<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Digital Twins and Semantic Data Fusion for Security in a Healthcare Environment?</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Barry Norton</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Mathias Jes Normann</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Milestone Systems A/S</institution>
          ,
          <country country="DK">Denmark</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>While the concept of digital twin, and the use of semantic technologies, is already established in the eld of IoT, and while the co-existence of such other sensor devices with IP-enabled video cameras is common, this combination, in so-called Video IoT, has yet to see widespread adoption of these technologies. In this paper we discuss our `in use' context in managing all of these devices, and our experience in building a prototypical implementation of digital twins using semantic technologies.</p>
      </abstract>
      <kwd-group>
        <kwd>Video</kwd>
        <kwd>IoT</kwd>
        <kwd>Digital twin Semantic technologies</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>Introduction</title>
      <p>
        The introduction of the IP-enabled digital video camera, commonly called IP
camera, by Axis Communications in 1996 [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ] enabled video management systems
(VMSs) to be built in software. VMSs allow a number of core functions: live
viewing of video streams from multiple camera sources; the application of a
policy on when to record video; and, the viewing of previously-recorded video
streams. Modern VMSs expand beyond these core capabilities, as illustrated in
Figure 1 [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ].
      </p>
      <p>In particular, modern VMSs provide multiple user interfaces which may be
`desktop' (installed), which allows capabilities like driving a video wall, or Web
or mobile based | native mobile clients often providing more advanced user
interactions, including comprehensive provision for searching over existing video
recordings. Furthermore, modern IP cameras allow a high degree of
softwarebased con guration, both with analogues to traditional cameras | i.e. aperture,
shutter speed, etc. | and digital speci c video streams characteristics | such as
resolution and codec / compression targets. In fact a single camera might produce
multiple streams with di erent settings for this latter class. Furthermore, for an
entire class of cameras, commonly called `PTZ cameras', there is continuous
operational control of motorised pan and tilt, as well as zoom. These settings
motivate having a database of device management settings, as well as a media
database, containing the actual recordings.
? Supported by the EU Horizon 2020 project 'SAFECARE: Integrated cyber-physical
security for health services', grant agreement number 787002.</p>
      <p>Video Wall
IP-based Video</p>
      <p>Cameras</p>
      <p>Desktop Client</p>
      <p>Search</p>
      <p>Alarms</p>
      <p>Video
Monitoring</p>
      <p>Video
Review
Camera
Drivers</p>
      <p>Video Management Server
Recording
Module
Media DB
Video
Analytics</p>
      <p>Video
Monitoring</p>
      <p>Video
Review</p>
      <p>Mobile Client</p>
      <p>Search</p>
      <p>Alarms
Integration</p>
      <p>Plug-ins
Search</p>
      <p>Module
Device Mgt.</p>
      <p>DB
Events, Rules</p>
      <p>&amp; Alarms</p>
      <p>The next common feature of modern VMSs is some provision for rules and
events via which they are triggered. An in-built source of events might be motion
detection within a video stream, so that the rule can trigger recording of the
stream; in this way storage is not wasted on video in which no motion occurs.
Some more sophisticated level of video analytics might also provide events that
trigger rules: for instance, license plate recognition might trigger the recording
of vehicles. External devices might also trigger events via integration plug-ins.</p>
      <p>
        One of the most successful commercial VMS o erings is XProtect [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ],
produced by Milestone Systems. XProtect is an open platform, which makes
available a number of APIs for extension. In the following we will use XProtect as
an example, and concentrate on video analytics and access control integration.
      </p>
      <p>
        XProtect has adopted the open source framework GStreamer [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ] to allow
extension with video analytics. In this way, integrators can run inference on
video streams using o -the-shelf models for deep learning-based object detection,
such as YOLOv3 [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ], and stream the results to object tracking solutions. Such a
solution creates rst a classi cation of objects | for instance detecting people
and vehicles of di erent types | together with bounding boxes within video
frames, but also tracks of the movement of objects across video frames.
      </p>
      <p>One of the key device integrations in XProtect is with access control
systems, which control physical access to areas of buildings. Figure 2 illustrates in
more detail how an access control system may be used in a door. What might
colloquially be called a `lock', or more properly a `strike', controls electronically
when a door can be opened. A door controller unit contains the logic to control
the strike, and this is connected to a reader, which may simply be an RFID card
reader or PIN pad or, commonly, a combination thereof. When a card is used to
identify a permitted person, the door controller can operate the strike to allow
the door to be opened.
