ACCESS CONTROL PROCEDURES AND ACCESS CONTROL SYSTEM

DE502017017341D1Active Publication Date: 2026-06-03DORMAKABA DEUT GMBH +1

Patent Information

Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
DORMAKABA DEUT GMBH
Filing Date
2017-11-27
Publication Date
2026-06-03

AI Technical Summary

Technical Problem

Existing access control systems rely heavily on data stored in access control devices, necessitating extensive updates to ensure compliance with current access requirements, and lack flexibility in access verification processes.

Method used

Implementing a method where access verification is partially conducted in a mobile device using predefined rules, reducing the reliance on data stored in the access control device, and enabling verification through mobile device and access control device interaction.

Benefits of technology

This approach reduces the data storage requirements in access control devices, enhances flexibility in access management, and allows for more efficient and secure access control procedures.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The invention relates to a method, in particular an access control method, for granting access to a physical area according to claim 1. The invention also relates to an access control system according to independent claim 14. A computer program product for a mobile device of the access control system according to the invention is also protected.

[0002] Access control procedures for granting access to a physical area are known, for example, from WO2006 / 098690 A1. In this procedure, an access code is transmitted to an access control device. The access control device has a tabular database to perform an access check. If the access check is successful, the access control device grants access. For example, if access is permitted for the corresponding access code within a specific time period according to the tabular database, the access control device grants access to the physical area.

[0003] In WO2006 / 098690 A1, granting access depends on the tabular database stored in the access control device. This tabular database contains a large amount of data within the access control device. Therefore, extensive updates are necessary to ensure that access granting meets the current requirements of an access administrator. WO2006 / 098690 A1 does not provide for access granting checks that are not stored in the database.

[0004] WO2017 / 180454 A1 discloses an access method in which a user's intent to grant access via a mobile device can be determined. WO2008 / 110589 A1 discloses an access method in which a PIN is first verified in a mobile device before a certificate is sent to an access control device. WO2015 / 124168 A1 discloses the forwarding of encrypted access information via a mobile device to an access control device.

[0005] The object of the invention is therefore to provide a method and an access control system that improves at least one of the aforementioned disadvantages, in particular to make the granting of access partially independent of data stored in an access control device.

[0006] The problem is solved by independent claim 1. Advantageous embodiments of the method are specified in the dependent method claims, the description, and the figures. Furthermore, the problem is also solved by the features of the access control system according to the invention as defined in independent claim 14.

[0007] Advantageous further developments of the device are specified in the description and in the figures. Features and details described in connection with the method according to the invention also apply in connection with the access control system according to the invention, and vice versa. The features mentioned in the description and in the claims may be essential to the invention individually or in combination. In particular, an access control system is protected with which the method according to the invention, especially the method according to any one of claims 1 to 13, can be carried out, as well as a method that can be carried out with the access control system according to the invention, especially with an access control system according to claim 14.

[0008] According to the invention, the method serves to grant access to a physical area. The method according to the invention is carried out by at least one access control device attributable to the physical area and by a mobile device. The mobile device contains at least one first rule for granting access. The method includes the step of verifying the first rule in the mobile device.

[0009] Because at least one initial rule is checked in the mobile device, access verification is partially independent of information stored in the access control device, particularly data stored there. This makes it possible, firstly, to reduce the amount of data in the access control device. Secondly, it allows access verification to be partially independent of data stored in the access control device.

[0010] The procedure is, in particular, an access control procedure. The access control procedure is implemented specifically to grant a user access to the physical area. The physical area is blocked at the beginning of the access control procedure. Access to the physical area is denied at the beginning of the access control procedure. Checking whether access may be granted is an essential part of the access control procedure. At least the first rule is checked for this purpose.

[0011] The access control procedure is carried out at least by means of the access control device and the mobile device, particularly if the mobile device is located near the access control device. The access control procedure can end, in particular, with the granting or termination of access. Specifically, the access control procedure can end with the granting or termination of access when the access requirements are met. If an access requirement is not met, the access control procedure can end prematurely, in which case access remains denied.

[0012] The access control procedure preferably includes at least one step that the user must consciously perform. In particular, the user must enter information on the mobile device. This input may be the first step or part of the first step of the access control procedure. Furthermore, the transmission and / or execution of instructions on how access should be granted may be part of the access control procedure.

[0013] During the process, particularly during the access control procedure, one or more rules are checked. A rule serves to grant access to the physical area. Thus, a rule serves to control access. A rule can define an access requirement. Therefore, an access authorization profile can include at least one rule. A "rule check" means verifying whether the access requirement defined in the rule has been met.

[0014] If the rule review is unsuccessful, access to the physical area will be denied. A successful rule review is at least a prerequisite for granting access. If only one rule is reviewed during the procedure, or if the reviewed rule is the same as the last rule to be reviewed, access will be granted if the review is successful. If another rule still needs to be reviewed, the procedure will continue with the aim of granting access if the review is successful. Access will only be granted if all rules to be reviewed have a successful outcome.

[0015] Multiple rules can be checked in the mobile device. When a rule to be checked in the mobile device is mentioned below, it may also refer to multiple rules to be checked in the mobile device.

[0016] The physical area is preferably blocked by a barrier. The barrier can be designed as a door, in particular as a building door, as a cover, as a flap, as a turnstile, or as a gate. The door can be, for example, a revolving door, a sliding door, or a carousel door.

[0017] The physical area is, in particular, fixed. The physical area can be designed as a room or as a box. For example, the physical area can be a room enclosed by a door. Alternatively, the physical area can be designed as a locked box, in particular a mailbox, as a locker, as an outdoor area, or as an area obstructed by a barrier, e.g., a parking area.

[0018] The mobile device is intended, in particular, for carrying by a user who wishes to be granted access to the physical area. The mobile device includes, in particular, a processor with which the mobile device can verify the first rule. The mobile device includes, in particular, memory.

[0019] Preferably, the mobile device includes a connection to a mobile communications network. The mobile communications network can be configured as a telecommunications network. The mobile device is particularly preferably configured as a mobile phone. Preferably, the mobile phone is configured as a smartphone. The mobile device can, in particular, include a display. Most preferably, the user can input commands via the display.

[0020] The mobile device and the access control device can communicate with each other wirelessly. This communication typically involves short-range communication technologies such as Bluetooth, especially Bluetooth Low Energy (BLE), RFID, or NFC.

[0021] The mobile device includes, in particular, a first transmitting and receiving device for the telecommunications network. The mobile device includes, in particular, a second transmitting and receiving device for short-range communication. The access control device includes, in particular, a transmitting and receiving unit for short-range communication.

