A secure access control method for authorizing access to a secure area, operating in a user-activated Ultra Broadband communication mode.
By awakening the secure access control reader only upon user detection and establishing a certified distance, the method addresses security vulnerabilities and energy inefficiencies in Ultra Wideband systems, ensuring secure and efficient access control.
Patent Information
- Application Number
- FR2023007365
- Authority / Receiving Office
- FR · FR
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2023-07-10
- Publication Date
- 2025-12-12
- Estimated Expiration
- 2043-07-10
AI Technical Summary
Existing secure access control systems using Ultra Wideband communication remain constantly activated, leading to security vulnerabilities, unnecessary energy consumption, and increased risk of data interception due to frequent and unintended user detection and telemetry, especially when users with no intention to access secure areas.
A method where the secure access control reader is awakened by user detection, followed by a secure telemetry step between a portable authentication device and the reader, establishing a certified distance before authorizing access, optimizing data exchanges and reducing power consumption.
This approach enhances security by validating user intent, reduces unnecessary data exchanges and power consumption, and minimizes the risk of unauthorized access and data interception.
Smart Images

Figure 00000049_0000 
Figure 00000049_0001 
Figure 00000050_0000
Abstract
Description
Title of the invention: Secure access control method for authorizing access to a secure area, operating in a user-activated Ultra Broadband communication mode. Technical field
[0001] The invention relates to a secure access control method for controlling and authorizing or denying a user access to a secure space.
[0002] It relates more particularly to a secure access control method based on Ultra Wide Band radio frequency communication.
[0003] The invention finds a favorite application in the implementation of a secure access control method involving an access control unit with which, via a secure access control reader, a user authenticates himself using a portable authentication device; the secure access control reader and the portable authentication device both operating in Ultra Wideband radio frequency communication mode and exchanging data for user authentication in this same communication mode. Previous technique
[0004] Ultra Wideband (UWB) is a well-known radio frequency modulation technique that has recently become more widespread. It is based on the transmission of pulses, generally shorter than a nanosecond, and is used in a wide frequency band, between 3.1 GHz and 10.6 GHz. Among the advantages of Ultra Wideband communication are a very high network data transfer rate over a wide bandwidth (greater than 500 MHz) over relatively short distances and at low power, without interfering with conventional narrowband and carrier wave transmissions in the same frequency bands. For simplicity, radio frequency systems using this modulation technique to exchange data are said to be communicating in Ultra Wideband mode.
[0005] Ultra Broadband technology being promising, it is now being considered in the design of geolocation, tracking, pairing (i.e. point-to-point data transfer), payment, and also access control solutions.
[0006] Indeed, some mobile phone models available on the market incorporate Ultra Wideband transceivers allowing them to communicate and exchange information in Ultra Wideband.
[0007] This is why secure access control readers incorporating Ultra Wideband transceivers are designed so that the implementation of access control solutions to authorize or deny a user access to a secure area, protected by an access control bay (door, airlock, barrier, etc.) equipped with a locking / unlocking system, which operate in Ultra Wideband communication mode, and for which the user identifies / authenticates themselves, via a secure access control reader, to an access control unit installed in the building and connected to the locking / unlocking system of the access control bay, by means of a mobile phone integrating an Ultra Wideband transceiver.Once the user approaches the secure access control reader so that it can detect the mobile phone, a secure ranging (or "securing ranging") telemetry step begins. During this step, the secure access control reader and the mobile phone exchange data, using a secure communication protocol, to authenticate the user. This data may include, for example, virtual identification keys, a user ID, etc. The data is transmitted by the secure access control reader to the access control unit. Upon receiving the data, the access control unit verifies it and, based on the result of this verification, authorizes or denies access to the secure area by activating the locking / unlocking system of the access control bay.
[0008] Due to the characteristics of the Ultra Wideband communication mode in terms of performance, accuracy, and speed, secure telemetry enhances the security of exchanges during point-to-point data transfers, drastically limiting the risks of interception of data transfer between a transmitter and a receiver, i.e., "man in the middle" attacks.
[0009] Detailed explanations of the operating principle of secure telemetry are given by NO Tippenhauer and S. Capkun in the technical report "UWB-based secure ranging and localization" published in 2012 (Technical Report / ETH Zurich, Department of Computer Science 586); and in the article "UWB with Puise Reordering: Secure Ranging against Relay and Physical-Layer Attacks" written by M. Singh, P. Leu, and S. Capkun and published in 2017 by the IACR (International Association for Cryptology Research - Network and Distributed Systems Security (NDSS) Symposium 2019, 24-27 February 2019, San Diego, CA, USA - ISBN 1-891562-55-X).
[0010] However, in the solutions currently proposed and available, the secure access control reader remains constantly activated in Ultra Wideband communication mode in order to locate the position of a user's mobile phone equipped with an Ultra Wideband transceiver in order to communicate with it and carry out secure telemetry in this communication mode.
[0011] The drawback of such an approach is that it presents security vulnerabilities because the mobile phone detection by the secure access control reader and secure telemetry occur if the user with the mobile phone passes near the access control point, regardless of whether or not they intend to access the secure area. If the access control system allows access to a user who is merely passing in front of the access control reader and has no intention of accessing it, it could potentially allow an unauthorized user to access the secure area protected by the access control bay.
[0012] Furthermore, if the mobile phone remains within the communication range of the secure access control reader for a certain period, the reader may periodically implement the secure telemetry step with the mobile phone; meaning that it will request the access control unit at regular intervals to verify the data it transmits. If the mobile phone user has access rights to the secure area but does not wish to enter, the periodic implementation of secure telemetry and data verification by the access control unit may result in repeated opening and closing of the access control bay.Besides unnecessarily straining the access control system, the increased exchanges between the mobile phone, the secure access control reader, and the access control system weaken their security because they increase the risk that the exchanged data could be intercepted by a malicious system.
[0013] Furthermore, when secure access control readers remain constantly activated in Ultra Wideband communication mode, they consume energy unnecessarily if they do not detect any mobile phone, or if they detect a user's mobile phone and start communicating with him when said user has no intention of entering a secure space whose access they control, or does not have the necessary accreditations.
[0014] Furthermore, the typical current consumption during Ultra Wideband communication, whether transmitting or receiving a signal, can range from a few tens to over a hundred milliamperes. Therefore, Ultra Wideband communication is energy-intensive and can be problematic when a deployed secure access control reader is battery-powered, as there is a risk that the battery will discharge after a period of activity, especially if the reader is consuming power simply to detect mobile phones when none are present or requesting access. Summary of the invention
[0015] The invention aims to address the aforementioned problems by proposing a secure access control method to control and authorize a user's access to at least one secure area accessible via at least one access control bay equipped with a locking / unlocking system. The secure access control method involves several pieces of equipment, including: - a portable authentication device worn by the user and containing the user's identification data, said portable authentication device comprising at least one Ultra Wideband transceiver, - at least one secure access control reader associated with at least one access control bay and comprising at least one Ultra Wideband transceiver, - an access control unit which is at least in communication with the access control reader and which is linked to the locking / unlocking system of at least one access control bay; in which the secure access control process includes at least: - a step of waking up the secure access control reader initiated by a detection by at least one sensor of an approach or contact of the user or the portable authentication device with said secure access control reader, and followed by a waking up of the Ultra Wideband transceiver of said secure access control reader in order to be able to transmit and receive in an Ultra Wideband communication mode; - a secure telemetry step between the secure access control reader and the portable authentication device, during which their Ultra Wideband transceivers exchange at least security data in Ultra Wideband communication mode, and at the end of which a certified distance between the secure access control reader and the portable authentication device is established and then verified; - an access control step during which the access control unit, after receiving the user's identification data, verifies this data to authorize or deny access to the secure area accessible through the access control bay and, if necessary, commands the locking / unlocking system of said access control bay.
[0016] Thus, the secure telemetry step is implemented only if the Ultra Wideband transceiver of the secure access control reader is awake; this awakening occurs following the wake-up step and therefore following the detection by the secure access control reader of an approach or contact by a user or their portable authentication device with respect to this secure access control reader. The awakening of the Ultra Wideband transceiver of the secure access control reader means that it transitions from a standby state (in which it can only receive, but it cannot transmit), towards an awake state (in which it can both transmit and receive).
[0017] It should be noted that, for the implementation of the secure telemetry step, the Ultra Wideband transceiver of the portable authentication device must also be in the awake state, in order to be able to transmit and receive in the Ultra Wideband communication mode.
[0018] Advantageously, implementing the wake-up step allows: - to validate a concrete intention of the user to want to access a secure space accessible from the access control bay associated with the secure access control reader; - to optimize the exchanges between the secure access control reader, the portable authentication device and the access control unit by limiting them to the exchanges useful and necessary for the implementation of the secure access control process; - to reduce the strain on the access control system by implementing a single access control step; - in connection with the two previous points, to strengthen the security of exchanges and reduce the risks of data interception by a malicious system; - to reduce power consumption in the Ultra Wideband mode of the secure access control reader, and possibly, if it is powered by a battery, to save the battery.
[0019] During the secure telemetry step, the portable authentication device and the access control reader exchange security data. At the end of the secure telemetry step, a certified distance between the secure access control reader and the portable authentication device is also established and then verified.
[0020] During the access control step, the access control unit checks the user's identification data (or, in English, credentials) to determine if he has the accreditations to enter the secure area.
[0021] According to different embodiments of the invention, the locking / unlocking system of the access control bay, which may for example correspond to a strike plate opening and closing, may either be physically connected by a cable to the access control unit, or be linked to the access control unit through a wireless connection.
[0022] According to one feature of the invention, the access control unit receives the user identification data on the condition that prior to, during the secure telemetry stage, it has been verified that the certified distance is less than or equal to an authorization distance.
[0023] In other words, the transmission of the user's identification data to the access control unit for the implementation of the access control step is conditional by a certified distance check performed after the secure telemetry step. This certified distance check verifies whether it is within, or equal to, an authorized distance. If so, the user's identification data is transmitted to the access control center. If not, it is not transmitted.
[0024] This distance control is an additional security measure to ensure that the user with the required credentials is near the secure access control reader and / or the access control bay before unlocking the bay's locking / unlocking system. This is because the user may have moved away from the secure access control reader or the bay; or, if the wake-up step relies on user approach detection, the secure access control reader may have detected the presence of the user or their portable authentication device even though they are at a distance from it and / or the access control bay.
[0025] According to one possibility, the method includes, prior to the secure telemetry step, a step of waking up the portable authentication device in which the Ultra Wideband transceiver of said portable authentication device is woken up in order to be able to transmit and receive in the Ultra Wide communication mode.
