A secure access control method operating in Ultra Broadband communication mode to authorize access to a secure area for a user after unlocking their connected mobile terminal.
The secure access control method addresses vulnerabilities in Ultra Wideband systems by initiating telemetry only after unlocking and verifying user intent, optimizing system interactions and enhancing security.
Patent Information
- Application Number
- FR2023007366
- Authority / Receiving Office
- FR · FR
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2023-07-10
- Publication Date
- 2025-12-12
- Estimated Expiration
- 2043-07-10
AI Technical Summary
Existing secure access control systems using Ultra Wideband communication continuously activate, leading to security vulnerabilities and unnecessary strain by detecting and verifying user credentials regardless of access intent, increasing the risk of unauthorized access and system overload.
A secure access control method that initiates secure telemetry only after the connected mobile terminal is unlocked, involving a certified distance verification and validation actions, optimizing exchanges and enhancing security by ensuring user intent and reducing unnecessary system interactions.
Optimizes system interactions, strengthens security by confirming user intent and reducing interception risks, while minimizing unnecessary access control steps and system strain.
Smart Images

Figure 00000048_0000 
Figure 00000048_0001 
Figure 00000049_0000
Abstract
Description
Title of the invention: Secure access control method operating in an Ultra Broadband communication mode to authorize access to a secure area for a user following the unlocking of their connected mobile terminal. Technical field
[0001] The invention relates to a secure access control method for authorizing or denying a user access to a secure space.
[0002] It relates more particularly to a secure access control method based on Ultra Wide Band radio frequency communication.
[0003] The invention finds a favorite application in the implementation of a secure access control method involving an access control unit with which, via a secure access control reader, a user authenticates himself using a connected mobile terminal; the secure access control reader and the connected mobile terminal both operating in Ultra Wideband radio frequency communication mode and exchanging data for user authentication in this same communication mode. Previous technique
[0004] Ultra Wideband (UWB) is a well-known radio frequency modulation technique that has recently become more widespread. It is based on the transmission of pulses, generally shorter than a nanosecond, and is used in a wide frequency band, between 3.1 GHz and 10.6 GHz. Among the advantages of Ultra Wideband communication are a very high network data transfer rate over a wide bandwidth (greater than 500 MHz) over relatively short distances and at low power, without interfering with conventional narrowband and carrier wave transmissions in the same frequency bands. For simplicity, radio frequency systems using this modulation technique to exchange data are said to be communicating in Ultra Wideband mode.
[0005] Ultra Broadband technology being promising, it is now being considered in the design of geolocation, tracking, pairing (i.e. point-to-point data transfer), payment, and also access control solutions.
[0006] Indeed, some mobile phone models available on the market incorporate Ultra Wideband transceivers allowing them to communicate and exchange information in Ultra Wideband.
[0007] This is why secure access control readers incorporating Ultra Wideband transceivers are designed so that access control solutions can be implemented to authorize or not a user to access a secure space, protected by an access control bay (door, airlock, barrier, etc.) equipped with a locking / unlocking system, which operate in Ultra Wideband communication mode, and for which the user identifies / authenticates himself, via a secure access control reader, with an access control unit installed in the building and connected to the locking / unlocking system of the access control bay, by means of a mobile phone incorporating an Ultra Wideband transceiver.Once the user approaches the secure access control reader so that it can detect the mobile phone, a secure ranging process begins. During this process, the secure access control reader and the mobile phone exchange data, using a secure communication protocol, to authenticate the user. This data may include, for example, virtual identification keys, a user ID, etc. The data is transmitted by the secure access control reader to the access control unit installed in the building and connected to the access control bay's locking / unlocking system. Upon receiving the data, the access control unit verifies it and, based on the result of this verification, authorizes or denies access to the secure area by controlling the access control bay's locking / unlocking system.Secure telemetry, operated within the framework of an Ultra Broadband exchange, enhances the security of exchanges during point-to-point data transfers, drastically limiting the risks of interception of data transfer between a sender and a receiver, i.e., "man-in-the-middle" attacks.
[0008] Detailed explanations of the operating principle of secure telemetry are given by NO Tippenhauer and S. Capkun in the technical report "UWB-based secure ranging and localization" published in 2012 (Technical Report / ETH Zurich, Department of Computer Science 586); and in the article "UWB with Puise Reordering: Secure Ranging against Relay and Physical-Layer Attacks" written by M. Singh, P. Leu, and S. Capkun and published in 2017 by the IACR (International Association for Cryptology Research - Network and Distributed Systems Security (NDSS) Symposium 2019, 24-27 February 2019, San Diego, CA, USA - ISBN 1-891562-55-X).
[0009] However, in currently proposed and available solutions, the secure access control reader remains constantly activated in Ultra Broadband communication mode in order to locate the position of a mobile phone of a user equipped with an Ultra Wideband transceiver to communicate with it and perform secure telemetry in this communication mode.
[0010] The drawback of such an approach is that it presents security vulnerabilities because the mobile phone detection by the secure access control reader and secure telemetry occur if the user with the mobile phone passes near the access control point, regardless of whether or not they intend to access the secure area. If the access control system allows access to a user who is merely passing in front of the access control reader and has no intention of accessing it, it could potentially allow an unauthorized user to access the secure area protected by the access control bay.
[0011] Furthermore, if the mobile phone remains within the communication range of the secure access control reader for a certain period, the reader may periodically implement the secure telemetry step with the mobile phone; meaning that it will request the access control unit at regular intervals to verify the data it transmits. If the mobile phone user has access rights to the secure area but does not wish to enter, the periodic implementation of secure telemetry and data verification by the access control unit may result in repeated opening and closing of the access control bay.Besides unnecessarily straining the access control system, the increased exchanges between the mobile phone, the secure access control reader, and the access control system weaken their security because they increase the risk that the exchanged data could be intercepted by a malicious system. Summary of the invention
[0012] The invention aims to address the aforementioned problems by proposing a secure access control method to control and authorize a user's access to at least one secure area accessible via at least one access control bay equipped with a locking / unlocking system. The secure access control method involves several pieces of equipment, including: - a connected mobile terminal carried by the user and containing the user's identification data, said connected mobile terminal comprising at least one Ultra Wideband transceiver, - at least one secure access control reader associated with at least one access control bay and comprising at least one Ultra Wideband transceiver, - an access control unit which is at least in communication with the access control reader and which is linked to the locking / unlocking system of at least one access control bay; in which the secure access control process includes at least: - a step to unlock the connected mobile terminal, changing said connected mobile terminal from a locked state to an unlocked state; - a secure telemetry step between the secure access control reader and the connected mobile terminal, during which their Ultra Wideband transceivers exchange security data in an Ultra Wideband communication mode, and at the end of which a certified distance between the secure access control reader and the connected mobile terminal is established and then verified; said secure telemetry step being initiated on the condition at least that the unlocking step has been previously implemented; - an access control step during which the access control unit, after receiving the user's identification data, verifies this data to authorize or deny access to the secure area accessible through the access control bay and, if necessary, commands the locking / unlocking system of said access control bay.
[0013] As indicated above, the secure telemetry step is implemented only if at least the step of unlocking the connected mobile terminal by its user is completed. Unlocking the connected mobile terminal indicates the user's intention to access a secure area accessible from the access control bay associated with the secure access control reader.
[0014] Advantageously, implementing the secure telemetry step following unlocking of the connected mobile terminal allows: - to optimize the exchanges between the secure access control reader, the connected mobile terminal and the access control unit; - to reduce the strain on the access control system by implementing a single access control step, at the end of which access to the secure area is either authorized or denied to the user; - in connection with the two previous points, to strengthen the security of exchanges and reduce the risks of data interception by a malicious system; and - to respond positively to the security issue mentioned earlier when a secure access control reader detects a user's connected mobile terminal and initiates a secure telemetry step with it which may lead to the unlocking of an access control bay because the user has the required credentials, even though the user does not wish to access the secure space protected by the access control bay.
[0015] The implementation of the secure telemetry step assumes that the Ultra Wideband transceivers of the secure access control reader and the connected mobile terminal are both awake, i.e., in a state where they are in ability to transmit and receive signals in Ultra Wideband communication mode.
[0016] During the secure telemetry step, the connected mobile terminal and the access control reader exchange security data. At the end of the secure telemetry step, a certified distance between the secure access control reader and the connected mobile terminal is also established and then verified.
[0017] During the access control step, the access control unit checks the user's identification data (or, in English, credentials) to determine if he has the accreditations to enter the secure area.
[0018] According to different embodiments of the invention, the locking / unlocking system of the access control bay, which may for example correspond to a strike plate opening and closing, may in one embodiment either be physically connected by a cable to the access control unit, or in another embodiment be connected to the access control unit through a wireless link.
[0019] According to one feature of the invention, the access control unit receives the user identification data on the condition that prior to, during the secure telemetry stage, it has been verified that the certified distance is less than or equal to an authorization distance.
[0020] In other words, the transmission of the user's identification data to the access control unit for the implementation of the access control step is conditional upon a certified distance check performed at the end of the secure telemetry step. This certified distance check consists of verifying whether it is within, that is, less than or equal to, an authorized distance. If so, the user's identification data is transmitted to the access control unit. If not, it is not transmitted.
[0021] This distance control is an additional security measure to ensure that the user with the required credentials is near the secure access control reader and / or the access control bay before unlocking the bay's locking / unlocking system. Indeed, the secure telemetry step may have been triggered by the user unlocking their connected mobile device, even if the user is away from the secure access control reader and unlocked their connected mobile device for a reason other than accessing the secure area protected by the access control bay.
[0022] According to one feature of the invention, during the secure telemetry step, the certified distance between the connected mobile terminal and the secure access control reader is: - established by being calculated by at least one of the connected mobile terminal and the secure access control reader; and - verified either by the connected mobile terminal or by the secure access control reader.
[0023] The certified distance is obtained from the calculation by at least one of the connected mobile terminal and the secure access control reader of a distance between the connected mobile terminal and the secure access control reader.
[0024] In one embodiment of the invention, only one of the two pieces of equipment, the connected mobile terminal and the secure access control reader, calculates the distance separating the two pieces of equipment.
[0025] In another embodiment of the invention, the connected mobile terminal and the secure access control reader both calculate the distance between them. They then exchange the distance value they have calculated. Each device then compares the distance it received with the distance it calculated itself. If the distances are not consistent, the telemetry step is stopped. If they are consistent, the telemetry step continues.
[0026] In one embodiment of the invention, the certified distance is calculated from a time-of-flight measurement, performed by at least one of the two devices, during a bidirectional exchange of safety data. Once the distance is calculated.
