detect inconsistencies among the site-specific events attributed to each of the multiple disparate sites</claim-text></claim-text></claim>
<claim id="c-en-01-0002" num="0002">
<claim-text>The method of claim 1 wherein the site-specific event specifies either one of a) a location of the event at the multiple disparate sites, or b) a person interacting with an object at the multiples disparate sites</claim-text></claim>
<claim id="c-en-01-0003" num="0003">
<claim-text>The method of claim 1 wherein the site-independent event specifies an action occurring at the multiple disparate sites</claim-text></claim>
<claim id="c-en-01-0004" num="0004">
<claim-text>The method of claim 2, sub-clause b), wherein the object is site-specific</claim-text></claim>
<claim id="c-en-01-0005" num="0005">
<claim-text>The method of claim 2, sub-clause b), wherein the object is site-independent</claim-text></claim>
<claim id="c-en-01-0006" num="0006">
<claim-text>The method of claim 1 further comprising modifying at least one site-specific event of a rule and distributing the modified rule to a site associated with the inconsistencies.</claim-text></claim>
<claim id="c-en-01-0007" num="0007">
<claim-text>The method of claim 1 further comprising transmitting a secondary alert to a site based on the received alerts</claim-text></claim>
<claim id="c-en-01-0008" num="0008">
<claim-text>The method of claim 7 wherein the received alerts on which the secondary alert is based are received from sites other than the site to which the secondary alert was transmitted.</claim-text></claim>
<claim id="c-en-01-0009" num="0009">
<claim-text>The method of claim 8 wherein the site to which the secondary alert was transmitted is determined based on an inferred relationship between the site to which the secondary alert was transmitted and the sites from which the alerts were received.</claim-text></claim>
<claim id="c-en-01-0010" num="0010">
<claim-text>The method of claim 1 further comprising:<!-- EPO <DP n="41"> -->
<claim-text>receiving, at a central location, definitions describing the site-specific events at each of the multiple disparate sites;</claim-text>
<claim-text>receiving surveillance data from the multiple disparate sites; and</claim-text>
<claim-text>applying one or more of the rules to the surveillance data, thereby detecting the occurrence of the events of interest at the sites</claim-text></claim-text></claim>
<claim id="c-en-01-0011" num="0011">
<claim-text>The method of claim 10 further comprising approving the site-specific event at the central location.</claim-text></claim>
<claim id="c-en-01-0012" num="0012">
<claim-text>A system for facilitating monitoring of multiple disparate sites, the system comprising:
<claim-text>a rule-definition module for defining a set of rules, each rule describing an event of interest and comprising one or more site-specific components and one or more site-independent components,</claim-text>
<claim-text>a transmission module for (i) transmitting one or more of the rules to one or more disparate sites, thereby facilitating the definition of the one or more site-specific components at the multiple disparate sites and (ii) receiving one or more alerts from the sites, each alert indicating occurrence of one or more of the events of interest ; and</claim-text>
<claim-text>an analysis module for analyzing the received alerts to detect inconsistencies among the site-specific components attributed to the one or more multiple disparate sites</claim-text></claim-text></claim>
<claim id="c-en-01-0013" num="0013">
<claim-text>The system of claim 12 further including a web server for providing remote clients at the sites with access to the rule-definition module and optionally wherein the web server is configured to limit access provided to remote clients to defining the site-specific components,</claim-text></claim>
<claim id="c-en-01-0014" num="0014">
<claim-text>The system of claim 12 wherein the analysis module is further configured to aggregate the received alerts, thereby facilitating statistical analysis thereof, and optionally, wherein the analysis module is further configured to analyze the aggregated alerts to determine if one or more of the site-specific components are suboptimal</claim-text></claim>
<claim id="c-en-01-0015" num="0015">
