Secure access control method for authorizing access to a secure space in a user-activated ultra wide band communication mode
Patent Information
- Authority / Receiving Office
- EP · EP
- Patent Type
- Applications
- Current Assignee / Owner
- SYSTEMES ET TECHNOLOGIES IDENTIFICATION (STID)
- Filing Date
- 2024-07-04
- Publication Date
- 2026-05-20
AI Technical Summary
Current secure access control systems using Ultra Wide Band communication mode for authentication are vulnerable to unauthorized access and excessive energy consumption due to constant activation, leading to security risks and battery drain, as they detect and authenticate users regardless of their intention to access the secure space.
Implementing a secure access control method where the Ultra Wide Band transceivers are awakened only upon detection of a user's approach, enabling secure telemetry and access control only when necessary, thereby reducing unnecessary data exchanges and energy consumption.
This approach enhances security by validating user intention and optimizing data exchanges, while reducing power consumption and minimizing risks of data interception and battery drain.
Smart Images

Figure FR2024050904_16012025_PF_FP_ABST
Abstract
Description
[0001] DESCRIPTION
[0002] TITLE: Secure access control method for authorizing access to a secure area and operating in an Ultra Wide Band communication mode activated by a user
[0003] [Technical field]
[0004] The invention relates to a secure access control method for controlling and authorizing or not authorizing access to a user to a secure space.
[0005] It relates more particularly to a secure access control method based on the Ultra Wide Band radio frequency communication mode.
[0006] The invention finds a preferred application in the implementation of a secure access control method involving an access center at which, via a secure access control reader, a user authenticates himself by means of a portable authentication device; the secure access control reader and the portable authentication device both operating in the Ultra Wideband radio frequency communication mode and exchanging data for the authentication of the user in this same communication mode.
[0007] [State of the art]
[0008] Ultra Wide Band is a radio frequency modulation technique that has recently become more widespread and is based on the transmission of pulses generally less than a nanosecond and used in a wide frequency band, between 3.1 GHz and 10.6 GHz. Among the advantages of Ultra Wide Band communication: a very high network data transfer rate over a wide bandwidth (greater than 500 MHz) over relatively short distances and at low power, without interfering with conventional narrowband and carrier wave transmissions in the same frequency bands. By misuse of language, radio frequency systems using this modulation technique to exchange data are said to communicate in an Ultra Wide Band communication mode.
[0009] Ultra Wideband technology is promising and is now being considered in the design of geolocation, tracking, pairing (point-to-point data transfer), payment, and access control solutions. Indeed, some mobile phone models available on the market integrate Ultra Wideband transceivers allowing them to communicate and exchange information in Ultra Wideband.
[0010] This is why secure access control readers are designed incorporating Ultra Wide Band transceivers so that access control solutions can be implemented to authorize or not a user to access a secure area, protected by an access control bay (door, airlock, barrier, etc.) equipped with a locking / unlocking system, which operate in the Ultra Wide Band communication mode, and for which the user identifies / authenticates himself, via a secure access control reader, with an access control center installed in the building and connected to the locking / unlocking system of the access control bay, by means of a mobile phone incorporating an Ultra Wide Band transceiver.Once the user has approached the secure access control reader so that it can detect the mobile phone, a stage called secure telemetry, or "secure ranging" or "securing ranging" in English, begins during which the secure access control reader and the mobile phone exchange data, according to a secure communication protocol, in order to authenticate the user. This data may, for example, include virtual identification keys, a user ID, etc. The data is transmitted by the secure access control reader to the access control center. Following receipt of the data, the access control center verifies it and, depending on the result of this verification, authorizes or denies access to the secure area by controlling the locking / unlocking system of the access control bay.
[0011] Due to the characteristics of the Ultra Wide Band communication mode in terms of performance, precision, and speed, secure telemetry reinforces the security of exchanges during point-to-point data transfers, by drastically limiting the risks of interception of data transfer between a transmitter and a receiver, i.e. “man in the middle” attacks.
[0012] Detailed explanations on the operating principle of secure ranging are given by N.O. Tippenhauer and S. Capkun in the technical report "UWB-based secure ranging and localization" published in 2012 (Technical Report / ETH Zurich, Department of Computer Science 586); and in the article "UWB with Pulse Reordering: Secure Ranging against Relay and Physical-Layer Attacks" written by M. Singh, P. Leu, and S. Capkun and published in 2017 by the International Association for Cryptologic Research - Network and Distributed Systems Security (NDSS) Symposium 2019, 24-27 February 2019, San Diego, CA, USA - ISBN 1-891562-55-X).
[0013] However, in the solutions currently proposed and available, the secure access control reader remains constantly activated in the Ultra Wide Band communication mode in order to locate the position of a mobile phone of a user equipped with an Ultra Wide Band transceiver to communicate with it and carry out secure telemetry in this communication mode.
[0014] The disadvantage of such an approach is that it presents security vulnerabilities because the detection of the mobile phone by the secure access control reader and the secure telemetry occur if the user with the mobile phone passes near the access control, whether or not they intend to access the secure area. In the case where the access control panel allows access to a user who is only passing in front of the access control reader and has no intention of access, it can potentially allow an unauthorized user to access the secure area protected by the access control bay.
[0015] Furthermore, in the case where the mobile phone remains for a certain period of time within the communication range of the secure access control reader, the latter may potentially periodically implement the secure telemetry step with the mobile phone; meaning that it will request the access center at regular intervals so that it checks the data that it transmits to it. In the case where the user of the mobile phone has access rights to access the secure area but does not wish to enter it, the periodic implementation of secure telemetry and data control by the access center may possibly result in repeated openings and closings of the access control bay.In addition to unnecessarily placing demands on the access control center, the increase in exchanges between the mobile phone, the secure access control reader, and the access control center weakens their security because it increases the risk that the data exchanged could be intercepted by a malicious system.
[0016] Furthermore, when secure access control readers remain constantly activated in the Ultra Wideband communication mode, they consume unnecessary energy if they do not detect any mobile phone, or if they detect a user's mobile phone and start communicating with them when said user has no intention of entering a secure area to which they control access, or does not have the necessary accreditations. In addition, the typical current consumption in the context of Ultra Wideband communication during signal transmission or reception can vary from a few tens to more than a hundred milliamps.Thus, the Ultra Wideband communication mode is energy-intensive and can be problematic in the case where a deployed secure access control reader is powered by a battery, because there is a risk that the battery will discharge after a period of activity of the secure access control reader, especially if it consumes energy just to detect mobile phones without any being present or requesting access.
[0017] [Summary of the invention]
[0018] The invention aims to address the issues raised by proposing a secure access control method for controlling and authorizing access by a user to at least one secure space accessible by at least one access control bay equipped with a locking / unlocking system, the secure access control method involving several pieces of equipment including:
[0019] - a portable authentication device carried by the user and containing user identification data, said portable authentication device comprising at least one Ultra Wide Band transceiver,
[0020] - at least one secure access control reader associated with at least one access control bay and comprising at least one Ultra Wide Band transceiver,
[0021] - an access center which is at least in communication with the access control reader and which is linked to the locking / unlocking system of the at least one access control bay; in which the secure access control method comprises at least:
[0022] - a step of waking up the secure access control reader initiated by a detection by at least one sensor of an approach or contact of the user or the portable authentication device with said secure access control reader, and followed by a waking up of the Ultra Wide Band transceiver of said secure access control reader to be able to transmit and receive in an Ultra Wide Band communication mode;
[0023] - a secure telemetry step between the secure access control reader and the portable authentication device, during which their Ultra Wide Band transceivers exchange at least security data in the Ultra Wide Band communication mode, and at the end of which a certified distance is established and then verified between the secure access control reader and the portable authentication device;
[0024] - an access control step during which the access center, after receiving the user's identification data, checks these to authorize or not access to the secure space accessible by the access control bay and, if necessary, controls the locking / unlocking system of said access control bay.
[0025] Thus, the secure telemetry step is implemented only on the condition that the Ultra Wide Band transceiver of the secure access control reader is woken up; this wake-up occurring following the wake-up step and therefore following the detection by the secure access control reader of an approach or contact of a user or their portable authentication device with respect to this secure access control reader. The waking up of the Ultra Wide Band transceiver of the secure access control reader means that it passes from a sleep state (in which it can only receive, but it cannot transmit), to an awake state (in which it can both transmit and receive).
[0026] It should be noted that, for the implementation of the secure telemetry step, the Ultra Wide Band transceiver of the portable authentication device must also be in the awake state, in order to also be able to transmit and receive in the Ultra Wide Band communication mode.
[0027] Advantageously, the implementation of the wake-up step allows:
[0028] - to validate a concrete intention of the user to want to access a secure space accessible from the access control bay associated with the secure access control reader;
[0029] - to optimize the exchanges between the secure access control reader, the portable authentication device and the access center by limiting them to the exchanges useful and necessary for the implementation of the secure access control process;
[0030] - less use of the access center by implementing a single access control step;
[0031] - in connection with the two previous points, to strengthen the security of exchanges and reduce the risks of data interception by a malicious system;
[0032] - to reduce power consumption in the Ultra Wide Band mode of the secure access control reader, and possibly, in the case where it is powered by a battery, to save the latter.
[0033] During the secure telemetry phase, the portable authentication device and the access control reader exchange security data. At the end of the secure telemetry phase, a certified distance between the secure access control reader and the portable authentication device is also established and then checked. During the access control phase, the access control center verifies the user's identification data (or, in English, credentials) to determine whether they have the accreditations to enter the secure area.
[0034] According to different embodiments of the invention, the locking / unlocking system of the access control bay, which may for example correspond to a latch that opens and closes, may either be physically connected by a cable to the access center, or be connected to the access center via a wireless link.
[0035] According to a characteristic of the invention, the access center receives the user's identification data on the condition that previously, during the secure telemetry step, it has been verified that the certified distance is less than or equal to an authorization distance.
[0036] In other words, the transmission of the user's identification data to the access center for the implementation of the access control step is conditioned by a check of the certified distance carried out at the end of the secure telemetry step. This check of the certified distance consists of verifying whether it is included, i.e. less than or equal to, an authorization distance. If yes, the user's identification data are transmitted to the access center. If no, they are not transmitted.
[0037] This distance control is an additional security measure to ensure that the user with the required credentials is in close proximity to the secure access control reader and / or the access control bay before unlocking the access control bay locking / unlocking system. This is because the user may have moved away from the secure access control reader or the access control bay; or, in the case where the wake-up step relies on detection of the user approaching, the secure access control reader may have detected the presence of the user or their portable authentication device while they are far from the user and / or the access control bay.
[0038] According to one possibility, the method comprises, prior to the secure telemetry step, a step of waking up the portable authentication device in which the Ultra Wide Band transceiver of said portable authentication device is woken up to be able to transmit and receive in the Ultra Wide communication mode.