[0026] The Ultra Wideband transceiver of the wearable authentication device is designed to transmit and receive in Ultra Wideband communication mode when it is in a so-called awake state; and only receive in Ultra Wideband communication mode when it is in a so-called standby state. Waking up the Ultra Wideband transceiver of the wearable authentication device means that it transitions from the standby state to the awake state (in which it can both transmit and receive).
[0027] In various application contexts, the portable authentication device may include a battery for its power supply. To reduce power consumption and conserve battery energy in the portable authentication device, the Ultra Wideband transceiver of the portable authentication device is, at the start of the access control process, in a standby state, thus only capable of receiving data in Ultra Wideband communication mode (but not transmitting it). However, in order for the secure telemetry step to be implemented, and for the authentication device to communicate with the secure access control reader, it is essential that its Ultra Wideband transceiver be in the awake state or switch to the awake state.This is why the secure access control process may include, prior to the secure telemetry stage, a wake-up stage. portable authentication device to wake up your Ultra Wideband transceiver.
[0028] In other application contexts, this wake-up step is not necessary because the transmitter-receiver of the portable authentication device is already woken up when the secure access control process starts.
[0029] According to one embodiment of the invention, after the wake-up step of the secure access control reader, the secure access control reader emits a wake-up signal in Ultra Wideband communication mode which is received by the Ultra Wideband transceiver of the portable authentication device, causing the wake-up step of the portable authentication device (in other words, causing its Ultra Wideband transceiver to wake up).
[0030] Following the wake-up step, the secure access control reader sends a wake-up signal in Ultra Wideband communication mode to the Ultra Wideband transceiver of the portable authentication device, which is in standby mode and therefore able to receive this wake-up signal. Once the portable authentication device receives this wake-up signal, its Ultra Wideband transceiver switches to the awake state, enabling it to transmit data in Ultra Wideband communication mode, and thus participate in the secure telemetry state.
[0031] According to an embodiment of the invention, prior to the secure telemetry step, a wake-up action is performed by the user on the portable authentication device in order to trigger the wake-up step of the portable authentication device.
[0032] In other words, the awakening of the Ultra Wideband transceiver is, in one embodiment, triggered by an interaction of the user on their portable authentication device, this interaction being referred to as a wake-up action. This embodiment can be implemented in the case where the access control reader, once its Ultra Wideband transceiver has awakened, is not configured / designed to send a wake-up signal to the portable authentication device.
[0033] According to one embodiment of the invention, the portable authentication device initiates the secure telemetry step following the wake-up step of said portable authentication device (in other words following the wake-up of its Ultra Wideband transceiver).
[0034] In this embodiment of the invention, the portable authentication device is the master and the secure access control reader is the slave. In other words, the portable authentication device initiates the secure telemetry step provided that its The Ultra Wide Band transceiver and the secure access control reader should be woken up.
[0035] According to one embodiment of the invention, the secure access control reader initiates the secure telemetry step after receiving, in Ultra Wideband communication mode, a start signal from the portable authentication device, said start signal being emitted by the portable authentication device following the wake-up step of said portable authentication device (in other words following the wake-up of its Ultra Wideband transceiver).
[0036] In this embodiment, the secure access control reader sends a wake-up signal to the portable authentication device so that the latter wakes up its Ultra Wideband transceiver. The access control reader awaits a response from the portable authentication device to initiate the secure telemetry step. This response takes the form of the secure access control reader receiving the start signal from the portable authentication device, which start signal is emitted when the portable authentication device's Ultra Wideband transceiver wakes up.
[0037] In one embodiment of the invention, during the secure telemetry step, the certified distance: - is established by being calculated by at least one of the portable authentication device and the secure access control reader, then - verified either by the portable authentication device or by the secure access control reader.
[0038] In one embodiment of the invention, only one of the two pieces of equipment, the portable authentication device and the secure access control reader, calculates the certified distance.
[0039] It is also possible for both the portable authentication device and the secure access control reader to calculate the distance between them. Each exchanges the distance value they have calculated. Each device then compares the distance it received with the distance it calculated itself. If the distances are not consistent, the telemetry step is stopped. If they are consistent, the telemetry step continues.
[0040] In one embodiment of the invention, the certified distance is calculated from a time-of-flight measurement, carried out by at least one of the two pieces of equipment, during at least one bidirectional exchange of safety data.
[0041] More specifically, during the secure telemetry step, a distance is calculated between the portable authentication device and the secure access control reader, said distance being certified by nature, hence the notion of certified distance.
[0042] The distance is certified by nature because it occurs during the secure telemetry step, and because it relies on at least one bidirectional exchange of Ultra Wideband signals between two pieces of equipment (the wearable authentication device and the secure access control reader) each having: an embedded secure component; or a previously loaded trusted firmware or application inside, or a Trusted Execution Environment (TEE).
[0043] Certified distance is an additional means of strengthening the security level of the secure access protocol when it needs to be verified to determine whether or not to implement the subsequent access control step. Indeed, an uncertified distance could potentially be fraudulent and originate from a malicious system seeking to gain access to the secure area protected by the access control bay. Thus, if the equipment responsible for verifying the certified distance, but not for calculating it, receives a certified distance, it implements its verification. Conversely, if the received distance is not certified, the verification is not performed and the secure access control process is stopped.
[0044] As previously stated, once the certified distance has been calculated, the secure telemetry step continues with a check to verify whether it is less than or equal to the authorized distance. This verification can be performed using the secure access control reader or the portable authentication device.
[0045] In a first embodiment in which the certified distance is calculated by only one of the two pieces of equipment among the secure access control reader and the portable authentication device, the equipment in charge of calculating the certified distance is also the one that controls it.
[0046] In a second embodiment in which the equipment in charge of the calculation is not the same as that in charge of verifying the certified distance, there is transmission of the certified distance from the equipment that calculated it to the equipment that is to verify it.
[0047] The secure telemetry step may not be limited to the exchanges and principles described above. Further information on secure telemetry is available in the two references indicated in the Prior Art.
[0048] According to one feature of the invention, the access control unit receives the user's identification data from: - either the secure access control reader, which secure access control reader has network access to communicate with the access control unit, via direct communication or via hop-by-hop communication (first embodiment); - either the portable authentication device, which portable authentication device has network access and contains a connection address to connect remotely to the access control unit and communicate with it (second embodiment).
[0049] According to one embodiment of the invention, the certified distance is verified by the equipment among the portable authentication device and the secure access control reader in charge of transmitting the user's identification data to the access control unit.
[0050] Given that the access control reader and the portable authentication device exchange their respective security data, in another embodiment in which the equipment among the portable authentication device and the secure access control reader verifying the certified distance is not the same as that in charge of transmitting the user's identification data to the access control unit, the equipment in charge of verifying the certified distance sends, if the certified distance is within the authorization distance, an authorization signal to the equipment in charge of transmitting the user's identification data so that it implements said transmission.
[0051] In a first embodiment of the invention, the user's identification data is transmitted to the access control unit by the secure access control reader. This configuration can be implemented because the portable authentication device does not have network access.
[0052] If it is responsible for initiating the secure telemetry step, calculating and verifying the certified distance, and transmitting the user identification data to the access control unit, the secure access control reader then plays the central role in the execution of the secure access control process.
[0053] Advantageously, the calculation and verification of the certified distance, and then the transmission of the user identification data to the access control center by the secure access control reader, makes it possible to significantly strengthen the level of security of the secure access control process since, by definition, the secure access control reader is a trusted system designed and compliant to be an integral part of an access control installation implementing secure access control processes.
[0054] In a first variant of the first embodiment, the secure access control reader is in wireless communication with the access control unit and transmits the user's identification data directly to it.
[0055] In a second variant of the first embodiment, the secure access control reader and the access control unit are part of a mesh network comprising several other secure access control readers. Each of the devices of the A mesh network is capable of communicating with its close neighbors using a hop-by-hop communication protocol. Advantageously, the mesh network addresses the problem of indoor network coverage when the building structure and the materials used for its construction interfere with signal transmission, preventing, for example, the secure access control reader involved in the secure access control process and the access control unit from communicating with each other, even if they are within communication range (for example, because they are located in the basement, or on different floors of a building, or separated by a thick wall, etc.).
[0056] Not limited to, the secure access control reader and the access control unit can communicate with each other using a wireless communication protocol such as Wifi® or Bluetooth Mesh®.
[0057] In a third variant of the first embodiment, the secure access control reader is in wired / physical connection with the access control unit (for example, by means of Ethernet links, or an RS485 interface), so that it can transmit the user identification data directly to it via wired connection.
[0058] In a second embodiment of the invention, the portable authentication device transmits the user's identification data to the access control unit if the user has network access and a connection address to remotely connect to the access control unit. This second embodiment can be implemented because the secure access control reader is self-contained and therefore does not have direct contact with the access control unit.
[0059] The connection address may correspond to data previously loaded into the portable authentication device, or to data transmitted by the secure access control reader to the portable authentication device when the secure telemetry step is implemented.
[0060] Moreover, if the portable authentication device initiates the secure telemetry step, calculates and verifies the certified distance, it then plays the central role in the execution of the secure access control process.
[0061] According to one embodiment of the invention, when the access control unit receives the user's identification data from the secure access control reader, the secure access control process also includes, prior to the access control step, a transmission step during which the portable authentication device transmits, in Ultra Broadband communication mode, the user's identification data to the secure access control reader; said transmission step being implemented as follows: - following the wake-up step of the secure access control reader and before the secure telemetry step begins, or - during the secure telemetry stage, or - once the secure telemetry stage is completed.
[0062] In other words, if the user's identification data is transmitted to the access control unit by the secure access control reader, the portable authentication device must implement a step to transmit the user's identification data to the secure access control reader. As indicated above, this transmission step can be implemented before, during, or after the secure telemetry step.
[0063] The implementation of the step of transmitting the user's identification data to the secure access control reader, where it is planned to take place before the secure telemetry step, requires at a minimum that the Ultra Wideband transceiver of the portable authentication device be in the awake state. In embodiments where the Ultra Wideband transceiver of the portable authentication device is woken up upon receiving the wake-up signal from the secure access control reader, the transmission of the user's identification data may occur simultaneously with the transmission of the start signal by the portable authentication device.
