Secure access control method for authorizing access to a secure space by locating a connected mobile terminal by means of ultra wide band geolocation beacons

EP4744033A1Pending Publication Date: 2026-05-20SYSTEMES ET TECHNOLOGIES IDENTIFICATION (STID)
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
EP · EP
Patent Type
Applications
Current Assignee / Owner
SYSTEMES ET TECHNOLOGIES IDENTIFICATION (STID)
Filing Date
2024-07-04
Publication Date
2026-05-20

AI Technical Summary

Technical Problem

Current secure access control methods using Ultra Wide Band technology for geolocation-based access control face issues such as unauthorized access due to uncontrolled initiation of secure telemetry steps, high installation costs, and energy inefficiency, particularly when access control readers remain active without detecting a mobile phone or when users do not intend to access secure spaces.

Method used

A secure access control method where a connected mobile terminal initiates secure telemetry steps with nearby geolocation beacons, determining beacon data packets that include identifiers and certified distances, allowing the mobile terminal to geolocate and identify the closest access control bay, thereby reducing the need for geolocation beacons near access control bays and enabling their shared use across multiple spaces, and optimizing energy consumption by only activating communication when access is intended.

Benefits of technology

This method enhances security by ensuring authorized access, reduces installation and maintenance costs by allowing geolocation beacons to be freely positioned, and conserves energy by minimizing unnecessary communication and activation of access control devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure FR2024050907_16012025_PF_FP_ABST
    Figure FR2024050907_16012025_PF_FP_ABST
Patent Text Reader

Abstract

The invention relates to a secure access control method (100) in the ultra wide band mode for controlling and authorizing access by a user to a secure space. The method is based in particular on a geolocation phase (GeoP) during which: the position of a user's connected mobile terminal (1) in the environment where the user is located is determined, and from among several access control bays protecting several secure spaces accessible from said environment, a target bay is identified which corresponds to the access control bay that is physically closest to the connected mobile terminal. It is then verified whether or not the user is authorized to access the secure space protected by the target bay. The geolocation phase is based on processing data from secure telemetry steps (SR1, SR2) between the connected mobile terminal and geolocation beacons (B1, B2) installed in the environment.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] DESCRIPTION

[0002] TITLE: Secure access control method for authorizing access to a secure area by locating a mobile terminal connected by means of geolocation beacons operating in Ultra Wide Band

[0003] [Technical field]

[0004] The invention relates to a secure access control method for authorizing or not authorizing access to a user to a secure space.

[0005] It relates more particularly to a secure access control method based on the Ultra Wide Band radio frequency communication mode.

[0006] The invention finds a preferred application in the implementation of a secure access control method involving an access center, geolocation beacons to which a user connects by means of a connected mobile terminal; the geolocation beacons and the connected mobile terminal all operating in the Ultra Wide Band radio frequency communication mode and exchanging secure data for user authentication in this same communication mode.

[0007] [State of the art]

[0008] As is known in the field of access control, to authorize or not a user to access a secure space accessible by an access control bay (door, airlock, barrier, etc.) equipped with a locking / unlocking system, there are access control solutions for which the user can identify / authenticate himself at an access center, via a secure radiofrequency access control reader and by means of his mobile phone; the secure radiofrequency access control reader being associated with the access control bay. Once the user has approached the secure access control reader so that it detects the mobile phone, a so-called mutual authentication step begins during which the secure access control reader and the mobile phone exchange data, according to a secure communication protocol, in order to authenticate the user.This data may, for example, include virtual identification keys, a user ID, etc. The data is transmitted by the secure access control reader to an access control center installed in the building and connected to the locking / unlocking system of the access control bay. Following receipt of the data, the access control center verifies it during an access control phase. Depending on the result of this verification, the access control center authorizes or denies access to the secure area by controlling the locking / unlocking system of the access control bay.

[0009] Some of the available solutions, for example, offer the secure access control reader and the mobile phone to exchange data using Bluetooth® or Bluetooth® Low Energy (BLE) wireless transmission technologies.

[0010] Ultra Wide Band (UWB) is a radio frequency modulation technique that is becoming increasingly widespread and is based on the transmission of pulses generally less than a nanosecond and used in a wide frequency band, between 3.1 GHz and 10.6 GHz. Among the advantages of Ultra Wide Band communication: a very high network data transfer rate over a wide bandwidth (greater than 500 MHz) over relatively short distances and at low power. By abuse of language, radio frequency systems using this modulation technique to exchange data are said to communicate in an Ultra Wide Band communication mode.

[0011] Ultra Wideband technology is promising and is now being considered in the design of geolocation, tracking, pairing (point-to-point data transfer), payment, and access control solutions.

[0012] Indeed, some mobile phone models available on the market integrate Ultra Wide Band modules allowing them to communicate and exchange information in Ultra Wide Band. This is why secure access control readers are designed integrating Ultra Wide Band modules so that access control solutions can be implemented whose operating principle is similar to that described above, for which the secure exchange takes place in the Ultra Wide Band communication mode.

[0013] Conventionally, when access to a secure area through an access door needs to be controlled, the access control reader is mounted on the wall near the access door. However, this type of installation requires the installation of cables and other infrastructure to connect the secure access control reader to the access door, and therefore presents a significant financial cost. Furthermore, any work to be carried out on the access door (such as repair or replacement of the existing access door with a new one) requires dismantling all or part of the entire infrastructure formed by the access door and the secure access control reader; dismantling requires at least unwiring the secure access control reader from the door. Finally, the secure access control reader can be subject to vandalism.

[0014] To address this issue, it is known from the literature that one of the secure access control methods provided for building interiors consists of locating a user's mobile phone in a first space in order to determine whether or not this user is approaching an access control bay among several access control bays giving access to a secure space from this first space.Indoor positioning is implemented by means of several access control readers located in the first space such that when the wearer's mobile phone is within communication range of at least one of the access control readers, the latter initiates, in the Ultra Wide Band communication mode, a step called secure ranging, with the mobile phone in order to exchange data in a secure communication channel, and to determine a distance between the mobile phone and itself, which it communicates to the access control center.Depending on the distances returned by this access control reader, the access control center then checks from the data whether or not the user is authorized to access the secure area protected by the access control bay associated with this access control reader, to control the corresponding locking / unlocking system. Secure telemetry, operated within the framework of an Ultra Wide Band exchange, reinforces the security of exchanges during point-to-point data transfers, by drastically limiting the risks of interception of the data transfer between a transmitter and a receiver, i.e. "man in the middle" attacks.

[0015] Detailed explanations of the operating principle of secure ranging are given by N.O. Tippenhauer and S. Capkun in the technical report “UWB-based secure ranging and localization” published in 2012 (Technical Report / ETH Zurich, Department of Computer Science 586); and in the article “UWB with Pulse Reordering: Secure Ranging against Relay and Physical-Layer Attacks” written by M. Singh, P. Leu, and S. Capkun and published in 2017 by the I'IACR (International Association for Cryptologic Research - Network and Distributed Systems Security (NDSS) Symposium 2019, 24-27 February 2019, San Diego, CA, USA - ISBN 1-891562-55-X).

[0016] Document W02022090159 proposes a secure access control method based on such a principle for Ultra Wide Band technology, i.e. with the access control readers and the wearer's mobile phone communicating in Ultra Wide Band communication mode.

[0017] However, this secure access control method presents a significant security flaw because, as indicated, the secure telemetry steps (and consequently the location of the mobile phone and the access control phase) are initiated by the access control readers when they detect the carrier's mobile phone; this is regardless of whether the carrier intends to access a secure area from the first area or not. Indeed, the user may only be moving around / moving within the first area. If the user has the appropriate authorizations, the access control center can unlock the access control bay to which he is closest. Consequently, by opening the access control bay closest to the user when he does not intend to access the secure area protected by the latter, the access control center potentially allows an unauthorized person to access said secure area.

[0018] Also, implementing such a secure access control method can lead to high installation costs. In particular, the secure access control method limits the deployment of low-cost access control readers that may have limited switching and data processing capabilities, since the access control readers must at least detect the bearer's mobile phone and communicate with it, initiate and ensure the proper execution of the secure telemetry steps (in particular by calculating the distance separating them from the mobile phone), and communicate with the access control center.

[0019] This is why solutions based on such a secure access control method, including that presented in W02022090159, use secure access control readers which can be expensive depending on the technologies they integrate; even if such secure access control readers are shared with several access control bays.

[0020] Furthermore, in solutions implementing this access control method in Ultra Wideband technology, the secure access control readers remain constantly activated in the Ultra Wideband communication mode in order to detect the mobile phone and carry out the secure telemetry step in this communication mode. In fact, the secure access control readers consume energy unnecessarily if they do not detect any mobile phone, or if they detect a user's mobile phone and start communicating with him when said user has no intention of entering a secure space to which they control access, or does not have the necessary accreditations. In addition, the typical current consumption in the context of Ultra Wideband communication during signal transmission or reception can vary from a few tens to more than a hundred milliamps.Thus, the Ultra Wideband communication mode is energy-intensive and can be problematic in the case where a deployed secure access control reader is powered by a battery, because there is a risk that the battery will discharge after a period of activity of the secure access control reader, especially if it consumes energy just to detect mobile phones without any being present or requesting access.

[0021] [Summary of the invention]

[0022] The invention aims to address the issues raised by proposing a secure access control method for controlling and authorizing a user to access secure spaces accessible via access control bays each equipped with a locking / unlocking system, the secure access control method involving several pieces of equipment including:

[0023] - a connected mobile terminal carried by the user and containing at least user identification data, said connected mobile terminal comprising at least one Ultra Wide Band transceiver,

[0024] - geolocation beacons each comprising at least one Ultra Wide Band transceiver,

[0025] - an access center which is connected to the locking / unlocking systems of the several access control bays, and in communication at least with the connected mobile terminal; the secure access control method implementing at least the following steps:

[0026] - a scanning phase in which the connected mobile terminal initiates secure telemetry steps with several geolocation beacons, called near geolocation beacons, among the geolocation beacons, said near geolocation beacons having their respective Ultra Wide Band transceivers within a communication range of the Ultra Wide Band transceiver of said connected mobile terminal, said secure telemetry steps operating in respective Ultra Wide Band communication channels and at the end of which beacon data packets associated with each of the near geolocation beacons are determined and stored in the connected mobile terminal, where each of the beacon data packets comprises at least one identifier of the associated near geolocation beacon, transmitted by said near geolocation beacon to the connected mobile terminal,and a certified distance between the connected mobile terminal and said associated nearby geolocation beacon;,

[0027] - a geolocation phase in which the connected mobile terminal is geolocated in a plan from said beacon data packets, which plan identifies at least some of the access control bays and at least the nearby geolocation beacons among the geolocation beacons, and at the end of which a position of the connected mobile terminal is determined in the plan and an access control bay, called the target bay, is identified, which is the closest to the connected mobile terminal among the access control bays present in said plan;

[0028] - an access control phase implemented by the access center, which verifies at least the user identification data sent from the connected mobile terminal to the access center, to authorize or not access to the secure space accessible by the target bay and, where appropriate, control the locking / unlocking system of said target bay.

[0029] As indicated above, advantageously, the scanning phase is initiated and managed by the connected mobile terminal; that is to say that the connected mobile terminal, which is here the master, initiates the secure telemetry steps with the nearby geolocation beacons, which are the slaves, as soon as its Ultra Wide Band transceiver is within communication range of the nearby geolocation beacons among the geolocation beacons which can be installed in the space, such as a building, in which the user is moving.

[0030] At the end of the secure telemetry steps carried out by the connected mobile terminal with each of the nearby geolocation beacons in the Ultra Wideband communication mode, and during which data are exchanged, beacon data packets relating to each of the nearby geolocation beacons are determined and stored in the connected mobile terminal. Each of the beacon data packets comprises at least one identifier of a nearby geolocation beacon, transmitted by said nearby geolocation beacon to the connected mobile terminal, and a certified distance between the nearby geolocation beacon and the connected mobile terminal.

[0031] Following the scanning phase, the geolocation phase is implemented during which the beacon data packets are linked to a map identifying at least some of the access control bays and at least the geolocation beacons close to them among the geolocation beacons. At least some of the access control bays and the geolocation beacons are identified in this map at least by means of an identifier specific to them. The exploitation and analysis of the map and the beacon data packets make it possible to determine the position of the connected mobile terminal and of an access control bay to which it is physically closest, designated as the target bay.

[0032] In one embodiment of the invention, three-dimensional Cartesian coordinates are associated with each of the access control bays and geolocation beacons contained in the plan. From the plan and the beacon data packets comprising the identifiers of the nearby geolocation beacons and the distances separating them from the connected mobile terminal, it becomes possible to determine the three-dimensional Cartesian coordinates of the connected mobile terminal, and then to identify the target bay.

[0033] Since the location of the connected mobile terminal in a space and the identification of the target bay allowing access to a secure space are based on the use of a map and the analysis of beacon data packets, geolocation beacons do not need to be installed near the access control bays. In addition, a single geolocation beacon can be used for access control to several secure spaces accessible from the space where the user is located. In other words, a single geolocation beacon can be associated with or shared with several access control bays. Such a solution therefore makes it possible to reduce the installation costs and the dismantling costs of geolocation beacons. In addition, since they are not physically connected to the access control bays, the geolocation beacons can be placed freely in the space.They can therefore be positioned high up near the ceiling, or hung from the ceiling, to significantly limit acts of vandalism against them.

[0034] The access control process ends following the completion of the access control phase, implemented by the access center.

[0035] The access control unit is designed to be remote, i.e. physically distant, from the geolocation beacons. In other words, the geolocation beacons are not contained in the access control unit, or the geolocation beacons and the access control unit are not contained in the same radiofrequency equipment intended for access control.

[0036] According to different embodiments of the invention, the locking / unlocking system of each of the access control bays, which may for example correspond to a latch that opens and closes, may in one embodiment either be physically connected by a cable to the access center, or in another embodiment be connected to the access center via a wireless link. According to a characteristic of the invention, during each of the secure telemetry steps carried out between the connected mobile terminal and a nearby geolocation beacon among the nearby geolocation beacons, the certified distance between the connected mobile terminal and said nearby geolocation beacon is calculated by at least one of the connected mobile terminal and said nearby geolocation beacon.