[0039] The Ultra Wideband transceiver of the portable authentication device is designed to transmit and receive in the Ultra Wideband communication mode when it is in a state called the awake state; and only receive in the Ultra Wideband communication mode when it is in a state called the sleep state. Waking up the Ultra Wideband transceiver of the portable authentication device means that it transitions from the sleep state to the awake state (in which it can both transmit and receive).
[0040] In different application contexts, the portable authentication device may include a battery for its power supply. For the purposes of reducing power consumption and saving energy in the battery of the portable authentication device, the Ultra Wide Band transceiver of the portable authentication device is, at the start of the access control method, in the sleep state and is therefore only able to receive data in the Ultra Wide Band communication mode (but not to transmit it). However, in order for the secure telemetry step to be implemented, and for the authentication device to be able to communicate with the secure access control reader, it is essential that its Ultra Wide Band transceiver be in the awake state or switch to the awake state.This is why the secure access control method may include, prior to the secure telemetry step, a step of waking up the portable authentication device to wake up its Ultra Wide Band transceiver.
[0041] In other application contexts, this wake-up step is not necessary because the transceiver of the portable authentication device is already woken up when the secure access control process starts.
[0042] According to one embodiment of the invention, after the step of waking up the secure access control reader, the secure access control reader transmits a wake-up signal in the Ultra Wide Band communication mode which is received by the Ultra Wide Band transceiver of the portable authentication device, causing the step of waking up the portable authentication device (in other words causing the waking up of its Ultra Wide Band transceiver).
[0043] Following the wake-up step, the secure access control reader sends a wake-up signal in the Ultra Wide Band communication mode to the Ultra Wide Band transceiver of the portable authentication device, which is in the standby state and is therefore able to receive this wake-up signal. Once the portable authentication device receives this wake-up signal, its Ultra Wide Band transceiver switches to the awake state, allowing it to transmit data in the Ultra Wide Band communication mode, and therefore to participate in the secure telemetry state. According to an alternative embodiment of the invention, prior to the secure telemetry step, a wake-up action is performed by the user on the portable authentication device in order to trigger the wake-up step of the portable authentication device.
[0044] In other words, the waking up of the Ultra Wide Band transceiver is, in one embodiment, caused by an interaction of the user on his portable authentication device, this interaction being referred to as a wake-up action. This embodiment can be implemented in the case where the access control reader, once its Ultra Wide Band transceiver is woken up, is not configured / designed to send a wake-up signal to the portable authentication device.
[0045] According to one embodiment of the invention, the portable authentication device initiates the secure telemetry step following the step of waking up said portable authentication device (in other words following the waking up of its Ultra Wide Band transceiver).
[0046] In this embodiment of the invention, the portable authentication device is master and the secure access control reader is slave. In other words, the portable authentication device initiates the secure telemetry step provided that its Ultra Wide Band transceiver and that of the secure access control reader are awake.
[0047] According to an alternative embodiment of the invention, the secure access control reader initiates the secure telemetry step after having received, in the Ultra Wide Band communication mode, a start signal from the portable authentication device, said start signal being emitted by the portable authentication device following the step of waking up said portable authentication device (in other words following the waking up of its Ultra Wide Band transceiver).
[0048] In this variant, the secure access control reader sends a wake-up signal to the portable authentication device so that the latter wakes up its Ultra Wide Band transceiver, the access control reader is waiting for a response from the portable authentication device to initiate the secure telemetry step. This response is in the form of reception by the secure access control reader of the start signal from the portable authentication device, which start signal is emitted when the Ultra Wide Band transceiver of the portable authentication device wakes up.
[0049] In one embodiment of the invention, during the secure telemetry step, the certified distance: - is established by being calculated by at least one of the portable authentication device and the secure access control reader, then
[0050] - verified either by the portable authentication device or by the secure access control reader.
[0051] In one embodiment of the invention, only one of the two devices among the portable authentication device and the secure access control reader calculates the certified distance.
[0052] It is also possible for both the portable authentication device and the secure access control reader to calculate the distance between them. They exchange the distance value they have calculated. Each device then compares the distance it received with the distance it calculated itself. If the consistency between the distances is not verified, the telemetry step is stopped. If consistency is verified, the telemetry step continues.
[0053] In one embodiment of the invention, the certified distance is calculated from a measurement of a flight time, carried out by at least one of the two devices, during at least one bidirectional exchange of safety data.
[0054] More precisely, during the secure telemetry step a distance is calculated between the portable authentication device and the secure access control reader, said distance being by nature certified, hence the notion of certified distance.
[0055] The distance is certified by nature because it occurs during the secure telemetry step, and because it relies on at least one bidirectional exchange of Ultra Wide Band signals between two devices (the portable authentication device and the secure access control reader) each having: an embedded secure component; or trusted firmware or application previously loaded inside, or a trusted execution environment (TEE).
[0056] Certified distance is an additional means of strengthening the security level of the secure access protocol when the latter must be controlled for implementation or not by the subsequent access control step. Indeed, an uncertified distance could possibly be fraudulent and come from a malicious system that seeks to gain access to the secure space protected by the access control bay. Thus, if the equipment responsible for controlling the certified distance, but not for its calculation, receives a certified distance, it implements its control. Conversely, if the received distance is not certified, the control is not carried out and the secure access control process is stopped. As previously indicated, once the certified distance has been calculated, the secure telemetry step continues with its control to verify whether it is less than or equal to the authorization distance.Verification is performed by the secure access control reader, or by the portable authentication device.
[0057] In a first embodiment variant for which the certified distance is calculated by only one of the two devices among the secure access control reader and the portable authentication device, the device responsible for calculating the certified distance is also the one which controls it.
[0058] In a second variant embodiment for which the equipment responsible for the calculation is not the same as that responsible for verifying the certified distance, the certified distance is transmitted from the equipment having calculated it to the equipment having to verify it.
[0059] Optionally, the secure telemetry step is not limited to the exchanges and principles described. Further information on secure telemetry is available in the two references indicated in the State of the art.
[0060] According to a characteristic of the invention, the access center receives the user's identification data, from:
[0061] - either the secure access control reader, which secure access control reader has network access to communicate with the access center, via direct communication or via step-by-step communication (first embodiment);
[0062] - or the portable authentication device, which portable authentication device has network access and contains a connection address for connecting remotely to the access center and communicating with it (second embodiment).
[0063] According to one embodiment of the invention, the certified distance is verified by the equipment among the portable authentication device and the secure access control reader responsible for transmitting the user's identification data to the access center.
[0064] Knowing that the access control reader and the portable authentication device exchange their respective security data, in another embodiment variant for which the equipment among the portable authentication device and the secure access control reader verifying the certified distance is not the same as that in charge of transmitting the user's identification data to the access center, the equipment in charge of verifying the certified distance sends, if the certified distance is included in the authorization distance, an authorization signal to the equipment in charge of transmitting the user's identification data so that it implements said transmission.
[0065] In a first embodiment of the invention, the user's identification data is transmitted to the access center by the secure access control reader. This configuration can be implemented because the portable authentication device does not have network access.
[0066] If it is responsible for initiating the secure telemetry step, calculating and verifying the certified distance, and transmitting the user's identification data to the access control center, the secure access control reader then plays the central role in the execution of the secure access control process.
[0067] Advantageously, the calculation and verification of the certified distance, then the transmission of the user's identification data to the access center by the secure access control reader makes it possible to significantly strengthen the security level of the secure access control process since, by definition, the secure access control reader is a trusted system designed and conformed to be an integral part of an access control installation implementing secure access control processes.
[0068] In a first variant of the first embodiment, the secure access control reader is in wireless communication with the access control center and transmits the user's identification data directly to it.
[0069] In a second variant of the first embodiment, the secure access control reader and the access control center are part of a mesh network comprising several other secure access control readers. Each of the devices in the mesh network is capable of communicating with its close neighbors according to a close-to-close communication protocol. Advantageously, the mesh network addresses the problem of indoor network coverage, when the structure of the building and the materials used for its construction interfere with the transmission of signals, for example not allowing the secure access control reader involved in the secure access control method and the access control center to communicate with each other, even if they are within communication range (for example, because they are located in the basement, or on different floors of a building, or separated by a thick wall, etc.).
[0070] Without limitation, the secure access control reader and the access control center can communicate together using a wireless communication protocol such as Wifi® or Bluetooth Mesh®. In a third variant of the first embodiment, the secure access control reader is wired / physically connected to the access control center (for example, by means of Ethernet links, or an RS485 interface), meaning that it can transmit the user's identification data directly to it by wire.
[0071] In a second embodiment of the invention, the portable authentication device transmits the user's identification data to the access center if the user has network access and a connection address to connect remotely to the access center. This second embodiment can be implemented because the secure access control reader is autonomous and is therefore not in contact with the access center.
[0072] The connection address may correspond to data previously loaded into the portable authentication device, or correspond to data transmitted by the secure access control reader to the portable authentication device when the secure telemetry step is implemented.
[0073] Furthermore, if the portable authentication device initiates the secure telemetry step, calculates and verifies the certified distance, then it plays the central role in the execution of the secure access control process.
[0074] According to one embodiment of the invention, when the access center receives the user's identification data from the secure access control reader, the secure access control method also comprises, prior to the access control step, a transmission step during which the portable authentication device transmits, in the Ultra Wide Band communication mode, the user's identification data to the secure access control reader; said transmission step being implemented:
[0075] - following the secure access control reader wake-up step and before the secure telemetry step begins, or
[0076] - during the secure telemetry stage, or
[0077] - once the secure telemetry stage is completed.
[0078] In other words, in the case where the user identification data are transmitted to the access center by the secure access control reader, it is necessary for the portable authentication device to implement a step of transmitting the user identification data to the secure access control reader. As indicated above, this transmission step can be implemented before, during, or after the secure telemetry step. The implementation of the step of transmitting the user identification data to the secure access control reader, in the case where it is planned to take place before the secure telemetry step, implies at least that the Ultra Wide Band transceiver of the portable authentication device is in the awake state.It is conceivable, in the embodiment variants for which the Ultra Wide Band transceiver of the portable authentication device is woken up following receipt of the wake-up signal from the secure access control reader, that the transmission of the user identification data takes place simultaneously with the transmission of the start signal by the portable authentication device.
[0079] In the case where the transmission step is planned to take place following the secure telemetry step and before the access control step, it is possible for said transmission step to be implemented on the condition that it has been verified that the certified distance is less than or equal to the authorization distance. In other words, if the certified distance is greater than the authorization distance, neither the transmission step nor the access control step are implemented. Otherwise, if the certified distance is valid, then it is possible:
[0080] - when the portable authentication device carries out the control and validation of the certified distance, that it transmits the user's identification data immediately after validation of the certified distance; or
[0081] - when the secure access control reader is responsible for controlling and validating the certified distance, it sends a request signal to the portable authentication device after validation thereof, which portable authentication device, after receiving said request signal, transmits the user's identification data to the secure access control reader.