[0064] Where the transmission step is scheduled to take place after the secure telemetry step and before the access control step, it is possible for said transmission step to be implemented provided that it has been verified that the certified distance is less than or equal to the authorization distance. In other words, if the certified distance is greater than the authorization distance, neither the transmission step nor the access control step is implemented. Otherwise, if the certified distance is valid, then it is possible to: - when the portable authentication device performs the check and validation of the certified distance, it must transmit the user's identification data immediately after validating the certified distance; or else - when the secure access control reader is in charge of controlling and validating the certified distance, it sends a request signal to the portable authentication device after validation of the latter, which portable authentication device, after receiving said request signal, transmits the user's identification data to the secure access control reader.
[0065] In a first embodiment, during the wake-up step of the secure access control reader, the detection of approach or contact consists of detecting contact from the user by at least one sensor located on a part of the secure access control reader.
[0066] In this first embodiment, at least one sensor can be chosen from a touch, a mechanical sensor, a capacitive sensor, and an inductive sensor.
[0067] In other words, according to different embodiments of the invention, the detection of user contact may, but is not limited to: - contact of a user's hand on a part of the secure access control reader, detected for example by means of electrostatic sensors (inductive sensor, capacitive sensor) or sound or optical sensors; - pressing a key or button that the secure access control reader includes on its casing or on a touchpad.
[0068] In a second embodiment, during the wake-up step of the secure access control reader, the approach or contact detection consists of a detection by at least one sensor of the approach of the user or the portable authentication device with a part of the secure access control reader within a given activation distance from the secure access control reader.
[0069] In this second embodiment, at least one sensor can be chosen from a capacitive sensor, an inductive sensor, a radar sensor, an ultrasonic sensor, an optical sensor, a vibration sensor.
[0070] In other words, according to different embodiments of the invention, the detection of the user's approach may, but is not limited to, relate to: - detection of user or wearable authentication device movements by a motion sensor (e.g., a passive infrared motion sensor); - vibrations caused by the user's steps on the ground, which are detected by an accelerometer; - a microphone detects the sounds caused by the user's footsteps on the floor.
[0071] The approach of the user or their portable authentication device is detected when they are within a distance of the secure access control reader that is less than or equal to an activation distance.
[0072] In one embodiment of the invention, the activation distance is defined by the designers or installers of the secure access control reader as being equal to the authorization distance.
[0073] In another embodiment of the invention, the activation distance is defined by the designers or installers of the secure access control reader as being substantially equal to the authorization distance, for example the activation distance is equal to 1.25 times the authorization distance.
[0074] According to one feature of the invention, at least one sensor is mounted on the secure access control reader, or is remote from the secure access control reader and in connection with the secure access control reader.
[0075] In other words, at least one sensor detecting an approach of the user or their portable authentication device can be integrated into the secure access control reader or remote from it.
[0076] In one embodiment of the invention, the remote sensor is integrated into a housing that also includes a push button which the user presses. The housing is, for example, fixed to a wall in the space where the secure access control reader is located.
[0077] According to variant embodiments of the invention, the remote sensor is physically connected to the secure access control reader by a cable; or communicates with it by means of a wireless communication protocol (for example, Bluetooth Low Energy BLE®).
[0078] According to a first possibility, the portable authentication device is a physical access card or badge equipped with its Ultra Wide Band transceiver.
[0079] According to a second possibility, the portable authentication device is a connected mobile terminal, such as a mobile phone, a touch tablet or a smartwatch.
[0080] According to a feature of the invention, the connected mobile terminal participates in the secure telemetry step with the secure access control reader if the user has previously performed at least one validation action on the connected mobile terminal, otherwise the secure telemetry step is not performed.
[0081] In certain application contexts, the secure access control reader may have detected contact with or an approach by the user without the user intending to access the secure area, because: the user accidentally touched or brushed against the reader; because the user is moving near the secure access control reader, such that the distance between the user and the secure access control reader falls within the activation distance; or another person touches the secure access control reader while an authorized user is near the secure access control reader, etc. Thus, the wake-up step of the secure access control reader is accidentally implemented, followed by the secure telemetry step and the access control step.
[0082] Advantageously, the validation action is an additional security in the implementation of the secure access control process, to ensure that the user of the connected mobile terminal actually intends to access the secure space protected by the access control bay associated with the secure access control reader. Until this validation action is carried out, the telemetry step, and the subsequent access control step, are not implemented.
[0083] Other advantages are: reducing the power consumption of the secure access control reader and the connected mobile terminal in Ultra Wideband communication mode, by not making them perform an unwanted secure telemetry step; and not unnecessarily stressing the access control unit.
[0084] When the user identification data transmission step is scheduled to occur before the secure telemetry step, and the portable authentication device is a connected mobile terminal, it is possible for this step to be implemented after at least one validation action has been completed. If at least one validation action comprises several validation actions, the transmission step can be implemented after the completion of the last of these validation actions.
[0085] According to one embodiment of the invention, at least one validation action includes at least the wake-up action which triggers the wake-up step of the connected mobile terminal.
[0086] This embodiment can be implemented, for example, if the Ultra Wideband transceiver of the connected mobile terminal is in a standby state at the start of the secure access control process, and the secure access control reader is not configured to send a wake-up signal to the connected mobile terminal following the wake-up step of the secure access control reader in order to wake it up.
[0087] According to another embodiment of the invention, the connected mobile terminal transmits the start signal to the secure access control reader following the completion of at least one validation action.
[0088] In other words, in this other embodiment of the invention in which the secure telemetry step is implemented by the access control reader following the reception of the start signal from the connected mobile terminal, said start signal is sent once the user has performed at least one validation action.
[0089] In one embodiment of the invention, at least one validation action is the cause of the wake-up of the Ultra Wideband transceiver of the connected mobile terminal and the sending of the start signal; the sending of the start signal occurring automatically following the wake-up of the Ultra Wideband transceiver of the connected mobile terminal.
[0090] According to one embodiment of the invention, at least one validation action includes at least one unlocking of the connected mobile terminal, taking said connected mobile terminal from a locked state to an unlocked state.
[0091] In other words, the telemetry step, then the access control step, are carried out on the condition that: the Ultra Wide Band transceivers of the secure access control reader and the connected mobile terminal are both awake, and that the user has unlocked his connected mobile terminal.
[0092] According to one embodiment of the invention, the unlocking of the connected mobile terminal is implemented by the user according to at least one of the following operations: - a touch screen activation included in the connected mobile terminal by the user pressing it, or by pressing a power button also included in the connected mobile terminal; - an operation to enter an unlock code on the connected mobile terminal; - an operation to enter an unlock pattern on the touch screen of the connected mobile terminal; - a fingerprint recognition operation on a fingerprint sensor of the connected mobile terminal; - a facial recognition operation of the user using a camera integrated into the connected mobile terminal.
[0093] In one embodiment of the invention, the connected mobile terminal initiates the secure telemetry step following its unlocking.
[0094] In one embodiment of the invention, following its unlocking, the connected mobile terminal transmits the start signal to the secure access control reader so that the latter initiates the secure telemetry step.
[0095] According to one embodiment of the invention, at least one validation action includes at least one launch operation carried out in a launch menu displayed by a mobile launch application, loaded in the connected mobile terminal.
[0096] In other words, the telemetry step, then the access control step, are carried out on the condition that: the Ultra Wide Band transceivers of the secure access control reader and the connected mobile terminal are both awake, and that the user has performed a launch operation carried out in the launch menu of a dedicated application designed for the implementation of the secure access control process, and previously loaded into the connected mobile terminal.
[0097] In a particular embodiment, at least one validation action consists of unlocking the connected mobile terminal, followed by the launch operation.
[0098] In other words, the user must unlock his connected mobile terminal, then perform the launch operation in the launch menu, so that the secure telemetry step can be carried out.
[0099] According to one embodiment of the invention, the launching operation consists of at least one of the following operations: - an operation to enter a launch code on the launch menu; - a touch input operation of a launch pattern on the launch menu; - a validation operation on the launch menu.
[0100] In one embodiment of the invention, the connected mobile terminal initiates the secure telemetry step following the execution of the launch operation.
[0101] In one embodiment of the invention, following the execution of the launch operation, the connected mobile terminal transmits the start signal to the secure access control reader so that the latter initiates the secure telemetry step.
[0102] According to one embodiment of the invention, the mobile launch application opens automatically and displays the launch menu following the unlocking of the connected mobile terminal.
[0103] In one embodiment of the invention, the user must first unlock his mobile, then interact with the mobile launch application and execute the launch operation so that the connected mobile terminal starts communicating with the secure access control reader to initiate the telemetry step.
[0104] In one embodiment of the invention, the connected mobile terminal initiates the secure telemetry step following its unlocking and the execution of the launch operation in the mobile launch application.
[0105] According to one embodiment of the invention, at least one validation action includes at least one tilting of the connected mobile terminal through a tilt angle within a predefined launch angular range.
[0106] In one embodiment of the invention, the user's validation action corresponds to a certain orientation / tilt of the connected mobile terminal relative to the secure access control reader, or to the ground. The orientation of the connected mobile terminal is considered valid if the tilt angle of the connected mobile terminal relative to the secure access control reader or to the ground is within a predefined angular range. This verification is performed either by the connected mobile terminal or by the secure access control reader.
[0107] If the tilt angle of the connected mobile terminal is valid, then the secure telemetry step is initiated.
[0108] The angular launch interval can be representative of an orientation of the connected mobile terminal such as: - the front face of the connected mobile terminal faces or is very close to facing the user; - the rear face of the connected mobile terminal faces or is very close to facing the secure access control reader.
[0109] According to one embodiment of the invention, the mobile launch application opens and displays the launch menu on the condition that the tilt angle is within the predefined launch angular range.
[0110] In other words, the mobile launch application is only displayed on the touch screen of the connected mobile terminal if the user tilts their connected mobile terminal at a valid tilt angle within the launch angular range.
[0111] The secure telemetry step is therefore initiated only following two actions by the user: proper orientation of the connected mobile terminal, and execution of the launch operation in the mobile launch application.
[0112] In one embodiment of the invention, the mobile launch application opens and displays the launch menu on the condition that the connected mobile terminal is unlocked, and the tilt angle is within the predefined launch angular range.
[0113] In one embodiment of the invention, the connected mobile terminal initiates the secure telemetry step successively: - to unlocking the connected mobile terminal; - to the tilt of the connected mobile terminal such that the tilt angle is within the launch angular range; and - to the execution of the launch operation in the launch menu of the mobile launch application.
[0114] According to one embodiment of the invention, the angle of inclination is measured by means of an inertial measurement unit integrated into the connected mobile terminal.
[0115] In other words, in one embodiment, the angle of inclination is measured by the connected mobile terminal using an inertial measurement unit that it contains.