[0037] More precisely, during the secure telemetry step, a distance is calculated between the portable connected mobile terminal and the nearby geolocation beacon by at least one of these two devices, said distance being by nature certified, hence the notion of certified distance.

[0038] The distance is certified by nature because it occurs during the secure telemetry step, and because it is based on at least one bidirectional exchange of Ultra Wide Band signals between two devices (the connected mobile terminal and the nearby geolocation beacon) each having: an embedded secure component; or trusted firmware or application previously loaded inside, or a trusted execution environment (or "Trusted Execution Environment" TEE in English).

[0039] Certified distance is an additional means of strengthening the security level of the secure access protocol when the latter must be controlled for implementation or not by the subsequent access control step. Indeed, an uncertified distance could possibly be fraudulent and come from a malicious system that seeks to gain access to the secure space protected by the access control bay. Thus, if the equipment responsible for controlling the certified distance, but not for its calculation, receives a certified distance, it implements its control. Conversely, if the received distance is not certified, the control is not carried out and the secure access control process is stopped.

[0040] In one embodiment of the invention, only one of the two devices among the connected mobile terminal and the nearby geolocation beacon calculates the certified distance separating the two devices.

[0041] In another embodiment of the invention, the connected mobile terminal and the nearby geolocation beacon both calculate the certified distance separating them. Both exchange the certified distance value that they have calculated. Each device then compares the certified distance that it has received with the certified distance that it has itself calculated. In the case where the consistency between the certified distances is not verified, the telemetry step is stopped. In the case where the consistency is verified, the secure access control method continues. In one embodiment of the invention, the certified distance is calculated from a measurement of a flight time, carried out by at least one of the two devices among the connected mobile terminal and the nearby geolocation beacon, during a bidirectional exchange of security data.

[0042] Optionally, the secure telemetry step is not limited to the exchanges described. Further information on secure telemetry is available in the two references indicated in the State of the art.

[0043] According to one embodiment of the invention, the access center contains the plan, and implements the geolocation phase after having received at least the user identification data and the beacon data packets from the connected mobile terminal.

[0044] In a first embodiment, the geolocation phase is carried out by the access center. Advantageously, the computing power required to carry out all the processing of the geolocation phase is transferred from the geolocation beacons to the access center. Thus, the geolocation beacons used in the context of implementing the secure access control method can correspond just as well to Ultra Wide Band secure access control readers, as to lower-cost solutions such as active tags operating in Ultra Wide Band and designed to implement the secure telemetry steps together with the connected mobile terminal. The secure access control method of the invention therefore positively addresses the previously mentioned installation cost issue.

[0045] As indicated above, the beacon data packets include, in particular, a distance between the connected mobile terminal and a nearby geolocation beacon that is certified. The purpose of certifying this distance is to provide proof to the access center that it is secure data originating from a trusted system. This is advantageously a security measure for implementing the geolocation phase. Indeed, an uncertified distance could possibly be fraudulent and originate from a malicious system seeking to gain access to secure areas. In other words, if the distances contained in the beacon data packets are certified, the access center implements the geolocation phase. If a distance in a beacon data packet is not certified, the access center does not implement the geolocation phase.

[0046] As the access center implements the geolocation phase and then consecutively the access control phase, it constitutes the central system of the access control method insofar as it successively carries out the geolocation phase and the access control phase. It therefore concentrates / centralizes a major part of the intelligence / computing power necessary for the implementation of all the phases included in the secure access control method. Consequently, and advantageously, this first embodiment makes it possible to reduce / limit the processing carried out by the connected mobile terminal and the nearby geolocation beacons during the scanning phase (in other words, a reduction in “edge computing”).

[0047] In order for the access center to be able to successively implement the geolocation and access control phases, the access control method comprises an intermediate step which takes place between the scanning phase and the geolocation phase, and during which the access center receives from the connected mobile terminal at least the user identification data and the beacon data packets.

[0048] According to a characteristic of the invention, the access center receives at least the user identification data and the beacon data packets from the connected mobile terminal:

[0049] - either directly from the connected mobile terminal, which connected mobile terminal has network access and contains a connection address to connect remotely to the access center and communicate with it;

[0050] - either indirectly through one or more geolocation beacons among the geolocation beacons, which geolocation beacons have network access to communicate with the access center, via direct communication or via step-by-step communication.

[0051] In other words, in a given application context, if it has network access and a connection address to connect to the access center, the connected mobile terminal can connect directly to it to transmit at least the user identification data and the beacon data packets.

[0052] In another application context, the geolocation beacons have network access, and the connected mobile terminal transmits at least the user identification data and the beacon data packets to the access center via at least one of the nearby geolocation beacons with which it is in communication. This transmission can be implemented for example because the connected mobile terminal does not have network access, nor does it have a connection address to the access center.

[0053] In another embodiment associated with wireless links, a mesh network is set up between all the geolocation beacons capable of communicating, according to a close-to-close communication protocol, with the geolocation beacons that are close neighbors and / or the access center if they are within communication range. Advantageously, the mesh network addresses the problem of installing groups of geolocation beacons in several spaces of the same building such that certain geolocation beacons cannot communicate directly with the access center.It also addresses the problem of indoor network coverage, when the structure of the building and the materials used for its construction interfere with signal transmission, preventing two systems present in the building but within communication range from exchanging data (for example, two systems in the basement, or located on different floors of the building, or separated by a thick wall, etc.).

[0054] Without limitation, geolocation beacons communicate with each other and with the access center by being physically connected to each other (for example, using Ethernet links), or using a wireless communication protocol such as Wifi® or Bluetooth Mesh®.

[0055] According to another embodiment of the invention, the connected mobile terminal contains the plan, and implements the geolocation phase once the beacon data packets of the nearby geolocation beacons are stored in the connected mobile terminal; and at the end of which at least one certified identifier of the target bay is then transmitted to the access center with the user's identification data.

[0056] In this second embodiment of the invention, the geolocation phase is carried out by the connected mobile terminal which contains the plan. The intelligence / computing power is therefore decentralized here from the access center to the connected mobile terminal which then intervenes in the scanning phase and also in the geolocation phase. Advantageously, compared to the first embodiment, the access center can have less computing power because it is only used in the context of implementing the access control phase by controlling and verifying whether the information from the connected mobile terminal is valid to authorize the user to access the secure space. It also does not have to contain the plan. In fact, its development is simplified.

[0057] In this second embodiment, the secure access control method comprises, between the geolocation phase and the access control phase, an intermediate step during which the access center receives from the connected mobile terminal at least the user identification data as well as an identifier of the target bay determined by the connected mobile terminal during the geolocation phase.

[0058] Advantageously, this target bay identifier is also certified. Thus, the access center does not implement the access control phase if the target bay identifier it receives is not certified, strengthening / increasing the degree of security of the secure access control process.

[0059] According to one embodiment of the invention, the plan loaded into the connected mobile terminal identifies all access control bays and all geolocation beacons.

[0060] According to one embodiment of the invention, the plan loaded into the connected mobile terminal is a local plan locating a portion of the access control bays and the nearby geolocation beacons, said local plan being constituted by the connected mobile terminal during a construction step from plan pieces communicated to the connected mobile terminal by each of the nearby geolocation beacons during the secure telemetry steps; the plan piece associated with each of the nearby geolocation beacons locating the nearby geolocation beacon concerned and at least one access control bay in the vicinity of said nearby geolocation beacon.

[0061] According to one embodiment of the invention, the connected mobile terminal determines its position, the target bay and the identifier of the target bay from the plan.

[0062] In other words, in an alternative embodiment of the invention, the plan is previously loaded into the connected mobile terminal, and identifies all of the access control bays and the geolocation beacons that can be installed, for example, in a building.

[0063] In another variant of the invention, the connected mobile terminal, at the start of the secure access control method, does not contain the plan. On the other hand, the geolocation beacons are designed and shaped to each contain a piece of plan, representative of a nearby environment. This piece of plan associated with each of the geolocation beacons identifies at least one access control bay in the vicinity of said geolocation beacon. In different embodiments, the piece of plan can also identify several access control bays in the vicinity of the geolocation beacon, and other geolocation beacons within communication range...

[0064] During the secure telemetry steps of the scanning phase, each of the nearby geolocation beacons transmits to the connected mobile terminal, in addition to its identifier, its piece of plan. The secure access control method comprises, between the scanning phase and the geolocation phase, a construction step during which the connected mobile terminal merges the pieces of plan that it has received to construct a more complete local plan identifying all the access control bays and geolocation beacons known from the pieces of plan associated with the nearby geolocation beacons.

[0065] According to one embodiment of the invention, the access center receives at least the user identification data, the position of the connected mobile terminal, and the certified identifier of the target bay directly from the connected mobile terminal, which connected mobile terminal:

[0066] - signs the target bay identifier to form the certified target bay identifier, and

[0067] - has network access and contains a connection address to remotely connect to the access center and communicate with it.

[0068] In other words, in one embodiment of the invention, the connected mobile terminal plays the central role in implementing the access control method by: initiating and intervening in the scanning phase; implementing the geolocation phase (and possibly the construction step); signing the identifier of the target bay to certify it; then transmitting to the access center all the information (the user identification data, the certified identifier of the target bay, the position of the connected mobile terminal) that it needs to carry out the access control phase.

[0069] According to one embodiment of the invention, the connection address (for a connection to the access center) corresponds to data previously loaded into the connected mobile terminal, or corresponds to data transmitted to the connected mobile terminal from one of the nearby geolocation beacons during one of the secure telemetry steps.

[0070] According to one embodiment of the invention, the connected mobile terminal transmits to a nearby geolocation beacon, called the first nearby geolocation beacon, among the nearby geolocation beacons at least the user identification data, the position of the connected mobile terminal and the identifier of the target bay, which first nearby geolocation beacon timestamps the identifier of the target bay to thus form the certified identifier of the target bay and the access center receives at least the user identification data and the certified identifier of the target bay indirectly through one or more geolocation beacons among the geolocation beacons, including at least the first nearby geolocation beacon; which geolocation beacons have network access to communicate with the access center, via direct communication or via near-near communication.

[0071] In one embodiment of the invention, the certification of the target bay identifier and the transmission of the information necessary to the access center for the implementation of the access control phase are managed by the geolocation beacons.

[0072] This solution is advantageous in the following situations:

[0073] - the connected mobile terminal may not have network access to connect to the access center or a connection address to connect to the access center;

[0074] - nearby geolocation beacons can communicate during the scanning phase with a malicious system whose aim is to transmit false data to the access center, thus allowing an unauthorized person to access a secure area.

[0075] Indeed, the signing of the target bay identifier and the transmission of information to the access center by the geolocation beacons significantly strengthens the security level of the secure access control process; especially since, by definition, the geolocation beacons are trusted systems since they are designed and conformed to be an integral part of an access control installation implementing secure access control processes.

[0076] Specifically, the first nearby geolocation beacon timestamps the target bay's ID once it receives it from the connected mobile terminal; the timestamp of the target bay's ID implicitly implies its signature / certification.

[0077] According to a characteristic of the invention, the secure access control method comprises a validation phase during which:

[0078] - the connected mobile terminal or one of the nearby geolocation beacons among the nearby geolocation beacons detects at least one access intention action carried out by the user;

[0079] - and then additional access intention information is generated by the connected mobile terminal or one of the nearby geolocation beacons among the nearby geolocation beacons after detection of at least one access intention action; and in which at least one of the geolocation phase and the scanning phase is implemented at least on the condition of prior completion of the validation phase. Thus, the implementation of this validation phase makes it possible to validate a concrete intention of the user to access a secure space.

[0080] When implementing the secure access control method, as described so far, the connected mobile terminal periodically initiates secure telemetry steps in the Ultra Wideband communication mode with geolocation beacons that are close to it. Therefore, the geolocation and access control phases are also implemented at regular intervals.

[0081] In one embodiment of the invention, the geolocation phase (and therefore the access control phase which follows) is implemented only on the condition that the validation phase is carried out beforehand.

[0082] Advantageously, the implementation of this validation phase, when it serves as a condition for the implementation of the geolocation phase, allows:

[0083] - to significantly reduce exchanges between the different actors (the connected mobile terminal, the geolocation beacons, the access center) of the secure access control process, which amounts to optimizing them;

[0084] - to strengthen the security of the secure access control process and the security of the exchange of data relating to the user, their connected mobile terminal, and the geolocation beacons which pass between the different actors of the access control process only on condition that the validation phase is carried out; thus reducing the risks of interception of this data by a malicious system;

[0085] - to place less strain on the access center with the implementation of a single access control phase (and a single geolocation phase if it is responsible for it).

[0086] As indicated, the validation phase consists of the detection, by the connected mobile terminal or by one of the nearby geolocation beacons among the nearby geolocation beacons, of at least one access intention action carried out by the user.

[0087] In one embodiment of the invention, the validation phase comprises the detection of a single access intent action.

[0088] In other embodiments of the invention, the validation phase comprises detecting multiple access intent actions.

[0089] According to one embodiment of the invention, the scanning phase is performed on the condition of the performance of at least one access intention action, so that the connected mobile terminal initiates the secure telemetry steps after generation or reception by the connected mobile terminal of the complementary access intention information. In other words, in one embodiment of the invention, the performance of the at least one access intention action detected during the validation phase serves as a condition for the implementation of the scanning phase. The connected mobile terminal therefore does not initiate the secure telemetry steps in Ultra Wide Band with the nearby geolocation beacons until the validation phase has been performed. More precisely, the connected mobile terminal implements the secure telemetry steps:

[0090] - after generating the additional access intention information after detecting the at least one access intention action; or

[0091] - after receiving the additional access intention information from the nearby geolocation beacon having detected at least one access intention action.

[0092] Advantageously, the connected mobile terminal and the nearby geolocation beacons consume less energy. Also, the connected mobile terminal and the nearby geolocation beacons do not communicate unnecessarily if the user of the connected mobile terminal does not wish to access a secure space from the space where he is located; the desire to access the space must be translated by the user's action of intention to access, at the origin of the validation phase.

