A secure access control method for authorizing access to a secure area by locating a connected mobile terminal using geolocation beacons operating in Ultra Wideband

The secure access control method using a connected mobile terminal and geolocation beacons with certified distance calculations and validation phases addresses high costs and energy consumption, enhancing security and efficiency in Ultra Wideband access control systems.

FR3151169B1Active Publication Date: 2025-12-12SYSTEMES ET TECHNOLOGIES IDENTIFICATION (STID)
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
FR2023007367
Authority / Receiving Office
FR · FR
Patent Type
Patents
Current Assignee / Owner
Filing Date
2023-07-10
Publication Date
2025-12-12
Estimated Expiration
2043-07-10

AI Technical Summary

Technical Problem

Existing secure access control methods using Ultra Wideband technology face issues such as high installation costs, energy consumption, and security vulnerabilities due to unnecessary activation and potential unauthorized access, especially when users are not intending to enter secure areas.

Method used

A secure access control method involving a connected mobile terminal with an Ultra Wideband transceiver, geolocation beacons, and an access control unit, where the scanning and geolocation phases are initiated by the mobile terminal, reducing the need for geolocation beacons near access control bays, and implementing certified distance calculations and validation phases to enhance security and reduce energy consumption.

Benefits of technology

This approach reduces installation costs, minimizes energy waste, and strengthens security by ensuring authorized access, while optimizing data exchanges and reducing power consumption in the access control system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000057_0000
    Figure 00000057_0000
  • Figure 00000057_0001
    Figure 00000057_0001
  • Figure 00000058_0000
    Figure 00000058_0000
Patent Text Reader

Abstract

The invention is a secure access control method (100) operating in Ultra Broadband for controlling and authorizing a user's access to a secure area. The method relies in particular on a geolocation (GeoP) phase during which: the position of a connected mobile terminal (1) belonging to the user is determined within the user's environment; and a target terminal, corresponding to the access control terminal to which the connected mobile terminal is physically closest, is identified from among several access control bays protecting several secure areas accessible from said environment. It is then verified whether or not the user is authorized to access the secure area protected by the target terminal. The geolocation phase relies on the processing of data from secure telemetry steps (SR1, SR2) between the connected mobile terminal and geolocation beacons (B1, B2) installed in the environment.Figure from the summary: Figure 3.
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: Secure access control method for authorizing access to a secure area by locating a connected mobile terminal using geolocation beacons operating in Ultra Broadband. Technical field

[0001] The invention relates to a secure access control method for authorizing or denying a user access to a secure space.

[0002] It relates more particularly to a secure access control method based on Ultra Wide Band radio frequency communication.

[0003] The invention finds a favorite application in the implementation of a secure access control method involving an access control unit, geolocation beacons to which a user connects by means of a connected mobile terminal; the geolocation beacons and the connected mobile terminal all operating in Ultra Wide Band radio frequency communication mode and exchanging secure data for user authentication in this same communication mode. Previous technique

[0004] As is well known in the field of access control, to authorize or deny a user access to a secure area accessible via an access control bay (door, airlock, barrier, etc.) equipped with a locking / unlocking system, there are access control solutions whereby the user can identify / authenticate themselves to an access control unit via a secure radio frequency access control reader and their mobile phone; the secure radio frequency access control reader being associated with the access control bay. Once the user has approached the secure access control reader so that it can detect the mobile phone, a so-called mutual authentication step begins during which the secure access control reader and the mobile phone exchange data, according to a secure communication protocol, in order to authenticate the user.This data can include, for example, virtual identification keys, a user ID, etc. The data is transmitted by the secure access control reader to an access control unit installed in the building and connected to the access control bay's locking / unlocking system. Upon receiving the data, the access control unit verifies it during an access control phase. Depending on the result of this verification, the... The access control unit authorizes or denies access to the secure area by controlling the locking / unlocking system of the access control bay.

[0005] Some of the available solutions propose, for example, that the secure access control reader and the mobile phone exchange data using Bluetooth® or Bluetooth® Low Energy (Bluetooth® Low Energy BLE) wireless transmission technologies.

[0006] Ultra Wideband (UWB) is a radio frequency modulation technique that is becoming increasingly widespread and is based on the transmission of pulses generally shorter than a nanosecond and used in a wide frequency band, between 3.1 GHz and 10.6 GHz. Among the advantages of Ultra Wideband communication are a very high network data transfer rate over a wide bandwidth (greater than 500 MHz) over relatively short distances and at low power. For simplicity, radio frequency systems using this modulation technique to exchange data are said to be communicating in Ultra Wideband mode.

[0007] Ultra Broadband technology being promising, it is now being considered in the design of geolocation, tracking, pairing (i.e. point-to-point data transfer), payment, and also access control solutions.

[0008] Indeed, some mobile phone models available on the market incorporate Ultra Broadband modules, enabling them to communicate and exchange information in Ultra Broadband. Therefore, secure access control readers incorporating Ultra Broadband modules are designed to implement access control solutions with a similar operating principle to that described above, whereby secure exchange takes place in Ultra Broadband communication mode.

[0009] Conventionally, when access to a secure area via an access door needs to be controlled, the access control reader is mounted on the wall near the access door. However, this type of installation requires the installation of cables and other infrastructure to connect the secure access control reader to the access door, and therefore represents a significant financial cost. Furthermore, any work to be carried out on the access door (such as repairing or replacing the existing access door with a new one) requires dismantling all or part of the infrastructure formed by the access door and the secure access control reader; dismantling this requires at least disconnecting the secure access control reader from the door. Finally, the secure access control reader may be subject to vandalism.

[0010] To address this issue, it is known from the literature that one of the secure access control methods intended for building interiors consists of locating a user's mobile phone in a first space in order to determine whether or not this user is approaching an access control bay among several access control bays giving access to a secure space from this first space.Indoor positioning is implemented using several access control readers located in the first space such that when the bearer's mobile phone is within communication range of at least one of the access control readers, the latter initiates, in Ultra Wideband communication mode, a step called secure ranging with the mobile phone in order to exchange data in a secure communication channel, and to determine a distance between the mobile phone and itself which it communicates to the access control center.Based on the distances reported by this access control reader, the access control unit then verifies, using the data, whether the user is authorized to access the secure area protected by the access control bay associated with this reader, in order to control the corresponding locking / unlocking system. Secure telemetry, operated within the framework of an Ultra Broadband exchange, enhances the security of exchanges during point-to-point data transfers by drastically limiting the risk of interception of data transfer between a sender and a receiver, i.e., "man-in-the-middle" attacks.

[0011] Detailed explanations of the operating principle of secure telemetry are given by NO Tippenhauer and S. Capkun in the technical report "UWB-based secure ranging and localization" published in 2012 (Technical Report / ETH Zurich, Department of Computer Science 586); and in the article "UWB with Puise Reordering: Secure Ranging against Relay and Physical-Layer Attacks" written by M. Singh, P. Leu, and S. Capkun and published in 2017 by the IACR (International Association for Cryptology Research - Network and Distributed Systems Security (NDSS) Symposium 2019, 24-27 February 2019, San Diego, CA, USA - ISBN 1-891562-55-X).

[0012] Document WO2022090159 proposes a secure access control method based on such a principle for Ultra Broadband technology, i.e. with access control readers and the carrier's mobile phone communicating in Ultra Broadband communication mode.

[0013] However, this secure access control method has a significant security flaw because, as indicated, the secure telemetry steps (and consequently the location of the mobile phone and the access control phase) These actions are initiated by access control readers when they detect the user's mobile phone, regardless of whether the user intends to access a secure area from the first area. Indeed, the user may simply be moving around within the first area. If the user has the appropriate permissions, the access control system can unlock the nearest access control bay. Consequently, by opening the access control bay closest to the user when they have no intention of accessing the secure area protected by it, the access control system potentially allows an unauthorized person to access that secure area.

[0014] Also, implementing such a secure access control process can lead to high installation costs. In particular, the secure access control process limits the deployment of low-cost access control readers that may have limited switching and data processing capabilities, since the access control readers must at a minimum detect the bearer's mobile phone and communicate with it, initiate and ensure the proper execution of the secure telemetry steps (in particular by calculating the distance separating them from the mobile phone), and communicate with the access control center.

[0015] This is why solutions based on such a secure access control process, including the one presented in WO2022090159, use secure access control readers which can be expensive depending on the technologies they incorporate; even if such secure access control readers are shared with several access control bays.

[0016] Furthermore, in solutions implementing this access control method using Ultra Broadband technology, the secure access control readers remain constantly activated in Ultra Broadband communication mode in order to detect the mobile phone and perform the secure telemetry step in this communication mode. Consequently, the secure access control readers consume energy unnecessarily if they do not detect any mobile phone, or if they detect a user's mobile phone and begin communicating with it when the user has no intention of entering a secure area whose access they control, or does not possess the necessary credentials. Moreover, the typical current consumption during Ultra Broadband communication, whether transmitting or receiving a signal, can vary from a few tens to over a hundred milliamperes.Thus, the Ultra Wideband communication mode is energy-intensive and can prove problematic in the case where a deployed secure access control reader is powered by a battery, as there is a risk that it will discharge after a period of activity of the secure access control reader, especially if it consumes a lot of power. the energy just to detect mobile phones without any being present or requesting access. Summary of the invention

[0017] The invention aims to address the aforementioned problems by proposing a secure access control method to control and authorize a user to access secure areas accessible via access control bays, each equipped with a locking / unlocking system. The secure access control method involves several pieces of equipment, including: - a connected mobile terminal carried by the user and containing at least user identification data, said connected mobile terminal comprising at least one Ultra Wideband transceiver, - geolocation beacons, each comprising at least one Ultra Wideband transceiver, - an access control unit which is linked to the locking / unlocking systems of the several access control bays, and in communication at least with the connected mobile terminal; the secure access control process implementing at least the following steps: - a scanning phase in which the connected mobile terminal initiates secure telemetry steps with several geolocation beacons, referred to as near-field geolocation beacons, among the geolocation beacons, said near-field geolocation beacons having their respective Ultra Broadband transceivers within a communication range of the Ultra Broadband transceiver of said connected mobile terminal, said secure telemetry steps operating in respective Ultra Broadband communication channels and at the end of which beacon data packets associated with each of the near-field geolocation beacons are determined and stored in the connected mobile terminal, where each of the beacon data packets includes at least one identifier of the associated near-field geolocation beacon, transmitted by said near-field geolocation beacon to the connected mobile terminal,and a certified distance between the connected mobile terminal and said associated proximity geolocation beacon; - a geolocation phase in which the connected mobile terminal is geolocated in a map based on said beacon data packets, which map identifying at least some of the access control bays and at least the nearby geolocation beacons among the geolocation beacons, and at the end of which a position of the connected mobile terminal is determined in the map and it is identified an access control bay, called the target bay, which is the closest to the connected mobile terminal among the access control bays present in said plan; - an access control phase implemented by the access control unit, which verifies at least the user identification data sent from the connected mobile terminal to the access control unit, to authorize or deny access to the secure space accessible by the target bay and, if necessary, control the locking / unlocking system of said target bay.

[0018] As indicated above, advantageously, the scanning phase is initiated and managed by the connected mobile terminal; that is to say, the connected mobile terminal, which is here the master, initiates the secure telemetry steps with the nearby geolocation beacons, which are the slaves, as soon as its Ultra Wideband transceiver is within communication range of the nearby geolocation beacons among the geolocation beacons that can be installed in the space, such as a building, in which the user moves.

[0019] Following the secure telemetry steps performed by the mobile terminal connected to each of the nearby geolocation beacons in Ultra Broadband communication mode, during which data is exchanged, beacon data packets relating to each of the nearby geolocation beacons are determined and stored in the connected mobile terminal. Each beacon data packet includes at least one identifier of a nearby geolocation beacon, transmitted by said nearby geolocation beacon to the connected mobile terminal, and a certified distance between the nearby geolocation beacon and the connected mobile terminal.

[0020] Following the scanning phase, the geolocation phase is implemented, during which the beacon data packets are correlated with a map locating at least some of the access control bays and at least the nearest geolocation beacons. At least some of the access control bays and geolocation beacons are identified in this map by means of a unique identifier. The use and analysis of the map and the beacon data packets make it possible to determine the position of the connected mobile terminal and the access control bay to which it is physically closest, designated as the target bay.

[0021] In one embodiment of the invention, three-dimensional Cartesian coordinates are associated with each of the access control bays and geolocation beacons contained in the plane. From the plane and the beacon data packets comprising the identifiers of nearby geolocation beacons and the distances separating them from the connected mobile terminal, it becomes possible to determine the three-dimensional Cartesian coordinates of the connected mobile terminal, then to identify the target bay.

[0022] Since locating the connected mobile terminal within a space and identifying the target bay for accessing a secure area rely on the use of a map and the analysis of beacon data packets, geolocation beacons do not need to be installed near access control bays. Furthermore, a single geolocation beacon can be used for access control to several secure areas accessible from the user's location. In other words, a single geolocation beacon can be associated with, or shared with, several access control bays. This solution therefore reduces the installation and decommissioning costs of geolocation beacons. Moreover, since they are not physically connected to the access control bays, geolocation beacons can be placed freely within the space.They can therefore be positioned high up near the ceiling, or hung from the ceiling, to significantly limit acts of vandalism against them.

[0023] The access control process is completed following the completion of the access control phase, implemented by the access control unit.

[0024] According to different embodiments of the invention, the locking / unlocking system of each of the access control bays, which may for example correspond to a strike plate opening and closing, may in one embodiment be either physically connected by a cable to the access control unit, or in another embodiment be connected to the access control unit via a wireless link.