[0027] More specifically, during the secure telemetry step, a distance is calculated between the portable authentication device and the secure access control reader, said distance being certified by nature, hence the notion of certified distance.
[0028] The distance is certified by nature because it occurs during the secure telemetry step, and because it is based on at least one bidirectional exchange of Ultra Wideband signals between two pieces of equipment (the connected mobile terminal and the secure access control reader) each having, for example: an embedded secure component; or a previously loaded trusted firmware or application inside, or a trusted execution environment (TEE).
[0029] Certified distance is an additional means of strengthening the security level of the secure access protocol when it must be verified for the subsequent implementation of the access control step. Indeed, an uncertified distance could potentially be fraudulent and originate from a malicious system seeking to gain access to the secure space protected by the access control bay. Thus, if the equipment responsible for verifying the certified distance, but not for calculating it, receives a certified distance, it implements its verification. Conversely, If the received distance is not certified, the check is not carried out and the secure access control process is stopped.
[0030] As previously stated, once the certified distance has been calculated, the secure telemetry step continues with a check to verify whether it is less than or equal to the authorized distance. This verification can be performed by the secure access control reader or by the connected mobile terminal.
[0031] In a first embodiment in which the certified distance is calculated by only one of the two pieces of equipment among the secure access control reader and the connected mobile terminal, the equipment in charge of calculating the certified distance is also the one that controls it.
[0032] In a second embodiment in which the equipment in charge of the calculation is not the same as that in charge of verifying the certified distance, there is transmission of the certified distance from the equipment that calculated it to the equipment that is to verify it.
[0033] The secure telemetry step may not be limited to the exchanges and principles described above. Further information on secure telemetry is available in the two references indicated in the Prior Art.
[0034] According to one feature of the invention, the step of unlocking the connected mobile terminal is implemented by the user according to at least one of the following operations: - a touch screen activation included in the connected mobile terminal by pressing it by the user, or on a power button also included in the connected mobile terminal; - an operation to enter an unlock code on the connected mobile terminal; - a touch-sensitive unlock pattern entry operation on a touch screen of the connected mobile terminal; - a fingerprint recognition operation on a fingerprint sensor of the connected mobile terminal; - a facial recognition operation of the user using a camera integrated into the connected mobile terminal.
[0035] According to one feature of the invention, the access control unit receives the user's identification data from: - either the connected mobile terminal, which connected mobile terminal has network access and contains a connection address to connect remotely to the access control unit and communicate with it; - either the secure access control reader, which secure access control reader has network access to communicate with the access control unit, via direct communication or via hop-by-hop communication.
[0036] According to one embodiment of the invention, the certified distance is verified by the equipment between the connected mobile terminal and the secure access control reader in charge of transmitting the user's identification data to the access control unit.
[0037] Given that the access control reader and the connected mobile terminal exchange their respective security data, in another embodiment in which the equipment among the connected mobile terminal and the secure access control reader verifying the certified distance is not the same as that in charge of transmitting the user identification data to the access control unit, the equipment in charge of verifying the certified distance sends, if the certified distance is within the authorization distance, an authorization signal to the equipment in charge of transmitting the user identification data so that it implements said transmission.
[0038] In a first embodiment of the invention, the connected mobile terminal transmits the user's identification data to the access control unit if it has network access and a connection address to remotely connect to the access control unit. This first embodiment can be implemented because the secure access control reader is autonomous and therefore not in contact with the access control unit.
[0039] The connection address may correspond to data previously loaded into the connected mobile terminal, or to data transmitted by the secure access control reader to the connected mobile terminal when the secure telemetry step is implemented.
[0040] In a second embodiment of the invention, the user's identification data is transmitted to the access control unit by the secure access control reader. This configuration can be implemented because the connected mobile terminal does not have network access.
[0041] Advantageously, the calculation and verification of the certified distance, and the transmission of the user identification data to the access control center by the secure access control reader makes it possible to significantly strengthen the level of security of the secure access control process since, by definition, the secure access control reader is a trust system designed and conformed to be an integral part of an access control installation implementing secure access control processes.
[0042] In a first embodiment, the secure access control reader is in wireless communication with the access control unit and transmits the user's identification data directly to it.
[0043] In a second embodiment, the secure access control reader and the access control unit are part of a mesh network comprising several other secure access control readers. Each device in the mesh network is capable of communicating with its nearest neighbors according to a hop-by-hop communication protocol. Advantageously, the mesh network addresses the problem of indoor network coverage when the building structure and the materials used in its construction interfere with signal transmission, preventing, for example, the secure access control reader involved in the secure access control process and the access control unit from communicating with each other, even if they are within communication range (for example, because they are located in the basement, or on different floors of a building, or separated by a thick wall, etc.).
[0044] Not limited to, the secure access control reader and the access control unit can communicate with each other using a wireless communication protocol such as Wifi® or Bluetooth Mesh®.
[0045] In a third variant, the secure access control reader is in wired / physical connection with the access control unit (for example, by means of Ethernet links, or an RS485 interface), so that it can transmit the user's identification data to it even though it does not have network access.
[0046] According to one embodiment of the invention, when the access control unit receives the user's identification data from the secure access control reader, the secure access control process also includes, prior to the access control step, a transmission step during which the connected mobile terminal transmits, in Ultra Broadband communication mode, the user's identification data to the secure access control reader; said transmission step being implemented as follows: - following the unlocking step and before the secure telemetry step begins, or - during the secure telemetry step, or - once the secure telemetry step is completed
[0047] In other words, if the user's identification data is transmitted to the access control unit by the secure access control reader, the connected mobile terminal must implement a step to transmit the user's identification data to the secure access control reader. As indicated above, this transmission step can be implemented before, during, or after the secure telemetry step.
[0048] The implementation of the transmission step implies, on the one hand, that the connected mobile terminal is within communication range of the access control reader secure in Ultra Wideband communication mode; and other than that the transceiver of the connected mobile terminal is in the awake state to be able to transmit the user's identification data to the secure access control reader.
[0049] It is conceivable that the transmission step, in the case where it is planned before the secure telemetry step, will be implemented following the unlocking of the connected mobile terminal.
[0050] Where the transmission step is scheduled to take place after the secure telemetry step and before the access control step, it is possible for said transmission step to be implemented provided that it has been verified that the certified distance is less than or equal to the authorization distance. In other words, if the certified distance is greater than the authorization distance, neither the transmission step nor the access control step is implemented. Otherwise, if the certified distance is valid, then it is possible to: - when the connected mobile terminal performs the check and validation of the certified distance, it must transmit the user's identification data immediately after validating the certified distance; or else - when the secure access control reader is in charge of controlling and validating the certified distance, it sends a request signal to the connected mobile terminal after validation of the latter, which connected mobile terminal, after receiving said request signal, transmits the user's identification data to the secure access control reader.
[0051] According to one embodiment of the invention, the secure access control reader periodically emits a probing signal, and the telemetry step is implemented by the secure access control reader following the receipt of a confirmation signal from the connected mobile terminal; said confirmation signal being generated and then transmitted by the connected mobile terminal on the condition that at least: the unlocking step is implemented, and then the connected mobile terminal has received the probing signal once in the unlocked state.
[0052] In other words, the secure access control reader periodically emits a probing signal into its environment (in the space in which it is located). This probing signal can be received by a user's connected mobile terminal if it is within the communication range of the secure access control reader.
[0053] If the connected mobile terminal receives this signal, and if the user unlocks it, then the connected mobile terminal generates a confirmation signal which it transmits to the secure access control reader. Upon receiving the confirmation signal, the connected mobile terminal then initiates the secure telemetry step.
[0054] Possibly, as the probe signal is sent periodically by the secure access control reader into its environment, it may not be received and therefore lost if a connected mobile terminal is not within the communication range of the secure access control reader at the time of its transmission, and if its Ultra Wideband transceiver is not in the awake state.
[0055] According to one embodiment of the invention, the telemetry step is implemented by the connected mobile terminal when at least: it is in the unlocked state following the unlocking step, and is within Ultra Wideband communication range with the secure access control reader.
[0056] In another embodiment of the invention, the secure telemetry step is initiated, and therefore managed, following the unlocking of the connected mobile terminal, which acts as the master. The secure access control reader, which acts as the slave, is configured to await commands / instructions from the connected mobile terminal, which acts as the master. In other words, and advantageously, the secure access control reader does not perform any action until the user's connected mobile terminal establishes communication with it. This configuration also has the advantage of reducing the power consumption of the secure access control reader in Ultra Wideband communication mode, since it does not unnecessarily emit a signal into its environment that may not be received by a connected mobile terminal.
[0057] According to one embodiment of the invention, the secure telemetry step is initiated on the condition at least that: the unlocking step is implemented, and that at least one validation action is also carried out on the connected mobile terminal; otherwise the secure telemetry step is not carried out.
[0058] Unlocking only the connected mobile device does not definitively determine whether or not the user intends to access the secure area. For example, the user may, while near or even within communication range of the secure access control reader, have unlocked their connected mobile device simply to check their email. In this case, the secure telemetry and access control steps are performed unnecessarily. Advantageously, the fact that the secure telemetry step is performed only if the user has unlocked their mobile phone and has performed at least one validation action with it provides greater confirmation of their intention to access the secure area.
[0059] In one embodiment of the invention, when the secure access control reader initiates the secure telemetry step following receipt of the confirmation signal from the connected mobile terminal, said confirmation signal is generated by the connected mobile terminal following its unlocking and after the user has performed at least one validation action.
[0060] In another embodiment of the invention, the connected mobile terminal initiates the secure telemetry step following its unlocking and after the user has performed at least one validation action.
[0061] When the step of transmitting the user identification data from the connected mobile terminal to the secure access control reader is scheduled to occur before the secure telemetry step, it is possible for it to be implemented after the completion of at least one validation action. If the at least one validation action comprises several validation actions, the transmission step may be implemented after the completion of the last of the several validation actions.
[0062] According to one embodiment of the invention, at least one validation action includes at least one launch operation carried out in a launch menu displayed by a mobile launch application, loaded in the connected mobile terminal.
[0063] According to one embodiment of the invention, the launching operation consists of at least one of the following operations: - an operation to enter a launch code on the launch menu; - a touch input operation of a launch pattern on the launch menu; - a validation operation on the launch menu.
[0064] According to one embodiment of the invention, the mobile launch application opens automatically and displays the launch menu following the unlocking step.
[0065] In other words, the telemetry step, then the access control step, are carried out on the condition that the user has, firstly, unlocked his connected mobile terminal and then, secondly, carried out a launch operation in the launch menu of a dedicated application designed for the implementation of the secure access control process, and previously loaded into the connected mobile terminal.