[0093] Thus, this condition makes it possible to reduce the energy consumption of the connected mobile terminal and the geolocation beacons, with the implementation of the other phases that the method includes (scanning, geolocation, access control) while the user of the connected mobile terminal does not wish to access a secure space. Ultimately, the reduction in energy consumption allows the battery of the connected mobile terminal, and possibly those of the geolocation beacons if they integrate them.

[0094] According to one embodiment of the invention, the at least one access intention action comprises a first access intention action and a second access intention action such that:

[0095] - the scanning phase is implemented on the condition that the first action of access intention is previously carried out, and

[0096] - the geolocation phase is implemented on the condition that the second access intention action is carried out beforehand, and following the implementation of the scanning phase; the additional access intention information being generated by the mobile terminal or by one of the nearby geolocation beacons among the nearby geolocation beacons after detection of the first access intention action. In other words, in a particular embodiment of the invention, the validation phase comprises the detection of two access intention actions such as:

[0097] - the scanning phase is initiated by the connected mobile terminal following the detection of the first access intention action;

[0098] - the geolocation phase is initiated following the detection of the second access intention which is carried out by the user after the scanning phase.

[0099] Thus, temporally, in this particular embodiment, the validation phase takes place in two stages: before and after the scanning phase.

[0100] The additional access intention information is generated following the detection of the first access intention action, either by the connected mobile terminal or by one of the nearby geolocation beacons, depending on which of the connected mobile terminal or the nearby geolocation beacon detected said second access intention action.

[0101] In a second embodiment, the validation phase takes place temporally before the scanning phase. In other words, one or more access intent actions condition the implementation of the scanning phase.

[0102] In a third embodiment, the validation phase takes place temporally after the scanning phase. In other words, one or more access intent actions condition the implementation of the geolocation phase.

[0103] According to one embodiment of the invention, the connected mobile terminal transmits to the access center at least the user identification data and the beacon data packets, so that said access center can carry out the geolocation phase, on condition of the prior implementation of the validation phase.

[0104] Advantageously, and as indicated above, the validation phase allows less demand on the access center to carry out the access control phase; and the geolocation phase if it is responsible for it.

[0105] According to one embodiment of the invention, the additional access intention information is transmitted to the access center with at least the user's identification data; and during the access control phase, the access center also checks said additional access intention information to authorize or not access to the secure space.

[0106] According to one embodiment of the invention, the access center receives from the connected mobile terminal at least the beacon data packets, the additional access intention information and the user identification data following completion of the validation phase.

[0107] In other words, the access center authorizes the user to access a secure space after having verified and validated at least the user's identification data and also the additional information of access intention; these two data being transmitted according to different embodiments either by the connected mobile terminal, or by a nearby geolocation beacon among the nearby geolocation beacons by direct communication or indirect communication.

[0108] For example, in the application context where the connected mobile terminal has network access and the connection address to the access center, it can communicate to the access center at least the user identification data and the additional access intention information.

[0109] In the application context where the geolocation beacons have network access, and the connected mobile terminal does not, the access center receives from at least one of the nearby geolocation beacons at least the user identification data and the additional access intention information. In the case where the additional access intention information is generated by the connected mobile terminal, the latter transmits it to one of the nearby geolocation beacons so that it can relay it to the access center.

[0110] According to one embodiment of the invention, during the validation phase, the at least one access intention action is detected by the connected mobile terminal and corresponds to:

[0111] - a predefined impact or displacement movement of the connected mobile terminal detected by an accelerometer integrated into the connected mobile terminal;

[0112] - an unlocking action by the user of the connected mobile terminal to change it from a locked state to an unlocked state;

[0113] - an access validation action carried out by the user of the connected mobile terminal on an access validation application loaded in the connected mobile terminal.

[0114] In other words, in different embodiments, the access intention action corresponds to an interaction of the user with his connected mobile terminal; which subsequently generates the additional access intention information.

[0115] According to different embodiments, the predefined impact or displacement movement of the connected mobile terminal may, but is not limited to:

[0116] - a tap on the connected mobile terminal; - a change in orientation of the connected mobile terminal. For example, an accelerometer integrated in the connected mobile terminal measures the angle of inclination of the latter relative to the ground. The access intention action is detected if this angle of inclination is included in a defined range of angles such that any angle included within corresponds to an application context where the user uses his connected mobile terminal (for example, navigation in the menus of the connected mobile terminal, reading a message, etc.), with the front face of the connected mobile terminal facing or substantially facing the user;

[0117] - an analysis of the user's gait by an application previously loaded into the connected mobile terminal.

[0118] According to different embodiments of the invention, the action of unlocking the connected mobile terminal may correspond, without limitation, to:

[0119] - switching on a touch screen included in the connected mobile terminal by the user pressing it, or on a switch-on button also included in the connected mobile terminal;

[0120] - an operation of entering an unlocking code on the connected mobile terminal;

[0121] - a touch entry operation of an unlock pattern on a touch screen of the connected mobile terminal;

[0122] - a fingerprint recognition operation on a fingerprint sensor of the connected mobile terminal;

[0123] - a facial recognition operation of the user using a camera integrated into the connected mobile terminal.

[0124] According to different embodiments of the invention, the access validation action carried out by the user of the mobile terminal connected to the validation application comprises at least one operation carried out on a launch menu of the validation application by the following:

[0125] - an operation to enter a launch code;

[0126] - a touch input operation of a launch pattern;

[0127] - a validation operation.

[0128] According to one embodiment of the invention, the first access intention action and the second access intention action are detected by the connected mobile terminal, and such that:

[0129] - the first access intention action corresponds to the unlock action, and

[0130] - the second access intention action corresponds to the access validation action.

[0131] In other words, in a particular embodiment of the invention, when the secure access protocol is started, the user unlocks his connected mobile terminal to switch it from a locked state to an unlocked state. This unlocking action corresponds to a first access intention action that includes the validation phase. The connected mobile terminal, once unlocked, initiates the scanning phase and the secure telemetry steps with the nearby geolocation beacons.

[0132] The user performs a second access intent action once the scanning phase is complete. The second access intent action consists of performing a validation action on the access validation application loaded in the connected mobile terminal. The validation action has the effect of causing the connected mobile terminal to generate the additional access intent information, and also to initiate the geolocation phase.

[0133] In a variant of this particular embodiment, the access validation application runs automatically after completion of the scanning phase, and for example displays the launch menu on the screen of the connected mobile terminal.

[0134] According to one embodiment of the invention, during the validation phase, the at least one access intention action corresponds to a detection by at least one sensor of:

[0135] - a contact of the user on a nearby geolocation beacon, called a nearby starting geolocation beacon, among the nearby geolocation beacons; or

[0136] - an approach of the user or the connected mobile terminal to a nearby geolocation beacon, called a nearby starting geolocation beacon, among the nearby geolocation beacons within a given activation distance from said nearby starting geolocation beacon.

[0137] In other words, in variant embodiments of the invention, the at least one action of intention to access an interaction of the user with one of the geolocation beacons present in the space where he is located, this beacon being called the near-start geolocation beacon.

[0138] According to one embodiment of the invention, the at least one sensor is chosen from a mechanical sensor, a capacitive sensor, an inductive sensor, a radar sensor, an ultrasonic sensor, an optical sensor, a vibration sensor.

[0139] The action of intention to access may, without limitation, relate to:

[0140] - contact or approach of a hand of the user on a part of the shell of the geolocation beacon close to the start, detected for example by means of electrostatic sensors (inductive sensor, capacitive sensor) or sound or optical sensors;

[0141] - pressing a key or button included in the geolocation beacon near the start;

[0142] - detection of the user's approach by the nearby geolocation beacon which incorporates: a motion sensor (for example, a passive infrared motion sensor) to detect movements of the user; or an accelerometer to detect vibrations caused by the user's footsteps on the ground: or even a microphone to detect noises caused by the footsteps.

[0143] In other embodiments of the invention, the geolocation beacons can incorporate several sensors among those mentioned above to determine, for example, the speed of movement of the user in the space where they are positioned, or a trajectory of the connected mobile terminal.

[0144] According to one embodiment of the invention, the at least one sensor is mounted on the near-start geolocation beacon, or is remote from said near-start geolocation beacon and connected to it.

[0145] In other words, the sensors can be integrated into the geolocation beacons, as in the examples cited above, or else be removed from the geolocation beacons.

[0146] In one embodiment of the invention, the remote sensor is integrated into a housing which also includes a push button with which the user interacts; pressing the push button corresponds to the action of intention to access. The housing is for example fixed to a wall of the space where geolocation beacons are located, including the nearby geolocation beacon of departure.

[0147] According to alternative embodiments of the invention, the remote sensor is physically connected to the nearby geolocation beacon by a wire; or communicates with it by means of a wireless communication protocol (for example, Bluetooth Low Energy BLE®)

[0148] According to one embodiment of the invention, at the start of the secure access control method, the Ultra Wide Band transceiver of each of the geolocation beacons is in a standby state, being only capable of receiving in Ultra Wide Band, and in which, following detection of at least one access intention action by the near-start geolocation beacon, at least the Ultra Wide Band transceiver of the near-start geolocation beacon switches to a wake-up state, being capable of transmitting and receiving in Ultra Wide Band, so that the connected mobile terminal can initiate the secure telemetry step with said near-start geolocation beacon.

[0149] In one embodiment of the invention, the Ultra Wide Band transceivers of the geolocation beacons are configured to remain in a sleep state until they detect an access intent action, which may be the only one or included among several other access intent actions performed by the user during the validation phase. In other words, the connected mobile terminal, even with its Ultra Wide Band transceiver in the awake state, is not able to initiate the scanning phase and a secure telemetry step with a nearby geolocation beacon until the transceiver thereof has switched to an awake state.

[0150] Advantageously, the validation phase allows, when at least one access intention action is detected by the geolocation beacons:

[0151] - to validate the user's intention to access a secure space;

[0152] - to optimize exchanges between nearby geolocation beacons and the connected mobile terminal during the entire secure access control process;

[0153] - to reduce power consumption in the Ultra Wide Band mode of geolocation beacons; and possibly, if they are battery powered, to save them.

[0154] In one embodiment of the invention, the geolocation beacons that have been requested during the implementation of the secure access control method are configured to switch their Ultra Wide Band transceiver from the awake state to the standby state once a time period of activity has elapsed; the time period of activity being, for example, established from an average duration of implementation of the secure access control method.

[0155] According to one embodiment of the invention, following the detection of at least one access intention action by the nearby geolocation beacon of departure, said nearby geolocation beacon of departure sends to each of the other nearby geolocation beacons among the nearby geolocation beacons within communication range an Ultra Wide Band wake-up signal so that their respective transceiver also switches to the woken-up state; this is so that the connected mobile terminal can initiate the secure telemetry steps.

[0156] In other words, in connection with the preceding explanations, when the starting near geolocation beacon detects at least one action of access intention, the access control method comprises a transmission step during which the starting near geolocation beacon transmits a wake-up signal in the Ultra Wide Band communication mode to the geolocation beacons located within communication range, which switch their Ultra Wide Band transceiver from the standby state to the awake state upon receipt of said wake-up signal, then allowing the connected mobile terminal to initiate the scanning phase.

[0157] According to one embodiment of the invention, at the start of the secure access control method, the Ultra Wide Band transceiver of the connected mobile terminal is in a standby state, being only capable of receiving in Ultra Wide Band, and in which the at least one access intention action detected by the connected mobile terminal during the validation phase switches the Ultra Wide Band transceiver of the connected mobile terminal into an awake state, making it capable of transmitting and receiving in Ultra Wide Band, and consequently capable of initiating the scanning phase.

[0158] Advantageously, switching the Ultra Wide Band transceiver of the connected mobile terminal to the awake state following the detection of at least one access intention action, so that the connected mobile terminal can initiate the scanning phase, allows, as explained previously:

[0159] - to validate the user's intention to access, so as not to unnecessarily request nearby geolocation beacons to implement secure telemetry steps if the user does not wish to access a secure space;

[0160] - in connection with the previous point, to optimize exchanges between the connected mobile terminal and nearby geolocation beacons: only useful exchanges take place between the equipment for the complete implementation of the secure access control process;

[0161] - to reduce the power consumption of the mobile terminal connected in the Ultra Wide Band communication mode by limiting it solely to the implementation of the secure access control process.

[0162] According to one embodiment of the invention, the first access intention action detected by the connected mobile terminal during the validation phase, and which corresponds to the unlocking action, switches the Ultra Wide Band transceiver of the connected mobile terminal into an awake state making it capable of transmitting and receiving in Ultra Wide Band, and consequently capable of initiating the scanning phase.

[0163] In other words, in the particular embodiment for which the validation phase comprises the detection of the first access intention action and the second access intention action both detected by the connected mobile terminal, if at the start of the secure access control method, the Ultra Wide Band transceiver of the connected mobile terminal is in the standby state, then the detection of the first access intention action, which corresponds to the unlocking of the connected mobile terminal, has the effect of waking up its Ultra Wide Band transceiver.

[0164] According to one embodiment of the invention, at the start of the secure access control method, the Ultra Wide Band transceiver of the connected mobile terminal is in a standby state, being only capable of receiving in Ultra Wide Band, and in which following the detection of at least one access intention action by the near-start geolocation beacon, said near-start geolocation beacon sends to the connected mobile terminal an Ultra Wide Band wake-up signal which, when received by the connected mobile terminal, switches the Ultra Wide Band transceiver thereof into a wake-up state, making it capable of receiving and transmitting in Ultra Wide Band, and therefore capable of initiating the scanning phase.

[0165] In a given application context, for the purpose of reducing power consumption and saving battery energy of the connected mobile terminal, the Ultra Wide Band transceiver of the connected mobile terminal is, at the start of the access control method, in a standby state, being only able to receive data in the Ultra Wide Band communication mode (but not to transmit it). In one embodiment of the invention, at least one access intention action is detected by the near-start geolocation beacon, said near-start geolocation beacon sends a wake-up signal in the Ultra Wide Band communication mode to the connected mobile terminal.Once the connected mobile terminal receives this wake-up signal, its Ultra Wideband transceiver turns on and / or switches to the awake state, allowing it to transmit data in the Ultra Wideband communication mode and thus initiate the scanning phase.

