Access control system for buildings with a monitoring unit for recording signs of misuse.
The access control system uses dual radio standards and a monitoring unit to enhance security by detecting misuse patterns and requiring a secondary authentication factor, balancing security and convenience.
Patent Information
- Authority / Receiving Office
- DE · DE
- Patent Type
- Utility models
- Current Assignee / Owner
- MARQUARDT GMBH
- Filing Date
- 2026-02-03
- Publication Date
- 2026-04-23
AI Technical Summary
Existing wireless access control systems in buildings face a challenge in balancing increased security against user convenience, often leading to compromised security due to users avoiding additional security measures that disrupt convenience.
An access control system using a mobile and stationary unit with dual radio standards (BLE and UWB) for authentication and position determination, combined with a monitoring unit to detect misuse signals, requiring a second authentication factor for secure access.
Provides enhanced security by detecting misuse patterns and requiring a secondary authentication factor only when necessary, maintaining user convenience and improving system reliability.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[0001] The invention relates to an access control system for buildings with a monitoring unit which is configured to extract at least one signal feature from signals transmitted from a mobile unit of the system to a stationary unit of the system and to compare the signal features with each assigned, predetermined reference features and to identify them as abuse features depending on the comparison, wherein the monitoring unit is further configured to lock the control of the function in the case of at least one abuse feature or several abuse features until release by a second authentication factor.
[0002] An access control system within the meaning of the invention is understood to be a system comprising a stationary or fixed unit and a mobile unit that can be carried by a user, in which these units communicate wirelessly with each other for the authentication and authorization of the mobile unit, and thus of the user, vis-à-vis the stationary unit. Based on this authentication and authorization, the stationary unit controls various functions and, in particular, releases, i.e., unlocks, the associated access point, for example, a door or gate. Beyond most conventional access systems, the access system according to the invention also provides position determination, as will be explained in more detail below.
[0003] Wireless access control systems are state of the art and are known, for example, from documents WO 2023 / 222462 A1 and DE 10 2020 114 403 A1.
[0004] However, such systems can be further optimized.
[0005] In the field of building access control systems, particularly wireless access solutions, there is a steadily growing need for increased security and protection against unauthorized access. This desire for enhanced security arises especially in situations where either the building itself, specific areas within the building requiring special protection (such as vaults, server rooms, or archives containing sensitive data), or individual users with heightened security needs (e.g., management, administrators, or security officers) are affected.
[0006] At the same time, the increased need for security clashes with the desire for maximum user-friendliness. Particularly with access systems designed for the most automated and interaction-free operation possible, additional effort required for manual input (such as PIN entry, fingerprint scanning, etc.) is perceived as disruptive and impractical. In practice, this often leads users to forgo implementing additional security measures to avoid compromising convenience, which in turn weakens access protection.
[0007] The invention is therefore based on the objective of overcoming the aforementioned disadvantages and providing an access control system with simultaneously improved security and increased comfort.
[0008] This problem is solved by the combination of features according to claim 1.
[0009] According to the invention, an access control system for buildings, or a building access control system, is proposed, comprising a stationary unit (i.e., fixed in place and preferably permanently connected to the building) and a mobile unit (i.e., not fixed in place) that can be carried or transported by a user. The mobile unit is essentially an electronic key, which can, for example, be in the form of a smart fob or a smartphone. For clarification, it should be noted that the access control system can comprise a plurality of mobile units, each of which is distinguishable by a unique identifier specific to the mobile unit. The stationary unit can, for example, be a unit that can be attached to a door lock or that replaces the door lock.Fundamentally, both the stationary unit and the mobile unit each have a transceiver, where a transceiver is understood to be a transmit-receive unit. The transceiver of the mobile unit, referred to as the mobile transceiver, preferably has at least one antenna and electronics for transmitting signals via the at least one antenna and for further processing the signals received via the at least one antenna.
[0010] The transceiver of the stationary unit, referred to as the stationary transceiver, preferably has at least two antennas and electronics for transmitting signals via at least one of the two antennas and for further processing the signals received via both antennas. The mobile transceiver is configured to wirelessly transmit encrypted signals, particularly via radio, to the stationary unit for authentication and authorization of the mobile unit vis-à-vis the stationary unit, and optionally for control of the stationary unit by the mobile unit.
[0011] Fundamentally, authentication and authorization of the mobile unit are understood as the verification of whether the mobile unit, or rather its identity, is known to the stationary unit, in particular whether a unique identifier of the mobile unit is stored in the stationary unit, and whether the authenticated mobile unit has access authorization for the access controlled by the access control system. Authentication and authorization can be performed integrally or separately.