[0082] In a first embodiment, during the step of waking up the secure access control reader, the detection of the approach or contact consists of a detection of the contact of the user by the at least one sensor arranged on a part of the secure access control reader.
[0083] In this first embodiment, the at least one sensor can be chosen from a key, a mechanical sensor, a capacitive sensor, and an inductive sensor.
[0084] In other words, according to different embodiments of the invention, the detection of user contact may non-exhaustively correspond to:
[0085] - contact of a user's hand on a part of the secure access control reader, detected for example by means of electrostatic sensors (inductive sensor, capacitive sensor) or sound or optical sensors;
[0086] - pressing a key or button included in the secure access control reader on its shell or on a touchpad.
[0087] In a second embodiment, during the step of waking up the secure access control reader, the detection of the approach or contact consists of a detection by the at least one sensor of the approach of the user or the portable authentication device with a part of the secure access control reader within a given activation distance relative to the secure access control reader.
[0088] In this second embodiment, the at least one sensor can be chosen from a capacitive sensor, an inductive sensor, a radar sensor, an ultrasonic sensor, an optical sensor, a vibration sensor.
[0089] In other words, according to different embodiments of the invention, the detection of the user's approach may, without limitation, relate to:
[0090] - detection of movements of the user or the portable authentication device by a motion sensor (for example, a passive infrared motion sensor);
[0091] - vibrations caused by the user's steps on the ground, which are detected by an accelerometer;
[0092] - microphone detection of noises caused by the user's footsteps on the floor.
[0093] The approach of the user or their portable authentication device is detected as soon as they are within a distance of the secure access control reader that is less than or equal to an activation distance.
[0094] In one embodiment of the invention, the activation distance is defined by the designers or installers of the secure access control reader as being equal to the authorization distance.
[0095] In another embodiment of the invention, the activation distance is defined by the designers or installers of the secure access control reader as being substantially equal to the authorization distance, for example the activation distance is equal to 1.25 times the authorization distance.
[0096] According to a characteristic of the invention, the at least one sensor is mounted on the secure access control reader, or is remote from the secure access control reader and connected to the secure access control reader. In other words, the at least one sensor detecting an approach of the user or their portable authentication device can be integrated into the secure access control reader or remote from it.
[0097] In one embodiment of the invention, the remote sensor is integrated into a housing that also includes a push button that the user presses. The housing is, for example, attached to a wall in the space in which the secure access control reader is located.
[0098] According to alternative embodiments of the invention, the remote sensor is physically connected to the secure access control reader by a cable; or communicates with it by means of a wireless communication protocol (for example, Bluetooth Low Energy BLE®).
[0099] According to a first possibility, the portable authentication device is a physical access card or badge equipped with its Ultra Wide Band transceiver.
[0100] In a second possibility, the portable authentication device is a connected mobile terminal, such as a mobile phone, a tablet or a connected watch.
[0101] According to a characteristic of the invention, the connected mobile terminal participates in the secure telemetry step with the secure access control reader if the user has previously carried out at least one validation action on the connected mobile terminal, otherwise the secure telemetry step is not carried out.
[0102] In certain application contexts, the secure access control reader may have detected contact or an approach of the user without the user having the intention of accessing the secure space, because: the user accidentally touched or brushed against the reader; because the user moves close to the secure access control reader, causing the distance between the user and the secure access control reader to be included in the activation distance, or another person touches the secure access control reader while an accredited user is close to the secure access control reader, etc. Thus, the step of waking up the secure access control reader is accidentally implemented, then subsequently the secure telemetry step and the access control step.
[0103] Advantageously, the validation action is an additional security in the implementation of the secure access control method, to ensure that the user of the connected mobile terminal actually intends to access the secure space protected by the access control bay associated with the secure access control reader. As long as this validation action is not carried out, the telemetry step, and the subsequent access control step, are not implemented.
[0104] Other advantages are: reducing the power consumption of the secure access control reader and the connected mobile terminal in Ultra Wideband communication mode, by not making them perform an unwanted secure telemetry step; and not unnecessarily soliciting the access control center.
[0105] When the step of transmitting the user identification data is planned to take place before the secure telemetry step, and the portable authentication device is a connected mobile terminal, it is possible for it to be implemented following the completion of at least one validation action. In the case where the at least one validation action comprises several validation actions, the implementation of the transmission step can take place following the completion of the last of the several validation actions.
[0106] According to one embodiment of the invention, the at least one validation action comprises at least the wake-up action which triggers the step of waking up the connected mobile terminal.
[0107] This embodiment can be implemented, if for example, the Ultra Wide Band transceiver of the connected mobile terminal is in a sleep state at the start of the secure access control method, and the secure access control reader is not configured to send a wake-up signal to the connected mobile terminal following the step of waking up the secure access control reader in order to wake it up.
[0108] According to another embodiment of the invention, the connected mobile terminal transmits the start signal to the secure access control reader following the performance of at least one validation action.
[0109] In other words, in this other embodiment of the invention in which the secure telemetry step is implemented by the access control reader following receipt of the start signal from the connected mobile terminal, said start signal is sent once the user has carried out at least one validation action.
[0110] In an alternative embodiment of the invention, the at least one validation action is at the origin of the waking up of the Ultra Wide Band transceiver of the connected mobile terminal and the sending of a start signal; the sending of the start signal occurring automatically following the waking up of the Ultra Wide Band transceiver of the connected mobile terminal. According to an embodiment of the invention, the at least one validation action comprises at least one unlocking of the connected mobile terminal, causing said connected mobile terminal to switch from a locked state to an unlocked state.
[0111] In other words, the telemetry step, then the access control step, are carried out on the condition that: the Ultra Wide Band transceivers of the secure access control reader and the connected mobile terminal are both awake, and that the user has unlocked his connected mobile terminal.
[0112] According to one embodiment of the invention, the unlocking of the connected mobile terminal is implemented by the user according to at least one of the following operations:
[0113] - switching on a touch screen included in the connected mobile terminal by the user pressing it, or on a switch-on button also included in the connected mobile terminal;
[0114] - an operation of entering an unlocking code on the connected mobile terminal;
[0115] - a touch entry operation of an unlock pattern on a touch screen of the connected mobile terminal;
[0116] - a fingerprint recognition operation on a fingerprint sensor of the connected mobile terminal;
[0117] - a facial recognition operation of the user using a camera integrated into the connected mobile terminal.
[0118] In one embodiment of the invention, the connected mobile terminal initiates the secure telemetry step following its unlocking.
[0119] In one embodiment of the invention, following its unlocking, the connected mobile terminal transmits the start signal to the secure access control reader so that the latter initiates the secure telemetry step.
[0120] According to one embodiment of the invention, the at least one validation action comprises at least one launch operation carried out in a launch menu displayed by a mobile launch application, loaded into the connected mobile terminal.
[0121] In other words, the telemetry step, then the access control step, are carried out on the condition: that the Ultra Wide Band transceivers of the secure access control reader and the connected mobile terminal are both awake, and that the user has carried out a launch operation carried out in the launch menu of a dedicated application designed for the implementation of the secure access control method, and previously loaded into the connected mobile terminal. In a particular embodiment, the at least one validation action consists of unlocking the connected mobile terminal, followed by the launch operation.
[0122] In other words, the user must unlock their connected mobile terminal, then perform the launch operation in the launch menu, so that the secure telemetry step can be carried out.
[0123] According to one embodiment of the invention, the launching operation consists of at least one of the following operations:
[0124] - an operation of entering a launch code on the launch menu;
[0125] - a touch input operation of a launch pattern on the launch menu;
[0126] - a validation operation on the launch menu.
[0127] In one embodiment of the invention, the connected mobile terminal initiates the secure telemetry step following the execution of the launch operation.
[0128] In one embodiment of the invention, following execution of the launch operation, the connected mobile terminal transmits the start signal to the secure access control reader so that the latter initiates the secure telemetry step.
[0129] According to one embodiment of the invention, the mobile launcher application opens automatically and displays the launcher menu following unlocking of the connected mobile terminal.
[0130] In one embodiment of the invention, the user must first unlock his mobile, then interact with the launching mobile application and execute the launching operation so that the connected mobile terminal begins communicating with the secure access control reader to initiate the telemetry step.
[0131] In one embodiment of the invention, the connected mobile terminal initiates the secure telemetry step following its unlocking and the execution of the launch operation in the launch mobile application.
[0132] According to one embodiment of the invention, the at least one validation action comprises at least one inclination of the connected mobile terminal according to an inclination angle included in a predefined launch angular interval.
[0133] In one embodiment of the invention, the user's validation action corresponds to a certain orientation / inclination of the connected mobile terminal with respect to the secure access control reader, or the ground. The orientation of the connected mobile terminal is considered valid if the inclination angle of the connected mobile terminal with respect to the secure access control reader or the ground is within a predefined launch angular interval. This verification is performed either by the connected mobile terminal or by the secure access control reader.
[0134] If the tilt angle of the connected mobile terminal is valid, then the secure telemetry step is initiated.
[0135] The launch angular interval may be representative of an orientation of the connected mobile terminal such as:
[0136] - the front face of the connected mobile terminal faces or substantially faces the user;
[0137] - the rear face of the connected mobile terminal faces or substantially faces the secure access control reader.
[0138] According to one embodiment of the invention, the launch mobile application opens and displays the launch menu under the condition that the tilt angle is within the predefined launch angular range.
[0139] In other words, the launch mobile application is only displayed on the touch screen of the connected mobile terminal if the user tilts his connected mobile terminal at a valid tilt angle within the launch angular range.
[0140] The secure telemetry step is therefore only initiated following two user actions: adequate orientation of the connected mobile terminal, and carrying out the launch operation in the launch mobile application.
[0141] In one embodiment of the invention, the launcher mobile application opens and displays the launcher menu under the condition that the connected mobile terminal is unlocked, and the tilt angle is within the predefined launcher angular range.
[0142] In one embodiment of the invention, the connected mobile terminal initiates the secure telemetry step successively following:
[0143] - unlocking the connected mobile terminal;
[0144] - to the inclination of the connected mobile terminal such that the inclination angle is within the launch angular range; and
[0145] - to perform the launch operation in the launch menu of the launcher mobile application.
[0146] According to one embodiment of the invention, the angle of inclination is measured by means of an inertial unit integrated into the connected mobile terminal.
[0147] In other words, in one embodiment, the inclination angle is measured by the connected mobile terminal using an inertial unit that it contains. In one embodiment of the invention, the connected mobile terminal verifies whether the measured inclination angle is within the launch angular range or not. If this is the case then:
[0148] - the connected mobile terminal generates the start signal and transmits it to the secure access control reader so that it initiates the secure telemetry step; or else
[0149] - the connected mobile terminal initiates the secure telemetry step if it is responsible for it.