[0166] [Brief description of the figures]

[0167] Other characteristics and advantages of the present invention will appear on reading the detailed description below, of a non-limiting example of implementation, made with reference to the appended figures in which:

[0168] [Fig 1] is a schematic view of an example of a building comprising several secure spaces: which are each protected by an access control bay which comprises a locking / unlocking system, which locking / unlocking system is controlled by an access control unit; and in which geolocation beacons are installed, which are fixed to a wall or ceiling, and which are used for geolocation and authentication of a connected mobile terminal of a user who seeks to access one of the secure spaces from the space in which he is located;

[0169] [Fig 2] is a schematic view of a two-way data exchange, in Ultra Wideband communication mode, between the connected mobile terminal and a geolocation beacon installed in the building;

[0170] [Fig 3] is an operating diagram of a first embodiment of the invention, for which an access center installed in the building is configured to, on the one hand, geolocate the connected mobile terminal and identify an access control bay, called a target bay, physically close to the connected mobile terminal and, on the other hand, verify whether the user has the required accreditations to access the secure space protected by the target bay;the geolocation of the connected mobile terminal, implemented during a geolocation phase, based on processing of data from secure telemetry steps initiated by the connected mobile terminal with the geolocation beacons and which are carried out during a scanning phase, called nearby geolocation beacons, installed in the space in which it is located, and authentication, implemented during an access control phase based at least on a check of the user's identification data which are included in the connected mobile terminal and which are transmitted to the access center;

[0171] [Fig 4] is a schematic view of a principle for calculating a time of flight during a bidirectional exchange of data between the connected mobile terminal and a geolocation beacon during a secure telemetry step implemented during the secure access control method;

[0172] [Fig 5] is an illustration related to the embodiment illustrated in Figure 3 in which the connected mobile terminal, which has network access and a connection address to connect to the access center, transmits to the access center, following the secure telemetry steps carried out by the connected mobile terminal with the nearby geolocation beacons, the data which allows the latter to implement the geolocation and access control phases;

[0173] [Fig 6] is a schematic view of a plan contained in the access center, said plan identifying all the geolocation beacons and the access control bays (here, by means of their three-dimensional Cartesian coordinates) and also containing their respective identifiers; the plan being used by the access center during the geolocation phase to determine the position of the connected mobile terminal and the target bay; [Fig 7] is an operating diagram of a second embodiment corresponding to a variant of the embodiment illustrated in Figure 3, in which the connected mobile terminal does not have network access and / or the connection address to connect to the access center;and in which it then transmits, following the secure telemetry steps, the data necessary for the implementation of the geolocation and access control phases to one of the nearby geolocation beacons, called the first nearby geolocation beacon, which first nearby geolocation beacon is responsible for relaying the data to the access center;

[0174] [Fig 8] is a schematic view related to the embodiment of Figure 7, in which the first nearby geolocation beacon directly transmits to the access center the data necessary for the implementation of the geolocation and access control phases;

[0175] [Fig 9] is a schematic view in connection with the embodiment of Figure 7, in which the first nearby geolocation beacon indirectly transmits to the access center the data necessary for the implementation of the geolocation and control phases by passing through at least one other geolocation beacon according to a step-by-step communication protocol, the first nearby geolocation beacon not being able in this configuration to communicate directly with the access center;

[0176] [Fig 10] is an operating diagram of a third embodiment, in which the geolocation phase is implemented by the connected mobile terminal and not by the access center, which however remains in charge of the access control phase; this third embodiment comprising at least one transmission by the connected mobile terminal to the access center of the data necessary for the implementation of the access control phase;

[0177] [Fig 11] is a schematic view of the operating principle of the geolocation phase when it is carried out by the connected mobile terminal;

[0178] [Fig 12] is an operating diagram of a fourth embodiment for which the connected mobile terminal remains in charge of the geolocation phase but this time transmits the data necessary for the implementation of the geolocation phase to the first nearby geolocation beacon, which first nearby geolocation beacon is further configured to timestamp part of the data and then transmit them to the access center;

[0179] [Fig 13] is a schematic view of an access intention action that the user must perform in order for the geolocation phase to be implemented (whether this is performed by the connected mobile terminal or the access center), the access intention action corresponding here to an access validation action performed on an access validation application previously loaded into the connected mobile terminal before the implementation of the secure access control method;

[0180] [Fig 14] is a schematic view of the access intention action which, in another context, corresponds to a specific inclination of the connected mobile terminal relative to the ground;

[0181] [Fig 15] is a schematic view of the access intent action which, in another context, corresponds to an impact on the connected mobile terminal, such as a tap;

[0182] [Fig 16] is a schematic view of the access intention action which, in another context, corresponds to a contact of the user on one of the geolocation beacons installed in the space where he is located, this context implying that one of the geolocation beacons is accessible to the user, for example by being fixed to a wall;

[0183] [Fig 17] is a schematic view of the access intention action which, in another context, corresponds to a detection by one of the geolocation beacons installed in the space of an approach of the user or his connected mobile terminal when he is within an activation distance;

[0184] [Fig 18] is an operating diagram of a fifth operating mode in which the access intention action, in addition to the geolocation phase, also conditions the implementation of the scanning phase; the access intention action is thus carried out at the start of the secure access control method and here corresponds to an approach detection as illustrated in Figure 17;

[0185] [Fig 19] is an operating diagram of a sixth embodiment in which the access intention action, in addition to the geolocation phase, also conditions the implementation of the scanning phase; the access intention action is thus carried out at the start of the secure access control method and here corresponds to an unlocking of the connected mobile terminal by its user;

[0186] [Fig 20] is an operating diagram of a seventh embodiment in which the implementation of the geolocation phase is conditioned by the performance of several access intention actions, said several access intention actions being performed successively at the end of the scanning phase and corresponding to an unlocking of the connected mobile terminal then to a validation action carried out on the mobile validation application;[Fig 21] is an operating diagram of an eighth embodiment, which also corresponds to the preferred embodiment of the invention: the scanning phase is implemented following unlocking of the connected mobile terminal, the geolocation phase is implemented following a validation action carried out on the mobile validation application at the end of the scanning phase, the geolocation and access control phases are implemented by the access center following reception of data from the connected mobile terminal;unlocking the connected mobile terminal also having the function of switching the connected mobile terminal from a standby state, in which it can only receive data in the Ultra Wide Band communication mode, to an awake state, in which it can transmit and receive data in the Ultra Wide Band communication mode, thus making it capable of initiating the secure telemetry steps with the nearby geolocation beacons during the scanning phase;

[0187] [Fig 22] is an operating diagram of a ninth embodiment in which the geolocation beacons are at the start of the secure access control method in a sleep state, in which they can only receive data in the Ultra Wide Band communication mode, and in which the user must interact with one of the geolocation beacons in the space, called the starting near geolocation beacon, either by contact or by approaching, so that it wakes up, making it then capable of transmitting and receiving data in the Ultra Wide Band communication mode; said starting near geolocation beacon transmitting, following its waking, a wake-up signal to the at least one other geolocation beacon installed in the same space as it to wake it up in turn, thus allowing the connected mobile terminal to carry out the secure telemetry steps with all the nearby geolocation beacons;

[0188] [Fig 23] is an operating diagram of a tenth embodiment in which the geolocation beacons and the connected mobile terminal are in a standby state at the start of the secure access control method, and in which the user must interact with the nearby geolocation beacon so that, on the one hand, said nearby geolocation beacon transmits, following its awakening, a wake-up signal to at least one other geolocation beacon installed in the same space as it to wake it up in turn, and on the other hand, it transmits another wake-up signal to the connected mobile terminal which also wakes up, thus allowing the scanning phase to be implemented. [Detailed description of one or more embodiments of the invention]

[0189] The subject of the invention relates to a secure access control method 100 designed to operate in the Ultra Wideband geolocation mode. This secure access control method 100 of the invention proposes to geolocate and authenticate a connected mobile terminal 1 of a user U located in a space of a building and wishing to access one of several secure spaces accessible from said space, each of the secure spaces being protected by an access control bay.

[0190] Non-exhaustively, the connected mobile terminal 1 is equipped with a touch screen and can refer to: a mobile phone, a touch tablet, a connected watch, etc.

[0191] The geolocation of the connected mobile terminal 1 makes it possible to determine the local position of the connected mobile terminal 1 in the space as well as the access control bay to which the connected mobile terminal 1 is physically closest. If it is verified following authentication that the user U has the required accreditations to access the secure space protected by the access control bay to which he is physically closest, then access to said secure space is authorized.

[0192] Referring to Figure 1, the secure access control method 100 is illustrated in the context of a building comprising:

[0193] - four secure spaces El, E2, E3, E4 such that: the second secure space E2 and the third secure space among the four secure spaces El, E2, E3, E4 are accessible from the first secure space El, and the fourth secure space E4 is accessible from the second secure space E2;

[0194] - five access control bays D1, D2, D3, D4, D5 such that: the first secure space is protected by the first and second access control bays D1, D2 among the six access control bays D1, D2, D3, D4, D5; the second secure space E2 is protected by the first, third and fourth access control bays D1, D3, D4; the third secure space E3 is protected by the second access control bay D2; and the fourth secure space E4 is protected by the fourth and fifth access control bays D4, D5. Each of the access control bays has a locking / unlocking system allowing them to switch from a locked state to an unlocked state, to allow a user U to enter the secure space E1, E2, E3, E4 that it protects; and vice versa from an unlocked state to a locked state to prevent a user U from accessing the secure space E1, E2, E3, E4.The secure access control method 100 is implemented by means of the following equipment 1, B1, B2, B3, B4, B5, B6, 2:.

[0195] - the connected mobile terminal 1 of the user U which contains at least user identification data udata (or in English, credentials), and an Ultra Wide Band transceiver U1;

[0196] - geolocation beacons that can be installed in a space by being fixed and / or on the ceiling. With reference to Figure 1, six geolocation beacons Bl, B2, B3, B4, B5, B6 are used and arranged such that: geolocation beacon Bl and geolocation beacon B2 among the six geolocation beacons Bl, B2, B3, B4, B5, B6 are installed in the first secure space El; geolocation beacon B3 and geolocation beacon B4 are installed in the second secure space E2; geolocation beacon B5 is installed in the third secure space E3, and geolocation beacon B6 is installed in the fourth secure space E4. Each of the geolocation beacons Bl, B2, B3, B4, B5, B6 comprises at least one Ultra Wide Band transceiver UB1, UB2, UB3, UB4, UB5, UB6; and

[0197] - an access center 2 which is connected to the locking / unlocking systems of the several access control bays D1, D2, D3, D4, D5, and in communication at least with the connected mobile terminal 1. With reference to Figure 1, the access center 2 is installed in the fourth secure space E4. According to different embodiments of the invention, the locking / unlocking systems of the access control bays D1, D2, D3, D4, D5 may for example correspond to a latch that opens and closes, and may either be physically connected by a wire to the access center 2, or be connected to it via a wireless link.

[0198] The access center 2 is designed to be remote, that is to say physically distant, from the geolocation beacons Bl, B2, B3, B4, B5, B6. In other words, the geolocation beacons Bl, B2, B3, B4, B5, B6 are not contained in the access center 2, or the geolocation beacons Bl, B2, B3, B4, B5, B6 and the access center 2 are not contained in the same radiofrequency equipment intended for access control.

[0199] The secure access control method 100 is based on data exchanges between the different devices 1, B1, B2, B3, B4, B5, B6, 2, and in particular on exchanges between the connected mobile terminal 1 and at least one of the geolocation beacons B1, B2, B3, B4, B5, B6 in the Ultra Wide Band communication mode in order to authenticate and geolocate it. The Ultra Wide Band transceiver U1 of the connected mobile terminal 1 and the Ultra Wide Band transceivers UB1, UB2, UB3, UB4, UB5, UB6 of the geolocation beacons B1, B2, B3, B4, B5, B6 are designed to:

[0200] - only be capable of receiving data in Ultra-Wideband communication mode when in a standby state;

[0201] - be able to transmit and receive data in the Ultra-Wideband communication mode when in an awake state (i.e. when they are awake).

[0202] In other words, with reference to Figure 2, the connected mobile terminal 1 is able to carry out a bidirectional exchange of UWB1, UWB2, UWB3, UWB4, UWB5, UWB6 data with one of the six geolocation beacons Bl, B2, B3, B4, B5, B6 when their respective transceivers Ul, UB1, UB2, UB3, UB4, UB5, UB6 are awakened. In the remainder of the description, when it will be described that the connected mobile terminal 1 exchanges data with a geolocation beacon Bl, B2, B3, B4, B5, B6, it is understood that it is its Ultra Wide Band transceiver Ul which exchanges said data with the Ultra Wide Band transceiver UB1, UB2, UB3, UB4, UB5, UB6 of the geolocation beacon Bl, B2, B3, B4, B5, B6.

[0203] In the remainder of the description, several embodiments of the secure access control method 100 are detailed, non-exhaustively. In other words, other embodiments are also possible depending on the characteristics defining the secure access control method 100. For each of the embodiments that are described, it is considered, with reference to Figure 1, that the user U is in the first secure space E1 and wishes to access the second secure space E2 protected by the first access control layer D1.

[0204] A first embodiment of the invention is illustrated by the flowchart Figure 3. In this embodiment, at the start of the secure access control method 100, it is considered that the Ultra Wide Band transceivers Ul, UB1, UB2, UB3, UB4, UB5, UB6 of the connected mobile terminal 1 and the geolocation beacons are woken up Bl, B2, B3, B4, B5, B6.

[0205] At the start of the secure access control method 100, the connected mobile terminal 1 triggers a scanning phase ScanP during which it initiates secure telemetry steps with the geolocation beacons having their respective transceivers within communication range of its own. With reference to Figure 3, and for all the embodiments which will be described subsequently, it is considered that, during the scanning phase ScanP, the Ultra Wide Band transceivers UB1, UB2 of the geolocation beacon Bl and of the geolocation beacon B2 are within communication range of the Ultra Wide Band transceiver U1 of the connected mobile terminal 1. In other words, for all the embodiments described, during the scanning phase ScanP, the connected mobile terminal 1 initiates a first secure telemetry step SRI with the geolocation beacon Bl, and a second secure telemetry step SR2 with the geolocation beacon B2.

