Access control system with temporary IP connection

By temporarily switching to IP communication mode in the access control reader for configuration updates, the problem of limited bandwidth and data rate of the OSDP communication protocol is solved, enabling a fast, secure, and efficient update process and improving system functionality and security.

CN121844537APending Publication Date: 2026-04-10ASSA ABLOY AB
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-08-14
Publication Date
2026-04-10

AI Technical Summary

Technical Problem

When the configuration update process of the existing access control reader is carried out through the OSDP communication protocol, the bandwidth and data rate are limited, resulting in long update time and high resource consumption, which limits the overall function of the system.

Method used

The server sends a command to the access control reader to temporarily switch it to IP communication mode, which is used to efficiently transmit configuration information. After the update is completed, it switches back to OSDP communication mode, using IP communication only for a specified period of time.

Benefits of technology

It enables fast, secure, and efficient updates to the access control reader, reducing system latency and resource consumption, and minimizing the risk of security vulnerabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121844537A_ABST
    Figure CN121844537A_ABST
Patent Text Reader

Abstract

Methods and systems are provided for temporarily enabling an Internet Protocol (IP) connection for an access control system. The method and system perform operations including: receiving, by a server, a request to update a configuration of an access control reader; transmitting, by the server, a first instruction to the access control reader over the wired link to temporarily switch from using the first communication mode to communicate with the server to the IP communication mode; transmitting an IP packet including the configuration information from the server to the access control reader to update a configuration of the access control reader; and after the configuration of the access control reader has been updated, transmitting, by the server, a second instruction to the access control reader to switch from using the IP communication mode to using the first communication mode.
Need to check novelty before this filing date? Find Prior Art

Description

BACKGROUND

[0001] Access control readers are widely used in various settings to control access to restricted areas. These readers are typically connected to a server that manages access control policies and configurations. To update the configuration of an access control reader, the server needs to communicate with the reader and send updated configuration information. Conventionally, this communication is done using a wired link and a specific communication protocol supported by the reader. SUMMARY

[0002] In some aspects, the technology described herein relates to a method comprising: receiving, by a server, a request to update a configuration of an access control reader; transmitting, by the server, first instructions to the access control reader over a wired link to temporarily switch from communicating with the server using a first communication mode to an Internet Protocol (IP) communication mode; sending, from the server to the access control reader, IP packets comprising configuration information (which can also or alternatively include firmware updates and / or configuration updates) to update the configuration of the access control reader; and after the configuration of the access control reader has been updated, transmitting, by the server to the access control reader, second instructions to switch back from communicating using the IP communication mode to communicating using the first communication mode.

[0003] In some aspects, the technology described herein relates to a method wherein the first communication mode comprises an Open Supervised Devices Protocol (OSDP) communication mode.

[0004] In some aspects, the technology described herein relates to a method wherein the access control reader communicates with the server using the first communication mode via a wired link, and wherein the access control reader communicates with the server using the IP communication mode via the wired link of the first communication mode.

[0005] In some aspects, the technology described herein relates to a method wherein the access control reader communicates with the server using the first communication mode via a first physical connection, and wherein the access control reader communicates with the server using the IP communication mode via a second connection different from the first physical connection.

[0006] In some aspects, the technology described herein relates to a method wherein the second connection comprises a wireless connection, the method further comprising: causing the access control reader to activate a WiFi device to establish an IP connection with the server.

[0007] In some aspects, the technology described herein relates to a method wherein the IP packets are sent from the server to the access control reader over a private IP connection.

[0008] In some aspects, the techniques described herein relate to a method further comprising establishing a secure IP connection between the server and the access control reader in response to transmitting the first instruction to the access control reader.

[0009] In some aspects, the techniques described herein relate to a method wherein the access control reader is configured to send access control information to the server using the first communication mode and is configured to receive updated configuration information (e.g., firmware updates and / or configuration updates) from the server using the IP communication mode.

[0010] In some aspects, the techniques described herein relate to a method wherein a data rate associated with the IP communication mode is greater than a data rate associated with the first communication mode.

[0011] In some aspects, the techniques described herein relate to a method further comprising causing the access control reader to activate a local physical (PHY) controller in response to receiving the first instruction.

[0012] In some aspects, the techniques described herein relate to a method further comprising causing the access control reader to deactivate the local PHY controller in response to receiving the second instruction.

[0013] In some aspects, the techniques described herein relate to a method further comprising receiving, by the server from the access control reader, a message indicating that the access control reader has completed switching to the IP communication mode.

[0014] In some aspects, the techniques described herein relate to a method wherein the message indicating that the access control reader has completed switching to the IP communication mode is received using the first communication mode.

[0015] In some aspects, the techniques described herein relate to a method wherein the message indicating that the access control reader has completed switching to the IP communication mode is received using the IP communication mode.

[0016] In some aspects, the techniques described herein relate to a method wherein the first instruction is sent from the server to the access control reader via an input / output (I / O) module coupled to the server.

[0017] In some aspects, the techniques described herein relate to a method wherein the I / O module is coupled to a plurality of access control readers, including the access control reader described above.

[0018] In some aspects, the technology described herein relates to a method, wherein the request to update a configuration of an access control reader includes a time, date, or time period that allows the access control reader to operate using an IP communication mode. The time, date, or time period is communicated to the access control reader and the access control reader is caused to automatically stop operating in the IP communication mode when the current time fails to match the time, date, or time period received from the server.

[0019] In some aspects, the technology described herein relates to a system comprising: one or more processors coupled to a memory, the memory comprising non-transitory computer instructions that, when executed by the one or more processors, cause the one or more processors to perform operations comprising: receiving, by a server, a request to update a configuration of an access control reader; communicating, by the server, first instructions to the access control reader over a wired link to temporarily switch from communicating with the server using a first communication mode to an IP communication mode; sending, from the server to the access control reader, an IP packet comprising configuration information to update the configuration and / or firmware of the access control reader; and after the configuration of the access control reader has been updated, communicating, by the server to the access control reader, second instructions to switch back to communicating using the first communication mode from communicating using the IP communication mode.

[0020] In some aspects, the technology described herein relates to a system, wherein the first communication mode comprises an OSDP communication mode.

[0021] In some aspects, the technology described herein relates to a system, wherein the access control reader communicates with the server using a first communication mode via a wired link, and wherein the access control reader communicates with the server using the IP communication mode via the wired link of the first communication mode.