[0012] Furthermore, the mobile transceiver may be configured to include a first mobile module for communication via a first radio standard, in particular Bluetooth Low Energy (BLE), and a second mobile module for communication via a second radio standard, in particular Ultra-Wide-Band (UWB). Similarly, the stationary transceiver may be configured to include a first stationary module for communication via the first radio standard and a second stationary module for communication via the second radio standard. The aforementioned evaluation unit and antennas may be provided for each module individually or shared between the two modules.
[0013] The system envisages that the signals transmitted wirelessly and in encrypted form from the mobile unit to the stationary unit serve as the first authentication factor for the mobile unit's authentication and authorization to the stationary unit. The stationary unit has a control device configured to repeatedly determine the mobile unit's position relative to the stationary unit from the signals transmitted by the mobile transceiver to the stationary transceiver and to control a function depending on a trigger condition. The trigger condition is determined by the position and / or a movement pattern (also referred to as a movement path) formed by a series of positions and / or a control command transmitted by the mobile unit. For example, access controlled by the access control system can be unlocked or granted for the purpose of controlling a function if...Access is granted as soon as the trigger conditions have been determined. Such a request exists when the mobile unit or a user carrying the mobile unit moves towards the access point following a predetermined movement pattern and / or the determined position lies within a predetermined access area.
[0014] A key aspect of the invention is that the stationary unit further comprises a monitoring unit which is configured to extract at least one signal feature from the signals and to compare the signal features with each assigned, predetermined reference features, and to identify the signal features as abuse features depending on the comparison, i.e., depending on the comparison, in the case of a match or in the case of a lack of match.
[0015] Furthermore, the monitoring unit is designed to block the control of the function if at least one abuse characteristic is present, or if several abuse characteristics are present, until it is released by a second authentication factor.
[0016] Although a single occurrence of an abuse feature can lead to a block, it is preferably intended that several abuse features or one abuse feature must be present multiple times to lead to a block, so that a high level of user comfort is still guaranteed.
[0017] Assuming that the first radio connection uses BLE signal transmission and the second uses UWB signal transmission, it can be implemented that, after successful authorization via BLE communication as the first authentication factor between the mobile and stationary units, UWB communication is initiated. This allows the stationary unit to locate the mobile unit, i.e., determine its position. The localization of the mobile unit can be used, in particular, to determine a user's access request from its movement pattern, such as its tracked route. This enables a particularly convenient, largely automated access solution that recognizes the access request contextually and initiates the access process without requiring any explicit user interaction.
[0018] This combination of features provides a particularly secure access control system that is not only based on wireless authentication but also takes into account the position and movement patterns of the mobile unit. The monitoring unit further enhances security by detecting attempted misuse and enabling a lockout until additional authentication is successful.
[0019] Further training stipulates that the mobile unit and / or the stationary unit must have an authentication device capable of requesting access data from the user as a second authentication factor and transmitting this data to the monitoring unit. This authentication device can include a screen and / or a keyboard and / or, for example, a fingerprint reader; other devices for capturing the user's biometric characteristics are also possible. Furthermore, it should be noted that if the mobile unit is, for example, a smartphone and has an authentication device, the authentication device can be implemented via an application (app) on the smartphone and, if applicable, via existing hardware components of the smartphone.
[0020] The advantage of this design lies in the creation of an additional security layer by requiring a second authentication factor for access, which, however, should only be used in cases of potential misuse. This further secures the system against unauthorized access attempts while maintaining a high level of user-friendliness.
[0021] It is also advantageous if the monitoring unit is designed to compare the access data entered by the user with, for example, comparison data stored in the monitoring unit and to unlock the control of the function by means of the signals transmitted by the mobile unit if there is a match.
[0022] This ensures that only valid login credentials are accepted.
[0023] One advanced design proposes that the monitoring unit be integrated into the control device, enabling a compact and cost-effective system architecture since no separate hardware is required for the monitoring unit. This integration also simplifies communication between the control and monitoring functions.
[0024] According to a further embodiment, at least one signal feature is provided that it is an identifier attributable to the mobile unit and / or a signature transmitted for authentication of the mobile unit and / or data transmitted by the signal and / or a format of transmitted data. These signal features can then each be compared with predetermined reference values, and in the event of a deviation exceeding a tolerance or in the event of a match, they can be recorded as indicators of misuse.
[0025] The identifier can thus be used as a signal feature and compared with a list of valid identifiers as reference features. If there is no match, the signal feature is recognized and recorded as a misuse feature.
[0026] Similarly, the identifier can be used as a signal feature and compared with a list of conspicuous or invalid identifiers as reference features. If a match is found, the signal feature is recognized and recorded as an indicator of misuse.