[0025] According to a feature of the invention, during each of the secure telemetry steps carried out between the connected mobile terminal and a nearby geolocation beacon among the nearby geolocation beacons, the certified distance between the connected mobile terminal and said nearby geolocation beacon is calculated by at least one of the connected mobile terminal and said nearby geolocation beacon.

[0026] More specifically, during the secure telemetry step, a distance is calculated between the connected portable mobile terminal and the nearby geolocation beacon by at least one of these two devices, said distance being certified by nature, hence the notion of certified distance.

[0027] The distance is certified by nature because it occurs during the secure telemetry step, and because it relies on at least one bidirectional exchange of Ultra Wideband signals between two pieces of equipment (the connected mobile terminal and the nearby geolocation beacon) each having: an embedded secure component; or a trusted firmware or application loaded previously inside, or a trusted execution environment (or "Trusted Execution Environment" TEE in English).

[0028] The certified distance is an additional means of strengthening the security level of the secure access protocol when it must be verified to determine whether or not to implement the subsequent access control step. Indeed, an uncertified distance could potentially be fraudulent and originate from a malicious system seeking to gain access to the secure area protected by the access control bay. Thus, if the equipment responsible for verifying the certified distance, but not for calculating it, receives a certified distance, it implements its verification. Conversely, if the received distance is not certified, the verification is not performed and the secure access control process is stopped.

[0029] In one embodiment of the invention, only one of the two devices, the connected mobile terminal and the nearby geolocation beacon, calculates the certified distance separating the two devices.

[0030] In another embodiment of the invention, the connected mobile terminal and the nearby geolocation beacon both calculate the certified distance between them. They then exchange the certified distance value they have calculated. Each device then compares the certified distance it received with the certified distance it calculated itself. If the consistency between the certified distances is not verified, the telemetry step is stopped. If the consistency is verified, the secure access control process continues.

[0031] In one embodiment of the invention, the certified distance is calculated from a time-of-flight measurement, carried out by at least one of the two devices among the connected mobile terminal and the nearby geolocation beacon, during a bidirectional exchange of security data.

[0032] The secure telemetry step may not be limited to the exchanges described above. Further information on secure telemetry is available in the two references indicated in the Prior Art.

[0033] According to one embodiment of the invention, the access control unit contains the plan, and implements the geolocation phase after receiving at least the user identification data and the beacon data packets from the connected mobile terminal.

[0034] In a first embodiment, the geolocation phase is performed by the access control unit. Advantageously, the computing power required to perform all the processing of the geolocation phase is transferred from the geolocation beacons to the access control unit. Thus, the geolocation beacons used in the implementation of the secure access control process can just as easily be Ultra Large secure access control readers Broadband, rather than lower-cost solutions such as active tags operating in Ultra Wideband and designed to implement secure telemetry steps in conjunction with the connected mobile terminal. The secure access control method of the invention therefore positively addresses the previously mentioned installation cost issue.

[0035] As mentioned above, the beacon data packets include, in particular, a distance between the connected mobile terminal and a nearby certified geolocation beacon. The certification of this distance provides proof to the access control center that the data is secure and originates from a trusted system. This is advantageously a security measure for implementing the geolocation phase. Indeed, an uncertified distance could potentially be fraudulent and originate from a malicious system seeking to gain access to secure areas. In other words, if the distances contained in the beacon data packets are certified, the access control center implements the geolocation phase. If a distance in a beacon data packet is not certified, the access control center does not implement the geolocation phase.

[0036] Since the access control unit implements the geolocation phase and then the access control phase, it constitutes the central system of the access control process insofar as it successively performs the geolocation and access control phases. It therefore concentrates / centralizes a major part of the intelligence / computing power necessary for implementing all the phases included in the secure access control process. Consequently, and advantageously, this first embodiment makes it possible to reduce / limit the processing performed by the connected mobile terminal and nearby geolocation beacons during the scanning phase (in other words, a reduction in "edge computing").

[0037] In order for the access control unit to be able to successively implement the geolocation and access control phases, the access control process includes an intermediate step which takes place between the scanning phase and the geolocation phase, and during which the access control unit receives from the connected mobile terminal at least the user identification data and the beacon data packets.

[0038] According to one feature of the invention, the access control unit receives at least the user identification data and the beacon data packets from the connected mobile terminal: - either directly from the connected mobile terminal, which connected mobile terminal has network access and contains a connection address to connect remotely to the access control unit and communicate with it; - either indirectly through one or more geolocation beacons among the geolocation beacons, which geolocation beacons have network access to communicate with the access control center, via direct communication or via step-by-step communication.

[0039] In other words, in a given application context, if it has network access and a connection address to connect to the access control center, the connected mobile terminal can connect directly to it to transmit at least the user identification data and the beacon data packets.

[0040] In another application context, the geolocation beacons have network access, and the connected mobile terminal transmits at least the user identification data and beacon data packets to the access control center via at least one of the nearby geolocation beacons with which it is communicating. This transmission can be implemented, for example, because the connected mobile terminal does not have network access, nor does it have a connection address to the access control center.

[0041] In another embodiment associated with wireless connections, a mesh network is established between all the geolocation beacons capable of communicating, according to a hop-by-hop communication protocol, with the geolocation beacons that are in close proximity and / or the access control unit if they are within communication range. Advantageously, the mesh network addresses the problem of installing groups of geolocation beacons in several areas of the same building such that some geolocation beacons cannot communicate directly with the access control unit.It also addresses the problem of indoor network coverage, where the building structure and the materials used for its construction interfere with signal transmission, preventing two systems present in the building and yet within communication range from exchanging data (for example, two systems in the basement, or located on different floors of the building, or separated by a thick wall, etc.).

[0042] By way of exception, geolocation beacons communicate with each other and with the access control unit by being physically connected to each other (for example by means of Ethernet links), or according to a wireless communication protocol such as Wifi® or Bluetooth Mesh®.

[0043] According to another embodiment of the invention, the connected mobile terminal contains the map and implements the geolocation phase once the beacon data packets from nearby geolocation beacons are stored in the connected mobile terminal; and at the end of which at least one certified identifier of the The target bay is then transmitted to the access control center along with the user's identification data.

[0044] In this second embodiment of the invention, the geolocation phase is performed by the connected mobile terminal containing the map. The computing power is therefore decentralized from the access control unit to the connected mobile terminal, which then plays a role in both the scanning and geolocation phases. Advantageously, compared to the first embodiment, the access control unit requires less computing power because it is only used for the access control phase, checking and verifying whether the information from the connected mobile terminal is valid to authorize the user to access the secure area. It also does not have to contain the map. Consequently, its development is simplified.

[0045] In this second embodiment, the secure access control process includes, between the geolocation phase and the access control phase, an intermediate step during which the access control unit receives from the connected mobile terminal at least the user identification data and an identifier of the target bay determined by the connected mobile terminal during the geolocation phase.

[0046] Advantageously, this target bay identifier is also certified. Thus, the access control unit does not implement the access control phase if the target bay identifier it receives is not certified, strengthening / increasing the degree of security of the secure access control process.

[0047] According to one embodiment of the invention, the map loaded into the connected mobile terminal locates all access control bays and all geolocation beacons.

[0048] According to one embodiment of the invention, the map loaded into the connected mobile terminal is a local map identifying a portion of the access control bays and nearby geolocation beacons, said local map being constituted by the connected mobile terminal during a construction step from map pieces communicated to the connected mobile terminal by each of the nearby geolocation beacons during the secure telemetry steps; the map piece associated with each of the nearby geolocation beacons identifying the nearby geolocation beacon concerned and at least one access control bay in the vicinity of said nearby geolocation beacon.

[0049] According to one embodiment of the invention, the connected mobile terminal determines its position, the target bay and the target bay identifier from the plane.

[0050] In other words, in one embodiment of the invention, the plan is previously loaded into the connected mobile terminal, and identifies all the bays access control and geolocation beacons can, for example, be installed in a building.

[0051] In another embodiment of the invention, the connected mobile terminal, at the start of the secure access control process, does not contain the map. Instead, the geolocation beacons are designed and shaped to each contain a map segment representing a nearby environment. This map segment, associated with each geolocation beacon, identifies at least one access control bay in the vicinity of said geolocation beacon. In various embodiments, the map segment can also identify several access control bays in the vicinity of the geolocation beacon, and other geolocation beacons within communication range...

[0052] During the secure telemetry steps of the scanning phase, each of the nearby geolocation beacons transmits to the connected mobile terminal, in addition to its identifier, its piece of the map.

[0053] The secure access control process includes, between the scanning phase and the geolocation phase, a construction step during which the connected mobile terminal merges the plan pieces it has received to build a more complete local plan locating all the access control bays and geolocation beacons known from the plan pieces associated with the nearby geolocation beacons.

[0054] According to one embodiment of the invention, the access control unit receives at least the user identification data, the position of the connected mobile terminal, and the certified identifier of the target bay directly from the connected mobile terminal, which connected mobile terminal: - signs the target bay identifier to form the certified identifier of the target bay, and - has network access and contains a connection address to remotely connect to and communicate with the access control unit.

[0055] In other words, in one embodiment of the invention, the connected mobile terminal plays the central role in the implementation of the access control process by: initiating and intervening in the scanning phase; implementing the geolocation phase (and possibly the construction step); signing the identifier of the target bay to certify it; and then transmitting to the access control center all the information (the user identification data, the certified identifier of the target bay, the position of the connected mobile terminal) that it needs to carry out the access control phase.

[0056] According to one embodiment of the invention, the connection address (for a connection to the access control unit) corresponds to data previously loaded into the connected mobile terminal, or corresponds to data transmitted to the connected mobile terminal from one of the nearby geolocation beacons during one of the secure telemetry steps.

[0057] According to one embodiment of the invention, the connected mobile terminal transmits to a nearby geolocation beacon, referred to as the first nearby geolocation beacon, at least the user identification data, the position of the connected mobile terminal and the identifier of the target bay, which first nearby geolocation beacon timestamps the identifier of the target bay to thus form the certified identifier of the target bay and the access control center receives at least the user identification data and the certified identifier of the target bay indirectly through one or more geolocation beacons among the geolocation beacons, including at least the first nearby geolocation beacon; which geolocation beacons have network access to communicate with the access control center, via direct communication or via hop-by-hop communication.

[0058] In one embodiment of the invention, the certification of the target bay identifier and the transmission of information necessary to the access control unit for the implementation of the access control phase are managed by the geolocation beacons.

[0059] This solution is advantageous in the following situations: - The connected mobile terminal may not have network access to connect to the access control center or a connection address to connect to the access control center; - Nearby geolocation beacons may communicate during the scanning phase with a malicious system whose purpose is to transmit false data to the access control center, and thus allow an unauthorized person to access a secure area.

[0060] Indeed, the signing of the identifier of the target bay and the transmission of information to the access control center by the geolocation beacons makes it possible to significantly strengthen the level of security of the secure access control process; especially since, by definition, the geolocation beacons are trusted systems since they are designed and configured to be an integral part of an access control installation implementing secure access control processes.

[0061] More specifically, the first nearby geolocation beacon timestamps the identifier of the target bay once it receives it from the connected mobile terminal; the timestamping of the identifier of the target bay implicitly implying its signature / certification.

[0062] According to one feature of the invention, the secure access control method includes a validation phase during which: - the connected mobile terminal or one of the nearby geolocation beacons among the nearby geolocation beacons detects at least one access intent action performed by the user; - and then additional information about the intent to access is generated by the connected mobile terminal or one of the nearby geolocation beacons among the nearby geolocation beacons after detection of at least one intent to access action; and in which at least one of the geolocation and scanning phases is implemented at least on the condition of prior completion of the validation phase.

[0063] Thus, the implementation of this validation phase makes it possible to validate a concrete intention of the user to access a secure space.

[0064] During the implementation of the secure access control method, as described so far, the connected mobile terminal periodically initiates secure telemetry steps in Ultra Broadband communication mode with geolocation beacons that are close to it. Consequently, the geolocation and access control phases are also implemented at regular intervals.

[0065] In one embodiment of the invention, the geolocation phase (and therefore the subsequent access control phase) is implemented only on the condition that the validation phase has been carried out beforehand.

[0066] Advantageously, the implementation of this validation phase, when it serves as a condition for the implementation of the geolocation phase, allows: - to significantly reduce the exchanges between the different actors (the connected mobile terminal, the geolocation beacons, the access control unit) of the secure access control process, which amounts to optimizing them; - to strengthen the security of the secure access control process and the security of the exchange of data relating to the user, their connected mobile terminal, and the geolocation tags which pass between the different actors of the access control process only on the condition of the completion of the validation phase; thus reducing the risks of interception of this data by a malicious system; - to reduce the strain on the access control center by implementing only one access control phase (and only one geolocation phase if it is in charge of it).

[0067] As indicated, the validation phase consists of the detection, by the connected mobile terminal or by one of the nearby geolocation beacons among the nearby geolocation beacons, of at least one access intention action carried out by the user.

[0068] In one embodiment of the invention, the validation phase includes the detection of a single access intention action.

[0069] In other embodiments of the invention, the validation phase includes the detection of several access intention actions.

[0070] According to one embodiment of the invention, the scanning phase is carried out on the condition of the execution of at least one access intention action, so that the connected mobile terminal initiates the secure telemetry steps after a generation or reception by the connected mobile terminal of the additional access intention information.

[0071] In other words, in one embodiment of the invention, the execution of at least one access intent action detected during the validation phase serves as a condition for the implementation of the scanning phase. The connected mobile terminal therefore does not initiate the secure Ultra Broadband telemetry steps with nearby geolocation beacons until the validation phase has been completed. More precisely, the connected mobile terminal implements the secure telemetry steps: - after generating the additional access intent information after detecting at least one access intent action; or - after receiving additional access intent information from the nearby geolocation beacon that detected at least one access intent action.