<claim-text>The system of claim 12 wherein the rule-definition module is further configured to modify the rules based on the detected inconsistencies, and optionally, wherein the transmission module is further configured to transmit the modified rules to the remote sites</claim-text></claim>
<claim id="c-en-01-0016" num="0016">
<claim-text>The system of claim 12 further comprising a data storage module for storing the rules, and optionally, wherein the data storage module further stores surveillance data received from the multiple disparate sites</claim-text></claim>
</claims>
<claims id="claims02" lang="de"><!-- EPO <DP n="42"> -->
<claim id="c-de-01-0001" num="0001">
<claim-text>Verfahren zum Erleichtern der Überwachung von mehrfachen verschiedenen Standorten, wobei das Verfahren umfasst:
<claim-text>Bereitstellen eines Regelsatzes, der mindestens ein Ereignis von Interesse beschreibt, wobei das Ereignis mindestens ein standortspezifisches Ereignis und mindestens ein standortunabhängiges Ereignis umfasst;</claim-text>
<claim-text>Definieren des standortunabhängigen Ereignisses;</claim-text>
<claim-text>Verteilen des Regelsatzes auf die mehrfachen verschiedenen Standorte, wodurch die Definition des mindestens einen standortspezifischen Ereignisses an jedem der mehrfachen verschiedenen Standorte erleichtert wird und Überwachen der Standorte gemäß den Regeln;</claim-text>
<claim-text>Empfangen von Warnungen von mehrfachen Standorten, die das Auftreten eines oder mehrerer der Ereignisse von Interesse an den jeweiligen Standorten angeben; und</claim-text>
<claim-text>Analysieren der Warnungen, um Widersprüche unter den standortspezifischen Ereignissen zu erkennen, die jedem der mehrfachen verschiedenen Standorte zugesprochen werden.</claim-text></claim-text></claim>
<claim id="c-de-01-0002" num="0002">
<claim-text>Verfahren nach Anspruch 1, worin das standortspezifische Ereignis entweder eins von: a) einer Position des Ereignisses an den mehrfachen verschiedenen Standorten; oder b) einer Person spezifiziert, die mit einem Objekt an den mehrfachen verschiedenen Standorten interagiert.</claim-text></claim>
<claim id="c-de-01-0003" num="0003">
<claim-text>Verfahren nach Anspruch 1, worin das standortunabhängige Ereignis eine Aktion spezifiziert, die an den mehrfachen verschiedenen Standorten auftritt.</claim-text></claim>
<claim id="c-de-01-0004" num="0004">
<claim-text>Verfahren nach Anspruch 2, Abschnitt b), worin das Objekt standortspezifisch ist.</claim-text></claim>
<claim id="c-de-01-0005" num="0005">
<claim-text>Verfahren nach Anspruch 2, Abschnitt b), worin das Objekt standortunabhängig ist.</claim-text></claim>
<claim id="c-de-01-0006" num="0006">
<claim-text>Verfahren nach Anspruch 1, ferner umfassend Modifizieren von mindestens einem standortspezifischen Ereignis einer Regel und Verteilen der modifizierten Regel an einen Standort, der mit den Widersprüchen in Verbindung steht.</claim-text></claim>
<claim id="c-de-01-0007" num="0007">
<claim-text>Verfahren nach Anspruch 1, ferner umfassend Übertragen einer Sekundärwarnung an einen Standort, basierend auf den empfangenen Warnungen.</claim-text></claim>
<claim id="c-de-01-0008" num="0008">
<claim-text>Verfahren nach Anspruch 7, worin die empfangenen Warnungen, auf denen die Sekundärwarnung basiert, von Standorten empfangen werden, die vom Standort, an den die Sekundärwarnung übertragen wurde, verschieden sind.</claim-text></claim>
<claim id="c-de-01-0009" num="0009">
<claim-text>Verfahren nach Anspruch 8, worin der Standort, an den die Sekundärwarnung übertragen wurde, auf der Basis eines gefolgerten Verhältnisses zwischen dem Standort, an den die Sekundärwarnung übertragen wurde, und den Standorten, von denen die Warnungen empfangen wurden, bestimmt wird.<!-- EPO <DP n="43"> --></claim-text></claim>
<claim id="c-de-01-0010" num="0010">
<claim-text>Verfahren nach Anspruch 1, ferner umfassend:
<claim-text>Empfangen, an einer zentralen Position, von Definitionen, die die standortspezifischen Ereignisse an jedem der mehrfachen verschiedenen Standorte beschreiben;</claim-text>
<claim-text>Empfangen von Beobachtungsdaten von den mehrfachen verschiedenen Standorten; und</claim-text>
<claim-text>Anwenden einer oder mehrerer der Regeln auf die Beobachtungsdaten, wodurch das Auftreten der Ereignisse von Interesse an den Standorten ermittelt wird.</claim-text></claim-text></claim>