[0022] The access control device is assigned to the physical area. A user, in particular, will assign the access control device to the physical area. The access control device serves as a guard, especially a permanently installed one, for the physical area. The access control device is preferably designed to be located close to the physical area. The access control device can comprise an electromechanical device, e.g., an electric motor or a solenoid, or an electromagnetic device, by means of which the user can gain access to the physical area. For example, the access control device can include a handle that can be operatively connected to a lock by means of the electromechanical device. Alternatively, the access control device can actuate a locking element, in particular a bolt and / or a latch, by means of the electromechanical device.Alternatively, the access control device can permit the opening of the barrier, in particular the door, turnstile, or gate, by means of an electromechanical or electromagnetic device. The access control device can be designed, in particular, as an electromechanical fitting, an electromechanical locking cylinder, an electromechanical door opener, or a motorized lock. The access control device can include an electric motor for moving the barrier, in particular the door, turnstile, or gate. The access control device can be designed with multiple components. For example, the access control device can include a reader.The reader can preferably communicate wirelessly or via cable with the electromechanical or electromagnetic device, in particular with the electromechanical fitting, the electromechanical locking cylinder, the electromechanical door opener, the electric motor, the electromagnet or the motor lock.

[0023] The access control device includes, in particular, a processor for carrying out the method according to the invention. The access control device also includes, in particular, a memory.

[0024] Preferably, the mobile device includes access information for the access control device. This access information is preferably specific to the access control device. That is, the access information contains, in particular, only information intended for granting access to the physical area monitored by the specific access control device. The access information can be assigned to the access control device. If the mobile device can grant the user access to several physical areas monitored by different access control devices, the mobile device preferably contains multiple sets of access information. In particular, separate access information can be provided and stored in the mobile device for each of the access control devices.

[0025] The process may be terminated if the mobile device does not transmit at least some of the access information to the access control device during the process. In other words, the transmission of at least some of the access information from the mobile device to the access control device may be a prerequisite for granting access.

[0026] The access information may, in particular, include an encrypted portion that is undecipherable by the mobile device. The access information may also include a readable portion that is either unencrypted or decryptable by the mobile device.

[0027] The encrypted portion may be intended to be transmitted to the access control device during the process, particularly during the access control procedure. The transmission of the encrypted portion from the mobile device to the access control device may be a prerequisite for granting access.

[0028] The readable portion may include the first rule or data for the first rule. Alternatively, the first rule may have been transmitted to the mobile device by another means. In particular, the first rule may be transmitted from the access management device to the mobile device.

[0029] The readable portion may include information that can be displayed to the user on the mobile device.

[0030] The access information is preferably provided to the mobile device by an access management device. The access management device can, for example, store the access information in a cloud. The mobile device can receive the access information wirelessly, particularly via the mobile communication network. The mobile device can, for example, retrieve the access information wirelessly from the cloud, particularly via the mobile communication network.

[0031] Preferably, the access information expires after a predetermined time. If the access information has expired, the mobile device must retrieve the access information again to grant access.

[0032] The access information can include an access authorization code, in particular an access control device identifier, and / or at least one access attribute. The access attribute can correspond to a rule, data for a rule, an instruction, and / or data for an instruction.

[0033] The displayable information can be shown, in particular, on a display of the mobile device. The displayable information can be, for example, information about the physical area and / or the barrier. This information can include, for example, the name of the physical area, an image of the physical area and / or the barrier, and the status of the physical area and / or the barrier. The displayable information can additionally or alternatively include a display of the status of the procedure and / or a display of the checking rule.

[0034] The encrypted portion is transmitted to the access control device, particularly during the current access control procedure. The encrypted portion is always transmitted to the access control device, specifically during the current access control procedure.

[0035] Preferably, only the access information, or a portion thereof, for the access control device to which access is to be granted is transmitted from the mobile device to the access control device during the process. The mobile device can select the appropriate access information based on the access control device identifier. If multiple access control devices are possible, the mobile device can display the possible access control devices or references to them, allowing the user to select the appropriate access control device and / or access information.

[0036] It may be stipulated that the access control device has knowledge of a second rule or of data relating to a second rule, or acquires such knowledge during the execution of the procedure. The procedure, in particular the access control procedure, may include the step of verifying the second rule in the access control device.

[0037] The second rule serves to grant access to the physical area. The second rule defines an access requirement. A check of the second rule means verifying whether the access requirement defined in the rule is met or not.

[0038] Multiple rules can be checked in the access control device. When a rule to be checked in the access control device is mentioned below, it may also refer to multiple rules to be checked in the access control device.

[0039] The verification of the rule(s) to be checked in the mobile device can take place before or after the verification of the rule(s) to be checked in the access control device. Specifically, the rule(s) to be checked in the access control device are checked first, before the rule(s) to be checked in the mobile device. Alternatively, it is conceivable, for example, that at least one rule in the access control device is checked first, before at least one rule in the mobile device is checked, and then at least one further rule in the access control device is checked.

[0040] It is conceivable that, after verifying at least one second rule, the access control device sends a message to the mobile device, whereupon the mobile device verifies the first rule.

[0041] Preferably, the mobile device includes the second rule or data for verifying the second rule, and the mobile device transmits the second rule or the data for verifying the second rule to the access control device during the procedure. The data for verifying the second rule is referred to below as the data for the second rule. The data for a rule can, in particular, be provided instead of the complete rule. If data for the second rule is transmitted, the second rule can be stored in the access control device. In this case, the second rule can be completed using the data transmitted by the mobile device. The access control device can then use the data for the rule to verify the corresponding rule.

[0042] For example, a rule might state that access is only granted within a specific time range. The access information could include, for instance, the time range as data for the rule. An algorithm stored in the access control device can use the time range to complete and verify the rule. Alternatively, a rule might state that access is only granted if a comparison of a reference value with a verification value is positive. The access information could include the reference value as data for the rule. An algorithm stored in the access control device can use the reference value to verify the rule by comparing the reference value with the verification value.

[0043] The second rule, or the data for the second rule, is transmitted to the access control device in encrypted form. This allows the access control device to verify the second rule in an updated form.

[0044] The access information, especially the encrypted portion, may particularly preferably include the second rule or the data for the second rule.

[0045] It is particularly desirable that the access control device uses the second rule or the data for the second rule transmitted by the mobile device only during the current access control procedure to obtain access authorization to a physical area. This eliminates the need to store the transmitted second rule or the data for the second rule in the access control device. Instead, the second rule or the data for the second rule are always used for the current access control procedure.

[0046] It is possible that if the relevant information is not transmitted from the mobile device to the access control device during the current access control procedure, access will not be granted.

[0047] Access may be granted only after a successful comparison of a reference value with a verification value. Preferably, the access control device performs the comparison of the reference value with the verification value. A successful comparison of the reference value with the verification value can be a prerequisite for granting access. The comparison of the reference value with the verification value thus corresponds to a second rule that is checked by the access control device. This comparison serves to identify the mobile device as being authorized in principle by the access control device. The reference value and / or the verification value can be in the form of a code, in particular a hash value or an electronic signature. The reference value and / or the verification value can therefore correspond to data for the second rule.

[0048] At least the verification value is transmitted from the mobile device to the access control device during the process, particularly during the access control procedure. The mobile device contains the verification value.

[0049] The verification value is provided to the mobile device by the access control device. The verification value may, for example, be contained in the readable portion. Alternatively, the verification value may have been provided to the mobile device by the access control device in addition to the access information.

[0050] The verification value can be encrypted. The verification value is preferably always transmitted from the mobile device to the access control device.