[0116] In one embodiment of the invention, the connected mobile terminal verifies whether the measured tilt angle is within the launch angular range. If it is, then: - the connected mobile terminal generates the start signal and transmits it to the secure access control reader so that it initiates the secure telemetry step; or - the connected mobile terminal initiates the secure telemetry step if it is in charge of it.
[0117] In another embodiment, the connected mobile terminal transmits its tilt angle measurement to the secure access control reader so that the latter can verify whether it falls within the launch angular range. If so: - the access control reader initiates the secure telemetry step if it is responsible for it; or else - transmits a confirmation signal to the connected mobile terminal, which upon receiving said confirmation signal, initiates the secure telemetry step.
[0118] According to another embodiment of the invention, the tilt angle is measured by the secure access control reader, from reception signals of an Ultra Wideband wave from the connected mobile terminal.
[0119] This embodiment assumes that the transceiver of the connected mobile terminal is awake. In a first configuration, the transceiver of the connected mobile terminal is woken up when the secure access protocol starts, meaning that the tilt angle measurement can be performed by the secure access control reader before the wake-up step of said secure access control reader (since its Ultra Wideband transceiver is capable of receiving Ultra Wideband signals). In a second configuration, the transceiver of the connected mobile terminal is in a sleep state when the secure access protocol starts.The tilt angle measurement is then performed after the wake-up step of the secure access control reader, and after the Ultra Wideband transceiver of the connected mobile terminal has been woken up following receipt of the wake-up signal from the secure access control reader.
[0120] In an embodiment where the connected mobile terminal is configured to initiate the secure telemetry step, then: - either the secure access control reader transmits the angle measurement it has measured to the connected mobile terminal for verification and then implementation or not of said secure telemetry step; - either transmits a confirmation signal confirming that the tilt angle is contained within the launch angular range, the connected mobile terminal implementing the secure telemetry step upon receipt of the confirmation signal.
[0121] According to one feature of the invention, the at least one secure space comprises at least one other secure space accessible by at least one other access control bay equipped with another locking / unlocking system and associated with another secure access control reader comprising an Ultra Wideband transceiver, wherein the secure access control method comprises a step of generating an access token followed by a step of storing said access token in the connected mobile terminal, the generation step and the storage step being implemented when access to the secure space is authorized by the access control unit, and wherein the secure access control method implements an access control phase to access the other secure space which comprises the following steps: - a step to detect an access request made by the user on the connected mobile terminal; - a transmission step during which the connected mobile terminal transmits, in Ultra Wideband communication mode, the access indicator to the other secure access control reader in response to the detection of the access request; - a reception stage during which the Ultra Wideband transceiver of the other secure access control reader receives the access indicator; - a transmission step during which the other secure access control reader transmits said access indicator to the access control unit; - an access control step during which the access control unit, after receiving the access indicator, authorizes access to the other secure space accessible through the other access control bay and, if necessary, commands the other locking / unlocking system of said other access control bay, without receiving or verifying the user's identification data by said access control unit.
[0122] Indeed, a building may include several secure areas with restricted access, each of the secure areas being protected by its own access control bay, to which a secure access control reader is associated.
[0123] In an embodiment of the invention, in which the secure access control readers have network access and can communicate with the access control unit, when a secure telemetry step is implemented between a secure access control reader associated with a building access control bay and the portable authentication device of a user wishing to access a first secure space protected by said access control bay, and the access control unit authorizes the user to enter the secure space, an access token (or “cookie” in English) is generated and then stored in the connected mobile terminal.
[0124] In one embodiment of the invention, the access indicator is generated and then transmitted by the access control unit to the connected mobile terminal, either directly if the connected mobile terminal and the access control unit are in direct communication, or via the secure access control reader that previously participated in the secure telemetry step (via direct communication between the access control unit and the secure access control reader, or via hop-by-hop communication with other secure access control readers).
[0125] In another embodiment of the invention, the access token is generated by the connected mobile terminal by means of a dedicated application previously loaded inside; the generation may, for example, follow the receipt of data relating to an agreement to generate an access token from the access control center.
[0126] Advantageously, the access indicator is used to speed up user authentication with the access control system if the user wishes to pass through another access control bay to enter a second secure area of the building.
[0127] To do this, when the user approaches the secure access control reader associated with this other access control bay, the user interacts with their connected mobile terminal so that it detects a request (i.e., an intention) for access.
[0128] According to different embodiments of the invention, the access request can be detected following: - to a contact of the user with their connected mobile terminal; - an orientation / tilt of the connected mobile terminal with respect to the secure access control reader of the other access control bay; - to unlocking the mobile phone; - to a launch operation performed in a mobile application.
[0129] In other words, the methods used to detect the user's validation action from their connected mobile terminal to previously implement the secure telemetry step can also be used to detect the access request.
[0130] Once the access request is detected, the connected mobile terminal transmits only the access indicator to the secure access control reader of the other access control bay, which relays it to the access control center (via direct communication or hop-by-hop communication).
[0131] Upon receipt of the access token, the access control unit then authorizes the user to access the second secure space; this without having carried out a verification of the user's identification data.
[0132] In one embodiment of the invention, the access indicator is generated based on the user's identification data.
[0133] In other words, the access token only allows the user to facilitate their authentication to access secure areas for which they have the required credentials. The access token does not allow the user to access secure areas to which they are not authorized.
[0134] According to a feature of the invention, the access indicator has a limited validity period.
[0135] Advantageously, in order to secure simplified user authentication using an access token, said access token has a limited validity period. Once the validity period has expired, the access token expires. User authentication with the access control system to access a secure area then consists of repeating, at a minimum, the wake-up and telemetry steps. secure, and access control (with control by the access control center of the user's identification data).
[0136] According to one embodiment of the invention, the authorization distance is less than or equal to 1 m. Brief description of the drawings
[0137] Other features and advantages of the present invention will become apparent from the following detailed description of a non-limiting implementation example, made with reference to the accompanying figures in which:
[0138] [Fig-1] is a schematic view of an example of a building comprising two secure spaces, each protected by an access control bay which includes a locking / unlocking system, controlled by an access control unit, and which is associated with a secure access control reader operating in Ultra Wideband communication mode, with a user seeking to access one of the secure spaces by authenticating with the access control unit via a secure access control reader, this by means of a portable authentication device;
[0139] [Fig.2] is a schematic view of a bidirectional data exchange, in the Ultra Broadband communication mode, between a portable authentication device, which can correspond to a connected mobile terminal or a physical access card, and a secure access control reader;
[0140] [Fig.3] is a diagram of the operation of a first embodiment of the secure access control method, where the portable authentication device can correspond to either a connected mobile terminal or a physical access card;
[0141] [Fig.4] is a schematic view of a first implementation variant of a wake-up step included in the secure access control process to switch the Ultra Wideband transceiver of the secure access control reader from a standby state to a woke state in which it is able to transmit and receive data in Ultra Wideband communication mode; the wake-up of the Ultra Wideband transceiver occurring following detection of physical contact of the user with the secure access control reader;
[0142] [Fig.5] is a schematic view of a second variant of the implementation of the step wake-up, with the Ultra Wideband transceiver waking up following detection of an approach by the user, or their portable authentication device, within a given activation distance from the secure access control reader;
[0143] [Fig.6] is a schematic view of a principle for calculating a flight time during a bidirectional data exchange between the portable authentication device and the secure access control reader during a secure telemetry step implemented during the secure access control process;
[0144] [Fig.7] is an illustration, following the secure telemetry step, of a transmission data to authenticate the user from the secure access control reader to the access control unit which is configured to control the user's identification data in order to authorize or not the user to access a secure area, the transmission of data can be done by direct communication ([Fig.7]-a) or by hop-by-hop communication ([Fig.7]-b);
[0145] [Fig.8] is a schematic view of a validation action to be performed for implement the telemetry step following the wake-up step of the secure access control reader, said validation action being implemented only in embodiments for which the portable authentication device is a connected mobile terminal, and corresponding here, in a given embodiment variant, to a launch operation performed by the user on a launch menu available from a mobile launch application included in the connected mobile terminal;
[0146] [Fig.9] is a schematic view of a second variant of the implementation of the action of validation, which corresponds to an inclination of the connected mobile terminal relative to the ground and the secure access control reader;
[0147] [Fig. 10] is an operating diagram of a second embodiment of the secure access control process where the portable authentication device is a connected mobile terminal, which operating diagram includes the performance of validation actions necessary to start the secure telemetry step;
[0148] [Fig. 11] is a schematic view of an embodiment of the secure access control method, in which the transmission of user identification data following the secure telemetry step is implemented by the connected mobile terminal, which has a connection address to connect to the access control center to make said transmission possible;
[0149] [Fig. 12] is an operating diagram of a third embodiment of the secure access control method where the portable authentication device is a connected mobile terminal, which secure access control method includes in particular the generation and then the storage of an access token in the user's connected mobile terminal following authorization of access to a first secure space by the access control center, said access token subsequently being used to accelerate the authentication of the user with another secure access control reader to access another secure space;
[0150] [Fig. 13] is a schematic view of the building of [Fig. 1] and illustrating an application context related to the operating diagram of [Fig. 12], for which The user, after entering a secure area, will use the access token contained in their connected mobile terminal to authenticate themselves with the access control center to access another secure area;
[0151] [Fig. 14] is a schematic view related to [Fig. 12] and [Fig. 13], in which, in one embodiment, and in order to authenticate itself with the access control center, the connected mobile terminal transmits the access indicator to another secure access control reader following the detection of a contact, here a tap, from the user.
[0152] [Detailed description of one or more embodiments of the invention]
[0153] With reference to [Fig.1] and [Fig.2], the secure access control method 100 of the invention, designed to operate in Ultra Wideband communication mode, is implemented in the application context of a building comprising at least two secure spaces SI, S2 whose access is protected by access control bays D1, D2 each equipped with a locking / unlocking system, and each associated with a secure access control reader RI, R2 comprising an Ultra Wideband transceiver UR1, UR2 in order to be able to transmit and receive signals / data in this communication mode.
[0154] In the rest of the description: - the secure SI, S2 spaces are designated under the terms secure SI space and other secure S2 spaces; - Access control bays D1 and D2 are referred to as access control bay D1 and other access control bay D2; and - RI, R2 secure access control readers are referred to as RI secure access control reader and other R2 secure access control reader.
[0155] It is also assumed in the rest of the description that a user U wishes to access the secure space SL. To do this, he must authenticate himself with the secure access control reader RI by means of a portable authentication device 1, 10; which portable authentication device 1, 10 also includes an Ultra Wideband transceiver Ul, U10 in order to be able to transmit and receive in the Ultra Wideband communication mode.