<claim id="c-de-01-0011" num="0011">
<claim-text>Verfahren nach Anspruch 10, ferner umfassend Bestätigen des standortspezifischen Ereignisses an der zentralen Position.</claim-text></claim>
<claim id="c-de-01-0012" num="0012">
<claim-text>System zum Erleichtern der Überwachung von mehrfachen verschiedenen Standorten, wobei das System umfasst:
<claim-text>ein Regeldefinitionsmodul zum Definieren eines Regelsatzes, wobei jede Regel ein Ereignis von Interesse beschreibt und eine oder mehrere standortspezifische Komponenten und eine oder mehrere standortunabhängige Komponenten umfasst;</claim-text>
<claim-text>ein Übertragungsmodul zum (i) Übertragen einer oder mehrerer der Regeln an einen oder mehrere verschiedene Standorte, wodurch die Definition der einen oder mehreren standortspezifischen Komponenten an den mehrfachen verschiedenen Standorten erleichtert wird und (ii) Empfangen einer oder mehrerer Warnungen von den Standorten, wobei jede Warnung das Auftreten eines oder mehrerer der Ereignisse von Interesse angibt; und</claim-text>
<claim-text>ein Analysemodul zum Analysieren der empfangenen Warnungen, um Widersprüche unter den standortspezifischen Komponenten, die dem einen oder den mehreren mehrfachen verschiedenen Standorten zugeschrieben werden, zu ermitteln.</claim-text></claim-text></claim>
<claim id="c-de-01-0013" num="0013">
<claim-text>System nach Anspruch 12, ferner einschließend einen Webserver zum Bereitstellen von fernen Kunden an den Standorten mit Zugang zum Regeldefinitionsmodul und worin wahlweise der Webserver dazu konfiguriert ist, Zugang zur Definition von standortspezifischen Komponenten, der fernen Kunden bereitgestellt wird, zu begrenzen.</claim-text></claim>
<claim id="c-de-01-0014" num="0014">
<claim-text>System nach Anspruch 12, worin das Analysemodul ferner dazu konfiguriert ist, die empfangenen Warnungen zu sammeln, wodurch die statistische Analyse davon erleichtert wird, und worin wahlweise das Analysemodul ferner dazu konfiguriert ist, die gesammelten Warnungen zu analysieren, um zu bestimmen, ob eine oder mehrere der standortspezifischen Komponenten suboptimal sind.</claim-text></claim>
<claim id="c-de-01-0015" num="0015">
<claim-text>System nach Anspruch 12, worin das Regeldefinitionsmodul ferner dazu konfiguriert ist, die Regeln auf der Basis der detektierten Widersprüche zu modifizieren und worin wahlweise das Übertragungsmodul ferner dazu konfiguriert ist, die modifizierten Regeln an die entfernten Standorte zu übertragen.<!-- EPO <DP n="44"> --></claim-text></claim>
<claim id="c-de-01-0016" num="0016">
<claim-text>System nach Anspruch 12, ferner umfassend ein Datenspeichermodul zum Speichern der Regeln, und worin wahlweise das Datenspeichermodul ferner von den mehrfachen verschiedenen Standorten empfangene Beobachtungsdaten speichert.</claim-text></claim>
</claims>
<claims id="claims03" lang="fr"><!-- EPO <DP n="45"> -->
<claim id="c-fr-01-0001" num="0001">
<claim-text>Procédé destiné à faciliter la surveillance de multiples sites disparates, le procédé comprenant les étapes ci-dessous :
<claim-text>fourniture d'un ensemble de règles, décrivant au moins un événement d'intérêt, l'évènement comprenant au moins un événement spécifique au site et au moins un événement indépendant du site ;</claim-text>
<claim-text>définition de l'événement indépendant du site ;</claim-text>
<claim-text>distribution de l'ensemble de règles aux multiples sites disparates, facilitant ce faisant la définition de l'au moins un événement spécifique au site au niveau de chacun des multiples sites disparates, et surveillance des sites en conformité avec les règles;</claim-text>
<claim-text>réception d'alertes en provenance de sites multiples indiquant l'occurrence d'un ou de plusieurs des événements d'intérêt au niveau des sites respectifs ; et</claim-text>
<claim-text>analyse des alertes pour détecter les inconsistences parmi les événements spécifiques au site attribués à chacun des sites multiples disparates.</claim-text></claim-text></claim>
<claim id="c-fr-01-0002" num="0002">
<claim-text>Procédé selon la revendication 1, dans lequel l'événement spécifique au site spécifie l'un ou l'autre de : a) un emplacement de l'événement au niveau des multiples sites disparates ; et b) une personne interagissant avec un objet au niveau des multiples sites disparates.</claim-text></claim>