[0051] Preferably, the mobile device transmits the reference value to the access control device during the process, particularly during the access control process. The reference value can be encrypted. The reference value can be encrypted in such a way that it is undecipherable by the mobile device. In particular, the encrypted portion can contain the reference value.

[0052] It is conceivable that the reference value is always transmitted during the procedure before a comparison is made with the verification value, so that the access control device only ever uses the transmitted reference value in the current access control procedure. Therefore, it is not necessary to store the reference value in the access control device. Rather, access is denied if the reference value is not transmitted from the mobile device to the access control device during the current access control procedure. This ensures that a current reference value is always used, particularly without having to perform extensive updates on the access control device in quick succession.

[0053] A positive result from comparing the reference value with the verification value can be a prerequisite for verifying the first rule in the mobile device. That is, the reference value is preferably compared with the verification value first, and only if the result is positive is the first rule subsequently verified.

[0054] The first and / or second rule may correspond to or include the following rule: Access is granted only after a positive result from comparing the reference value with the verification value (rule a.). Preferably, rule a. is always checked as the second rule in the access control device. Rule a. identifies the mobile device as authorized in principle.

[0055] The first and / or second rule may correspond to or include the following rule: Access is granted only within a specific time range (rule b). The time range may include times of day, days of the week, working and non-working days, months, and / or years. The time range may be transmitted in encrypted form from the mobile device to the access control device during the access control procedure. In particular, the encrypted portion may include the time range. If the time range is always transmitted in the current access control procedure, there is no need to store the time range in the access control device.

[0056] The first and / or second rule may correspond to or include the following rule: Access is granted only if a further authentication, in particular by means of a code or biometric identification, is successful (rule c). Preferably, the access control device performs the further authentication. For this purpose, a control value is compared with a code or biometric identifier. The code and / or biometric identification can be entered or captured on the mobile device and transmitted to the access control device. The comparison of the code and / or biometric identification with the control value preferably takes place in the access control device. A successful comparison results in further authentication.

[0057] The authentication control value can be received by the access control device from the mobile device in encrypted form during the access control procedure. The control value can include a control code and / or control biometric recognition. In particular, the encrypted portion can encompass the control value. This eliminates the need to store the control value in the access control device.

[0058] The first and / or second rule may correspond to or include the following rule: Access is granted only if a marker identifying the user as a guard is negative (rule d.). It may be desirable for a guard to identify themselves at the access control device during a patrol to ensure the patrol is completed correctly. It may be desirable for the guard not to be granted access. Therefore, access is denied if the marker identifies the user as a guard.

[0059] The positive or negative guard designation can be transmitted in encrypted form from the mobile device to the access control device during the access control procedure. Specifically, the encrypted portion can include the positive or negative guard designation. If the positive or negative guard designation is always transmitted in the current access control procedure, there is no need to store the designation.

[0060] Preferably, at least rule a. is checked. It is particularly preferred that at least one further rule is checked. This can be at least one of rules b., c., or d. Preferably, at least two of the rules, i.e., b. and c., c. and d., or b. and d., are checked. It is particularly preferred that rules b., c., and d. are checked. The check can take place, in particular, in the access control device. This can increase security.

[0061] The time range, the control value, and / or the designation as a guard thus corresponds to a second rule or data for a second rule, which is preferably transmitted from the mobile device to the access control device. This transmission preferably always occurs within the current access control procedure.

[0062] Preferably, at least one rule is checked in the mobile device that cannot be checked in the access control device, since the necessary data cannot be provided to the access control device.

[0063] Preferably, the first rule corresponds to the following rule: Access is granted only if the mobile device undergoes further authentication, in particular by entering a code or using biometric recognition, with a positive result (rule e). In contrast to rule b, the mobile device performs the further authentication. This further authentication takes place, in particular, during the access control procedure. Thus, the further authentication is provided specifically in addition to unlocking the mobile device.

[0064] Preferably, the first rule corresponds to the following rule: Access is granted only if the mobile device's location history matches a specified location history (rule f). The location history can be stored on the mobile device. The location history can include a history of access being granted to at least one specified physical area. The physical area included in the location history can differ from the physical area to which access is sought using the access control procedure. The location history can include a sequence of granted access to specified physical areas. The location history can include a specified time range for granting access to the specified area(s). For example, a user seeks access to an office area.For example, access to the office area is granted only if access has been granted within the last half hour, first to a main entrance area and then to a changing area.

[0065] Preferably, the first rule corresponds to the following rule: Access is granted only if a payment has been made beforehand (rule g). In particular, access can only be granted if confirmation of a payment has been made is available. The mobile device can capture or include confirmation of the payment.

[0066] Preferably, the first rule should correspond to the following rule: Access will only be granted if a set of rules for the use of the physical area has been accepted (rule h). The rules for use may include, for example, conditions for the use of the physical area, such as "No smoking".

[0067] Preferably, the first rule corresponds to the following rule: Access is granted only if instruction, in particular safety instruction, has been successfully completed (rule i). The instruction, in particular safety instruction, can be successfully completed by acknowledgment of receipt. The instruction, in particular safety instruction, can be successfully completed by passing a test. The test can be performed and / or evaluated on the mobile device. Alternatively, the result of the test can be transmitted to the mobile device.

[0068] Preferably, at least one of the rules e., f., g., h., or i., e.g., exactly one rule, is checked in the mobile device. In particular, rule f. is checked in the mobile device. In particular, rule g. is checked in the mobile device. In particular, rule h. and / or i. is checked in the mobile device.

[0069] It is also possible that at least two of the rules, e.g. e. and f., e. and g., e. and h., e. and i., f. and g., f. and h., f. and i., g. and h., g. and i. or h. and i., e.g. exactly two rules, are checked.

[0070] It is also possible that at least three of the rules, e.g. e. / f. / g., e. / f. / h., e. / f. / i., e. / g. / h., e. / g. / i., e. / h. / i., f. / g. / h., f. / g. / i., f. / h. / i. or g. / h. / i., e.g. exactly three rules, are checked.

[0071] Likewise, four rules f. / g. / h. / i., e. / g. / h. / i., e. / f. / h. / i., e. / f. / g. / i. or e. / f. / g. / h. or all five rules e., f., g., h. and i. can be checked.

[0072] It is possible that the first and / or second rule only applies within a specific time frame. In particular, the first and / or second rule that only applies within a specific time frame may be at least one of rules c. to i.

[0073] Outside of the specified time window, compliance with the rule is not a prerequisite for granting access. In particular, compliance with the rule is not checked outside of the specified time window. The time window can encompass times of day, days of the week, working and non-working days, months, and / or years. The rule encompasses the time window. Multiple rules can only apply within a single specified time window. The time windows of different rules may differ from one another. Where the term "time window" is used below, it may refer to multiple time windows.

[0074] For example, rule g only needs to be fulfilled on one working day to grant access. Access is free on weekends. Rule g would then state that access is only granted on weekdays and after prior payment.

[0075] For example, rule f only needs to be fulfilled on Mondays. On the other weekdays, it is not necessary to have been granted access to at least one other physical area before being granted access to the physical area in question.