[0072] Advantageously, the connected mobile terminal and nearby geolocation beacons consume less energy. Also, the connected mobile terminal and nearby geolocation beacons do not communicate unnecessarily if the user of the connected mobile terminal does not wish to access a secure area from their current location; the desire to access the area must be expressed by the user's intention to access, which triggers the validation phase.

[0073] Thus, this condition makes it possible to reduce the energy consumption of the connected mobile terminal and the geolocation beacons, by implementing the other phases of the process (scanning, geolocation, access control) even when the user of the connected mobile terminal does not wish to access a secure area. Ultimately, the reduction in energy consumption saves the battery of the connected mobile terminal, and potentially those of the geolocation beacons if they have them.

[0074] According to one embodiment of the invention, the at least one access intention action comprises a first access intention action and a second access intention action such as: - the scanning phase is implemented on the condition that the first access intent action has been carried out beforehand, and - the geolocation phase is implemented on the condition that the second action of intent to access is carried out beforehand, and following the implementation of the scanning phase; additional access intent information being generated by the mobile terminal or by one of the nearby geolocation beacons among the nearby geolocation beacons after detection of the first access intent action.

[0075] In other words, in a particular embodiment of the invention, the validation phase includes the detection of two access intention actions such that: - the scanning phase is initiated by the connected mobile terminal following the detection of the first access intention action; - the geolocation phase is initiated following the detection of the second access intention which is carried out by the user after the scanning phase.

[0076] Thus, temporally, in this particular embodiment, the validation phase takes place in two stages: before and after the scanning phase.

[0077] The additional access intention information is generated following the detection of the first access intention action, either by the connected mobile terminal or by one of the nearby geolocation beacons, according to which of the connected mobile terminal or of the nearby geolocation beacon detected said second access intention action.

[0078] In a second embodiment, the validation phase takes place temporally before the scanning phase. In other words, one or more access intention actions condition the implementation of the scanning phase.

[0079] In a third embodiment, the validation phase takes place temporally after the scanning phase. In other words, one or more access intent actions condition the implementation of the geolocation phase.

[0080] According to one embodiment of the invention, the connected mobile terminal transmits to the access control center at least the user identification data and the beacon data packets, so that said access control center can perform the geolocation phase, provided that the validation phase has been implemented beforehand.

[0081] Advantageously, and as indicated above, the validation phase allows less strain on the access control unit for the execution of the access control phase; and the geolocation phase if it is in charge of it.

[0082] According to one embodiment of the invention, the additional access intention information is transmitted to the access control unit with at least the user identification data; and during the access control phase, the access control unit also checks said additional access intention information to authorize or not access to the secure space.

[0083] According to one embodiment of the invention, the access control unit receives from the connected mobile terminal at least the beacon data packets, the additional information of intent to access and the user identification data following the completion of the validation phase.

[0084] In other words, the access control unit authorizes the user to access a secure space after verifying and validating at least the user's identification data and also the additional information of intent to access; these two data being transmitted according to different embodiments either by the connected mobile terminal, or by a nearby geolocation beacon among nearby geolocation beacons by direct or indirect communication.

[0085] For example, in the application context where the connected mobile terminal has network access and the connection address to the access control center, it can communicate to the access control center at least the user identification data and additional information on the intent to access.

[0086] In the application context where the geolocation beacons have network access, but the connected mobile terminal does not, the access control unit receives, from at least one of the nearby geolocation beacons, at least the user's identification data and additional access intent information. If the additional access intent information is generated by the connected mobile terminal, the latter transmits it to one of the nearby geolocation beacons for relay to the access control unit.

[0087] According to one embodiment of the invention, during the validation phase, at least one access intent action is detected by the connected mobile terminal and corresponds to: - a predefined impact or displacement movement of the connected mobile terminal detected by an accelerometer integrated into the connected mobile terminal; - an unlocking action by the user of the connected mobile terminal to change it from a locked state to an unlocked state; - an access validation action performed by the user of the connected mobile terminal on an access validation application loaded in the connected mobile terminal.

[0088] In other words, in different embodiments, the access intention action corresponds to an interaction of the user with his connected mobile terminal; which subsequently generates the additional access intention information.

[0089] According to different embodiments, the predefined impact or displacement movement of the connected mobile terminal may, but is not limited to: - a tap on the connected mobile terminal; - a change in the orientation of the connected mobile device. For example, an accelerometer integrated into the connected mobile device measures the angle of inclination of it in relation to the ground. The access intent action is detected if this angle of inclination is within a defined range of angles such that any angle within it corresponds to an application context where the user is using their connected mobile terminal (for example, navigating the menus of the connected mobile terminal, reading a message, etc.), with the front of the connected mobile terminal facing or substantially facing the user; - an analysis of the user's gait by an application previously loaded on the connected mobile terminal.

[0090] According to different embodiments of the invention, the action of unlocking the connected mobile terminal may correspond, but is not limited to: - a touch screen activation included in the connected mobile terminal by pressing it by the user, or on a power button also included in the connected mobile terminal; - an operation to enter an unlock code on the connected mobile terminal; - a touch-sensitive unlock pattern entry operation on a touch screen of the connected mobile terminal; - a fingerprint recognition operation on a fingerprint sensor of the connected mobile terminal; - a facial recognition operation of the user using a camera integrated into the connected mobile terminal.

[0091] According to various embodiments of the invention, the access validation action performed by the user of the mobile terminal connected to the validation application includes at least one operation performed on a launch menu of the validation application by the following: - an operation to enter a launch code; - a touch input operation of a launch pattern; - a validation operation.

[0092] According to one embodiment of the invention, the first access intention action and the second access intention action are detected by the connected mobile terminal, and such that: - the first access intent action corresponds to the unlocking action, and - the second access intention action corresponds to the access validation action.

[0093] In other words, in a particular embodiment of the invention, at the start of the secure access protocol, the user unlocks their connected mobile terminal to switch it from a locked state to an unlocked state. This unlocking action corresponds to a first access intent action that includes the validation phase. Once unlocked, the connected mobile terminal initiates the phase scanning and secure telemetry steps with nearby geolocation beacons.

[0094] The user performs a second access intent action once the scanning phase is complete. This second access intent action consists of performing a validation action on the access validation application loaded on the connected mobile terminal. The validation action causes the connected mobile terminal to generate additional access intent information and also initiates the geolocation phase.

[0095] In a variant of this particular embodiment, the access validation application runs automatically after the completion of the scanning phase, and displays, for example, the launch menu on the screen of the connected mobile terminal.

[0096] According to one embodiment of the invention, during the validation phase, at least one access intention action corresponds to a detection by at least one sensor of: - a contact of the user on a nearby geolocation beacon, called the starting nearby geolocation beacon, among the nearby geolocation beacons; or - an approach of the user or the connected mobile terminal towards a nearby geolocation beacon, called the starting nearby geolocation beacon, among the nearby geolocation beacons within a given activation distance from said starting nearby geolocation beacon.

[0097] In other words, in variants of embodiments of the invention, at least one action of intent to access an interaction of the user with one of the geolocation beacons present in the space where he is located, this beacon being called the near-start geolocation beacon.

[0098] According to one embodiment of the invention, at least one sensor is chosen from a mechanical sensor, a capacitive sensor, an inductive sensor, a radar sensor, an ultrasonic sensor, an optical sensor, a vibration sensor.

[0099] The access intent action may, but is not limited to, relate to: - contact or approach of a user's hand on a part of the casing of the near-start geolocation beacon, detected for example by means of electrostatic sensors (inductive sensor, capacitive sensor) or sound or optical sensors; - pressing a key or button that includes the near-start geolocation beacon; - detection of the user's approach by the nearby geolocation beacon which integrates: a motion sensor (for example, a passive infrared motion sensor) to detect user movements; or an accelerometer to detect vibrations caused by the user's steps on the ground; or even a microphone to detect noises caused by steps.

[0100] In other embodiments of the invention, the geolocation beacons can carry several sensors from among those mentioned above to determine, for example, a speed of movement of the user in the space where they are positioned, or a trajectory of the connected mobile terminal.

[0101] According to one embodiment of the invention, at least one sensor is mounted on the near-start geolocation beacon, or is remote from said near-start geolocation beacon and linked to it.

[0102] In other words, the sensors can be integrated into the geolocation beacons, as in the case of the examples cited above, or they can be located remotely from the geolocation beacons.

[0103] In one embodiment of the invention, the remote sensor is integrated into a housing that also includes a push button with which the user interacts; pressing the push button corresponds to the action indicating the intention to access. The housing is, for example, fixed to a wall in the area where geolocation beacons are located, including the nearest starting geolocation beacon.

[0104] According to alternative embodiments of the invention, the remote sensor is physically connected to the near-start geolocation beacon by a wire; or communicates with it by means of a wireless communication protocol (for example, Bluetooth Low Energy BLE®).

[0105] According to one embodiment of the invention, at the start of the secure access control process, the Ultra Wideband transceiver of each of the geolocation beacons is in a standby state, only able to receive in Ultra Wideband, and in which, following the detection of at least one action of intent to access by the near-start geolocation beacon, at least the Ultra Wideband transceiver of the near-start geolocation beacon switches to an awake state, able to transmit and receive in Ultra Wideband, so that the connected mobile terminal can initiate the secure telemetry step with said near-start geolocation beacon.

[0106] In one embodiment of the invention, the Ultra Wideband transceivers of the geolocation beacons are configured to remain in a standby state until they detect an access intent action, which may be the only one or one of several access intent actions performed by the user during the validation phase. In other words, the connected mobile terminal, even with its Ultra Wideband transceiver in the awake state, is unable to initiate the scanning phase and a secure telemetry step with a nearby geolocation beacon until the beacon's transceiver has switched to an awake state.

[0107] Advantageously, the validation phase allows, when at least one access intent action is detected by the geolocation tags: - to validate a user's intention to access a secure space; - to optimize the exchanges between nearby geolocation beacons and the connected mobile terminal during the entire secure access control process; - to reduce power consumption in Ultra Wideband mode of geolocation beacons; and possibly, if they are battery powered, to save on battery power.

[0108] In one embodiment of the invention, the geolocation beacons that have been used during the implementation of the secure access control process are configured to switch their Ultra Wideband transceiver from the awake state to the standby state once a period of activity has elapsed; the period of activity being established, for example, from an average duration of implementation of the secure access control process.

[0109] According to one embodiment of the invention, following the detection of at least one action of intent to access by the starting near geolocation beacon, said starting near geolocation beacon sends to each of the other near geolocation beacons among the near geolocation beacons within communication range an Ultra Wideband wake-up signal so that their respective transceiver also switches to the awake state; This is so that the connected mobile terminal can initiate the secure telemetry steps.

[0110] In other words, in connection with the previous explanations, when the near-start geolocation beacon detects at least one action of intent to access, the access control process includes a transmission step during which the near-start geolocation beacon transmits a wake-up signal in Ultra Wideband communication mode to the geolocation beacons within communication range, which switch their Ultra Wideband transceiver from the standby state to the awake state upon receipt of said wake-up signal, thus allowing the connected mobile terminal to initiate the scanning phase.

[0111] According to one embodiment of the invention, at the start of the secure access control process, the Ultra Wideband transceiver of the connected mobile terminal is in a standby state, only able to receive in Ultra Wideband, and in which at least one access intention action detected by the connected mobile terminal during the validation phase causes the Ultra Wideband transceiver of the connected mobile terminal to switch to an awake state, making it able to transmit and receive in Ultra Wideband, and consequently able to initiate the scanning phase.

[0112] Advantageously, switching the Ultra Wideband transceiver of the connected mobile terminal to the awake state following the detection of at least one access intent action, so that the connected mobile terminal can initiate the scanning phase, allows, as explained previously: - to validate a user's access intention, in order to avoid unnecessarily requesting nearby geolocation beacons to implement secure telemetry steps if the user does not wish to access a secure space; - in connection with the previous point, to optimize the exchanges between the connected mobile terminal and nearby geolocation beacons: only useful exchanges take place between the equipment for the complete implementation of the secure access control process; - to reduce the power consumption of the connected mobile terminal in Ultra Wideband communication mode by limiting it solely to the implementation of the secure access control process.

[0113] According to one embodiment of the invention, the first access intention action detected by the connected mobile terminal during the validation phase, which corresponds to the unlocking action, switches the Ultra Wideband transceiver of the connected mobile terminal into an awake state, making it capable of transmitting and receiving in Ultra Wideband, and consequently capable of initiating the scanning phase.

[0114] In other words, in the particular embodiment in which the validation phase includes the detection of the first access intent action and the second access intent action, both detected by the connected mobile terminal, If, at the start of the secure access control process, the Ultra Wideband transceiver of the connected mobile terminal is in standby mode, then the detection of the first action of intent to access, which corresponds to the unlocking of the connected mobile terminal, has the effect of waking up its Ultra Wideband transceiver.

[0115] According to one embodiment of the invention, at the start of the secure access control process, the Ultra Wideband transceiver of the connected mobile terminal is in a standby state, only able to receive in Ultra Wideband, and in which following the detection of at least one action of intent to access by the near-start geolocation beacon, said near-start geolocation beacon sends to the connected mobile terminal a wake-up signal in Ultra Wideband which, when received by the connected mobile terminal, switches the Ultra Wideband transceiver of the latter into a wake-up state, making it able to receive and transmit in Ultra Wideband, and therefore able to initiate the scanning phase.