[0027] The same applies to the signature of the signal as a signal feature and valid or invalid signatures as reference features.
[0028] The data and format are compared to expected data or formats as reference characteristics. Any deviation can be identified and recorded as an indicator of misuse.
[0029] The advantage of this measure lies in the monitoring of various authentication and communication parameters to detect manipulation or misuse at an early stage. Comparability with reference values increases the reliability of misuse detection.
[0030] Further training provides that the monitoring unit can additionally be trained to lock the control of the function until it is released by a second authentication factor if, or as soon as, the trigger condition is not generated within a predetermined time interval by the position and / or a movement pattern formed by a series of positions and / or a control command transmitted by the mobile unit.
[0031] Alternatively or additionally, the monitoring unit can be configured to lock the function's control until it is released by a second authentication factor if the trigger condition is not generated within a predetermined number of access attempts. An access attempt is defined as a movement pattern or, more generally, behavior that at least partially corresponds to the behavior or movement pattern necessary to generate the trigger condition. For example, if a user repeatedly approaches the access point following the predetermined movement pattern and then aborts the approach according to the same pattern, this can be considered abusive behavior, and the function's control will be locked.
[0032] If the second authentication factor is then provided and is valid, i.e., the access data matches the comparison data, the block is lifted again, meaning that the control of the function by the stationary unit, especially when a trigger condition (access request) is detected, is released again.
[0033] This helps to identify conspicuous user behavior and classify it as potential abuse.
[0034] In addition to or as an alternative to the repeated absence of the triggering condition, further abnormalities in the position or movement pattern of the mobile unit can also be recorded and recognized as a characteristic of misuse.
[0035] The monitoring unit can be configured to lock the function's control until a second authentication factor is used to release it if a movement pattern formed by a series of positions corresponds to a predetermined movement pattern classified as suspicious, and the trigger condition is not generated within a predetermined time interval. Such a suspicious movement pattern might occur, for example, if an otherwise linear movement is interrupted shortly before reaching the access point.
[0036] In particular, the monitoring unit can be configured to store all characteristics of misuse or anomalies along with the mobile unit's identifier. This enables targeted tracking and analysis of misuse attempts and increases the transparency and traceability of security incidents. The technical benefit is that this logging allows for the derivation of targeted measures for system hardening and improved access security.
[0037] The generation and management of the second authentication factor can also be carried out during the installation of the access control system. For example, when setting up the mobile unit (e.g., via an application), the user can be prompted to enter a personal numerical code or a code generated by a biometric sensor as access or verification data for the second authentication factor. This code is then stored in the stationary unit along with the device ID (identifier) of the mobile unit. The technical benefit is increased system security through a personalized, difficult-to-guess second factor that can also be flexibly adapted to the needs of the individual user.
[0038] The features disclosed above can be combined in any way, provided that this is technically possible and they do not contradict each other.
[0039] Reference is also made to earlier German utility model applications, published as DE 20 2025 102 409 U1, DE 20 2025 102 410 U1, DE 202025102413 U1, DE 20 2025 102 412 U1, DE 20 2025 102 414 U1, DE 202025102415 U1, DE 20 2025 102 416 U1, DE 20 2025 102 417 U1 and DE 20 2025 102 418 U1, which also further develop an access control system according to the invention. Reference is hereby made to the aforementioned disclosures, so that their content is incorporated into the disclosure and teaching of the present application.
[0040] Other advantageous embodiments of the invention are characterized in the dependent claims or are described in more detail below together with the description of the preferred embodiment of the invention with reference to the figures. The figures show: Fig. 1. an access control system; Fig. 2 Detailed representation of a mobile and a stationary unit; Fig. 3 Flowchart for abuse detection.
[0041] The figures are schematic examples. Identical reference symbols in the figures indicate identical functional and / or structural features.
[0042] In Fig. Figure 1 shows the essential components of an access control system 1 at a building 2 according to the invention.
[0043] Such an access control system 1 basically comprises a stationary unit 20 and a mobile unit 10, wherein the stationary unit 20 is fixed in place or connected to the building 2 and is designed to control the access point 3, for example, a door, of the building 2 and, in particular, to lock or unlock the access point 3 or the door 3 depending on the position of the mobile unit 10, wherein the stationary unit 20 receives signals S from the mobile unit 10 to determine its position and to authenticate and authorize it. The mobile unit 10 has a mobile transceiver 11, which has a first mobile module for communication via a first radio standard, specifically a BLE module for communication via BLE, and a second mobile module for communication via a second radio standard, specifically a UWB module for communication via UWB.This enables the mobile transceiver 11 to wirelessly and encryptedly transmit signals S for authentication and authorization of the mobile unit 10 to the stationary unit 20 and, if necessary, for control of the stationary unit 20 by the mobile unit 10 to a stationary transceiver 21 of the stationary unit 20.