[0150] In another embodiment, the connected mobile terminal transmits its tilt angle measurement to the secure access control reader so that the latter checks whether it is within the launch angle range. If so:
[0151] - the access control reader initiates the secure telemetry step if it is responsible for it; or else
[0152] - transmits a confirmation signal to the connected mobile terminal, which upon receipt of said confirmation signal, initiates the secure telemetry step.
[0153] According to another embodiment of the invention, the tilt angle is measured by the secure access control reader, from reception signals of an Ultra Wide Band wave coming from the connected mobile terminal.
[0154] This embodiment assumes that the transceiver of the connected mobile terminal is woken up. In a first configuration, the transceiver of the connected mobile terminal is woken up at the start of the secure access protocol, meaning that the measurement of the tilt angle can be carried out by the secure access control reader before the step of waking up said secure access control reader (since its Ultra Wide Band transceiver is capable of receiving Ultra Wide Band signals). In a second configuration, the transceiver of the connected mobile terminal is in a sleep state at the start of the secure access protocol. The angle measurement of the tilt angle is then carried out after the step of waking up the secure access control reader, and after the Ultra Wide Band transceiver of the connected mobile terminal has been woken up following the reception of the wake-up signal from the secure access control reader.
[0155] In an embodiment where the connected mobile terminal is configured to initiate the secure telemetry step, then:
[0156] - either the secure access control reader transmits the angle measurement that it has measured to the connected mobile terminal for verification and then implementation or not of said secure telemetry step;
[0157] - either transmits a confirmation signal to it confirming that the inclination angle is contained within the launch angular interval, the connected mobile terminal implementing the secure telemetry step upon receipt of the confirmation signal.
[0158] According to a characteristic of the invention, the at least one secure space comprises at least one other secure space accessible by at least one other access control bay equipped with another locking / unlocking system and associated with another secure access control reader comprising an Ultra Wide Band transceiver, in which the secure access control method comprises a step of generating an access indicator and followed by a step of storing said access indicator in the connected mobile terminal, the generation step and the storage step being implemented when access to the secure space is authorized by the access center, and in which secure access control method is implemented an access control phase to access the other secure space which comprises the following steps:
[0159] - a step of detecting an access request made by the user on the connected mobile terminal;
[0160] - a transmission step during which the connected mobile terminal transmits, in the Ultra Wide Band communication mode, the access indicator to the other secure access control reader in response to the detection of the access request;
[0161] - a reception step during which the Ultra Wide Band transceiver of the other secure access control reader receives the access indicator;
[0162] - a transmission step during which the other secure access control reader transmits said access indicator to the access center;
[0163] - an access control step during which the access center, after receiving the access indicator, authorizes access to the other secure space accessible by the other access control bay and, where applicable, controls the other locking / unlocking system of said other access control bay, without receiving or verifying the user's identification data by said access center.
[0164] In fact, a building can include several secure areas with restricted access, each of the secure areas being protected by its own access control bay, to which a secure access control reader is associated.
[0165] In one embodiment of the invention, for which the secure access control readers have network access and can communicate with the access center, when a secure telemetry step is implemented between a secure access control reader associated with an access control bay of the building and the portable authentication device of a user wishing to access a first secure space protected by said access control bay, and the access center authorizes the user to enter the secure space, an access witness (or "cookie" in English) is generated then stored in the connected mobile terminal.
[0166] In one embodiment of the invention, the access indicator is generated and then transmitted by the access center to the connected mobile terminal, either directly if the connected mobile terminal and the access center are in direct communication, or via the secure access control reader having previously participated in the secure telemetry step (via direct communication between the access center and the secure access control reader, or via step-by-step communication with other secure access control readers).
[0167] In another embodiment of the invention, the access cookie is generated by the connected mobile terminal by means of a dedicated application previously loaded therein; the generation may, for example, follow the receipt of data relating to an access cookie generation agreement from the access center.
[0168] Advantageously, the access witness is used to speed up the authentication of the user with the access center if he wishes to cross another access control bay to enter a second secure area of the building.
[0169] To do this, when the user approaches the secure access control reader associated with this other access control bay, the user interacts with his connected mobile terminal so that it detects a request (i.e. an intention) for access.
[0170] According to different embodiments of the invention, the access request can be detected following:
[0171] - to contact between the user and his connected mobile terminal;
[0172] - an orientation / tilt of the connected mobile terminal with respect to the secure access control reader of the other access control bay;
[0173] - to unlock the mobile;
[0174] - to a launch operation carried out in a mobile application.
[0175] In other words, the methods used to detect the user's validation action from their connected mobile terminal to previously implement the secure telemetry step can also be used to detect the access request.
[0176] Once the access request is detected, the connected mobile terminal transmits only the access token to the secure access control reader of the other access control bay, which relays it to the access control center (via direct communication or step-by-step communication).
[0177] Upon receipt of the access cookie, the access center then authorizes the user to access the second secure area; this without having carried out a verification of the user's identification data.
[0178] In one embodiment of the invention, the access cookie is generated based on the user's identification data.
[0179] In other words, the access cookie only allows the user to facilitate their authentication to access secure areas for which they have the required accreditations. The access cookie does not allow the user to access secure areas for which they are not authorized.
[0180] According to a characteristic of the invention, the access witness has a limited validity period.
[0181] Advantageously, in order to secure simplified user authentication by using an access cookie, said access cookie has a limited validity period. Once the validity period has expired, the access cookie expires. Authenticating the user with the access center to access a secure area then consists of re-implementing at least the steps of wake-up, secure telemetry, and access control (with control by the access center of the user's identification data).
[0182] According to one embodiment of the invention, the authorization distance is less than or equal to 1 m.
[0183] [Brief description of the figures]
[0184] Other characteristics and advantages of the present invention will appear on reading the detailed description below, of a non-limiting example of implementation, made with reference to the appended figures in which:
[0185] [Fig 1] is a schematic view of an example of a building comprising two secure spaces each protected by an access control bay which comprises a locking / unlocking system, controlled by an access control unit, and which is associated with a secure access control reader operating in the Ultra Wide Band communication mode, with a user who seeks to access one of the secure spaces by authenticating himself to the access control unit via a secure access control reader, this by means of a portable authentication device;
[0186] [Fig 2] is a schematic view of a bidirectional data exchange, in the Ultra Wideband communication mode, between a portable authentication device, which may correspond to a connected mobile terminal or to a physical access card, and a secure access control reader;
[0187] [Fig 3] is a flow diagram of a first embodiment of the secure access control method, when the portable authentication device can correspond to both a connected mobile terminal and a physical access card;
[0188] [Fig 4] is a schematic view of a first variant of implementation of a wake-up step included in the secure access control method for switching the Ultra Wideband transceiver of the secure access control reader from a standby state to a woken-up state in which it is capable of transmitting and receiving data in the Ultra Wideband communication mode; the wake-up of the Ultra Wideband transceiver occurring following detection of physical contact of the user with the secure access control reader;
[0189] [Fig 5] is a schematic view of a second alternative implementation of the wake-up step, with the wake-up of the Ultra Wideband transceiver occurring following detection of an approach of the user, or their portable authentication device, within a given activation distance from the secure access control reader;
[0190] [Fig 6] is a schematic view of a principle for calculating a time of flight during a bidirectional exchange of data between the portable authentication device and the secure access control reader during a secure telemetry step implemented during the secure access control method;
[0191] [Fig 7] is an illustration, following the secure telemetry step, of a data transmission to authenticate the user from the secure access control reader to the access center which is configured to control the user's identification data in order to authorize or not the user to access a secure area, the transmission of the data being able to be done by direct communication (Figure 7-a) or by a step-by-step communication (Figure 7-b);
[0192] [Fig 8] is a schematic view of a validation action to be performed to implement the telemetry step following the step of waking up the secure access control reader, said validation action being implemented only in embodiments for which the portable authentication device is a connected mobile terminal, and corresponding here, in a given variant embodiment, to a launch operation performed by the user on an available launch menu of a mobile launch application included in the connected mobile terminal; [Fig 9] is a schematic view of a second variant embodiment of the validation action, which corresponds to an inclination of the connected mobile terminal with respect to the ground and the secure access control reader;
[0193] [Fig 10] is a flow diagram of a second embodiment of the secure access control method when the portable authentication device is a connected mobile terminal, which flow diagram comprises performing validation actions necessary to start the secure telemetry step;
[0194] [Fig 11] is a schematic view of an embodiment of the secure access control method, in which the transmission of the user identification data following the secure telemetry step is implemented by the connected mobile terminal, which has a connection address to connect to the access center to make said transmission possible;
[0195] [Fig 12] is an operating diagram of a third embodiment of the secure access control method when the portable authentication device is a connected mobile terminal, which secure access control method notably comprises generating and then storing an access cookie in the connected mobile terminal of the user following authorization of access to a first secure space by the access center, said access cookie subsequently serving to accelerate the authentication of the user with another secure access control reader to access another secure space;
[0196] [Fig 13] is a schematic view of the building in Figure 1 and illustrating an application context linked to the operating diagram in Figure 12, for which the user, after entering a secure space, will use the access cookie contained in his connected mobile terminal to authenticate himself with the access center to access another secure space;
[0197] [Fig 14] is a schematic view linked to Figure 12 and Figure 13, for which, in one embodiment, and in order to authenticate itself with the access center, the connected mobile terminal transmits the access indicator to another secure access control reader following the detection of a contact, here a tap, from the user.
[0198] [Detailed description of one or more embodiments of the invention]
[0199] With reference to Figure 1 and Figure 2, the secure access control method 100 of the invention, designed to operate in the Ultra Wide Band communication mode, is implemented in the application context of a building comprising at least two secure spaces SI, S2, access to which is protected from access control bays DI, D2 each equipped with a locking / unlocking system, and each associated with a secure access control reader RI, R2 comprising an Ultra Wide Band transceiver UR1, UR2 in order to be able to transmit and receive signals / data in this communication mode.
[0200] In the following description:
[0201] - the secure spaces SI, S2 are designated under the terms of secure space SI and other secure space S2;
[0202] - the DI, D2 access control bays are referred to as the DI access control bay and other D2 access control bay; and
[0203] - RI, R2 secure access control readers are referred to as RI secure access control reader and other R2 secure access control reader.
[0204] It is also considered in the remainder of the description that a user U wishes to access the secure space SI. To do this, he must authenticate himself with the secure access control reader RI by means of a portable authentication device 1, 10; which portable authentication device 1, 10 also comprises an Ultra Wide Band transceiver Ul, U10 in order to be able to transmit and receive in the Ultra Wide Band communication mode.