[0022] In some aspects, the technology described herein relates to a non-transitory computer readable medium comprising non-transitory computer readable instructions that, when executed by one or more processors, configure the one or more processors to perform operations comprising: receiving, by a server, a request to update a configuration of an access control reader; communicating, by the server, first instructions to the access control reader over a wired link to temporarily switch from communicating with the server using a first communication mode to an IP communication mode; sending, from the server to the access control reader, an IP packet comprising configuration information to update the configuration of the access control reader; and after the configuration of the access control reader has been updated, communicating, by the server to the access control reader, second instructions to switch back to communicating using the first communication mode from communicating using the IP communication mode. BRIEF DESCRIPTION OF DRAWINGS

[0023] Figure 1 is a block diagram of an example access control system according to some examples.

[0024] Figure 2 shows an example access control device with multiple communication modes according to some examples.

[0025] Figure 3 is a flowchart showing example operations of an access control system according to some examples.

[0026] Figure 4 is a block diagram showing an example software architecture that can be used in conjunction with the various hardware architectures described herein.

[0027] Figure 5 is a block diagram showing components of a machine according to some examples. DETAILED DESCRIPTION

[0028] Example methods and systems for updating an access control system (e.g., a physical or logical access control system) over IP are described. In the following description, for the purposes of explanation, numerous specific details are set forth in order to provide a thorough understanding of the examples. It will be apparent, however, to one skilled in the art that the examples of the present disclosure can be practiced without

[0029] In a typical access control system, a centralized controller communicates with one or more access control readers via a physical wired connection. The access control readers can send access control information to the centralized controller over an OSDP communication protocol. The centralized controller can verify and authenticate access to a secure resource by processing the access control information received from the access control readers. The centralized controller can then send a command to the access control readers over the OSDP communication protocol indicating whether access to the secure resource is permitted.

[0030] In some cases, it is necessary to update the parameters, configuration information, and firmware of access control readers, for example, to improve various operations or enable new functionality. In order to update the parameters, configuration information, or firmware of access control readers (also collectively referred to herein as “configuration information”) in a secure manner, according to the OSDP communication protocol, updates are sent from a centralized controller to the access control readers over a physical wired connection. However, because the OSDP communication protocol is designed to efficiently communicate access control information, the OSDP communication protocol is limited in terms of bandwidth and data rate. As a result, it takes a significant amount of time and consumes a significant amount of resources to transmit updates to access control readers using the OSDP protocol. During the time it takes to update access control readers over the OSDP protocol, the access control readers are typically offline, which limits and constrains their overall use and functionality. Thus, while such systems generally work well, they introduce various delays in operating the devices and can frustrate users.

[0031] The disclosed examples provide a smart solution that can temporarily operate an access control system in an IP communication mode to quickly, securely, and efficiently provide updates to configuration information of access control readers. Additionally, because the access control readers only operate in the IP communication mode and communicate with the centralized controller for a user-specified period of time (e.g., a user-specified date, time, and / or duration), the risk of security breaches is controlled and reduced. In this way, access control readers can be quickly and efficiently updated, which improves the overall functionality of the system.

[0032] In particular, the disclosed examples receive, by a server (e.g., a centralized controller), a request to update a configuration of an access control reader. The server transmits, over a wired link, first instructions to the access control reader to temporarily switch from communicating with the server using a first communication mode to an IP communication mode. The server sends IP packets including configuration information to the access control reader to update the configuration of the access control reader. After the configuration of the access control reader has been updated, the server transmits second instructions to the access control reader to switch back to communicating using the first communication mode from communicating using the IP communication mode.

[0033] Figure 1 is a block diagram illustrating an example system 100 according to various examples. The system 100 can be an access control system that includes a client device 120, one or more access control devices 110 that control access to a protected asset or secure resource, for example, through a lockable door, and a server / controller 140 that is communicatively coupled over a network 130 (e.g., a LAN, a WAN, such as the Internet, a WiFi, a BLE, an Ultra-Wideband (UWB) communication protocol, a telephone network, or other wired or wireless communication protocol).

[0034] Client device 120 and access control device 110 can be communicatively coupled via electronic messages (e.g., packets exchanged over the Internet, BLE, UWB, WiFi Direct, NFC, or any other protocol). While Figure 1 A single access control device 110 and a single client device 120 are shown, but it should be understood that in other examples, multiple access control devices 110 and multiple client devices 120 can be included in system 100. As used herein, the term “client device” can refer to any machine that interfaces with a communication network (e.g., network 130) to exchange credentials with an access control device 110, a server / controller 140, another client device 120, or any other component to gain access to an asset or resource protected by the access control device 110. In some examples, a client device can additionally or alternatively communicate directly with, for example, an access control device or another client device.

[0035] In some cases, some or all of the components and functionality of server / controller 140 can be included in client device 120. Client device 120 can be, but is not limited to, a mobile phone, a desktop computer, a laptop computer, a portable digital assistant (PDA), a smart phone, a wearable device (e.g., a smart watch), a tablet, an ultrabook, a netbook, a laptop computer, a multi-processor system, a microprocessor-based or programmable consumer electronic, or any other communication device that a user can use to access a network.

[0036] Access control device 110 can include an access reader device (also referred to as an access control reader) connected to a secure / protected resource (e.g., a door locking mechanism or a backend server) that controls the secure / protected resource (e.g., a door locking mechanism). The resource associated with access control device 110 can include a door lock, an ignition system of a vehicle, or any other device that grants or denies access to a physical component and can be operated to grant or deny access to a physical component. For example, in the case of a door lock, access control device 110 can deny access, in which case the door lock remains locked and the door cannot be opened; or access control device 110 can grant access, in which case the door lock becomes unlocked to allow the door to be opened. As another example, in the case of an ignition system, access control device 110 can deny access, in which case the vehicle ignition system remains disabled and the vehicle cannot be started; or access control device 110 can grant access, in which case the vehicle ignition system becomes enabled and allows the vehicle to be started.