<claim id="c-fr-01-0003" num="0003">
<claim-text>Procédé selon la revendication 1, dans lequel l'événement indépendant du site spécifie une action ayant lieu au niveau des multiples sites disparates.</claim-text></claim>
<claim id="c-fr-01-0004" num="0004">
<claim-text>Procédé selon la revendication 2, sous-clause b), dans laquelle l'objet est spécifique au site.</claim-text></claim>
<claim id="c-fr-01-0005" num="0005">
<claim-text>Procédé selon la revendication 2, sous-clause b), dans lequel l'objet est indépendant du site.</claim-text></claim>
<claim id="c-fr-01-0006" num="0006">
<claim-text>Procédé selon la revendication 1, comprenant en outre la modification d'au moins un événement spécifique au site d'une règle et la distribution de la règle modifiée à un site associé aux inconsistences.</claim-text></claim>
<claim id="c-fr-01-0007" num="0007">
<claim-text>Procédé selon la revendication 1, comprenant en outre la transmission d'une alerte secondaire à un site sur la base des alertes reçues.</claim-text></claim>
<claim id="c-fr-01-0008" num="0008">
<claim-text>Procédé selon la revendication 7, dans lequel les alertes reçues sur lesquelles l'alerte secondaire est basée sont reçues par des sites autres que le site auquel l'alerte secondaire a été transmise.</claim-text></claim>
<claim id="c-fr-01-0009" num="0009">
<claim-text>Procédé selon la revendication 8, dans lequel le site vers lequel l'alerte secondaire a été transmise est déterminé sur la base d'une relation déduite entre le site vers lequel l'alerte secondaire a été transmise et les sites à partir desquels les alertes ont été reçues.</claim-text></claim>
<claim id="c-fr-01-0010" num="0010">
<claim-text>Procédé selon la revendication 1, comprenant en outre :
<claim-text>la réception, au niveau d'un emplacement central, de définitions décrivant les événements spécifiques au site au niveau de chacun des multiples sites disparates ;<!-- EPO <DP n="46"> --></claim-text>
<claim-text>la réception de données de surveillance à partir des multiples sites disparates ; et</claim-text>
<claim-text>l'application d'une ou de plusieurs des règles aux données de surveillance, détectant ce faisant l'occurrence des événements d'intérêt au niveau des sites.</claim-text></claim-text></claim>
<claim id="c-fr-01-0011" num="0011">
<claim-text>Procédé selon la revendication 10, comprenant en outre l'approbation de l'événement spécifique au site au niveau de l'emplacement central.</claim-text></claim>
<claim id="c-fr-01-0012" num="0012">
<claim-text>Système pour faciliter la surveillance de multiples sites disparates, le système comprenant :
<claim-text>un module de définition de règles, configuré de sorte à définir un ensemble de règles, chaque règle décrivant un événement d'intérêt et comprenant une ou plusieurs composantes spécifiques au site et une ou plusieurs composantes indépendantes du site ;</claim-text>
<claim-text>un module de transmission pour (i) transmettre une ou plusieurs des règles vers un ou plusieurs sites disparates, facilitant ainsi la définition de la ou des composantes spécifiques au site au niveau des multiples sites disparates et (ii) la réception d'une ou de plusieurs alertes en provenance des sites, chaque alerte indiquant l'occurrence d'un ou de plusieurs des événements d'intérêt ; et</claim-text>
<claim-text>un module d'analyse pour analyser les alertes reçues pour détecter des inconsistences parmi les composantes spécifiques au site attribuées au ou aux multiples sites disparates.</claim-text></claim-text></claim>
<claim id="c-fr-01-0013" num="0013">
<claim-text>Système selon la revendication 12, incluant en outre un serveur Web pour fournir à des clients éloignés au niveau des sites un accès au module de définition de règles et optionnellement dans lequel le serveur Web est configuré pour limiter l'accès à la définition des composantes spécifiques au site fourni aux clients éloignés.</claim-text></claim>
<claim id="c-fr-01-0014" num="0014">
<claim-text>Système selon la revendication 12, dans lequel le module d'analyse est en outre configuré pour regrouper les alertes reçues, facilitant ainsi leur analyse statistique, dans lequel le module d'analyse est en outre optionnellement configuré de sorte à analyser les alertes regroupées, pour déterminer si une ou plusieurs des composantes spécifiques au site sont sous-optimales.</claim-text></claim>
