Secure access control method operating in ultra-wideband communication mode to grant access to a secure space to a user following the unlocking of their connected mobile terminal
Patent Information
- Authority / Receiving Office
- EP · EP
- Patent Type
- Applications
- Current Assignee / Owner
- SYSTEMES ET TECHNOLOGIES IDENTIFICATION (STID)
- Filing Date
- 2024-07-04
- Publication Date
- 2026-05-20
AI Technical Summary
Current secure access control systems using Ultra Wide Band communication mode for authorizing access to secure spaces face security vulnerabilities and energy consumption issues, as they remain constantly activated, potentially allowing unauthorized access and increasing battery drain due to continuous data exchanges.
A secure access control method that initializes Ultra Wide Band communication only upon user intention to access a secure space by waking up the Ultra Wide Band transceiver of the connected mobile terminal after unlocking, limiting data exchanges to when access is intended, thereby reducing power consumption and enhancing security.
This approach strengthens security by ensuring data exchanges occur only when access is intended, reducing unauthorized access risks and conserving battery life by minimizing unnecessary communication.
Smart Images

Figure FR2024050905_16012025_PF_FP_ABST
Abstract
Description
[0001] DESCRIPTION
[0002] TITLE: Secure access control method operating in an Ultra Wide Band communication mode to authorize access to a secure space for a user following the unlocking of their connected mobile terminal
[0003] [Technical field]
[0004] The invention relates to a secure access control method for authorizing or not authorizing access to a user to a secure space.
[0005] It relates more particularly to a secure access control method based on the Ultra Wide Band radio frequency communication mode.
[0006] The invention finds a preferred application in the implementation of a secure access control method involving an access center at which, via a secure access control reader, a user authenticates himself by means of a connected mobile terminal; the secure access control reader and the connected mobile terminal both operating in the Ultra Wideband radio frequency communication mode and exchanging data for the authentication of the user in this same communication mode.
[0007] [State of the art]
[0008] Ultra Wide Band is a radio frequency modulation technique that has recently become more widespread and is based on the transmission of pulses generally less than a nanosecond and used in a wide frequency band, between 3.1 GHz and 10.6 GHz. Among the advantages of Ultra Wide Band communication: a very high network data transfer rate over a wide bandwidth (greater than 500 MHz) over relatively short distances and at low power, without interfering with conventional narrowband and carrier wave transmissions in the same frequency bands. By misuse of language, radio frequency systems using this modulation technique to exchange data are said to communicate in an Ultra Wide Band communication mode.
[0009] Ultra Wideband technology is promising and is now being considered in the design of geolocation, tracking, pairing (point-to-point data transfer), payment, and access control solutions. Indeed, some mobile phone models available on the market integrate Ultra Wideband transceivers allowing them to communicate and exchange information in Ultra Wideband.
[0010] This is why secure access control readers are designed incorporating Ultra Wide Band transceivers so that access control solutions can be implemented to authorize or not a user to access a secure area, protected by an access control bay (door, airlock, barrier, etc.) equipped with a locking / unlocking system, which operate in the Ultra Wide Band communication mode, and for which the user identifies / authenticates himself, via a secure access control reader, with an access control center installed in the building and connected to the locking / unlocking system of the access control bay, by means of a mobile phone incorporating an Ultra Wide Band transceiver.Once the user has approached the secure access control reader so that it can detect the mobile phone, a stage called secure ranging begins during which the secure access control reader and the mobile phone exchange data, using a secure communication protocol, in order to authenticate the user. This data may, for example, include virtual identification keys, a user ID, etc. The data is transmitted by the secure access control reader to the access control center installed in the building and connected to the locking / unlocking system of the access control bay. Following receipt of the data, the access control center verifies it and, depending on the result of this verification, authorizes or denies access to the secure area by controlling the locking / unlocking system of the access control bay.Secure telemetry, carried out within the framework of an Ultra Wide Band exchange, reinforces the security of exchanges during point-to-point data transfers, by drastically limiting the risks of interception of the data transfer between a transmitter and a receiver, i.e. “man in the middle” attacks.
[0011] Detailed explanations on the operating principle of secure ranging are given by N.O. Tippenhauer and S. Capkun in the technical report “UWB-based secure ranging and localization” published in 2012 (Technical Report / ETH Zurich, Department of Computer Science 586); in the article “UWB with Pulse Reordering: Secure Ranging against Relay and Physical-Layer Attacks” written by M. Singh, P. Leu, and S. Capkun and published in 2017 by the lACR (International Association for Cryptologic Research - Network and Distributed Systems Security (NDSS) Symposium 2019, 24-27 February 2019, San Diego, CA, USA - ISBN 1-891562-55-X); or in the white paper “UWB Secure Ranging in FiRa” by the FiRa™ consortium (August 1, 2022, XP093125607).
[0012] However, in the solutions currently proposed and available, the secure access control reader remains constantly activated in the Ultra Wide Band communication mode in order to locate the position of a mobile phone of a user equipped with an Ultra Wide Band transceiver to communicate with it and carry out secure telemetry in this communication mode.
[0013] The disadvantage of such an approach is that it presents security vulnerabilities because the detection of the mobile phone by the secure access control reader and the secure telemetry occur if the user with the mobile phone passes near the access control, whether or not they intend to access the secure area. In the case where the access control panel allows access to a user who is only passing in front of the access control reader and has no intention of access, it can potentially allow an unauthorized user to access the secure area protected by the access control bay.
[0014] Furthermore, in the case where the mobile phone remains for a certain period of time within the communication range of the secure access control reader, the latter may potentially periodically implement the secure telemetry step with the mobile phone; meaning that it will request the access center at regular intervals so that it checks the data that it transmits to it. In the case where the user of the mobile phone has access rights to access the secure area but does not wish to enter it, the periodic implementation of secure telemetry and data control by the access center may possibly result in repeated openings and closings of the access control bay.In addition to unnecessarily placing demands on the access control center, the increase in exchanges between the mobile phone, the secure access control reader, and the access control center weakens their security because it increases the risk that the data exchanged could be intercepted by a malicious system.
[0015] In order to resolve this problem, document EP 3 373 254 A1 proposes that the radiofrequency connection, established according to a long-distance wireless communication protocol, and during which data are exchanged between a connected mobile terminal of a user in order to authenticate said user, is conditioned by the implementation of an access action carried out by the bearer; the access action reflecting an intention of the user to want to access a secure space, and may for example correspond to an unlocking of the connected mobile terminal. However, the proposed secure access control method assumes that the radiofrequency transceiver of the connected mobile terminal, when it is started, is capable of receiving signals in the communication mode considered.Thus, such a solution has the disadvantage of being energy-intensive for the battery of the connected mobile terminal if applied to Ultra Wide Band because this communication protocol consumes more power than a long-distance wireless communication protocol.
[0016] [Summary of the invention]
[0017] The invention aims to address the issues raised by proposing a secure access control method for controlling and authorizing access by a user to at least one secure space accessible by at least one access control bay equipped with a locking / unlocking system, the secure access control method involving several pieces of equipment including:
[0018] - a connected mobile terminal carried by the user and containing user identification data, said connected mobile terminal comprising at least one Ultra Wide Band transceiver,
[0019] - at least one secure access control reader associated with the at least one access control bay and comprising at least one Ultra Wide Band transceiver which is, at the start of the secure access control method, in an off state for which it is configured not to transmit and not to receive signals in an Ultra Wide Band communication mode,
[0020] - an access center which is at least in communication with the access control reader and which is linked to the locking / unlocking system of the at least one access control bay; in which the secure access control method successively comprises at least:
[0021] - a step of unlocking the connected mobile terminal, causing said connected mobile terminal to switch from a locked state to an unlocked state;
[0022] - a step of waking up the Ultra Wide Band transceiver of the connected mobile terminal which is implemented on condition at least that the unlocking step has been carried out, and during which the Ultra Wide Band transceiver of the connected mobile terminal switches from the off state to a so-called woken up state in which it is configured to transmit and receive signals in the Ultra Wide Band communication mode;
[0023] - a secure telemetry step between the secure access control reader and the connected mobile terminal, during which their Ultra Wide Band transceivers exchange security data in the Ultra Wide Band communication mode, and at the end of which a certified distance is established and then verified between the secure access control reader and the connected mobile terminal; said secure telemetry step being initiated on the condition at least that the unlocking step has been previously implemented;
[0024] - an access control step during which the access center, after receiving the user's identification data, checks them to authorize or not access to the secure space accessible by the access control bay and, if necessary, controls the locking / unlocking system of said access control bay.
[0025] The implementation of the secure telemetry step assumes that the Ultra Wide Band transceivers of the secure access control reader and the connected mobile terminal are in respective states, called awake states, configured to transmit and receive signals in the Ultra Wide Band communication mode.
[0026] At the start of the secure access control process, the Ultra Wide Band transceiver of the connected mobile terminal is in a so-called off state in which it is configured not to transmit and not to receive in the Ultra Wide Band communication mode, so that it is not capable of transmitting or receiving signals in this Ultra Wide Band communication mode.
[0027] For the purposes of the invention, the Ultra Wide Band transceiver of the connected mobile terminal is considered to be in the off state when, for example:
[0028] - it is physically or electrically switched off; or
[0029] - it is switched on but its Ultra Wideband functions are deactivated, making it unable to respond to external requests from other systems using Ultra Wideband to communicate.
[0030] The Ultra Wideband features of the connected mobile terminal can be deactivated by activating, for example, an offline mode (also called airplane mode) available in said connected mobile terminal.
[0031] In order to make communication in Ultra Wide Band mode possible between the connected mobile terminal and the secure access control reader (in other words, in order to implement the secure telemetry step), the Ultra Wide Band transceiver of the connected mobile terminal switches from the off state to the awake state, in which it is, as a reminder, able to transmit and receive in Ultra Wide Band; such awakening being carried out during a wake-up step which is implemented on condition at least that the connected mobile terminal is unlocked by the user.
[0032] Thus, within the framework of the secure access control process, unlocking the connected mobile terminal reflects the user's intention to access a secure space accessible from the access control bay associated with the secure access control reader, while approaching it.
[0033] The implementation of the secure telemetry step following unlocking of the connected mobile terminal and therefore the waking up of its Ultra Wide Band transceiver allows:
[0034] - to reduce the power consumption of the connected mobile terminal by limiting the operation of its Ultra Wide Band transceiver, and therefore to save its battery;
[0035] - to optimize exchanges between the secure access control reader, the connected mobile terminal and the access center;
[0036] - to reduce the use of the access center by implementing a single access control step, at the end of which access to the secure area is authorized or refused to the user;
[0037] - in connection with the two previous points, to strengthen the security of exchanges and reduce the risks of data interception by a malicious system; and
[0038] - respond positively to the security issue mentioned above when a secure access control reader detects a user's connected mobile terminal and initiates with it a secure telemetry step which eventually leads to the unlocking of an access control bay because the user has the required accreditations, while the user does not wish to access the secure space protected by the access control bay.