[0037] Physical access control encompasses a range of systems and methods for managing access, for example, of personnel to secure areas or secure assets. Physical access control includes: identification of authorized users or devices (e.g., vehicles, drones, etc.); and activation of gates, doors, or other facilities for securing an area; or activation of control mechanisms (e.g., physical or electronic / software control mechanisms) to allow access to secure assets. Access control device 110 forms part of a physical access control system (PACS), which can include readers (e.g., online or offline readers) that can hold authorization data (also referred to as access control information) and can be able to determine whether a credential (e.g., from a credential or key device such as a radio frequency identification (RFID) chip in a card, fob, or personal electronic device such as a mobile phone) is authorized for an actuator or control mechanism (e.g., a door lock, door opener, software control mechanism, closing an alarm, etc.), or the PACS can include a host server to which readers and actuators (e.g., via controllers) connect in a centrally managed configuration. In a centrally managed configuration, a reader can obtain credentials from a credential or key device and pass these credentials to a PACS host server or front-end system. The reader can send the credentials over a wired or wireless link using the OSDP communication protocol / mode. The host server then determines whether the credentials authorize access to a secure area or secure asset and commands the actuator or other control mechanism accordingly by sending an allow / deny message back to the reader over a wired or wireless link using the OSDP communication protocol / mode again. While examples of physical access control are used herein, the present disclosure is equally applicable to logical access control system (LACS) use cases (e.g., logical access to personal electronic devices, rider identification in transportation services, access and asset control for unmanned stores, etc.).

[0038] Generally, the access control device 110 can include one or more of a memory, a processor, one or more antennas, a communication module, a network interface device, a user interface, and a power source or power supply. The memory of the access control device 110 can be used in conjunction with the execution of an application or instructions by the processor of the access control device 110 and for the temporary or long-term storage of program instructions or instruction sets and / or credential or authorization data, such as credential data, credential authorization data, or access control data or instructions. For example, the memory can contain executable instructions used by the processor to run other components of the access control device 110 and / or make access determinations based on the credential or authorization data. The memory of the access control device 110 can include a computer-readable medium, which can be any medium that can contain, store, communicate, or transport data, program code, or instructions for use by or in connection with the access control device 110. The computer-readable medium can be, for example, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device. More specific examples of a suitable computer-readable medium include, but are not limited to, an electrical connection or a tangible storage medium such as a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), a dynamic RAM (DRAM), a compact disc read-only memory (CD-ROM), or other optical or magnetic storage devices. The computer-readable medium includes a computer-readable storage medium but excludes a computer-readable storage medium that is solely a transitory, propagating signal per se.

[0039] The processor of the access control device 110 can correspond to one or more computer processing devices or resources. For example, the processor can be provided as silicon, as a field-programmable gate array (FPGA), an application-specific integrated circuit (ASIC), any other type of integrated circuit (IC) chip, a collection of IC chips, etc. As a more specific example, the processor can be provided as a microprocessor, a central processing unit (CPU), or a plurality of microprocessors or CPUs configured to execute instruction sets stored in internal memory and / or memory of the access control device 110.

[0040] The antennas of the access control device 110 can correspond to one or more antennas and can be configured to provide wireless communication between the access control device 110 and a credential or key device (e.g., the client device 120). The antennas can be arranged to operate using one or more wireless communication protocols and operating frequencies including, but not limited to, IEEE 802.15.1, Bluetooth, BLE, NFC, ZigBee, Global System for Mobile Communications (GSM), Code Division Multiple Access (CDMA), Wi-Fi, RF, UWB, etc. By way of example, the antennas can be RF antennas and, as such, can transmit / receive RF signals through free space for reception / transmission by a credential or key device having an RF transceiver.

[0041] The communication module of the access control device 110 can be configured to communicate with one or more different systems or devices (e.g., one or more client devices 120 and / or the server / controller 140) remotely or locally from the access control device 110 according to any suitable communication protocol. In some cases, the communication module of the access control device 110 is configured to operate according to an IP communication mode when the access control device 110 is receiving updates to configuration information from the controller 140. After the access control device 110 is updated, the communication module of the access control device 110 automatically switches back to communicating according to a slower communication mode (e.g., the OSDP communication protocol / mode). In some cases, the communication module uses the same wired or wireless link between the access control device 110 and the controller 140 for all communication modes. In some cases, the communication module uses one wired or wireless link between the access control device 110 and the controller 140 to communicate access control information and a different wired or wireless link to communicate or receive configuration information updates from the controller 140 by the IP communication mode.

[0042] The network interface devices of the access control device 110 include hardware that is used to facilitate communication with other devices, such as one or more client devices 120 and / or a server / controller 140 (e.g., a PACS server), over a communication network (e.g., the network 130) utilizing any of a number of transfer protocols (e.g., frame relay, IP, transmission control protocol (TCP), user datagram protocol (UDP), hypertext transfer protocol (HTTP), etc.). Example communication networks can include a local area network (LAN), a wide area network (WAN), a packet data network (e.g., the Internet), mobile telephone networks (e.g., cellular networks), plain old telephone (POTS) networks, wireless data networks (e.g., IEEE 802.11 family of standards known as Wi-Fi, IEEE 802.16 family of standards known as WiMax), IEEE 802.15.4 family of standards, and peer-to-peer (P2P) networks, among others. In some examples, the network interface devices can include an Ethernet port or other physical jacks, a Wi-Fi card, a network interface card (NIC), a cellular interface (e.g., an antenna, filter, and associated circuitry), etc. In some examples, the network interface devices can include multiple antennas to enable wireless communication using at least one of single-input multiple-output (SIMO), multiple-input multiple-output (MIMO), or multiple-input single-output (MISO) techniques. In some cases, a portion of the hardware for communicating via IP communication modes with the network 130 can be disabled by default. This portion of the hardware can be enabled for a user-specified period of time to allow the access control device 110 to be updated via IP communication modes. In this way, rather than sending updates to the access control device 110 using the OSDP protocol, which has a relatively low data rate, the updates can be sent to the access control device 110 over IP communication modes, which have substantially higher data rates. Once these updates are complete, the access control device 110 returns to operating using the slower OSDP communication modes.

[0043] The user interface of the access control device 110 can include one or more input devices and / or display devices. Examples of suitable user input devices that can be included in the user interface include, but are not limited to, one or more buttons, a keyboard, a mouse, a touch-sensitive surface, a stylus, a video camera, a microphone, etc. Examples of suitable user output devices that can be included in the user interface include, but are not limited to, one or more LEDs, an LCD panel, a display screen, a touch screen, one or more lights, a speaker, etc. It will be appreciated that the user interface can also include combined user input and user output devices, such as a touch-sensitive display, etc.