[0116] In a given application context, for the purpose of reducing power consumption and saving battery energy on the connected mobile terminal, the Ultra Wideband transceiver of the connected mobile terminal is, at the start of the access control process, in a standby state, only capable of receiving data in Ultra Wideband communication mode (but not transmitting it). In one embodiment of the invention, at least one access intent action is detected by the near-departure geolocation beacon; said near-departure geolocation beacon sends a wake-up signal in Ultra Wideband communication mode to the connected mobile terminal.Once the connected mobile terminal receives this wake-up signal, its Ultra Wideband transceiver turns on and / or switches to the awake state, allowing it to transmit data in Ultra Wideband communication mode and thus initiate the scanning phase. Brief description of the drawings

[0117] Other features and advantages of the present invention will become apparent from the following detailed description, of a non-limiting example of implementation, made with reference to the accompanying figures in which:

[0118] [Fig-1] is a schematic view of an example of a building comprising several secure spaces: each of which is protected by an access control bay which includes a locking / unlocking system, which locking / unlocking system is controlled by an access control unit; and in which are installed geolocation beacons, which are fixed to a wall or ceiling, and which are used for geolocation and authentication of a connected mobile terminal of a user who seeks to access one of the secure spaces from the space in which he is located;

[0119] [Fig.2] is a schematic view of a bidirectional data exchange, in Ultra Broadband communication mode, between the connected mobile terminal and a geolocation beacon installed in the building;

[0120] [Fig. 3] is a diagram of the operation of a first embodiment of the invention, in which an access control unit installed in the building is configured to, on the one hand, geolocate the connected mobile terminal and identify an access control bay, referred to as the target bay, physically close to the connected mobile terminal and, on the other hand, verify whether the user has the necessary credentials to access the secure area protected by the target bay; the geolocation of the connected mobile terminal, implemented during a geolocation phase, is based on the processing of data from secure telemetry steps initiated by the connected mobile terminal with the geolocation beacons and which are carried out during a scanning phase, called nearby geolocation beacons, installed in the space in which it is located, and authentication, implemented during an access control phase based at least on a control of the user's identification data which are included in the connected mobile terminal and which are transmitted to the access control center;

[0121] [Fig.4] is a schematic view of a principle for calculating a flight time during a bidirectional data exchange between the connected mobile terminal and a geolocation beacon during a secure telemetry step implemented during the secure access control process;

[0122] [Fig.5] is an illustration related to the embodiment illustrated [Fig.3] in which the connected mobile terminal, which has network access and a connection address to connect to the access control center, transmits to the access control center, following the secure telemetry steps carried out by the connected mobile terminal with the nearby geolocation beacons, the data which allows the latter to implement the geolocation and access control phases;

[0123] [Fig.6] is a schematic view of a plan contained within the access control unit. plan locating all geolocation beacons and access control bays (here, using their three-dimensional Cartesian coordinates) and also containing their respective identifiers; the plan being used by the access control unit during the geolocation phase to determine the position of the connected mobile terminal and the target bay;

[0124] [Fig.7] is a diagram of the operation of a second embodiment corresponding to a variant of the illustrated embodiment [Fig.3], in which the connected mobile terminal does not have network access and / or the connection address to connect to the access control unit; and in which it then transmits, following the secure telemetry steps, the data necessary for the implementation of the geolocation and access control phases to one of the nearby geolocation beacons, called the first nearby geolocation beacon, which first nearby geolocation beacon is responsible for relaying the data to the access control unit;

[0125] [Fig.8] is a schematic view related to the embodiment of [Fig.7], in which the first nearby geolocation beacon transmits directly to the access control center the data necessary for the implementation of the geolocation and access control phases;

[0126] [Fig.9] is a schematic view related to the embodiment of [Fig.7], in which the first nearby geolocation beacon indirectly transmits to the access control center the data necessary for implementing the geolocation and control phases, passing through at least one other geolocation beacon according to a hop-by-hop communication protocol. nearby geolocation beacon unable in this configuration to communicate directly with the access control unit;

[0127] [Fig. 10] is an operating diagram of a third embodiment, in which the geolocation phase is implemented by the connected mobile terminal and not by the access control unit, which nevertheless remains in charge of the access control phase; this third embodiment includes at least one transmission by the connected mobile terminal to the access control unit of the data necessary for the implementation of the access control phase;

[0128] [Fig. 11] is a schematic view of the operating principle of the geolocation phase when performed by the connected mobile terminal;

[0129] [Fig. 12] is an operating diagram of a fourth embodiment in which the connected mobile terminal remains in charge of the geolocation phase but this time transmits the data necessary for the implementation of the geolocation phase to the first nearby geolocation beacon, which first nearby geolocation beacon is further configured to time-stamp part of the data and then transmit it to the access control center;

[0130] [Fig. 13] is a schematic view of an access intent action that the user must perform in order for the geolocation phase to be implemented (whether this is carried out by the connected mobile terminal or the access control unit), the access intent action here corresponding to an access validation action carried out on an access validation application previously loaded into the connected mobile terminal before the implementation of the secure access control process;

[0131] [Fig.14] is a schematic view of the access intention action which, in another context, corresponds to a specific inclination of the connected mobile terminal relative to the ground;

[0132] [Fig. 15] is a schematic view of the access intention action which, in another context, corresponds to an impact on the connected mobile terminal, such as a tap;

[0133] [Fig. 16] is a schematic view of the access intention action which, in another context, corresponds to a contact by the user on one of the geolocation beacons installed in the space where he is located, this context implying that one of the geolocation beacons is accessible to the user, for example by being attached to a wall;

[0134] [Fig. 17] is a schematic view of the access intention action which, in another context, corresponds to a detection by one of the geolocation beacons installed in the space of an approach of the user or his connected mobile terminal when he is within an activation distance;

[0135] [Fig. 18] is an operating diagram of a fifth mode of operation in which the action of intent to access, in addition to the geolocation phase, also conditions the implementation of the scanning phase; the action of intent to access being thus carried out at the start of the secure access control process and corresponding here to an approach detection as illustrated [Fig.17];

[0136] [Fig. 19] is an operating diagram of a sixth embodiment in which the access intent action, in addition to the geolocation phase, also conditions the implementation of the scanning phase; the access intent action is thus carried out at the start of the secure access control process and corresponds here to an unlocking of the connected mobile terminal by its user;

[0137] [Fig.20] is an operating diagram of a seventh embodiment in which the implementation of the geolocation phase is conditional upon the execution of several access intent actions, said several access intent actions being carried out successively at the end of the scanning phase and corresponding to an unlocking of the connected mobile terminal and then to a validation action carried out on the mobile validation application;

[0138] [Fig.21] is an operating diagram of an eighth embodiment, which also corresponds to the preferred embodiment of the invention: the scanning phase is implemented following an unlocking of the connected mobile terminal, the geolocation phase is implemented following a validation action carried out on the mobile validation application at the end of the scanning phase, the geolocation and access control phases are implemented by the access control unit following the receipt of data from the connected mobile terminal;unlocking the connected mobile terminal also serves to switch the connected mobile terminal from a standby state, in which it can only receive data in Ultra Wideband communication mode, to an awake state, in which it can transmit and receive data in Ultra Wideband communication mode, thus enabling it to initiate secure telemetry steps with nearby geolocation beacons during the scanning phase;

[0139] [Fig.22] is an operating diagram of a ninth embodiment in which the geolocation beacons are in a standby state at the start of the secure access control process, in which they can only receive data in Ultra Wideband communication mode, and in which the user must interact with one of the geolocation beacons in the space, called the starting proximity geolocation beacon, either by contact or by approaching it, in order to wake it up, making it then capable of transmitting and receiving data in the Ultra Wideband communication mode; said starting geolocation beacon transmitting, after its awakening, a wake-up signal to at least one other geolocation beacon installed in the same space as it to wake it up in turn, thus allowing the connected mobile terminal to proceed with the secure telemetry steps with all the nearby geolocation beacons;

[0140] [Fig.23] is an operating diagram of a tenth embodiment in which the geolocation beacons and the connected mobile terminal are in a standby state at the start of the secure access control process, and in which the user must interact with the near-start geolocation beacon so that, on the one hand, said near-start geolocation beacon transmits a wake-up signal to at least one other geolocation beacon installed in the same space as it to wake it up in turn, and on the other hand that it transmits another wake-up signal to the connected mobile terminal so that it also wakes up, thus enabling the implementation of the scanning phase.

[0141] [Detailed description of one or more embodiments of the invention]

[0142] The object of the invention relates to a secure access control method 100 designed to operate in Ultra Broadband geolocation mode. This secure access control method 100 of the invention proposes to geolocate and authenticate a connected mobile terminal 1 of a user U located in a space within a building and wishing to access one of several secure spaces accessible from said space, each of the secure spaces being protected by an access control bay.

[0143] Not exhaustively, the connected mobile terminal 1 is equipped with a touch screen and can refer to: a mobile phone, a touch tablet, a connected watch, etc.

[0144] Geolocation of the connected mobile terminal 1 allows the local position of the connected mobile terminal 1 to be determined, as well as the access control bay to which the connected mobile terminal 1 is physically closest. If, following authentication, it is verified that the user U has the necessary credentials to access the secure area protected by the access control bay to which they are physically closest, then access to said secure area is granted.

[0145] With reference to [Fig. 1], the secure access control method 100 is illustrated in the context of a building comprising: - four secure spaces El, E2, E3, E4 such that: the second secure space E2 and the third secure space among the four secure spaces El, E2, E3, E4 are accessible from the first secure space El, and the fourth secure space E4 is accessible from the second secure space E2; - five access control bays D1, D2, D3, D4, D5 such that: the first secure area is protected by the first and second access control bays D1, D2 among The six access control bays D1, D2, D3, D4, D5; the second secure space E2 is protected by the first, third, and fourth access control bays D1, D3, D4; the third secure space E3 is protected by the second access control bay D2; and the fourth secure space E4 is protected by the fourth and fifth access control bays D4, D5. Each access control bay has a locking / unlocking system allowing it to switch from a locked state to an unlocked state, to allow a user U to enter the secure space E1, E2, E3, E4 that it protects; and conversely, from an unlocked state to a locked state to prevent a user U from accessing the secure space E1, E2, E3, E4.

[0146] The secure access control process 100 is implemented using the following equipment 1, B1, B2, B3, B4, B5, B6, 2: - the connected mobile terminal 1 of user U which contains at least user identification data udata (or in English, credentials), and an Ultra Wideband transceiver U1; - geolocation beacons that can be installed in a space by being fixed and / or to the ceiling. With reference to [Fig. 1], six geolocation beacons Bl, B2, B3, B4, B5, B6 are used and arranged as follows: geolocation beacons B1 and B2 are installed in the first secure space E1; geolocation beacons B3 and B4 are installed in the second secure space E2; geolocation beacon B5 is installed in the third secure space E3, and geolocation beacon B6 is installed in the fourth secure space E4.Each of the geolocation beacons Bl, B2, B3, B4, B5, B6 comprises at least one Ultra Wideband transceiver UB1, UB2, UB3, UB4, UB5, UB6; and - an access control unit 2 which is linked to the locking / unlocking systems of the several access control bays D1, D2, D3, D4, D5, and in communication with at least the connected mobile terminal 1. With reference to [Fig. 1], the access control unit 2 is installed in the fourth secure space E4. According to different embodiments of the invention, the locking / unlocking systems of the access control bays D1, D2, D3, D4, D5 may, for example, correspond to a strike plate that opens and closes, and may either be physically connected by a wire to the access control unit 2, or be linked to it via a wireless connection.

[0147] The secure access control process 100 relies on data exchanges between the different equipment 1, B1, B2, B3, B4, B5, B6, 2, and in particular on exchanges between the connected mobile terminal 1 and at least one of the geolocation beacons B1, B2, B3, B4, B5, B6 in Ultra Broadband communication mode in order to authenticate and geolocate it.

[0148] The Ultra Wideband transceiver U1 of the connected mobile terminal 1 and the Ultra Wideband transceivers UB1, UB2, UB3, UB4, UB5, UB6 of the geolocation beacons Bl, B2, B3, B4, B5, B6 are designed to: - only be able to receive data in Ultra-Wideband communication mode when in a standby state; - be able to transmit and receive data in Ultra-Wideband communication mode when in an awake state (i.e. when they are awake).

[0149] In other words, with reference to [Fig.2], the connected mobile terminal 1 is able to carry out a bidirectional exchange of UWB1, UWB2, UWB3, UWB4, UWB5, UWB6 data with one of the six geolocation beacons Bl, B2, B3, B4, B5, B6 when their respective transceivers Ul, UB1, UB2, UB3, UB4, UB5, UB6 are woken up. In the following description, when it is described that the connected mobile terminal 1 exchanges data with a geolocation beacon Bl, B2, B3, B4, B5, B6, it is understood that it is its Ultra Wideband transceiver Ul that exchanges said data with the Ultra Wideband transceiver UB1, UB2, UB3, UB4, UB5, UB6 of the geolocation beacon Bl, B2, B3, B4, B5, B6.

[0150] The following description details, but is not exhaustive, several embodiments of the secure access control process 100. In other words, other embodiments are also possible depending on the characteristics defining the secure access control process 100. For each of the embodiments described, it is assumed, with reference to [Fig.1], that the user U is in the first secure space El and wishes to access the second secure space E2 protected by the first access control gate DI.

[0151] A first embodiment of the invention is illustrated by the flowchart [Fig.3]. In this embodiment, at the start of the secure access control process 100, it is assumed that the Ultra Wide Band transceivers Ul, UB1, UB2, UB3, UB4, UB5, UB6 of the connected mobile terminal 1 and of the geolocation beacons are woken up Bl, B2, B3, B4, B5, B6.