[0039] During the secure telemetry phase, the connected mobile terminal and the access control reader exchange security data. At the end of the secure telemetry phase, a certified distance between the secure access control reader and the connected mobile terminal is also established and then checked.
[0040] During the access control stage, the access center checks the user's identification data (or, in English, credentials) to determine if they have the accreditations to enter the secure area.
[0041] According to different embodiments of the invention, the locking / unlocking system of the access control bay, which may for example correspond to a latch that opens and closes, may in one embodiment either be physically connected by a cable to the access center, or in another embodiment be connected to the access center via a wireless link.
[0042] According to a characteristic of the invention, the access center receives the user's identification data on the condition that previously, during the secure telemetry step, it has been verified that the certified distance is less than or equal to an authorization distance.
[0043] In other words, the transmission of the user's identification data to the access center for the implementation of the access control step is conditioned by a check of the certified distance carried out at the end of the secure telemetry step. This check of the certified distance consists of verifying whether it is included, i.e. less than or equal to, an authorization distance. If yes, the user's identification data are transmitted to the access center. If no, they are not transmitted.
[0044] This distance control is an additional security measure to ensure that the user with the required credentials is close to the secure access control reader and / or the access control bay before unlocking the access control bay locking / unlocking system. Indeed, the secure telemetry step may have been triggered following an unlocking of the connected mobile terminal of the user, who is far from the secure access control reader and has unlocked his connected mobile terminal for a reason other than wanting to access the secure area protected by the access control bay.
[0045] According to a characteristic of the invention, during the secure telemetry step, the certified distance between the connected mobile terminal and the secure access control reader is:
[0046] - established by being calculated by at least one of the connected mobile terminal and the secure access control reader; and
[0047] - verified either by the connected mobile terminal or by the secure access control reader.
[0048] The certified distance is obtained from the calculation by at least one of the connected mobile terminal and the secure access control reader of a distance between the connected mobile terminal and the secure access control reader.
[0049] In one embodiment of the invention, only one of the two devices, the connected mobile terminal and the secure access control reader, calculates the distance separating the two devices. In another embodiment of the invention, the connected mobile terminal and the secure access control reader both calculate the distance separating them. Both exchange the distance value that they have calculated. Each device then compares the distance that it has received with the distance that it has itself calculated. In the case where the consistency between the distances is not verified, the telemetry step is stopped. In the case where the consistency is verified, the telemetry step continues.
[0050] In one embodiment of the invention, the certified distance is calculated from a measurement of a flight time, carried out by at least one of the two devices, during a two-way exchange of safety data. Once the distance has been calculated.
[0051] More precisely, during the secure telemetry step a distance is calculated between the portable authentication device and the secure access control reader, said distance being by nature certified, hence the notion of certified distance.
[0052] The distance is certified by nature because it occurs during the secure telemetry step, and because it is based on at least one bidirectional exchange of Ultra Wide Band signals between two devices (the connected mobile terminal and the secure access control reader) each having for example: an embedded secure component; or trusted firmware or application previously loaded inside, or a trusted execution environment (or "Trusted Execution Environment" TEE in English).
[0053] Certified distance is an additional means of strengthening the security level of the secure access protocol when the latter must be controlled for implementation or not subsequently in the access control step. Indeed, an uncertified distance could possibly be fraudulent and come from a malicious system that seeks to gain access to the secure space protected by the access control bay. Thus, if the equipment responsible for controlling the certified distance, but not for its calculation, receives a certified distance, it implements its control. Conversely, if the received distance is not certified, the control is not carried out and the secure access control process is stopped.
[0054] As previously indicated, once the certified distance has been calculated, the secure telemetry step continues with its control to verify whether it is less than or equal to the authorization distance. The verification can be carried out by the secure access control reader, or by the connected mobile terminal. In a first embodiment variant for which the certified distance is calculated by only one of the two devices among the secure access control reader and the connected mobile terminal, the device in charge of calculating the certified distance is also the one that controls it.
[0055] In a second variant embodiment for which the equipment responsible for the calculation is not the same as that responsible for verifying the certified distance, the certified distance is transmitted from the equipment having calculated it to the equipment having to verify it.
[0056] Optionally, the secure telemetry step is not limited to the exchanges and principles described. Further information on secure telemetry is available in the two references indicated in the State of the art.
[0057] According to a characteristic of the invention, the step of unlocking the connected mobile terminal is implemented by the user according to at least one of the following operations:
[0058] - switching on a touch screen included in the connected mobile terminal by the user pressing it, or on a switch-on button also included in the connected mobile terminal;
[0059] - an operation of entering an unlocking code on the connected mobile terminal;
[0060] - a touch entry operation of an unlock pattern on a touch screen of the connected mobile terminal;
[0061] - a fingerprint recognition operation on a fingerprint sensor of the connected mobile terminal;
[0062] - a facial recognition operation of the user using a camera integrated into the connected mobile terminal.
[0063] According to a characteristic of the invention, the access center receives the user's identification data, from:
[0064] - either from the connected mobile terminal, which connected mobile terminal has network access and contains a connection address to connect remotely to the access center and communicate with it;
[0065] - either the secure access control reader, which secure access control reader has network access to communicate with the access control center, via direct communication or via step-by-step communication.
[0066] According to one embodiment of the invention, the certified distance is verified by the equipment among the connected mobile terminal and the secure access control reader responsible for transmitting the user's identification data to the access center.Knowing that the access control reader and the connected mobile terminal exchange their respective security data, in another embodiment variant for which the equipment among the connected mobile terminal and the secure access control reader verifying the certified distance is not the same as that in charge of transmitting the user's identification data to the access center, the equipment in charge of verifying the certified distance sends, if the certified distance is included in the authorization distance, an authorization signal to the equipment in charge of transmitting the user's identification data so that it implements said transmission.
[0067] In a first embodiment of the invention, the connected mobile terminal transmits to the access center the user's identification data if he has network access and a connection address to connect remotely to the access center. This first embodiment can be implemented because the secure access control reader is autonomous and is therefore not in contact with the access center.
[0068] The connection address may correspond to data previously loaded into the connected mobile terminal, or correspond to data transmitted by the secure access control reader to the connected mobile terminal when the secure telemetry step is implemented.
[0069] In a second embodiment of the invention, the user's identification data is transmitted to the access center by the secure access control reader. This configuration can be implemented because the connected mobile terminal does not have network access.
[0070] Advantageously, the calculation and verification of the certified distance, and the transmission of the user's identification data to the access center by the secure access control reader makes it possible to significantly strengthen the security level of the secure access control process since, by definition, the secure access control reader is a trusted system designed and conformed to be an integral part of an access control installation implementing secure access control processes.
[0071] In a first embodiment, the secure access control reader is in wireless communication with the access control center and transmits the user's identification data directly to it.
[0072] In a second variant, the secure access control reader and the access control center are part of a mesh network comprising several other secure access control readers. Each of the devices in the mesh network is capable of communicating with its close neighbors according to a close-to-close communication protocol. Advantageously, the mesh network addresses the problem of indoor network coverage, when the structure of the building and the materials used for its construction interfere with the transmission of signals, for example, not allowing the secure access control reader involved in the secure access control process and the access control center to communicate with each other, even if they are within communication range (for example, because they are located in the basement, or on different floors of a building, or separated by a thick wall, etc.).
[0073] Without limitation, the secure access control reader and the access control center can communicate together using a wireless communication protocol such as Wifi® or Bluetooth Mesh®.
[0074] In a third variant, the secure access control reader is wired / physically connected to the access control unit (for example, by means of Ethernet links, or an RS485 interface), meaning that it can transmit the user's identification data to it even though it does not have network access.
[0075] According to one embodiment of the invention, when the access center receives the user's identification data from the secure access control reader, the secure access control method also comprises, prior to the access control step, a transmission step during which the connected mobile terminal transmits, in the Ultra Wide Band communication mode, the user's identification data to the secure access control reader; said transmission step being implemented:
[0076] - following the unlocking step and before the secure telemetry step begins, or
[0077] - during the secure telemetry stage, or
[0078] - once the secure telemetry stage is completed
[0079] In other words, in the case where the user identification data are transmitted to the access center by the secure access control reader, it is necessary for the connected mobile terminal to implement a step of transmitting the user identification data to the secure access control reader. As indicated above, this transmission step can be implemented before, during, or after the secure telemetry step.
[0080] The implementation of the transmission step implies on the one hand that the connected mobile terminal is within communication range of the secure access control reader in the Ultra Wide Band communication mode; and on the other hand that the transceiver of the connected mobile terminal is in the awake state to be able to transmit the user's identification data to the secure access control reader.
[0081] The transmission step, if planned before the secure telemetry step, is implemented following the wake-up step.
[0082] In the case where the transmission step is planned to take place following the secure telemetry step and before the access control step, it is possible for said transmission step to be implemented on the condition that it has been verified that the certified distance is less than or equal to the authorization distance. In other words, if the certified distance is greater than the authorization distance, neither the transmission step nor the access control step are implemented. Otherwise, if the certified distance is valid, then it is possible:
[0083] - when the connected mobile terminal carries out the control and validation of the certified distance, that it transmits the user's identification data immediately after validation of the certified distance; or else
[0084] - when the secure access control reader is responsible for controlling and validating the certified distance, it sends a request signal to the connected mobile terminal after validation thereof, which connected mobile terminal, after receiving said request signal, transmits the user's identification data to the secure access control reader.
[0085] According to one embodiment of the invention, the secure access control reader periodically emits a probing signal in the Ultra Wide Band communication mode, and the telemetry step is started by the secure access control reader following the reception of a confirmation signal from the connected mobile terminal in the Ultra Wide Band communication mode; said confirmation signal being generated and then transmitted by the connected mobile terminal on the condition that at least: the step of waking up the Ultra Wide Band transceiver of the connected mobile terminal is implemented, then that the connected mobile terminal has received the probing signal once in the woken up state.
[0086] In other words, the secure control reader periodically emits into its environment (in the space in which it is located) a probing signal in the Ultra Wide Band communication mode. This probing signal can be received by the connected mobile terminal of a user if it is within the communication range of the secure access control reader, and if its Ultra Wide Band transceiver is in the awake state. As previously indicated, the awakening step is implemented at least following the unlocking of the connected mobile terminal.
[0087] Thus, when the user unlocks the connected mobile terminal, its Ultra Wideband transceiver is able to receive the probing signal. Once this is received, the connected mobile terminal generates a confirmation signal which it transmits to the secure access control reader. Upon receipt of the confirmation signal, the secure access control reader then initiates / starts the secure telemetry step.