[0044] The network 130 can include or operate in conjunction with an ad hoc network, an intranet, an extranet, a virtual private network (VPN), a LAN, a wireless network, a wireless LAN (WLAN), a WAN, a wireless WAN (WW AN), a metropolitan area network (MAN), a BLE, a UWB, the Internet, a portion of the Internet, a portion of the Public Switched Telephone Network (PSTN), a POTS network, a cellular telephone network, a wireless network, a Wi-Fi® network, another type of network, or a combination of two or more such networks. For example, a network or a portion of a network can include a wireless or cellular network, and a coupling can be a CDMA connection, a GSM connection, or other type of cellular or wireless coupling. In this example, the coupling can enable any of a variety of types of data transfer technology, such as single-carrier radio transmission technology (lxRTT), Evolution-Data Optimized (EVDO) technology, General Packet Radio Service (GPRS) technology, Enhanced Data rates for GSM Evolution (EDGE) technology, third Generation Partnership Project (3GPP) including 3G, fourth generation wireless (4G) networks, fifth generation wireless (5G) networks, Universal Mobile Telecommunications System (UMTS), High Speed Packet Access (HSPA), Worldwide Interoperability for Microwave Access (WiMAX), Long Term Evolution (LTE) standards, other standards defined by various standards-setting organizations, other short- or long-range protocols, or other data transfer technology.

[0045] In an example, as the client device 120 approaches the access control device 110 (e.g., comes within range of a BLE communication protocol), the client device 120 transmits a credential of the client device 120 over the network 130. In some cases, the credential can be selected from a plurality of credentials based on a current geographic location of the client device 120. For example, a plurality of credentials can be stored on the client device 120, each associated with a different geographic location. When the client device 120 comes within a certain distance (e.g., within 10 meters) of a geographic location associated with one of the credentials, the client device 120 retrieves the associated credential from local storage.

[0046] In one example, the client device 120 provides the credential directly to the access control device 110. In such cases, the access control device 110 transmits the credential to the server / controller 140. Figure 1 The server / controller 140 includes an authorization system 142 and a configuration update system 144. The server / controller 140 can also include elements described with respect to Figure 4 and Figure 5 The elements described, such as the memory having instructions stored thereon and the processor, cause the processor to control the functions of the server / controller 140 when the instructions are executed by the processor.

[0047] The server / controller 140 searches the list of credentials stored in the authorization system 142 to determine whether the received credential matches a credential in the list of authorized credentials for accessing a secure asset or resource (e.g., a door or secure area) protected by the access control device 110. In response to determining that the received credential is authorized to access the access control device 110, the server / controller 140 instructs the access control device 110 to perform an operation that grants access by the client device 120 (e.g., instructs the access control device 110 to unlock a lock on a door). In another example, the client device 120 provides a credential to the server / controller 140. The server / controller 140 searches the list of credentials stored in the authorization system 142 to determine whether the received credential matches a credential in the list of authorized credentials for accessing a secure asset or resource (e.g., a door or secure area) protected by the access control device 110. In response to determining that the received credential is authorized to access the access control device 110, the server / controller 140 instructs the access control device 110 (that is associated with the received credential and within a geographic distance of the client device 120) to perform an operation that grants access by the client device 120 (e.g., instructs the access control device 110 to unlock a lock on a door).

[0048] In some examples, the configuration update system 144 receives a request to update one or more access control devices 110. The request can identify the access control device 110 by an ID number or some other unique identifier. Based on the ID number or unique identifier of the access control device 110, the configuration update system 144 can initiate an update to the configuration parameters of the access control device 110. In some cases, the request can identify a particular set of multiple access control devices 110 that need to be updated. The configuration update system 144 can then initiate an update to the configuration parameters of each of the multiple access control devices 110 in the set.

[0049] In some examples, the controller 140 is coupled to an I / O module 146 or multiple I / O modules. Each I / O module 146 is coupled to a set of access control devices 110. The controller 140 can send instructions via the I / O module 146 to cause the access control devices 110 to switch operational modes. For example, the controller 140 can send an instruction to switch the operational mode of one or more access control devices 110. The instruction is sent to a particular I / O module 146. The I / O module 146 then forwards the instruction to the one or more access control devices 110 that are coupled to the I / O module 146. Similarly, any messages or information received by the I / O module 146 from one or more access control devices 110 can be forwarded back to the controller 140 for processing.

[0050] The request can indicate a time, date, and / or time period at which the update can be performed on the access control device 110. In such cases, the configuration update system 144 can wait until the current time matches the time, date, and / or time period indicated in the request before initiating the update process. At that time, the configuration update system 144 can send a first instruction to the access control device 110 (or to multiple access control devices 110 indicated in the request). The first instruction can instruct the access control device 110 to switch from communicating using the first communication mode (e.g., the OSDP mode) to communicating using the IP communication mode.

[0051] The access control device 110 can receive the first instruction and can activate one or more IP communication devices (e.g., a PHY controller or a WiFi device) to enable communication with the controller 140 via the IP communication mode / protocol. The access control device 110 can perform various IP handshake operations with the controller 140 to establish a private or public IP connection with the controller 140 via the network 130. Once the access control device 110 has completed the switch to the IP communication mode, the access control device 110 sends a message to the configuration update system 144 (e.g., a PACS server) indicating that the access control device 110 is operating in the IP communication mode and is ready to receive updated configuration information. In some examples, the message is sent from the access control device 110 to the controller 140 using the previous OSDP mode. In some examples, the message is sent from the access control device 110 to the controller 140 using the IP communication mode.

[0052] In response to receiving the message from the access control device 110 indicating that the access control device 110 is operating in the IP communication mode, the configuration update system 144 retrieves the configuration information from storage. The configuration update system 144 generates an IP packet including the configuration information. The configuration update system 144 sends the IP packet with the configuration information to the access control device 110 over the IP communication mode. In some cases, the IP packet is sent over the same physical link that the access control device 110 used to send access control information according to the OSDP communication mode. In some cases, the IP packet is sent over a completely different physical link than the physical link that the access control device 110 used to send access control information according to the OSDP communication mode.

[0053] The access control device 110 receives the IP packet including the configuration information. In response, the access control device 110 modifies or updates the local configuration information using the configuration information including the updated configuration information. After completing the update to the configuration information, the access control device 110 notifies the configuration update system 144 that the update has been completed. In response to completing the update to the configuration information (or in response to receiving all data associated with the configuration information from the controller 140), the access control device 110 also automatically switches back from operating using the IP communication mode to operating using the OSDP communication mode or other mode for exchanging access control information and communicates with the controller 140. For example, the configuration update system 144 can send a second instruction to the access control device 110 indicating confirmation that the update has been completely sent and instructing the access control device 110 to switch back to using the OSDP communication mode. In response to receiving the second instruction, the access control device 110 automatically switches from operating in the IP communication mode back to operating in the OSDP communication mode.