REX</p>
      <sec id="sec-1-1">
        <title>Lock</title>
      </sec>
      <sec id="sec-1-2">
        <title>Door controller</title>
      </sec>
      <sec id="sec-1-3">
        <title>Reader</title>
        <p>In some con gurations, a reader is used on both sides of the door. In others,
a simple REX (request-exit) button is used, in which the operator does not
need to identify themselves with a card or PIN, as exit is allowed for all. In
more sophisticated set-ups the door might be equipped to automatically open,
or `speed gates' might be employed, which have both physical and digital means
to prevent | or at least provide an alarm in the case of | `tailgating', that
is a second unauthorised person gaining access by following closely behind an
authorised user.</p>
        <p>In this paper, we will sketch a combination of the above technologies in which
access control on a simple door is combined with video analytics, speci cally
object detection and tracking, to provide a means for tailgating detection. Further,
a knowledge graph that contains information on the layout of a hospital building
and the devices deployed in it, based on a set of ontologies that also allow the
representation of events based thereon in dynamic scenarios, will be shown to
allow inference of the vulnerabilities when such situations occur. An integration
with re sensors will also be included, which show escalation of the scenario of
attack.</p>
        <p>These scenarios are de ned by the collaborative project SAFECARE1,
specifically by three hospital consortium partners, the Assistance Publique | H^opitaux
de Marseille (coordinator of the project), the Academisch Medisch Centrum in
Amsterdam and ASLTO5 (Azienda Sanitaria Locale - Chieri - Carmagnola
Moncalieri - Nichelino) | hospitals in the Piedmont region of Italy. While trials
of the project's results are planned with all three hospital partners, an interim
test platform will be housed at the Instituto Superior de Engenharia do Porto,
as illustrated in Figure 3.</p>
        <sec id="sec-1-3-1">
          <title>1 https://www.safecare-project.eu/</title>
          <p>
            This part of the test platform for the SAFECARE project is built in Unreal
Engine [
            <xref ref-type="bibr" rid="ref9">9</xref>
            ]; although this is primarily a game engine, it has a long history of
use in building simulation [
            <xref ref-type="bibr" rid="ref3">3</xref>
            ] and in machine learning [
            <xref ref-type="bibr" rid="ref5">5</xref>
            ]. Within an o
-theshelf hospital model, we have added models for virtual cameras, virtual re
detectors (smoke and heat type) and virtual access control, as shown in Figure 4.
Furthermore, we have written generic and reusable extensions to Unreal such
that these device models appear to the XProtect VMS as real devices, as shown
on the left-hand side of Figure 5. In the case of cameras these provide live video
feeds from the point of view of the model instances. In the case of access control
and re sensors these are true digital twins to hardware devices and respond,
within the virtual world, to the events produced by the real world counterparts.
The right-hand of Figure 5 shows the novel map-based interface built for
demonstration of this work.
          </p>
          <p>In the remainder of this paper we will rst introduce the ontologies used to
build this system, and then sketch the cloud-based architecture via which the
system was created.
2</p>
        </sec>
      </sec>
    </sec>
    <sec id="sec-2">
      <title>Ontologies</title>
      <p>In order to locate devices within a building, simulated or real, it is natural
that we introduce a building ontology, which is shown in Figure 6. While this
ontology introduces concepts of Building and Floor, further structure is left to the
concept Location, which is de ned in the Grid Ontology, shown in Figure 7; this
concept is subclassed to de ne Zones and Intersections. In a building context,
Zones describe areas such as rooms and hallways, while Intersections are those
junctures between Zones, which may be controlled for instance by physical access
control.</p>
      <p>It is worthy of note that the Grid Ontology was not de ned for this
buildingbased use case, but originated in the description of tra c networks, where
Intersections are literal tra c intersections, and these are controlled by tra c lights.</p>
      <p>In a similar way, the IoT Ontology shown in Figure 8 is intended to
represent a whole array of sensor-type devices, which in another context might be
tra c sensors like inductive loops. Two characteristics of the IoT ontology are
of particular relevance. First, those subset of devices modelled by the Camera
class have a FieldOfView property, which is illustrated by four yellow triangles
on the map in Figure 5, representing the eld captured by the cameras in the
XProtect Smart Client on the left. Second, while all devices have a locatedAt
relationship with locations, AccessController s have a second relationship named
controlsAccessTo; this is shown for select parts on the oor plan in Figure 10.
leadsTo
leadsTo
leadsTo
leadsTo
Hallway 1</p>
      <p>Door 1</p>
      <p>Hallway 2
locatedAt
leadsTo
leadsTo</p>
      <p>Door 2
leadsTo</p>
      <p>Door 3
Fig. 10. Graph Representing Segment of Floor Plan
leadsTo
leadsTo
leadsTo
leadsTo</p>
      <p>Observation
Room 1</p>
      <p>Emergency Room 1</p>
      <p>Finally, the Events Ontology, shown in Figure 9 is used to model the dynamics
of this system, as follows:
{ AccessControlEvent is used to represent the operation of the access control
reader | this carries a property to convey whether the authorisation was
successful;
{ AccessChangeEvent is used to represent the operation of the door sensor
associated with the access controller, or of the gate in the case of speed
gates;
{ DoorTransitionEvent is used to represent the event that a human actually
transits through a door, and is produced using video analytics (though in the
current prototype this is simulated by having an extension to Unreal Engine
that produces this event when a person model passes through a door);
{ FireDetectionEvent is used to represent the operation of the re detection
sensors;
{ Alarms are produced by event processing logic, described in the following
section, as relate the events that led to the alarm.</p>
      <p>All instances of these event types carry a timestamp, and can be related to
locations, sensors and actors.