[0066] According to one embodiment of the invention, at least one validation action includes at least one tilting of the connected mobile terminal through a tilt angle within a predefined launch angular range.
[0067] In one embodiment of the invention, the user's validation action corresponds to a certain orientation / tilt of the connected mobile terminal relative to the secure access control reader, or to the ground. The orientation of the connected mobile terminal is considered valid if the angle of inclination of the connected mobile terminal relative to the secure access control reader or to the ground is within a predefined angular launch range. This verification is performed either by the connected mobile terminal or by the secure access control reader.
[0068] If the tilt angle of the connected mobile terminal is valid, then the secure telemetry step is initiated.
[0069] The angular launch interval is representative of an orientation of the connected mobile terminal such that the user interacts with: - the front of the connected mobile device facing or almost facing it; this is for: navigating the menus of the connected mobile device, reading messages... -the rear face of the connected mobile terminal facing or substantially facing the front face of the secure access control reader.
[0070] According to one embodiment of the invention, the mobile launch application opens and displays the launch menu on the condition that the tilt angle is within the predefined launch angular range.
[0071] In other words, the mobile launch application is only displayed on the screen of the connected mobile terminal if the user tilts their connected mobile terminal at a valid angle of inclination within the launch angular range. In this configuration, the user therefore performs two validation actions.
[0072] In one embodiment of the invention, the telemetry step is therefore implemented only if the user has successively: - unlocked their connected mobile terminal; then - oriented its connected mobile terminal at an angle of inclination within the launch angular range; then - performed a launch operation in the mobile launch application which was displayed on the screen of the connected mobile terminal following the proper orientation of the latter.
[0073] According to one embodiment of the invention, the angle of inclination is measured by an inertial measurement unit integrated into the connected mobile terminal.
[0074] In other words, in one embodiment of the invention, the tilt angle is measured by the connected mobile terminal using an inertial measurement unit (IMU) it contains. It then verifies whether the measured tilt angle is within the considered launch angular range to determine whether the orientation / tilt of the connected mobile terminal corresponds to a validation action.
[0075] According to one embodiment of the invention, the tilt angle is measured by the secure access control reader, from reception signals of an Ultra Wideband wave from the connected mobile terminal.
[0076] The measurement of the angle by the secure access control reader implies that the Ultra Wideband transceiver of the connected mobile terminal is awake, i.e. capable of transmitting and receiving signals in Ultra Wideband communication mode.
[0077] In one embodiment of the invention, the secure access control reader transmits the tilt angle it has measured to the connected mobile terminal in order to check whether or not it is within the launch angular range, and thus detects or not a validation action.
[0078] In another embodiment of the invention, the access control reader performs this comparison itself. If the tilt angle is within the launch angular range, then the secure access control reader sends a validation signal to the connected mobile terminal, which, upon receiving said validation signal, considers that a validation action has occurred.
[0079] According to one embodiment of the invention, at the start of the secure access control process, the Ultra Wideband transceiver of the secure access control reader is in a standby state, only capable of receiving in Ultra Wideband, and prior to the secure telemetry step, a wake-up step of the secure access control reader is implemented, initiated by a detection by at least one sensor of an approach or contact of the user or the mobile terminal connected with said secure access control reader, and followed by a wake-up of the Ultra Wideband transceiver of said secure access control reader in order to be able to transmit and receive in the Ultra Wideband communication mode and thus allow the implementation of the secure telemetry step; and such that in the absence of said wake-up step, the secure telemetry step is not implemented.
[0080] In one embodiment of the invention, the Ultra Wide transceiver of the secure access control reader is, at the start of the access control process, in a standby state, only able to receive signals in Ultra Wide Band communication mode.
[0081] The Ultra Wideband transceiver of the secure access control reader transitions from this standby state to an awake state, in which it is then also capable of emitting Ultra Wideband signals, following the detection, during a wake-up step, of an approach of the user or their connected mobile terminal to the secure access control reader, or of contact with it.
[0082] Advantageously, the power consumption of the Ultra Wideband transceiver of the secure access control reader is reduced since it is only activated during the implementation of the access control process. secure (for the implementation of secure telemetry, and possibly to communicate with the access control center if it is compliant / designed for it).
[0083] Also, the implementation of the wake-up step prevents the secure access control reader from periodically and unnecessarily emitting the probing signal in its environment if no connected mobile terminal is present, or if the connected mobile terminal is not within communication range of the secure access control reader.
[0084] In addition, the detection of the approach of the user (or his connected mobile terminal) or of his contact with the secure access control reader, combined with the unlocking of the connected mobile terminal, tends to confirm / validate the user's intention to access the secure space.
[0085] The secure telemetry step requires that both the transceivers of the connected mobile terminal and the secure access control reader be awake and therefore capable of transmitting and receiving signals. In other words, if the wake-up step is not implemented, and the Ultra Wideband transceiver of the secure access control reader remains in a sleep state, the secure telemetry step cannot be implemented.
[0086] According to two variants of the invention, the wake-up step of the secure access control reader takes place before or after the unlocking step.
[0087] According to one embodiment of the invention, during the wake-up step, the detection of approach or contact consists of detecting contact from the user by at least one sensor located on a part of the secure access control reader.
[0088] According to one embodiment of the invention, at least one sensor is chosen from a touch, a mechanical sensor, a capacitive sensor, and an inductive sensor.
[0089] In other words, according to different embodiments of the invention, the detection of user contact may, but is not limited to: - contact or approach of a user's hand on a part of the secure access control reader, detected for example by means of electrostatic sensors (inductive sensor, capacitive sensor) or sound or optical sensors; - pressing a key or button that the secure access control reader includes on its casing or on a touchpad.
[0090] According to one embodiment of the invention, during the wake-up step, the detection of approach or contact consists of a detection by at least one sensor of the approach of the user or the mobile terminal connected with a part of the secure access control reader within a given activation distance from the secure access control reader.
[0091] According to one embodiment of the invention, at least one sensor is chosen from a capacitive sensor, an inductive sensor, a radar sensor, an ultrasonic sensor, an optical sensor, a vibration sensor.
[0092] In other words, according to different embodiments of the invention, the detection of the user's approach may, but is not limited to, relate to: - detection of user or connected mobile device movements by a motion sensor (for example, a passive infrared motion sensor); - vibrations caused by the user's steps on the ground, which are detected by an accelerometer; - a microphone detects the sounds caused by the user's footsteps on the floor.
[0093] The approach of the user or their connected mobile terminal is detected when they are within a distance of the secure access control reader that is less than or equal to an activation distance.
[0094] In one embodiment of the invention, the activation distance is defined by the designers or installers of the secure access control reader as being equal to the authorization distance.
[0095] In another embodiment of the invention, the activation distance is defined by the designers or installers of the secure access control reader as being substantially equal to the authorization distance, for example the activation distance is equal to 1.25 times the authorization distance.
[0096] According to one embodiment of the invention, at least one sensor is mounted on the secure access control reader, or is remote from the secure access control reader and connected to the secure access control reader
[0097] In other words, at least one sensor detecting contact by the user on the secure access control reader or an approach by the user or their connected mobile terminal can be integrated into the remote secure access control reader.
[0098] According to one embodiment of the invention, at the start of the secure access control process, the Ultra Wideband transceiver of the connected mobile terminal is in a standby state, only able to receive in Ultra Wideband, and after the wake-up step of the secure access control reader, the secure access control reader emits a wake-up signal in the Ultra Wideband communication mode which is received by the Ultra Wideband transceiver of the connected mobile terminal, causing said Ultra Wideband transceiver to wake up so that it can transmit and receive in the Ultra Wideband communication mode and thus enable the implementation of the secure telemetry step.
[0099] The connected mobile terminal may include a battery for its power supply. For the purpose of reducing power consumption and saving energy on said battery, the Ultra Wideband transceiver of the connected mobile terminal is, at the start of the access control process, in a standby state, only capable of receiving data in Ultra Wideband communication mode (but not of transmitting it).
[0100] The implementation of the telemetry step requires that the Ultra Wideband transceiver of the connected mobile terminal be awake, i.e. capable of receiving, but also of transmitting, in Ultra Wideband communication mode.
[0101] In one embodiment of the invention, after its Ultra Wideband transceiver wakes up following the detection of contact or the approach of the user, the secure access control reader transmits a wake-up signal in Ultra Wideband communication mode to the Ultra Wideband transceiver of the connected mobile terminal. Once the wake-up signal is received, the Ultra Wideband transceiver of the connected mobile terminal wakes up.
[0102] According to one embodiment of the invention, the secure access control method includes a wake-up step of the Ultra Wideband transceiver of the connected mobile terminal so that it can transmit and receive in Ultra Wideband communication mode and thus enable the implementation of the secure telemetry step; said wake-up step being implemented on the condition at least where the unlocking step of the connected mobile terminal is carried out.
[0103] In other words, in another embodiment of the invention, at least unlocking the connected mobile terminal has the effect of waking up its Ultra Wideband transceiver of the connected mobile terminal, making it then capable of initiating the secure telemetry step.
[0104] According to one embodiment of the invention, the wake-up step of the Ultra Wideband transceiver of the connected mobile terminal is implemented on the condition that at least one validation action is also carried out.
[0105] In other words, in one of the other possible embodiments of the invention, the wake-up of the Ultra Wideband transmitter of the connected mobile terminal only occurs if the user unlocks the connected mobile terminal and performs at least one validation action with it (the at least one validation action being able to correspond to the actions presented previously).
[0106] According to one embodiment of the invention, the Ultra Wideband transceiver of the connected mobile terminal is in an awake state at the start of the secure access control process in order to be able to transmit and receive in Ultra Wideband communication mode.
[0107] In other words, in one of the other possible embodiments of the invention, the Ultra Wideband transceiver of the connected mobile terminal is, at the start of the secure control process, woken up.
[0108] According to one embodiment of the invention, the at least one secure space comprises at least one other secure space accessible by at least one other access control bay equipped with another locking / unlocking system and associated with another secure access control reader comprising an Ultra Wideband transceiver, wherein the secure access control method comprises a step of generating an access token followed by a step of storing said access token in the connected mobile terminal, the generation step and the storage step being implemented when access to the secure space is authorized by the access control unit, and wherein the secure access control method implements an access control phase to access the other secure space which comprises the following steps: - a step to detect an access request made by the user on the connected mobile terminal; - a transmission step during which the connected mobile terminal transmits, in Ultra Wideband communication mode, the access indicator to the other secure access control reader in response to the detection of the access request; - a transmission step during which the other secure access control reader transmits said access indicator to the access control unit; - an access control step during which the access control unit, after receiving the access indicator, authorizes access to the other secure space accessible through the other access control bay and, if necessary, commands the other locking / unlocking system of said other access control bay, without receiving or verifying the user's identification data by said access control unit.
