Method for controlling access authorization to a restricted area
By employing NFC technology between mobile terminals and blocking devices, along with an external server for access management, the method addresses the inefficiencies of traditional access authorization systems, providing streamlined and dynamic control over access to restricted areas.
Patent Information
- Application Number
- DE102023211564
- Authority / Receiving Office
- DE · DE
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-11-21
- Publication Date
- 2025-05-22
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Current methods for managing access authorizations to restricted areas, such as factory sites and parking spaces, are cumbersome and inefficient, often requiring physical cards and manual system updates.
A method utilizing near-field communication (NFC) between a mobile terminal and a blocking device, coupled with an external server, to dynamically manage access authorizations, allowing for easy allocation, quick withdrawal, and real-time updates.
This solution simplifies and accelerates access control, enabling more efficient management of access authorizations, reducing the need for physical cards, and allowing for real-time adjustments to meet changing access needs.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[0001] The present invention relates to the field of access monitoring of restricted areas, in particular factory-owned areas which are to be accessible only to certain users.
[0002] To gain access to factory premises or other restricted areas, authorization cards are often issued. These are usually provided with access authorization information, which can be read, for example, by a card reader in a locking device using near-field communication. If the access authorization information is valid, the locking device grants access.
[0003] Restricted access areas include parking lots, company premises and buildings, or even internal company rooms. The relevant access authorization information, based on the employee's status, is usually stored on an employee ID card, which the employee receives from a central location. Access to a parking space is generally not part of the stored access authorization information. Parking space access is generally only possible with a separate card. Obtaining cards, particularly for temporary access, is often problematic, as the authorization must first be stored in an internal system, then queried by the card-issuing office, and the corresponding card must be created. To delete an access authorization, e.g.Because access is no longer authorized or the card has been lost, the card can be blocked if the system is designed for this, or cards are always issued only with time-limited, valid access authorization information.
[0004] Since the current methods for granting access authorizations are cumbersome, the object of the invention is to provide an improved method for controlling access authorization to a restricted area.
[0005] This object is achieved by the features of the independent claims. Advantageous embodiments are the subject of the dependent claims.
[0006] A method is proposed for controlling access authorization to a restricted-access area, wherein the restricted-access area has a blocking device which has at least a first communication interface for near-field communication and which grants or denies access to the restricted-access area based on predetermined, valid access authorization information, and wherein a user's mobile terminal serves as a second communication interface which can communicate with the first communication interface by means of near-field communication in order to exchange access authorization information in the event of an authorization request through the second communication interface, and can communicate with an external server in order to obtain access authorization in the form of access authorization information for the restricted-access area after authentication and authentication in a predetermined system.wherein the first communication interface checks the access authorization information communicated by the second communication interface via near-field communication and allows access if the access authorization information is valid and denies access if the access authorization information is not valid.
[0007] In one embodiment, the restricted access area is a factory parking lot or a factory entrance.
[0008] In one embodiment, the specified system is a company-internal employee list that represents the users, wherein the employee list contains at least one employee status with associated access authorizations for company facilities, and wherein the server automatically assigns the access authorization to the restricted area depending on an employee status.
[0009] In one embodiment, valid access authorization information is stored in the first communication interface and is used to compare it with access authorization information communicated by the second communication interface, or wherein the first communication interface communicates with the server as soon as access authorization information is communicated by the second communication interface in order to query the server as to whether the access authorization information is valid or not.
[0010] In one embodiment, if the access-restricted area is limited to a quota for a number of users, the server processes this information in such a way that, once the quota is reached, it withdraws access authorization for all other users.
[0011] In one implementation, a notification is issued to a user about reaching the quota limit.
[0012] In one embodiment, if a quota limit is reached, a user can request the server to release additional quotas, or the server can automatically release additional quotas.
[0013] In one embodiment, additional information is transmitted to the second communication interface and displayed to the user, comprising: available parking spaces in a parking area and / or a quota of a parking area.
[0014] Furthermore, a computer program product is provided which carries out the method when implemented on one or more computing units.
[0015] Further features and advantages of the invention will become apparent from the following description of exemplary embodiments of the invention, with reference to the figures of the drawing, which illustrate details of the invention, and from the claims. The individual features can be implemented individually or in combination in a variant of the invention.
[0016] Preferred embodiments of the invention are explained in more detail below with reference to the accompanying drawings.
[0017] Fig. 1 shows important components for carrying out the method according to an embodiment of the present invention.
[0018] There are many applications where access to a restricted area is only possible using an authorization card, such as an employee ID card. This is often the case on company premises, in particular, where only employees are allowed to be in certain areas. This also applies to employee parking spaces. Here it is often necessary to sign in and out with plant security, for example. Authorization cards, such as an employee ID card with the appropriate authorization stored, may be available, for example to open barriers in parking areas such as parking garages or car parks. Such authorization cards and their functionality are well known in the art.
