Access control system and method therein for handling access to access-restricted physical resource

JP2023055634A5Pending Publication Date: 2025-08-04AXIS
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2022139408
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2021-09-09
Filing Date
2022-09-01
Publication Date
2025-08-04

AI Technical Summary

Technical Problem

Existing access control systems require administrator involvement for granting and changing access rights, which can be cumbersome and inefficient.

Method used

An access control system and method that allows hosts to dynamically add and modify access rights for visitors by using credential readers and resource controllers, enabling hosts to grant access without administrator intervention.

Benefits of technology

Facilitates easy and flexible management of access rights, allowing hosts to provide temporary or restricted access to visitors without needing administrator involvement, enhancing efficiency and convenience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

To provide an access control system for handling an access to an access-restricted physical resource.SOLUTION: An access control system 100 includes a first resource controller 101', a first qualification certificate reader 102', a second qualification certificate reader 102'' and a physical resource 104'. The first qualification certificate reader receives a qualification certificate 108 which starts requesting to give one or more visitors an access to the physical resource restricting a first access. Also, the second qualification certificate reader receives a qualification certificate 108' which finalizes a request to give the visitor 110 an access. The first resource controller allows the visitor 110 to access the physical resource restricting the first access when a visitor qualification certificate 112 is presented to the first qualification certificate reader.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an access control system and a method therein for handling access to physical resources with restricted access.

Background Art

[0002] Access control systems are widely used to provide access to restricted resources only to those who are deemed to have the authority to access them. Restricted resources may include real estate, offices, or specific spaces within them, and authorized individuals may be owners, employees, or visitors of the real estate, but these are just some examples. Generally, the administrator of an access control system issues access cards to authorized individuals. The access card may be configured with data that grants the authorized individual access to the restricted physical resource, according to a configuration made by the administrator. Alternatively, the access control system may be configured with data that grants access to authorized individuals, and the access card may be uniquely associated with data on the access control system. This configuration defines which restricted physical resources the person should be granted access to, and it may also define when and / or how many times access should be permitted. Upon receiving an access card, the authorized person presents their access card to a card reader located in the restricted access area they wish to enter. The card reader reads the data on the access card, and the access control system determines whether the person is authorized to access the restricted access area. If it is determined that the person is authorized to enter the restricted access area, and any possible restrictions regarding when and / or how many times access is permitted are met, access is granted. For example, upon successful authentication and authorization, a locked door or gate preventing entry into the restricted access area is unlocked, allowing the authorized person to enter.

[0003] Whenever a change is made to the rights of an authorized person to access restricted physical resources, the administrator must make those changes by reconfiguring the access card or access control system. Therefore, if a host wants to grant a visitor access to certain restricted physical areas, as determined by the host, for a period of time also determined by the host, they must request the administrator to issue an access card and configure the access control system to grant the visitor access to those restricted physical areas for the desired period. The host must also request the administrator to make any desired changes to the visitor's access rights.

[0004] US9,990,786B1 discloses a system in which a member of a granting authority that authorizes certificates receives a request to issue an electronic visitor certificate to a visitor of that granting authority. The electronic visitor certificate enables access to the resources of the granting authority that authorizes certificates. Based on a determination that a member of the granting authority that authorizes certificates is authorized to issue certificates to visitors, the electronic visitor certificate is issued with at least one timing constraint that defines the period in which the electronic visitor certificate is valid, and at least one usage constraint that restricts the resources of the granting authority that the electronic visitor certificate enables access to.

[0005] US7,770,206B2 describes how the right to grant access to the resources of the first organization to the requesting party of the second organization is transferred from the first administrator of the first organization to the second administration of the second organization.

[0006] EP3358534A1 describes a system for controlling access to physical spaces within a building. An administrator's smartphone stores access rights, readable via an electronic lock, and user rights to access an access control server and transfer access rights. When an access rights transfer request is received from the administrator's smartphone, the access control server may define access rights to another mobile phone, and once those access rights are enabled, the electronic lock can be opened using that other mobile phone.

[0007] EP1325476A1 discloses a wireless lock and key system that uses a pair of encryption keys. When the lock detects a person nearby, a random signal is generated. The key encrypts the signal and returns it to the lock. The lock decrypts the signal and compares it to the original to determine whether it should be opened. The key may temporarily generate a ticket for the guest that allows them to open the lock a limited number of times.

[0008] EP1398737A2 discloses a method and system for uniquely identifying an entity. The system includes a wireless identification device with a controller mechanism for wirelessly transmitting, acquiring, processing, and transmitting data. A reader device having a controller mechanism acquires, processes, and transmits data, and a sensing mechanism communicates with the reader device to acquire, process, and transmit data from the wireless identification device. A wireless control device is included for communicating with the reader device, which can communicate with the reader device, the wireless identification device, or subsequent wireless identification devices to constitute them.

[0009] WO2021 / 050616A1 discloses an entry system for a building having a first door lock including a controller, wherein the first door lock is configured to encode access rights to a first client key card in response to a first engagement with a master key card.

[0010] Some traditional procedures, which required administrator involvement in issuing access cards and setting and changing access rights, could be cumbersome for the host because they could not grant or change access rights without administrator intervention.