[0156] The portable authentication device may, but is not limited to: - an access card, or a badge, or a key fob, etc. - or to a connected mobile terminal 1 equipped with a touch screen, for example: a mobile phone, a touch tablet, a smartwatch, etc.
[0157] The Ultra Wideband transceivers UR1, UR2, Ul, U10 of the secure access control readers RI, R2 and of the portable authentication device 1, 10 can operate: - in a standby state, only capable of receiving Ultra Wideband data / signals, but not capable of transmitting Ultra Wideband data / signals; or - in an awake state where they are able to transmit and receive Ultra Wideband data / signals.
[0158] In other words, with reference to [Fig.2], when awake (in other words in the awake state), the Ultra Wideband transceivers Ul, U10, UR1, UR2 of the portable authentication device 1, 10 and the secure access control reader UR1, UR2 can carry out a bidirectional exchange of UWB1, UWB10 data in Ultra Wideband communication mode.
[0159] In the rest of the description, when it is written that a portable authentication device 1, 10 and a secure access control reader RI, R2 exchange data (during transmissions and receptions), it is understood that it is their Ultra Wide Band transceivers Ul, U10, UR1, UR2 that exchange said data.
[0160] User authentication U is made possible when: the portable authentication device 1, 10 is within the communication range of the access control reader RI; the Ultra Wide Band transceivers Ul, U10, UR1 of these two devices are woken up.
[0161] The secure access control process 100 is notable in that, at startup, the Ultra Wideband transceivers UR1, UR2 of the secure access control readers RI, R2 are in a standby state. As explained previously, putting the Ultra Wideband transceivers of the secure access control readers RI, R2 into standby mode when they are not required to participate in the secure access control process 100 allows, in particular: - to reduce their power consumption in Ultra Wideband mode, and possibly, if powered by a battery, to save the battery; - to avoid automatic and unnecessary communication between the secure access control readers RI, R2 and the portable authentication device 1, 10 within their communication range when its user does not wish to access the secure spaces SI, S2; - in connection with the previous point, to strengthen the security level of the access control process 100 and the security of exchanges: by reducing the risks of interception of data that can be exchanged between the secure access control readers RI, R2 and the portable authentication device 1, 10 by a malicious system during the authentication of user U.
[0162] Thus, the secure access control method 100 is designed so that, prior to the authentication of the user U with one of the secure access control readers RI, R2, a switchover of its Ultra Wide Band transceiver UR1, UR2 from the standby state to the awake state is implemented.
[0163] Several embodiments of the secure access control process 100 are possible.
[0164] Among them, the secure access control method 100 presented [Fig. 3] is conceivable for all the aforementioned portable authentication devices 1, 10. It is assumed that the Ultra Wideband transceivers Ul, U10 of the portable authentication device 1, 10 and of the secure access control reader RI are both in the standby state.
[0165] In this embodiment of [Fig. 3], the secure access control method 100 begins with a wake-up step WP-R of the secure access control reader RI in order to wake up its Ultra Wideband URL transceiver
[0166] With reference to [Fig. 4], in a first embodiment, the activation of the Ultra Wideband transceiver UR1 of the secure access control reader RI occurs following detection of a user contact U by at least one sensRl sensor located on a part of the secure access control reader RL. In this first embodiment, the at least one sensRl sensor is selected from a button, a mechanical sensor, a capacitive sensor, and an inductive sensor. Thus, the detection of the user contact U may, but is not limited to: - a contact of a hand of the user U on a part of the secure access control reader RI, detected for example by means of electrostatic sensors (inductive sensor or capacitive sensor); - pressing a key or button that includes the secure RI access control reader on its casing or on a touchpad.
[0167] With reference to [Fig. 5], in a second embodiment, the awakening of the Ultra Wideband transceiver UR1 of the secure access control reader RI occurs following detection by at least one sensRl sensor of the approach of the user U or the portable authentication device 1, 10 with a part of the secure access control reader RI within a given activation distance d-act relative to the secure access control reader RL. In this second embodiment, the at least one sensRl sensor is selected from a capacitive sensor, an inductive sensor, a radar sensor, an ultrasonic sensor, an optical sensor, or a vibration sensor. Thus, the detection of the approach of the user U may, but is not limited to, refer to: - detection of the movements of the user U or the portable authentication device 1, 10 by a motion sensor (for example, a passive infrared motion sensor or other optical sensor); - vibrations caused by the user's steps on the ground, which are detected by an accelerometer; - detection by a microphone of the noises caused by the footsteps of user U on the ground.
[0168] In this second variant, at least one sensRl sensor detecting an approach by the user U or their portable authentication device 1, 10 can be integrated into the secure access control reader RI or located remotely from it. For example, the remote sensor can be contained in a housing that also includes a push button that the user U presses, which housing is fixed to a wall in the space where the secure access control reader RI is located and: either is physically connected to the secure access control reader RI by a cable; or communicates with it by means of a wireless communication protocol (for example, Bluetooth Low Energy BLE®).
[0169] In one embodiment of the invention, it is conceivable that the secure access control reader RI incorporates a light-emitting diode such that it lights up when the Ultra Wideband transceiver UR1 of the secure access control reader RI is woken up, and is not lit when it is in standby state; so as to signal / inform the user U of the state of the Ultra Wideband transceiver UR1, also indicating whether after approaching or touching the secure access control reader RI, the wake-up step WP-R has taken place properly.
[0170] Once its Ultra Wideband transceiver UR1 is awake, the secure access control reader RI, during a transmission step El, transmits a wake-up signal ws to the portable authentication device 1, 10. Following the reception of the wake-up signal ws during a reception step El', the Ultra Wideband transceiver Ul, U10 of the portable authentication device 1, 10 switches from the sleep state to the wake-up state during a wake-up step WP-T of said portable authentication device 1, 10.
[0171] Following the awakening of the Ultra Wideband transmitter Ul, U10 of the portable authentication device 1, 10, the portable authentication device 1, 10 and the secure access control reader RI communicate with each other during a secure telemetry step SR in order to authenticate the user U. According to two different embodiments, the secure telemetry step SR can be initiated: - either by the secure access control reader RI; - either by the portable authentication device 1, 10 following the awakening of its Ultra Wide Band transceiver Ul, U10.
[0172] The portable authentication device 1, 10 contains at least user identification data udata, or credentials in English.
[0173] In the embodiment presented [Fig.3], the secure access control reader RI is considered to be the equipment initiating the secure telemetry step SR.
[0174] In one embodiment of the invention, the secure access control reader RI can initiate the secure telemetry step SR after a certain delay following the sending of the wake-up signal ws during the transmission step EL. In another embodiment, as illustrated [Fig. 3], the secure access control reader is configured to implement the secure telemetry step once it has received, during a receive step E2', a start signal ack from the portable authentication device 1, 10. This start signal ack, which can be considered an acknowledgment signal, is transmitted in Ultra Wideband communication mode by the portable authentication device 1, 10 during a transmit step E2 following the awakening of its Ultra Wideband transceiver Ul, U10.
[0175] With reference to [Fig.3], the secure telemetry step SR includes at least: - a transmission step ESR1 during which the secure access control reader RI transmits security data sdatal to the portable authentication device 1, 10; - an ESR2 transmission step during which the portable authentication device 1, 10 transmits security data sdata2 to the secure access control reader RI. - an EC calculation step of a certified distance sdist between the portable authentication device 1, 10 and the secure access control reader RI; and - an Everif verification step following the EC calculation step during which a verification of the certified distance sdist is carried out.
[0176] In one embodiment of the invention, the secure telemetry step SR is preceded by a first exchange between the portable authentication device 1, 10 and the secure access control reader RI; this first bidirectional exchange taking place after the wake-up step WP-T.
[0177] With reference to [Fig. 6], in one embodiment of the invention, the certified distance sdist is calculated, according to equation Eq. 1, by at least one of the portable authentication device 1, 10 and the secure access control reader RI from a Time Of Flight (ToF) measured by said at least one of the portable authentication device 1, 10 and the secure access control reader RL Y O p= T1oo ^ T Eq. 1
[0178] where Treply is the response time of the portable authentication device 1, 10 which corresponds to the time interval between: the instant when it receives during a receive step ESR1' the security data sdata from the secure access control reader RI and the instant, and the implementation of the transmission step ESR2; and Tloop is the duration of the bidirectional exchange between the secure access control reader RI and the portable authentication device 1, 10, i.e. here the time interval between the transmission step ESR1 and a receive step ESR2' during which the secure access control reader RI receives from the portable authentication device 1, 10 the security data sdata2.
[0179] In one embodiment of the invention, as illustrated [Fig.3], only one of the two devices 1, 10, RI calculates the certified distance sdist (here, the secure access control reader RI).
[0180] The distance certification stems from the fact that the distance is calculated during the SR secure telemetry step, and that it is based on at least one bidirectional exchange of Ultra Wideband signals between two devices (the wearable authentication device and the secure access control reader) each having: an embedded secure component; or a previously loaded trusted firmware or application inside, or a Trusted Execution Environment (TEE).
[0181] In another embodiment of the invention, the portable authentication device 1, 10 and the secure access control reader RI both calculate the certified distance sdist. They exchange the certified distance value sdist that they have calculated. Each device 1, 10, RI then compares the certified distance sdist that it received with the certified distance sdist that it calculated itself. If the consistency between the certified distances sdist is not verified, the telemetry step SR is stopped. If the consistency is verified, the telemetry step SR continues with the verification step Everif.
[0182] The Everif verification step consists of comparing the certified sdist distance with a dauth authorization distance. More precisely, it consists of verifying whether the certified sdist distance is included in the dauth authorization distance, that is, whether it is less than or equal to the latter.
[0183] In a first embodiment, the equipment 1, 10, RI in charge of the EC calculation step is also the one in charge of the Everif verification step.
[0184] Preferably, with reference to [Fig.3], it is the secure access control reader RI that is responsible for implementing the EC calculation and Everif verification steps.
[0185] In a second embodiment, one of the two devices 1, 10, RI—the portable authentication device 1, 10 and the secure access control reader RI—is responsible for the EC calculation step, while the other is responsible for the Everif verification step. Thus, once one of the two devices 1, 10, RI has calculated the certified distance sdist, it must transmit it to the other device 1, 10, RI for checking / verification.
[0186] Comparing the certified distance sdist to the authorization distance dauth makes it possible to determine whether user U is near or not the secure access control reader RI, this proximity reflecting a desire of user U to access the secure space SI.