[0152] At the start of the secure access control process 100, the connected mobile terminal 1 triggers a ScanP scan phase during which it initiates secure telemetry steps with the geolocation beacons whose respective transceivers are within communication range of its own. With reference to [Fig. 3], and for all the embodiments that will be described subsequently, it is assumed that, during the ScanP scan phase, the Ultra Wideband transceivers UB1, UB2 of the geolocation beacon B1 and of the geolocation beacon B2 are within communication range of the Ultra Wideband transceiver U1 of the connected mobile terminal 1. In other words, for all the embodiments described, during the ScanP scanning phase, the connected mobile terminal 1 initiates a first step of secure telemetry SRI with the geolocation beacon Bl, and a second step of secure telemetry SR2 with the geolocation beacon B2.

[0153] The geolocation beacon B1 and the geolocation beacon B2, in order to be distinguished from the other geolocation beacons B3, B4, B5, B6 with which the connected mobile terminal 1 does not carry out secure telemetry steps, are designated as being near geolocation beacons Bl, B2.

[0154] It should be noted that it is conceivable that, in different embodiments of the invention, the ScanP scanning phase may include a single secure telemetry step initiated by the connected mobile terminal 1 with a single geolocation beacon.

[0155] Each of the secure telemetry steps SRI, SR2 comprises at least one bidirectional UWB1, UWB2 data exchange in Ultra Broadband communication mode between the connected mobile terminal 1 and the near geolocation beacon Bl, B2. Thus, with reference to [Fig. 3], the secure telemetry step SRI, SR2 comprises at least: - a transmission step SRI 1, SR21 during which the connected mobile terminal 1 emits security data datai 1, data21 to the nearby geolocation beacon Bl, B2, which receives them during a reception step SRI 1', SR21'; - a transmission step SR12, SR22 during which the nearby geolocation beacon Bl, B2 also transmits security datal2, data 22 including at least one identifier idBl, idB2 of the nearby geolocation beacon Bl, B2, which receives them during a reception step SR12', SR22'; - a calculation step ECB1, ECB2 of a certified distance sdistBl, sdistB2 between the connected mobile terminal 1 and the nearby geolocation beacon Bl, B2 following at least one bidirectional exchange (i.e. following at least the reception step SR12', SR22').

[0156] With reference to [Fig.4], in one embodiment of the invention, during the calculation step ECB1, ECB2, the certified distance sdistBl, sdistB2 is calculated, according to equation Eq.l, by at least one connected mobile terminal 1 and the nearby geolocation beacon Bl, B2 from a time of flight ToF (“Time Of Flight” in English) measured by said at least one connected mobile terminal 1 and the nearby geolocation beacon Bl, B2. _ Tloop-Treply Eq. 1

[0157] where Treply is the response time of the near geolocation beacon B1, B2, i.e. the time interval between the reception stage SRU', SR21' and the transmission stage SR12, SR22; and Tloop is the duration of the bidirectional exchange between the connected mobile terminal 1 and the near geolocation beacon Bl, B2, i.e. the time interval between the transmission stage SR11, SR21 and the reception stage SR12', SR22'.

[0158] In the illustrated embodiment [Fig.3], the certified distance sdistBl, sdistB2 is calculated by the nearby geolocation beacon Bl, B2.

[0159] In another embodiment of the invention, the connected mobile terminal 1 and the proximity geolocation beacon Bl, B2 both calculate the certified distance sdistBl, sdistB2 during the secure telemetry step SRI, SR2. They exchange the certified distance value sdistBl, sdistB2 that they have calculated. The connected mobile terminal 1 and the proximity geolocation beacon Bl, B2 then compare the certified distance sdistBl, sdistB2 that it received with the certified distance sdistBl, sdistB2 that it itself calculated. If the consistency between the certified distances sdistBl, sdistB2 is not verified, the telemetry step SRI, SR2 is stopped. If the consistency is verified, it continues.

[0160] As explained previously, the distance is certified by nature because its calculation is carried out during the secure telemetry step SRI, SR2, and because it is based on at least one bidirectional exchange of Ultra Wideband signals between the connected mobile terminal 1 and the nearby geolocation beacon Bl, B2, each of which has: an embedded secure component; or a previously loaded trusted firmware or application inside, or a Trusted Execution Environment (TEE).

[0161] In embodiments where the nearby geolocation beacons Bl, B2 are intended to calculate and certify the certified distance sdsitBl, sdistB2, it is conceivable that the connected mobile terminal 1, during transmission steps SR11, SR21, also transmits to the nearby geolocation beacons Bl, B2 a connected mobile terminal identifier specific to itself. This connected mobile terminal identifier is returned to the connected mobile terminal 1 by the nearby geolocation beacons Bl, B2 during the transmission of the certified distance sdistBl, sdistB2 during transmission steps SRI3, SR23.

[0162] Advantageously, returning the identifier of the connected mobile terminal allows the connected mobile terminal 1 to verify that the certified distance sdistBl, sdistB2 that it received during the reception step SR13', SR23': - firstly, that the calculated certified distance sdsitBl, sdistB2 corresponds to that between the nearby geolocation beacon Bl, B2 and itself, and not to a certified distance calculated between the nearby geolocation beacon Bl, B2 and another connected mobile terminal 1 that may be in its vicinity; and - on the other hand, it does indeed come from the nearby geolocation beacon Bl, B2 with which it implemented the secure telemetry step SRI, SR2. This is an additional security measure allowing the connected mobile terminal to determine whether the certified distance sdsitBl, sdistB2 comes from a malicious system or not, which malicious system cannot possess the identifier of the connected mobile terminal since the connected mobile terminal 1 and it did not carry out a secure telemetry step.

[0163] It is also conceivable, with a view to increasing the security level of the secure access control process 100, that the nearby geolocation beacons Bl, B2, after calculating the certified distance sdistBl, sdistB2, also generate a signature of this distance. The signature is such that it is unique to each of the nearby geolocation beacons Bl, B2. Thus, the connected mobile terminal 1, after obtaining a certified distance sdistBl, sdistB2, verifies its signature to determine whether or not it corresponds to the signature of the nearby geolocation beacon Bl, B2 that transmitted it (this therefore means that the signatures of the nearby geolocation beacons Bl, B2 are known to the connected mobile terminal 1).

[0164] If the mobile terminal identifier received from a nearby geolocation beacon Bl, B2 does not match the identifier of the connected mobile terminal 1, and / or if the received certified distance signature sdistBl, sdistB2 does not match the signature of said nearby geolocation beacon Bl, B2 that should have transmitted it, the connected mobile terminal 1 does not form the beacon data packet dataBl, dataB2 associated with said geolocation beacon Bl, B2 with which it is supposed to have communicated. In other words, and more simply, it does not take into account the certified distance sdistBl, sdistB2 that should have come from the nearby geolocation beacon Bl, B2 with which it is supposed to have been in communication during the secure telemetry step Bl, B2.The ScanP scanning phase ends once all the secure telemetry steps carried out by the connected mobile terminal 1 with all nearby geolocation beacons are completed (i.e., in the case of [Fig.3], following the completion of the first secure telemetry step El and the second secure telemetry step E2).

[0165] Optionally, the secure telemetry steps SRI, SR2 are not limited to the exchanges described above. Further information on secure telemetry is available in the two references indicated in the Prior Art.

[0166] At the end of the ScanP scanning phase, the connected mobile terminal 1 contains at least the identifier idBl, idB2 and the certified distance sdistBl, sdistB2 associated with the nearby geolocation beacon Bl, B2 with which it performed the telemetry step secure SRI, SR2. The minimum identifier idBl, idB2 and certified distance sdistBl, sdistB2 form a data packet of tag dataBl, dataB2 associated with the nearby geolocation tag Bl, B2.

[0167] Following the ScanP scanning phase, with reference to [Fig.5], the connected mobile terminal 1 transmits to the access control center 2 during a transmission step El at least the data packets of beacon dataBl, dataB2 relating to the two nearby geolocation beacons Bl, B2, as well as the user identification data udata.

[0168] In order to implement this transmission step El, the connected mobile terminal has network access with an add-c connection address to connect to the access control center 2 and communicate with it.

[0169] In one embodiment, the add-c connection address is already contained in the connected mobile terminal 1, having been previously loaded into it before the implementation of the secure access control method 100.

[0170] In another embodiment, the add-c connection address is transmitted to the connected mobile terminal 1 by at least one nearby geolocation beacon Bl, B2 during the secure telemetry step SRI, SR2. By way of exception, the add-c connection address may be transmitted: - during at least one bidirectional exchange between the connected mobile terminal and at least one nearby geolocation beacon Bl, B2, i.e., during the transmission step SR 12, SR22; or - with the certified distances sdistBl, sdistB2 during transmission steps SR13, SR23. Referring to [Fig. 3], the add-c connection address is transmitted to the connected mobile terminal 1 by only one of the two nearby geolocation beacons Bl, B2 during transmission step SR13; or - during another transmission step (which is not illustrated in the Figures).

[0171] With reference to [Fig. 6], during the GeoP geolocation phase, the access control unit links the data packets from beacon dataB1, dataB2 with a plane P that it contains. In the embodiment presented, all the access control bays D1, D2, D3, D4, D5 and the geolocation beacons Bl, B2, B3, B4, B5, B6 of the building are located in plane P using three-dimensional Cartesian coordinates. Plan P also contains the identifiers idBl, idB2, idB3, idB4, idB5, idB6 of the geolocation beacons B1, B2, B3, B4, B5, B6 and the identifiers id-Dl, id-D2, id-D3, id-D4, id-D5 associated with each of the access control bays Dl, D2, D3, D4, D5.

[0172] Relating plan P with the certified distances sdistBl, sdistB2 and the identifiers idBl, idB2 of nearby geolocation beacons allows the access control center to determine the local position of the connected mobile terminal 1 in the first Secure space El and determine the access control bay from among the first access control bay DI and the second access control bay D2 to which it is physically closest. In the given example, the identified access control bay, which is subsequently referred to as the target bay DC, corresponds to the first access control bay D1. In the remainder of the description, the target bay DC is assumed to have a target bay identifier id-DC.

[0173] Since the GeoP geolocation phase is based on the use of a P plan and on the analysis of data packets from beacon dataBl, dataB2, the geolocation beacons Bl, B2, B3, B4, B5, B6 do not need to be installed near the access control bays Dl, D2, D3, D4, D5.

[0174] Following the GeoP geolocation phase, the access control unit implements an access control phase (CP) during which it checks, at a minimum, whether user U has the required access rights to access the second secure space E2 protected by the target array DC, by verifying the user's identification data (udata). If so, the access control unit commands the unlocking of the locking / unlocking system associated with the target array DC. User U can then enter the second secure space E2, and the secure access control process (100) is completed. If not, the access control unit denies access to user U and does not command the unlocking of the locking / unlocking system associated with the target array DC.

[0175] Figure 7 illustrates a second embodiment of the access control method secure. In this mode, the connected mobile terminal 1 does not have network access and cannot transmit the user identification data udata and the beacon data packets dataBl, dataB2 to the access control unit 2. In this case, following the ScanP scanning phase, the sequence of which is similar to that of the embodiment illustrated [Fig.3] (except that no add-c connection address is transmitted to the connected mobile terminal 1), and then the storage of the beacon data packets dataBl, dataB2 in the connected mobile terminal 1, the connected mobile terminal 1 transmits during a transmission step E21 the user identification data udata and the beacon data packets dataBl, dataB2 to one of the two nearby geolocation beacons Bl, B2 which is then designated as the first nearby geolocation beacon.This first nearby geolocation beacon can, for example, correspond to the nearby geolocation beacon that is physically closest to the connected mobile terminal 1. In the rest of the description, it is considered that the nearby geolocation beacon Bl corresponds to the first nearby geolocation beacon.

[0176] Once the user identification data udata and the beacon data packets dataBl, dataB2 are received during a reception step E21', the first nearby geolocation beacon B1 must transmit them to the access control center 2.

[0177] In a first embodiment, the geolocation beacons B1, B2, B3, B4, B5, B6 are capable of communicating directly with the access control unit 2, either by being physically connected to it via Ethernet cables or using a wireless communication protocol such as Wi-Fi®. Thus, as referred to in [Fig. 7] and [Fig. 8], the first nearby geolocation beacon B1 directly transmits the user identification data udata and the beacon data packets dataB1, dataB2 to the access control unit during a transmission step E22.

[0178] In another variant, with reference to [Fig. 9], the geolocation beacons B2, B3, B4, B5, B6 and the access control unit 2 form a mesh network. The mesh network addresses the problem of installing groups of geolocation beacons in several areas of the same building, such that some geolocation beacons cannot communicate directly with the access control unit. It also addresses the problem of indoor network coverage when the building's structure and the materials used in its construction interfere with signal transmission, preventing two systems present in the building but within communication range from exchanging data (for example, two systems in the basement, or located on different floors of the building, or separated by a thick wall, etc.).Thus, in this variant, the transmission of the user identification data udata and the data packets of the beacon dataBl, dataB2 is done by means of a hop-by-hop communication, according to a hop-by-hop Bluetooth Mesh® communication protocol, in which the first near geolocation beacon Bl and at least one of the five other geolocation beacons B2, B3, B4, B5, B6 participate.

[0179] Note that in both variants, exchanges between geolocation beacons Bl, B2, B3, B4, B5, B6 or with the access control unit 2 can be done in Ultra Wideband as well as in another radio frequency communication protocol.

[0180] Once the access control unit receives from the first nearby geolocation beacon Bl the user identification data udata and the beacon data packets dataBl, dataB2 during a reception step E22', it implements the geolocation phase GeoP and the access control phase CP similarly to the first embodiment presented previously.