[0109] A building may include several secure areas with restricted access, each of the secure areas being protected by its own access control bay, to which a secure access control reader is associated.
[0110] In one embodiment of the invention, when a secure telemetry step is implemented between a secure access control reader associated with a building access control bay and the connected mobile terminal of a user wishing to access a first secure space protected by said access control bay, and the access control unit authorizes the user to enter the secure space, an access token (or "cookie" in English) is generated and then stored in the connected mobile terminal.
[0111] In one embodiment of the invention, the access indicator is generated and then transmitted by the access control unit to the connected mobile terminal, either directly if the connected mobile terminal and the access control unit are in direct communication, or via the secure access control reader that previously participated in the secure telemetry step (via direct communication between the access control unit and the secure access control reader, or via hop-by-hop communication with other secure access control readers).
[0112] In another embodiment of the invention, the access token is generated by the connected mobile terminal by means of a dedicated application previously loaded inside; the generation may, for example, follow the receipt of data relating to an agreement to generate an access token from the access control center.
[0113] Advantageously, the access indicator is used to speed up user authentication with the access control system if the user wishes to pass through another access control bay to enter a second secure area of the building.
[0114] To do this, when the user approaches the secure access control reader associated with this other access control bay, the user interacts with their connected mobile terminal so that it detects a request (i.e., an intention) for access.
[0115] According to different embodiments of the invention, the access request can be detected following: - to a contact of the user with their connected mobile terminal; - an orientation / tilt of the connected mobile terminal with respect to the secure access control reader of the other access control bay; - to unlocking the mobile phone; - to a launch operation performed in a mobile application.
[0116] In other words, the methods used to detect the user's validation action from their connected mobile terminal to previously implement the secure telemetry step are also applicable to detecting the access request.
[0117] Once the access request is detected, the connected mobile terminal transmits only the access indicator to the secure access control reader of the other access control bay, which relays it to the access control center (via direct communication or hop-by-hop communication).
[0118] Upon receipt of the access token, the access control unit then authorizes the user to access the second secure space; this without having carried out a verification of the user's identification data.
[0119] In one embodiment of the invention, the access indicator is generated based on the user's identification data.
[0120] In other words, the access token only allows the user to facilitate their authentication to access secure areas for which they have the required credentials. The access token does not allow the user to access secure areas to which they are not authorized.
[0121] According to one embodiment of the invention, the access indicator has a limited validity period.
[0122] Advantageously, in order to secure simplified user authentication using an access token, said access token has a limited validity period. Once the validity period has expired, the access token expires. User authentication with the access control system to access a secure area then consists of repeating, at a minimum, the wake-up, secure telemetry, and access control steps (with the access control system verifying the user's identification data).
[0123] According to a feature of the invention, the authorization distance is less than or equal to 1 m. Brief description of the drawings
[0124] Other features and advantages of the present invention will become apparent from the following detailed description, of a non-limiting example of implementation, made with reference to the accompanying figures in which:
[0125] [Fig-1] is a schematic view of an example of a building comprising two secure spaces, each protected by an access control bay which includes a locking / unlocking system, controlled by an access control unit, and which is associated with a secure access control reader operating in Ultra Wideband communication mode, with a user seeking to access one of the secure spaces by authenticating with the access control unit via a secure access control reader, this by means of a connected mobile terminal;
[0126] [Fig.2] is a schematic view of a bidirectional data exchange, in the Ultra Broadband communication mode, between a connected mobile terminal and a secure access control reader;
[0127] [Fig.3] is a flow diagram of a first embodiment of the invention wherein the connected mobile terminal and the secure access control reader participate in a secure telemetry step after the user of the connected mobile terminal has unlocked it; the secure access control reader transmitting user identification data to the access control unit following the secure telemetry step so that it can implement a step of access control allowing the user to be authenticated and authorized or denied access to the secure area protected by the access control bay associated with the secure access control reader;
[0128] [Fig.4] is a schematic view of a principle for calculating a flight time during a bidirectional data exchange between the connected mobile terminal and the secure access control reader during a secure telemetry step implemented during the secure access control process;
[0129] [Fig.5] is an illustration, following the secure telemetry step, of a transmission data to authenticate the user from the secure access control reader to the access control unit which is configured to control the transmitted data in order to authorize or not the user to access a secure area, the transmission of data can be done by direct communication ([Fig.5]-a) or by hop-by-hop communication ([Fig.5]-b);
[0130] [Fig.6] is an operating diagram in which the connected mobile terminal transmits to the access control center the user identification data necessary for the implementation of the secure access control step, the connected mobile terminal having to communicate with the access control center a connection address that the secure access control reader transmitted to it during the secure telemetry step;
[0131] [Fig.7] is a schematic view of the building in [Fig.1] in relation to the diagram of operation of [Fig.6], showing the transmission of data necessary for the implementation of the access control step by the connected mobile terminal to the access control unit;
[0132] [Fig.8] is a schematic view of a validation action to be performed for implement the telemetry step following the unlocking of the connected mobile terminal, said validation action corresponding here, in a given embodiment variant, to a launch operation performed by the user on a launch menu available from a mobile launch application included in the connected mobile terminal;
[0133] [Fig.9] is a schematic view of a second variant of the implementation of the action of validation, which corresponds to an inclination of the connected mobile terminal relative to the ground and the secure access control reader;
[0134] [Fig. 10] is an operating diagram of an embodiment in which the telemetry step is implemented on the condition that the user first unlocks their connected mobile terminal, and that in a second step at least one validation action is carried out using the connected mobile terminal, said at least one validation action corresponding here to a specific tilt of the connected mobile terminal relative to the ground and / or the secure access control reader;
[0135] [Fig. 11] is a schematic view of a first implementation variant of a wake-up step included in the secure access control method to switch the Ultra Wideband transceiver of the secure access control reader from a standby state to a woke state in which it is able to transmit and receive data in Ultra Wideband communication mode; the wake-up of the Ultra Wideband transceiver occurring following detection of physical contact of the user with the secure access control reader;
[0136] [Fig. 12] is a schematic view of a second implementation variant of the wake-up step, with the wake-up of the Ultra Wideband transceiver occurring following detection of an approach of the user, or their connected mobile terminal, within a given activation distance from the secure access control reader;
[0137] [Fig. 13] is a flow diagram of an embodiment of the secure access control method, wherein the probing signal is transmitted by the secure access control reader to the connected, unlocked and woken-up mobile terminal, following the implementation of the wake-up step according to its illustrated embodiment variant [Fig. 11];
[0138] [Fig. 14] is a flow diagram of an embodiment of the secure access control method, wherein the switching of the Ultra Wideband transceiver of the connected mobile terminal from the standby state to the awake state occurs following the reception of a wake-up signal emitted by the secure access control reader after the Ultra Wideband transceiver of the latter has also switched from the standby stage to the awake state following the detection of contact of the user with the secure access control reader;
[0139] [Fig. 15] is a flow diagram of an embodiment of the secure access control method which includes the generation and storage of an access token in the user's connected mobile terminal following authorization of access to a first secure space by the access control unit, said access token subsequently being used to accelerate the authentication of the user with another secure access control reader to access another secure space;
[0140] [Fig.16] is a schematic view of the building of [Fig.1], and illustrating an application context related to the operating diagram of [Fig. 15], for which the user, after entering a secure space, will use the access indicator contained in his connected mobile terminal to authenticate himself from the access control center to access another secure space;
[0141] [Fig. 17] a schematic view related to [Fig. 16] and [Fig. 17], in which, in one embodiment, and in order to authenticate itself with the access control center, the connected mobile terminal transmits the access indicator to another secure access control reader following the detection of a contact, here a tap, from the user.
[0142] [Detailed description of one or more embodiments of the invention]
[0143] With reference to [Fig.1] and [Fig.2], the secure access control method 100 of the invention, which is designed to operate in Ultra Wideband communication mode, is implemented in the application context of a building comprising at least two secure spaces SI, S2 whose access is protected by access control bays D1, D2 each equipped with a locking / unlocking system, and each associated with a secure access control reader RI, R2 comprising an Ultra Wideband transceiver UR1, UR2 in order to be able to transmit and receive signals / data in this communication mode.
[0144] In the rest of the description: - the secure SI, S2 spaces are designated under the terms secure SI space and other secure S2 spaces; - Access control bays D1 and D2 are referred to as access control bay D1 and other access control bay D2; and - RI, R2 secure access control readers are referred to as RI secure access control reader and other R2 secure access control reader.
[0145] It is also assumed in the remainder of the description that a user U wishes to access the secure space SL. To do so, they must authenticate themselves with an access control unit 2 responsible for controlling access to the secure space SI, using a connected mobile terminal 1 and via the secure access control reader SL. The connected mobile terminal also includes an Ultra Wideband transceiver U1 to enable transmission and reception in Ultra Wideband communication mode. It also contains the user U's identification data udata (or credentials).
[0146] The connected mobile terminal 1 is a device equipped with a touch screen and which may, but is not limited to, correspond to a mobile phone, a touch tablet, a connected watch, etc.
[0147] The Ultra Wideband transceivers UR1, UR2, Ul, the secure access control readers RI, R2 and the connected mobile terminal 1 can operate: - in a standby state, only capable of receiving Ultra Wideband data / signals, but not capable of transmitting Ultra Wideband data / signals; or - in an awake state where they are able to transmit and receive Ultra Wideband data / signals.
[0148] In other words, with reference to [Fig. 2], when they are awake (i.e., in the awake state), the Ultra Wideband transceivers Ul, UR1, UR2 of the connected mobile terminal 1 and of the secure access control reader UR1, UR2 can proceed with a bidirectional exchange of UWB1 data in Ultra Wideband communication mode.
[0149] In the rest of the description, when it is written that a connected mobile terminal 1 and a secure access control reader RI, R2 exchange data (during transmissions and receptions), it is understood that it is their Ultra Wide Band transceivers Ul, UR1, UR2 that exchange said data.
[0150] The following description presents, but is not exhaustive, several embodiments of the secure access control process 100. They constitute a non-exhaustive list of all the possible embodiments for designing the secure access control process 100.
[0151] Regardless of the embodiment of the secure access protocol 100, the authentication of user U is based first of all on a secure telemetry step SR in the Ultra Broadband communication mode between the connected mobile terminal 1 and the secure access control reader RI, which secure telemetry step requires at least for its implementation that user U unlocks his connected mobile terminal 1 during a ulock unlocking step, taking the connected mobile terminal from a locked state to an unlocked state.
[0152] A first embodiment is illustrated [Fig.3]. In this first embodiment, it is assumed that the Ultra Wideband transceiver UR1 of the secure access control reader RI is in the awake state.