3</p>
    </sec>
    <sec id="sec-3">
      <title>Architecture</title>
      <p>The software architecture used for this system in shown in Figure 11. This is
cloud-based, built on Amazon Web Services, and uses the following services in
particular:
{ AWS EKS | the Elastic Kubernetes Service | allows the orchestration of
containers of custom code, for instance deployed using Docker containers;
{ AWS MSK | the Managed Streaming in Kafka service | allows horizontally
scalable publish-subscribe messaging of payloads such as JSON messages, via
Apache Kafka;
{ AWS AppSync | a managed service based on Apache Apollo that allows
the formation of GraphQL-based APIs, including the ability to subscribe to
receive noti cations according to a graph pattern;
{ AWS Neptune | a managed graph database service, which supports the
W3C RDF and SPARQL standards.</p>
      <p>
        Using these technologies together with the ontologies described in the
previous section, we can construct this system according to a uniform graph-based
data model. In particular, JSON-LD payloads are used on Kafka via which the
sensors, in the prototype proxied via the virtual hospital in Unreal Engine,
transmit their changes. Clients can both subscribe to hear particular messages, for
instance ltering by sensor or event type, using GraphQL, a combination of
technologies that is explored for instance in [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ], and on which the W3C has just
initiated a working group2.
      </p>
      <sec id="sec-3-1">
        <title>2 https://www.w3.org/community/graphql-rdf/</title>
        <p>The complex event processing involved in inferring tailgating from constituent
events is illustrated in Figure 12. In particular the sequence of a single
authorisation in the form of an AccessControlEvent, followed by two
DoorTransitionEvents, without an interleaved AccessControlEvent leads to Events Processing
to raise a TailgatingAlarm and publishing this back to the Kafka topic.
true
ac1
cam1
cam1
ac1
cam1
AccessControlEvent</p>
        <p>DoorTransitionEvent</p>
        <p>DoorTransitionEvent</p>
        <p>TailgateAlarm
AWS MSK (Kafka)</p>
        <p>target
Door1
target</p>
        <p>target
Door1</p>
        <p>Door1</p>
        <p>target
Door1</p>
        <p>By querying the oor plan graph, according to the dynamic information
on state, we can consequently determine a reachability graph for the tailgater.
Similarly, since the state of doors change in the event of a re alarm, allowing free
access due to the potential need to escape res, this reachability result can be
updated in the event of re, as shown (reachability indicated in red) in Figure 13.</p>
      </sec>
    </sec>
    <sec id="sec-4">
      <title>Conclusion and Further Work</title>
      <p>We have shown how an ontology-based approach allows both static
information on the situation of security devices within a hospital environment, and the
dynamics of these devices, to be modelled. We have shown further that an
architecture based on modern, horizontally-scalable cloud technologies can be used to
realise a useful implementation. We have illustrated the use of digital twins for
both access control devices and re sensors for simulation within this framework.</p>
      <p>Work is already underway in ontology-based representation of the full set
of camera, and other device, con guration based on the XProtect Management
Server. In future work we will make the virtual cameras true digital twins, where
these can be used as proxies for real hardware cameras.</p>
      <p>The approach here would be greatly aided by the convergence of GraphQL
and RDF/SPARQL, and we aim to contribute to this e ort. Similarly the use
of Apache Kafka together with JSON-LD, we feel, is an important enabling
approach for scaling the promising approach of digital twins in an IoT context
where network connectivity is neither constant nor reliable.</p>
    </sec>
    <sec id="sec-5">
      <title>Note</title>
      <p>The demonstration is available at https://youtu.be/UYH YI 31v4?t=906, but
the intention is also to give this demonstration at ESWC2020, both during the
workshop and at the demo session, for which a shorter paper has been submitted.</p>
    </sec>
    <sec id="sec-6">
      <title>Acknowledgements</title>
      <p>The authors would like to acknowledge the work of Dennis J rgensen at
Milestone Systems in assembling the complete virtual hospital model and developing
its virtual devices, as well as John Madsen and Tong Su at Milestone Systems
for their work on ontologies and graph data. We would also like to thank the
sta of Data Language for their collaboration on this project, and particularly
their insights into the use of GraphQL and cloud architecture.</p>
      <p>The virtual hospital made use of:
{ 'Modular Hospital', a 3D model developed by Aleksandr Zhdanov, and
purchased via Unreal Marketplace.