[0206] The geolocation beacon Bl and the geolocation beacon B2, in order to be distinguished from the other geolocation beacons B3, B4, B5, B6 with which the connected mobile terminal 1 does not carry out secure telemetry steps, are designated as being nearby geolocation beacons Bl, B2.

[0207] It should be noted that it is conceivable that, in different embodiments of the invention, the ScanP scanning phase may comprise a single secure telemetry step initiated by the connected mobile terminal 1 with a single geolocation beacon.

[0208] Each of the secure telemetry steps SRI, SR2 comprises at least one bidirectional exchange of UWB1, UWB2 data in the Ultra Wide Band communication mode between the connected mobile terminal 1 and the nearby geolocation beacon Bl, B2. Thus, with reference to Figure 3, the secure telemetry step SRI, SR2 comprises at least:

[0209] - a transmission step SR11, SR21 during which the connected mobile terminal 1 transmits security data datall, data21 to the nearby geolocation beacon Bl, B2, which receives them during a reception step SRU', SR21';

[0210] - a transmission step SR12, SR22 during which the nearby geolocation beacon Bl, B2 also transmits security data datal2, data 22 comprising at least one identifier idBl, idB2 of the nearby geolocation beacon Bl, B2, which receives them during a reception step SR12', SR22';

[0211] - a calculation step ECB1, ECB2 of a certified distance sdistBl, sdistB2 between the connected mobile terminal 1 and the nearby geolocation beacon Bl, B2 following at least one bidirectional exchange (i.e. following at least the reception step SR12', SR22').

[0212] With reference to Figure 4, in one embodiment of the invention, during the calculation step ECB1, ECB2, the certified distance sdistBl, sdistB2 is calculated, according to the equation Eq.l, by at least one connected mobile terminal 1 and the nearby geolocation beacon Bl, B2 from a time of flight ToF (“Time Of Flight” in English) measured by said at least one connected mobile terminal 1 and the nearby geolocation beacon Bl, B2.

[0213] Tloop — Treply

[0214] ToF Eq.l where Treply is the response time of the nearby geolocation beacon Bl, B2, i.e. the time interval between the reception step SRU', SR21' and the transmission step SR12, SR22; and Tloop is the duration of the bidirectional exchange between the connected mobile terminal 1 and the nearby geolocation beacon Bl, B2, i.e. the time interval between the transmission step SR11, SR21 and the reception step SR12', SR22'.

[0215] In the embodiment illustrated in Figure 3, the certified distance sdistBl, sdistB2 is calculated by the nearby geolocation beacon Bl, B2.

[0216] In another embodiment of the invention, the connected mobile terminal 1 and the nearby geolocation beacon Bl, B2 both calculate the certified distance sdistBl, sdistB2 during the secure telemetry step SRI, SR2. Both exchange the certified distance value sdistBl, sdistB2 that they have calculated. The connected mobile terminal 1 and the nearby geolocation beacon Bl, B2 then compare the certified distance sdistBl, sdistB2 that it has received with the certified distance sdistBl, sdistB2 that it has itself calculated. In the case where the consistency between the certified distances sdistBl, sdistB2 is not verified, the telemetry step SRI, SR2 is stopped. In the case where the consistency is verified, it continues.

[0217] As explained previously, the distance is certified by nature because its calculation is carried out during the secure telemetry step SRI, SR2, and because it is based on at least one bidirectional exchange of Ultra Wide Band signals between the connected mobile terminal 1 and the nearby geolocation beacon Bl, B2 which each have: an embedded secure component; or trusted micro-software or application previously loaded inside, or a trusted execution environment (or “Trusted Execution Environment” TEE in English).

[0218] In the embodiments for which it is provided that the nearby geolocation beacons Bl, B2 carry out the calculation and certification of the certified distance sdsitBl, sdistB2, it is conceivable that the connected mobile terminal 1, during transmission steps SR11, SR21, also transmits to the nearby geolocation beacons Bl, B2 also a connected mobile terminal identifier which is specific to it. This connected mobile terminal identifier is returned to the connected mobile terminal 1 by the nearby geolocation beacons Bl, B2 during the transmission of the certified distance sdistBl, sdistB2 during transmission steps SR13, SR23.

[0219] Advantageously, the return of the connected mobile terminal identifier allows the connected mobile terminal 1 to verify that the certified distance sdistBl, sdistB2 that it received during the reception step SR13', SR23':

[0220] - on the one hand that the certified distance sdsitBl, sdistB2 calculated corresponds to that between the nearby geolocation beacon Bl, B2 and it, and not to a certified distance calculated between the nearby geolocation beacon Bl, B2 and another connected mobile terminal 1 which may be located near it; and

[0221] - on the other hand, comes from the nearby geolocation beacon Bl, B2 with which it has implemented the secure telemetry step SRI, SR2. This is an additional security means allowing the connected mobile terminal to determine whether or not the certified distance sdsitBl, sdistB2 comes from a malicious system, which malicious system cannot possess the connected mobile terminal identifier since the connected mobile terminal 1 and it have not carried out a secure telemetry step.

[0222] Also, it is conceivable with a view to increasing the degree of security of the secure access control method 100 that the nearby geolocation beacons Bl, B2, following the calculation of the certified distance sdistBl, sdistB2, also carry out a signature of the latter. The signature is such that it is specific to each of the nearby geolocation beacons Bl, B2. Thus, the connected mobile terminal 1, after having a certified distance sdistBl, sdistB2, verifies its signature to determine whether or not it corresponds to the signature of the nearby geolocation beacon Bl, B2 having transmitted it (this therefore means that the signatures of the nearby geolocation beacons Bl, B2 are known to the connected mobile terminal 1).

[0223] In the case where the mobile terminal identifier received from a nearby geolocation beacon Bl, B2 does not correspond to the identifier of the connected mobile terminal 1, and / or the signature of the certified distance sdistBl, sdistB2 received does not correspond to the signature of said nearby geolocation beacon Bl, B2 which is supposed to have transmitted it, the connected mobile terminal 1 does not form the beacon data packet dataBl, dataB2 associated with said geolocation beacon Bl, B2 with which it is supposed to have communicated. In other words, and more simply, it does not take into consideration the certified distance sdistBl, sdistB2 which must come from the nearby geolocation beacon Bl, B2 with which it is supposed to have been in communication during the secure telemetry step Bl, B2.The scanning phase ScanP ends once all the secure telemetry steps carried out by the connected mobile terminal 1 with all the nearby geolocation beacons are completed (i.e., in the case of Figure 3, following the completion of the first secure telemetry step El and the second secure telemetry step E2).

[0224] Optionally, the secure telemetry steps SRI, SR2 are not limited to the exchanges described above. Further information on secure telemetry is available in the two references indicated in the State of the art.

[0225] At the end of the scanning phase ScanP, the connected mobile terminal 1 contains at least the identifier idBl, idB2 and the certified distance sdistBl, sdistB2 associated with the nearby geolocation beacon Bl, B2 with which it carried out the secure telemetry step SRI, SR2. The at least identifier idBl, idB2 and certified distance sdistBl, sdistB2 form a beacon data packet dataBl, dataB2 associated with the nearby geolocation beacon Bl, B2.

[0226] Following the scanning phase ScanP, with reference to Figure 5, the connected mobile terminal 1 transmits to the access center 2 during a transmission step El at least the beacon data packets dataBl, dataB2 relating to the two nearby geolocation beacons Bl, B2, as well as the user identification data udata.

[0227] In order to implement this transmission step El, the connected mobile terminal has network access to an add-c connection address to connect to the access center 2 and communicate with it.

[0228] In an alternative embodiment, the add-c connection address is already contained in the connected mobile terminal 1, having been previously loaded into it before implementing the secure access control method 100.

[0229] In another embodiment variant, the connection address add-c is transmitted to the connected mobile terminal 1 by the at least one nearby geolocation beacon B1, B2 during the secure telemetry step SRI, SR2. Non-limitingly, it is possible for the connection address add-c to be transmitted:

[0230] - during at least one bidirectional exchange between the connected mobile terminal and at least one nearby geolocation beacon B1, B2, or during the transmission step SR12, SR22; or

[0231] - with the certified distance sdistBl, sdistB2 during the transmission step SR13, SR23. With reference to Figure 3, the connection address add-c is transmitted to the connected mobile terminal 1 by only one of the two nearby geolocation beacons Bl, B2 during the transmission step SR13; or

[0232] - during another transmission step (which is not illustrated in the Figures).

[0233] With reference to Figure 6, during the geolocation phase GeoP, the access center connects the beacon data packets dataBl, dataB2 with a plane P that it contains. In the embodiment presented, all of the access control bays D1, D2, D3, D4, D5 and the geolocation beacons Bl, B2, B3, B4, B5, B6 of the building are located in the plane P by means of three-dimensional Cartesian coordinates. Plan P also contains the identifiers idBl, idB2, idB3, idB4, idB5, idB6 of the geolocation beacons Bl, B2, B3, B4, B5, B6 and the identifiers id-Dl, id-D2, id-D3, id-D4, id-D5 associated with each of the access control bays Dl, D2, D3, D4, D5.

[0234] The connection of the plane P with the certified distances sdistBl, sdistB2 and the identifiers idBl, idB2 of the nearby geolocation beacons allows the access center to determine the position locl of the connected mobile terminal 1 in the first secure space E1 and to determine the access control bay among the first access control bay D1 and the second control bay D2 to which it is physically closest. In the example given, the identified access control bay, and which is subsequently referred to as the target bay DC, corresponds to the first access control bay D1. In the remainder of the description, it is considered that the target bay DC has a target bay identifier id-DC.

[0235] Since the geolocation phase GeoP is based on the use of a plan P and on the analysis of the beacon data packets dataBl, dataB2, the geolocation beacons Bl, B2, B3, B4, B5, B6 do not need to be installed near the access control bays Dl, D2, D3, D4, D5.

[0236] Following the geolocation phase GeoP, the access center implements an access control phase CP during which it checks at least whether the user U has the access rights required to access the second secure space E2 protected by the target bay DC, by verifying the user's identification data udata. If this is the case, the access center commands the unlocking of the locking / unlocking system associated with the target bay DC. The user U can then enter the second secure space E2 and the secure access control method 100 ends. If not, the access center 2 refuses access to the user U, and does not command the unlocking of the locking / unlocking system associated with the target bay DC.

[0237] Figure 7 illustrates a second embodiment of the secure access control method. In this mode, the connected mobile terminal 1 does not have network access and cannot transmit the user identification data udata and the beacon data packets dataB1, dataB2 to the access center 2. In this case, following the scanning phase ScanP, the progress of which is similar to that of the embodiment illustrated in Figure 3 (except that no connection address add-c is transmitted to the connected mobile terminal 1), and then the storage of the beacon data packets dataB1, dataB2 in the connected mobile terminal 1, the connected mobile terminal

[0238] I transmits during a transmission step E21 the user identification data udata and the beacon data packets dataB1, dataB2 to one of the two nearby geolocation beacons Bl, B2 which is then referred to as the first nearby geolocation beacon. This first nearby geolocation beacon may for example correspond to the nearby geolocation beacon which is physically closest to the connected mobile terminal 1. In the remainder of the description, it is considered that the nearby geolocation beacon B1 corresponds to the first nearby geolocation beacon.

[0239] Once the user identification data udata and the beacon data packets dataBl, dataB2 have been received during a reception step E21', the first nearby geolocation beacon B1 must transmit them to the access center 2.

[0240] In a first variant, the geolocation beacons B1, B2, B3, B4, B5, B6 are capable of communicating directly with the access center 2, by being either physically connected to it by means of Ethernet cables or according to a wireless communication protocol such as Wifi®. Thus, with reference to Figure 7 and Figure 8, the first nearby geolocation beacon B1 directly transmits the user identification data udata and the beacon data packets dataB1, dataB2 to the access center during a transmission step E22.

[0241] In another variant, with reference to Figure 9, the geolocation beacons B2, B3, B4, B5, B6 and the access center 2 form a mesh network. The mesh network addresses the problem of installing groups of geolocation beacons in several spaces of the same building such that certain geolocation beacons cannot communicate directly with the access center.

[0242] It also addresses the problem of indoor network coverage, when the structure of the building and the materials used for its construction interfere with the transmission of signals, preventing two systems present in the building and yet within communication range from exchanging data (for example, two systems in the basement, or located on different floors of the building, or separated by a wall of significant thickness, etc.). Thus, in this variant, the transmission of the user identification data udata and the beacon data packets dataBl, dataB2 is done by means of a step-by-step communication, according to a Bluetooth Mesh® step-by-step communication protocol, in which the first nearby geolocation beacon B1 and at least one of the five other geolocation beacons B2, B3, B4, B5, B6 participate.

[0243] Note that in both variants, exchanges between geolocation beacons Bl, B2, B3, B4, B5, B6 or with access center 2 can be done in Ultra Wide Band as well as in another radio frequency communication protocol.

[0244] Once the access center receives from the first nearby geolocation beacon Bl the user identification data udata and the beacon data packets dataBl, dataB2 during a reception phase E22', it implements the geolocation phase GeoP and the access control phase CP similarly to the first embodiment presented previously.

[0245] In other embodiments, it is conceivable that the geolocation phase GeoP is implemented not by the access center 2 but by the connected mobile terminal 1, the geolocation phase GeoP always being implemented following the scanning phase ScanP. In these said embodiments, the access center 2 can have less computing power because it is only requested in the context of the implementation of the access control phase CP by controlling and verifying whether the information to authenticate the user U is valid or not to authorize or not to access the secure space E2. It also does not have to contain the plan P. In fact, its design is simplified.