[0181] In other embodiments, it is conceivable that the GeoP geolocation phase is implemented not by the access control unit 2 but by the connected mobile terminal 1, the GeoP geolocation phase always being implemented following the ScanP scanning phase. In these embodiments, the Access control unit 2 can have less computing power because it is only used during the implementation of the access control phase CP by checking and verifying whether the information to authenticate user U is valid or not in order to authorize or deny them access to the secure space E2. It also does not have to contain the plan P. In fact, its design is simplified.

[0182] In a first embodiment, the connected mobile terminal, in order to implement the GeoP geolocation phase, contains a P-plan similar to that possessed by the access control unit in the previous embodiments described, that is to say, a P-plan as illustrated [Fig. 5] containing: the set of three-dimensional Cartesian coordinates of the geolocation beacons Bl, B2, B3, B4, B5, B6 and their respective identifiers idBl, idB2, idB3, idB4, idB5, idB6; the set of three-dimensional Cartesian coordinates of the access control bays Dl, D2, D3, D4, D5 and their respective identifiers id-Dl, id-D2, id-D3, id-D4, id-D5. This P-plan is preloaded into the connected mobile terminal before the secure access control process 100 is implemented.

[0183] During a DS determination step included in the GeoP geolocation phase, and from the plane P, the mobile terminal determines: its position locl and that of the target bay DC (in other words, their respective Cartesian, three-dimensional coordinates); the identifier of the target bay id-DC.

[0184] In a second embodiment, with reference to Figures 10 and 11, the connected mobile terminal 1 does not contain a map P. The geolocation beacons Bl, B2, B3, B4, B5, B6 are designed to each contain a piece of the map. The piece of the map associated with each of the geolocation beacons Bl, B2, B3, B4, B5, B6 locates said geolocation beacon Bl, B2, B3, B4, B5, B6 and at least one access control bay D1, D2, D3, D4, D5 physically close to said geolocation beacon Bl, B2, B3, B4, B5, B6.

[0185] In other words, the piece of plan contains the three-dimensional Cartesian coordinates of the geolocation beacon Bl, B2, B3, B4, B5, B6 and those of at least one access control bay Dl, D2, D3, D4, D5 physically close to it.

[0186] The piece of plan also includes the identifiers idBl, idB2, idB3, idB4, idB5, idB6 of the geolocation beacon Bl, B2, B3, B4, B5, B6 and the identifiers id-Dl, id-D2, id-D3, id-D4, id-D5 of the access control bays it locates Dl, D2, D3, D4, D5.

[0187] It is conceivable that the piece of plan P identifies, in addition to the geolocation beacon Bl, B2, B3, B4, B5, B6 to which it is associated, other geolocation beacons Bl, B2, B3, B4, B5, B6 located in the vicinity of said geolocation beacon Bl, B2, B3, B4, B5, B6.

[0188] Thus, with reference to [Fig. 10], when the connected mobile terminal 1 carries out the secure telemetry steps SRI, SR2 with the nearby geolocation beacons Bl, B2, each of them transmits its piece of plan PI, P2 to the connected mobile terminal; for example during the transmission step SRI3, SR23 or during a transmission step independent of those illustrated.

[0189] In the embodiment presented, with reference to [Fig. 11], it is considered that the piece of plan PI associated with the near geolocation beacon Bl contains its three-dimensional Cartesian coordinates, its identifier idBl, the three-dimensional Cartesian coordinates of the first access control bay DI and the identifier id-Dl of the latter; and that the piece of plan P2 associated with the second near geolocation beacon B2 contains its three-dimensional Cartesian coordinates, its identifier idB2, the three-dimensional Cartesian coordinates of the first access control bay D2 and the identifier id-D2 of the latter.

[0190] When the connected mobile terminal 1 implements the GeoP geolocation phase, it performs, prior to the DS determination step, a BS construction step during which it merges the plan pieces PI, P2; the plan pieces PI, P2 thus merged then forming a local plan P containing: the three-dimensional Cartesian coordinates of the geolocation beacons near Bl, B2, of the first access control bay DI and of the second access control bay D2; and their respective identifiers idBl, idB2, id-Dl, id-D2.

[0191] The merging of plan pieces PI, P2 is made possible by a mobile plan merging application previously loaded into the connected mobile terminal 1 before the start of the secure access control process 100.

[0192] Regardless of the variant, in the case where it has network access and the add-c connection address enabling it to connect to the access control center 2, the connected mobile terminal is configured to sign during an ESid signing step, which follows the GeoP geolocation phase, the target bay identifier id-DC in order to form a certified target bay identifier sid-DC.

[0193] With reference to [Fig. 10], the connected mobile terminal 1 then transmits during a transmission step E4 at least its position locl, the user identification data udata and the certified identifier of the target bay sid-DC to the access control center 2.

[0194] Once the local position of the connected mobile terminal 1, the user identification data udata and the certified identifier of the target bay sid-DC to the access control center 2 are received during a reception step E4', the access control center implements the access control phase CP.

[0195] During the CP access control phase, the access control unit 2 checks the certified identifier of the target bay id-DC to determine if the signature has been This is performed by a known / trusted system (i.e., by the connected mobile terminal 1). If not, it is possible that the udata, sid-DC, and locl data received during the E4' reception step originated from a malicious system. It also verifies, using the udata user's credentials, whether user U has the necessary authorization to access the secure space E2 protected by the target array DC (which, as a reminder, corresponds to the first access control array D1). It is also possible that it checks the consistency between the certified identifier of the target array id-DC determined by the connected mobile terminal 1 and its location locl.

[0196] Depending on the result of the access control phase, the access control unit 2 unlocks or does not unlock the locking / unlocking system of the target bay DC.

[0197] With reference to [Fig. 12], when the secure access control method 100 is designed so that the connected mobile terminal 1 communicates with the access control center 2 via geolocation beacons Bl, B2, B3, B4, B5, B6, the connected mobile terminal 1, in the case where it is configured to carry out the geolocation phase GeoP, transmits during a transmission step E5 its position locl, the identifier of the target bay id-DC and the user identification data udata to the first nearby geolocation beacon Bl.

[0198] Following the reception of the locl position of the connected mobile terminal 1 and the identifier of the target bay id-DC during a reception step E5', the first nearby geolocation beacon performs a timestamp of the identifier of the target bay id-DC during a timestamping step EH, forming a timestamped and consequently certified sid-DC target bay identifier id-DC.

[0199] After the timestamping step EH, the first geolocation beacon Bl transmits to the access control unit 2, during a transmission step E6, the user identification data (received during the SRI reception step 1' of the secure telemetry step SRI), the local position of the connected mobile terminal 1, and the certified identifier of the target bay sid-DC. According to various embodiments, the transmission can be direct, carried out via hop-by-hop communication between geolocation beacons Bl, B2, B3, B4, B5, and B6.

[0200] Following their reception during a reception step E6', the access control unit 2 implements the access control phase CP as described above.

[0201] In the embodiments presented so far, the access control unit is called upon at regular intervals because the connected mobile terminal 1 periodically initiates secure telemetry steps SRI, SR2 with the nearby geolocation beacons Bl, B2.

[0202] Therefore, in various embodiments, the secure access control process 100 includes a validation phase which conditions the implementation of the The GeoP geolocation phase, and therefore the CP access control phase. The validation phase thus allows:

[0203] - to significantly reduce exchanges between the different actors (the terminal connected mobile 1; geolocation beacons Bl, B2, B3, B4, B5, B6; the access control unit 2) of the secure access control process 100, which amounts to optimizing them; - to strengthen the security of the secure access control process 100 and the security of data exchanges; thus reducing the risks of interception of this data by a malicious system; - to reduce the strain on access control center 2 by implementing only one access control phase CP (and only one geolocation phase GeoP if it is responsible for its implementation).

[0204] It also reflects a genuine intention on the part of the user to want to access a secure space.

[0205] When detected by the connected mobile terminal 1, at least one access intent action may take the form of a ulock unlock of the connected mobile terminal 1, changing said connected mobile terminal 1 from a locked state to an unlocked state. This ulock unlock may, but is not limited to, be implemented following: - the activation of a touchscreen included in the connected mobile terminal 1 by pressing it by the user U, or by pressing a power button also included in the connected mobile terminal 1; or - an operation to enter an unlock code on the connected mobile terminal 1; or - a touch-sensitive unlock pattern entry operation on the touchscreen of the connected mobile terminal 1; or - a fingerprint recognition operation on a fingerprint sensor of the connected mobile terminal 1; or - a facial recognition operation of user U using a camera integrated into the connected mobile terminal 1.

[0206] It can also take the form, with reference to [Fig. 13], of an opt access validation action performed in a launch menu displayed by an access validation application 1-app, loaded on the connected mobile terminal 1. Without limitation, the opt access validation action may consist of: - an operation to enter a launch code on the launch menu; - a touch input operation of a launch pattern on the launch menu; - a validation operation on the launch menu

[0207] In one embodiment of the invention, it is conceivable that the 1-app access validation application also corresponds to the previously mentioned mobile plan merging application.

[0208] This can also refer, with reference to [Fig. 14], to an inclination of the connected mobile terminal 1. This consists of measuring the tetal tilt angle of the connected mobile terminal 1 relative to the ground, which is then compared to a predefined launch angular range. If the tetal tilt angle falls within the launch angular range, then the tilt is considered a valid access intent action. The launch angular range corresponds to an orientation of the connected mobile terminal 1 relative to the near geolocation beacon Bl, B2, or to the ground such that the front face Fl of the connected mobile terminal 1 faces or is substantially facing the user U. The tetal tilt angle is measured by an inertial measurement unit (IMU) within the connected mobile terminal 1.

[0209] In another variant, the access intention action detected by the connected mobile terminal consists, with reference to [Fig. 15], of a predefined impact movement of the user U on the connected mobile terminal, such as a tap.

[0210] When detected by a geolocation beacon B1, B2, B3, B4, B5, B6, in a first variant, at least one access intention action may correspond, with reference to [Fig. 16], to a detection of a touch by the user U on said geolocation beacon Bl, B2, B3, B4, B5, B6. The touch is detected by at least one sensor sensB1, sensB2, sensB3, sensB4, sensB5, sensB6 included in the geolocation beacon Bl, B2, B3, B4, B5, B6 and which is chosen from a key, a mechanical sensor, a capacitive sensor, and an inductive sensor. The user U contact may, but not exhaustively, refer to: - a contact of a hand of the user U on a part of the geolocation beacon near the starting point B1, detected for example by means of electrostatic sensors (inductive sensor or capacitive sensor); - pressing a key or button that includes the near-start geolocation beacon on its case or on a touchpad.

[0211] The detection of at least one contact attempt by user U on the geolocation beacon Bl, B2, B3, B4, B5, B6 implies that it is accessible to the user. In other words, it must be fixed to a wall and not to the ceiling.

[0212] The access intent action detected by the geolocation beacon Bl, B2, B3, B4, B5, B6 can also correspond, in a second variant, to a detection by at least one sensor sensBl, sensB2, sensB3, sensB4, sensB5, sensB6 of a prox approach of the user U within a given activation distance d-act relative to the geolocation beacon Bl, B2, B3, B4, B5, B6, which can be fixed to a wall, as illustrated [Fig.17], or to the ceiling. At least one sensor (sensB1, sensB2, sensB3, sensB4, sensB5, sensB6) is chosen from among a capacitive sensor, an inductive sensor, a radar sensor, an ultrasonic sensor, an optical sensor, and a vibration sensor. Thus, the detection of the proximity approach of user U can, but is not limited to: - a detection of the movements of user U or connected mobile terminal 1 by a motion sensor (for example, a passive infrared motion sensor or other optical sensor); - vibrations caused by the user's steps on the ground, which are detected by an accelerometer; - detection by a microphone of the noises caused by the footsteps of user U on the ground.

[0213] In this second variant, at least one sensor sensB1, sensB2, sensB3, sensB4, sensB5, sensB6 detecting an approach of the user U or their connected mobile terminal 1 can be integrated into the geolocation beacon Bl, B2, B3, B4, B5, B6 or located remotely from it. For example, the remote sensor can be contained in a housing that also includes a push button that the user U presses, which housing is fixed to a wall of the space in which one or more geolocation beacons Bl, B2, B3, B4, B5, B6 are located and: is either physically connected to one of the geolocation beacons that is configured to implement the detection of the intent to access action; or communicates with it by means of a wireless communication protocol (for example, Bluetooth Low Energy BLE®).

[0214] The geolocation beacon Bl, B2, B3, B4, B5, B6 configured to detect the access intent action is called the starting near geolocation beacon. In the following description, the starting near geolocation beacon is also considered to be the first near geolocation beacon BL

[0215] At the end of the validation phase, the equipment (i.e. the connected mobile terminal or the near-start geolocation beacon B1) having detected at least one access intention action is conformed to generate additional access intention information i-act.

[0216] The validation phase may consist of a combination, or a succession, of detections of user U's access intention action. In other words, at least one access intention action may include several access intention actions.

[0217] As indicated above, the validation phase conditions the implementation of the GeoP geolocation phase; meaning that it is carried out before the latter.

[0218] Thus, in different embodiments of the invention, the validation phase can be implemented before and / or after the scanning phase. In other words, the validation phase can consist of: - the detection of one or more access intent actions occurring after the ScanP scanning phase; or - the detection of one or more access intent actions occurring before the ScanP scanning phase; or - the detection of multiple access intentions such that at least one of the multiple access intention actions is detected before the ScanP scan phase, and such that at least one other of the multiple access intention actions is detected after the ScanP scan phase.

[0219] The secure access control method 100 provides that when the validation phase includes the detection of at least one access intent action before the scanning phase, said at least one access intent action conditions the implementation of the ScanP scanning phase. In other words, the connected mobile terminal implements the P scanning phase, i.e., it initiates the secure telemetry steps SRI, SR2, only if it contains the additional access intent information i-act.