[0076] As another example, rule c. or e. only needs to be fulfilled on a weekend. No additional authentication is required on a working day.

[0077] In a third example, checks are only carried out at night between 20:00 and 6:00 to see if someone is marked as a guard; otherwise, rule d. is not checked.

[0078] The time window can be transmitted to the access control device in encrypted form, particularly if the access control device verifies the relevant rule that applies within the time window. Specifically, the encrypted portion can encompass the entire time window.

[0079] The time window allows for a specific deviation from the general validity of a rule, particularly at least one of rules c. to i. Thus, the access information can contain a specific rule relative to a general rule. The additional information can also contain the general rule. The specific rule defines a deviation from the general rule. The specific rule and the general rule belong to the same rule type, specifically one of rules c. to i. For example, the generally valid rule might state that an additional PIN entry according to rule c. is required every Monday. The specific rule might state that an additional PIN entry according to rule c. is not required in August. The specific rule can override the general rule. Therefore, as a result of the example, no PIN entry is necessary on Mondays in August.In particular, the encrypted portion can include the general and / or the specific rule.

[0080] Preferably, the mobile device includes a time recording device, and the first rule contains a time-dependent condition for granting access. The first rule is verified using the time available to the mobile device via the time recording device. Verifying a time-dependent rule is particularly useful if the access control device does not have a time indicator. In this case, it is especially advantageous to have rule b. verified by the mobile device. This can also apply to rule c. or d. if rule c. or d. includes a time window. Thus, at least one of rules b. to d. may be verified by the mobile device.

[0081] The time-dependent condition checked in the mobile device can, in particular, correspond to rule b. The time-dependent condition checked in the mobile device can correspond to one of rules c. to i., which are only valid within a specified time window.

[0082] The time recording device can be a receiving device of the communication network through which the time is received and / or an internal timer. The mobile device can use the generally accepted time of the relevant time zone, which is transmitted to the mobile device or set by the user. Alternatively, the mobile device may only be permitted to use the time provided to it by the access control device, or at least the time it provided within a predetermined time period.

[0083] It is conceivable that the first rule contains an additional condition in addition to the second rule and / or contains a restriction of the second rule.

[0084] To grant access, a positive result under both the first and second rules is preferable. In particular, it is not permissible for the first rule to be less restrictive than the second. Specifically, it is not permissible for a positive result under the first rule to be sufficient to grant access. This increases the security of the procedure against manipulation.

[0085] It can be arranged that the mobile device transmits the result of the first rule check to the access control device, which then decides whether to grant access. This can increase the tamper resistance of the process. The mobile device will report the result of the check to the access control device. If the report of the check result is not submitted, access is denied. The access control device may set a predetermined timeframe for this report. If the mobile device does not submit the result within the specified timeframe, access is denied.

[0086] The access control device may have been previously informed that at least one initial rule is checked as an additional condition for granting access. The fact that at least one initial rule is checked as an additional condition for granting access is transmitted to the access control device, particularly in encrypted form. Preferably, the encrypted portion includes the fact that at least one initial rule is checked as an additional condition for granting access. For example, the access information, especially the encrypted portion, may include a code value indicating the necessity of considering the result of the rule check in the mobile device when granting access. If the code value is positive, the access control device expects a positive result from the rule to be checked in the mobile device within a specified timeframe.

[0087] Alternatively, the mobile device can send an opening command to the access control device.

[0088] The access control device may include a programming interface. The access control device and the mobile device can communicate with each other via the programming interface during the process, particularly during the access control procedure. The programming interface may correspond to an API.

[0089] In particular, it is provided that the access control device opens the programming interface during the procedure. The procedure can, in particular, correspond to the access control procedure.

[0090] In particular, the access control device can open the programming interface following a successful rule check. That is, a rule that is checked to grant access to the physical area can also enable the opening of the programming interface. The check can be a condition for opening the programming interface. It is conceivable that further conditions must be met to open the programming interface. In particular, it is conceivable that the mobile device contains a command or data for a command that opens the programming interface. The command or data for the command can, in particular, be transmitted from the mobile device to the access control device in encrypted form.

[0091] The verification of the rule corresponding to a condition for opening the programming interface preferably takes place in the access control device. For example, the rule corresponding to a condition for opening the programming interface can particularly preferably correspond to the comparison of the comparison value with the verification value (rule a.).

[0092] Preferably, the access control device opens the programming interface at least partially before granting access to the physical area. This allows the programming interface to be available to receive data for the current access control procedure.

[0093] The programming interface can be opened to obtain data for verifying a rule, particularly another rule. A positive result from the verification of the other rule may be a prerequisite for granting access. For example, a user's biometric data can be transmitted to the access control device via the programming interface. The biometric data can then be captured using the mobile device.

[0094] The programming interface can be opened to obtain the results of a check of a rule that is being checked in the mobile device.

[0095] The programming interface can be opened to receive an instruction or control command regarding the manner in which access is granted.

[0096] The programming interface can be opened to receive an opening command from the mobile device. Following this command, the access control device activates the electromechanical device to grant access.

[0097] The object of the invention is also achieved by an access control system. The access control system can be configured, in particular, to carry out a method according to the invention, especially a method according to any one of claims 1 to 13.

[0098] The access control system according to the invention comprises an access control device that can be assigned to a physical area and a mobile device. The mobile device contains at least one first rule for granting access to the physical area. According to the invention, the mobile device verifies the first rule for granting access to the physical area.

[0099] This means that part of the access verification takes place in the mobile device. Therefore, this part of the access verification is independent of data stored in the access control device.

[0100] A computer program product for a mobile device of an access control system according to the invention, in particular an access control system according to claim 14, and / or for carrying out a method according to the invention, in particular a method according to any one of claims 1 to 13, is also granted protection. The installation of the computer program product enables the mobile device to function as part of the access control system. The computer program product may include instructions by which the mobile device can carry out the method according to the invention and / or function as part of the access control system according to the invention.

[0101] The invention is explained in more detail below with reference to exemplary embodiments. Technical features with the same function are indicated in the figures by identical reference numerals. The figures show: Fig. 1 an access control system according to a first embodiment according to the invention, Fig. 2 the access control system Figure 1 , which depicts the transmission of access information, Fig. 3 a method according to a first embodiment of the invention, Fig. 4 a method according to a second embodiment and Fig. 5 a method according to the invention in a third embodiment.

[0102] In Figure 1Figure 1 shows an access control system 1 according to the invention. The access control system 1 comprises a mobile device 2 and an access control device 3. The mobile device 2 is shown schematically. The mobile device 2 is designed as a smartphone. The mobile device 2 includes a display 18. The access control system 1 according to the invention can perform a method 100, 100a, 200, 300 according to the invention.

[0103] The mobile device 2 accesses a cloud 5 via a telecommunications network 4. For this purpose, the mobile device 2 includes a first transmitting and receiving device. The telecommunications network 4 is schematically represented by a double arrow. Access information 10 is located in the cloud 5.