[0205] The portable authentication device may, but is not limited to:
[0206] - an access card 10, or a badge, or a key ring, etc.
[0207] - or to a connected mobile terminal 1 equipped with a touch screen, for example: a mobile phone, a touch tablet, a connected watch, etc.
[0208] The Ultra Wide Band transceivers UR1, UR2, Ul, U10 of the secure access control readers RI, R2 and the portable authentication device 1, 10 can operate:
[0209] - in a standby state with only the ability to receive Ultra Wideband data / signals, but not the ability to transmit Ultra Wideband data / signals; or
[0210] - in an awake state where they are able to transmit and receive data / signals in Ultra Wide Band.
[0211] In other words, with reference to Figure 2, when woken up (i.e. in the woken up state), the Ultra Wide Band transceivers Ul, U10, UR1, UR2 of the portable authentication device 1, 10 and the secure access control reader UR1, UR2 can carry out a bidirectional exchange of UWB1, UWB10 data in the Ultra Wide Band communication mode.
[0212] In the remainder of the description, when it is written that a portable authentication device 1, 10 and a secure access control reader RI, R2 exchange data (during transmissions and receptions), it is understood that it is their Ultra Wide Band transceivers Ul, U10, UR1, UR2 which exchange said data.
[0213] Authentication of user U is made possible when: the portable authentication device 1, 10 is within the communication range of the access control reader RI; the Ultra Wide Band transceivers Ul, U10, UR1 of these two devices are awakened.
[0214] The secure access control method 100 is remarkable in that, at its start, the Ultra Wide Band transceivers UR1, UR2 of the secure access control readers RI, R2 are in a standby state. As explained previously, putting the Ultra Wide Band transceivers of the secure access control readers RI, R2 into standby when they are not to intervene in the secure access control method 100 allows in particular:
[0215] - to reduce their power consumption in Ultra Wide Band mode, and possibly, in the case where it is powered by a battery, to save the latter;
[0216] - to avoid automatic and unnecessary communication between the secure access control readers RI, R2 and the portable authentication device 1, 10 located within their communication range while its user does not wish to access the secure areas SI, S2;
[0217] - in connection with the previous point, to strengthen the security level of the access control process 100 and the security of exchanges: by reducing the risks of interception of data that can be exchanged between the secure access control readers RI, R2 and the portable authentication device 1, 10 by a malicious system during the authentication of the user U.
[0218] Thus, the secure access control method 100 is designed so that, prior to the authentication of the user U with one of the secure access control readers RI, R2, a switch of its Ultra Wide Band transceiver UR1, UR2 from the standby state to the awake state is implemented.
[0219] Several embodiments of the secure access control method 100 are possible. Among them, the secure access control method 100 shown in Figure 3 is conceivable for all of the above-mentioned portable authentication devices 1, 10. It is considered that the Ultra Wide Band transceivers Ul, U10 of the portable authentication device 1, 10 and the secure access control reader RI are both in the standby state.
[0220] In this embodiment of Figure 3, the secure access control method 100 begins with a wake-up step WP-R of the secure access control reader RI in order to wake up its Ultra Wide Band transceiver UR1.
[0221] With reference to Figure 4, in a first embodiment variant, the awakening of the Ultra Wide Band transceiver UR1 of the secure access control reader RI occurs following detection of a contact of the user U by at least one sensor sensRl arranged on a part of the secure access control reader RI. In this first variant, the at least one sensor sensRl is chosen from a key, a mechanical sensor, a capacitive sensor, and an inductive sensor. Thus, the detection of the contact of the user U may non-exhaustively correspond to:
[0222] - contact of a hand of the user U on a part of the secure access control reader RI, detected for example by means of electrostatic sensors (inductive sensor or capacitive sensor);
[0223] - pressing a key or button included in the secure RI access control reader on its shell or on a touchpad.
[0224] With reference to Figure 5, in a second embodiment variant, the awakening of the Ultra Wide Band transceiver UR1 of the secure access control reader RI occurs following detection by at least one sensor sensRl of the approach of the user U or of the portable authentication device 1, 10 with a part of the secure access control reader RI within a given activation distance d-act relative to the secure access control reader RI. In this second variant, the at least one sensor sensRl is chosen from a capacitive sensor, an inductive sensor, a radar sensor, an ultrasonic sensor, an optical sensor, a vibration sensor. Thus, the detection of the approach of the user U may, without limitation, relate to:
[0225] - detection of movements of the user U or of the portable authentication device 1, 10 by a motion sensor (for example, a passive infrared motion sensor or other optical sensor);
[0226] - vibrations caused by the steps of user U on the floor, which are detected by an accelerometer; - detection by a microphone of the noises caused by the steps of user U on the floor.
[0227] In this second variant, the at least one sensor sensRl detecting an approach of the user U or of his portable authentication device 1, 10 can be integrated into the secure access control reader RI or remote from it. For example, the remote sensor can be contained in a housing which also comprises a push button which the user U presses, which housing is fixed to a wall of the space in which the secure access control reader RI is located and: either is physically connected to the secure access control reader RI by a cable; or communicates with it by means of a wireless communication protocol (for example, in Bluetooth Low Energy BLE®).
[0228] In one embodiment of the invention, it is conceivable that the secure access control reader RI incorporates a light-emitting diode such that it lights up when the Ultra Wide Band transceiver UR1 of the secure access control reader RI is woken up, and is not lit when it is in the standby state; so as to signal / inform the user U of the state of the Ultra Wide Band transceiver UR1, also indicating to him whether after approaching the secure access control reader RI or touching it, the wake-up step WP-R has been correctly carried out.
[0229] Once its Ultra Wideband transceiver UR1 is awakened, the secure access control reader RI, during a transmission step El, transmits a wake-up signal ws to the portable authentication device 1, 10. Following reception of the wake-up signal ws during a reception step El', the Ultra Wideband transceiver Ul, U10 of the portable authentication device 1, 10 switches from the standby state to the awakened state during a wake-up step WP-T of said portable authentication device 1, 10.
[0230] Following the awakening of the Ultra Wide Band transmitter Ul, U10 of the portable authentication device 1, 10, the portable authentication device 1, 10 and the secure access control reader RI communicate together during a secure telemetry step SR in order to authenticate the user U. According to two different embodiments, the secure telemetry step SR can be initiated:
[0231] - either by the RI secure access control reader;
[0232] - either by the portable authentication device 1, 10 following the awakening of its Ultra Wide Band Ul, U10 transceiver.
[0233] The portable authentication device 1, 10 contains at least user identification data udata, or credentials in English. In the embodiment shown in Figure 3, the secure access control reader RI is considered to be the equipment initiating the secure telemetry step SR.
[0234] In an alternative embodiment of the invention, the secure access control reader RI can initiate the secure telemetry step SR after a certain time after sending the wake-up signal ws during the transmission step El. In another alternative embodiment, as illustrated in Figure 3, the secure access control reader is configured to implement the secure telemetry step once it has received, during a reception step E2', from the portable authentication device 1, 10, a start signal ack. This start signal ack, comparable to an acknowledgment signal, is transmitted in the Ultra Wide Band communication mode by the portable authentication device 1, 10 during a transmission step E2 following the awakening of its Ultra Wide Band transceiver Ul, U10.
[0235] With reference to Figure 3, the secure telemetry step SR includes at least:
[0236] - a transmission step ESR1 during which the secure access control reader RI transmits security data sdatal to the portable authentication device 1, 10;
[0237] - a transmission step ESR2 during which the portable authentication device 1, 10 transmits security data sdata2 to the secure access control reader RI.
[0238] - a step EC of calculating a certified distance sdist between the portable authentication device 1, 10 and the secure access control reader RI; and
[0239] - an Everif verification step following the EC calculation step during which a verification of the certified distance sdist is carried out.
[0240] In one embodiment of the invention, the secure telemetry step SR is preceded by a first exchange between the portable authentication device 1, 10 and the secure access control reader RI; this first bidirectional exchange taking place after the wake-up step WP-T.
[0241] With reference to Figure 6, in one embodiment of the invention, the certified distance sdist is calculated, according to the equation Eq.l, by at least one of the portable authentication device 1, 10 and the secure access control reader RI from a time of flight ToF (Time Of Flight) measured by said at least one of the portable authentication device 1, 10 and the secure access control reader RI.
[0242] Tloop — Treply
[0243] ToF = - Eq.l
[0244] 2 where Treply is the response time of the portable authentication device 1, 10 which corresponds to the time interval between: the instant when it receives during a reception step ESR1' the security data sdatal from the secure access control reader RI and the instant, and the implementation of the transmission step ESR2; and Tloop is the duration of the bidirectional exchange between the secure access control reader RI and the portable authentication device 1, 10, i.e. here the time interval between the transmission step ESR1 and a reception step ESR2' during which the secure access control reader RI receives from the portable authentication device 1, 10 the security data sdata2.
[0245] In one embodiment of the invention, as illustrated in Figure 3, only one of the two devices 1, 10, RI calculates the certified distance sdist (here, the secure access control reader RI).
[0246] The certification of the distance comes from the fact that the distance is calculated during the SR secure telemetry step, and that it is based on at least one bidirectional exchange of Ultra Wide Band signals between two devices (the portable authentication device and the secure access control reader) each having: an embedded secure component; or a trusted firmware or application previously loaded inside, or a trusted execution environment (or "Trusted Execution Environment" TEE in English).
[0247] In another embodiment of the invention, the portable authentication device 1, 10 and the secure access control reader RI both calculate the certified distance sdist. Both exchange the certified distance value sdist that they have calculated. Each device 1, 10, RI then compares the certified distance sdist that it has received with the certified distance sdist that it has itself calculated. In the case where the consistency between the certified distances sdist is not verified, the telemetry step SR is stopped. In the case where the consistency is verified, the telemetry step SR continues with the verification step Everif.
[0248] The Everif verification step consists of comparing the certified distance sdist with an authorization distance dauth. More precisely, it is a matter of checking whether the certified distance sdist is included in the authorization distance dauth, that is, whether it is less than or equal to the latter.
[0249] In a first embodiment variant, the equipment 1, 10, RI in charge of the EC calculation step is also the one in charge of the Everif verification step. Preferably, with reference to Figure 3, it is the secure access control reader RI which is responsible for implementing the EC calculation and Everif verification steps.
[0250] In a second embodiment, one of the two devices 1, 10, RI among the portable authentication device 1, 10 and the secure access control reader RI is in charge of the calculation step EC, while the other is in charge of the verification step Everif. Thus, once one of the two devices 1, 10, RI has calculated the certified distance sdist, it must transmit it to the other device 1, 10, RI so that it can be checked / verified.
[0251] Comparing the certified distance sdist to the authorization distance dauth makes it possible to determine whether the user U is close or not to the secure access control reader RI, this proximity reflecting the user U's desire to access the secure space SI.