[0153] At the start of the secure access control process 100, user U unlocks their connected mobile terminal 1 during the ulock unlock state. According to different embodiments of the invention, the unlocking of the connected mobile terminal can occur following: - the activation of a touchscreen included in the connected mobile terminal 1 by pressing it by the user U, or by pressing a power button also included in the connected mobile terminal 1; or - an operation to enter an unlock code on the connected mobile terminal 1; or - a touch-sensitive unlock pattern entry operation on the touchscreen of the connected mobile terminal 1; or - a fingerprint recognition operation on a fingerprint sensor of the connected mobile terminal 1; or - a facial recognition operation of user U using a camera integrated into the connected mobile terminal 1.
[0154] At the start of the secure access control process 100, the Ultra Wideband Ul transceiver of the connected mobile terminal 1, in a first In a second configuration, it can be considered to be either in a standby state, or even in a switched-off state (i.e., unable to transmit and receive a signal in Ultra Wideband communication mode).
[0155] In this second configuration, and as illustrated [Fig.3] for the first embodiment and subsequently in the other embodiments which will be described, unlocking the connected mobile terminal 1 has the effect of waking up its Ultra Wideband transceiver U1 during a wake-up step WP-1, either by switching it from the sleep state to the wake-up state, or by turning it on.
[0156] According to two possible embodiments of the secure access control method 100, the secure telemetry step SR can be initiated by the secure access control reader RI, or by the connected mobile terminal.
[0157] In the first embodiment illustrated [Fig. 3], the secure telemetry step SR is initiated by the secure access control reader RI when it successfully performs a first bidirectional exchange of Ultra Wideband UWB1 data with a connected mobile terminal 1. To do this, the secure access control reader RI periodically emits a scanning probe signal sscan into its environment during a transmission step El, which is received by the connected mobile terminal 1 during a reception step El'. During this reception step El', the Ultra Wideband transceiver U1 of the connected mobile terminal 1 is either in the standby state or in the awake state, i.e., in a state enabling it to receive an Ultra Wideband signal.
[0158] Following reception step El', the connected mobile terminal 1 must implement a transmission step E2 during which it will transmit an ack confirmation signal to the secure access control reader.
[0159] The implementation of the transmission step E2 requires, on the one hand, that the Ultra Wideband transceiver U1 of the connected mobile terminal 1 be in the awake state and, on the other hand, that the user U has unlocked his connected mobile terminal 1. If at least one of the two conditions is not met, then the connected mobile terminal 1 does not respond to the secure access control reader RI (it therefore does not implement the transmission step E2).
[0160] As previously stated, in the embodiment presented [Fig.3], the ulock unlocking step, carried out at the start of the secure access control process 100, has the effect of unlocking the connected mobile terminal 1 and waking up its Ultra Wideband transceiver Ul, making the two conditions fulfilled for the implementation of the transmission step E2 following the reception step El'.
[0161] Optionally, if the connected mobile terminal 1 is woken up at the start of the secure access control process 100, it is possible that the sscan scanning signal will be received by the connected mobile terminal 1 before the user U unlocks it, since it is capable of receiving Ultra Wideband signals. In other words, in this configuration, the transmission steps El and El' occur before the unlocking step ulock.
[0162] With reference to [Fig.3], following the receipt of the confirmation signal ack during a reception step E2', the secure access control reader RI initiates the secure telemetry step SR.
[0163] The secure telemetry SR step includes at least: - an ESR1 transmission step during which the secure access control reader RI transmits security data sdatal to the connected mobile terminal 1; and - an ESR2 transmission step during which the connected mobile terminal 1 transmits security data sdata 2 to the secure access control reader RI; - a calculation step EC of a certified distance sdist between the connected mobile terminal 1 and the secure access control reader RI; and - an Everif verification step following the EC calculation step during which a verification of the certified distance sdist is carried out.
[0164] In embodiments where the connected mobile terminal 1 initiates the secure telemetry step SR, it is possible for said telemetry step to begin following the unlock step ulock, with the connected mobile terminal 1 communicating security data sdatal and the user access data udata to the secure access control reader RI within its communication range. Thus, these embodiments do not require either the periodic transmission of the sscan probing signal by the secure access control reader RI or the transmission of the ack confirmation signal by the connected mobile terminal 1 to the secure access control reader RI.
[0165] With reference to [Fig. 4], in one embodiment of the invention, the certified distance sdist is calculated, according to equation Eq. 1, by at least one of the connected mobile terminal 1 and the secure access control reader RI from a Time Of Flight (ToF) measured by said at least one of the connected mobile terminal 1 and the secure access control reader RL _ Tloop-Treply Eq. 1
[0166] where Treply is the response time of the connected mobile terminal 1 which corresponds to the time interval between: the instant when it receives during a reception step ESR1' the security data sdata from the secure access control reader RI and the instant, and the implementation of the transmission step ESR2; and Tloop is the duration of the bidirectional exchange between the secure access control reader RI and the connected mobile terminal 1, i.e. here the time interval between the transmission step ESR1 and a reception step ESR2' during which the secure access control reader RI receives from the connected mobile terminal 1 the security data sdata2.
[0167] In one embodiment of the invention, such as that illustrated [Fig.3], only the RI secure access control reader calculates the certified distance sdist.
[0168] The distance certification stems from the fact that the distance is calculated during the SR secure telemetry step, and that it is based on at least one bidirectional exchange of Ultra Wideband signals between two pieces of equipment (the connected mobile terminal and the secure access control reader) each having: an embedded secure component; or a previously loaded trusted firmware or application inside, or a Trusted Execution Environment (TEE).
[0169] In another embodiment of the invention, the connected mobile terminal and the secure access control reader RI both calculate the certified distance sdist separating them. They then exchange the certified distance sdist value they have calculated. Each device RI then compares the certified distance sdist it received with the certified distance sdist it calculated itself. If the consistency between the certified distances sdist is not verified, the SR telemetry step is stopped. If consistency is verified, the SR telemetry step continues with the Everif verification step.
[0170] The Everif verification step consists of comparing the certified sdist distance with a dauth authorization distance. More precisely, it consists of verifying whether the certified sdist distance is included in the dauth authorization distance, that is, whether it is less than or equal to the latter.
[0171] In a first embodiment, the equipment 1, RI in charge of the EC calculation step is also the one in charge of the Everif verification step.
[0172] Preferably, with reference to [Fig.3], it is the secure access control reader RI that is responsible for implementing the EC calculation and Everif verification steps.
[0173] In a second embodiment, one of the two devices 1, RI, between the connected mobile terminal 1 and the secure access control reader RI, is in charge of the EC calculation step, while the other is in charge of the Everif verification step. Thus, once one of the two devices 1, RI has calculated the certified distance sdist, it must transmit it to the other device 1, RI so that it can be checked / verified.
[0174] Comparing the certified distance sdist to the authorization distance dauth makes it possible to determine whether user U is near or not the secure access control reader RI, this proximity reflecting a desire of user U to access the secure space SI.
[0175] If the certified distance sdist is greater than the authorization distance dauth, the access control process 100 stops. If the certified distance sdist is less than or equal to the authorization distance, the SR telemetry step ends and the secure access control process 100 continues.
[0176] In one embodiment of the invention, the dauth authorization distance is less than or equal to 1 m.
[0177] In various embodiments of the invention, the secure telemetry step SR may not be limited to the exchanges and principles described. Further information on secure telemetry is available in the two references indicated in the Prior Art.
[0178] At the end of the secure telemetry step SR, if the certified distance is valid, the user identification data udata is transmitted to the access control unit 2. According to two different embodiments, the transmission is ensured either by the secure access control reader, or by the connected mobile terminal according to which equipment 1, RI has network access to be able to communicate with the access control unit 2.
[0179] In one embodiment of the invention, the equipment 1, RI having carried out the Everif verification step of the certified distance sdist is the one in charge of transmitting the user identification data udata to the access control unit 2. In the embodiment illustrated [Fig.3], it is therefore the secure access control reader RI which implements a transmission step E3 of the user identification data udata.
[0180] Advantageously, the implementation of the EC calculation, Everif verification, and E3 transmission steps by the RI secure access control reader makes it possible to significantly strengthen the security level of the secure access control process 100 since, by definition, the RI secure access control reader is a trust system designed and conformed to be an integral part of an access control installation implementing secure access control processes.
[0181] In two embodiments, the secure access control reader RI is directly linked to the access control unit 2: either by being physically connected to it (for example, by means of Ethernet links, or an RS485 interface), or by being in direct communication with it via a wireless communication protocol (see [Fig. 5]-a) operating in a frequency band within or outside the Ultra Wideband range. For example, the RI secure access control reader is directly linked to the access control unit and can communicate via Wi-Fi®.
[0182] In a third embodiment of the invention, the secure access control reader RI and the access control unit 2 are part of a mesh network comprising several other secure access control readers. In the illustrated example [Fig. 1], the other secure access control reader R2 is also part of this mesh network. Each of the devices RI, R2, and 2 in the mesh network is capable of communicating with its nearest neighbor(s) according to a peer-to-peer communication protocol, for example, Bluetooth Mesh®.
[0183] Advantageously, the mesh network addresses the problem of indoor network coverage, where the building structure and the materials used for its construction interfere with signal transmission and prevent two devices from communicating properly even though they are within communication range of each other.
[0184] In the illustrated example [Fig.5]-b, the secure access control reader RI transmits the user identification data udata to the other secure access control reader R2; which other secure access control reader R2 then relays them to the access control unit 2.
[0185] It is also possible that the device 1, RI that performed the Everif verification step is not the one that will transmit the user identification data udata to the access control unit 2. Possibly, the device 1, RI responsible for verifying the certified distance sdist, if validated, can transmit a Goto authorization signal to the other device 1, RI; the other device 1, RI then transmitting the user identification data to the access control unit 2 once the Goto authorization signal is received. This application context will be illustrated below.
[0186] In the event that the secure access control reader RI has to transmit the user identification data udata to the access control unit 2 (directly, or indirectly via hop-by-hop communication), it is necessary that the connected mobile terminal 1 has previously transmitted the said user identification data udata to it.
[0187] The user identification data udata is transmitted by the connected mobile terminal 1 to the secure access control reader RI during a transmission step provided for in the Ultra Wideband communication mode.
[0188] Thus, the implementation of the transmission step implies, on the one hand, that the connected mobile terminal 1 is within communication range of the secure access control reader RI in Ultra Wideband communication mode; and on the other that the Ultra Wideband U1 transceiver of the connected mobile terminal 1 is in the awake state to be able to transmit the user identification data udata to the secure access control reader RI.