<claim id="c-fr-01-0015" num="0015">
<claim-text>Système selon la revendication 12, dans lequel le module de définition de règles est en outre configuré pour modifier les règles sur la base des inconsistances détectées, et, optionnellement, dans lequel le module de transmission est en outre configuré de sorte à transmettre les règles modifiées vers les sites éloignés.</claim-text></claim>
<claim id="c-fr-01-0016" num="0016">
<claim-text>Système selon la revendication 12, comprenant en outre un module de stockage de données pour stocker les règles, et optionnellement, dans lequel le module de stockage de données stocke en outre des données de surveillance reçues depuis les multiples sites disparates.</claim-text></claim>
</claims>
<drawings id="draw" lang="en"><!-- EPO <DP n="47"> -->
<figure id="f0001" num="1"><img id="if0001" file="imgf0001.tif" wi="132" he="185" img-content="drawing" img-format="tif"/></figure><!-- EPO <DP n="48"> -->
<figure id="f0002" num="2"><img id="if0002" file="imgf0002.tif" wi="127" he="178" img-content="drawing" img-format="tif"/></figure><!-- EPO <DP n="49"> -->
<figure id="f0003" num="3"><img id="if0003" file="imgf0003.tif" wi="128" he="146" img-content="drawing" img-format="tif"/></figure><!-- EPO <DP n="50"> -->
<figure id="f0004" num="4"><img id="if0004" file="imgf0004.tif" wi="117" he="159" img-content="drawing" img-format="tif"/></figure><!-- EPO <DP n="51"> -->
<figure id="f0005" num="5"><img id="if0005" file="imgf0005.tif" wi="116" he="173" img-content="drawing" img-format="tif"/></figure><!-- EPO <DP n="52"> -->
<figure id="f0006" num="6"><img id="if0006" file="imgf0006.tif" wi="130" he="178" img-content="drawing" img-format="tif"/></figure><!-- EPO <DP n="53"> -->
<figure id="f0007" num="7"><img id="if0007" file="imgf0007.tif" wi="136" he="179" img-content="drawing" img-format="tif"/></figure><!-- EPO <DP n="54"> -->
<figure id="f0008" num="8"><img id="if0008" file="imgf0008.tif" wi="127" he="180" img-content="drawing" img-format="tif"/></figure><!-- EPO <DP n="55"> -->
<figure id="f0009" num="9"><img id="if0009" file="imgf0009.tif" wi="134" he="180" img-content="drawing" img-format="tif"/></figure><!-- EPO <DP n="56"> -->
<figure id="f0010" num="10"><img id="if0010" file="imgf0010.tif" wi="139" he="181" img-content="drawing" img-format="tif"/></figure><!-- EPO <DP n="57"> -->
<figure id="f0011" num="11"><img id="if0011" file="imgf0011.tif" wi="139" he="174" img-content="drawing" img-format="tif"/></figure><!-- EPO <DP n="58"> -->
<figure id="f0012" num="12"><img id="if0012" file="imgf0012.tif" wi="132" he="180" img-content="drawing" img-format="tif"/></figure><!-- EPO <DP n="59"> -->
<figure id="f0013" num="13"><img id="if0013" file="imgf0013.tif" wi="134" he="181" img-content="drawing" img-format="tif"/></figure>
</drawings>
<ep-reference-list id="ref-list">
<heading id="ref-h0001"><b>REFERENCES CITED IN THE DESCRIPTION</b></heading>
<p id="ref-p0001" num=""><i>This list of references cited by the applicant is for the reader's convenience only. It does not form part of the European patent document. Even though great care has been taken in compiling the references, errors or omissions cannot be excluded and the EPO disclaims all liability in this regard.</i></p>
<heading id="ref-h0002"><b>Patent documents cited in the description</b></heading>
<p id="ref-p0002" num="">
<ul id="ref-ul0001" list-style="bullet">
<li><patcit id="ref-pcit0001" dnum="US2005016525A1"><document-id><country>US</country><doc-number>2005016525</doc-number><kind>A1</kind></document-id></patcit><crossref idref="pcit0001">[0007]</crossref></li>
<li><patcit id="ref-pcit0002" dnum="US706850A" dnum-type="L"><document-id><country>US</country><doc-number>706850</doc-number><kind>A</kind></document-id></patcit><crossref idref="pcit0002">[0024]</crossref></li>
<li><patcit id="ref-pcit0003" dnum="US44350006A" dnum-type="L"><document-id><country>US</country><doc-number>44350006</doc-number><kind>A</kind><date>20060530</date></document-id></patcit><crossref idref="pcit0003">[0024]</crossref></li>
</ul></p>
</ep-reference-list>
</ep-patent-document>