[0252] In one embodiment of the invention, the dauth authorization distance is less than or equal to 1 m.
[0253] In an alternative embodiment, the authorization distance dauth is equal to the activation distance d-act (described previously) from which the secure access control reader RI is able to detect an approach of the user U or his portable authentication device 1, 10.
[0254] In another variant, the activation distance d-act is defined to be substantially equal to the authorization distance dauth, for example the activation distance is equal to 1.25 times the authorization distance dauth.
[0255] If the certified distance sdist is greater than the authorization distance dauth, the access control method 100 stops. In an alternative embodiment, it is possible for the secure access control reader RI to switch its Ultra Wide Band transceiver UR1 to the standby state. If the user U wishes to authenticate again, which implies a new implementation of the secure access control method 100, he will then have to touch or approach the secure access control reader RI again for the wake-up step WP-R to be carried out.
[0256] If the certified distance sdist is less than or equal to the authorization distance, the telemetry step SR ends and the secure access control method 100 continues.
[0257] In various embodiments of the invention, the secure telemetry step SR may not be limited to the exchanges and principles described. Further information on secure telemetry is available in the two references indicated in the State of the art. At the end of the secure telemetry step SR, if the certified distance is valid, the user identification data udata are transmitted to an access center 2.
[0258] According to two different embodiments, the transmission is ensured by the secure access control reader or by the portable authentication device 1, 10 according to which equipment 1, 10, RI has network access to be able to communicate with the access center 2.
[0259] In one embodiment of the invention, the equipment 1, 10, RI having carried out the Everif verification step of the certified distance sdist is the one in charge of transmitting the user identification data udata to the access center 2. In the embodiment illustrated in Figure 3, it is therefore the secure access control reader RI which implements a transmission step E3 of the user identification data udata.
[0260] Advantageously, the implementation of the EC calculation, Everif verification, and E3 transmission steps by the secure access control reader RI makes it possible to significantly strengthen the security level of the secure access control method 100 since, by definition, the secure access control reader RI is a trusted system designed and conformed to be an integral part of an access control installation implementing secure access control methods.
[0261] In two embodiments, the secure access control reader RI is directly linked to the access control center 2: either by being physically connected to it (for example, by means of Ethernet links, or an RS485 interface), or by being in direct communication with it according to a wireless communication protocol (see Figure 7-a) operating in a frequency band included or not in the Ultra Wide Band. For example, the secure access control reader RI is directly linked to the access control center 2 can communicate in Wifi®.
[0262] In a third embodiment of the invention, the secure access control reader RI and the access control unit 2 are part of a mesh network comprising several other secure access control readers. In the example illustrated in Figure 1, the other secure access control reader R2 is also part of this mesh network. Each of the devices RI, R2, 2 of the mesh network is capable of communicating with its closest neighbor(s) according to a close-to-close communication protocol, for example Bluetooth Mesh®.
[0263] Advantageously, the mesh network addresses the problem of indoor network coverage, when the structure of the building and the materials used for its construction interfere with the transmission of signals and do not allow two devices to communicate correctly while they are within communication range of each other.
[0264] In the example shown in Figure 7-b, the secure access control reader RI transmits the user identification data udata to the other secure access control reader R2; which other secure access control reader R2 then relays it to the access control unit 2.
[0265] In order for the secure access control reader RI to be able to transmit the user identification data udata to the access control unit 2 so that it can carry out the access control step CS, it is necessary for the authentication device 1, 10 to have previously transmitted said user identification data udata to the secure access control reader RI.
[0266] The secure access control method 100 provides that the portable authentication device 1, 10, once awakened, communicates the user identification data udata to the secure access control reader RI during a transmission step. This transmission step can take place before, during, or after the secure telemetry step SR.
[0267] In the described embodiments for which the secure access control reader RI is responsible for transmitting the user identification data, therefore including that illustrated in Figure 3, it is considered that the transmission step takes place during the secure telemetry step SR, and that the user identification data udata are transmitted during the transmission step ESR2.
[0268] Optionally, in the case where the transmission of the user identification data udata from the portable authentication device 1, 10 to the secure access control reader RI is planned to take place following the secure telemetry step SR, said transmission is implemented in the case where the certified distance is validated (i.e. if it is less than or equal to the authorization distance dauth).
[0269] With reference to Figure 3, following the reception of the identification data of the user udata during a reception step E3', the access center 2 is configured to implement an access control step CS during which it checks at least the identification data of the user udata to determine whether the user U has the required accreditations to access the secure space SI protected by the access control bay D1. If this is not the case, access to the secure space SI is refused to the user. Once at least the identification data of the user udata have been validated, the access center 2 unlocks the locking / unlocking system of the access control bay DI to allow the user U to enter the secure space SI.
[0270] According to different embodiments of the invention, the locking / unlocking system of the access control bay D1, which may for example correspond to a latch that opens and closes, may either be physically connected by a cable to the access center 2, or be connected to the access center 2 via a wireless link.
[0271] In one embodiment of the invention, the secure access control reader RI is configured to switch its Ultra Wide Band transceiver UR1 into the standby state after an activity duration which is established according to the time necessary to implement all of the steps of the secure access control method 100.
[0272] In another embodiment, the access center 2, following the implementation of the access control step CS, transmits a standby signal to the secure access control reader RI. Once this standby signal is received, the Ultra Wide Band transceiver UR1 of the secure access control reader RI switches to the standby state.
[0273] When the portable authentication device 1, 10 considered is only a connected mobile terminal 1, it is possible for the secure telemetry step SR to be implemented: when the Ultra Wide Band transceivers Ul, UR1 of the connected mobile terminal 1 and of the secure access control reader RI are woken up, but also that at least one validation action ulock, opt, inc is carried out beforehand on the connected mobile terminal 1.
[0274] The at least one validation action ulock, opt, inc is an additional security / condition in the implementation of the secure access control method 100 in order to ensure that the user U of the connected mobile terminal 1 actually intends to access the secure space SI protected by the access control bay D1 associated with the secure access control reader RI.
[0275] The at least one validation action ulock, opt, inc avoids implementing the secure telemetry step SR, then subsequently the access control step CS, if the secure access control reader RI has detected contact from the user U or an approach of the latter or his connected mobile terminal 1 while he has no intention of accessing the secure space SI. Other advantages are: reducing the power consumption of the secure access control reader RI and the connected mobile terminal 1 in the Ultra Wideband communication mode, and not unnecessarily soliciting the access center 2.
[0276] The at least one ulock, opt, inc validation action may be in the form of a ulock unlocking of the connected mobile terminal 1, causing said connected mobile terminal 1 to switch from a locked state to an unlocked state. Non-exhaustively, this ulock unlocking may be implemented following:
[0277] - switching on a touch screen included in the connected mobile terminal 1 by the user U pressing on it, or on a switch-on button also included in the connected mobile terminal 1; or
[0278] - an operation of entering an unlocking code on the connected mobile terminal 1; or
[0279] - a touch entry operation of an unlock pattern on the touch screen of the connected mobile terminal 1; or
[0280] - a fingerprint recognition operation on a fingerprint sensor of the connected mobile terminal 1; or
[0281] - a facial recognition operation of the user U by means of a camera integrated into the connected mobile terminal 1.
[0282] With reference to Figure 8, the at least one ulock, opt, inc validation action may also be in the form of an opt launch operation carried out in a launch menu displayed by a mobile launch application l-app, loaded in the connected mobile terminal 1. Non-limitingly, it is possible for the opt launch operation to consist of:
[0283] - an operation of entering a launch code on the launch menu;
[0284] - a touch input operation of a launch pattern on the launch menu;
[0285] - a validation operation on the launch menu.
[0286] With reference to Figure 9, the at least one validation action ulock, opt, inc may also correspond to an inclination inc of the connected mobile terminal 1. It consists of a measurement of an inclination angle tetal, teta2 of the connected mobile terminal 1, which is then compared to a predefined launch angular interval. If the inclination angle tetal, teta2 is included in the launch angular interval, then the inclination is considered valid for the subsequent implementation of the secure telemetry step SR. The launch angular interval corresponds to an orientation of the connected mobile terminal 1 with respect to the secure access control reader RI, or the ground such that:
[0287] - the front face Fl of the connected mobile terminal 1 faces or substantially faces the user U; - the rear face F2 of the connected mobile terminal 1 faces or substantially faces the secure access control reader RI.
[0288] In a first embodiment variant illustrated in Figure 9 (a), the inclination inc consists of a measurement of a tetal inclination angle by the secure access control reader RI from reception signals of an Ultra Wide Band wave coming from the connected mobile terminal, for example during a bidirectional exchange of UWB1 data taking place when the Ultra Wide Band transceivers Ul, RI of the connected mobile terminal and of the secure access control reader RI are both woken up; which inclination angle is then compared to the launch angular interval.
[0289] In a second embodiment illustrated in Figure 9 (b), the inclination inc consists of a measurement of an inclination angle teta2 of the connected mobile terminal 1 relative to the ground by an inertial unit included in the connected mobile terminal 1.
[0290] According to several configurations:
[0291] - either the equipment 1, RI among the connected mobile terminal 1 and the secure access control reader RI which carries out the measurement of the inclination angle tetal, teta2 and its validation, via its comparison with the launch angular interval, is the same as that which initiates the secure telemetry step SR, in which case it is launched by said equipment 1, RI following said validation;
[0292] - either the equipment 1, RI among the connected mobile terminal 1 and the secure access control reader RI which is responsible for measuring the inclination angle tetal, teta2 is not the same as the one which validates it, in which case there is transmission of the inclination angle tetal, teta2 of said equipment 1, RI to the other equipment 1, RI;
[0293] - either the equipment 1, RI among the connected mobile terminal 1 and the secure access control reader RI which is responsible for validating the inclination inc is not the same one which initiates the secure telemetry step, in which case the equipment 1, RI transmits, if the inclination inc is valid, a confirmation signal to the other equipment 1, RI which, upon receipt of the latter, starts the secure telemetry step SR.
[0294] According to various embodiments of the secure access control method 100, the at least one ulock, opt, inc validation action may comprise several ulock, opt, inc validation actions carried out prior to the secure telemetry step SR. It is conceivable that these several ulock, opt, inc validation actions are carried out successively one after the other or not. For example, in an alternative embodiment, the user must perform a ulock unlocking of his connected mobile terminal 1 followed by an opt launch operation in the l-app launch mobile application, which opens automatically and displays the launch menu following the ulock unlocking of the connected mobile terminal 1.