[0088] Possibly, as the probing signal is sent periodically by the secure access control reader in its environment, it may not be received and therefore lost if a connected mobile terminal is not within the communication range of the secure access control reader at the time of its transmission, and if its Ultra Wideband transceiver is not in the awake state.
[0089] According to one embodiment of the invention, the telemetry step is started by the connected mobile terminal when at least the step of waking up the Ultra Wide Band transceiver of the connected mobile terminal is implemented, and said connected mobile terminal is within an Ultra Wide Band communication range with the secure access control reader.
[0090] In another embodiment of the invention, the secure telemetry step is initiated / started, therefore managed, by the connected mobile terminal following the switch to the awake state of its Ultra Wide Band transceiver, after unlocking the connected mobile terminal. In this other embodiment, the connected mobile terminal therefore plays the role of master. The secure access control reader, which plays the role of slave, is configured to wait for commands / instructions from the connected mobile terminal. In other words, and advantageously, the secure access control reader does not perform any action until the user's connected mobile terminal enters into communication with it.This configuration also has the advantage of reducing the power consumption of the secure access control reader in Ultra Wide Band communication mode since it does not unnecessarily emit a signal into its environment that may not be received by a connected mobile terminal.
[0091] According to one embodiment of the invention, the secure telemetry step is initiated on the condition that at least: the unlocking step is implemented, and that at least one validation action is also subsequently performed on the connected mobile terminal; otherwise the secure telemetry step is not performed. Unlocking only the connected mobile terminal does not make it possible to determine with certainty whether or not its user intends to access the secure space. Indeed, the user may, for example, while in the vicinity, or even within communication range of the secure access control reader, have unlocked their connected mobile terminal only to consult their messaging. In this case, the secure telemetry step and the access control step are performed unnecessarily.Advantageously, the fact that the secure telemetry step is carried out on the condition that the user has unlocked his mobile phone, and on the other hand that he has carried out at least one validation action with it, further confirms his intention to access the secure space.
[0092] In one embodiment of the invention, when the secure access control reader initiates the secure telemetry step following receipt of the confirmation signal from the connected mobile terminal, said confirmation signal is generated by the connected mobile terminal following its unlocking and after the user has performed the at least one validation action.
[0093] In another embodiment of the invention, the connected mobile terminal initiates the secure telemetry step following its unlocking and after the user has performed at least one validation action.
[0094] When the step of transmitting the identification data of the user of the connected mobile terminal to the secure access control reader is planned to take place before the secure telemetry step, it is possible for it to be implemented following the completion of at least one validation action. In the case where the at least one validation action comprises several validation actions, the implementation of the transmission step can take place following the completion of the last of the several validation actions.
[0095] According to one embodiment of the invention, the at least one validation action comprises at least one launch operation carried out in a launch menu displayed by a mobile launch application, loaded into the connected mobile terminal.
[0096] According to one embodiment of the invention, the launching operation consists of at least one of the following operations:
[0097] - an operation of entering a launch code on the launch menu;
[0098] - a touch input operation of a launch pattern on the launch menu;
[0099] - a validation operation on the launch menu. According to one embodiment of the invention, the mobile launch application opens automatically and displays the launch menu following the unlocking step.
[0100] In other words, the telemetry step, then the access control step, are carried out on the condition that the user has, firstly, unlocked his connected mobile terminal and then, secondly, carried out a launch operation carried out in the launch menu of a dedicated application designed for the implementation of the secure access control method, and previously loaded into the connected mobile terminal.
[0101] According to one embodiment of the invention, the at least one validation action comprises at least one inclination of the connected mobile terminal according to an inclination angle included in a predefined launch angular interval.
[0102] In one embodiment of the invention, the user's validation action corresponds to a certain orientation / inclination of the connected mobile terminal with respect to the secure access control reader, or the ground. The orientation of the connected mobile terminal is considered valid if the inclination angle of the connected mobile terminal with respect to the secure access control reader or the ground is within a predefined launch angular interval. This verification is performed either by the connected mobile terminal or by the secure access control reader.
[0103] If the tilt angle of the connected mobile terminal is valid, then the secure telemetry step is initiated.
[0104] The launch angular interval is representative of an orientation of the connected mobile terminal such that the user interacts with:
[0105] - the front face of the connected mobile terminal facing or substantially facing it; this is for: navigation in the menus of the connected mobile terminal, reading messages, etc.
[0106] - the rear face of the connected mobile terminal facing or substantially facing the front face of the secure access control reader.
[0107] According to one embodiment of the invention, the launch mobile application opens and displays the launch menu under the condition that the tilt angle is within the predefined launch angular range.
[0108] In other words, the launch mobile application is only displayed on a screen of the connected mobile terminal if the user tilts his connected mobile terminal at a valid tilt angle within the launch angular range. In this configuration, the user therefore performs two validation actions.
[0109] In one embodiment of the invention, the telemetry step is therefore implemented only on the condition that the user has successively:
[0110] - unlocked his connected mobile terminal; then
[0111] - oriented its connected mobile terminal at an angle of inclination included in the launch angular interval; then
[0112] - performed a launch operation in the launch mobile application which was displayed on the screen of the connected mobile terminal following the latter's proper orientation.
[0113] According to one embodiment of the invention, the angle of inclination is measured by an inertial unit integrated into the connected mobile terminal.
[0114] In other words, in one embodiment of the invention, the tilt angle is measured by the connected mobile terminal using an inertial unit it contains. It then checks whether the measured tilt angle is within the launch angular range considered or not to conclude whether the orientation / tilt of the connected mobile terminal corresponds or not to a validation action.
[0115] According to one embodiment of the invention, the tilt angle is measured by the secure access control reader, from reception signals of an Ultra Wide Band wave coming from the connected mobile terminal.
[0116] The measurement of the angle by the secure access control reader implies that the Ultra Wide Band transceiver of the connected mobile terminal is awakened, that is to say capable of transmitting and receiving signals in the Ultra Wide Band communication mode. In this context, the step of awakening the Ultra Wide Band transceiver of the connected mobile terminal is implemented following the unlocking of the connected mobile terminal, and before the user performs at least one validation action.
[0117] In an alternative embodiment of the invention, the secure access control reader transmits the tilt angle that it has measured to the connected mobile terminal in order to check whether or not it is included in the launch angle interval, and thus detects or not a validation action.
[0118] In another alternative embodiment of the invention, the access control reader itself carries out this comparison. If the tilt angle is included in the launch angular interval, then the secure access control reader sends a validation signal to the connected mobile terminal which, upon receipt of said validation signal, considers that a validation action has occurred. According to one embodiment of the invention, at the start of the secure access control method, the Ultra Wide Band transceiver of the secure access control reader is in a standby state by being configured to receive in the Ultra Wide Band communication mode and not to transmit in the Ultra Wide Band communication mode, and prior to the secure telemetry step,a step of waking up the Ultra Wide Band transceiver of the secure access control reader is implemented, initiated by detection by at least one sensor of an approach or contact of the user or the mobile terminal connected with said secure access control reader, and in which the Ultra Wide Band transceiver of said secure access control reader switches from the standby state to an awakened state in which it is configured to transmit and receive in the Ultra Wide Band communication mode and thus allow the implementation of the secure telemetry step; and so that in the absence of said waking up step, the secure telemetry step is not implemented.,
[0119] In one embodiment of the invention, the Ultra Wide transceiver of the secure access control reader is, at the start of the access control method, in a standby state, being only capable of receiving signals in the Ultra Wide Band communication mode.
[0120] The Ultra Wide Band transceiver of the secure access control reader switches from this standby state to an awake state, in which it is then also capable of emitting Ultra Wide Band signals, following the detection, during a wake-up step, of an approach of the user or his connected mobile terminal to the secure access control reader, or of contact with him.
[0121] Advantageously, the power consumption of the Ultra Wide Band transceiver of the secure access control reader is reduced since it is only woken up as part of an implementation of the secure access control method (for the implementation of secure telemetry, and possibly to communicate with the access center if it is compliant / designed for this purpose).
[0122] Also, the implementation of the wake-up step makes it possible to prevent the Ultra Wide Band transceiver of the secure access control reader from periodically emitting the probing signal unnecessarily in its environment if no connected mobile terminal is located there, or if the connected mobile terminal is not within communication range of the secure access control reader.
[0123] In addition, the detection of the approach of the user (or his connected mobile terminal) or his contact with the secure access control reader, added to the unlocking of the connected mobile terminal, tends to confirm / validate the user's intention to access the secure space.
[0124] The secure telemetry step requires that the transceivers of the connected mobile terminal and the secure access control reader are both awake, and thus capable of transmitting and receiving signals. In other words, if the step of waking up the Ultra Wide Band transceiver of the secure access control reader is not implemented, and its Ultra Wide Band transceiver of the secure access control reader remains in the sleep state, the secure telemetry step cannot be implemented.
[0125] According to two variant embodiments of the invention, the step of waking up the Ultra Wide Band transceiver of the secure access control reader takes place before or after the unlocking step.
[0126] According to one embodiment of the invention, during the step of waking up the Ultra Wide Band transceiver of the secure access control reader, the detection of the approach or contact consists of a detection of the contact of the user by the at least one sensor arranged on a part of the secure access control reader.
[0127] According to one embodiment of the invention, the at least one sensor is chosen from a key, a mechanical sensor, a capacitive sensor, and an inductive sensor.
[0128] In other words, according to different embodiments of the invention, the detection of user contact may non-exhaustively correspond to:
[0129] - contact or approach of a user's hand to a part of the secure access control reader, detected for example by means of electrostatic sensors (inductive sensor, capacitive sensor) or sound or optical sensors;
[0130] - pressing a key or button included in the secure access control reader on its shell or on a touchpad.
[0131] According to one embodiment of the invention, during the step of waking up the Ultra Wide Band transceiver of the secure access control reader, the detection of the approach or contact consists of a detection by the at least one sensor of the approach of the user or the mobile terminal connected with a part of the secure access control reader within a given activation distance relative to the secure access control reader.
[0132] According to one embodiment of the invention, the at least one sensor is chosen from a capacitive sensor, an inductive sensor, a radar sensor, an ultrasonic sensor, an optical sensor, a vibration sensor. In other words, according to different embodiments of the invention, the detection of the approach of the user may, without limitation, relate to:
[0133] - detection of movements of the user or the connected mobile terminal by a motion sensor (for example, a passive infrared motion sensor);
[0134] - vibrations caused by the user's steps on the ground, which are detected by an accelerometer;
[0135] - microphone detection of noises caused by the user's footsteps on the floor.
[0136] The approach of the user or their connected mobile terminal is detected as soon as they are at a distance from the secure access control reader which is less than or equal to an activation distance.
[0137] In one embodiment of the invention, the activation distance is defined by the designers or installers of the secure access control reader as being equal to the authorization distance.