[0187] In one embodiment of the invention, the dauth authorization distance is less than or equal to 1 m.
[0188] In one embodiment, the authorization distance dauth is equal to the activation distance d-act (described previously) from which the secure access control reader RI is able to detect an approach of the user U or his portable authentication device 1, 10.
[0189] In another variant, the d-act activation distance is defined as being substantially equal to the dauth authorization distance, for example the activation distance is equal to 1.25 times the dauth authorization distance.
[0190] If the certified distance sdist is greater than the authorization distance dauth, the access control process 100 stops. In one embodiment, the secure access control reader RI switches its Ultra Wideband transceiver UR1 to standby mode. If the user U wishes to authenticate again, which requires a new implementation of the secure access control process 100, they will then have to touch or approach the secure access control reader RI again for the wake-up step WP-R to be performed.
[0191] If the certified distance sdist is less than or equal to the authorization distance, the SR telemetry step ends and the secure access control process 100 continues.
[0192] In various embodiments of the invention, the secure telemetry (SR) step may not be limited to the exchanges and principles described. Further information on secure telemetry is available in the two references indicated in the prior art.
[0193] At the end of the secure telemetry SR step, if the certified distance is valid, the user identification data udata is transmitted to an access control center 2.
[0194] According to two different embodiments, transmission is ensured by the secure access control reader or by the portable authentication device 1, 10 according to which equipment 1, 10, RI has network access to be able to communicate with the access control unit 2.
[0195] In one embodiment of the invention, the equipment 1, 10, RI having carried out the Everif verification step of the certified distance sdist is the one in charge of transmitting the user identification data udata to the access control unit 2. In the embodiment illustrated [Fig.3], it is therefore the secure access control reader RI which implements a transmission step E3 of the user identification data udata.
[0196] Advantageously, the implementation of the EC calculation, Everif verification, and E3 transmission steps by the RI secure access control reader makes it possible to significantly strengthen the security level of the secure access control process 100 since, by definition, the RI secure access control reader is a trust system designed and conformed to be an integral part of an access control installation implementing secure access control processes.
[0197] In two embodiments, the secure access control reader RI is directly linked to the access control unit 2: either by being physically connected to it (for example, by means of Ethernet links or an RS485 interface), or by communicating directly with it via a wireless communication protocol (see [Fig. 7]-a) operating in a frequency band that is or is not within the Ultra Wideband range. For example, the secure access control reader RI is directly linked to the access control unit 2 and can communicate via Wi-Fi®.
[0198] In a third embodiment of the invention, the secure access control reader RI and the access control unit 2 are part of a mesh network comprising several other secure access control readers. In the illustrated example [Fig. 1], the other secure access control reader R2 is also part of this mesh network. Each of the devices RI, R2, and 2 in the mesh network is capable of communicating with its nearest neighbor(s) according to a peer-to-peer communication protocol, for example, Bluetooth Mesh®.
[0199] Advantageously, the mesh network addresses the problem of indoor network coverage, when the building structure and the materials used for its construction interfere with signal transmission and prevent two devices from communicating properly even though they are within communication range of each other.
[0200] In the illustrated example [Fig.7]-b, the secure access control reader RI transmits the user identification data udata to the other secure access control reader R2; which other secure access control reader R2 then relays them to the access control unit 2.
[0201] In order for the secure access control reader RI to transmit the user identification data udata to the access control unit 2 so that it can proceed to the access control step CS, it is necessary that the authentication device 1, 10 has previously transmitted to the secure access control reader RI the said user identification data udata.
[0202] The secure access control method 100 provides that the portable authentication device 1, 10, once awakened, communicates the user identification data udata to the secure access control reader RI during a transmission step. This transmission step may take place before, during, or after the secure telemetry step SR.
[0203] In the described embodiments in which the secure access control reader RI is responsible for transmitting the user identification data, including the one illustrated [Fig.3], it is considered that the transmission step takes place during the secure telemetry step SR, and that the user identification data udata is transmitted during the transmission step ESR2.
[0204] Optionally, in the event that the transmission of the user identification data udata from the portable authentication device 1, 10 to the secure access control reader RI is planned to take place following the secure telemetry step SR, said transmission is implemented in the event that the certified distance is validated (i.e. if it is less than or equal to the authorization distance dauth).
[0205] With reference to [Fig. 3], following the receipt of the user's identification data udata during a reception step E3', the access control unit 2 is configured to implement an access control step CS during which it verifies at least the user's identification data udata to determine whether the user U has the necessary credentials to access the secure area SI protected by the access control bay D1. If not, access to the secure area SI is denied to the user.
[0206] Once at least the identification data of the user udata have been validated, the access control unit 2 unlocks the locking / unlocking system of the access control bay Dl to allow the user U to enter the secure space SI.
[0207] According to different embodiments of the invention, the locking / unlocking system of the access control bay Dl, which may for example correspond to a strike plate opening and closing, can either be physically connected by a cable to the access control unit 2, or be linked to the access control unit 2 through a wireless link.
[0208] In one embodiment of the invention, the secure access control reader RI is configured to switch its Ultra Wide Band transceiver UR1 into the standby state after a period of activity which is established according to the time required to implement all the steps of the secure access control process 100.
[0209] In another embodiment, the access control unit 2, following the implementation of the access control step CS, transmits a standby signal to the secure access control reader RI. Once this standby signal is received, the switchover to standby mode of the Ultra Wideband transceiver UR1 of the secure access control reader RI occurs.
[0210] When the portable authentication device 1, 10 considered is only a connected mobile terminal 1, it is conceivable that the secure telemetry step SR is implemented: when the Ultra Wideband transceivers Ul, UR1 of the connected mobile terminal 1 and the secure access control reader RI are woken up, but also that at least one ulock, opt, inc validation action is carried out beforehand on the connected mobile terminal 1.
[0211] At least one ulock, opt, inc validation action is an additional security / condition in the implementation of the secure access control process 100 to ensure that the user U of the connected mobile terminal 1 specifically intends to access the secure space SI protected by the access control bay DI associated with the secure access control reader RL
[0212] At least one ulock, opt, inc validation action avoids implementing the secure telemetry step SR, and subsequently the access control step CS, if the secure access control reader RI has detected contact with or an approach by the user U or their connected mobile terminal 1 when they have no intention whatsoever of accessing the secure space SL. Other advantages are: reducing the power consumption of the secure access control reader RI and the connected mobile terminal 1 in Ultra Wideband communication mode, and not unnecessarily stressing the access control unit 2.
[0213] At least one ulock, opt, inc validation action may take the form of a ulock unlock of the connected mobile terminal 1, changing said connected mobile terminal 1 from a locked state to an unlocked state. This ulock unlock may, but is not limited to, be implemented following: - the activation of a touchscreen included in the connected mobile terminal 1 by pressing it by the user U, or by pressing a power button also included in the connected mobile terminal 1; or - an operation to enter an unlock code on the connected mobile terminal 1; or - a touch-sensitive unlock pattern entry operation on the touchscreen of the connected mobile terminal 1; or - a fingerprint recognition operation on a fingerprint sensor of the connected mobile terminal 1; or - a facial recognition operation of user U using a camera integrated into the connected mobile terminal 1.
[0214] With reference to [Fig. 8], the at least one ulock, opt, inc validation action may also take the form of an opt launch operation performed in a launch menu displayed by a mobile launch application 1-app, loaded into the connected mobile terminal 1. Without limitation, the opt launch operation may consist of: - an operation to enter a launch code on the launch menu; - a touch input operation of a launch pattern on the launch menu; - a validation operation on the launch menu.
[0215] With reference to [Fig. 9], at least one validation action ulock, opt, inc can also correspond to an inclination inc of the connected mobile terminal 1. It consists of measuring an inclination angle tetal, theta2 of the connected mobile terminal 1, which is then compared to a predefined launch angular range. If the inclination angle tetal, theta2 is within the launch angular range, then the inclination is considered valid for the subsequent implementation of the secure telemetry step SR. The launch angular range corresponds to an orientation of the connected mobile terminal 1 with respect to the secure access control reader RI, or to the ground, such that: - the front face Fl of the connected mobile terminal 1 faces or is very much facing the user U; - the rear face F2 of the connected mobile terminal 1 faces or is substantially facing the secure access control reader RI.
[0216] In a first embodiment illustrated in [Fig.9] (a), the tilt inc consists of a measurement of a tilt angle tetal by the secure access control reader RI from reception signals of an Ultra Wideband wave from the connected mobile terminal, for example during a bidirectional UWB1 data exchange taking place when the Ultra Wideband U1, RI transceivers of the connected mobile terminal and the secure access control reader RI are both awake; which tilt angle is then compared to the launch angular interval.
[0217] In a second embodiment illustrated in [Fig.9] (b), the inclination inc consists of a measurement of an inclination angle theta2 of the connected mobile terminal 1 with respect to the ground by an inertial measurement unit included in the connected mobile terminal 1.
[0218] Depending on several configurations: - either equipment 1, RI, among the connected mobile terminal 1 and the secure access control reader RI, which measures the angle of inclination tetal, teta2 and its validation, via its comparison with the angular launch interval, is the same as that which initiates the secure telemetry step SR, in which case it is launched by said equipment 1, RI following said validation; - either the equipment 1, RI among the connected mobile terminal 1 and the secure access control reader RI which is responsible for measuring the tilt angle tetal, teta2 is not the same as the one which validates it, in which case there is transmission of the tilt angle tetal, teta2 from said equipment 1, RI to the other equipment 1, RI; - either the equipment 1, RI among the connected mobile terminal 1 and the secure access control reader RI which is in charge of validating the inclination inc is not the same one which initiates the secure telemetry step, in which case the equipment 1, RI transmits, if the inclination inc is valid, a confirmation signal to the other equipment 1, RI which, upon receiving the latter, starts the secure telemetry step SR.
[0219] According to different embodiments of the secure access control process 100, the at least one ulock, opt, inc validation action may include several ulock, opt, inc validation actions performed prior to the secure telemetry SR step. It is possible that these several ulock, opt, inc validation actions may be performed successively or not.
[0220] For example, in one embodiment, the user must perform a ulock unlock of his connected mobile terminal 1 followed by an opt launch operation in the launch mobile application 1-app, which opens automatically and displays the launch menu following the ulock unlock of the connected mobile terminal 1.