[0220] In the first case, it stores the additional access intention information i-act that was transmitted to it by the near-start geolocation beacon B1 if the latter is in charge of detecting at least one access intention action.

[0221] In a second case, the additional access intention information i-act is generated directly by the connected mobile terminal 1 if it is in charge of detecting at least one access intention action.

[0222] When at least one action intention includes several access intention actions: - when the validation phase is based on the detection of said access intent actions after the ScanP scanning phase; the additional access intent information i-act is generated when the last of several access intent actions is detected; - when the validation phase relies on the detection of said access intent actions before the ScanP scanning phase; the additional access intent information i-act is generated when the last of several access intent actions is detected;

[0223] - when the validation phase relies on the detection of access intent actions taking place before and after the ScanP scan phase; the additional access intent information i-act is generated upon detection of the last of several access intent actions that were detected before the ScanP scan phase.

[0224] The first case is illustrated [Fig. 18]. In this embodiment, the validation phase consists of detecting the proximity of the connected mobile terminal 1 of the user U within the activation distance d-act of the geolocation beacon. Near departure Bl. Upon detection of approach proximity (prox), the near departure geolocation beacon Bl generates the additional access intention information (i-act). Following detection, the near departure geolocation beacon B1 transmits the additional access intention information (i-act) to the connected mobile terminal 1 during a transmission step E20. After receiving the additional access intention information (i-act) during a reception step E20', the connected mobile terminal then implements the ScanP scanning phase, for which the secure telemetry steps SRI and SR2 are considered to occur similarly to those of the embodiment presented [Fig. 3].

[0225] In this embodiment, it is also assumed that the connected mobile terminal 1 communicates with the access control unit 2; and that the access control unit is responsible for the geolocation phase GeoP. At the end of the scanning phase, the connected mobile terminal transmits to the access control unit, during a transmission step E7, at least the user identification data U, the beacon data packets dataB1, dataB2, and the additional access intent information i-act.

[0226] Following their reception during a reception step E7', the access control center 2 successively implements the geolocation phase GeoP as previously described; and the access control phase CP for which at least: it verifies the additional access intention information i-act, and whether the user U has the access rights required to access the second secure space E2 protected by the target bay DC, which it identified during the geolocation phase GeoP, by verifying for this purpose the user identification data udata.

[0227] The second case is illustrated in [Fig. 19]. Here, at the start of the secure access control process 100, user U must unlock their connected mobile terminal 1 if they want it to initiate the secure telemetry steps SRI, SR2 with the nearby geolocation beacons Bl, B2. Unlocking the connected mobile terminal ulock causes it to generate the additional access intent information i-act, which it then stores. The secure access control process 100 is then considered to continue similarly to that of [Fig. 18].

[0228] With reference to [Fig. 20], in another embodiment, the validation phase consists of detecting a first access intent action actl and a second access intent action act2 after the ScanP scanning phase has been implemented, for which the secure telemetry steps SRI, SR2 are considered to occur similarly to those of [Fig. 10]. User U must first perform a ulock unlock on their connected mobile terminal 1; this is the first access intent action actl. The ulock unlock has the effect of automatically launching the access validation application 1-app from which the user will perform the opt validation action; this is the second access intention action act2. The additional access intention information i-act is generated by the connected mobile terminal when the second access intention action act2 is detected.

[0229] In this embodiment, it is considered that the connected mobile terminal 1 proceeds to the GeoP Geolocation phase following the generation of the additional access intention information i-act, and that it proceeds to the ESid signing step of the target bay identifier id-DC.

[0230] It is also considered that the connected mobile terminal 1 is in direct communication with the access control center 2. Thus, it transmits to the latter during a transmission step E8 at least the user identification data udata, its position locl, the certified identifier of the target bay sid-DC, and the additional access intent information i-act.

[0231] Following their receipt during a reception step E8', the access control center 2 implements the access control phase CP during which at least: it checks the certified identifier of the target bay id-DC, verifies using the user identification data udata whether the user U has the necessary accreditations to access the secure space E2 protected by the target bay DC, and verifies the additional access intent information i-act.

[0232] For all the embodiments presented so far, it is considered that at the start of the secure access control process 100, the Ultra Wideband transceiver U1 of the connected mobile terminal 1 and the Ultra Wideband transceivers UB1, UB2, UB3, UB4, UB5, UB6 of the geolocation beacons Bl, B2, B3, B4, B5, B6 are awake (therefore able to transmit and receive in Ultra Wideband).

[0233] Other embodiments consider that at the start of the secure access control process 100, the Ultra Wideband transceiver U1 of the connected mobile terminal 1 is in a standby state, capable only of receiving in Ultra Wideband. It must therefore be woken up to initiate the secure telemetry steps SRI, SR2 with the nearby geolocation beacons Bl, B2.

[0234] These embodiments thus provide that the validation phase includes at least one access intention action taking place before the ScanP scanning phase, and that this access intention action, once detected, causes the switch, during a wake-up step WP-1 of the Ultra Wideband transceiver U1 of the connected mobile terminal 1 from the sleep state to the wake-up state.

[0235] In the embodiment presented [Fig.21], which corresponds to the preferred embodiment of the invention, the validation phase includes a first access intention action act1 and a second access intention act2.

[0236] The first actl validation action, performed by user U on their connected mobile terminal at the start of the secure access control process 100, consists of unlocking the terminal ulock. Unlocking the ulock triggers both the generation of the additional access intent information i-act by the connected mobile terminal 1, and the awakening of its Ultra Wideband transmitter U1 during the wake-up step WP-1 that follows detection.

[0237] Following the wake-up step WP-1, the connected mobile terminal initiates the secure telemetry steps SRI, SR2 with the nearby geolocation beacons Bl, B2. In the preferred embodiment, the connected mobile terminal 1 is configured to calculate during the two secure telemetry steps SRI, SR2 the certified distances sdistBl, sdistB2 that separate it from the nearby geolocation beacons Bl, B2 during the calculation steps ECB1, ECB2.

[0238] In this embodiment, it is also considered that during the secure telemetry steps SRI, SR2, each of the nearby geolocation beacons Bl, B2 transmits, during a transmission step SR14, SR24, to the connected mobile terminal 1, the security data data12, data22; the connection address add-c; and its identifier idBl, idB2. In a first variant, the calculation steps ECB1, ECB2 can take place before the transmission step SR14, SR24. In another variant, and as illustrated [Fig. 21], the calculation steps ECB1, ECB2 occur after the connected mobile terminal 1 receives the security data data12, data22, the connection address add-c, and the identifier idBl, idB2 of the nearby geolocation beacons Bl, B2 during a reception step SR14', SR24'.

[0239] In this preferred embodiment, the connected mobile terminal 1 is able to connect to the access control center 2 and communicate directly with it, which implements the GeoP geolocation phase.

[0240] However, the connected mobile terminal transmits at least the user identification data udata, the beacon data packets dataBl, dataB2, and the additional access intention information i-act during the transmission step E7 only if the user performs, following the ScanP scan phase, the second access intention action act2.

[0241] The second access intention action act2 corresponds to the opt validation action carried out from the access validation application 1-app.

[0242] The preferred embodiment provides that the access validation application 1-app runs and is displayed on the screen of the connected mobile terminal 1 automatically after the implementation of the ScanP scanning phase.

[0243] Following the detection of the second validation action act2, the connected mobile terminal performs the transmission step E7 described above. Following the step of reception E7', access control unit 2 performs the geolocation phase GeoP and the access control phase CP similarly to the embodiment illustrated [Fig. 19].

[0244] In a variant of the preferred embodiment of the invention, the connected mobile terminal does not have network access to communicate with the access control unit 2. In this case, following the detection of the second access intention action act2, the connected mobile terminal transmits the data packets of the beacon dataBl, dataB2, the user identification data udata and the additional access intention information to the first nearby geolocation beacon B1 which relays them to the access control unit (by direct communication or by hop-by-hop communication).

[0245] At the start of the secure access control process 100, it is possible that the geolocation beacons Bl, B2, B3, B4, B5, B6 are in a standby state in order to reduce their energy consumption, in particular if they are powered by means of an integrated rechargeable battery in order to save the latter.

[0246] It is essential to wake up the Ultra Wideband transceivers UB1, UB2, UB3, UB4, UB5, UB6 of the geolocation beacons Bl, B2, B3, B4, B5, B6 so that the connected mobile terminal 1 can initiate secure telemetry steps with them. More specifically, it is necessary, at a minimum, to wake up the Ultra Wideband transceivers of the geolocation beacons located near the starting near-location beacon, for example, the geolocation beacons located in the same area as the starting near-location beacon. In the application context illustrated from [Fig. 1], it is necessary, at a minimum, to wake up the transceivers UB1, UB2 of beacon Bl, which corresponds to the starting near-location beacon, and beacon B2 to proceed with the secure telemetry steps SRI SR2.

[0247] The Ultra Wideband transceivers UB3, UB4, UB5, UB6 of the other geolocation beacons B3, B4, B5, B6 must be woken up in a configuration for which the information required by the access control center 2 to implement the access control phase CP (and possibly before the geolocation phase GeoP) is transmitted by way of Ultra Wideband hop-by-hop communication between geolocation beacons Bl, B2 B3, B4, B5, B6.

[0248] With reference to [Fig. 23], the secure access control method 100 is then designed such that at least one access intent action includes an access intent action detected before the implementation of the ScanP scanning phase by the near-start geolocation beacon B1. This can be either the detection of a proximity approach or the detection of a contact (as explained previously, the detection of a contact implies that the near-start geolocation beacon B1 is, in terms of installation, accessible to user U). Following the detection of the access intention action, corresponding in [Fig.23] to a contact tou, the Ultra Wide Band transceiver UB1 of the near start geolocation beacon B1 switches from the standby state to the awake state during a wake-up step WP-B1.

[0249] The detection of the contact also causes the generation of the additional access intention information i-act.

[0250] Following the wake-up step WP-B1, in the embodiment described [Fig. 22], the near-start geolocation beacon B1 is configured to transmit: - during a transmission step E9, the additional access intention information i-act and an acknowledgment signal ackl to the connected mobile terminal 1, whose Ultra Wideband transceiver is considered to be awake at the start of the secure access control process 100; and - during a transmission step E10, transmit a wsb beacon wake-up signal to, at a minimum, the nearby geolocation beacon B2.

[0251] Following the reception of the wake-up signal from the WSB beacon during a reception step E10', the Ultra Wideband transceiver UB2 of the near-field geolocation beacon B2 switches from standby to wake-up during a wake-up step WP-B2. The near-field geolocation beacon B2 then transmits an acknowledgment signal ack2 to the connected mobile terminal 1 during a transmission step El 1.

[0252] In this embodiment, the connected mobile terminal 1 is configured to initiate the secure telemetry step with each of the two beacons B1, B2 immediately after receiving their acknowledgment signal ack1, ack2 during a reception step E9', Eli'. Thus, following the reception step E9, the connected mobile terminal performs the first secure telemetry step SRI with the starting near-home geolocation beacon B1. It is at the end of the first secure telemetry step SRI that the starting near-home geolocation beacon B1 proceeds to the transmission step E10, from which all the steps E10', WB-2, Eli, Eli' then follow, culminating in the implementation of the second secure telemetry step SR2. In other words, the activation of the starting near-home geolocation beacon B2 occurs during the ScanP scanning phase.

[0253] In one variant, a time delay is defined between the moment when the connected mobile terminal 1 receives the acknowledgment signal from a nearby geolocation beacon and the moment when it initiates a secure telemetry step with that beacon. In such a configuration, it is possible for the mobile terminal to receive all the acknowledgment signals from the nearby geolocation beacons before the implementation of the secure telemetry steps, which are then carried out successively. In other words, in this variant, the steps E10, E10', WP-B2, Eli, Eli' occur chronologically before the secure telemetry steps SRI, SR2.

[0254] In the embodiment shown [Fig.22], the steps SRI, SR2, E7, E7', GeoP, CP take place similarly to those of the embodiments shown [Fig. 18] and [Fig.19],

[0255] Finally, it is conceivable that at the start of the secure access control process 100, the Ultra Wideband transceivers UB1, UB2 UB3, UB4, UB5, UB6 of the connected mobile terminal 1 and of the geolocation beacons Bl, B2 B3, B4, B5, B6 are all in the standby state.

[0256] With reference to [Fig.23] which illustrates one embodiment of this configuration case, the secure access control process 100 is designed such that at least one access intent action includes, at the start of the process, the detection of a proximity approach of the user U or of his connected mobile terminal 1 or, as illustrated here, of a contact of the user U. Following the awakening of its Ultra Wideband transceiver UB1 during the wake-up step WP-B1, the starting proximity geolocation beacon is configured to transmit to the connected mobile terminal, during a transmission step E12', the additional access intent information i-act as well as a wake-up signal wsl.

[0257] Following the reception of the wake-up signal during a reception step E12', the Ultra Wideband transceiver UB1 of the connected mobile terminal switches from the standby state to the awake state during the wake-up step WP-1.

[0258] The WSL wake-up signal also acts as an acknowledgment signal, so that the connected mobile terminal 1, once the wake-up step is complete, can initiate the first SRI secure telemetry step with the starting near-home geolocation beacon BL

[0259] The principle of waking up the Ultra Wide Band transceiver UB2 of the near geolocation beacon B2, and possibly those UB3, UB4, UB5, UB6 of the other geolocation beacons B3, B4, B5, B6 remains the same as that described in the previous embodiment.

[0260] In the embodiment presented [Fig.23], it is considered that the secure access control process 100 takes place identically to that described just before and illustrated [Fig.22] from the beginning of the implementation of the first step of secure telemetry SRI.