[0138] In another embodiment of the invention, the activation distance is defined by the designers or installers of the secure access control reader as being substantially equal to the authorization distance, for example the activation distance is equal to 1.25 times the authorization distance.
[0139] According to one embodiment of the invention, the at least one sensor is mounted on the secure access control reader, or is remote from the secure access control reader and connected to the secure access control reader.
[0140] In other words, at least one sensor detecting contact by the user on the secure access control reader or an approach by the user or their connected mobile terminal can be integrated into the secure access control reader remote from the latter.
[0141] According to one embodiment of the invention, the step of waking up the Ultra Wide Band transceiver of the connected mobile terminal is implemented on the condition that at least one validation action is also carried out.
[0142] As previously indicated, the step of waking up the Ultra Wide Band transceiver of the connected mobile terminal is implemented on the condition at least that the user unlocks his connected mobile terminal.
[0143] In one variant, the step of waking up the Ultra Wide Band transceiver of the connected mobile terminal may take place immediately after unlocking the connected mobile terminal, and before the user performs the at least one validation action for starting the secure telemetry step. In another variant, the implementation of the step of waking up the Ultra Wide Band transceiver of the connected mobile terminal requires that the user unlock the connected mobile terminal, then perform the at least one validation action. In other words, the step of waking up the Ultra Wide Band transceiver of the connected mobile terminal takes place after performing the at least one validation action.
[0144] According to one embodiment of the invention, the at least one secure space comprises at least one other secure space accessible by at least one other access control bay equipped with another locking / unlocking system and associated with another secure access control reader comprising an Ultra Wide Band transceiver, in which the secure access control method comprises a step of generating an access indicator and followed by a step of storing said access indicator in the connected mobile terminal, the generation step and the storage step being implemented when access to the secure space is authorized by the access center, and in which secure access control method is implemented an access control phase to access the other secure space which comprises the following steps:
[0145] - a step of detecting an access request made by the user on the connected mobile terminal;
[0146] - a transmission step during which the connected mobile terminal transmits, in the Ultra Wide Band communication mode, the access indicator to the other secure access control reader in response to the detection of the access request;
[0147] - a transmission step during which the other secure access control reader transmits said access indicator to the access center;
[0148] - an access control step during which the access center, after receiving the access indicator, authorizes access to the other secure space accessible by the other access control bay and, where applicable, controls the other locking / unlocking system of said other access control bay, without receiving or verifying the user's identification data by said access center.
[0149] A building may include several secure areas with restricted access, each of the secure areas being protected by its own access control bay, with an associated secure access control reader.
[0150] In one embodiment of the invention, when a secure telemetry step is implemented between a secure access control reader associated with an access control bay of the building and the connected mobile terminal of a user wishing to access a first secure space protected by said access control bay, and the access center authorizes the user to enter the secure space, an access witness (or "cookie" in English) is generated then stored in the connected mobile terminal.
[0151] In one embodiment of the invention, the access indicator is generated and then transmitted by the access center to the connected mobile terminal, either directly if the connected mobile terminal and the access center are in direct communication, or via the secure access control reader having previously participated in the secure telemetry step (via direct communication between the access center and the secure access control reader, or via step-by-step communication with other secure access control readers).
[0152] In another embodiment of the invention, the access cookie is generated by the connected mobile terminal by means of a dedicated application previously loaded therein; the generation may, for example, follow the receipt of data relating to an access cookie generation agreement from the access center.
[0153] Advantageously, the access witness is used to speed up the authentication of the user with the access center if he wishes to cross another access control bay to enter a second secure area of the building.
[0154] To do this, when the user approaches the secure access control reader associated with this other access control bay, the user interacts with his connected mobile terminal so that it detects a request (i.e. an intention) for access.
[0155] According to different embodiments of the invention, the access request can be detected following:
[0156] - to contact between the user and his connected mobile terminal;
[0157] - an orientation / tilt of the connected mobile terminal with respect to the secure access control reader of the other access control bay;
[0158] - to unlock the mobile;
[0159] - to a launch operation carried out in a mobile application.
[0160] In other words, the methods used to detect the user's validation action from his connected mobile terminal to previously implement the secure telemetry step can also be used to detect the access request. Once the access request is detected, the connected mobile terminal transmits only the access cookie to the secure access control reader of the other access control bay, which relays it to the access center (via direct communication or step-by-step communication).
[0161] Upon receipt of the access cookie, the access center then authorizes the user to access the second secure area; this without having carried out a verification of the user's identification data.
[0162] In one embodiment of the invention, the access cookie is generated based on the user's identification data.
[0163] In other words, the access cookie only allows the user to facilitate their authentication to access secure areas for which they have the required accreditations. The access cookie does not allow the user to access secure areas for which they are not authorized.
[0164] According to one embodiment of the invention, the access witness has a limited validity period.
[0165] Advantageously, in order to secure simplified user authentication by using an access cookie, said access cookie has a limited validity period. Once the validity period has expired, the access cookie expires. Authenticating the user with the access center to access a secure area then consists of re-implementing at least the secure telemetry and access control steps (with control by the access center of the user's identification data).
[0166] According to a characteristic of the invention, the authorization distance is less than or equal to 1 m.
[0167] [Brief description of the figures]
[0168] Other characteristics and advantages of the present invention will appear on reading the detailed description below, of a non-limiting example of implementation, made with reference to the appended figures in which:
[0169] [Fig 1] is a schematic view of an example of a building comprising two secure spaces each protected by an access control bay which comprises a locking / unlocking system, controlled by an access control unit, and which is associated with a secure access control reader operating in the Ultra Wide Band communication mode, with a user who seeks to access one of the secure spaces by authenticating himself to the access control unit via a secure access control reader, this by means of a connected mobile terminal; [Fig 2] is a schematic view of a bidirectional data exchange, in the Ultra Wide Band communication mode, between a connected mobile terminal and a secure access control reader;
[0170] [Fig 3] is an operating diagram of a first embodiment of the invention in which the connected mobile terminal and the secure access control reader participate in a secure telemetry step after the user of the connected mobile terminal has unlocked the latter; the secure access control reader transmitting to the access center, following the secure telemetry step, user identification data so that it implements an access control step making it possible to authenticate the user and authorize or not to access the secure space protected by the access control bay associated with the secure access control reader;
[0171] [Fig 4] is a schematic view of a principle for calculating a time of flight during a bidirectional exchange of data between the connected mobile terminal and the secure access control reader during a secure telemetry step implemented during the secure access control method;
[0172] [Fig 5] is an illustration, following the secure telemetry step, of a data transmission to authenticate the user from the secure access control reader to the access center which is configured to control the transmitted data in order to authorize or not the user to access a secure space, the transmission of the data being able to be done by direct communication (Figure 5-a) or by a step-by-step communication (Figure 5-b);
[0173] [Fig 6] is an operating diagram in which the connected mobile terminal transmits to the access center the user identification data necessary for implementing the secure access control step, the connected mobile terminal having, for communicating with the access center, a connection address that the secure access control reader transmitted to it during the secure telemetry step;
[0174] [Fig 7] is a schematic view of the building of Figure 1 in connection with the operating diagram of Figure 6, showing the transmission of the data necessary for the implementation of the access control step by the connected mobile terminal to the access center;
[0175] [Fig 8] is a schematic view of a validation action to be carried out to implement the telemetry step following the unlocking of the connected mobile terminal, said validation action corresponding here, in a given variant embodiment, to a launch operation carried out by the user on an available launch menu of a launch mobile application included in the connected mobile terminal;
[0176] [Fig 9] is a schematic view of a second variant of the validation action, which corresponds to an inclination of the connected mobile terminal with respect to the ground and the secure access control reader;
[0177] [Fig 10] is an operating diagram of an embodiment for which the telemetry step is implemented on the condition that the user first unlocks his connected mobile terminal, and that at least one validation action is subsequently carried out by means of the connected mobile terminal, said at least one validation action corresponding here to a specific inclination of the connected mobile terminal relative to the ground and / or to the secure access control reader;
[0178] [Fig 11] is a schematic view of a first variant of implementation of a wake-up step included in the secure access control method for switching the Ultra Wideband transceiver of the secure access control reader from a standby state to a woken-up state in which it is capable of transmitting and receiving data in the Ultra Wideband communication mode; the wake-up of the Ultra Wideband transceiver occurring following detection of physical contact of the user with the secure access control reader;
[0179] [Fig 12] is a schematic view of a second alternative implementation of the wake-up step, with the wake-up of the Ultra Wideband transceiver occurring following detection of an approach of the user, or of his connected mobile terminal, within a given activation distance from the secure access control reader;
[0180] [Fig 13] is a flow diagram of an embodiment of the secure access control method, for which the probing signal is transmitted by the secure access control reader to the connected, unlocked and awakened mobile terminal, following the implementation of the awakening step according to its embodiment variant illustrated in Figure 11;
[0181] [Fig 14] is an operating diagram of an embodiment of the secure access control method which comprises generating and then storing an access cookie in the user's connected mobile terminal following authorization of access to a first secure space by the access center, said access cookie subsequently serving to accelerate the authentication of the user with another secure access control reader to access another secure space; [Fig 15] is a schematic view of the building of Figure 1, and illustrating an application context related to the operating diagram of Figure 14, for which the user, after entering a secure space, will use the access cookie contained in his connected mobile terminal to authenticate himself with the access center to access another secure space;
[0182] [Fig 16] a schematic view in connection with Figure 15 and Figure 16, for which, in one embodiment, and in order to authenticate itself with the access center, the connected mobile terminal transmits the access witness to another secure access control reader following the detection of a contact, here a tap, from the user.
[0183] [Detailed description of one or more embodiments of the invention]
[0184] With reference to Figure 1 and Figure 2, the secure access control method 100 of the invention, which is designed to operate in the Ultra Wide Band communication mode, is implemented in the application context of a building comprising at least two secure spaces SI, S2, access to which is protected from access control bays DI, D2 each equipped with a locking / unlocking system, and each associated with a secure access control reader RI, R2 comprising an Ultra Wide Band transceiver UR1, UR2 in order to be able to transmit and receive signals / data in this communication mode.
[0185] In the following description:
[0186] - the secure spaces SI, S2 are designated under the terms of secure space SI and other secure space S2;
[0187] - the DI, D2 access control bays are referred to as the DI access control bay and other D2 access control bay; and
[0188] - RI, R2 secure access control readers are referred to as RI secure access control reader and other R2 secure access control reader.
[0189] It is also considered in the remainder of the description that a user U wishes to access the secure space SI. To do this, he must authenticate himself with an access center 2 in charge of controlling access to the secure space SI, by means of a connected mobile terminal 1 and via the secure access control reader SI. The connected mobile terminal also comprises an Ultra Wide Band transceiver U1 in order to be able to transmit and receive in the Ultra Wide Band communication mode. It also contains identification data udata of the user U (or in English, credentials).