[0221] In another particular embodiment, following the implementation of the wake-up steps WP-R, WP-T of the connected mobile terminal 1 and the secure access control reader RI, the secure telemetry step SR is initiated on the condition that the user: - performs a ulock unlock on its connected mobile terminal 1; - tilts its connected mobile terminal 1 according to a tilt angle tetal, teta2 conforming in order to validate the tilt inc; - performs an opt launch operation on the 1-app launch mobile application, which 1-app launch mobile application is displayed on the touch screen of the connected mobile terminal 1 following validation of the inc tilt (in other words, the 1-app launch mobile application is not displayed if the tilt is not valid).
[0222] Another example of implementation of the secure access control method 100 is given in [Fig. 10]. In this, the wake-ups of the Ultra Wideband transceivers Ul, UR1 of the connected mobile terminal 1 and the secure access control reader RI take place similarly to the example embodiment given [Fig. 3].
[0223] After touching the secure access control reader RI (which resulted in the completion of the two wake-up steps WP-T, WP-R, the transmission step El and the reception step El'), user U performs a ulock unlock of their connected mobile terminal 1. The ulock unlock of the connected mobile terminal has the effect of automatically launching the mobile launch application 1-app, whose launch menu is then displayed on the touch screen of the connected mobile terminal 1. Once the mobile launch application 1-app has started, user U performs an opt launch operation.
[0224] In the embodiment shown [Fig.10], the secure access control reader RI still initiates the secure telemetry step SR.
[0225] Following the completion of the opt launch operation, the connected mobile terminal 1 implements the transmission step E2 during which it sends the start signal ack to the secure access control reader. Once the start signal ack is received during the reception step E2', the secure access control reader RI initiates the secure telemetry step SR.
[0226] As explained previously, the user identification data udata can be transmitted to the access control unit 2 in the first case by the secure access control reader RI, or in the second case by the connected mobile terminal 1 itself (implying that the connected mobile terminal has network access). The embodiment shown [Fig. 10] covers this second case.
[0227] In order to communicate with the access control unit 2, the connected mobile terminal 1 must have an add-c connection address relative to the latter.
[0228] In a first embodiment, the add-c connection address is already contained in the connected mobile terminal 1, having been previously loaded into it before the implementation of the secure access control process 100.
[0229] In a second embodiment, the add-c connection address is transmitted to the connected mobile terminal 1 by the secure access control reader RI during the secure telemetry step SR. By way of exception, the add-c connection address may: - either transmitted during at least one bidirectional exchange between the secure access control reader RI and the connected mobile terminal 1 that comprises the secure telemetry step SR, and which encompasses the transmission steps ESR1, ESR2 and the reception steps ESR1', ESR2'. In other words, the connection address add-c is transmitted with the security data sdatal during the transmission step ESR1; or - either transmitted by the RI access control reader during a transmission step taking place during the SR secure telemetry step and independent of the at least one exchange mentioned above.
[0230] With reference to [Fig. 10], it is also conceivable, in the case where the access control reader implements RI the EC calculation and certified distance verification steps sdist, but is not responsible for transmitting the user identification data udata to the access control unit 2, that it transmits to the connected mobile terminal 1, during an ESR3 transmission step included in the secure telemetry step SR and which takes place after the Everif verification step, the add-c connection address simultaneously with a Goto authorization signal which is intended to indicate to the connected mobile terminal 1 that it can transmit the user identification data udata to the access control unit 2.
[0231] With reference to [Fig.10] and 11, following the receipt of the add-c connection address and the Goto authorization signal during an ESR3' reception step, the connected mobile terminal 1 transmits the udata user identification data to the access control center 2 during an E4 transmission step.
[0232] Following the receipt of the user identification data udata during a reception step E4', the access control unit 2 implements the access control step CS (as already described previously with reference to [Fig.3]).
[0233] In certain embodiments of the invention, the access control reader RI may not be configured to send a wake-up signal ws to the portable authentication device 1, 10 following the implementation of the wake-up step WP-R of the secure access control reader RI. In this case, the switching from the sleep state to the wake-up state of the Ultra Wideband transceiver Ul, U10 of the portable authentication device 1, 10 is triggered by a wake-up action wact performed by the user U on their portable authentication device 1, 10.
[0234] When the portable authentication device 1, 10 is a connected mobile terminal 1, the wake-up action wact corresponds to at least one validation action ulock, opt, inc.
[0235] In one embodiment of the invention, at least one wake-up action corresponds to a ulock unlock of the connected mobile terminal 1.
[0236] In addition to the wake-up action wact, the secure access control method 100 can be designed so that the user U must also perform at least one validation action ulock, opt, inc for the implementation of the secure telemetry step SR.
[0237] A third example of implementing the secure access control process 100 is illustrated [Fig. 12], in which the user must perform a wake-up action wact and a validation action ulock, opt, inc. In this embodiment, at the start of the secure access control process 100, the user U interacts with the secure access control reader RI (by touching it, or approaching it, etc.) in order to trigger the wake-up step WP-R of the secure access control reader RL
[0238] Following the WP-R wake-up step of the secure access control reader RI, the user U performs the wake-up action wact corresponding here to a ulock unlock of the connected mobile terminal 1, following which the WP-T wake-up step of the connected mobile terminal 1 occurs.
[0239] In the case where the wake-up action consists of a ulock unlock of the connected mobile terminal 1, then at least one ulock, opt, inc validation action is chosen from an opt launch operation in the launch mobile application 1-app and the inc tilt of the connected mobile terminal 1. With reference to the embodiment of [Fig. 12], the ulock, opt, inc validation action corresponds to the opt launch operation performed from the launch mobile application 1-app, which is launched automatically or not following the ulock unlock of the connected mobile terminal 1.
[0240] Similar to the embodiment shown in [Fig.2], it is considered for this third illustrated embodiment that the secure access control reader RI initiates the secure telemetry step SR, and has network access to transmit the user identification data udata to the access control unit 2 (by direct or hop-by-hop communication) so that it can implement the access control step CS.
[0241] Thus, following the completion of the opt launch operation, the connected mobile terminal 1 transmits during the transmission step E2 to the secure access control reader RI the start signal ack for the initiation of the secure telemetry step SR.
[0242] It is assumed that the steps taking place during the secure SR telemetry step are the same as in the embodiment presented [Fig. 2]. Therefore, they are not shown [Fig. 12].
[0243] The various embodiments of the secure access control process 100 so far can be implemented for any secure access control reader RI, R2 included in a building.
[0244] However, when secure access control readers have network access and can communicate with the access control unit 2, once user U has authenticated itself once with a secure access control reader as previously described, its authentication after another secure access control reader can be accelerated by means of an access cookie (or "cookie" in English).
[0245] With reference to [Fig.12] and [Fig.13], it is assumed that user U, after authenticating with the secure access control reader RI and accessing the secure space SI, also wishes to access the other secure space R2 protected by the other access control bay D2, which is associated with the other access control reader secure R2; and that authentication with the other secure R2 space is done using the coo access witness.
[0246] This access witness coo is generated during a generation step EG which takes place following the access control step CS in the case where the access control center 2 has authorized a first access to the user U (in the illustrated example, to the secure space SI).
[0247] In a first embodiment, the coo access token is generated by the connected mobile terminal 1 by means of a dedicated application previously loaded inside; the generation may, for example, follow the receipt of data relating to an agreement to generate a coo access token from the access control center 2. Once the coo access token has been generated, it is stored in the connected mobile terminal 1 following an Esto storage step.
[0248] In a second embodiment, and as illustrated in [Fig. 12], the generation step EG is implemented by the access control unit 2. Then, during a transmission step E5, it transmits the access token coo to the secure access control reader RI, which corresponds to the access control reader that participated in the secure telemetry step SR (the transmission being by direct communication or by hop-by-hop communication). Following the reception of the access token coo during a reception step E5', the secure access control reader RI transmits the access token during a transmission step E6 to the connected mobile terminal 1, which, following a reception step E6' of said access token coo, proceeds to the storage step Esto.
[0249] When the user is near the other secure access control reader R2, an access control phase CP begins. During this phase, the user U makes an access request using their connected mobile terminal 1, which is detected by said connected mobile terminal 1 during an ADD detection step.
[0250] In one embodiment, the access request may correspond to at least one validation action ulock, opt, inc.
[0251] In another embodiment, with reference to [Fig.14], the access request can correspond to a contact by the user U on his connected mobile terminal 1, such as a tap; the contact being detected by a sensor included in the connected mobile terminal 1 (such as, for example, a mechanical sensor, a capacitive sensor, an inductive sensor, an accelerometer or an inertial measurement unit).
[0252] Following the ADD detection step, the connected mobile terminal 1 transmits during a transmission step E7 the coo access indicator to the other secure access control reader R2.
[0253] Once the coo access indicator is received during a reception step E7', the other secure access control reader R2 transmits the coo access indicator to the access control unit 2 during an E8 transmission step (by direct communication or step-by-step communication).
[0254] Following the receipt of the access indicator coo during a reception step E8', the access control unit implements an access control step CS2 during which it checks the access indicator coo and then authorizes access to the other secure space S2 to the user U, by unlocking for this purpose the locking / unlocking system of the other access control bay D2.
[0255] Advantageously, the access control center 2 authorized access to the other secure space S2 on simple verification of the access indicator coo, therefore without having to carry out a new check of the user identification data udata.
[0256] In one embodiment of the invention, the access token coo is generated based on the user's identification data. Indeed, another user U may have the right to access the secure space SI, but not the other secure space S2. In other words, the access token only allows user U to facilitate their authentication to access the secure spaces for which they have the necessary credentials.
[0257] In one embodiment of the invention, the access token coo has a limited validity period. In other words, once the validity period has expired, the access token coo expires. If this is the case, the authentication of user U with the access control unit 2 to access a secure area then consists of implementing again, at a minimum, the wake-up step WP-R of a secure access control reader, the secure telemetry step SR, and the access control step CS (with control by the access control unit 2 of at least the user identification data udata).