[0295] In another particular variant embodiment, following the implementation of the wake-up steps WP-R, WP-T of the connected mobile terminal 1 and the secure access control reader RI, the secure telemetry step SR is initiated on the condition that the user:
[0296] - performs a ulock unlock of its connected mobile terminal 1;
[0297] - tilts its connected mobile terminal 1 according to a compliant tilt angle tetal, teta2 in order to validate the tilt inc;
[0298] - performs an opt launch operation on the l-app launcher mobile application, which l-app launcher mobile application is displayed on the touch screen of the connected mobile terminal 1 following validation of the inclination inc (i.e., the l-app launcher mobile application is not displayed if the inclination is invalid).
[0299] Another example of implementation of the secure access control method 100 is given in Figure 10. In this example, the wake-ups of the Ultra Wide Band transceivers Ul, UR1 of the connected mobile terminal 1 and of the secure access control reader RI take place similarly to the example embodiment given in Figure 3.
[0300] After touching the secure access control reader RI (which has resulted in the completion of the two wake-up steps WP-T, WP-R, the transmission step El and the reception step El'), the user U proceeds to unlock ulock of his connected mobile terminal 1. Unlocking ulock of the connected mobile terminal has the effect of automatically launching the launch mobile application l-app, the launch menu of which is then displayed on the touch screen of the connected mobile terminal 1. Once the launch mobile application l-app has started, the user U performs a launch operation opt.
[0301] In the embodiment shown in Figure 10, the secure access control reader RI still initiates the secure telemetry step SR.
[0302] Following the completion of the launch operation opt, the connected mobile terminal 1 implements the transmission step E2 during which it sends the start signal ack to the secure access control reader. Once the start signal ack has been received during the reception step E2', the secure access control reader RI initiates the secure telemetry step SR. As explained previously, the user identification data udata can be transmitted to the access center 2 in a first case by the secure access control reader RI, or else in a second case by the connected mobile terminal 1 itself (implying that the connected mobile terminal has network access). The embodiment presented in Figure 10 covers this second case.
[0303] In order to communicate with the access center 2, the connected mobile terminal 1 must have an add-c connection address relating to the latter.
[0304] In a first variant embodiment, the connection address add-c is already contained in the connected mobile terminal 1, having been previously loaded into it before the implementation of the secure access control method 100.
[0305] In a second embodiment, the connection address add-c is transmitted to the connected mobile terminal 1 by the secure access control reader RI during the secure telemetry step SR. Non-limitingly, it is possible for the connection address add-c:
[0306] - either transmitted during the at least one bidirectional exchange between the secure access control reader RI and the connected mobile terminal 1 that comprises the secure telemetry step SR, and which encompasses the transmission steps ESRI, ESR2 and the reception steps ESRI', ESR2'. In other words, the connection address add-c is transmitted with the security data sdatal during the transmission step ESR1; or
[0307] - either transmitted by the access control reader RI during a transmission step taking place during the secure telemetry step SR and independent of the at least one exchange in question.
[0308] With reference to Figure 10, it is also conceivable, in the case where the access control reader implements RI the steps of calculation EC and verification of the certified distance sdist, but is not responsible for transmitting the user identification data udata to the access center 2, that it transmits to the connected mobile terminal 1, during a transmission step ESR3 included in the secure telemetry step SR and which takes place after the verification step Everif, the connection address add-c simultaneously with a Goto authorization signal which aims to indicate to the connected mobile terminal 1 that it can transmit the user identification data udata to the access center 2.
[0309] With reference to Figures 10 and 11, following receipt of the connection address add-c and the authorization signal Goto during a reception step ESR3', the connected mobile terminal 1 transmits to the access center 2 during a transmission step E4 the identification data of the user udata.
[0310] Following the reception of the user identification data udata during a reception step E4', the access center 2 implements the access control step CS (as already described previously with reference to Figure 3).
[0311] In some embodiments of the invention, the access control reader RI may not be configured to send a wake-up signal ws to the portable authentication device 1, 10 following the implementation of the wake-up step WP-R of the secure access control reader RI. In this case, the switch from the sleep state to the woken-up state of the Ultra Wide Band transceiver Ul, U10 of the portable authentication device 1, 10 is caused by a wake-up action wact performed by the user U on his portable authentication device 1, 10.
[0312] When the portable authentication device 1, 10 is a connected mobile terminal 1, the wake-up action wact corresponds to the at least one validation action ulock, opt, inc.
[0313] In an alternative embodiment of the invention, the at least one wake-up action wact corresponds to an unlocking ulock of the connected mobile terminal 1.
[0314] In addition to the wake-up action wact, the secure access control method 100 may be designed so that the user U must also perform at least one validation action ulock, opt, inc for the implementation of the secure telemetry step SR.
[0315] A third example of implementation of the secure access control method 100 is illustrated in Figure 12, for which the user must perform a wake-up action wact and a validation action ulock, opt, inc. In this embodiment, at the start of the secure access control method 100, the user U interacts with the secure access control reader RI (by touching it, or by approaching it...) in order to trigger the wake-up step WP-R of the secure access control reader RI.
[0316] Following the WP-R wake-up step of the secure access control reader RI, the user U carries out the wact wake-up action corresponding here to an ulock unlocking of the connected mobile terminal 1, following which the WP-T wake-up step of the connected mobile terminal 1 occurs.
[0317] In the case where the wake-up action consists of ulock unlocking the connected mobile terminal 1, then the at least one validation action ulock, opt, inc is chosen from a launch operation opt in the launch mobile application l-app and the tilt inc of the connected mobile terminal 1. With reference to the embodiment of Figure 12, the validation action ulock, opt, inc corresponds to the launch operation opt carried out from the launch mobile application l-app, which is launched automatically or not following the ulock unlocking of the connected mobile terminal 1.
[0318] Similar to the embodiment presented in Figure 2, it is considered for this third illustrated embodiment that the secure access control reader RI initiates the secure telemetry step SR, and has network access to transmit the user identification data udata to the access center 2 (by direct or step-by-step communication) so that it implements the access control step CS.
[0319] Thus, following the completion of the launch operation opt, the connected mobile terminal 1 transmits during the transmission step E2 to the secure access control reader RI the start signal ack for the initiation of the secure telemetry step SR.
[0320] It is considered that the steps taking place during the secure telemetry step SR are the same as in the embodiment shown in Figure 2. Therefore, they are not shown in Figure 12.
[0321] The various embodiments of the secure access control method 100 so far can be implemented for any secure access control reader RI, R2 included in a building.
[0322] However, when the secure access control readers have network access and can communicate with the access center 2, once the user U has authenticated himself for the first time with a secure access control reader as previously described, his authentication after another secure access control reader can be accelerated by means of an access witness coo (or "cookie" in English).
[0323] With reference to Figure 12 and Figure 13, it is considered that the user U, after having authenticated himself with the secure access control reader RI and having accessed the secure space SI, also wishes to access the other secure space R2 protected by the other access control bay D2, which is associated with the other secure access control reader R2; and that the authentication with the other secure space R2 is done by means of the access cookie coo.
[0324] This access cookie coo is generated during a generation step EG taking place following the access control step CS in the case where the access center 2 has authorized a first access to the user U (in the example illustrated, to the secure space SI). In a first embodiment variant, the access cookie coo is generated by the connected mobile terminal 1 by means of a dedicated application previously loaded inside; the generation may for example follow the reception of data relating to an agreement to generate an access cookie coo from the access center 2. Once the access cookie coo has been generated, it is stored in the connected mobile terminal 1 following a storage step Esto.
[0325] In a second embodiment, and as illustrated in Figure 12, the generation step EG is implemented by the access center 2. Then, it transmits during a transmission step E5 the access indicator coo to the secure access control reader RI which corresponds to the access control reader having participated in the secure telemetry step SR (the transmission being done by direct communication or by a step-by-step communication). Following the reception of the access indicator coo during a reception step E5', the secure access control reader RI transmits during a transmission step E6 the access indicator to the connected mobile terminal 1, which, following a reception step E6' of said access indicator coo, proceeds to the storage step Esto.
[0326] When the user is near the other secure access control reader R2, an access control phase CP begins. During this phase, the user U makes an access request using his connected mobile terminal 1, which is detected by said connected mobile terminal 1 during a detection step ADD.
[0327] In an alternative embodiment, the access request may correspond to the at least one ulock, opt, inc. validation action.
[0328] In another alternative embodiment, with reference to Figure 14, the access request may correspond to a contact from the user U on his connected mobile terminal 1, such as a tap; the contact being detected by a sensor included in the connected mobile terminal 1 (such as for example a mechanical sensor, a capacitive sensor, an inductive sensor, an accelerometer or an inertial unit).
[0329] Following the ADD detection step, the connected mobile terminal 1 transmits during a transmission step E7 the access indicator coo to the other secure access control reader R2.
[0330] Once the access indicator coo has been received during a reception step E7', the other secure access control reader R2 transmits the access indicator coo to the access center 2 during a transmission step E8 (by direct communication or step-by-step communication). Following the reception of the access indicator coo during a reception step E8', the access center implements an access control step CS2 during which it verifies the access indicator coo and then authorizes access to the other secure space S2 to the user U, thereby unlocking the locking / unlocking system of the other access control bay D2.
[0331] Advantageously, the access center 2 authorized access to the other secure space S2 by simply verifying the coo access cookie, therefore without having to carry out a new check of the user's identification data udata.
[0332] In one embodiment of the invention, the access cookie coo is generated based on the user's identification data. Indeed, another user U may have the right to access the secure space SI, but not the other secure space S2. In other words, the access cookie only allows the user U to facilitate his authentication to access the secure spaces for which he has the accreditations.
[0333] In one embodiment of the invention, the access witness coo has a limited validity period. In other words, once the validity period has expired, the access witness coo expires. If this is the case, the authentication of the user U with the access center 2 to access a secure space then consists of re-implementing at least the wake-up step WP-R of a secure access control reader, the secure telemetry step SR, and access control step CS (with control by the access center 2 of at least the user identification data udata).
Claims
CLAIMS 1. Secure access control method (100) for controlling and authorizing access by a user (U) to at least one secure space accessible (SI, S2) by at least one access control bay (DI, D2) equipped with a locking / unlocking system, the secure access control method (100) involving several pieces of equipment (1, 10, RI, R2, 2) including: - a portable authentication device (1, 10) carried by the user (U) and containing user identification data (udata), said portable authentication device (1, 10) comprising at least one Ultra Wide Band transceiver (Ul, U10), - at least one secure access control reader (RI, R2) associated with at least one access control bay (DI, D2) and comprising at least one Ultra Wide Band transceiver (UR1, UR2), - an access center (2) which is at least in communication with the access control reader (RI, R2) and which is linked to the locking / unlocking system of the at least one access control bay (DI, D2); in which the secure access control method (100) comprises at least: - a step of waking up (WP-R) of the secure access control reader (RI, R2) initiated by a detection by at least one sensor (sensRl, sensR2) of an approach or contact of the user (U) or of the portable authentication device (1, 10) with said secure access control reader (RI, R2), and followed by a waking up of the Ultra Wide Band transceiver (UR1, UR2) of said secure access control reader (RI, R2) to be able to transmit and receive in an Ultra Wide Band communication mode; - a secure telemetry step (SR) between the secure access control reader (RI, R2) and the portable authentication device (1, 10), during which their Ultra Wide Band transceivers (Ul, U10, UR1, UR2) exchange in the Ultra Wide Band communication mode at least security data (sdatal, sdata2), and at the end of which a certified distance (sdist) is established and then verified between the secure access control reader (RI, R2) and the portable authentication device (1, 10); - an access control step (CS) during which the access center (2), after receiving the user's identification data (udata), checks these to authorize or not access to the secure space (SI, S2) accessible by the control bay access (DI, D2) and, where applicable, controls the locking / unlocking system of said access control bay (DI, D2).