[0190] The connected mobile terminal 1 is equipment equipped with a touch screen and may, but is not limited to, a mobile phone, a touch tablet, a connected watch, etc.
[0191] As part of the implementation of the secure access control method 100, the Ultra Wide Band transceivers UR1, UR2 of the secure access control readers RI, R2 can operate:
[0192] - in a standby state with only the ability to receive Ultra Wideband data / signals, but not the ability to transmit Ultra Wideband data / signals; or
[0193] - in an awake state where they are able to transmit and receive data / signals in Ultra Wide Band.
[0194] The Ultra Wide Band U1 transceiver of the connected mobile terminal can be:
[0195] - in a so-called off state in which it is unable to transmit or receive Ultra Wideband data / signals; or
[0196] - in an awake state in which it can transmit and receive Ultra Wideband data / signals.
[0197] The Ultra Wideband U1 transceiver may for example be in the off state when for example:
[0198] - it is physically or electrically switched off; or
[0199] - it is switched on but its Ultra Wideband functions are deactivated, making it unable to respond to external requests from other systems using Ultra Wideband to communicate, for example when it is operating in an offline mode.
[0200] In other words, with reference to Figure 2, when they are woken up (in other words in the woken up state), the Ultra Wide Band transceivers Ul, UR1, UR2 of the connected mobile terminal 1 and the secure access control reader UR1, UR2 can carry out a bidirectional exchange of UWB1 data in the Ultra Wide Band communication mode.
[0201] In the remainder of the description, when it is written that a connected mobile terminal 1 and a secure access control reader RI, R2 exchange data (during transmissions and receptions), it is understood that it is their Ultra Wide Band transceivers Ul, UR1, UR2 which exchange said data. In the remainder of the description, several embodiments of the secure access control method 100 are presented non-exhaustively. They constitute a non-exhaustive list of all the embodiments which are possible for designing the secure access control method 100.
[0202] Whatever the embodiment of the secure access protocol 100, the authentication of the user U is firstly based on a secure telemetry step SR in the Ultra Wide Band communication mode between the connected mobile terminal 1 and the secure access control reader RI, which secure telemetry step requires at least for its implementation that the user U unlocks his connected mobile terminal 1 during an unlocking step ulock, causing the connected mobile terminal to switch from a locked state to an unlocked state.
[0203] When the secure access control process starts, the Ultra Wideband U1 transceiver of the connected mobile terminal is in the off state.
[0204] A first embodiment is illustrated in Figure 3, for which it is considered that the Ultra Wide Band transceiver UR1 of the secure access control reader RI is in the awake state.
[0205] At the start of the secure access control method 100, the user U unlocks his connected mobile terminal 1 during the ulock unlocking state.
[0206] According to different embodiments of the invention, the unlocking of the connected mobile terminal can occur following:
[0207] - switching on a touch screen included in the connected mobile terminal 1 by the user U pressing on it, or on a switch-on button also included in the connected mobile terminal 1; or
[0208] - an operation of entering an unlocking code on the connected mobile terminal 1; or
[0209] - a touch entry operation of an unlock pattern on the touch screen of the connected mobile terminal 1; or
[0210] - a fingerprint recognition operation on a fingerprint sensor of the connected mobile terminal 1; or
[0211] - a facial recognition operation of the user U by means of a camera integrated into the connected mobile terminal 1.
[0212] Unlocking the connected mobile terminal 1 has the effect of starting a wake-up step WP-1 during which the Ultra Wide Band transceiver U1 of the connected mobile terminal 1 switches from the off state to the awake state. The Ultra Wide Band transceivers Ul, UR1 of the connected mobile terminal 1 and the secure access control reader RI are both in the awake state, the implementation of the secure telemetry step is made possible.
[0213] According to two possibilities for implementing the secure access control method 100, the secure telemetry step SR can be initiated by the secure access control reader RI, or by the connected mobile terminal 1.
[0214] In the first embodiment illustrated in Figure 3, the secure telemetry step SR is initiated by the secure access control reader RI when it manages to carry out a first bidirectional exchange of UWB1 data in Ultra Wide Band with a connected mobile terminal 1. To do this, the secure access control reader RI periodically transmits, in the Ultra Wide Band communication mode, a probing signal sscan in its environment during a transmission step El, which is received by the connected mobile terminal 1 during a reception step El' once its Ultra Wide Band transceiver Ul is in the awake state.
[0215] Following reception step El', the connected mobile terminal 1 implements a transmission step E2 during which it transmits to the secure access control reader a confirmation signal ack in the Ultra Wide Band communication mode.
[0216] Following receipt of the ack confirmation signal during an E2' reception step, the secure access control reader RI initiates the secure telemetry step SR.
[0217] The SR secure telemetry step includes at least:
[0218] - a transmission step ESR1 during which the secure access control reader RI transmits security data sdatal to the connected mobile terminal 1; and
[0219] - a transmission step ESR2 during which the connected mobile terminal 1 transmits security data sdata 2 to the secure access control reader RI;
[0220] - a step of calculating EC a certified distance sdist between the connected mobile terminal 1 and the secure access control reader RI; and
[0221] - an Everif verification step following the EC calculation step during which a verification of the certified distance sdist is carried out.
[0222] In the embodiments in which the connected mobile terminal 1 initiates the secure telemetry step SR, it is conceivable that said secure telemetry step SR begins following the wake-up step WP-1 of the Ultra Wide Band transceiver Ul, after unlocking thereof, with the connected mobile terminal 1 communicating security data sdatal and the user access data udata to the secure access control reader RI which is within its communication range. Thus, these embodiments require neither the periodic transmission of the probing signal sscan by the secure access control reader RI, nor the transmission by the connected mobile terminal 1 to the secure access control reader RI of the confirmation signal ack.
[0223] With reference to Figure 4, in one embodiment of the invention, the certified distance sdist is calculated, according to the equation Eq.l, by at least one of the connected mobile terminal 1 and the secure access control reader RI from a time of flight ToF (“Time Of Flight” in English) measured by said at least one of the connected mobile terminal 1 and the secure access control reader RI.
[0224] Tloop — Treply
[0225] ToF = - - - Eq.l where Treply is the response time of the connected mobile terminal 1 which corresponds to the time interval between: the instant when it receives during a reception step ESR1' the security data sdatal from the secure access control reader RI and the instant, and the implementation of the transmission step ESR2; and Tloop is the duration of the bidirectional exchange between the secure access control reader RI and the connected mobile terminal 1, i.e. here the time interval between the transmission step ESR1 and a reception step ESR2' during which the secure access control reader RI receives the security data sdata2 from the connected mobile terminal 1.
[0226] In one embodiment of the invention, such as that illustrated in Figure 3, only the secure access control reader RI calculates the certified distance sdist.
[0227] The certification of the distance comes from the fact that the distance is calculated during the SR secure telemetry step, and that it is based on at least one bidirectional exchange of Ultra Wide Band signals between two devices (the connected mobile terminal and the secure access control reader) each having: an embedded secure component; or trusted firmware or application previously loaded inside, or a trusted execution environment (or "Trusted Execution Environment" TEE in English).
[0228] In another embodiment of the invention, the connected mobile terminal 1 and the secure access control reader RI both calculate the certified distance sdist separating them. Both exchange the certified distance value sdist that they have calculated. Each device 1, RI then compares the certified distance sdist that it has received with the certified distance sdist that it has itself calculated. In the case where the consistency between the certified distances sdist is not verified, the telemetry step SR is stopped. In the case where the consistency is verified, the telemetry step SR continues with the verification step Everif.
[0229] The Everif verification step consists of comparing the certified distance sdist with an authorization distance dauth. More precisely, it is a matter of checking whether the certified distance sdist is included in the authorization distance dauth, that is, whether it is less than or equal to the latter.
[0230] In a first embodiment, the equipment 1, RI in charge of the EC calculation step is also the one in charge of the Everif verification step.
[0231] Preferably, with reference to Figure 3, it is the secure access control reader RI which is responsible for implementing the EC calculation and Everif verification steps.
[0232] In a second embodiment, one of the two devices 1, RI among the connected mobile terminal 1 and the secure access control reader RI is in charge of the EC calculation step, while the other is in charge of the Everif verification step. Thus, once one of the two devices 1, RI has calculated the certified distance sdist, it must transmit it to the other device 1, RI so that it can be checked / verified.
[0233] Comparing the certified distance sdist to the authorization distance dauth makes it possible to determine whether the user U is close or not to the secure access control reader RI, this proximity reflecting the user U's desire to access the secure space SI.
[0234] If the certified distance sdist is greater than the authorization distance dauth, the access control method 100 stops. If the certified distance sdist is less than or equal to the authorization distance, the telemetry step SR ends and the secure access control method 100 continues.
[0235] In one embodiment of the invention, the dauth authorization distance is less than or equal to 1 m.
[0236] In various embodiments of the invention, the secure telemetry step SR may not be limited to the exchanges and principles described. Further information on secure telemetry is available in the two references indicated in the State of the art.
[0237] At the end of the secure telemetry step SR, if the certified distance is valid, the user identification data udata are transmitted to the access center 2. According to two different embodiments, the transmission is ensured either by the secure access control reader RI, or by the connected mobile terminal according to which of the equipment 1, RI has network access to be able to communicate with the access center 2.
[0238] In one embodiment of the invention, the equipment 1, RI having carried out the Everif verification step of the certified distance sdist is the one in charge of transmitting the user identification data udata to the access center 2. In the embodiment illustrated in Figure 3, it is therefore the secure access control reader RI which implements a transmission step E3 of the user identification data udata.
[0239] Advantageously, the implementation of the EC calculation, Everif verification, and E3 transmission steps by the secure access control reader RI makes it possible to significantly strengthen the security level of the secure access control method 100 since, by definition, the secure access control reader RI is a trusted system designed and conformed to be an integral part of an access control installation implementing secure access control methods.
[0240] In two embodiments, the secure access control reader RI is directly linked to the access control center 2: either by being physically connected to it (for example, by means of Ethernet links, or an RS485 interface), or by being in direct communication with it according to a wireless communication protocol (see Figure 5-a) operating in a frequency band included or not in the Ultra Wide Band. For example, the secure access control reader RI is directly linked to the access control center 2 can communicate in Wifi®
[0241] In a third embodiment of the invention, the secure access control reader RI and the access control unit 2 are part of a mesh network comprising several other secure access control readers. In the example illustrated in Figure 1, the other secure access control reader R2 is also part of this mesh network. Each of the devices RI, R2, 2 of the mesh network is capable of communicating with its closest neighbor(s) according to a close-to-close communication protocol, for example Bluetooth Mesh®.
[0242] Advantageously, the mesh network addresses the problem of indoor network coverage, when the structure of the building and the materials used for its construction interfere with the transmission of signals and do not allow two devices to communicate correctly while they are within communication range of each other.