[0044] The stationary transceiver 21 has a first stationary module for communication via the first radio standard, specifically a BLE module for communication via BLE, and a second stationary module for communication via the second radio standard, specifically a UWB module for communication via UWB.
[0045] Generally, identification and authentication, particularly regarding the first authentication factor, preferably take place via BLE, whereas localization and position determination preferably occur via cryptographically secured communication over UWB. The transmission of signals relating to the second authentication factor is also preferably carried out via BLE.
[0046] It should be noted that the control of the stationary unit 20 should not, or preferably at least not exclusively, be based on control commands received from the mobile unit 10, but rather on the evaluation of the position of the mobile unit 10 relative to the stationary unit 20 or a movement pattern derived from a successive sequence of positions recorded over time. Regarding the position, an access request can be assumed as a trigger condition, for example, if the position of the mobile unit is within a predetermined access area 30. The sequence of successively recorded positions corresponds to a movement pattern from which an access request can also be determined as a trigger condition if the movement pattern corresponds, for example, to a straight-line approach of the mobile unit 10 to access point 3 or to the stationary unit 20.
[0047] The stationary unit 20 has a control device 22 which can be configured to determine the access request from the position, to determine a position of the mobile unit 10 relative to the stationary unit 20 from the signals S transmitted by the mobile transceiver 11 to the stationary transceiver 21, and to automatically control a function when the position of the mobile unit 10 is within a predetermined access area 30.
[0048] For example, the control device 22 can determine, from the signals S transmitted by the mobile transceiver 11 to the stationary transceiver 21, an angle Φ from which the signals S were received and a distance r from which the signals S were received, so that the respective position of the mobile unit 10 can be specified as polar coordinates of a polar coordinate system. It follows that the stationary transceiver 21 is located at the origin of this two-dimensional polar coordinate system.
[0049] In Fig. 2 is an access control system 1 according to Fig. Figure 1 shows the mobile unit 10 being carried by a user B. The illustration makes it clear that the signals S, which are exchanged wirelessly and preferably via BLE between the mobile transceiver 11 and the stationary transceiver 21, serve as the first authentication factor. Furthermore, the stationary unit 20 has a monitoring unit 23, which is configured to evaluate the signals S transmitted by the mobile unit 10 for signs of misuse and, if a predetermined number of signs of misuse are present, to block the control of the function by the signals S transmitted by the mobile unit 10 until it is released by a second authentication factor.
[0050] For the transmission of the second authentication factor, an authentication device 12, implemented for example by an application (app), is provided in the mobile unit 10, through which the user B can enter a numeric code serving as the second authentication factor as access data.
[0051] According to the procedure based on a flowchart Fig. 3. The access control system 1 is particularly suitable or designed by means of the control device 22 and the monitoring unit 23 to carry out the following procedural steps: Step A The mobile unit 10 communicates with the stationary unit 20 via signals S, which authenticates and, if necessary, authorizes the mobile unit 10 as a first authentication factor using the signals S or the data transmitted via the signals S. Step B During and / or after authentication, the monitoring unit 23 evaluates the signals S transmitted by the mobile unit 10 to detect signs of abuse. Step C: Were any signs of abuse detected? If yes, proceed to D. If no, proceed to G. Step D: The stationary unit 20, and in particular the monitoring unit 23 and / or the control device 22, locks the control of the function by means of the signals S and prompts the user B, in particular by means of a signal S transmitted wirelessly to the mobile unit 10, to authenticate by means of a second authentication factor, for example, by entering a numerical code. The user B generates access data as the second authentication factor by entering it at the mobile unit 10, whereby this data is transmitted to the stationary unit 20 or its monitoring unit 23. Step E: Monitoring unit 23 compares the access data with stored comparison data, i.e., for example, the numeric code entered by user B with a stored numeric code. Do they match? If yes, proceed to step F. If no, return to step D. Step F The control of the function by the signals S transmitted by the mobile unit 10 is released again, i.e., the locking of the function is reversed. Step G The stationary unit 20 determines a position of the mobile unit 10 relative to the stationary unit 20 from the signals S transmitted by the mobile transceiver 11 to the stationary transceiver 21. Step H The position or a succession of movement patterns of certain positions is monitored for conformity with predetermined positions or predetermined movement patterns, whereby a trigger condition and in particular an access request of user B to access 3 exists in the event of