[0189] The secure access control method 100 provides, in different embodiment variants, that the transmission step can be carried out before, during, or after the secure telemetry step SR.
[0190] It is conceivable that the transmission step, in the case where it is planned before the secure telemetry SR step, is implemented at the ulock unlocking step to unlock the connected mobile terminal 1.
[0191] In the case where it is planned that the transmission step takes place following the secure SR telemetry step and before the CS access control step, it is conceivable that said transmission step may be implemented on the condition that it has been verified that the certified distance sdist is less than or equal to the dauth authorization distance.
[0192] With reference to [Fig.3] and in the following description, for the embodiments of the secure access control method 100 illustrated, it is considered that when the access control unit 2 receives the user identification data udata from the secure access control reader RI, the step of transmitting this data from the connected mobile terminal 1 to the secure access control reader RI takes place during the secure telemetry step SR, during the transmission step ESR2.
[0193] With reference to [Fig. 3], following the receipt of the user's identification data udata during a reception step E3', the access control unit 2 is configured to implement an access control step CS during which it verifies at least the user's identification data udata to determine whether the user U has the necessary credentials to access the secure area SI protected by the access control bay DI. If not, access to the secure area SI is denied to the user.
[0194] Once at least the user udata identification data has been validated, the access control unit 2 unlocks the DI access control bay locking / unlocking system to allow user U to enter the secure SL space
[0195] According to different embodiments of the invention, the locking / unlocking system of the access control bay Dl, which may for example correspond to a strike plate opening and closing, can either be physically connected by a cable to the access control unit 2, or be linked to the access control unit 2 through a wireless link.
[0196] A second embodiment of the secure access control method is illustrated [Fig. 6]. Compared to the first embodiment described and illustrated [Fig. 3], the connected mobile terminal 1 is configured to transmit itself to the control unit access 2 the user identification data udata during a transmission step E4, which central following their reception during a reception step E4' implements the access control step CS.
[0197] To implement the transmission step E4, the connected mobile terminal 1 must have an add-c connection address enabling it to connect to and communicate with the access control unit 2.
[0198] In a first embodiment, the add-c connection address is already contained in the connected mobile terminal 1, having been previously loaded into it before the implementation of the secure access control process 100.
[0199] In a second embodiment, the add-c connection address is transmitted to the connected mobile terminal 1 by the secure access control reader RI during the secure telemetry step SR. By way of exception, the add-c connection address may: - either transmitted during at least one bidirectional exchange between the secure access control reader RI and the connected mobile terminal 1 that comprises the secure telemetry step SR, and which encompasses the transmission steps ESR1, ESR2 and the reception steps ESR1', ESR2'. In other words, the connection address add-c is transmitted with the security data sdatal during the transmission step ESR1; or - either transmitted by the secure access control reader RI during a transmission step taking place during the secure telemetry step SR and independent of the at least one exchange mentioned above.
[0200] It is also conceivable, with reference to [Fig.6], in the case where the access control reader implements the EC calculation and sdist certified distance verification steps, that it transmits to the connected mobile terminal 1, during an ESR3 transmission step included in the secure telemetry step SR and which takes place after the Everif verification step, the add-c connection address simultaneously with the previously defined Goto authorization signal and which aims to indicate to the connected mobile terminal 1 that it can transmit the user identification data udata to the access control unit 2.
[0201] With reference to [Fig.6] and 7, following the receipt of the add-c connection address and the Goto authorization signal during an ESR3' reception step, the connected mobile terminal 1 connects to the access control center 2 and implements the E4 transmission step.
[0202] In the following description, it is considered for all embodiments subsequently illustrated by a flow diagram that the secure access control reader RI: initiates the secure telemetry step SR, implements the calculation EC and verification Everif steps, and transmits the udata user identification data to the access control center 2 (during transmission step E3).
[0203] For the two embodiments presented above, the implementation of the secure telemetry step SR requires that the Ultra Wideband transceivers Ul, UR1 of the connected mobile terminal are both awake, and that the user U unlocks his connected mobile terminal 1 during the unlocking step ulock.
[0204] In other embodiments of the secure access control method 100, it is conceivable that the implementation of the secure telemetry step SR depends in addition on at least one opt, inc validation action carried out by the user U on his connected mobile terminal 1 just after unlocking it.
[0205] The at least one opt, inc validation action is an additional security / condition in the implementation of the secure access control process 100 to ensure that the user U of the connected mobile terminal 1 has the concrete intention of accessing the secure space SI protected by the access control bay DI associated with the secure access control reader RI.
[0206] The at least one opt, inc validation action thus avoids implementing the secure telemetry step SR, and subsequently the access control step CS in the case where the user U has unlocked his connected mobile terminal 1 near the secure access control reader RI when he does not intend to access the secure space SL. Other advantages are: reducing the power consumption of the secure access control reader RI and the connected mobile terminal 1 in Ultra Broadband communication mode, and not unnecessarily stressing the access control unit 2.
[0207] With reference to [Fig. 8], at least one opt, inc validation action may take the form of an opt launch operation performed in a launch menu displayed by a mobile launch application 1-app, loaded into the connected mobile terminal 1. Without limitation, the opt launch operation may consist of: - an operation to enter a launch code on the launch menu; - a touch input operation of a launch pattern on the launch menu; - a validation operation on the launch menu.
[0208] In one embodiment of the invention, it is conceivable that the launch mobile application 1-app opens automatically and displays the launch menu following at least the unlocking of the connected mobile terminal 1. Optionally, in another embodiment, the launch mobile application 1-app can open automatically and display the launch menu following the unlocking of the connected mobile terminal 1 and after the latter receives the sscan probe signal.
[0209] With reference to [Fig. 9], at least one validation action ulock, opt, inc can also correspond to an inclination inc of the connected mobile terminal 1. It consists of measuring an inclination angle tetal, theta2 of the connected mobile terminal 1, which is then compared to a predefined launch angular range. If the inclination angle tetal, theta2 is within the launch angular range, then the inclination is considered valid for the subsequent implementation of the secure telemetry step SR. The launch angular range corresponds to an orientation of the connected mobile terminal 1 with respect to the secure access control reader RI, or to the ground, such that: - the front face Fl of the connected mobile terminal 1 faces or is very much facing the user U; - the rear face F2 of the connected mobile terminal 1 faces or is substantially facing the secure access control reader RI.
[0210] In a first embodiment illustrated in [Fig.9] (a), the tilt inc consists of a measurement of a tilt angle tetal by the secure access control reader RI from reception signals of an Ultra Wideband wave from the connected mobile terminal, for example during a bidirectional UWB1 data exchange taking place when the Ultra Wideband transceivers Ul, UR1 of the connected mobile terminal and the secure access control reader RI are both awake; which tilt angle is then compared to the launch angular interval.
[0211] In a second embodiment illustrated in [Fig.9] (b), the inclination inc consists of a measurement of an inclination angle theta2 of the connected mobile terminal 1 with respect to the ground by an inertial measurement unit included in the connected mobile terminal 1.
[0212] According to several possibilities: - The equipment 1, RI, between the connected mobile terminal 1 and the secure access control reader RI, which measures and validates the tilt angle tetal, teta2, is the same as the one that initiates the secure telemetry step SR. If it is the connected mobile terminal 1, then it is possible that it could initiate the secure telemetry step SR following validation of the tilt angle inc. If it is the secure access control reader RI, it is possible, for example, that the secure access control reader RI could implement the secure telemetry step SR: following receipt of the ACK confirmation signal (sent by the unlocked connected mobile terminal 1 once it has received the sscan probe signal); and validation of the tilt angle inc;
[0213] - either equipment 1, RI among the connected mobile terminal 1 and the reader of RI secure access control which handles the measurement of the tetal inclination angle, teta2 is not the same as the one that validates it, in which case there is transmission of the angle of inclination tetal, teta2 of said equipment 1, RI to the other equipment 1, Ri;
[0214] - either equipment 1, RI among the connected mobile terminal 1 and the reader of The secure access control (RI) device that performs the tilt validation is not the same one that initiates the secure telemetry step. If the device 1, which validated the tilt, is the secure access control (RI) reader, then it may send a validation signal to the connected mobile terminal 1, which, upon receiving this signal, initiates the secure telemetry step. If the device 1, which validated the tilt, is the connected mobile terminal 1, then, as shown in [Fig. 10], it may send the confirmation signal to the secure access control (RI) reader only after the tilt validation.
[0215] According to different embodiments of the secure access control process 100, the at least one opt, inc validation action may include several opt, inc validation actions performed prior to the secure SR telemetry step. It is possible that these several opt, inc validation actions may be performed successively or not.
[0216] In a particular embodiment of the invention in which the secure telemetry step is initiated by the secure access control reader, it is possible for the connected mobile terminal 1 to transmit the ack confirmation signal to it, provided that the user, once their connected mobile terminal 1 is unlocked: - tilts its connected mobile terminal 1 according to a tilt angle tetal, teta2 conforming in order to validate the tilt inc; - performs an opt launch operation on the launch mobile application 1-app, which launch mobile application 1-app is displayed on the touchscreen of the connected mobile terminal 1 following validation of the inc tilt (in other words, the launch mobile application 1-app is not displayed if the inc tilt is not valid). Optionally, in an alternative embodiment, the launch menu is displayed on the condition that: the connected mobile terminal 1 has received the sscan probe signal, and that the inc tilt is valid.
[0217] Up to this point, it has been assumed that the UR1 Ultra Wideband transceiver of the RI secure access control reader was in the awake state at the start of the 100 secure access control process. In different embodiments, the RI access control reader is configured to be in the standby state at the start of the 100 secure access control process. In order for the secure telemetry step to be implemented, it is necessary that the Ultra transceiver The UR1 broadband of the RI secure access control reader switches from sleep to wake state during a WP-R wake-up step.
[0218] The WP-R wake-up step occurs following detection by at least one sensRl sensor of a prox approach or a tou contact of the user U or the mobile terminal connected 1 with the secure access control reader RL
[0219] Thus, in a first variant, with reference to [Fig. 2] and [Fig. 11], the wake-up step WP-R occurs upon detection of contact between the user U and the secure access control reader 1 by at least one sensRl sensor located on a part of the secure access control reader RL. This contact may, but is not limited to, correspond to: - a contact of a hand of the user U on a part of the secure access control reader RI, detected for example by means of electrostatic sensors (inductive sensor or capacitive sensor); - pressing a key or button that includes the RI secure access control reader on its casing or on a touchpad.