Claims
1. Demands A secure access control method (100) for controlling and authorizing access by a user (U) to at least one secure space accessible (SI, S2) by at least one access control bay (D1, D2) equipped with a locking / unlocking system, the secure access control method (100) involving several pieces of equipment (1, 10, RI, R2, 2) including: - a wearable authentication device (1, 10) carried by the user (U) and containing user identification data (udata), said wearable authentication device (1, 10) comprising at least one Ultra Wideband transceiver (Ul, U10), and corresponding to a connected mobile terminal, such as a mobile phone, a tablet or a smartwatch, - at least one secure access control reader (RI, R2) associated with at least one access control bay (Dl, D2) and comprising at least one Ultra Wideband transceiver (UR1, UR2), - an access control unit (2) which is at least in communication with the access control reader (RI, R2) and which is linked to the locking / unlocking system of at least one access control bay (Dl, D2); in which the secure access control process (100) includes at least: - a wake-up step (WP-R) of the secure access control reader (RI, R2) initiated by a detection by at least one sensor (sensR1, sensR2) of an approach or contact of the user (U) or the portable authentication device (1, 10) with said secure access control reader (RI, R2), and followed by a wake-up of the Ultra Wideband transceiver (UR1, UR2) of said secure access control reader (RI, R2) in order to be able to transmit and receive in an Ultra Wideband communication mode; - a secure telemetry (SR) step between the secure access control reader (RI, R2) and the portable authentication device (1, 10), during which their Ultra Wideband transceivers (Ul, U10, UR1, UR2) exchange at least some security data (sdatal, sdata2) in Ultra Wideband communication mode, and at the end of which a certified distance (sdist) between the secure access control reader (RI, R2) and the portable authentication device (1, 10); - an access control step (CS) during which the access control unit (2), after receiving the user identification data (udata), verifies this data to authorize or not access to the secure space (SI, S2) accessible by the access control bay (Dl, D2) and, if necessary, commands the locking / unlocking system of said access control bay (Dl, D2);The access control method is characterized in that at least one secure space (SI, S2) comprises at least one other secure space (S2) accessible by at least one other access control bay (D2) equipped with another locking / unlocking system and associated with another secure access control reader (R2) comprising an Ultra Wideband transceiver (UR2), in that the secure access control method (100) comprises a generation step (EG) of an access token (coo) followed by a storage step (Esto) of said access token (coo) in the connected mobile terminal (1), the generation step (EG) and the storage step (Esto) being implemented when access to the secure space (SI) is authorized by the access control unit (2), and in that the secure access control method (100) implements an access control phase (CP) to access the other secure space (S2), which comprises the steps following:; - a detection step (ADD) of an access request made by the user (U) on the connected mobile terminal (1); - a transmission step (E7) during which the connected mobile terminal (1) transmits, in Ultra Wideband communication mode, the access indicator (coo) to the other secure access control reader (R2) in response to the detection of the access request; - a reception step (E7') during which the Ultra Wide Band transceiver (UR2) of the other secure access control reader (R2) receives the access indicator (coo); - a transmission step (E8) during which the other secure access control reader (R2) transmits said access indicator (coo) to the access control unit; - an access control step (CS2) during which the access control unit (2), after receiving the access indicator (coo), authorizes access to the other secure space (S2) accessible through the other access control bay (D2) and, if necessary, commands the other locking / unlocking system of said other access control bay (D2), without receiving or verifying the user identification data (udata) by said access control unit (2).
2. A secure access control method (100) according to claim 1, wherein the access control unit (2) receives the user identification data (udata) provided that prior to, during the secure telemetry (SR) step, it has been verified that the certified distance (sdist) is less than or equal to an authorization distance (dauth).
3. A secure access control method (100) according to claim 1 or 2, comprising, prior to the secure telemetry step (SR), a wake-up step (WP-T) of the portable authentication device (1, 10) in which the Ultra Wideband transceiver (Ul, U10) of said portable authentication device (1, 10) is woken up to be able to transmit and receive in the Ultra Wideband communication mode.
4. A secure access control method (100) according to claim 3, wherein, after the wake-up step (WP-R) of the secure access control reader (RI, R2), the secure access control reader (RI, R2) emits a wake-up signal (ws) in Ultra Wideband communication mode which is received by the Ultra Wideband transceiver (Ul, U10) of the portable authentication device (1, 10), causing the wake-up step (WP-T) of the portable authentication device (1, 10).
5. Secure access control method (100) according to claim 3, wherein, prior to the secure telemetry step (SR), a wake-up action (wact) is performed by the user (U) on the portable authentication device (1, 10) in order to trigger the wake-up step (WP-T) of the portable authentication device (1, 10).
6. A secure access control method (100) according to any one of claims 3 to 5, wherein the portable authentication device (1, 10) initiates the secure telemetry (SR) step following the wake-up step (WP-T) of said portable authentication device (1, 10).
7. Secure access control method (100) according to any one of claims 3 to 5, wherein the secure access control reader (RI, R2) initiates the secure telemetry step (SR) after receiving, in Ultra Wideband communication mode, a start signal (ack) from the portable authentication device (1, 10), said start signal (ack) being emitted by the portable authentication device (1, 10) following the wake-up step of said portable authentication device (1, 10).
8. A secure access control method (100) according to any one of claims 1 to 7, wherein, during the secure telemetry step (SR), the certified distance (sdist): - is established by being calculated by at least one of the portable authentication device (1, 10) and the secure access control reader (RI, R2), and then - verified either by the portable authentication device (1, 10) or by the secure access control reader (RI, R2).
9. A secure access control method (100) according to any one of claims 1 to 8, wherein the access control unit (2) receives the user identification data (udata) from: - either the secure access control reader (RI, R2), which secure access control reader (RI, R2) having network access to communicate with the access control unit (2), via direct communication or via hop-by-hop communication; - or the portable authentication device (1, 10), which portable authentication device (1, 10) having network access and containing a connection address (add-c) to remotely connect to and communicate with the access control unit (2).
10. A secure access control method (100) according to claim 9, wherein, when the access control unit (2) receives the user identification data (udata) from the secure access control reader (RI, R2), the secure access control method (100) also includes, prior to the access control step (CS), a transmission step during which the portable authentication device (1, 10) transmits, in mode Ultra Wideband communication, the user identification data (udata) to the secure access control reader (RI, R2); said transmission step being implemented: - following the wake-up step (WP-R) of the secure access control reader (RI, R2) and before the start of the secure telemetry step (SR), or - during the secure telemetry step (SR), or - once the secure telemetry step (SR) has been completed.
11. A secure access control method (100) according to any one of claims 1 to 10, wherein, during the wake-up step (WP-R) of the secure access control reader (RI, R2), the approach or contact detection consists of detecting contact from the user (U) by at least one sensor (sensR1, sensR2) disposed on a part of the secure access control reader (RI, R2).
12. A secure access control method (100) according to claim 11, wherein at least one sensor (sensR1, sensR2) is selected from a key, a mechanical sensor, a capacitive sensor, and an inductive sensor.
13. A secure access control method (100) according to any one of claims 1 to 10, wherein, during the wake-up step (WP-R) of the secure access control reader (RI, R2), the approach or contact detection consists of a detection by at least one sensor (sensR1, sensR2) of the approach of the user (U) or the portable authentication device (1, 10) with a part of the secure access control reader (RI, R2) within a given activation distance (d-act) relative to the secure access control reader (RI, R2).
14. A secure access control method (100) according to claim 13, wherein at least one sensor (sensR1, sensR2) is selected from a capacitive sensor, an inductive sensor, a radar sensor, an ultrasonic sensor, an optical sensor, a vibration sensor.
15. A secure access control method (100) according to claim 13 or 14, wherein at least one sensor (sensR1, sensR2) is mounted on the secure access control reader (RI, R2), or is remote from the secure access control reader (RI, R2) and connected to the secure access control reader (RI, R2).
16. A secure access control method (100) according to any one of the preceding claims, wherein the mobile terminal connected (1) participates in the secure telemetry (SR) step with the secure access control reader (RI, R2) if the user (U) has previously performed at least one validation action (ulock, opt, inc) on the connected mobile terminal (1), otherwise the secure telemetry (SR) step is not performed.
17. Secure access control method (100) according to claims 6 and 16, wherein at least one validation action (ulock, opt, inc) includes at least the wake-up action (wact) which triggers the wake-up step (WP-T) of the connected mobile terminal (1).
18. Secure access control method (100) according to claims 7 and 16, wherein the connected mobile terminal (1) transmits the start signal (ack) to the secure access control reader (RI, R2) following the completion of at least one validation action (ulock, opt, inc).
19. A secure access control method (100) according to any one of claims 16 to 18, wherein at least one validation action (ulock, opt, inc) includes at least one unlocking (ulock) of the connected mobile terminal (1), taking said connected mobile terminal (1) from a locked state to an unlocked state.
20. A secure access control method (100) according to claim 19, wherein the unlocking (ulock) of the connected mobile terminal (1) is implemented by the user (U) by at least one of the following operations: - turning on a touch screen included in the connected mobile terminal (1) by pressing it by the user (U), or on a power button also included in the connected mobile terminal (1); - entering an unlock code on the connected mobile terminal (1); - entering an unlock pattern by touch on a touch screen of the connected mobile terminal (1); - recognizing a fingerprint on a fingerprint sensor of the connected mobile terminal (1); - facial recognition of the user (U) by means of a camera integrated into the connected mobile terminal (1).
21. A secure access control method (100) according to any one of claims 16 to 20, wherein at least one validation action (ulock, opt, inc) comprises at least one launch operation (opt) performed in a launch menu displayed by a launch mobile application (1-app), loaded into the connected mobile terminal (1).
22. A secure access control method (100) according to claims 19 and 21, wherein at least one validation action (ulock, opt, inc) consists of unlocking (ulock) the connected mobile terminal (1), followed by the launch operation (opt).
23. A secure access control method (100) according to claim 21 or 22, wherein the launch operation (opt) consists of at least one of the following operations: - an operation of entering a launch code on the launch menu; - an operation of entering a launch pattern by touch on the launch menu; - a validation operation on the launch menu.
24. A secure access control method (100) according to claims 19 and 21, wherein the launch mobile application (1-app) opens automatically and displays the launch menu following the unlocking (ulock) of the connected mobile terminal (1).
25. A secure access control method (100) according to any one of claims 16 to 24, wherein at least one validation action (ulock, opt, inc) includes at least one tilt (inc) of the connected mobile terminal (1) through a tilt angle (tetal, theta2) within a predefined launch angular range.
26. A secure access control method (100) according to claims 21 and 25, wherein the launch mobile application (1-app) opens and displays the launch menu on the condition that the tilt angle (tetal, theta2) is within the predefined launch angular range.
27. A method of secure access control (100) according to claim 25 or 26, wherein the tilt angle (tetal) is measured by means of an inertial measurement unit integrated into the connected mobile terminal (1).
28. A secure access control method (100) according to claim 25 or 26, wherein the tilt angle (teta2) is measured by the secure access control reader (RI, R2), from received signals of an Ultra Wideband wave from the connected mobile terminal (1).
29. A secure access control method (100) according to any one of claims 1 to 28, wherein the access witness (coo) has a limited validity period.
30. A secure access control method (100) according to claim 2, wherein the authorization distance (dauth) is less than or equal to 1 m.