[0246] In a first embodiment variant, the connected mobile terminal, in order to implement the geolocation phase GeoP, contains a plan P similar to that possessed by the access center in the previous embodiments described, that is to say a plan P as illustrated in Figure 5 containing: all the three-dimensional Cartesian coordinates of the geolocation beacons B1, B2, B3, B4, B5, B6 and their respective identifiers idB1, idB2, idB3, idB4, idB5, idB6; all the three-dimensional Cartesian coordinates of the access control bays D1, D2, D3, D4, D5 and their respective identifiers id-D1, id-D2, id-D3, id-D4, id-D5. This plan P is previously loaded into the connected mobile terminal, before the secure access control method 100 is implemented.

[0247] During a determination step DS included in the geolocation phase GeoP, and from the plan P, the mobile terminal determines: its position loci and that of the target bay DC (otherwise, their respective Cartesian, three-dimensional coordinates); the identifier of the target bay id-DC.

[0248] In a second embodiment, with reference to Figures 10 and 11, the connected mobile terminal 1 does not contain a plan P. The geolocation beacons B1, B2, B3, B4, B5, B6 are designed to each contain a piece of plan. The piece of plan associated with each of the geolocation beacons B1, B2, B3, B4, B5, B6 locates said geolocation beacon B1, B2, B3, B4, B5, B6 and at least one access control bay D1, D2, D3, D4, D5 physically close to said geolocation beacon B1, B2, B3, B4, B5, B6.

[0249] In other words, the piece of plan contains the three-dimensional Cartesian coordinates of the geolocation beacon Bl, B2, B3, B4, B5, B6 and those of at least one access control bay Dl, D2, D3, D4, D5 physically close to it.

[0250] The plan piece also includes the identifiers idBl, idB2, idB3, idB4, idB5, idB6 of the geolocation beacon Bl, B2, B3, B4, B5, B6 and the identifiers id-Dl, id-D2, id-D3, id-D4, id-D5 of the access control bays that it locates Dl, D2, D3, D4, D5.

[0251] It is possible that the piece of plan P identifies, in addition to the geolocation beacon Bl, B2, B3, B4, B5, B6 with which it is associated, other geolocation beacons Bl, B2, B3, B4, B5, B6 located near said geolocation beacon Bl, B2, B3, B4, B5, B6.

[0252] Thus, with reference to Figure 10, when the connected mobile terminal 1 carries out the secure telemetry steps SRI, SR2 with the nearby geolocation beacons B1, B2, each of them transmits its piece of plan P1, P2 to the connected mobile terminal; for example during the transmission step SR13, SR23 or during a transmission step independent of those illustrated.

[0253] In the embodiment presented, with reference to Figure 11, it is considered that the piece of plan PI associated with the nearby geolocation beacon Bl contains its three-dimensional Cartesian coordinates, its identifier idBl, the three-dimensional Cartesian coordinates of the first access control bay Dl and the identifier id-Dl of the latter; and that the piece of plan P2 associated with the second nearby geolocation beacon B2 contains its three-dimensional Cartesian coordinates, its identifier idB2, the three-dimensional Cartesian coordinates of the first access control bay D2 and the identifier id-D2 of the latter.

[0254] When the connected mobile terminal 1 implements the geolocation phase GeoP, it carries out, prior to the determination step DS, a construction step BS during which it merges the plan pieces Pl, P2; the plan pieces Pl, P2 thus merged then forming a local plan P containing: the three-dimensional Cartesian coordinates of the nearby geolocation beacons Bl, B2, of the first access control bay DI and of the second access control bay D2; and their respective identifiers idBl, idB2, id-Dl, id-D2.

[0255] The merging of the plan pieces Pl, P2 is made possible by a plan merging mobile application previously loaded into the connected mobile terminal 1 before the start of the secure access control method 100.

[0256] Whatever the variant, in the case where it has network access and the add-c connection address allowing it to connect to the access center 2, the connected mobile terminal is configured to sign during an ESid signature step, which follows the GeoP geolocation phase, the identifier of the target bay id-DC in order to form a certified target bay identifier sid-DC.

[0257] With reference to Figure 10, the connected mobile terminal 1 then transmits during a transmission step E4 at least its position locl, the user identification data udata and the certified identifier of the target bay sid-DC to the access center 2.

[0258] Once the position locl of the connected mobile terminal 1, the user identification data udata and the certified identifier of the target bay sid-DC at the access center 2 are received during a reception step E4', the access center implements the access control phase CP.

[0259] During the access control phase CP, the access center 2 checks the certified identifier of the target bay id-DC in order to determine whether or not the signature was carried out by a known / trusted system (in other words, by the connected mobile terminal 1). If not, it is possible that the data udata, sid-DC, locl received during the reception step E4' come from a malicious system. It also checks, using the user identification data udata, whether the user U has the necessary accreditations to access the secure space E2 protected by the target bay DC (which, as a reminder, corresponds to the first access control bay D1). It is also possible that it checks the consistency between the certified identifier of the target bay id-DC determined by the connected mobile terminal 1 and its position locl.

[0260] Depending on the result of the access control phase, the access control unit 2 unlocks or not the locking / unlocking system of the target DC bay.

[0261] With reference to Figure 12, when the secure access control method 100 is designed so that the connected mobile terminal 1 communicates with the access center 2 via the geolocation beacons B1, B2, B3, B4, B5, B6, the connected mobile terminal 1, in the case where it is configured to carry out the geolocation phase GeoP, transmits during a transmission step E5 its position locl, the identifier of the target bay id-DC and the user identification data udata to the first nearby geolocation beacon B1.

[0262] Following the reception of the position locl of the connected mobile terminal 1 and the identifier of the target bay id-DC during a reception step E5', the first nearby geolocation beacon timestamps the identifier of the target bay id-DC during a timestamping step EH, forming a timestamped identifier of the target bay id-DC and consequently, certified sid-DC.

[0263] After the timestamping step EH, the first geolocation beacon Bl transmits to the access center 2, during a transmission step E6, the user identification data (received during the reception step SRU' of the secure telemetry step SRI), the position locl of the connected mobile terminal 1 and the certified identifier of the target bay sid-DC. According to different embodiments, the transmission can be direct, carried out according to a step-by-step communication between geolocation beacons Bl, B2, B3, B4, B5, B6.

[0264] Following their reception during a reception step E6', the access center 2 implements the access control phase CP as described above.

[0265] In the embodiments presented so far, the access center is requested at regular intervals because the connected mobile terminal 1 periodically initiates secure telemetry steps SRI, SR2 with the nearby geolocation beacons Bl, B2.

[0266] This is why, in different embodiments, the secure access control method 100 comprises a validation phase which conditions the implementation of the geolocation phase GeoP, and therefore of the access control phase CP. The validation phase therefore allows:

[0267] - to significantly reduce the exchanges between the different actors (the connected mobile terminal 1; the geolocation beacons Bl, B2, B3, B4, B5, B6; the access center 2) of the secure access control process 100, which amounts to optimizing them;

[0268] - to strengthen the security of the secure access control process 100 and the security of data exchanges; thus reducing the risks of interception of this data by a malicious system;

[0269] - to reduce the use of access control center 2 with the implementation of a single CP access control phase (and a single GeoP geolocation phase if it is responsible for its implementation). It also reflects a genuine intention on the part of the user to want to access a secure area.

[0270] When detected by the connected mobile terminal 1, the at least one access intention action may be in the form of a ulock unlocking of the connected mobile terminal 1, causing said connected mobile terminal 1 to switch from a locked state to an unlocked state. Non-exhaustively, this ulock unlocking may be implemented following:

[0271] - switching on a touch screen included in the connected mobile terminal 1 by the user U pressing on it, or on a switch-on button also included in the connected mobile terminal 1; or

[0272] - an operation of entering an unlocking code on the connected mobile terminal 1; or

[0273] - a touch entry operation of an unlock pattern on the touch screen of the connected mobile terminal 1; or

[0274] - a fingerprint recognition operation on a fingerprint sensor of the connected mobile terminal 1; or

[0275] - a facial recognition operation of the user U by means of a camera integrated into the connected mobile terminal 1.

[0276] It can also be presented, with reference to Figure 13, in the form of an opt access validation action carried out in a launch menu displayed by an access validation application l-app, loaded into the connected mobile terminal 1. Non-limitingly, it is possible for the opt access validation action to consist of:

[0277] - an operation of entering a launch code on the launch menu;

[0278] - a touch input operation of a launch pattern on the launch menu;

[0279] - a validation operation on the launch menu

[0280] In one embodiment of the invention, it is conceivable that the access validation application l-app also corresponds to the previously mentioned plan merging mobile application.

[0281] It may also be, with reference to Figure 14, an inclination inc of the connected mobile terminal 1. It consists of a measurement of an inclination angle tetal of the connected mobile terminal 1 relative to the ground, which is then compared to a predefined launch angular interval. If the inclination angle tetal is included in the launch angular interval, then the inclination is considered to be a valid access intention action. The launch angular interval corresponds to an orientation of the connected mobile terminal 1 with respect to the nearby geolocation beacon Bl, B2, or the ground such that the front face Fl of the connected mobile terminal 1 faces or substantially faces the user U. The inclination angle tetal is measured by an inertial unit le included in the connected mobile terminal 1.

[0282] In another variant, the access intention action detected by the connected mobile terminal consists, with reference to Figure 15, of a predefined impact movement of the user U on the connected mobile terminal, such as a tap.

[0283] When detected by a geolocation beacon Bl, B2, B3, B4, B5, B6, in a first variant, the at least one access intention action may correspond, with reference to Figure 16, to a detection of a contact tou of the user U on said geolocation beacon Bl, B2, B3, B4, B5, B6. The contact tou is detected by at least one sensor sensBl, sensB2, sensB3, sensB4, sensB5, sensB6 that the geolocation beacon Bl, B2, B3, B4, B5, B6 comprises and which is chosen from a key, a mechanical sensor, a capacitive sensor, and an inductive sensor. The contact tou of the user U may non-exhaustively relate to:

[0284] - a contact of a hand of the user U on a part of the geolocation beacon close to the starting point Bl, detected for example by means of electrostatic sensors (inductive sensor or capacitive sensor);

[0285] - pressing a key or button included in the geolocation beacon close to departure Bl on its hull or on a touchpad.

[0286] The detection of at least one action of access intention by contact tou of the user U on the geolocation beacon Bl, B2, B3, B4, B5, B6 implies that it is accessible to the latter. In other words, it must be fixed to a wall and not to the ceiling.

[0287] The access intention action detected by the geolocation beacon Bl, B2, B3, B4, B5, B6 may also correspond, in a second variant, to a detection by the at least one sensor sensBl, sensB2, sensB3, sensB4, sensB5, sensB6 of a proximity approach of the user U within a given activation distance d-act relative to the geolocation beacon Bl, B2, B3, B4, B5, B6, which may be fixed to a wall, as illustrated in Figurel7, or to the ceiling. The at least one sensor sensBl, sensB2, sensB3, sensB4, sensB5, sensB6 is chosen from a capacitive sensor, an inductive sensor, a radar sensor, an ultrasonic sensor, an optical sensor, a vibration sensor. Thus, the detection of the proximity approach of the user U may, without limitation, relate to: - detection of the movements of the user U or connected mobile terminal 1 by a motion sensor (for example, a passive infrared motion sensor or other optical sensor);

[0288] - vibrations caused by the user's steps on the ground, which are detected by an accelerometer;

[0289] - detection by a microphone of noises caused by the user's footsteps on the ground.

[0290] In this second variant, the at least one sensor sensB1, sensB2, sensB3, sensB4, sensB5, sensB6 detecting an approach of the user U or of his connected mobile terminal 1 can be integrated into the geolocation beacon Bl, B2, B3, B4, B5, B6 or remote from it. For example, the remote sensor can be contained in a housing which also comprises a push button which the user U presses, which housing is fixed to a wall of the space in which one or more geolocation beacons Bl, B2, B3, B4, B5, B6 are located and: either is physically connected to one of the geolocation beacons which is shaped to implement the detection of the access intention action; or communicates with it by means of a wireless communication protocol (for example, in Bluetooth Low Energy BLE®).

[0291] The geolocation beacon Bl, B2, B3, B4, B5, B6 shaped to detect the access intention action is called the starting near geolocation beacon. In the remainder of the description, the starting near geolocation beacon is considered to be also the first near geolocation beacon Bl.

[0292] At the end of the validation phase, the equipment (i.e. the connected mobile terminal or the geolocation beacon close to the departure Bl) having detected the at least one access intention action is configured to generate additional access intention information i-act.

[0293] The validation phase may consist of a combination, or a succession, of detections of access intention actions of the user U. In other words, the at least one access intention action may comprise several access intention actions.

[0294] As indicated above, the validation phase conditions the implementation of the GeoP geolocation phase; meaning that it is carried out before the latter.

[0295] Thus, in different embodiments of the invention, the validation phase can be implemented before and / or after the scanning phase. In other words, the validation phase can consist of:

[0296] - the detection of one or more access intent actions occurring after the ScanP scanning phase; or

[0297] - the detection of one or more access intent actions occurring before the ScanP scanning phase; or

[0298] - detecting multiple access intents such that at least one of the multiple access intent actions is detected before the ScanP scanning phase, and such that at least one other of the multiple access intent actions is detected after the ScanP scanning phase.

[0299] The secure access control method 100 provides that when the validation phase comprises a detection of at least one access intention action before the scanning phase, said at least one access intention action conditions the implementation of the scanning phase ScanP. In other words, the connected mobile terminal implements the scanning phase P, that is to say that it initiates the secure telemetry steps SRI, SR2, only on the condition of containing the additional access intention information i-act.

[0300] In the first case, it stores the additional i-act access intention information transmitted to it by the nearby geolocation beacon B1 if the latter is responsible for detecting at least one access intention action.

[0301] In a second case, the additional i-act access intention information is generated directly by the connected mobile terminal 1 if it is responsible for detecting at least one access intention action.