[0220] In a second variant, with reference to [Fig. 12], the wake-up step WP-R occurs following detection by at least one sensRl sensor of the proximity of user U or the connected mobile terminal 1 with a part of the secure access control reader RI within a given activation distance d-act relative to the secure access control reader RL. In this second variant, the at least one sensRl sensor is selected from a capacitive sensor, an inductive sensor, a radar sensor, an ultrasonic sensor, an optical sensor, or a vibration sensor. Thus, the detection of the proximity of user U may, but is not limited to: - detection of the movements of user U or the connected mobile terminal 1 by a motion sensor (for example, a passive infrared motion sensor or other optical sensor); - vibrations caused by the user's steps on the ground, which are detected by an accelerometer; - detection by a microphone of the noises caused by the footsteps of user U on the ground.
[0221] In one embodiment, the activation distance d-act from which the secure access control reader RI is able to detect an approach of the user U or his connected mobile terminal 1 is equal to the authorization distance dauth.
[0222] In another variant, the d-act activation distance is defined as being substantially equal to the dauth authorization distance, for example the activation distance is equal to 1.25 times the dauth authorization distance.
[0223] In this second variant, at least one sensor sensR1, sensR2 used to detect an approach by the user U or their connected mobile terminal 1 can be integrated into the secure access control reader RI, R2 or located remotely from it. For example, the remote sensor can be contained in a housing that also includes a push button that the user U presses, which housing is fixed to a wall in the space where the secure access control reader RI, R2 is located and: either is physically connected to the secure access control reader RI, R2 by a cable; or communicates with it by means of a wireless communication protocol (for example, Bluetooth Low Energy BLE®).
[0224] In one embodiment of the invention, it is conceivable that the secure access control readers RI, R2 incorporate a light-emitting diode such that it lights up when their Ultra Wideband transceiver UR1, UR2 is woken up, and is not lit when it is in standby mode, so as to signal / inform the user U of the state of the Ultra Wideband transceiver UR1, UR2 of the secure access control reader RI, R2; also indicating to him whether after approaching or touching the secure access control reader RI, R2, the wake-up step WP-R has taken place properly.
[0225] With reference to [Fig. 1], in a first operating configuration in which the connected mobile terminal 1 initiates the secure telemetry SR step, the wake-up step WP-R is carried out before the unlocking step ulock, so that the connected mobile terminal 1, once unlocked, can transmit in Ultra Wideband communication mode to the secure access control reader RI the user identification data udata.
[0226] In a second operating configuration in which the secure access control reader RI initiates the secure telemetry step SR, the wake-up step WP-R can be performed before or after the ulock unlock step if the Ultra Wideband transceiver U1 of the connected mobile terminal 1 is in the awake state at the start of the secure access control process 100. If, on the other hand, the Ultra Wideband transceiver U1 of the connected mobile terminal 1 is in the sleep state, or even off, at the start of the secure access control process 100 and is configured to switch to the awake state following the ulock unlock step, then, as illustrated [Fig.13], the ulock unlock step must be performed before the wake-up step WP-R.
[0227] Advantageously, implementing the WP-R wake-up step reduces the power consumption of the U1 Ultra Wideband transceiver of the RI secure access control reader, since it is only woken up during the implementation of the 100 secure access control process (i.e., for the implementation of the SR secure telemetry step, and possibly depending on of the embodiment considered the implementation of the transmission step E3). In particular, the wake-up step WP-R can prevent periodic emission of the sscan probe signal if no connected mobile terminal 1 is within communication range of the secure access control reader RI.
[0228] Furthermore, the detection of the proximity approach of user U (or his connected mobile terminal 1) or of his contact with the secure access control reader RI, combined with the unlocking of the connected mobile terminal 1, tends to confirm / validate the intention of user U to access the secure space SI.
[0229] In one embodiment of the invention, the secure access control reader RI is configured to switch its Ultra Wide Band transceiver UR1 into the standby state after a period of activity which is established according to the time required to implement all the steps of the secure access control process 100.
[0230] In another embodiment, the access control unit 2, following the implementation of the access control step CS, transmits a standby signal to the secure access control reader RI. Once this standby signal is received, the Ultra Wideband transceiver UR1 of the secure access control reader RI switches from the awake state to the standby state.
[0231] Figure 14 illustrates an operating diagram for an alternative embodiment of the invention in which the Ultra Wideband transceivers Ul, UR1 of the connected mobile terminal 1 and of the secure access control reader RI are both in the standby state. It should be specified that this embodiment is only possible if the Ultra Wideband transceiver Ul of the connected mobile terminal 1 is in the standby state, and not in the switched-off state.
[0232] In this embodiment, it is considered that the ulock unlocking step of the connected mobile terminal 1 does not cause its Ultra Wideband UL transceiver to wake up. The implementation of the wake-up step WP-T of the Ultra Wideband Ul transceiver of the connected mobile terminal 1 following the reception by the connected mobile terminal 1, during a reception step EW', of a wake-up signal ws transmitted by the secure access control reader RI in the Ultra Wideband communication mode during a transmission step EW (hence the need for the Ultra Wideband Ul transceiver of the connected mobile terminal 1 to be in the standby state, and not switched off, to be able to receive this wake-up signal ws).The EW transmission state occurs following the awakening of the RI Ultra Wideband transceiver of the RI secure access control reader during the WP-R wake-up stage, following the detection by the RI secure access control reader of the proximity approach of user U or their connected mobile terminal 1, or the detection of contact with them.
[0233] When the connected mobile terminal 1 is configured to implement the secure telemetry step SR, after the wake-up step WP-R has occurred, and thus the wake-up signal reception step EW' of the ws wake-up signal has taken place, the user unlocks their connected mobile terminal 1. In other words, the unlock step ulock is performed following the wake-up steps WP-R and WP-T. Once the connected mobile terminal 1 is unlocked, it proceeds to the secure telemetry step SR.
[0234] With reference to [Fig. 14], when the secure access control reader RI is configured to implement the secure telemetry step SR, it subsequently transmits the wake-up signal ws after receiving the scan signal sscan during the transmit step El. As before, after waking up the secure access control reader RI, the user U proceeds to the unlock step ulock. In [Fig. 14], the unlock step ulock occurs after the receive step El', but it can optionally be performed before the transmit step El. Indeed, once the conditions for receiving the scan scan signal and unlocking are met, the connected mobile terminal 1 transmits the confirmation signal ack to the secure access control reader RI so that it can implement the secure telemetry step SR.
[0235] Note that in one embodiment it is conceivable that the sounding signal is transmitted simultaneously with the wake-up signal ws.
[0236] Alternatively, in another variant, the transmission of the sscan probe signal may not be implemented. Indeed, following the awakening of the Ultra Wideband transmitter U1 of the connected mobile terminal 1 by the secure access control reader RI by means of the wake-up signal ws, the confirmation signal ack would be generated by unlocking the connected mobile terminal 1.
[0237] The various embodiments of the secure access control method 100 described so far can be implemented for any secure access control reader RI, R2 included in a building.
[0238] However, when secure access control readers have network access and can communicate with the access control unit 2, once user U has authenticated itself once with a secure access control reader as previously described, its authentication after another secure access control reader can be accelerated by means of an access cookie (or "cookie" in English).
[0239] With reference to [Fig. 15] and [Fig. 16], it is assumed that user U, after authenticating with the secure access control reader RI and accessing the secure space SI, also wishes to access the other secure space R2 protected by the other access control bay D2, which is associated with the other secure access control reader R2; and that authentication with the other secure space R2 is carried out at access witness means. It is considered that the sequence of all the steps from the start of the secure access control process 100 to the access control step CS is similar to that illustrated [Fig.3].
[0240] The access witness coo is generated during a generation step EG which takes place following the access control step CS in the case where the access control center 2 has authorized a first access to the user U (in the illustrated example, to the secure space SI).
[0241] In a first embodiment, the coo access token is generated by the connected mobile terminal 1 by means of a dedicated application previously loaded inside; the generation may, for example, follow the receipt of data relating to an agreement to generate a coo access token from the access control center 2. Once the coo access token has been generated, it is stored in the connected mobile terminal 1 following an Esto storage step.
[0242] In a second embodiment, and as illustrated [Fig. 15], the generation step EG is implemented by the access control unit 2. Then, during a transmission step E5, it transmits the access token coo to the secure access control reader RI, which corresponds to the access control reader that participated in the secure telemetry step SR (the transmission being by direct communication or by hop-by-hop communication). Following the reception of the access token coo during a reception step E5', the secure access control reader RI transmits the access token during a transmission step E6 to the connected mobile terminal 1, which, following a reception step E6' of said access token coo, proceeds to the storage step Esto.
[0243] When the user is near the other secure access control reader R2, an access control phase CP begins. During this phase, the user U makes an access request using their connected mobile terminal 1, which is detected by said connected mobile terminal 1 during an ADD detection step.
[0244] In one embodiment, the access request may correspond to at least one validation action ulock, opt, inc.
[0245] In another embodiment, with reference to [Fig. 17], the access request can correspond to a contact by the user U on his connected mobile terminal 1, such as a tap; the contact being detected by a sensor included in the connected mobile terminal 1 (such as, for example, a mechanical sensor, a capacitive sensor, an inductive sensor, an accelerometer or an inertial measurement unit).
[0246] Following the ADD detection step, the connected mobile terminal 1 transmits during a transmission step E7 the coo access indicator to the other secure access control reader R2.
[0247] Once the coo access indicator is received during a reception step E7', the other secure access control reader R2 transmits the coo access indicator to the access control unit 2 during an E8 transmission step (by direct communication or step-by-step communication).
[0248] Following the receipt of the access indicator coo during a reception step E8', the access control unit implements an access control step CS2 during which it checks the access indicator coo and then authorizes access to the other secure space S2 to the user U, by unlocking for this purpose the locking / unlocking system of the other access control bay D2.
[0249] Advantageously, access control 2 authorized access to the other secure space S2 on simple verification of the access indicator coo, therefore without having to carry out a new check of the user identification data udata.
[0250] In one embodiment of the invention, the access token coo is generated based on the user's identification data. Indeed, another user U may have the right to access the secure space SI, but not other secure spaces S2. In other words, the access token only allows user U to facilitate their authentication to access the secure spaces for which they have the necessary credentials.
[0251] In one embodiment of the invention, the access token coo has a limited validity period. In other words, once the validity period has expired, the access token coo expires. If this is the case, the authentication of user U with the access control unit 2 to access a secure area then consists of implementing again, at a minimum, the wake-up step WP-R of a secure access control reader, the secure telemetry step SR, and the access control step CS (with control by the access control unit 2 of at least the user identification data udata).