[0054] In some examples, the access control device 110 can receive a message or instruction from a user specifying when the access control device 110 is allowed to operate in the IP communication mode and / or for how long the access control device 110 is allowed to operate in the IP communication mode. The access control device 110 can receive a message from the configuration update system 144 indicating that updated configuration information is available. The access control device 110 can access the local configuration information to determine when the access control device 110 is allowed to operate in the IP communication mode. In response to determining that the current time matches the time specified in the local configuration information for which the access control device 110 is allowed to operate in the IP communication mode, the access control device 110 can send a message to the configuration update system 144 indicating that the access control device 110 is ready to operate in the IP communication mode to receive the update.

[0055] In response to receiving the message from the access control device 110, the configuration update system 144 can send a first instruction to the access control device 110 to cause the access control device 110 to operate using the IP communication mode. The access control device 110 can then switch to operating in the IP communication mode and can then receive the updated configuration information from the configuration update system 144 through the IP communication mode.

[0056] Figure 2An example access control device 110 is shown in accordance with some examples. The access control device 110 (e.g., a PACS control device) can include an OSDP communication protocol 210, an IP communication protocol 220, configuration information 230, and / or an IP communication device 240. The access control device 110 can be configured to operate using the OSDP communication protocol 210 by default. The access control device 110 can send access control information to the controller 140 using the OSDP communication protocol 210.

[0057] The access control device 110 can receive an instruction from the controller 140 indicating that an update to the configuration information is available, e.g., via the OSDP communication protocol 210. In response to receiving the instruction, the access control device 110 can activate the IP communication device 240 to allow the access control device 110 to operate using the IP communication protocol 220. The IP communication device 240 can include a PHY controller, a WiFi device, a LAN device, or any other physical hardware that can be used to generate IP packets and process IP packets for transmission over an IP communication link. The access control device 110 can send a message to the controller 140 indicating that the access control device 110 is ready to receive the update using the IP communication protocol 220 and / or over the OSDP communication protocol 210. In response, the controller 140 can send the updated configuration information in an IP packet to the IP communication device 240. The IP communication device 240 processes the IP packet and retrieves the updated configuration information from the IP packet. The access control device 110 can then modify the locally stored configuration information 230 based on the updated configuration information. The access control device 110 can then notify the controller 140 that the update has been completed. The access control device 110 can then automatically switch back to operating using the OSDP communication protocol 210, or can switch back in response to receiving an instruction from the controller 140. In this case, the IP communication device 240 can be deactivated or turned off, e.g., to conserve power / energy.

[0058] Figure 3 is a flowchart showing an example process or method 300 of an access control system 100 in accordance with some examples. The process 300 can be implemented in computer-readable instructions for execution by one or more processors, such that the operations of the process or method 300 can be performed, in part or in whole, by functional components of the system 100; thus, the process or method 300 is described below by way of example with reference to the system 100. However, in other examples, at least some of the operations of the process or method 300 can be deployed on various other hardware configurations. Some or all of the operations of the process or method 300 can be performed in parallel, out of order, or entirely omitted.

[0059] At operation 301, as discussed above, server / controller 140 (e.g., PACS server) receives a request to update the configuration of the access control reader.

[0060] At operation 302, as discussed above, server / controller 140 transmits a first instruction to access control reader via a wired link to temporarily switch from communicating with the server using a first communication mode to IP communication mode.

[0061] At operation 303, as discussed above, server / controller 140 sends an IP packet including configuration information to the access control reader to update the access control reader's configuration.

[0062] At operation 304, as discussed above, after the access control reader's configuration has been updated, the server / controller 140 sends a second instruction to the access control reader to switch back from communicating in IP communication mode to communicating in the first communication mode.

[0063] Figure 4 This is a block diagram illustrating an example software architecture 406 that can be used in conjunction with various hardware architectures described herein. Figure 4 This is a non-limiting example of a software architecture, and it should be understood that many other architectures can be implemented to facilitate the functionality described herein. Software architecture 406 can be implemented in, for example... Figure 5 The execution is performed on the hardware of machine 500, which includes processor 504, memory 514, and I / O components 518, etc. A representative hardware layer 452 is shown and can be represented as, for example... Figure 5 The machine 500. A representative hardware layer 452 includes a processing unit 454 having associated executable instructions 404. The executable instructions 404 represent executable instructions of the software architecture 406, including implementations of the methods, components, etc., described herein. Hardware layer 452 also includes a memory and / or storage device 456, which also has executable instructions 404. Hardware layer 452 may also include other hardware 458. Software architecture 406 can be deployed on... Figure 1 In any one or more of the components shown.

[0064] exist Figure 4In the example architecture of FIG. 4, the software architecture 406 can be conceptualized as a stack of layers, where each layer provides particular functionality. For example, the software architecture 406 can include layers such as an operating system 402, libraries 420, frameworks / middleware 418, applications 416, and a presentation layer 414. Operationally, the applications 416 and / or other components within the layers can invoke API calls 408 through the software stack and receive messages 412 in response to the API calls 408. The layers illustrated are representative, and not all software architectures have all layers. For example, some mobile or special-purpose operating systems can not provide a frameworks / middleware 418, while others can provide such a layer. Other software architectures can include additional or different layers.

[0065] The operating system 402 can manage hardware resources and provide common services. The operating system 402 can include, for example, a kernel 422, services 424, and drivers 426. The kernel 422 can act as an abstraction layer between the hardware and the other software layers. For example, the kernel 422 can be responsible for memory management, processor management (for example, scheduling), component management, networking, security settings, and so on. The services 424 can provide other common services for the other software layers. The drivers 426 are responsible for controlling or interfacing with the underlying hardware. For instance, the drivers 426 include display drivers, camera drivers, BLUETOOTH® drivers, UWB drivers, Bluetooth® drivers, flash memory drivers, serial communication drivers (for example, Universal Serial Bus (USB) drivers), Wi-Fi® drivers, audio drivers, power management drivers, and so forth, depending on the hardware configuration.