[0243] In the example shown in Figure 5-b, the secure access control reader RI transmits the user identification data udata to the other secure access control reader R2; which other secure access control reader R2 then relays it to the access control unit 2.
[0244] It is also possible that the equipment 1, RI having carried out the Everif verification step is not the one that will transmit the user identification data udata to the access center 2. Possibly, the equipment 1, RI in charge of verifying the certified distance sdist, if it is validated, can transmit a Goto authorization signal to the other equipment 1, RI; the other equipment 1, RI then transmitting the user identification data to the access center 2 once the Goto authorization signal has been received. This application context will be illustrated below.
[0245] In the event that the secure access control reader RI must transmit the user identification data udata to the access control center 2 (directly, or indirectly via the communication from one place to another), it is necessary that the connected mobile terminal 1 has previously transmitted said user identification data udata to it.
[0246] The user identification data udata are transmitted by the connected mobile terminal 1 to the secure access control reader RI during a transmission step provided in the Ultra Wide Band communication mode.
[0247] Thus, the implementation of the transmission step implies on the one hand that the connected mobile terminal 1 is within communication range of the secure access control reader RI in the Ultra Wide Band communication mode; and on the other hand that the Ultra Wide Band transceiver U1 of the connected mobile terminal 1 is in the awake state to be able to transmit the user identification data udata to the secure access control reader RI.
[0248] The secure access control method 100 provides, in different embodiment variants, that the transmission step can be carried out before, during, or after the secure telemetry step SR.
[0249] In the case where it is planned that the transmission step takes place following the secure telemetry step SR and before the access control step CS, it is possible that said transmission step is implemented on the condition that it has been verified that the certified distance sdist is less than or equal to the authorization distance dauth.
[0250] With reference to Figure 3 and in the remainder of the description, for the embodiments of the secure access control method 100 illustrated, it is considered that when the access center 2 receives the user identification data udata from the secure access control reader RI, the step of transmitting them from the connected mobile terminal 1 to the secure access control reader RI takes place during the secure telemetry step SR, during the transmission step ESR2.
[0251] With reference to Figure 3, following the reception of the identification data of the user udata during a reception step E3', the access center 2 is configured to implement an access control step CS during which it checks at least the identification data of the user udata to determine whether the user U has the required accreditations to access the secure space SI protected by the access control bay D1. If this is not the case, access to the secure space SI is refused to the user.
[0252] Once at least the user's identification data udata have been validated, the access control unit 2 unlocks the locking / unlocking system of the access control bay Dl to allow the user U to enter the secure area SI.
[0253] According to different embodiments of the invention, the locking / unlocking system of the access control bay D1, which may for example correspond to a latch that opens and closes, may either be physically connected by a cable to the access center 2, or be connected to the access center 2 via a wireless link.
[0254] A second embodiment of the secure access control method is illustrated in Figure 6. Compared to the first embodiment described and illustrated in Figure 3, the connected mobile terminal 1 is configured to itself transmit to the access center 2 the user identification data udata during a transmission step E4, which center following their reception during a reception step E4' implements the access control step CS.
[0255] To implement the transmission step E4, the connected mobile terminal 1 must have an add-c connection address allowing it to connect to the access center 2 and communicate with it.
[0256] In a first variant embodiment, the connection address add-c is already contained in the connected mobile terminal 1, having been previously loaded into it before the implementation of the secure access control method 100.
[0257] In a second embodiment, the connection address add-c is transmitted to the connected mobile terminal 1 by the secure access control reader RI during the secure telemetry step SR. Non-limitingly, it is possible for the connection address add-c:
[0258] - either transmitted during the at least one bidirectional exchange between the secure access control reader RI and the connected mobile terminal 1 that comprises the secure telemetry step SR, and which encompasses the transmission steps ESRI, ESR2 and the reception steps ESRI', ESR2'. In other words, the connection address add-c is transmitted with the security data sdatal during the transmission step ESR1; or
[0259] - either transmitted by the secure access control reader RI during a transmission step taking place during the secure telemetry step SR and independent of the at least one exchange in question.
[0260] It is also conceivable, with reference to Figure 6, in the case where the access control reader RI implements the steps of calculation EC and verification of the certified distance sdist, that it transmits to the connected mobile terminal 1, during a transmission step ESR3 included in the secure telemetry step SR and which takes place after the verification step Everif, the connection address add-c simultaneously with the authorization signal Goto previously defined and which aims to indicate to the connected mobile terminal 1 that it can transmit the user identification data udata to the access center 2.
[0261] With reference to Figures 6 and 7, following the reception of the connection address add-c and the authorization signal Goto during a reception step ESR3', the connected mobile terminal 1 connects to the access center 2 and implements the transmission step E4.
[0262] In the remainder of the description, it is considered for all the embodiments subsequently illustrated by an operating diagram that the secure access control reader RI: initiates the secure telemetry step SR, implements the calculation steps EC and verification steps Everif, and transmits the user identification data udata to the access center 2 (during the transmission step E3).
[0263] For the two embodiments presented previously, the implementation of the secure telemetry step SR requires that the user U unlocks his connected mobile terminal 1 during the unlocking step ulock, so that the wake-up step WP-1 is implemented so that the Ultra Wide Band transceiver U1 of the connected mobile terminal 1 switches to the woken-up state.
[0264] In other variant embodiments of the secure access control method 100, it is conceivable that the implementation of the secure telemetry step SR additionally depends on at least one opt, inc validation action performed by the user U on his connected mobile terminal 1 just after having unlocked it. The WP-1 wake-up step of the Ultra Wide Band transceiver U1 of the connected mobile terminal 1 then takes place after the unlocking step, and before the user U performs the at least one opt, inc validation action. Also, it is conceivable that the WP-1 wake-up step is implemented on the condition that the user U unlocks his connected mobile terminal and performs the at least one opt, inc validation action. In other words, chronologically the WP-1 wake-up step takes place following the performance of the at least one opt, inc validation action, and before the implementation of the secure telemetry step SR.
[0265] The at least one validation action opt, inc is an additional security / condition in the implementation of the secure access control method 100 in order to ensure that the user U of the connected mobile terminal 1 has the concrete intention of accessing the secure space SI protected by the access control bay DI associated with the secure access control reader RI.
[0266] The at least one opt, inc validation action thus avoids implementing the secure telemetry step SR, then subsequently the access control step CS in the case where the user U has unlocked his connected mobile terminal 1 near the secure access control reader RI while he does not intend to access the secure space SI. Other advantages are: reducing the power consumption of the secure access control reader RI and the connected mobile terminal 1 in the Ultra Wideband communication mode, and not unnecessarily soliciting the access center 2.
[0267] With reference to Figure 8, the at least one opt, inc validation action may be in the form of an opt launch operation carried out in a launch menu displayed by a mobile launch application l-app, loaded into the connected mobile terminal 1. Non-limitingly, it is possible for the opt launch operation to consist of:
[0268] - an operation of entering a launch code on the launch menu;
[0269] - a touch input operation of a launch pattern on the launch menu;
[0270] - a validation operation on the launch menu.
[0271] In an alternative embodiment of the invention, it is conceivable that the mobile launch application l-app opens automatically and displays the launch menu following at least the ulock unlocking of the connected mobile terminal 1. Optionally, in another alternative embodiment, the mobile launch application l-app can open automatically and display the launch menu following the ulock unlocking of the connected mobile terminal 1 and after receipt by the latter of the sscan probing signal.
[0272] With reference to Figure 9, the at least one validation action ulock, opt, inc may also correspond to an inclination inc of the connected mobile terminal 1. It consists of a measurement of an inclination angle tetal, teta2 of the connected mobile terminal 1, which is then compared to a predefined launch angular interval. If the inclination angle tetal, teta2 is included in the launch angular interval, then the inclination is considered valid for the subsequent implementation of the secure telemetry step SR. The launch angular interval corresponds to an orientation of the connected mobile terminal 1 with respect to the secure access control reader RI, or the ground such that:
[0273] - the front face Fl of the connected mobile terminal 1 faces or substantially faces the user U;
[0274] - the rear face F2 of the connected mobile terminal 1 faces or substantially faces the secure access control reader RI.
[0275] In a first embodiment variant illustrated in Figure 9 (a), the inclination inc consists of a measurement of a tetal inclination angle by the secure access control reader RI from reception signals of an Ultra Wide Band wave coming from the connected mobile terminal, for example during a bidirectional exchange of UWB1 data taking place when the Ultra Wide Band transceivers Ul, UR1 of the connected mobile terminal 1 and the secure access control reader RI are both woken up; which inclination angle is then compared to the launch angular interval. This first embodiment variant implies that the wake-up step WP-1 of the Ultra Wide Band transceiver Ul of the connected mobile terminal 1 is implemented following the unlocking of the latter.
[0276] In a second embodiment illustrated in Figure 9 (b), the inclination inc consists of a measurement of an inclination angle teta2 of the connected mobile terminal 1 relative to the ground by an inertial unit included in the connected mobile terminal 1.
[0277] According to several possibilities:
[0278] - the equipment 1, RI among the connected mobile terminal 1 and the secure access control reader RI which carries out the measurement of the inclination angle tetal, teta2 and its validation is the same as that which initiates the secure telemetry step SR. If it is the connected mobile terminal 1, then it is possible that it can initiate the secure telemetry step SR following the validation of the inclination inc.If it is the secure access control reader RI, it is conceivable for example that the secure access control reader RI implements the secure telemetry step SR: following the reception of the confirmation signal ack (sent by the unlocked connected mobile terminal 1 once it has received the probing signal sscan); and the validation of the inclination inc; - either the equipment 1, RI among the connected mobile terminal 1 and the secure access control reader RI which is responsible for measuring the inclination angle tetal, teta2 is not the same as the one which validates it, in which case there is transmission of the inclination angle tetal, teta2 of said equipment 1, RI to the other equipment 1, RI;.
[0279] - either the equipment 1, RI among the connected mobile terminal 1 and the secure access control reader RI which is responsible for validating the inclination inc is not the same one which initiates the secure telemetry step. If the equipment 1, RI having validated the inclination inc is the secure access control reader RI, then it is conceivable that it sends a validation signal to the connected mobile terminal 1 which, upon receipt thereof, initiates the secure telemetry step. If the equipment 1, RI having validated the inclination inc is the connected mobile terminal 1 then, with reference to Figure 10, it is conceivable that once the probing signal sscan has been received, it only sends the confirmation signal ack to the secure access control reader RI after validation of the inclination inc.
[0280] According to different embodiments of the secure access control method 100, the at least one opt, inc validation action may comprise several opt, inc validation actions carried out prior to the secure telemetry step SR. It is conceivable that these several opt, inc validation actions are carried out successively one after the other or not.