[0302] When the at least one action intent includes multiple access intent actions:

[0303] - when the validation phase is based on the detection of said access intention actions after the scanning phase ScanP; the additional access intention information i-act is generated upon detection of the last of the several access intention actions;

[0304] - when the validation phase is based on the detection of said access intention actions before the scanning phase ScanP; the additional access intention information i-act is generated upon detection of the last of the several access intention actions;

[0305] - when the validation phase is based on the detections of access intention actions occurring before and after the ScanP scanning phase; the additional access intention information i-act is generated upon detection of the last of the several access intention actions having been detected before the ScanP scanning phase.

[0306] The first case is illustrated in Figure 18. In this embodiment, the validation phase consists of detecting the prox approach of the connected mobile terminal 1 of the user U within the activation distance d-act of the starting near geolocation beacon Bl. During the prox approach detection, the starting near geolocation beacon Bl generates the complementary access intention information i-act. Following the detection, the starting near geolocation beacon Bl transmits to the connected mobile terminal 1 during a transmission step E20 the complementary access intention information i-act. Following the reception of the complementary access intention information i-act during a reception step E20', the connected mobile terminal then implements the scanning phase ScanP for which it is considered that the secure telemetry steps SRI, SR2 take place similarly to those of the embodiment presented in Figure 3.

[0307] It is also considered in this embodiment that the connected mobile terminal 1 communicates with the access center 2; and that the access center is in charge of the geolocation phase GeoP. At the end of the scanning phase, the connected mobile terminal transmits to the access center during a transmission step E7 at least the identification data of the user U, the beacon data packets dataB1, dataB2, and the additional access intention information i-act.

[0308] Following their reception during a reception step E7', the access center 2 successively implements the geolocation phase GeoP as previously described; and the access control phase CP for which at least: it verifies the additional access intention information i-act, and whether the user U has the access rights required to access the second secure space E2 protected by the target bay DC, which it identified during the geolocation phase GeoP, by verifying for this the identification data of the user udata.

[0309] The second case is illustrated in Figure 19. Here, at the start of the secure access control method 100, the user U must unlock his connected mobile terminal 1 if he wishes it to initiate the secure telemetry steps SRI, SR2 with the nearby geolocation beacons Bl, B2. The unlocking ulock of the connected mobile terminal causes it to generate the additional access intention information i-act which it will then store. It is considered that the secure access control method 100 then continues similarly to that of Figure 18.

[0310] With reference to Figure 20, in another embodiment, the validation phase consists of the detection of a first access intention action actl and a second access intention action act2 after the scanning phase ScanP has been implemented, for which it is considered that the secure telemetry steps SRI, SR2 take place similarly to those of Figure 10. The user U must first proceed to unlock ulock of his connected mobile terminal 1; this is the first access intention action actl. The unlocking ulock has the effect of automatically launching the access validation application l-app from which the user will carry out the validation action opt; this is the second access intention action act2. The additional access intention information i-act is generated by the connected mobile terminal upon detection of the second access intention action act2.

[0311] In this embodiment, it is considered that the connected mobile terminal 1 proceeds to the Geolocation phase GeoP following the generation of the additional access intention information i-act, and that it proceeds to the ESid signature step of the identifier of the target bay id-DC.

[0312] It is also considered that the connected mobile terminal 1 is in direct communication with the access center 2. Thus, it transmits to the latter during a transmission step E8 at least the user identification data udata, his position locl, the certified identifier of the target bay sid-DC, and the additional access intention information i-act.

[0313] Following their reception during a reception step E8', the access center 2 implements the access control phase CP during which at least: it checks the certified identifier of the target bay id-DC, verifies by means of the user identification data udata whether the user U has the necessary accreditations to access the secure space E2 protected by the target bay DC, and verifies the additional access intention information i-act.

[0314] For all the embodiments presented so far, it is considered that at the start of the secure access control method 100, the Ultra Wideband transceiver U1 of the connected mobile terminal 1 and the Ultra Wideband transceivers UB1, UB2, UB3, UB4, UB5, UB6 of the geolocation beacons Bl, B2, B3, B4, B5, B6 are awakened (therefore capable of transmitting and receiving in Ultra Wideband).

[0315] Other embodiments consider that at the start of the secure access control method 100, the Ultra Wideband transceiver U1 of the connected mobile terminal 1 is in a standby state, being only capable of receiving in Ultra Wideband. It must therefore be woken up to initiate the secure telemetry steps SRI, SR2 with the nearby geolocation beacons B1, B2.

[0316] These embodiments thus provide that the validation phase comprises at least one access intention action taking place before the scanning phase ScanP, and that this access intention action, once detected, causes the switch, during a wake-up step WP-1 of the Ultra Wideband transceiver U1 of the connected mobile terminal 1 from the standby state to the awake state. In the embodiment presented in Figure 21, which corresponds to the preferred embodiment of the invention, the validation phase comprises a first access intention action act1 and a second access intention act2.

[0317] The first validation action actl, carried out by the user U on his connected mobile terminal at the start of the secure access control method 100, consists of unlocking it ulock. Unlocking ulock causes both the generation of the additional access intention information i-act by the connected mobile terminal 1, and the waking up of its Ultra Wide Band transmitter U1 during the waking up step WP-1 which follows the detection.

[0318] Following the wake-up step WP-1, the connected mobile terminal initiates the secure telemetry steps SRI, SR2 with the nearby geolocation beacons Bl, B2. In the preferred embodiment, the connected mobile terminal 1 is configured to calculate during the two secure telemetry steps SRI, SR2 the certified distances sdistBl, sdistB2 which separate it from the nearby geolocation beacons Bl, B2 during the calculation steps ECB1, ECB2.

[0319] It is also considered in this embodiment that during the secure telemetry steps SRI, SR2, each of the nearby geolocation beacons B1, B2 transmits during a transmission step SR14, SR24 to the connected mobile terminal 1 security data datal2, data22; the connection address add-c,; and its identifier idB1, idB2. In a first variant, the calculation steps ECB1, ECB2 can take place before the transmission step SR14, SR24. In another variant, and as illustrated in Figure 21, the calculation steps ECB1, ECB2 occur after reception by the connected mobile terminal 1 of the security data datal2, data22, the connection address add-c, and the identifier idB1, idB2 of the nearby geolocation beacons B1, B2 during a reception step SR14', SR24'.

[0320] In this preferred embodiment, the connected mobile terminal 1 is able to connect to the access center 2 and communicate directly with it, which implements the GeoP geolocation phase.

[0321] However, the connected mobile terminal transmits at least the user identification data udata, the beacon data packets dataBl, dataB2, and the additional access intention information i-act during the transmission step E7 only on condition that the user performs, following the scanning phase ScanP, the second access intention action act2.

[0322] The second access intention action act2 corresponds to the opt validation action carried out from the access validation application l-app. The preferred embodiment provides that the access validation application l-app executes and is displayed on the screen of the connected mobile terminal 1 automatically at the end of the implementation of the scanning phase ScanP.

[0323] Following the detection of the second validation action act2, the connected mobile terminal performs the transmission step E7 previously described. Following the reception step E7', the access center 2 performs the geolocation phase GeoP and the access control phase CP similarly to the embodiment illustrated in Figure 19.

[0324] In a variant of the preferred embodiment of the invention, the connected mobile terminal does not have network access to communicate with the access center 2. In this case, following the detection of the second access intention action act2, the connected mobile terminal transmits the beacon data packets dataB1, dataB2, the user identification data udata and the additional access intention information to the first nearby geolocation beacon B1 which relays them to the access center (by direct communication or by communication from one to another).

[0325] At the start of the secure access control method 100, it is possible for the geolocation beacons B1, B2, B3, B4, B5, B6 to be in a standby state in order to reduce their energy consumption, in particular if they are powered by means of an integrated rechargeable battery in order to save the latter.

[0326] Essentially, it is necessary to wake up the Ultra Wide Band transceiver UB1, UB2, UB3, UB4, UB5, UB6 of the geolocation beacons Bl, B2, B3, B4, B5, B6 so that the connected mobile terminal 1 can initiate secure telemetry steps with them. More precisely, it is necessary at least to wake up the Ultra Wide Band transceiver of the geolocation beacons located near the starting near geolocation beacon, for example that of the geolocation beacons located in the same space as the starting near geolocation beacon. In the application context illustrated from Figure 1, it is necessary at least to wake up the transceivers UB1, UB2 of the beacon Bl, which corresponds to the starting near geolocation beacon, and the beacon B2 to carry out the secure telemetry steps SRI SR2.

[0327] The Ultra Wide Band transceivers UB3, UB4, UB5, UB6 of the other geolocation beacons B3, B4, B5, B6 must be woken up in a configuration for which the information necessary for the access control unit 2 to implement the access control phase CP (and possibly previously the geolocation phase GeoP) is transmitted by means of Ultra Wide Band communication from one to the next between geolocation beacons Bl, B2 B3, B4, B5, B6.

[0328] With reference to Figure 23, the secure access control method 100 is then designed such that the at least one access intention action comprises an access intention action detected before the implementation of the scanning phase ScanP by the starting near-end geolocation beacon Bl. This may be either the detection of a prox approach, or the detection of a tou contact (as explained previously, the detection of a tou contact implies that the starting near-end geolocation beacon Bl is, in terms of installation, accessible to the user U). Following the detection of the access intention action, corresponding in Figure 23 to a tou contact, the Ultra Wide Band transceiver UB1 of the starting near-end geolocation beacon Bl switches from the standby state to the awake state during a wake-up step WP-B1.

[0329] The detection of the tou contact also causes the generation of the additional i-act access intention information.

[0330] Following the WP-B1 wake-up step, in the embodiment described in Figure 22, the near-departure geolocation beacon Bl is configured to transmit:

[0331] - during a transmission step E9, the additional access intention information i-act and an acknowledgment signal ackl to the connected mobile terminal 1, whose Ultra Wideband transceiver is considered to be awake at the start of the secure access control method 100; and

[0332] - during a transmission step E10, transmit a wsb beacon wake-up signal to, at a minimum, the nearby geolocation beacon B2.

[0333] Following the reception of the beacon wake-up signal wsb during a reception step E10', the Ultra Wide Band transceiver UB2 of the near geolocation beacon B2 switches in turn during a wake-up step WP-B2 from the standby state to the awake state. The near geolocation beacon B2 then transmits during a transmission step Eli an acknowledgment signal ack2 to the connected mobile terminal 1.

[0334] In this embodiment, the connected mobile terminal 1 is configured to initiate the secure telemetry step with each of the two beacons B1, B2 immediately after receiving their acknowledgment signal ackl, ack2 during a reception step E9', E11'. Thus, following the reception step E9, the connected mobile terminal proceeds to the first secure telemetry step SRI with the starting near-end geolocation beacon B1. It is then at the end of the first secure telemetry step SRI that the starting near-end geolocation beacon B1 proceeds to the transmission step E10 from which all of the steps E10', WB-2, E11, E11' then follow to result in the implementation of the second secure telemetry step SR2. In other words, the waking up of the near-end geolocation beacon B2 takes place during the scanning phase ScanP.

[0335] In one variant, a time delay is defined between the moment when the connected mobile terminal 1 receives the acknowledgment signal from a nearby geolocation beacon and the moment when it initiates a secure telemetry step with it. In such a configuration, it is conceivable that the mobile terminal receives all of the acknowledgment signals from the nearby geolocation beacons before implementing the secure telemetry steps which are then carried out successively. In other words, in this variant, the steps E10, E10', WP-B2, Eli, Eli' take place chronologically before the secure telemetry steps SRI, SR2.

[0336] In the embodiment shown in Figure 22, the steps SRI, SR2, E7, E7', GeoP, CP take place similarly to those of the embodiments shown in Figure 18 and Figure 19.

[0337] Finally, it is conceivable that at the start of the secure access control method 100, the Ultra Wideband transceivers UB1, UB2 UB3, UB4, UB5, UB6 of the connected mobile terminal 1 and the geolocation beacons Bl, B2 B3, B4, B5, B6 are all in the standby state.

[0338] With reference to Figure 23 which illustrates an embodiment of this configuration case, the secure access control method 100 is designed such that the at least one access intention action comprises, at the start thereof, the detection of a prox approach of the user U or of his connected mobile terminal 1 or, as illustrated here, of a contact tou of the user U. Following the awakening of its Ultra Wide Band transceiver UB1 during the awakening step WP-B1, the starting near geolocation beacon is configured to transmit to the connected mobile terminal, during a transmission step E12', the complementary access intention information i-act as well as a wake-up signal wsl.

[0339] Following reception of the wake-up signal during a reception step E12', the Ultra Wide Band transceiver UB1 of the connected mobile terminal switches from the standby state to the awake state during the wake-up step WP-1.

[0340] The wake-up signal wsl also acts as an acknowledgment signal, so that the connected mobile terminal 1, once the wake-up step is complete, can initiate the first secure telemetry step SRI with the starting near-end geolocation beacon Bl. The principle of waking up the Ultra Wide Band transceiver UB2 of the near-end geolocation beacon B2, and possibly those UB3, UB4, UB5, UB6 of the other geolocation beacons B3, B4, B5, B6 remains the same as that described in the previous embodiment.

[0341] In the embodiment presented in Figure 23, it is considered that the secure access control method 100 takes place identically to that described just previously and illustrated in Figure 22 from the start of the implementation of the first step of secure telemetry SRI.

[0342] Otherwise, in the embodiments shown in Figure 22 and Figure 23, and as indicated previously, the at least one access intention action may comprise, in addition to that used for implementing the wake-up step WP-B1, other access intention actions performed by the user U on his connected mobile terminal 1, for example an access intention action following the scanning phase ScanP and which is necessary to start the geolocation phase GeoP, like the embodiments shown in Figures 20 and 21.