[0066] The libraries 420 provide a common infrastructure that can be used by the applications 416 and / or other software modules and / or components within the environment 400. The libraries 420 provide functionality that allows other software components to perform tasks in an easier fashion than to interface directly with the underlying operating system 402 functionality (e.g., kernel 422, services 424 and / or drivers 426). The libraries 420 can include system libraries 444 (e.g., C standard library) that can provide functions such as memory allocation functions, string manipulation functions, mathematical functions, and the like. In addition, the libraries 420 can include API libraries 446 such as media libraries (e.g., libraries to support presentation and manipulation of various media formats such as MPREG4, H.264, MP3, AAC, AMR, JPG, PNG), graphics libraries (e.g., an OpenGL framework that can be used to render two-dimensional (2D) and three-dimensional (3D) graphics on a display), database libraries (e.g., SQLite that can provide various relational database functions), web libraries (e.g., WebKit that can provide web browsing functionality), and the like. The libraries 420 can also include a wide variety of other libraries 448 to provide many other APIs to the applications 416 and other software components / modules.

[0067] The frameworks / middleware 418 (also sometimes referred to as middleware) provide a higher-level common infrastructure that can be used by the applications 416 and / or other software components / modules. For example, the frameworks / middleware 418 can provide various graphic user interface (GUI) functions, high-level resource management, high-level location services, and so forth. The frameworks / middleware 418 can provide a broad spectrum of other APIs that can be used by the applications 416 and / or other software components / modules, some of which can be specific to a particular operating system 402 or platform.

[0068] The applications 416 include built-in applications 438 and / or third-party applications 440. Example representative built-in applications 438 can include, but are not limited to, a contacts application, a browser application, a book reader application, a location application, a media application, a messaging application, and / or a game application. A third-party application 440 can include an application developed by an entity other than the vendor of the particular platform. The third-party application 440 can be a mobile software running on a mobile operating system such as IOS™, ANDROID™, WINDOWS® Phone, or other mobile operating systems. The third-party application 440 is illustrated as being stored in the memory 430, but can also be stored in another computer-readable medium accessible by the device 400.

[0069] The applications 416 can use built-in operating system functions (e.g., kernel 422, services 424 and / or drivers 426), libraries 420, and frameworks / middleware 418 to create the UI and to interact with a user of the system. Alternatively, or additionally, in some systems, interaction with a user can occur through a presentation layer, such as presentation layer 414. In these systems, the application / component "logic" can be distinct from the aspects of the application / component that interface with the user.

[0070] Figure 5 is a block diagram illustrating components of a machine 500, according to some examples, able to read instructions from a machine-readable medium (e.g., a machine-readable storage medium) and perform any one or more of the methodologies discussed herein. Specifically, the Figure 5 The diagrammatic representations of the machine 500 illustrate the hardware used in rendering and displaying graphical information on the machine 500 within which instructions 510 (e.g., software, a program, an application, an applet, an app, or other executable code) can be executed to cause the machine 500 to perform any one or more of the methodologies discussed herein. Recall that the instructions 510 transform the general, non-programmed machine 500 into a particular machine 500 programmed to carry out the described and illustrated functionality.

[0071] Accordingly, the instructions 510 can be used to implement devices or components described herein. The instructions 510 transform the general, non-programmed machine 500 into a particular machine 500 programmed to carry out the described and illustrated functions, such as the client device 120, the access control device 110, or the server / controller 140. In alternative examples, the machine 500 operates as a standalone device or can be coupled (e.g., networked) to other machines. In a networked deployment, the machine 500 can operate in the capacity of a server machine or a client machine in server-client network environments, or it can act as a peer machine in peer-to-peer (or distributed) network environments. The machine 500 can comprise, but not be limited to, a server computer, a client computer, a personal computer (PC), a tablet computer, a laptop computer, a netbook, a set-top box (STB), a personal digital assistant (PDA), an entertainment media system, a cellular telephone, a smart phone, a mobile device, a wearable device (e.g., a smart watch), a smart home device (e.g., a smart appliance), other smart devices, a web appliance, a network router, a network switch, a network bridge, or any machine capable of executing the instructions 510, sequentially or otherwise, that specify actions to be taken by machine 500. Further, while only a single machine 500 is illustrated, the term "machine" shall also be taken to include a collection of machines 500 that individually or jointly execute the instructions 510 to perform any one or more of the methodologies discussed herein.

[0072] Machine 500 can include processors 504, memory / storage 506, and I / O components 518, which can be configured to communicate with one another such as via a bus 502. In an example, the processors 504 (e.g., CPUs, reduced instruction set computing (RISC) processors, complex instruction set computing (CISC) processors, graphics processing units (GPUs), digital signal processors (DSPs), ASICs, radio-frequency integrated circuits (RFICs), another processor, or any suitable combination thereof) can include, for example, a processor 508 and a processor 512 that can execute the instructions 510. The term “processor” is intended to include multiple processors 504 that can be present in a Figure 5 Multiple processors 504 are shown, but a machine 500 can include a single processor with a single core, a single processor with multiple cores (e.g., a multi-core processor), multiple processors with a single core, multiple processors with multiple cores, or any combination thereof.

[0073] Memory / storage 506 can include a main memory or other storage for program or data that is directly accessible to the processors 504, such as a memory 514, a database 510, and a storage unit 516, both of which the processors 504 can access, e.g., via bus 502. Storage unit 516 and memory 514 store the instructions 510 implementing any one or more of the methods or functions described herein. The instructions 510 can also reside completely or partially within memory 514, storage unit 516, at least one of the processors 504 (e.g., within cache memory of the processors), or any suitable combination thereof during their execution by machine 500. Thus, memory 514, storage unit 516, and the memory of processors 504 are examples of machine-readable media.

[0074] I / O components 518 can include a wide variety of components to receive input, provide output, produce output, transmit information, exchange information, capture measurements, and so on. The specific I / O components 518 that are included in a particular machine 500 will depend on the type and Figure 5Many other components not shown can also be present in the device. The I / O components 518 are grouped according to, inter alia, the function performed by the I / O component. For the sake of presentation, the I / O components 518 are grouped based on the functionality they provide in the examples described below. In various examples, the I / O components 518 can include output components 526 and input components 528. The output components 526 can include visual components (e.g., a display such as a plasma display panel (PDP), an LED display, an LCD, a projector, or a cathode ray tube (CRT)), acoustic components (e.g., speakers), haptic components (e.g., a vibratory motor, resistance mechanisms), other signal generators, and so forth. The input components 528 can include alphanumeric input components (e.g., a keyboard, a

[0075] In further examples, the I / O components 518 can include biometric components 539, motion components 534, environmental components 536, or position components 538, among a wide array of other components. For example, the biometric components 539 can include components to detect expressions (e.g., hand expressions, facial expressions, vocal expressions, body gestures, or eye tracking), measure biosignals (e.g., blood pressure, heart rate, body temperature, perspiration, or brain waves), identify a person (e.g., voice identification, retinal identification, facial identification, fingerprint identification, or electroencephalogram-based identification), and the like. The motion components 534 can include acceleration sensor components (e.g., accelerometer), gravitation sensor components, rotation sensor components (e.g., gyroscope), and so forth. The environmental components 536 can include, for example, illumination sensor components (e.g., photometer), temperature sensor components (e.g., one or more thermometers that detect ambient temperature in the