[0019] A common problem is that, due to the large number of authorizations required, separate cards or authorizations on employee ID cards are not issued to employees, or are issued too late. For example, permanently assigned parking spaces are not used, which further worsens the already strained parking situation and the workload of plant security.
[0020] Therefore, one of the aims of the invention is to make it easier and faster to assign and revoke authorizations for employee parking spaces, for example.
[0021] This is achieved by an authorization query using near field communication (NFC) between the locking device 1, which is already present in access-restricted areas 3 and is equipped with NFC as a communication interface 10, and a mobile terminal 20 of a user 2.
[0022] It is therefore intended that the communication interface 10 for near-field communication (NFC) of the barrier 1 will continue to be used to check whether access is granted or denied to a specific user 2, e.g., whether the barrier is opened or remains closed. Previously, this was achieved using an authorization card that communicates with the communication interface 10 of the barrier 1 via near-field communication.
[0023] In order to provide improved verification of access authorization, it is proposed to use a communication interface 20 of a mobile device of a user 2 instead of an authorization card. The communication interface 20 is an NFC interface that is already present in mobile devices. For example, such a mobile device can be a smartphone of a user 2. Such a mobile device can communicate with the NFC interface (communication interface 10) of the barrier device 1 via its NFC interface (communication interface 20) and exchange access authorization information. This information is then verified by the communication interface 10 of the barrier device 1, as described below. If the access authorization information is valid, the barrier device 1 grants access to the restricted-access area 3, e.g., by opening a barrier.
[0024] In addition, the mobile device must have a further interface 21 in order to be able to communicate with an external server 4 in order to obtain access authorization, which can be stored as access authorization information that can be compared with the communication interface 10 of the blocking device 1. Communication with the server 4 and the blocking device preferably takes place via a so-called app. The advantage of an app is that a dedicated authorization query and the storage of authorizations are possible. Each time the app is opened to establish communication with the communication interface 10 of the blocking device 1, a check can be made to determine whether the app's access authorization information is still current and valid by establishing communication with the server 4 in which the corresponding data is stored. Communication takes place in real time, e.g.via mobile communications, radio, WLAN, etc., depending on where the server is located.
[0025] Server 4 thus serves as an external administration device to manage access authorizations for the mobile devices on which the corresponding app is installed. Mobile devices and their associated users 2 can be stored here. These users can be assigned appropriate access authorizations on the server side, i.e., automatically or manually. These authorizations are then transferred to the mobile device or retrieved in real time when the app is used.
[0026] In one embodiment, server 4 can respond to a so-called push request and transmit corresponding access authorization information to the mobile device, i.e., user 2, in real time. This is preferably done automatically.
[0027] The server 4 stores the relevant data for transmitting the necessary information to a mobile device. For example, an internal company employee list is stored, whereby each employee (as user 2) can be assigned one or more access authorizations, e.g., depending on a status stored for the employee. As soon as the status changes, the access authorization(s) can also change. This information is then transmitted via the server 4 to the app when it is used, so that an up-to-date access authorization is always available for each user 2. If a mobile device is linked to an employee, the authorization, i.e. access authorization information valid for a blocking device 1, can be transmitted to the mobile device. This means that an up-to-date access authorization is always available for each user 2.
[0028] In one embodiment, access authorization(s) can be granted not only permanently or for a longer period of time, but also for a short period of time. For example, a user 2 can be granted access to an otherwise inaccessible, restricted area 3 for a special event, e.g., temporarily during a major priority event, by having the corresponding access authorization released by the server 4, e.g., based on an authorization list stored there.
[0029] In order to use the described method of using a mobile device and an app, authentication is necessary, for example, assigning a username and password. When using the app, authentication must then take place, meaning the username and password must be correctly entered into the app. A wide variety of authentication methods are known from the state of the art, from which a specialist can select and implement a suitable one.
[0030] In one embodiment, permanently valid access authorization information can be stored in the locking device 1, which serves to grant or deny access to the restricted area 3.
[0031] Alternatively, the blocking device 1 can be configured to communicate with the server 4 in order to request valid access authorization information for the respective user 2 from the server 4 for each access request by a mobile terminal and to compare it with the access authorization information communicated by the mobile terminal, i.e. to check it for compliance with the valid access authorization information.
[0032] The proposed improved control of access authorization to a restricted area 3 allows access to a restricted area 3 to be provided more easily, quickly, and variably than before. This is achieved primarily because previous individual authorization cards are replaced by a mobile system, through which access authorizations can be easily assigned and quickly revoked if necessary.