Claims

CLAIMS 1. Secure access control method (100) for controlling and authorizing a user (U) to access secure spaces (El, E2, E3, E4) accessible by access control bays (DC, D2, D3, D4, D5) each equipped with a locking / unlocking system, the secure access control method (100) involving several pieces of equipment (1, Bl, B2, B3, B4, B5, B6, 2) including: - a connected mobile terminal (1) carried by the user (U) and containing at least user identification data (udata), said connected mobile terminal (1) comprising at least one Ultra Wide Band transceiver (Ul), - geolocation beacons (B1, B2, B3, B4, B5, B6) each comprising at least one Ultra Wide Band transceiver (UB1, UB2, UB3, UB4, UB5, UB6), - an access center (2) which is connected to the locking / unlocking systems of the several access control bays (DC, D2, D3, D4, D5), and in communication at least with the connected mobile terminal (1); the secure access control method (100) implementing at least the following steps: - a scanning phase (ScanP) in which the connected mobile terminal (1) initiates secure telemetry steps (SRI, SR2) with several geolocation beacons (Bl, B2), called nearby geolocation beacons, among the geolocation beacons (Bl, B2, B3, B4, B5, B6), said nearby geolocation beacons (Bl, B2) having their respective Ultra Wide Band transceivers (UB1, UB2) within a communication range of the Ultra Wide Band transceiver (Ul) of said connected mobile terminal (1), said secure telemetry steps (SRI, SR2) operating in respective Ultra Wide Band communication channels and at the end of which are determined and stored in the connected mobile terminal (1) beacon data packets (dataBl, dataB2) associated with each of the nearby geolocation beacons (Bl, B2), where each of the beacon data packets (dataBl, dataB2) includes at least one identifier (id Bl,idB2) of the associated near geolocation beacon (Bl, B2), transmitted by said near geolocation beacon (Bl, B2) to the connected mobile terminal (1), and a certified distance (sdistBl, sdistB2) between the connected mobile terminal (1) and said associated near geolocation beacon (Bl, B2);, - a geolocation phase (GeoP) in which the connected mobile terminal (1) is geolocated in a plane (P) from said beacon data packets (databl, datab2), which plane (P) locates at least part of the access control bays (DC, D2, D3, D4, D5) and at least the nearby geolocation beacons (Bl, B2) among the geolocation beacons (Bl, B2, B3, B4, B5, B6), and at the end of which a position (locl) of the connected mobile terminal (1) is determined in the plane (P) and an access control bay (DC), called the target bay, is identified, which is the closest to the connected mobile terminal (1) among the access control bays (DC, D2, D3, D4, D5) present in said plane (P); - an access control phase (CP) implemented by the access center (2), which verifies at least the user identification data (udata) sent from the connected mobile terminal (1) to the access center (2), to authorize or not access to the secure space (E2) accessible by the target bay (DC) and, if necessary, control the locking / unlocking system of said target bay (DC).

2. Secure access control method (100) according to claim 1, wherein during each of the secure telemetry steps (SRI, SR2) carried out between the connected mobile terminal (1) and a nearby geolocation beacon (Bl; B2) among the nearby geolocation beacons (Bl, B2), the certified distance (sdistBl, sdistB2) between the connected mobile terminal (1) and said nearby geolocation beacon (Bl, B2) is calculated by at least one of the connected mobile terminal and said nearby geolocation beacon (Bl, B2).

3. Secure access control method (100) according to claim 1 or 2, wherein the access center (2) contains the plan (P), and implements the geolocation phase (GeoP) after having received at least the user identification data (udata) and the beacon data packets (dataBl, dataB2) from the connected mobile terminal (1).

4. Secure access control method (100) according to claim 3, wherein the access center (2) receives at least the user identification data (udata) and the beacon data packets (dataB1, dataB2) from the connected mobile terminal (1): - either directly from the connected mobile terminal (1), which connected mobile terminal (1) has network access and contains a connection address (add-c) to connect remotely to the access center (2) and communicate with it; - either indirectly through one or more geolocation beacons (Bl; B2; B3; B4; B5; B6) among the geolocation beacons (Bl, B2, B3, B4, B5, B6), which geolocation beacons (Bl, B2, B3, B4, B5, B6) have network access for communicate with the access center (2), via direct communication or via close communication.

5. Secure access control method (100) according to claim 1 or 2, wherein the connected mobile terminal (1) contains the plan (P), and implements the geolocation phase (GeoP) once the beacon data packets (dataBl, dataB2) of the nearby geolocation beacons (Bl, B2) are stored in the connected mobile terminal (1); and at the end of which at least one certified identifier of the target bay (sid-DC) is then transmitted to the access center (2) with the user identification data (udata).

6. Secure access control method (100) according to claim 5, wherein the plan (P) loaded into the connected mobile terminal (1) identifies all the access control bays (DC, D2, D3, D4, D5) and all the geolocation beacons (B1, B2, B3, B4, B5, B6).

7. Secure access control method (100) according to claim 5, wherein the plan (P) loaded into the connected mobile terminal (1) is a local plan locating a part of the access control bays (DC, D2) and the nearby geolocation beacons (Bl, B2), said local plan being constituted by the connected mobile terminal (1) during a construction step (BS) from plan pieces (PI, P2) communicated to the connected mobile terminal (1) by each of the nearby geolocation beacons (Bl, B2) during the secure telemetry steps (SRI, SR2); the plan piece (Pl, P2) associated with each of the nearby geolocation beacons (Bl, B2) locating the nearby geolocation beacon concerned (Bl, B2) and at least one access control bay (DC, D2) in the vicinity of said nearby geolocation beacon (Bl, B2).

8. Secure access control method (100) according to any one of claims 5 to 7, wherein the connected mobile terminal (1) determines its position (locl), the target bay (DC) and the identifier of the target bay (id-DC) from the plan (P).

9. Secure access control method (100) according to any one of claims 5 to 8, wherein the access center (2) receives at least the user identification data (udata), the position (locl) of the connected mobile terminal (1), and the certified identifier of the target bay (sid-DC) directly from the connected mobile terminal (1), which connected mobile terminal (1): - signs the target bay identifier (id-DC) to form the certified target bay identifier (sid-DC), and - has network access and contains a connection address (add-c) to remotely connect to the access center (2) and communicate with it.

10. Secure access control method (100) according to claim 4 or 9, wherein the connection address (add-c) corresponds to data previously loaded into the connected mobile terminal (1), or corresponds to data transmitted to the connected mobile terminal (1) from one of the nearby geolocation beacons (B1, B2) during one of the secure telemetry steps (SRI, SR2).

11. Secure access control method (100) according to any one of claims 5 to 8, wherein the connected mobile terminal (1) transmits to a nearby geolocation beacon (B1), called the first nearby geolocation beacon, among the nearby geolocation beacons (B1, B2) at least the user identification data (udata), the position (locl) of the connected mobile terminal (1) and the target bay identifier (id-DC), which first nearby geolocation beacon (B1) timestamps the target bay identifier (id-DC) to thus form the certified target bay identifier (sid-DC), and the access center (2) receives at least the user identification data (udata) and the certified target bay identifier (sid-DC) indirectly through one or more geolocation beacons (B1, B2, B3, B4, B5, B6) among the beacons geolocation (Bl, B2, B3, B4, B5, B6),comprising at least the first nearby geolocation beacon (Bl); which geolocation beacons (Bl, B2, B3, B4, B5, B6) have network access to communicate with the access center (2), via direct communication or via near-near communication., 12. Secure access control method (100) according to any one of the preceding claims, wherein the secure access control method (100) comprises a validation phase during which: - the connected mobile terminal (1) or one of the nearby geolocation beacons (Bl; B2) among the nearby geolocation beacons (Bl, B2) detects at least one access intention action (actl, act2) carried out by the user (U); - and then additional access intention information (i-act) is generated by the connected mobile terminal (1) or one of the nearby geolocation beacons (Bl; B2) among the nearby geolocation beacons (Bl, B2) after detection of at least one access intention action (actl, act2); and in which at least one of the scanning phase (ScanP) and the geolocation phase (GeoP) is implemented at least on the condition of prior completion of the validation phase.

13. Secure access control method (100) according to claim 12, wherein the scanning phase (ScanP) is carried out on the condition of the performance of the at least one access intention action (actl, act2), so that the connected mobile terminal (1) initiates the secure telemetry steps (SRI, SR2) after generation or reception by the connected mobile terminal (1) of the complementary access intention information (i-act).

14. Secure access control method (100) according to claim 12 or 13, wherein the at least one access intention action (actl, act2) comprises a first access intention action (actl) and a second access intention action (act2) such that: - the scanning phase (ScanP) is implemented on the condition that the first access intention action (actl) has been carried out beforehand, and - the geolocation phase (GeoP) is implemented on the condition that the second access intention action (act2) is carried out beforehand, and following the implementation of the scanning phase (ScanP); the additional access intention information (i-act) being generated by the mobile terminal (1) or by one of the nearby geolocation beacons (Bl; B2) among the nearby geolocation beacons (Bl, B2) after detection of the first access intention action (actl).

15. Access control method (100) according to claim 3, in combination with any one of claims 12 to 14, wherein the connected mobile terminal (1) transmits to the access center (2) at least the user identification data (udata) and the beacon data packets (dataB1, dataB2), so that said access center (2) can carry out the geolocation phase (GeoP), on condition of the prior implementation of the validation phase.

16. Secure access control method (100) according to any one of claims 12 to 15, in which the complementary access intention information (i-act) is transmitted to the access center (2) with at least the user identification data (udata); and during the access control phase (CP), the center access (2) also checks said additional access intention information (i-act) to authorize or not access to the secure space (E2).

17. Secure access control method (100) according to claim 16, in combination with claim 3 or 4, wherein the access center (2) receives from the connected mobile terminal (1) at least the beacon data packets (dataB1, dataB2), the additional access intention information (i-act) and the user identification data (udata) following completion of the validation phase.

18. Secure access control method according to any one of claims 12 to 17, wherein during the validation phase, the at least one access intention action (actl, act2) is detected by the connected mobile terminal (1) and corresponds to: - a predefined impact (tap) or displacement (inc) movement of the connected mobile terminal (1) detected by an accelerometer (al) integrated into the connected mobile terminal (1); - an unlocking action (ulock) by the user of the connected mobile terminal (1) to switch it from a locked state to an unlocked state; - an access validation action (opt) carried out by the user (U) of the connected mobile terminal (1) on an access validation application (l-app) loaded in the connected mobile terminal (1).

19. Secure access control method (100) according to claims 14 and 18, wherein the first access intention action (actl) and the second access intention action (act2) are detected by the connected mobile terminal (1), and such that: - the first access intention action (actl) corresponds to the unlock action (ulock), and - the second access intention action (act2) corresponds to the access validation action (opt).

20. Secure access control method (100) according to any one of claims 12 to 18, wherein during the validation phase, the at least one access intention action (actl, act2) corresponds to a detection by at least one sensor (sensBl) of: - a contact (tou) of the user (U) on a nearby geolocation beacon (Bl), called nearby geolocation beacon of departure, among the nearby geolocation beacons (Bl, B2); or - an approach (prox) of the user (U) or the connected mobile terminal (1) to a nearby geolocation beacon (Bl), called the starting nearby geolocation beacon, among the nearby geolocation beacons (Bl, B2) within a given activation distance (d-act) relative to said starting nearby geolocation beacon (Bl); and in which said starting nearby geolocation beacon (Bl) generates the additional access intention information (i-act).

21. Secure access control method (100) according to claim 20, wherein the at least one sensor (sensBl) is chosen from a mechanical sensor, a capacitive sensor, an inductive sensor, a radar sensor, an ultrasonic sensor, an optical sensor, a vibration sensor.

22. Secure access control method (100) according to claim 20 or 21, wherein the at least one sensor (sensBl) is mounted on the near-start geolocation beacon (Bl), or is remote from said near-start geolocation beacon (Bl) and connected thereto.

23. Secure access control method (100) according to any one of claims 20 to 22, wherein at the start of the secure access control method (100), the Ultra Wide Band transceiver (UB1, UB2, UB3, UB4, UB5, UB6) of each of the geolocation beacons (B1, B2, B3, B4, B5, B6) is in a standby state being only able to receive in Ultra Wide Band, and wherein, following detection of at least one access intention action (act1, act2) by the starting near geolocation beacon (B1), at least the Ultra Wide Band transceiver (UB1) of the starting near geolocation beacon (B1) switches to a wake-up state being able to transmit and receive in Ultra Wide Band, so that the connected mobile terminal (1) can initiate the secure telemetry step (SRI) with said beacon geolocation close to departure (Bl).

24. Secure access control method according to claim 23, wherein following the detection of at least one access intention action (actl, act2) by the starting near geolocation beacon, said starting near geolocation beacon (Bl) sends to each of the other near geolocation beacons (B2) among the near geolocation beacons (Bl, B2) within range of communication a wake-up signal (wsb) in Ultra Wide Band so that their respective transceiver (UB2) also switches to the awake state; this is so that the connected mobile terminal (1) can initiate the secure telemetry steps (SRI, SR2).

25. Secure access control method (100) according to any one of claims 12 to 24, wherein at the start of the secure access control method (100), the Ultra Wide Band transceiver (Ul) of the connected mobile terminal (1) is in a standby state, being only capable of receiving in Ultra Wide Band, and wherein the at least one access intention action (actl, act2) detected by the connected mobile terminal (1) during the validation phase switches the Ultra Wide Band transceiver (Ul) of the connected mobile terminal (1) into a wake-up state making it capable of transmitting and receiving in Ultra Wide Band, and consequently capable of initiating the scanning phase (ScanP).

26. Secure access control method (100) according to claims 18 and 25, wherein the first access intention action (actl) detected by the connected mobile terminal (1) during the validation phase, and which corresponds to the unlocking action (ulock), switches the Ultra Wide Band transceiver (Ul) of the connected mobile terminal (1) into an awake state making it capable of transmitting and receiving in Ultra Wide Band, and consequently capable of initiating the scanning phase (ScanP).

27. Secure access control method (100) according to claim 23 or 24, wherein at the start of the secure access control method (100), the Ultra Wide Band transceiver (Ul) of the connected mobile terminal (1) is in a standby state, being only capable of receiving in Ultra Wide Band, and wherein following the detection of the at least one access intention action (actl, act2) by the near-start geolocation beacon (Bl), said near-start geolocation beacon (Bl) sends to the connected mobile terminal (1) a wake-up signal (wsl) in Ultra Wide Band which, when received by the connected mobile terminal (1), switches the Ultra Wide Band transceiver (Ul) thereof into a wake-up state, making it capable of receiving and transmitting in Ultra Wide Band, and therefore capable of initiating the scanning phase (ScanP).