[0281] In a particular variant embodiment of the invention in which the secure telemetry step SR is initiated by the secure access control reader, it is possible for the connected mobile terminal 1 to transmit the confirmation signal ack to it on the condition that the user, once his connected mobile terminal 1 is unlocked:
[0282] - tilts its connected mobile terminal 1 according to a compliant tilt angle tetal, teta2 in order to validate the tilt inc;
[0283] - performs an opt launch operation on the l-app launcher mobile application, which l-app launcher mobile application is displayed on the touch screen of the connected mobile terminal 1 following validation of the inclination inc (i.e., the l-app launcher mobile application is not displayed if the inclination is invalid).
[0284] Optionally, in an alternative embodiment for which the Ultra Wide Band transceiver U1 of the connected mobile terminal 1 switches to the awake state following the unlocking of the latter, the launch menu is displayed on the condition: that the connected mobile terminal 1 has received the sscan sounding signal, and that the inclination inc is valid.
[0285] Up to now, it has been considered that the Ultra Wide Band transceiver UR1 of the secure access control reader RI was in the awake state at the start of the secure access control method 100. In different embodiments, the access control reader RI is configured to be in the sleep state at the start of the secure access control method 100. In order for the secure telemetry step SR to be implemented, it is necessary for the Ultra Wide Band transceiver UR1 of the secure access control reader RI to switch from the sleep state to the awake state during a wake-up step WP-R.
[0286] The WP-R wake-up step occurs following detection by at least one sensor sensRl of a prox approach or contact tou of the user U or the connected mobile terminal 1 with the secure access control reader RI.
[0287] Thus, in a first variant, with reference to Figure 2 and Figure 11, the WP-R wake-up step of the Ultra Wide Band transceiver UR1 of the secure access control reader RI occurs upon detection of contact of the user U with the secure access control reader RI by at least one sensor sensRl arranged on a part of the latter. This contact tou may non-exhaustively correspond to:
[0288] - contact of a hand of the user U on a part of the secure access control reader RI, detected for example by means of electrostatic sensors (inductive sensor or capacitive sensor);
[0289] - pressing a key or button included in the RI secure access control reader on its shell or on a touchpad.
[0290] In a second variant, with reference to Figure 12, the wake-up step WP-R of the Ultra Wide Band transceiver UR1 of the secure access control reader RI occurs following detection by at least one sensor sensRl of the prox approach of the user U or of the connected mobile terminal 1 with a part of the secure access control reader RI within a given activation distance d-act relative to the secure access control reader RI. In this second variant, the at least one sensor sensRl is chosen from a capacitive sensor, an inductive sensor, a radar sensor, an ultrasonic sensor, an optical sensor, a vibration sensor. Thus, the detection of the prox approach of the user U may, without limitation, relate to:
[0291] - detection of movements of the user U or of the connected mobile terminal 1 by a motion sensor (for example, a passive infrared motion sensor or other optical sensor);
[0292] - vibrations caused by the user's steps on the ground, which are detected by an accelerometer;
[0293] - detection by a microphone of the noises caused by the steps of the user U on the ground. In an alternative embodiment, the activation distance d-act from which the secure access control reader RI is able to detect an approach of the user U or his connected mobile terminal 1 is equal to the authorization distance dauth.
[0294] In another variant, the activation distance d-act is defined to be substantially equal to the authorization distance dauth, for example the activation distance is equal to 1.25 times the authorization distance dauth.
[0295] In this second variant, the at least one sensor sensR1, sensR2 used to detect an approach of the user U or of his connected mobile terminal 1 can be integrated into the secure access control reader RI, R2 or remote from it. For example, the remote sensor can be contained in a housing which also comprises a push button which the user U presses, which housing is fixed to a wall of the space in which the secure access control reader RI, R2 is located and: either is physically connected to the secure access control reader RI, R2 by a cable; or communicates with it by means of a wireless communication protocol (for example, in Bluetooth Low Energy BLE®).
[0296] In one embodiment of the invention, it is conceivable that the secure access control readers RI, R2 integrate a light-emitting diode such that it lights up when their Ultra Wide Band transceiver UR1, UR2 is woken up, and is not lit when it is in the standby state, so as to signal / inform the user U of the state of the Ultra Wide Band transceiver UR1, UR2 of the secure access control reader RI, R2; also indicating to him whether after approaching the secure access control reader RI, R2 or touching it, the wake-up step WP-R of the Ultra Wide Band transceiver UR1, UR2 of the secure access control reader RI, R2 has been correctly carried out.
[0297] In a first operating configuration for which the connected mobile terminal 1 initiates the secure telemetry step SR, the wake-up step WP-R of the Ultra Wide Band transceiver UR1 of the secure access control reader RI is carried out before the unlocking step ulock, so that the connected mobile terminal 1, once its Ultra Wide Band transceiver U1 is in the woken-up state, can transmit in the Ultra Wide Band communication mode to the secure access control reader RI the user identification data udata.
[0298] With reference to Figure 13, in a second operating configuration for which the secure access control reader RI initiates the secure telemetry step SR, the unlocking step ulock is performed before the wake-up step WP-R of the Ultra Wide Band transceiver UR1 of the secure access control reader RI.
[0299] Advantageously, the implementation of the wake-up step WP-R of the Ultra Wide Band transceiver UR1 of the secure access control reader RI makes it possible to reduce the power consumption of the Ultra Wide Band transceiver UR1 of the secure access control reader RI since it is only woken up within the framework of an implementation of the secure access control method 100 (i.e. for the implementation of the secure telemetry step SR, and possibly depending on the embodiment considered the implementation of the transmission step E3). In particular, the wake-up step WP-R can make it possible to avoid a periodic transmission of the probing signal sscan if no connected mobile terminal 1 is within communication range of the secure access control reader RI, or if its Ultra Wide Band transceiver U1 is in the off state.
[0300] In addition, the detection of the proximity approach of the user U (or of his connected mobile terminal 1) or of his contact with the secure access control reader RI, added to the unlocking of the connected mobile terminal 1, tends to confirm / validate the intention of the user U to access the secure space SI.
[0301] In one embodiment of the invention, the secure access control reader RI is configured to switch its Ultra Wide Band transceiver UR1 into the standby state after an activity duration which is established according to the time necessary to implement all of the steps of the secure access control method 100.
[0302] In another embodiment, the access center 2, following the implementation of the access control step CS, transmits a standby signal to the secure access control reader RI. Once this standby signal is received, the Ultra Wide Band transceiver UR1 of the secure access control reader RI switches from the awake state to the standby state.
[0303] The various embodiments of the secure access control method 100 described so far can be implemented for any secure access control reader RI, R2 included in a building.
[0304] However, when the secure access control readers have network access and can communicate with the access center 2, once the user U has authenticated himself for the first time with a secure access control reader as previously described, his authentication after another secure access control reader can be accelerated by means of an access cookie (or "cookie" in English). With reference to Figure 14 and Figure 15, it is considered that the user U, after having authenticated himself with the secure access control reader RI and having accessed the secure space SI, also wishes to access the other secure space R2 protected by the other access control bay D2, which is associated with the other secure access control reader R2; and that the authentication with the other secure space R2 is done by means of the access cookie coo.It is considered that the sequence of all the steps from the start of the secure access control method 100 to the access control step CS is similar to that illustrated in Figure 3.
[0305] The access witness coo is generated during a generation step EG taking place following the access control step CS in the case where the access center 2 has authorized initial access to the user U (in the example illustrated, to the secure space SI).
[0306] In a first embodiment, the access witness coo is generated by the connected mobile terminal 1 by means of a dedicated application previously loaded therein; the generation may, for example, follow the reception of data relating to an agreement to generate the access witness coo from the access center 2. Once the access witness coo has been generated, it is stored in the connected mobile terminal 1 following an Esto storage step.
[0307] In a second embodiment variant, and as illustrated in Figure 14, the generation step EG is implemented by the access center 2. Then, it transmits during a transmission step E5 the access indicator coo to the secure access control reader RI which corresponds to the access control reader having participated in the secure telemetry step SR (the transmission being done by direct communication or by a close-to-close communication). Following the reception of the access indicator coo during a reception step E5', the secure access control reader RI transmits during a transmission step E6 the access indicator to the connected mobile terminal 1, which, following a reception step E6' of said access indicator coo, proceeds to the storage step Esto.
[0308] When the user is near the other secure access control reader R2, an access control phase CP begins. During this phase, the user U makes an access request using his connected mobile terminal 1, which is detected by said connected mobile terminal 1 during a detection step ADD.
[0309] In an alternative embodiment, the access request may correspond to the at least one validation action ulock, opt, inc. In another alternative embodiment, with reference to Figure 16, the access request may correspond to a contact of the user U on his connected mobile terminal 1, such as a tap; the contact being detected by a sensor included in the connected mobile terminal 1 (such as for example a mechanical sensor, a capacitive sensor, an inductive sensor, an accelerometer or an inertial unit).
[0310] Following the ADD detection step, the connected mobile terminal 1 transmits during a transmission step E7 the access indicator coo to the other secure access control reader R2.
[0311] Once the access indicator coo has been received during a reception step E7', the other secure access control reader R2 transmits the access indicator coo to the access control unit 2 during a transmission step E8 (by direct communication or step-by-step communication).
[0312] Following receipt of the access indicator coo during a reception step E8', the access center implements an access control step CS2 during which it verifies the access indicator coo and then authorizes access to the other secure space S2 to the user U, by unlocking the locking / unlocking system of the other access control bay D2.
[0313] Advantageously, the access center 2 authorized access to the other secure space S2 by simply verifying the coo access cookie, therefore without having to carry out a new check of the user's identification data udata.
[0314] In one embodiment of the invention, the access cookie coo is generated based on the user's identification data. Indeed, another user U may have the right to access the secure space SI, but not the other secure space S2. In other words, the access cookie only allows the user U to facilitate his authentication to access the secure spaces for which he has the accreditations.
[0315] In one embodiment of the invention, the access cookie coo has a limited validity period. In other words, once the validity period has expired, the access cookie coo expires. If this is the case, the authentication of the user U with the access center 2 to access another secure space then consists of re-implementing at least the secure telemetry steps SR and access control CS (with control by the access center 2 of at least the user identification data udata).