{ 3D models for cameras, re sensors and access control panels purchased via
SketchFab, with the following credits:
https://sketchfab.com/Terizmeh
https://sketchfab.com/gleb tihon
https://sketchfab.com/michael.diaz029</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          1.
          <string-name>
            <given-names>Axis</given-names>
            <surname>Communications</surname>
          </string-name>
          <string-name>
            <surname>AB</surname>
          </string-name>
          :
          <article-title>Moments that made us (</article-title>
          <year>2020</year>
          ), https://www.axis.com/about-axis/history, last accessed
          <issue>26 February 2020</issue>
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          2.
          <string-name>
            <surname>Lima</surname>
            ,
            <given-names>G.A.F.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Santos</surname>
            ,
            <given-names>R.C.M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Azevedo</surname>
            ,
            <given-names>R.G.D.A.</given-names>
          </string-name>
          :
          <article-title>Programming multimedia applications in GStreamer</article-title>
          . In: de Jesus Lima Gomes, F., de Andrade Lira Rabelo, R., de Salles Soares Neto,
          <string-name>
            <given-names>C.</given-names>
            ,
            <surname>Willrich</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            ,
            <surname>Teixeira</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.A.C.</given-names>
            ,
            <surname>de Almeida</surname>
          </string-name>
          , J.M.,
          <string-name>
            <surname>de Carvalho</surname>
          </string-name>
          , W.V. (eds.)
          <source>WebMedia</source>
          . pp.
          <volume>19</volume>
          {
          <fpage>20</fpage>
          .
          <string-name>
            <surname>ACM</surname>
          </string-name>
          (
          <year>2016</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          3.
          <string-name>
            <surname>Mol</surname>
            ,
            <given-names>A.C.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Jorge</surname>
            ,
            <given-names>C.A.F.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Couto</surname>
            ,
            <given-names>P.M.</given-names>
          </string-name>
          :
          <article-title>Using a game engine for VR simulations in evacuation planning</article-title>
          .
          <source>IEEE Computer Graphics and Applications</source>
          <volume>28</volume>
          (
          <issue>3</issue>
          ),
          <volume>6</volume>
          {
          <fpage>12</fpage>
          (
          <year>2008</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          4.
          <string-name>
            <surname>Normann</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Suciu</surname>
            ,
            <given-names>G.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Mantzana</surname>
            ,
            <given-names>V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Gkotsis</surname>
            ,
            <given-names>I.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Sachian</surname>
            ,
            <given-names>M.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Petrescu</surname>
            ,
            <given-names>G.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Ijaz</surname>
            ,
            <given-names>H.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Norton</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          :
          <article-title>Security systems in the healthcare sector</article-title>
          .
          <source>In: Integrated Security of Critical Infrastructures</source>
          (to appear). Now Publishers (
          <year>2020</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          5.
          <string-name>
            <surname>Qiu</surname>
            ,
            <given-names>W.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Yuille</surname>
            ,
            <given-names>A.L.</given-names>
          </string-name>
          :
          <article-title>Unrealcv: Connecting computer vision to unreal engine</article-title>
          .
          <source>CoRR abs/1609</source>
          .01326 (
          <year>2016</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          6.
          <string-name>
            <surname>Redmon</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Farhadi</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          :
          <article-title>YOLOv3: An incremental improvement</article-title>
          . CoRR abs/
          <year>1804</year>
          .02767 (
          <year>2018</year>
          ), http://arxiv.org/abs/
          <year>1804</year>
          .02767
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          7.
          <string-name>
            <given-names>Security</given-names>
            <surname>Sales</surname>
          </string-name>
          &amp;
          <article-title>Integration: Milestone systems ranked top global VMS provider for 10th straight year (</article-title>
          <year>2020</year>
          ), https://www.securitysales.com/surveillance/milestonesystems-top
          <string-name>
            <surname>-</surname>
          </string-name>
          vms-provider/,
          <source>last accessed 26 February 2020</source>
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          8.
          <string-name>
            <surname>Taelman</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          ,
          <string-name>
            <given-names>Vander</given-names>
            <surname>Sande</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            ,
            <surname>Verborgh</surname>
          </string-name>
          , R.: GraphQL-LD:
          <article-title>Linked Data querying with GraphQL</article-title>
          .
          <source>In: Proceedings of the 17th International Semantic Web Conference: Posters and Demos (Oct</source>
          <year>2018</year>
          ), https://comunica.github.io/ArticleISWC2018-Demo-GraphQlLD/
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          9.
          <string-name>
            <surname>Tavakkoli</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          :
          <article-title>Game Development and Simulation with Unreal Technology. A. K. Peters</article-title>
          , Ltd., USA, 1st edn. (
          <year>2017</year>
          )
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>