Claims
1. Demands A secure access control method (100) for controlling and authorizing access by a user (U) to at least one secure space accessible (SI, S2) by at least one access control bay (D1, D2) equipped with a locking / unlocking system, the secure access control method (100) involving several pieces of equipment (1, RI, R2, 2) including: - a connected mobile terminal (1) carried by the user (U) and containing user identification data (udata), said connected mobile terminal (1) comprising at least one Ultra Wideband transceiver (Ul) which, at the start of the secure access control process (100), is in an off state for which it is configured not to transmit and not to receive in an Ultra Wideband communication mode, - at least one secure access control reader (RI, R2) associated with at least one access control bay (Dl, D2) and comprising at least one Ultra Wideband transceiver (UR1, UR2), - an access control unit (2) which is at least in communication with the access control reader (RI, R2) and which is linked to the locking / unlocking system of at least one access control bay (Dl, D2); in which the secure access control process (100) includes at least: - an unlocking step (ulock) of the connected mobile terminal (1), changing said connected mobile terminal from a locked state to an unlocked state; - a wake-up step (WP-1) of the Ultra Wideband (Ul) transceiver of the connected mobile terminal (1), implemented on condition that at least the unlocking step (ulock) has been carried out, and during which the Ultra Wideband (Ul) transceiver of the connected mobile terminal (1) switches from the off state to a woke state in which it is configured to transmit and receive in Ultra Wideband communication mode; - a secure telemetry (SR) step between the secure access control reader (RI, R2) and the connected mobile terminal (1), during which their Ultra Wideband transceivers (Ul, UR1, UR2) exchange data in Ultra Wideband communication mode at least security data (sdatal, sdata2), and at the end of which a certified distance (sdist) is established and then verified between the secure access control reader (RI, R2) and the connected mobile terminal (1); said secure telemetry step (SR) being initiated on the condition at least that the unlocking step (ulock) has been previously implemented; - an access control step (CS) during which the access control unit (2), after receiving the user identification data (udata), verifies this data to authorize or not access to the secure space (SI, S2) accessible by the access control bay (Dl, D2) and, if necessary, commands the locking / unlocking system of said access control bay (Dl, D2).
2. A secure access control method (100) according to claim 1, wherein the access control unit (2) receives the user identification data (udata) provided that prior to, during the secure telemetry (SR) step, it has been verified that the certified distance (sdist) is less than or equal to an authorization distance (dauth).
3. A secure access control method (100) according to claim 1 or 2, wherein during the secure telemetry (SR) step, the certified distance (sdist) between the connected mobile terminal (1) and the secure access control reader (RI, R2): - is established by being calculated by at least one of the connected mobile terminal (1) and the secure access control reader (RI, R2); and - verified either by the connected mobile terminal (1) or by the secure access control reader (RI, R2).
4. A secure access control method (100) according to any one of claims 1 to 3, wherein the unlocking step (ulock) of the connected mobile terminal (1) is implemented by the user (U) by means of at least one of the following operations: - turning on a touchscreen included in the connected mobile terminal (1) by pressing it, or on a power button also included in the connected mobile terminal (1); - entering an unlock code on the connected mobile terminal (1); - entering an unlock pattern by touch on a touchscreen of the connected mobile terminal (1); - a fingerprint recognition operation on a fingerprint sensor of the connected mobile terminal (1); - a facial recognition operation of the user using a camera integrated into the connected mobile terminal (1).
5. A secure access control method (100) according to any one of claims 1 to 4, wherein the access control unit (2) receives the user identification data (udata) from: - either the connected mobile terminal (1), which connected mobile terminal (1) having network access and containing a connection address (add-c) to remotely connect to the access control unit (2) and communicate with it; - or the secure access control reader (RI, R2), which secure access control reader (RI, R2) having network access to communicate with the access control unit (2), via direct communication or via hop-by-hop communication.
6. Secure access control method (100) according to claim 5, wherein, when the access control unit (2) receives the user identification data (udata) from the secure access control reader (RI, R2), the secure access control method (100) also includes, prior to the access control step (CS), a transmission step during which the connected mobile terminal (1) transmits, in Ultra Broadband communication mode, the user identification data (udata) to the secure access control reader (RI, R2); said transmission step being implemented: - following the unlocking step (ulock) and before the start of the secure telemetry step (SR), or - during the secure telemetry step (SR), or - after the secure telemetry step (SR) has been completed.
7. A secure access control method (100) according to any one of the preceding claims, wherein the secure access control reader (RI, R2) periodically emits a scanning signal (sscan), and wherein the telemetry step (SR) is implemented by the secure access control reader (RI, R2) upon receipt of an acknowledgment signal (ack) from the connected mobile terminal (1); said acknowledgment signal (ack) being generated and then transmitted by the connected mobile terminal (1) under the condition that at least: the unlocking step (ulock) is implemented, and then the connected mobile terminal (1) has received the probing signal (sscan) once in the unlocked state.
8. A secure access control method according to any one of claims 1 to 6, wherein the telemetry step (SR) is implemented by the connected mobile terminal (1) when at least: it is in the unlocked state following the unlocking step (ulock), and is within Ultra Wideband communication range with the secure access control reader (RI, R2).
9. A secure access control method (100) according to any one of the preceding claims, wherein the secure telemetry (SR) step is initiated on the condition at least that: the unlocking step (ulock) is implemented, and that at least one validation action (actl, act2) is also subsequently performed on the connected mobile terminal (1); otherwise the secure telemetry (SR) step is not performed.
10. Secure access control method (100) according to claim 9, wherein at least one validation action (act1, act2) comprises at least one launch operation (opt) performed in a launch menu displayed by a mobile launch application (1-app), loaded in the connected mobile terminal (1).
11. A secure access control method (100) according to claim 10, wherein the launch operation (opt) consists of at least one of the following operations: - an operation of entering a launch code on the launch menu; - an operation of entering a launch pattern by touch on the launch menu; - a validation operation on the launch menu.
12. A secure access control method (100) according to claims 9 and 10, wherein the launch mobile application (1-app) opens automatically and displays the launch menu following the unlock step (ulock).
13. A secure access control method (100) according to any one of claims 9 to 12, wherein at least one validation action (act1, act2) includes at least one tilt (inc) of the connected mobile terminal (1) through a tilt angle (tetal, teta2) within a predefined launch angular range.
14. A secure access control method (100) according to claims 10 and 13, wherein the launch mobile application (1-app) opens and displays the launch menu on the condition that the tilt angle (tetal, theta2) is within the predefined launch angular range.
15. A method of secure access control (100) according to claim 13 or 14, wherein the tilt angle (tetal) is measured by an inertial unit integrated into the connected mobile terminal (1).
16. A secure access control method (100) according to claim 13 or 14, wherein the tilt angle (teta2) is measured by the secure access control reader (RI, R2), from received signals of an Ultra Wideband wave from the connected mobile terminal (1).
17. A secure access control method (100) according to any one of the preceding claims, wherein, upon startup, the Ultra Wideband transceiver (UR1, UR2) of the secure access control reader (RI, R2) is in a standby state, capable only of receiving in Ultra Wideband, and wherein, prior to the secure telemetry step (SR), a wake-up step (WP-R) of the secure access control reader (RI, R2) is implemented, initiated by detection by at least one sensor (sensR1, sensR2) of an approach or contact by the user (U) or the mobile terminal connected (1) to said secure access control reader (RI, R2), and followed by a wake-up of the Ultra Wideband transceiver (UR1, UR2) of said secure access control reader (RI, R2) to enable it to transmit and receive in Ultra Wideband communication mode and thus allow the activation of the secure access control system. work of the secure telemetry (SR) stage;and so that in the absence of said wake-up step (WP-R), the secure telemetry step (SR) is not implemented.
18. A secure access control method (100) according to claim 17, wherein, during the wake-up step (WP-R), the approach or contact detection consists of detecting user contact (U) by at least one sensor (sensR1, sensR2) disposed on a part of the secure access control reader (1).
19. A secure access control method (100) according to claim 18, wherein at least one sensor (sensR1, sensR2) is selected from a touch, a mechanical sensor, a capacitive sensor, and an inductive sensor.
20. A secure access control method (100) according to claim 17, wherein, during the wake-up step (WP-R), the approach or contact detection consists of a detection by at least one sensor (sensR1, sensR2) of the approach of the user (U) or the connected mobile terminal (1) with a part of the secure access control reader (RI, R2) within a given activation distance (d-act) relative to the secure access control reader (RI, R2).
21. A secure access control method (100) according to claim 20, wherein at least one sensor (sensR1, sensR2) is selected from a capacitive sensor, an inductive sensor, a radar sensor, an ultrasonic sensor, an optical sensor, a vibration sensor.
22. A secure access control method (100) according to claim 20 or 21, wherein at least one sensor (sensR1, sensR2) is mounted on the secure access control reader (RI, R2), or is remote from the secure access control reader (RI, R2) and in connection with the secure access control reader (RI, R2).
23. Access control method (100) according to claim 9, wherein the wake-up step (WP-1) of the Ultra Wideband (Ul) transceiver of the connected mobile terminal (1) is implemented on the condition that at least one validation action (actl, act2) is also performed.
24. A secure access control method (100) according to any one of the preceding claims, wherein at least one secure space (SI, S2) comprises at least one other secure space (S2) accessible by at least one other access control bay (D2) equipped with another locking / unlocking system and associated with another secure access control reader (R2) comprising an Ultra Wideband transceiver (UR2), wherein the secure access control method (100) comprises a generation step (EG) of an access token (coo) followed by a storage step (Esto) of said access token (coo) in the connected mobile terminal (1), the generation step (EG) and the storage step (Esto) being implemented when access to the secure space (SI) is authorized by the access control unit (2), and in which secure access control process (100) is implemented an access control phase (CP) to access the other secure space (S2) which includes the following steps: - a detection step (ADD) of an access request made by the user (U) on the connected mobile terminal (1); - a transmission step (E7) during which the connected mobile terminal (1) transmits, in Ultra Wideband communication mode, the access indicator (coo) to the other secure access control reader (R2) in response to the detection of the access request; - a reception step (E7') during which the Ultra Wideband transceiver (UR2) of the other secure access control reader (R2) receives the access indicator (coo); - a transmission step (E8) during which the other secure access control reader (R2) transmits said access indicator (coo) to the access control unit;- an access control step (CS2) during which the access control unit (2), after receiving the access indicator (coo), authorizes access to the other secure space (S2) accessible through the other access control bay (D2) and, if necessary, commands the other locking / unlocking system of said other access control bay (D2), without receiving or verifying the user identification data (udata) by said access control unit (2).
25. A secure access control method (100) according to claim 24, wherein the access witness (coo) has a limited validity period.
26. A secure access control method (100) according to any one of claims 2 to 25, wherein the authorization distance (dauth) is less than or equal to 1 m.