Claims
CLAIMS 1. Secure access control method (100) for controlling and authorizing access by a user (U) to at least one secure space accessible (SI, S2) by at least one access control bay (DI, D2) equipped with a locking / unlocking system, the secure access control method (100) involving several pieces of equipment (1, RI, R2, 2) including: - a connected mobile terminal (1) carried by the user (U) and containing user identification data (udata), said connected mobile terminal (1) comprising at least one Ultra Wide Band transceiver (Ul) which is, at the start of the secure access control method (100), in an off state for which it is configured not to transmit and not to receive in an Ultra Wide Band communication mode, - at least one secure access control reader (RI, R2) associated with at least one access control bay (DI, D2) and comprising at least one Ultra Wide Band transceiver (UR1, UR2), - an access center (2) which is at least in communication with the access control reader (RI, R2) and which is linked to the locking / unlocking system of the at least one access control bay (DI, D2); in which the secure access control method (100) successively comprises at least: - a step of unlocking (ulock) the connected mobile terminal (1), causing said connected mobile terminal to switch from a locked state to an unlocked state; - a step of waking up (WP-1) the Ultra Wide Band (Ul) transceiver of the connected mobile terminal (1) which is implemented on condition at least that the unlocking step (ulock) has been carried out, and during which the Ultra Wide Band (Ul) transceiver of the connected mobile terminal (1) switches from the off state to a waking state in which it is configured to transmit and receive in the Ultra Wide Band communication mode; - a secure telemetry step (SR) between the secure access control reader (RI, R2) and the connected mobile terminal (1), during which their Ultra Wide Band transceivers (Ul, UR1, UR2) exchange in the Ultra Wide Band communication mode at least security data (sdatal, sdata2), and at the end of which a certified distance (sdist) is established and then verified between the secure access control reader (RI, R2) and the connected mobile terminal (1); said secure telemetry step (SR) being initiated on the condition at least that the step of unlocking (ulock) has been previously implemented; - an access control step (CS) during which the access center (2), after receiving the user identification data (udata), checks these to authorize or not access to the secure space (SI, S2) accessible by the access control bay (DI, D2) and, if necessary, controls the locking / unlocking system of said access control bay (DI, D2).
2. Secure access control method (100) according to claim 1, in which the access center (2) receives the user identification data (udata) on the condition that previously, during the secure telemetry step (SR), it has been verified that the certified distance (sdist) is less than or equal to an authorization distance (dauth).
3. Secure access control method (100) according to claim 1 or 2, wherein during the secure telemetry step (SR), the certified distance (sdist) between the connected mobile terminal (1) and the secure access control reader (RI, R2): - is established by being calculated by at least one of the connected mobile terminal (1) and the secure access control reader (RI, R2); and - verified either by the connected mobile terminal (1) or by the secure access control reader (RI, R2).
4. Secure access control method (100) according to any one of claims 1 to 3, in which the step of unlocking (ulock) the connected mobile terminal (1) is implemented by the user (U) according to at least one of the following operations: - switching on a touch screen that the connected mobile terminal (1) includes by the user (U) pressing on it, or on a switch-on button that the connected mobile terminal (1) also includes; - an operation of entering an unlocking code on the connected mobile terminal (1); - a touch input operation of an unlocking pattern on a touch screen of the connected mobile terminal (1); - an operation of recognizing a fingerprint on a fingerprint sensor of the connected mobile terminal (1); - a facial recognition operation of the user by means of a camera integrated into the connected mobile terminal (1).
5. Secure access control method (100) according to any one of claims 1 to 4, in which the access center (2) receives the user identification data (udata) from: - either the connected mobile terminal (1), which connected mobile terminal (1) has network access and contains a connection address (add-c) to connect remotely to the access center (2) and communicate with it; - either the secure access control reader (RI, R2), which secure access control reader (RI, R2) has network access to communicate with the access center (2), via direct communication or via step-by-step communication.
6. Secure access control method (100) according to claim 5, wherein, when the access center (2) receives the user identification data (udata) from the secure access control reader (RI, R2), the secure access control method (100) also comprises, prior to the access control step (CS), a transmission step during which the connected mobile terminal (1) transmits, in the Ultra Wideband communication mode, the user identification data (udata) to the secure access control reader (RI, R2); said transmission step being implemented: - following the unlocking step (ulock) and before the start of the secure telemetry step (SR), or - during the secure telemetry (SR) stage, or - once the secure telemetry (SR) stage is completed.
7. Secure access control method (100) according to any one of the preceding claims, wherein the secure access control reader (RI, R2) periodically transmits a probing signal (sscan) in the Ultra Wide Band communication mode, and wherein the secure telemetry step (SR) is started by the secure access control reader (RI, R2) following the reception of a confirmation signal (ack) from the connected mobile terminal (1) in the Ultra Wide Band communication mode; said confirmation signal (ack) being generated and then transmitted by the connected mobile terminal (1) on the condition that at least: the step of waking up (WP-1) of the Ultra Wide Band transceiver (Ul) of the connected mobile terminal (1) is implemented, then the connected mobile terminal (1) has received the probing signal (sscan) once in the woken up state.
8. Secure access control method according to any one of claims 1 to 6, wherein the telemetry step (SR) is started by the connected mobile terminal (1) when at least the wake-up step (WP-1) of the Ultra Wide Band transceiver (Ul) of the connected mobile terminal (1) is implemented, and said connected mobile terminal (1) is within an Ultra Wide Band communication range with the secure access control reader (RI, R2).
9. Secure access control method (100) according to any one of the preceding claims, in which the secure telemetry step (SR) is initiated on the condition at least: that the unlocking step (ulock) is implemented, and that at least one validation action (actl, act2) is also subsequently carried out on the connected mobile terminal (1); otherwise the secure telemetry step (SR) is not carried out.
10. Secure access control method (100) according to claim 9, wherein the at least one validation action (actl, act2) comprises at least one launch operation (opt) carried out in a launch menu displayed by a launch mobile application (l-app), loaded in the connected mobile terminal (1).
11. Secure access control method (100) according to claim 10, wherein the launch operation (opt) consists of at least one of the following operations: - an operation of entering a launch code on the launch menu; - a touch input operation of a launch pattern on the launch menu; - a validation operation on the launch menu.
12. Secure access control method (100) according to claims 9 and 10, wherein the launcher mobile application (l-app) opens automatically and displays the launcher menu following the unlocking step (ulock).
13. Secure access control method (100) according to any one of claims 9 to 12, wherein the at least one validation action (actl, act2) comprises at least one inclination (inc) of the connected mobile terminal (1) according to an inclination angle (tetal, teta2) included in a predefined launch angular interval.
14. A secure access control method (100) according to claims 10 and 13, wherein the launcher mobile application (l-app) opens and displays the menu launch under the condition that the inclination angle (tetal, teta2) is within the predefined launch angular range.
15. Secure access control method (100) according to claim 13 or 14, wherein the inclination angle (tetal) is measured by an inertial unit integrated into the connected mobile terminal (1).
16. Secure access control method (100) according to claim 13 or 14, wherein the tilt angle (teta2) is measured by the secure access control reader (RI, R2), from reception signals of an Ultra Wide Band wave coming from the connected mobile terminal (1).
17. Secure access control method (100) according to any one of the preceding claims, wherein, at its startup, the Ultra Wide Band transceiver (UR1, UR2) of the secure access control reader (RI, R2) is in a standby state by being configured to receive in the Ultra Wide Band communication mode and not to transmit in the Ultra Wide Band communication mode, and wherein, prior to the secure telemetry step (SR), a step of waking up (WP-R) of the Ultra Wide Band transceiver (UR1, UR2) of the secure access control reader (RI, R2) is implemented, initiated by a detection by at least one sensor (sensR1, sensR2) of an approach or contact of the user (U) or of the connected mobile terminal (1) with said secure access control reader (RI, R2), and wherein the Ultra Wide Band transceiver (UR1, UR2) of said secure access control reader (RI,R2) switches from the standby state to an awake state in which it is configured to transmit and receive in the Ultra Wide Band communication mode and thus allow the implementation of the secure telemetry step (SR); and so that in the absence of said wake-up step (WP-R), the secure telemetry step (SR) is not implemented., 18. Secure access control method (100) according to claim 17, wherein, during the step of waking up (WP-R) the Ultra Wide Band transceiver (UR1, UR2) of the secure access control reader (RI, R2), the detection of the approach or contact consists of a detection of the contact of the user (U) by the at least one sensor (sensRl, sensR2) arranged on a part of the secure access control reader (1).
19. Secure access control method (100) according to claim 18, wherein the at least one sensor (sensR1, sensR2) is chosen from a key, a mechanical sensor, a capacitive sensor, and an inductive sensor.
20. Secure access control method (100) according to claim 17, wherein, during the step of waking up (WP-R) the Ultra Wide Band transceiver (UR1, UR2) of the secure access control reader (RI, R2), the detection of the approach or contact consists of a detection by the at least one sensor (sensR1, sensR2) of the approach of the user (U) or the connected mobile terminal (1) with a part of the secure access control reader (RI, R2) within a given activation distance (d-act) relative to the secure access control reader (RI, R2).
21. Secure access control method (100) according to claim 20, wherein the at least one sensor (sensR1, sensR2) is chosen from a capacitive sensor, an inductive sensor, a radar sensor, an ultrasonic sensor, an optical sensor, a vibration sensor.
22. Secure access control method (100) according to claim 20 or 21, wherein the at least one sensor (sensR1, sensR2) is mounted on the secure access control reader (RI, R2), or is remote from the secure access control reader (RI, R2) and connected to the secure access control reader (RI, R2).
23. Access control method (100) according to claim 9, wherein the step of waking up (WP-1) the Ultra Wide Band transceiver (Ul) of the connected mobile terminal (1) is implemented on the condition that the at least one validation action (actl, act2) is also carried out.
24. Secure access control method (100) according to any one of the preceding claims, wherein the at least one secure space (SI, S2) comprises at least one other secure space (S2) accessible by at least one other access control bay (D2) equipped with another locking / unlocking system and associated with another secure access control reader (R2) comprising an Ultra Wide Band transceiver (UR2), wherein the secure access control method (100) comprises a step of generating (EG) an access indicator (coo) followed by a step of storing (Esto) said access indicator (coo) in the connected mobile terminal (1), the generation step (EG) and the storage step (Esto) being implemented when access to the secure space (SI) is authorized by the access center (2), and in which secure access control method (100) an access control phase (CP) is implemented to access the other secure space (S2) which comprises the following steps: - a detection step (ADD) of an access request made by the user (U) on the connected mobile terminal (1); - a transmission step (E7) during which the connected mobile terminal (1) transmits, in the Ultra Wide Band communication mode, the access indicator (coo) to the other secure access control reader (R2) in response to the detection of the access request; - a reception step (E7') during which the Ultra Wide Band transceiver (UR2) of the other secure access control reader (R2) receives the access indicator (coo); - a transmission step (E8) during which the other secure access control reader (R2) transmits said access indicator (coo) to the access center; - an access control step (CS2) during which the access center (2), after receiving the access indicator (coo), authorizes access to the other secure space (S2) accessible by the other access control bay (D2) and, where appropriate, controls the other locking / unlocking system of said other access control bay (D2), without receiving or verifying the user identification data (udata) by said access center (2).
25. Secure access control method (100) according to claim 24, wherein the access witness (coo) has a limited validity period.
26. Secure access control method (100) according to claim 2, wherein the authorization distance (dauth) is less than or equal to 1 m.