[0076] Communication can be implemented using a wide variety of technologies. The I / O components 518 can include communication components 540 operable to couple the machine 500, via the

[0077] Moreover, the communication components 540 can detect identifiers or include components operable to detect identifiers. For example, the communication components 540 can include Radio Frequency Identification (RFID) tag reader components, NFC smart tag detection components, optical reader components (e.g., an optical sensor to detect one-dimensional bar codes such as Universal Product Code (UPC) bar codes, multi-dimensional bar codes such as Quick Response (QR) codes, Aztec codes, Data Matrix, Dataglyph, MaxiCode, PDF417, Ultra Code, UCC RSS-2D bar codes, and other optical codes), or acoustic detection components (e.g., microphones to identify tagged audio signals). Also, a variety of information can be derived via the communication components 540, such as location via Internet Protocol (IP) geolocation, location via Wi-Fi® signal triangulation, location via detecting an NFC beacon signal that can indicate a particular location, and so forth.

[0078] Glossary:

[0079] “Carrier signal” refers to any intangible medium that is capable of storing, encoding, or carrying the instructions for execution by a machine and includes digital or analog communications signals, or other intangible media to facilitate communication of such instructions. Instructions can be communicated by the network interface device and using any one of a number of transfer protocols (e.g., file transfer protocol (FTP), file exit protocol (FTP), thunderbolt, etc.). Where instructions are transmitted recursively, for example, downloaded, electronic

[0080] A "client device" in this context refers to any machine that interfaces with a communications network to access resources from one or more server systems or other client devices, or to be directly

[0081] A "communications network" in this context refers to one or more portions of a network that can be an ad hoc network, an intranet, an extrananet, a VPN, a LAN, a BLE network, a UWB network, a WLAN, a WAN, a WWAN, a MAN, the Internet, a portion of the Internet, a portion of the PSTN, a POTS network, a cellular telephone network, a wireless network, a Wi-Fi® network, another type of network, or a combination of two or more such networks. For example, a network or a portion of a network can include a wireless network or a cellular network, and a coupling can be a CDMA connection, a GSM connection, or other type of cellular or wireless coupling. In this example, the coupling can enable any of a variety of types of data transfer techniques, such as 1xRTT, EVDO technology, GPRS technology, EDGE technology, 3GPP including 3G, 4G networks, UMTS, HSPA, WiMAX, LTE standards, other standards defined by various standards-setting organizations, other long-range protocols, or other data transfer techniques.

[0082] A "machine-readable medium" in this context refers to a component, device, or other tangible media capable of storing instructions and data temporarily or permanently, and can include, but is not limited to, RAM, ROM, buffer memory, flash memory, optical media, magnetic media, cache memory, other types of storage (e.g., Erasable Programmable Read Only Memory (EEPROM)) and / or any suitable combination thereof. The term "machine-readable medium" should be taken to include a single medium or multiple media (e.g., a centralized or distributed database, or associated caches and servers) capable of storing instructions that are executed by a machine, such that the instructions, when executed by one or more processors of the machine, cause the machine to perform any one or more of the methodologies described herein. Accordingly, a "machine-readable medium" is taken to include single storage apparatus or devices, as well as "cloud-based" storage systems or storage networks that include multiple storage apparatus or devices. The term "machine-readable medium" is taken to exclude signals per se.

[0083] "Component" in this context refers to a device, physical entity or logic having boundaries defined by the function or subroutine calls, branches, API, or other technologies that provide the boundaries of a particular processing or control function, implemented in either machine- readable medium code or software. A component can interface with other components at boundaries. A component can be a packaged functional hardware unit designed for use with other components and typically provides a particular functionality at an interface. Components can be software or hardware components. A "hardware component" is tangible unit capable of performing certain operations and can be configured or arranged in a certain physical manner. In various examples, one or more computer systems (e.g., a standalone computer system, a client computer system, or a server computer system) or one or more hardware components of a computer system (e.g., a processor or a group of processors) can be configured by software (e.g., an application or application portion) as a hardware component that operates to perform certain operations as described herein.

[0084] A hardware component can also be implemented mechanically, electronically, or in any suitable combination of the above. For example, a hardware component can include dedicated circuitry or logic that is permanently configured to perform certain operations. A hardware component can be a special-purpose processor, such as a FPGA or an ASIC. A hardware component can also include programmable logic or circuitry that is temporarily configured by software to perform certain operations. For example, a hardware component can include software executed by a general-purpose processor or other programmable processor. Once configured by such software, hardware components become specific machines (or specific components of a machine) uniquely tailored to perform the configured functions and are no longer general-purpose processors. It will be appreciated that a hardware component can be implemented in many different ways. For example, a hardware component can be implemented as a "processing system" which includes one or more processors. The processing system can be a system on a chip (SoC). In this example, a hardware component can be implemented by one or more processors within a SoC. Thus, the

[0085] Hardware components can provide information to, and receive information from, other hardware components. Thus, described hardware components can be regarded as being communicatively coupled. Where multiple hardware components exist contemporaneously, communications can be achieved through signal transmission (e.g., over appropriate circuits and buses) between or among two or more of the hardware components. In examples in which multiple hardware components are configured or instantiated at different times, communications between such hardware components can be achieved, for example, through the storage and retrieval of information in memory structures to which the multiple hardware components have access. For example, one hardware component can perform an operation and store the output of that operation in a memory device to which it is communicatively coupled. A further hardware component can then access the memory device to retrieve and process the stored output at a later time.

[0086] Hardware components can also initiate communications with input or output devices, and can operate on a resource (e.g., a collection of information). The various operations of example methods described herein can be performed, at least partially, by one or more processors that are temporarily configured (e.g., by software) or permanently configured to perform the relevant operations. Whether temporarily or permanently configured, such processors can constitute processor-implemented components that operate to perform one or more operations or functions described herein. As used herein, “processor- implemented component” refers to a hardware component implemented using one or more processors. Similarly, the methods described herein can be at least partially processor-implemented, with a particular processor or processors being an example of hardware. For example, at least some of the operations of a method can be performed by one or more processors or processor-implemented components. Moreover, a processor or processors can also operate to support performance of the relevant operations in a “cloud computing” environment or as a “software as a service” (SaaS). For example, at least some of the operations can be performed by a group of computers (as examples of machines including processors), with these operations being accessible via a network (e.g., the Internet) and via one or more appropriate interfaces (e.g., an API). The performance of certain of the operations can be distributed among the processors, not only residing within a single machine, but deployed across a number of machines. In some examples, the processors or processor-implemented components can be located in a single geographic location (e.g., within a home environment, an office environment, or a server farm). In other examples, the processors or processor-implemented components can be distributed across a number of geographic locations.