2. Secure access control method (100) according to claim 1, in which the access center (2) receives the user identification data (udata) on the condition that previously, during the secure telemetry step (SR), it has been verified that the certified distance (sdist) is less than or equal to an authorization distance (dauth).
3. Secure access control method (100) according to claim 1 or 2, comprising, prior to the secure telemetry step (SR), a step of waking up (WP-T) the portable authentication device (1, 10) in which the Ultra Wide Band transceiver (Ul, U10) of said portable authentication device (1, 10) is woken up to be able to transmit and receive in the Ultra Wide Band communication mode.
4. Secure access control method (100) according to claim 3, wherein, after the wake-up step (WP-R) of the secure access control reader (RI, R2), the secure access control reader (RI, R2) transmits a wake-up signal (ws) in the Ultra Wide Band communication mode which is received by the Ultra Wide Band transceiver (Ul, U10) of the portable authentication device (1, 10), causing the wake-up step (WP-T) of the portable authentication device (1, 10).
5. Secure access control method (100) according to claim 3, wherein, prior to the secure telemetry step (SR), a wake-up action (wact) is performed by the user (U) on the portable authentication device (1, 10) in order to trigger the wake-up step (WP-T) of the portable authentication device (1, 10).
6. Secure access control method (100) according to any one of claims 3 to 5, wherein the portable authentication device (1, 10) initiates the secure telemetry step (SR) following the wake-up step (WP-T) of said portable authentication device (1, 10).
7. Secure access control method (100) according to any one of claims 3 to 5, wherein the secure access control reader (RI, R2) initiates the secure telemetry step (SR) after having received, in the Ultra Wide Band communication mode, a start signal (ack) from the device portable authentication device (1, 10), said start signal (ack) being emitted by the portable authentication device (1, 10) following the step of waking up said portable authentication device (1, 10).
8. Secure access control method (100) according to any one of claims 1 to 7, wherein, during the secure telemetry step (SR), the certified distance (sdist): - is established by being calculated by at least one of the portable authentication device (1, 10) and the secure access control reader (RI, R2), then - verified either by the portable authentication device (1, 10) or by the secure access control reader (RI, R2).
9. Secure access control method (100) according to any one of claims 1 to 8, in which the access center (2) receives the user identification data (udata), from: - either the secure access control reader (RI, R2), which secure access control reader (RI, R2) has network access to communicate with the access center (2), via direct communication or via step-by-step communication; - either the portable authentication device (1, 10), which portable authentication device (1, 10) has network access and contains a connection address (add-c) for connecting remotely to the access center (2) and communicating with it.
10. Secure access control method (100) according to claim 9, wherein, when the access center (2) receives the user identification data (udata) from the secure access control reader (RI, R2), the secure access control method (100) also comprises, prior to the access control step (CS), a transmission step during which the portable authentication device (1, 10) transmits, in the Ultra Wideband communication mode, the user identification data (udata) to the secure access control reader (RI, R2); said transmission step being implemented: - following the wake-up step (WP-R) of the secure access control reader (RI, R2) and before the start of the secure telemetry step (SR), or - during the secure telemetry (SR) stage, or - once the secure telemetry (SR) stage is completed.
11. Secure access control method (100) according to any one of claims 1 to 10, wherein, during the waking step (WP-R) of the secure access control reader (RI, R2), the detection of the approach or contact consists of a detection of the contact of the user (U) by the at least one sensor (sensRl, sensR2) arranged on a part of the secure access control reader (RI, R2).
12. Secure access control method (100) according to claim 11, wherein the at least one sensor (sensR1, sensR2) is chosen from a key, a mechanical sensor, a capacitive sensor, and an inductive sensor.
13. Secure access control method (100) according to any one of claims 1 to 10, wherein, during the step of waking up (WP-R) of the secure access control reader (RI, R2), the detection of the approach or contact consists of a detection by the at least one sensor (sensRl, sensR2) of the approach of the user (U) or of the portable authentication device (1, 10) with a part of the secure access control reader (RI, R2) within a given activation distance (d-act) relative to the secure access control reader (RI, R2).
14. Secure access control method (100) according to claim 13, wherein the at least one sensor (sensR1, sensR2) is chosen from a capacitive sensor, an inductive sensor, a radar sensor, an ultrasonic sensor, an optical sensor, a vibration sensor.
15. Secure access control method (100) according to claim 13 or 14, wherein the at least one sensor (sensR1, sensR2) is mounted on the secure access control reader (RI, R2), or is remote from the secure access control reader (RI, R2) and connected to the secure access control reader (RI, R2).
16. Secure access control method (100) according to any one of claims 1 to 15, wherein the portable authentication device (1, 10) is a card (10) or a physical access badge equipped with its Ultra Wide Band transceiver (U10).
17. Secure access control method (100) according to any one of claims 1 to 15, wherein the portable authentication device (1, 10) is a connected mobile terminal (1), such as for example a mobile telephone, a touch tablet or a connected watch.
18. Secure access control method (100) according to claim 17, wherein the connected mobile terminal (1) participates in the secure telemetry step (SR) with the secure access control reader (RI, R2) if the user (U) has previously carried out at least one validation action (ulock, opt, inc) on the connected mobile terminal (1), otherwise the secure telemetry step (SR) is not carried out.
19. Secure access control method (100) according to claims 6 and 18, wherein the at least one validation action (ulock, opt, inc) comprises at least the wake-up action (wact) which triggers the wake-up step (WP-T) of the connected mobile terminal (1).
20. Secure access control method (100) according to claims 7 and 18, in which the connected mobile terminal (1) transmits the start signal (ack) to the secure access control reader (RI, R2) following the performance of at least one validation action (ulock, opt, inc).
21. Secure access control method (100) according to any one of claims 18 to 20, wherein the at least one validation action (ulock, opt, inc) comprises at least one unlocking (ulock) of the connected mobile terminal (1), causing said connected mobile terminal (1) to switch from a locked state to an unlocked state.
22. Secure access control method (100) according to claim 21, wherein the unlocking (ulock) of the connected mobile terminal (1) is implemented by the user (U) according to at least one of the following operations: - switching on a touch screen that the connected mobile terminal (1) includes by the user (U) pressing on it, or on a switch-on button that the connected mobile terminal (1) also includes; - an operation of entering an unlocking code on the connected mobile terminal (1); - a touch input operation of an unlocking pattern on a touch screen of the connected mobile terminal (1); - an operation of recognizing a fingerprint on a fingerprint sensor of the connected mobile terminal (1); - a facial recognition operation of the user (U) by means of a camera integrated into the connected mobile terminal (1).
23. Secure access control method (100) according to any one of claims 18 to 22, wherein the at least one validation action (ulock, opt, inc) includes at least one launch operation (opt) performed in a launch menu displayed by a launch mobile application (l-app), loaded into the connected mobile terminal (1).
24. Secure access control method (100) according to claims 21 and 23, wherein the at least one validation action (ulock, opt, inc) consists of unlocking (ulock) the connected mobile terminal (1), followed by the launch operation (opt).
25. Secure access control method (100) according to claim 23 or 24, wherein the launch operation (opt) consists of at least one of the following operations: - an operation of entering a launch code on the launch menu; - a touch input operation of a launch pattern on the launch menu; - a validation operation on the launch menu.
26. Secure access control method (100) according to claims 21 and 23, wherein the launcher mobile application (l-app) opens automatically and displays the launcher menu following unlocking (ulock) of the connected mobile terminal (1).
27. Secure access control method (100) according to any one of claims 18 to 26, wherein the at least one validation action (ulock, opt, inc) comprises at least one inclination (inc) of the connected mobile terminal (1) according to an inclination angle (tetal, teta2) included in a predefined launch angular interval.
28. A secure access control method (100) according to claims 23 and T1, wherein the launcher mobile application (l-app) opens and displays the launcher menu under the condition that the tilt angle (tetal, teta2) is within the predefined launcher angular range.
29. Secure access control method (100) according to claim T1 or 28, wherein the inclination angle (tetal) is measured by means of an inertial unit integrated into the connected mobile terminal (1).
30. Secure access control method (100) according to claim T1 or 28, wherein the tilt angle (teta2) is measured by the control reader secure access (RI, R2), from reception signals of an Ultra Wide Band wave coming from the connected mobile terminal (1).
31. Secure access control method (100) according to any one of claims 17 to 30, wherein the at least one secure space (SI, S2) comprises at least one other secure space (S2) accessible by at least one other access control bay (D2) equipped with another locking / unlocking system and associated with another secure access control reader (R2) comprising an Ultra Wide Band transceiver (UR2), wherein the secure access control method (100) comprises a step of generating (EG) an access indicator (coo) followed by a step of storing (Esto) said access indicator (coo) in the connected mobile terminal (1), the generation step (EG) and the storage step (Esto) being implemented when access to the secure space (SI) is authorized by the access center (2),and in which secure access control method (100) an access control phase (CP) is implemented to access the other secure space (S2) which comprises the following steps:, - a detection step (ADD) of an access request made by the user (U) on the connected mobile terminal (1); - a transmission step (E7) during which the connected mobile terminal (1) transmits, in the Ultra Wide Band communication mode, the access indicator (coo) to the other secure access control reader (R2) in response to the detection of the access request; - a reception step (E7') during which the Ultra Wide Band transceiver (UR2) of the other secure access control reader (R2) receives the access indicator (coo); - a transmission step (E8) during which the other secure access control reader (R2) transmits said access indicator (coo) to the access center; - an access control step (CS2) during which the access center (2), after receiving the access indicator (coo), authorizes access to the other secure space (S2) accessible by the other access control bay (D2) and, where appropriate, controls the other locking / unlocking system of said other access control bay (D2), without receiving or verifying the user identification data (udata) by said access center (2).
32. Secure access control method (100) according to claim 31, wherein the access witness (coo) has a limited validity period.
33. Secure access control method (100) according to any one of claims 2 to 32, wherein the authorization distance (dauth) is less than or equal to 1 m.