[0261] Alternatively, in the embodiments presented [Fig.22] and [Fig.23], and as previously indicated, at least one access intention action may include, in addition to that used to implement the wake-up step WP-B1, other access intention actions performed by the user U on his connected mobile terminal 1, for example an access intention action following the ScanP scanning phase and which is necessary to start the GeoP geolocation phase, similar to the embodiments illustrated [Fig.20] and 21.

Claims

1. Demands Secure access control method (100) for controlling and authorizing a user (U) to access secure areas (E1, E2, E3, E4) accessible via access control bays (DC, D2, D3, D4, D5), each equipped with a locking / unlocking system, the secure access control method (100) involving several pieces of equipment (I, B1, B2, B3, B4, B5, B6, B2), including: - a connected mobile terminal (1) carried by the user (U) and containing at least user identification data (udata), said connected mobile terminal (1) comprising at least one Ultra Wideband transceiver (Ul), - geolocation beacons (Bl, B2, B3, B4, B5, B6) each comprising at least one Ultra Wideband transceiver (UB1, UB2, UB3, UB4, UB5, UB6), - an access control unit (2) which is linked to the locking / unlocking systems of the several access control bays (DC, D2, D3, D4, D5), and in communication at least with the connected mobile terminal (1); the secure access control process (100) implementing at least the following steps: - a scanning phase (ScanP) in which the connected mobile terminal (1) initiates secure telemetry steps (SRI, SR2) with several geolocation beacons (B1, B2), referred to as nearby geolocation beacons, among the geolocation beacons (B1, B2, B3, B4, B5, B6), said nearby geolocation beacons (B1, B2) having their respective Ultra Wideband transceivers (UB1, UB2) within a communication range of the Ultra Wideband transceiver (U1) of said connected mobile terminal (1), said secure telemetry steps (SRI, SR2) operating in respective Ultra Wideband communication channels and at the end of which beacon data packets (dataB1, dataB2) associated with each of the nearby geolocation beacons (B1, B2) are determined and stored in the connected mobile terminal (1), where each of the beacon data packets (dataB1, dataB2) includes at least one identifier (idBl,idB2) of the associated nearby geolocation beacon (Bl, B2), transmitted by said nearby geolocation beacon, (Bl, B2) to the connected mobile terminal (1), and a certified distance (sdistBl, sdistB2) between the connected mobile terminal (1) and said associated near geolocation beacon (Bl, B2); - a geolocation phase (GeoP) in which the connected mobile terminal (1) is geolocated in a plane (P) from said beacon data packets (databl, datab2), which plane (P) locating at least a part of the access control bays (DC, D2, D3, D4, D5) and at least the nearby geolocation beacons (Bl, B2) among the geolocation beacons (Bl, B2, B3, B4, B5, B6), and at the end of which a position (locl) of the connected mobile terminal (1) is determined in the plane (P) and an access control bay (DC), called the target bay, is identified which is closest to the connected mobile terminal (1) among the access control bays (DC, D2, D3, D4, D5) present in said plane (P); - an access control (AC) phase implemented by the access control unit (2), which verifies at least the user identification data (udata) sent from the connected mobile terminal (1) to the access control unit (2), to authorize or deny access to the secure space (E2) accessible via the target bay (DC) and, if necessary, control the locking / unlocking system of said target bay (DC); and the secure access control process (100) being characterized in that: - the connected mobile terminal (1) contains the plan (P), and implements the geolocation phase (GeoP) once the beacon data packets (dataBl, dataB2) from nearby geolocation beacons (Bl, B2) are stored in the connected mobile terminal (1); and at the end of which at least one certified identifier of the target bay (sid-DC) is then transmitted to the access control center (2) with the user identification data (udata); and in that - the plan (P) loaded into the connected mobile terminal (1) is a local plan identifying a part of the access control bays (DC, D2) and the nearby geolocation beacons (Bl, B2), said local plan being constituted by the connected mobile terminal (1) during a construction step (BS) from plan pieces (PI, P2) communicated to the connected mobile terminal (1) by each of the nearby geolocation beacons (Bl, B2) during the secure telemetry steps (SRI, SR2);the associated piece of plan (PI, P2); to each of the nearby geolocation beacons (Bl, B2) locating the relevant nearby geolocation beacon (Bl, B2) and at least one access control bay (DC, D2) in the vicinity of said nearby geolocation beacon (Bl, B2).

2. A secure access control method (100) according to claim 1, wherein during each of the secure telemetry steps (SRI, SR2) performed between the connected mobile terminal (1) and a nearby geolocation beacon (B1; B2) among the nearby geolocation beacons (B1, B2), the certified distance (sdistBl, sdistB2) between the connected mobile terminal (1) and said nearby geolocation beacon (B1, B2) is calculated by at least one of the connected mobile terminal and said nearby geolocation beacon (B1, B2).

3. A secure access control method (100) according to claim 1 or 2, wherein the connected mobile terminal (1) determines its position (locl), the target bay (DC) and the target bay identifier (id-DC) from the plane (P).

4. A secure access control method (100) according to any one of claims 1 to 3, wherein the access control unit (2) receives at least the user identification data (udata), the location (locl) of the connected mobile terminal (1), and the certified identifier of the target bay (sid-DC) directly from the connected mobile terminal (1), which connected mobile terminal (1): - signs the identifier of the target bay (id-DC) to form the certified identifier of the target bay (sid-DC), and - has network access and contains a connection address (add-c) to remotely connect to and communicate with the access control unit (2).

5. Secure access control method (100) according to claim 4, wherein the connection address (add-c) corresponds to data previously loaded into the connected mobile terminal (1), or corresponds to data transmitted to the connected mobile terminal (1) from one of the nearby geolocation beacons (B1, B2) during one of the secure telemetry steps (SRI, SR2).

6. A secure access control method (100) according to any one of claims 1 to 3, wherein the connected mobile terminal (1) transmits to a nearby geolocation beacon (Bl), referred to as the first nearby geolocation beacon, among the geolocation beacons close (Bl, B2) at least the user identification data (udata), the position (locl) of the connected mobile terminal (1) and the identifier of the target bay (id-DC), which first close geolocation beacon (Bl) timestamps the identifier of the target bay (id-DC) to thus form the certified identifier of the target bay (sid-DC), and the access control unit (2) receives at least the user identification data (udata) and the certified identifier of the target bay (sid-DC) indirectly through one or more geolocation beacons (Bl, B2, B3, B4, B5, B6) among the geolocation beacons (Bl, B2, B3, B4, B5, B6), including at least the first close geolocation beacon (Bl); which geolocation beacons (Bl, B2, B3, B4, B5, B6) have network access to communicate with the access control center (2), via direct communication or via hop-by-hop communication.

7. A secure access control method (100) according to any one of the preceding claims, wherein the secure access control method (100) comprises a validation phase during which: - the connected mobile terminal (1) or one of the nearby geolocation beacons (B1; B2) among the nearby geolocation beacons (B1, B2) detects at least one access intention action (act1, act2) performed by the user (U); - and then additional access intention information (i-act) is generated by the connected mobile terminal (1) or one of the nearby geolocation beacons (B1; B2) among the nearby geolocation beacons (B1, B2) after detection of at least one access intention action (act1, act2); and in which at least one of the scanning phase (ScanP) and the geolocation phase (GeoP) is implemented at least on the condition of prior completion of the validation phase.

8. Secure access control method (100) according to claim 7, wherein the scanning phase (ScanP) is carried out on the condition of the realization of at least one access intent action (act1, act2), so that the connected mobile terminal (1) initiates the secure telemetry steps (SRI, SR2) after a generation or reception by the connected mobile terminal (1) of the additional access intent information (i-act).

9. Secure access control method (100) according to claim 7 or 8, wherein at least one access intent action (actl, act2) comprises a first access intent action (actl) and a second access intent action (act2) such that: - the scanning phase (ScanP) is implemented on the condition that the first access intent action (actl) has been carried out beforehand, and - the geolocation phase (GeoP) is implemented on the condition that the second access intent action (act2) has been carried out beforehand, and following the implementation of the scanning phase (ScanP); the additional access intent information (i-act) being generated by the mobile terminal (1) or by one of the nearby geolocation beacons (B1; B2) among the nearby geolocation beacons (Bl, B2) after detection of the first access intent action (actl).

10. A secure access control method (100) according to any one of claims 7 to 9, wherein the additional access intent information (i-act) is transmitted to the access control unit (2) with at least the user identification data (udata); and during the access control phase (CP), the access control unit (2) also checks said additional access intent information (i-act) to authorize or deny access to the secure space (E2).

11. A secure access control method (100) according to claim 10, in combination with claim 3 or 4, wherein the access control unit (2) receives from the connected mobile terminal (1) at least the beacon data packets (dataB1, dataB2), the additional access intent information (i-act) and the user identification data (udata) following completion of the validation phase.

12. A secure access control method according to any one of claims 7 to 11, wherein during the validation phase, at least one access intent action (act1, act2) is detected by the connected mobile terminal (1) and corresponds to: - a predefined impact (tap) or displacement (inc) movement of the connected mobile terminal (1) detected by an accelerometer (al) integrated into the connected mobile terminal (1); - an unlocking action (ulock) by the user of the connected mobile terminal (1) to move it from a locked state to an unlocked state; - an access validation action (opt) performed by the user (U) of the connected mobile terminal (1) on an access validation application (1-app) loaded in the connected mobile terminal (1).

13. A secure access control method (100) according to claims 9 and 12, wherein the first access intention action (actl) and the second access intention action (act2) are detected by the connected mobile terminal (1), and such that: - the first access intention action (actl) corresponds to the unlock action (ulock), and - the second access intention action (act2) corresponds to the access validation action (opt).

14. A secure access control method (100) according to any one of claims 7 to 12, wherein during the validation phase, at least one access intent action (act1, act2) corresponds to a detection by at least one sensor (sensBl) of: - a contact (tou) by the user (U) on a nearby geolocation beacon (Bl), referred to as the starting nearby geolocation beacon, among the nearby geolocation beacons (Bl, B2); or - an approach (prox) by the user (U) or the connected mobile terminal (1) towards a nearby geolocation beacon (Bl), referred to as the starting nearby geolocation beacon, among the nearby geolocation beacons (Bl, B2) within a given activation distance (d-act) relative to said starting nearby geolocation beacon (Bl); and in which said near-start geolocation beacon (Bl) generates the additional access intent information (i-act).

15. A secure access control method (100) according to claim 14, wherein at least one sensor (sensBl) is selected from a mechanical sensor, a capacitive sensor, an inductive sensor, a radar sensor, an ultrasonic sensor, an optical sensor, a vibration sensor.

16. A method for secure access control (100) according to claim 14 or 15, wherein at least one sensor (sensBl) is mounted on the near-start geolocation beacon (Bl), or is remotely located from said geolocation beacon near the starting point (Bl) and in connection with it.

17. A secure access control method (100) according to any one of claims 14 to 16, wherein at the start of the secure access control method (100), the Ultra Wideband transceiver (UB1, UB2, UB3, UB4, UB5, UB6) of each of the geolocation beacons (B1, B2, B3, B4, B5, B6) is in a standby state, capable only of receiving in Ultra Wideband, and wherein, following detection of at least one access intent action (act1, act2) by the starting near geolocation beacon (B1), at least the Ultra Wideband transceiver (UB1) of the starting near geolocation beacon (B1) switches to an awake state, capable of transmitting and receiving in Ultra Wideband, so that the connected mobile terminal (1) can initiate the secure telemetry step (SRI) with said geolocation beacon near starting point (Bl).

18. A secure access control method according to claim 17, wherein following the detection of at least one access intention action (act1, act2) by the starting near geolocation beacon, said starting near geolocation beacon (B1) sends to each of the other near geolocation beacons (B2) among the near geolocation beacons (B1, B2) within communication range an Ultra Wideband wake-up signal (wsb) so that their respective transceiver (UB2) also switches to the woke state; this so that the connected mobile terminal (1) can initiate the secure telemetry steps (SRI, SR2).

19. A secure access control method (100) according to any one of claims 7 to 18, wherein at the start of the secure access control method (100), the Ultra Wideband (Ul) transceiver of the connected mobile terminal (1) is in a standby state, only able to receive in Ultra Wideband, and wherein at least one access intent action (actl, act2) detected by the connected mobile terminal (1) during the validation phase causes the Ultra Wideband (Ul) transceiver of the connected mobile terminal (1) to switch to an awake state, making it capable of transmitting and receiving in Ultra Wideband, and consequently capable of initiating the scanning phase (ScanP).

20. A secure access control method (100) according to claims 12 and 19, wherein the first access intent action (actl) detected by the connected mobile terminal (1) during the validation phase, and which corresponds to the unlock action (ulock), switches the Ultra Wideband (Ul) transceiver of the connected mobile terminal (1) into an awake state making it capable of transmitting and receiving in Ultra Wideband, and consequently capable of initiating the scanning phase (ScanP).

21. A secure access control method (100) according to claim 17 or 18, wherein at the start of the secure access control method (100), the Ultra Wideband transceiver (Ul) of the connected mobile terminal (1) is in a standby state, only capable of receiving in Ultra Wideband, and wherein following the detection of at least one access intention action (actl, act2) by the near-start geolocation beacon (Bl), said near-start geolocation beacon (Bl) sends to the connected mobile terminal (1) a wake-up signal (wsl) in Ultra Wideband which, when received by the connected mobile terminal (1), switches the Ultra Wideband transceiver (Ul) of the latter into a woke state, making it capable of receiving and transmitting in Ultra Wideband, and thus capable of initiating the scanning phase (ScanP).