[0104] The access information 10 comprises an encrypted part 11 and a readable part 12. If the access information 10 is intended for the mobile device 2, the mobile device 2 can retrieve the access information 10 from the cloud 5. The retrieval capability for the mobile device 2 is limited to the access information 10 intended for the mobile device 2. Furthermore, the access information 10 is specific to the access control device 3. That is, the access information 10 contains information intended for granting access to the physical area monitored by the specific access control device 3. If the user can be granted access to multiple physical areas monitored by different access control devices 3 via the mobile device 2, the mobile device 2 contains multiple access information 10s.In particular, for each of the access control devices 3, access information 10 can be provided and stored in the mobile device 2. The access information 10 can be in the form of a file. Figure 2 In a purely schematic way, access information 10 for the depicted access control device 3 is stored in the mobile device 2.

[0105] The access information 10 is provided to the cloud 5 by a purely schematic access management device 9. The access management device 9 can be part of the access control system 1 according to the invention. The access management device 9 or the cloud 5 encrypts the encrypted portion 11 of the access information 10 in such a way that the mobile device 2 is unable to decrypt the encrypted portion 11. The encrypted portion 11 is intended to be transmitted, at least partially, from the mobile device 2 to the access control device 3. The access control device 3 can decrypt the encrypted portion 11.

[0106] The access management device 9 can communicate with the cloud 5 via a communication link 19.

[0107] Cloud 5 can be part of the access control system 1. Alternatively, Cloud 5 is not part of the access control system 1 according to the invention. Instead, the mobile device 2 can be configured such that the access control information 10 can be retrieved from Cloud 5 by the mobile device 2. The access management device 9 can be configured such that the access information 10 can be stored in Cloud 5 by the access management device 9.

[0108] In an alternative not shown, the access management device 9 can send the access information to the mobile device 2 via the telecommunications network 4 without storing it in the cloud 5.

[0109] The access control device 3 serves as a permanently installed guardian of a physical area (not shown) blocked by a barrier. Figure 1The access control device 3 is shown by way of example as an electromechanical fitting 3. Such a fitting 3 is described, purely by way of example, in EP2998484 A1. Alternatively, the access control device 3 can be designed, for example, as an electromechanical locking cylinder, a door opener, or a motorized lock. The access control device 3 can also be designed in multiple parts (not shown). The access control device 3 can, for example, comprise a reader and an electromechanical or electromagnetic device, such as a motorized lock (not shown).

[0110] The access control device 3 and the mobile device 2 communicate with each other via a short-range communication link 6, such as Bluetooth, BLE, RFID, or NFC. BLE is preferably used. The short-range communication link 6 is shown schematically as a double arrow. The mobile device 2 has a second transmitter and receiver for the short-range communication link 6. The access control device 3 has a transmitter and receiver for short-range communication 6. The mobile device 2 and the access control device 3 each comprise at least one processor (not shown) for carrying out the method 100, 100a, 200, 300 according to the invention. The mobile device 2 and the access control device 3 each comprise at least one memory (not shown) for carrying out the method 100, 100a, 200, 300 according to the invention.The mobile device 2 can use a processor and / or memory, which can also be used to perform other functions of the mobile device 2.

[0111] The mobile device 2 comprises a computer program product according to the invention, e.g. an app, by means of which the mobile device 2 can carry out the method 100, 100a, 200, 300 according to the invention.

[0112] The access control system 1 according to the invention can, in particular, do without a connection of the access control device 3 to the telecommunications network 4 and / or a wired connection to the access management device 9. Thus, the access control device 3 can be designed as a stand-alone / offline device.

[0113] The access control device 3 comprises a Figure 1Electromechanical device 7 is shown in a purely schematic representation. The electromechanical device 7 is located inside the access control device 3 and is therefore in Figure 1The electromechanical device 7 can couple a handle 17 of the access control device 3 with a lock to grant access to the physical area. In the coupled state, a user can move the lock to an unlocked state by actuating the handle 17. If access is denied again, the handle 17 is decoupled from the lock by the electromechanical device 7. This is described, for example, in EP2998484 A1. Alternatively, the electromechanical device 7 can automatically move the lock to an unlocked state by retracting a bolt and / or a latch. In a further alternative, the electromechanical device 7 can release a latch of a door opener.

[0114] In the Figure 3The methods 100, 100a described according to the invention are access control methods. At the beginning of the access control method 100, 100a, the access control device 3 denies access to the physical area. The access control method 100, 100a serves to verify whether access can be granted to the user of the mobile device 2. The access control method 100, 100a can begin with initial communication between the mobile device 2 and the access control device 3 for the purpose of granting access to the physical area. If the verification is successful, the access control method 100, 100a can include granting access. The access control method can end with either granting access or terminating access, if the verification is successful. The manner in which access is granted is also part of the access control method 100, 100a.

[0115] In a first process step 101 of the inventive method 100, 100a, an access control device identifier is sent from the access control device 3 to the mobile device 2.

[0116] In a second process step 102 of process 100, 100a, the mobile device 2 then checks whether access information 10, which can be identified as belonging to the access control device 3 based on the access control device identifier, is stored in the mobile device 2. If such access information 10 is stored, the mobile device 2 sends the encrypted portion 11 of the access information 10 that has been identified as belonging to the access control device 3 to the access control device 3. This is particularly relevant in Figure 2The access information is received by the transmitting and receiving unit of the access control device 2. If corresponding access information 10 for the access control device 3 is not stored in the mobile device 2, the procedure 100 ends. This is indicated by an arrow at the second procedure step 102 in Figure 3 clarifies.

[0117] In process step 101, the user may be required to perform an input on the mobile device 2, such as pressing a button or launching an app, thereby indicating their intention to access the device. If this input is missing, process 100 may be terminated. This is indicated by an arrow at the beginning of process step 101. Figure 3 clarifies.

[0118] Part of the first process step 101 may additionally or alternatively include the mobile device 2 displaying to the user on the display 18 all access control devices 3 with which the mobile device 2 can communicate, in particular their access control device identifiers, for which access information 10 is stored in the mobile device 2. The display of the access control devices 3 is supported by the information contained in the respective readable portion 12 of the access information 10 for the corresponding access control devices 3. Thus, the readable portion 12 may include an image or a description of the possible access control devices 3, the possible physical spaces, and / or the barriers monitored by the possible access control devices 3.The corresponding images and / or descriptions can be displayed on the screen 18 of the mobile device 2. The user can select one of the displayed access control devices 3. In process step 102, the mobile device 2 then sends the encrypted portion 11 and the associated access information 10 only to the selected access control device 3.

[0119] The encrypted portion 11 received in process step 102 is decrypted by the access control device 3 in a third process step 103 of process 100, 100a. The encrypted portion 11 contains a comparison value.

[0120] Mobile device 2 has received a verification value from access management device 9, for example via Cloud 5. The verification value may be contained in the readable portion 12. It is also conceivable that mobile device 2 receives the verification value separately from access information 10 from access management device 9. The verification value can be downloaded by mobile device 2, for example via Cloud 5.

[0121] The comparison value and the verification value have a code-like character and can be, for example, in the form of a hash value or an electronic signature.

[0122] In a fourth process step 104 of process 100, 100a, the mobile device 2 transmits the verification value to the access control device 3. The verification value is received by means of the transmitting and receiving unit of the access control device 3.