conformity. Step J: Was an access request detected within a predetermined time? If no, proceed to step L. If yes, proceed to step K. Step K The control device 22 unlocks access 3. In step L, parallel to or following step H, the movement pattern recorded by the sequence of positions is checked for anomalies. Such an anomaly exists, for example, if a straight movement pattern leading to access point 3, which suggests a desire for access, is interrupted shortly before reaching access point 3 and, for example, the patient veers to the side. Step M: Were any abnormalities detected multiple times? If no, proceed to step H. If yes, proceed to step D. Reference symbol list: 1 Access control system 2 buildings 3 Access / Door 10 mobile units 11 mobile transceivers 12 Authentication device 20 stationary units 21 stationary transceivers 22 Control device 23 Monitoring unit 30 Access area B Users S Signal(s) r distance Φ angle (polar coordinates) QUOTES INCLUDED IN THE DESCRIPTION
[0000] This list of documents cited by the applicant was automatically generated and is included solely for the reader's convenience. The list is not part of the German patent or utility model application. The DPMA accepts no liability for any errors or omissions. Cited patent literature
[0000] WO 2023 / 222462 A1
[0003] DE 10 2020 114 403 A1
[0003] DE 20 2025 102 409 U1
[0039] DE 20 2025 102 410 U1
[0039] DE 202025102413 U1
[0039] DE 20 2025 102 412 U1
[0039] DE 20 2025 102 414 U1
[0039] DE 202025102415 U1
[0039] DE 20 2025 102 416 U1
[0039] DE 20 2025 102 417 U1
[0039] DE 20 2025 102 418 U1
[0039]
Claims
[1] Access control system (1) for buildings (2) with a stationary unit (20) and a mobile unit (10) that can be carried by a user (B), wherein the mobile unit (10) has a mobile transceiver (11) which is configured to wirelessly and encryptedly transmit signals (S) for authentication and authorization of the mobile unit (10) to the stationary unit (20) as a first authentication factor and for control of the stationary unit (20) by the mobile unit (10) to a stationary transceiver (21) of the stationary unit (20), wherein the stationary unit (20) has a control device (22) which is configured, to repeatedly determine a position of the mobile unit (10) relative to the stationary unit (20) from the signals (S) transmitted by the mobile transceiver (11) to the stationary transceiver (21) and to control a function depending on a trigger condition which is determined by the position and / or a movement pattern formed by a series of positions and / or a control command transmitted by the mobile unit (10), wherein the stationary unit (20) further comprises a monitoring unit (23) which is configured to extract at least one signal feature of the signals (S) and to compare the signal features with each assigned, predetermined reference features and to identify them as abuse features depending on the comparison, wherein the monitoring unit (23) is further configured to block the control of the function in the presence of at least one or more abuse characteristics until release by a second authentication factor. [2] Access control system according to claim 1, wherein the mobile unit (10) and / or the stationary unit (20) has an authentication device (12) which is designed to query access data from the user serving as a second authentication factor and to transmit the access data to the monitoring unit (23). [3] Access control system according to the preceding claim, wherein the monitoring unit (23) is configured to compare the access data with stored comparison data and to unlock the control of the function by means of the signals (S) transmitted by the mobile unit (10) if there is a match. [4] Access control system according to one of the preceding claims, wherein the monitoring unit (23) is integrally formed by the control device (22). [5] Access control system according to one of the preceding claims, wherein the at least one signal feature is an identifier attributable to the mobile unit (10) and / or a signature transmitted for authentication of the mobile unit (10) and / or data transmitted via the signal (S) and / or a format of the transmitted data. [6] Access control system according to one of the preceding claims, wherein the monitoring unit (23) is configured to lock the control of the function until release by a second authentication factor if the trigger condition is not generated within a predetermined time interval by the position and / or a movement pattern formed by a series of positions and / or a control command transmitted by the mobile unit (10). [7] Access control system according to one of the preceding claims, wherein the monitoring unit (23) is configured to lock the control of the function until release by a second authentication factor if a movement pattern formed by a series of positions corresponds to a predetermined movement pattern and the trigger condition is not generated within a predetermined time interval. [8] Access control system according to one of the preceding claims, wherein the monitoring unit (23) is configured to lock the control of the function until release by a second authentication factor if the trigger condition is not generated within a predetermined number of access attempts.
Citation Information
Patent Citations
Access control system and procedures for controlling access control
DE102020114403A1
Access control system for buildings
DE202025102409U1
Access control system for buildings
DE202025102410U1
Access control system for buildings
DE202025102412U1
Access control system for buildings
DE202025102413U1