[0087] A "processor" in this context refers to any circuit or virtual circuit (physical circuit emulated by logic executing on an actual processor) that manipulates data values according to control signals (e.g., "commands", "op codes", "machine code", etc.) and that produces results of the operations as output signals that are used by other circuits or virtual circuits. A processor can be a CPU, RISC processor, CISC processor, GPU, DSP, ASIC, RFIC, or any combination thereof, for example. A processor can also be a multi-core processor having two or more independent processors (sometimes called "cores") that can execute instructions concurrently.

[0088] Changes and modifications can be made to the disclosed examples without departing from the scope of the present disclosure. These and other changes or modifications are intended to be included within the scope of the present disclosure as expressed in the following claims.

[0089] The abstract of the disclosure is provided to allow the reader to quickly ascertain the nature of the technical disclosure. It is submitted with the understanding that it will not be used to interpret or limit the scope or the meaning of the claims. In addition, in the foregoing Detailed Description, it can be seen that various features are grouped together in a single example for the purpose of streamlining the disclosure. The method of the present disclosure is not to be interpreted as reflecting an intention that the claimed examples require more features than are expressly recited in each claim. Rather, as the appended claims reflect, inventive subject matter can lie in fewer than all features of a single disclosed example. Thus, the following claims are hereby incorporated into the Detailed Description, wherein each claim independently represents a separate example.

Claims

1. A method comprising: receiving, by a server, a request to update a configuration of an access control reader; transmitting, by the server, first instructions to the access control reader over a wired link to temporarily switch from communicating with the server using a first communication mode to an Internet Protocol (IP) communication mode; sending, from the server to the access control reader, an IP packet including configuration information to update the configuration of the access control reader; and after the configuration of the access control reader has been updated, transmitting, by the server to the access control reader, second instructions to switch back from communicating using the IP communication mode to communicating using the first communication mode. the first communication mode comprises an Open Supervised Device Protocol (OSDP) communication mode.

2. The method of claim 1, wherein, the access control reader communicates with the server using the first communication mode via a wired link; and 3. The method of any one of claims 1-2, wherein, wherein the access control reader communicates with the server using the IP communication mode via the wired link of the first communication mode. the access control reader communicates with the server using the first communication mode via a first physical connection; and wherein the access control reader communicates with the server using the IP communication mode via a second connection different from the first physical connection.

4. The method of any one of claims 1 to 3, wherein, the second connection comprises a wireless connection, the method further comprising: causing the access control reader to activate a WiFi device to establish an IP connection with the server.

5. The method of claim 4, wherein, sending the IP packet from the server to the access control reader over a private IP connection.

7. The method of any of claims 1-6, further comprising:

6. The method of any one of claims 1 to 5, wherein, establishing, between the server and the access control reader, a secure IP connection in response to transmitting the first instructions to the access control reader. the access control reader is configured to send access control information to the server using the first communication mode and is configured to receive updated configuration information from the server using the IP communication mode. a data rate associated with the IP communication mode is greater than a data rate associated with the first communication mode.

8. The method of any one of claims 1 to 7, wherein, 10. The method of any of claims 1-9, further comprising:

9. The method of any one of claims 1 to 8, wherein, causing the access control reader to activate a local physical (PHY) controller in response to receiving the first instructions.

11. The method of claim 10, further comprising: causing the access control reader to deactivate the local PHY controller in response to receiving the second instructions.

12. The method of any of claims 1-11, further comprising: receiving, by the server from the access control reader, a message indicating that the access control reader has completed switching to the IP communication mode. receiving the message using the first communication mode. receiving the message using the IP communication mode.

13. The method of claim 12, wherein, sending the first instructions from the server to the access control reader via an input / output (I / O) module coupled to the server.

14. The method of any one of claims 12-13, wherein, ​ 15. The method of any one of claims 1 to 14, wherein, ​ 16. The method of claim 15, wherein, The I / O module is coupled to a plurality of access control readers, including the access control reader.

17. The method of any one of claims 1 to 16, wherein, The request to update the configuration of the access control reader includes at least one of a time, a date, or a time period during which the access control reader is permitted to operate using the IP communication mode.

18. The method of claim 17, wherein, The at least one of the time, the date, or the time period is communicated to the access control reader and the access control reader is caused to automatically stop operating in the IP communication mode when a current time fails to match the at least one of the time, the date, or the time period received from the server.

19. A system comprising: one or more processors coupled to memory, the memory including non-transitory computer readable instructions that, when executed by the one or more processors, cause the one or more processors to perform operations comprising: receiving, by a server, a request to update a configuration of an access control reader; communicating, by the server, first instructions to the access control reader over a wired link to temporarily switch from communicating with the server using a first communication mode to an Internet Protocol (IP) communication mode; sending, from the server to the access control reader, an IP packet including configuration information to update the configuration of the access control reader; and after the configuration of the access control reader has been updated, communicating, by the server to the access control reader, second instructions to switch back from communicating using the IP communication mode to communicating using the first communication mode.

20. A non-transitory computer readable medium including non-transitory computer readable instructions that, when executed by one or more processors, configure the one or more processors to perform operations comprising: receiving, by a server, a request to update a configuration of an access control reader; communicating, by the server, first instructions to the access control reader over a wired link to temporarily switch from communicating with the server using a first communication mode to an Internet Protocol (IP) communication mode; sending, from the server to the access control reader, an IP packet including configuration information to update the configuration of the access control reader; and after the configuration of the access control reader has been updated, communicating, by the server to the access control reader, second instructions to switch back from communicating using the IP communication mode to communicating using the first communication mode.

21. A computer readable medium carrying computer readable instructions that, when executed by one or more processors, configure the one or more processors to perform the method of any of claims 1-18.

22. A system comprising: one or more processors; and ​ A computer-readable medium storing computer-readable instructions that, when executed by the one or more processors, cause the one or more processors to perform the method of any one of claims 1-18.