[0123] In a fifth process step 105 of process 100, 100a, the access control device 3 compares the comparison value with the verification value. In doing so, the access control device 3 verifies a rule. If the comparison is positive, the access control device 3 recognizes the mobile device 2 as being authorized in principle, and the access control process 100, 100a continues.

[0124] If the comparison value and / or the verification value is not transmitted in the current procedure 100, or if the comparison between the comparison value and the verification value is negative, access remains denied and the access control procedure 100, 100a ends. This is indicated by arrows at procedure steps 103, 104 and 105 in Figure 3 depicted.

[0125] Several options are conceivable for the next steps: In Figure 3Methods 100 and 100a are described, in which, following the fifth method step 105, the access control device 3 of the mobile device first sends a message in a sixth method step 106. According to the invention, at least one rule is then checked in the mobile device 2. The at least one rule to be checked in the mobile device 2 is referred to as the first rule. According to the invention, this eliminates the need to use data from the access control device 3 when checking the first rule. Instead, the rule to be checked in the mobile device 2, or data for the rule to be checked in the mobile device 2, is located in the readable portion 12. Alternatively, the rule to be checked in the mobile device 2, or data for the first rule to be checked, can be transmitted from the access management device 9 to the mobile device 2 via a different route, in particular via the cloud 5.

[0126] ZB, mobile device 2 checks as its first rule whether the user may be granted access at the current time. That is, mobile device 2 checks whether the current time falls within a predefined time range. Thus, mobile device 2 checks rule b. For this purpose, mobile device 2 receives a current time specified by access management device 9, in particular via cloud 5.

[0127] Furthermore, mobile device 2 can check whether further authentication is required at the current time. Specifically, mobile device 2 verifies whether the current time falls within a time window in which further authentication is necessary. If so, mobile device 2 prompts the user to enter a PIN code, password, or biometric identification. This information is entered on mobile device 2 and compared to a control value (rule e). Preferably, the control value and / or the current time are provided to mobile device 2 by access management device 9.

[0128] The mobile device 2 can additionally or alternatively check further rules. For example, the mobile device 2 can prompt the user to accept a rule of use such as "this is a non-smoking room" by entering a text message on the mobile device 2 (rule i.).

[0129] Further initial rules, which have already been disclosed in the general description, can also be verified in the mobile device 2.

[0130] If all the first rules to be checked in mobile device 2 have been verified with a positive result, then the device on the left sends a signal. Figure 3In the seventh step 107 of the described procedure 100, the mobile device 2 sends an opening command to the access control device 3. The controller of the access control device 3 then activates the electromechanical device 7 to grant access. Alternatively, the electromechanical device 7 is activated directly by the opening command to grant access. If at least one of the rules to be checked in the mobile device 2 could not be verified with a positive result, access remains denied and the access control procedure 100 ends. This is described in Figure 3 represented by an arrow at process step 106.

[0131] Access to the physical area is granted in an eighth process step 108 by means of the electromechanical device 7.

[0132] The in Figure 3The described method is particularly suitable for access control devices 3 that are designed to be free from any knowledge of time.

[0133] The method of access is determined by at least one instruction. The instruction may include how the granting of access is indicated visually and / or audibly in the access control device 3. Alternatively or additionally, the instruction may include how the granting of access is terminated, e.g., after a predetermined period of time following the commencement of the grant, at a predetermined time regardless of when the grant commencement, or after a certain number of grants. The instruction may also include whether information about the procedure is sent to the mobile device 2. The at least one instruction may be contained in the encrypted portion 11. The instruction is transmitted to the access control device 3 in step 102.

[0134] Optionally, the access control method 100 according to the invention comprises a further step in which the granting of access is terminated again in accordance with the instruction. This further step follows step 108.

[0135] In contrast to the one in Figure 3 The method 100 shown on the left can also be a method according to the invention. Figure 3Procedure 100a, as shown on the right, is carried out. Procedure steps 101, 102, 103, 104, 105, 106, and 108 remain the same as in procedure 100. In procedure 100a, the mobile device 2 can check the aforementioned rules to be verified in the mobile device 2 in step 106, but the mobile device 2 does not send the opening command according to step 107. That is, step 107 is omitted. If all rules to be verified in the mobile device 2 have been checked with a positive result in step 106, the mobile device 2 instead transmits the positive result to the access control device 3 in an alternative seventh step 107a. This alternative is described in Figure 3This is illustrated in procedure 100a shown on the right. The access control device 3 awaits the positive result within a predetermined timeframe. The timeframe begins with the sending of the message in step 106. If the positive result reaches the access control device 3 within the timeframe, the access control device 3, in particular its controller, activates the electromechanical device 7 to grant access. If no positive result reaches the access control device 3 within the timeframe, access remains denied and the access control procedure ends. This is indicated by an arrow at procedure step 107a.

[0136] In Figure 4 A further method 200 according to the invention is shown. Method 200 can, in particular, be configured as an access control method 200. Method 200 can be implemented using the access control system 1 according to the invention. Figure 1 and 2 to be carried out. The first, second, third, fourth and fifth process steps 101, 102, 103, 104, 105 of procedures 100, 100a from Figure 3 corresponds to the first, second, third, fourth and fifth process steps 201, 202, 203, 204, 205 of process 200 from Figure 4 . In deviation from procedure 100, 100a from Figure 3 In a sixth procedural step 206 of procedure 200, at least one further rule is initially checked in the access control device 3.

[0137] ZB checks whether the user is permitted access at the current time. That is, access control device 3 checks whether the current time falls within a predefined time range. Thus, access control device 3 checks rule b. The time range for checking rule b is contained in encrypted part 11.

[0138] Furthermore, the access control device 3 can check whether further authentication is required at the current time. Specifically, the access control device 3 verifies whether the current time falls within a time window in which further authentication is necessary. If so, the mobile device 2 prompts the user to enter a PIN code, password, or biometric identifier. This information is entered on the mobile device 2. The entered PIN code, password, or biometric identifier is then transmitted to the access control device 3. The access control device 3 compares the transmitted PIN code, password, or biometric identifier with a control value (rule c). The control value and the time window are contained in the encrypted portion 11.

[0139] Additionally or alternatively, the access control device 3 can check whether a marker identifying the user as a guard is negative. If the marker is negative, then rule d. has been successfully verified. The marker identifying the user as a guard is contained in the encrypted part 11.

[0140] If a rule to be checked in the access control device 3 returns a negative result, access is denied and procedure 200 ends. This is in Figure 4 indicated by an arrow at process step 206.

[0141] In procedure 200, those rules that can be transmitted to access control device 3 in encrypted form 11 by access management device 9 are checked in access control device 3. In procedure 200, at least one first rule, which depends on data that cannot be readily transmitted to access control device 3, is checked in mobile device 2. The check of at least one first rule takes place in procedure step 207. First, access control device 3 sends a message to mobile device 2. Mobile device 2 then begins checking the at least one rule. At the same time, access control device 3 begins measuring the time for the time frame.