[0033] One application of the process is the release of parking spaces, for example, in parking garages. Currently, parking spaces are often not used because access has not been granted. This can be improved with the proposed process, as appropriate authorizations can be stored for each employee in a central system (server), which can be accessed in real time via the app. Thus, a physical card no longer needs to be issued, as was previously the case.
[0034] By registering with an app, for example, access rights can be assigned or revoked to a much larger group of people than before. In one version, the app is only available internally to the company, meaning it is only available to employees.
[0035] A major advantage of this process is that new access authorization requirements (both expanded and restricted) can be rolled out on a daily basis or in real time. This includes, for example, unlocking available visitor parking spaces for access, for example, when regular spaces are already occupied. This can also be achieved by integrating the system into an existing app or linking it to an existing app that displays available parking spaces.
[0036] Access is actually granted by holding the NFC-enabled mobile device to the corresponding interface 10 of the locking device 1, which, upon recognition of authorization, grants access, e.g., opens the barrier. Further processes, such as billing, allocation, occupancy updates, etc., can be triggered if the relevant data and / or interfaces are stored in the app.
[0037] Another special feature of the system is that it is implemented without the operator having to provide additional hardware (RFIDs / NFC tags), and furthermore that the system is networked, with numerous functions and options for using these functions.
[0038] The procedure can be extended so that, for example, another access point can be realized than just for a parking area, for example for turnstiles.
[0039] In a further embodiment, it can be provided that, for example, a switch can be made on a daily basis from a physical authorization card to access via a mobile device. It is advantageous that only one medium, i.e., mobile device or authorization card, can be used at a time to prevent two people from using the same access authorization. In the event of a loss of the authorization card, the switch can serve as a simple bridging option; if it is found again, the real-time connection to server 4 allows for immediate switching back to the physical card.
[0040] The process is cost-effective and easy to implement, as it can be used with a standard smartphone, for example. The function can be implemented as part of an app, such as a parking or ride-hailing app. It also offers the option of implementing micropayments or other billing methods (e.g., pro rata usage allocated to quotas).
[0041] In one embodiment, if a predetermined quota of accesses is set, each access request to the blocking device 1 is checked to determine whether a quota limit has been reached. If this is the case, access is denied. Optionally, a message can be displayed in the app indicating that the quota limit has been reached. Furthermore, if quota limits exist, these can be reset daily, hourly, or at specific time intervals or times to meet demand. This can be easily done from a central workstation with access to the server 4, since the activation takes place electronically. List of reference symbols 1 locking device 10 Communication interface 2 users 20 NFC communication interface mobile device 21 Server communication interface mobile device 3 restricted access areas 4 servers
Claims
[1] Method for controlling access authorization to a restricted access area (3), wherein - the access-restricted area (3) has a blocking device (1) which has at least one first communication interface (10) for near-field communication and which allows or denies access to the access-restricted area (3) based on predetermined, valid access authorization information, and wherein - a mobile terminal of a user (2) serves as a second communication interface (20), which - can communicate with the first communication interface (10) by means of near-field communication in order to exchange access authorization information in the event of an authorization request through the second communication interface (20), and - can communicate with an external server (4) in order to obtain, after authentication and authentication in a predetermined system, an access authorization in the form of access authorization information for the access-restricted area (3), wherein the first communication interface (10) checks the access authorization information communicated by the second communication interface (20) via near-field communication and allows access if the access authorization information is valid and denies access if the access authorization information is not valid. [2] Method according to claim 1, wherein the restricted access area (3) is a factory parking lot or a factory entrance. [3] Method according to claim 1 or 2, wherein the predetermined system is an internal company employee list which represents the users (2), wherein at least one employee status with associated access authorizations for company facilities is stored in the employee list, and wherein the server (4) automatically assigns the access authorization to the restricted area (3) depending on an employee status. [4] Method according to one of the preceding claims, wherein - valid access authorization information is stored in the first communication interface (10) and is used to compare with access authorization information communicated by the second communication interface (20), or wherein - the first communication interface (10) communicates with the server (4) as soon as access authorization information is communicated by the second communication interface (20) in order to query the server (4) as to whether the access authorization information is valid or not. [5] Method according to one of the preceding claims, wherein in the case that the access-restricted area (3) is limited to a quota for a number of users (2), the server (4) processes this information in such a way that, once the quota has been reached, it withdraws the access authorization for all further users (2). [6] Method according to claim 5, wherein a notification is issued to a user (2) about reaching the quota limit. [7] Method according to claim 5 or 6, wherein in the event that a quota upper limit is reached, a user (2) can request the release of further quotas from the server (4), or an automatic release of further quotas is carried out by the server (4). [8] Method according to one of the preceding claims, wherein additional information is transmitted to the second communication interface (20) and displayed to the user (2), comprising: available parking spaces in a parking area and / or a quota of a parking area. [9] Computer program product which carries out the method according to one of the preceding claims when it is implemented on one or more computing units.