[0142] For example, mobile device 2 can prompt the user to accept a rule of use such as "this is a non-smoking room" by entering a command on mobile device 2 (rule h).

[0143] Additionally or alternatively, the mobile device 2 can verify the successful completion of a safety briefing (Rule i.). For this purpose, the mobile device 2 can perform and evaluate a test.

[0144] Additionally or alternatively, mobile device 2 can only grant access if another access has been granted previously. In this case, the user may first have to pass through another physical area, such as an airlock or cleanroom, before being granted the currently requested access. Mobile device 2 thus checks its own location history (rule f.).

[0145] The mobile device 2 can also verify whether a payment for the use of the physical area has been previously made (Rule g).

[0146] If a rule to be checked in the mobile device 2 yields a negative result, access is denied and procedure 200 ends. This is in Figure 4 indicated by an arrow at process step 207.

[0147] The rules checked in mobile device 2 can only supplement the rules checked in access control device 3. Access may not be granted if only one rule being checked returns a negative result. If a rule of the same type, e.g., "access is only granted within a specific time range," is checked in both step 206 of access control device 3 and step 207 of mobile device 2, with a different time range specified in step 206 than in step 207, access is only granted if a positive result is found for both time ranges.

[0148] If all rules to be checked in the mobile device 2 have been verified with a positive result, the mobile device 2 transmits the positive result to the access control device 3 in a process step 208. The access control device 3 expects the positive result within a predetermined time frame. If the positive result reaches the access control device 3 within the time frame, the access control device 3, in particular the controller of the access control device 3, activates the electromechanical device 7 in a process step 209. If no positive result reaches the access control device 3 within the time frame, access remains denied and the access control procedure ends. This is described in Figure 4 indicated by an arrow at process step 208.

[0149] In process step 210, the controller of the access control device 3 terminates the granting of access after a predetermined time period. For this purpose, the controller activates the electromechanical device 7, which puts the access control device 3 into a decoupled state. For example, this deactivates a handle 17 (see figure). Fig. 1 ) is uncoupled from a lock, so that a torque from the handle 17 can no longer be transmitted to the lock. The predetermined time interval was transmitted in the encrypted part 11.

[0150] As an alternative to procedure step 208 and not shown, the mobile device 2 can directly control the controller of the access control device 3 or the electromechanical device 7 with an opening command if all rules to be checked in the mobile device 2 have been checked with a positive result.

[0151] In Figure 5A further method 300 according to the invention is presented. Figure 5 Do process steps 301, 302, 303, 304, 305, 306 and 307 correspond to process steps 201, 202, 203, 204, 205, 206, 207, which are in Figure 4 are shown. In contrast to procedure 200, in procedure 300 the access control device 3 opens a programming interface (API) 8 of the access control device 3 during the time frame. The programming interface 8 is in Figure 1 The diagram is shown purely schematically. Programming interface 8 contains data from the transmitting and receiving unit of the access control device 3. Programming interface 8 is only opened if, in step 306, the rules to be checked in the access control device 3 have been verified with a positive result.

[0152] If all rules to be checked in the mobile device 2 have been verified with a positive result in step 307, the mobile device 2 transmits the positive result to the programming interface 8 of the access control device 3 in a process step 308. The access control device 3 then decides in a process step 309 that access is granted and controls the electromechanical device 7 with an opening command in process step 309. Alternatively, an opening command can be sent from the mobile device 2 to the programming interface 8 of the access control device 3 in step 308.

[0153] Alternatively, and not shown, a conventional method can initially be used in process step 308. Figure 1The result of the rules to be checked in the mobile device 2 is transmitted to the access control device 3 via an interface not shown, e.g., a binary interface. Only then can the access control device 3 open the programming interface 8. The programming interface 8 serves, after step 308, to receive the instruction(s) or data for an instruction regarding the manner of granting access. The instruction or data received via programming interface 8 can concern an instruction on when to terminate access. The instruction or data received via programming interface 8 can also include the manner of visual and / or audible indication of the granting of access.

[0154] In another implementation variant, programming interface 8 opens as soon as the comparison of the reference value with the check value is successful. That is, programming interface 8 opens after step 305. Specifically, programming interface 8 opens before step 306. This allows data, rules, or commands for step 306 to be transmitted to the controller of the access control device 3 via programming interface 8. For example, a check value required for further authentication in the access control device 3 can be transmitted via programming interface 8.

[0155] The programming interface can alternatively or additionally be used to receive an updated version of firmware and / or additional firmware, an updated version of an access control device identifier and / or an updated version of data in order to perform decryption.

[0156] The programming interface 8 can only be partially opened. Thus, the programming interface 8 can be opened only for receiving specific data, while other data that could also be received via the programming interface 8 is not received if this is prohibited by at least one command.

[0157] The mobile device 2 can contain at least one command specifying when and / or for what purpose the programming interface 8 is to be opened. This means that, as an alternative to what has been described above, the programming interface 8 does not open immediately following a successful completion of step 305 or 306, but only after the mobile device 2 has sent a command to the access control device 3, in particular the conventional interface, to at least partially open the programming interface 8.

[0158] The programming interface 8 and the conventional interface receive the data and / or commands through the receiving unit of the access control device 3.

[0159] In the methods 100, 100a, 200, 300 according to the invention, the encrypted portion 11 is used only in the current access control method 100, 100a, 200, 300. The encrypted portion 11 is not stored in the access control device 3 after the access control method 100, 100a, 200, 300 has ended. Rather, in each access control method 100, 100a, 200, 300, the data from the encrypted portion 11 transmitted to the access control device 3 in the current access control method 100, 100a, 200, 300 is used. Thus, current data is always used. If the encrypted part 11 is not transmitted from the mobile device 2 to the access control device 3, access is denied and the access control procedure 100, 100a, 200, 300 ends.

[0160] In the Figures 3 to 5In the described procedure, at least one initial rule in mobile device 2 is only checked after at least one rule in access control device 3 has been checked. The rule to be checked in access control device 3 can correspond at least to the comparison of the reference value with the check value. Alternatively, it is also conceivable that at least one rule to be checked in access control device 3 is checked after a rule to be checked in mobile device 2. Thus, in procedure 200, steps 206 and 207 could be reversed in time.

[0161] As another example, a first rule in mobile device 2 can be checked before a rule in access control device 3 is checked. For example, a first rule in mobile device 2 can be checked before the comparison value is compared with the verification value in access control device 3. For example, a first rule can already be checked in process steps 101, 201, 301. Thus, it is possible that for each received access control device identifier, it is first checked whether a payment has been made (rule g). Only those access control devices 3 for which a corresponding payment has been made are displayed on display 18 for the user to select.

Claims

1. An access control method (100, 100a, 200, 300) for granting access to a physical region, wherein the method (100, 100a, 200, 300) is carried out at least by an access control device (3), which is assignable to the physical region, and by a mobile device (2), wherein the mobile device (2) comprises an item of access information (10) for the access control device (3), wherein the mobile device (2) wirelessly receives the access information (10), wherein the access information (10) comprises an access control device identifier and at least one access attribute, wherein the access attribute corresponds to a rule, data for a rule, an instruction and / or data for an instruction, wherein the access information (10) comprises an encrypted portion (11) which is not decryptable by the mobile device (2), wherein the encrypted portion (11) is provided to be transmitted to the access control device (3) during the method (100, 100a, 200, 300), wherein the access information (10) comprises a readable portion (12) which is unencrypted or decryptable by the mobile device, wherein the readable portion (12) comprises the first rule or data for the first rule, wherein the mobile device (2) comprises a processor which can be used by the mobile device (2) to verify the first rule, wherein the mobile device (2) contains at least the first rule for granting access, wherein the method (100, 100a, 200, 300) comprises the step (106, 207, 307): - Verifying (106, 207, 307) the first rule in the mobile device (2), wherein the first rule applies only in a predefined time window, wherein, during the method (100, 100a, 200, 300), a plurality of rules are verified, wherein a rule defines an access requirement, wherein, in the case of a negative result of the verification of the rule, access to the physical region is denied, wherein, while the method (100, 100a, 200, 300) is carried out, the access control device (3) obtains knowledge of a second rule or data for a second rule, wherein the mobile device (2) comprises the second rule or data for verifying the second rule and the mobile device (2) transmits the second rule or the data for verifying the second rule to the access control device (3) during the method (100, 100a, 200, 300), wherein the encrypted portion (11) comprises the second rule or the data for verifying the second rule, wherein the method (100, 100a, 200, 300) comprises the step (105, 205, 206, 305, 306): - Verifying (105, 205, 206, 305, 306) the second rule in the access control device (3).

2. The method (100, 100a, 200, 300) according to claim 1, characterised in that the readable portion (12) comprises an item of information that can be displayed to the user on the mobile device (2).

3. The method (100, 100a, 200, 300) according to one of the preceding claims, characterised in that the access control device (3) uses the second rule transmitted by the mobile device (2) or the data for verifying the second rule only during the current access control method (100, 100a, 200, 300) for granting access to the physical region.

4. The method (100, 100a, 200, 300) according to one of the preceding claims, characterised in that the mobile device (2) transmits a comparison value, which is contained in particular in the encrypted portion (11), during the method (100, 100a, 200, 300) in a step (102, 202, 302) of the method (100, 100a, 200, 300) to the access control device (3), wherein the method (100, 100a, 200, 300) comprises the following steps (104, 204, 304, 105, 205, 305): - Transmitting (104, 204, 304) a verification value from the mobile device (2) to the access control device (3) - Comparing (105, 205, 305) the comparison value with the verification value in the access control device (3), in particular in that the comparison value and the verification value are always transmitted during the method (100, 100a, 200, 300) before a comparison of the comparison value with the verification value takes place, such that the access control device (3) always uses the transmitted comparison value and the transmitted verification value only in the current access control method (100, 100a, 200, 300).

5. The method (100, 100a, 200, 300) according to one of the preceding claims, characterised in that the first and / or the second rule, in particular the second rule, corresponds to or comprises one of the following rules: a. Access is granted only after a positive result of the comparison of the comparison value with the verification value, b. Access is granted only in a certain time range, c. Access is granted only if a positive result of a further authentication, in particular by means of a code or biometric recognition, is present, d. Access is granted only if a mark identifying the user as a security guard is designed to be negative.

6. The method (100, 100a, 200, 300) according to one of the preceding claims, characterised in that the first rule corresponds to or comprises at least one of the following rules: e. Access is granted only if the mobile device (2) carries out a further authentication, in particular by means of the input of a code or biometric recognition, with a positive result, f. Access is granted only if a location history of the mobile device (2) matches a specification of the location history, g. Access is granted only if a payment has been made in advance, h. Access is granted only if usage regulations for the physical region have been accepted, i. Access is granted only if training, in particular safety training, has been successfully completed.

7. The method (100, 100a, 200, 300) according to one of the preceding claims, characterised in that the second rule applies only in a predefined time window.

8. The method (100, 100a, 200, 300) according to one of the preceding claims, characterised in that the mobile device (2) comprises a time recording means and the first rule contains a time-dependent condition for granting access, wherein the first rule is verified by means of the time available to the mobile device (2) by means of the time recording means, wherein, in particular, the access control device (3) is designed to have no knowledge of a time.

9. The method (100, 100a, 200, 300) according to one of the preceding claims, characterised in that the first rule contains an additional condition in addition to the second rule and / or contains a restriction of the second rule.

10. The method (100, 100a, 200, 300) according to one of the preceding claims, characterised in that the mobile device (2) transmits the result of the verification of the first rule to the access control device (3), and the access control device (3) decides on the granting of access.

11. The method (100, 100a, 200, 300) according to one of the preceding claims, characterised in that the access control device (3) comprises a programming interface (8), wherein the access control device (3) and the mobile device (2) communicate with one another via the programming interface (8) during the method (100, 100a, 200, 300), in particular during the access control method (100, 100a, 200, 300).

12. The method (100, 100a, 200, 300) according to one of the preceding claims, characterised in that the access control device (3) opens the programming interface (8) during the method (100, 100a, 200, 300), wherein, in particular, the access control device (3) opens the programming interface (8) following a positive result of a verification of the rule, which is preferably verified in the access control device (3), particularly preferably following the comparison of the comparison value with the verification value.

13. An access control system (1) for carrying out a method (100, 100a, 200, 300) according to one of claims 1 to 12, comprising an access control device (3), which is assignable to a physical region, and comprising a mobile device (2), wherein the mobile device comprises an item of access information for the access control device, wherein the mobile device is designed to receive the access information wirelessly, wherein the access information comprises an access control device identifier and at least one access attribute, wherein the access attribute corresponds to a rule, data for a rule, an instruction and / or data for an instruction, wherein the access information (10) comprises an encrypted portion (11) which is not decryptable by the mobile device (2), wherein the encrypted portion (11) is provided to be transmitted to the access control device (3) during the method (100, 100a, 200, 300), wherein the access information (10) comprises a readable portion (12) which is unencrypted or decryptable by the mobile device, wherein the readable portion (12) comprises the first rule or data for the first rule, wherein the mobile device comprises a processor which can be used by the mobile device to verify the first rule, wherein the mobile device (2) contains at least one first rule for granting access to the physical region, wherein the mobile device (2) verifies the first rule for granting access to the physical region, wherein the first rule applies only in a predefined time window, wherein, during the method, a plurality of rules are verified, wherein a rule defines an access requirement, wherein, in the case of a negative result of the verification of the rule, access to the physical region is denied, wherein, while the method (100, 100a, 200, 300) is carried out, the access control device (3) obtains knowledge of a second rule or data for a second rule, wherein the mobile device (2) comprises the second rule or data for verifying the second rule and the mobile device (2) transmits the second rule or the data for verifying the second rule to the access control device (3) during the method (100, 100a, 200, 300), wherein the encrypted portion (11) comprises the second rule or the data for verifying the second rule, wherein the access control device is designed to verify the second rule in the access control device (3).

14. A computer program product for a mobile device (2) of an access control system (1) according to claim 13, for carrying out a method (100, 100a, 200, 300) according to one of claims 1 to 12.