[0011] Even with systems in place that allow administrators to delegate access rights, there is room for improvement in achieving a simplified handling of access to physical resources with restricted access. [Overview of the Initiative]

[0012] In view of the foregoing, the object of the present invention is therefore to provide an access control system and method that simplifies the handling of access to physical resources with restricted access, while mitigating the drawbacks of the prior art.

[0013] According to a first aspect of the present invention, the above object is achieved by a method for handling access to a restricted physical resource. This method includes a first credential reader associated with a first restricted physical resource receiving credentials to initiate an access request, which grants one or more visitors access to the first restricted physical resource. The first credential reader is configured to communicate with a first resource controller that controls access to the first restricted physical resource. Furthermore, this method includes the first credential reader receiving visitor credentials for each visitor for whom access has been requested and informing the first resource controller of each received visitor credential, and a second credential reader configured to communicate with the first resource controller receiving credentials to finalize the access request, which grants one or more of those visitors access to the first restricted physical resource. Furthermore, this method includes allowing a visitor to access a physical resource whose access is restricted by the first resource controller when the visitor's visitor credentials are presented to the first credential reader.

[0014] The procedure for requesting and granting access rights to multiple visitors is simplified by receiving, first, the credentials to initiate the access request, second, visitor credentials for all visitors to whom access has been requested, and third, the credentials to finalize the access request, at a credential reader communicating with a resource controller that controls access to a first restricted physical resource. For example, a host may present the credentials to initiate the access request to a credential reader, which then receives the credentials to initiate the access request by reading them. Upon receiving the credentials to initiate the access request, the access control system, such as a resource controller or access controller, recognizes that a request to grant access rights has been initiated and that the right to access the first restricted physical resource should be granted to visitors who possess one or more visitor credentials received after the credentials to initiate the access request. The access request is finalized upon receipt of the credentials to finalize the access request. Subsequently, when those visitors present their visitor credentials to the first credential reader, they are granted access to the first physical resource whose access is restricted.

[0015] When the phrase "handling access to restricted physical resources" is used here, it means handling the right to access restricted physical resources. This can also be expressed as managing access, or managing the right to access. For example, this could mean granting the right to access restricted physical resources to authorized persons, modifying the right to access for those authorized persons, renewing the right to access in response to access made by those authorized persons, and revoking access rights if those authorized persons should no longer be permitted to have access.

[0016] Where the expression “restricted access physical resources” is used in this disclosure, it means substantial, that is, specific resources to which access is restricted. For example, restricted access physical resources may be restricted areas such as buildings, rooms, offices, or outdoor environments, or restricted access facilities such as charging stations for electric vehicles or computer-controlled facilities. Access to physical resources may be restricted so that only authorized persons are permitted to access the restricted area. For example, authorized persons may be permitted to enter the physical resources only a certain number of times, a certain number of times per day, and / or for a certain number of days. Furthermore, access to physical resources may be restricted so that the use of restricted facilities is permitted only to authorized persons. The latter may be the case where an authorized person is permitted to access a charging station to charge his / her electric vehicle.

[0017] Where the term "access" is used herein, it may refer to consuming, entering into, and / or using a physical resource for which access is restricted. Therefore, the act of accessing may mean consuming, entering into, or using that resource. The permission to access a resource is called authorization, and a person who has been authorized is a person who is permitted to access a physical resource for which access is restricted.

[0018] Where the term “credentials” is used herein, it means anything that can be used to authenticate a person. A credential may be something a person possesses, something a person knows, or something unique to that person. Something a person possesses may be an access card, something a person knows may be a keypad code, and something unique to that person may be a person’s fingerprint, but these are just some examples. A credential may be a device such as a smart card containing data, also referred to herein as a credential, that is received by a credential reader and used to authenticate the person, but as mentioned above, a credential may also be data such as a keypad code given to a keypad. Thus, a credential may take the form of a smart card such as an access card, a key fob, a user ID, a secret password, an authentication code such as a quick response (QR) code presented on a mobile device such as a smartphone or smartwatch, an electronic identity document and a near-field communication (NFC) device that functions as a key card, biometric data such as a fingerprint, facial recognition, voice recognition, and / or retinal scan, or a public key certificate such as an X.509 certificate. It should be understood that the term "certificate of qualification" may also refer to two or more combinations of the examples above.

[0019] A "Credential to initiate an access request" is a certificate that grants credentials to initiate an access request, such as a request to add access to a new visitor.

[0020] A "certificate of credentials to finalize access requests" is a certificate of credentials that finalizes access requests, such as requests to grant access to a new visitor.

[0021] A "Visitor Credential" is the certificate of credentials associated with the visitor for whom access has been requested.

[0022] Where the term “credential reader” is used in this disclosure, it means a device capable of receiving credentials. For example, a credential reader may receive credentials by being configured to receive, read, or scan them when the credentials are given to or presented to the credential reader. The credentials do not need to be in physical contact with the credential reader, and may be presented away from the credential reader. However, depending on the technology used to read or scan the credentials, the credentials may need to be in close proximity to the credential reader. The credential reader may be a card reader such as a magnetic card reader, an NFC reader, a keypad, or a biometric reader such as a fingerprint reader or a facial scanner. The device may also be an imaging device capable of taking an image of the credentials. Thus, the credential reader is a device through which credentials are input into an access control system. Furthermore, the credential reader may be a device configured to read a first credential carried by a mobile device, such as a smartwatch, using, for example, ultra-wideband technology. Such a credential reader may also be configured to read a second credential, which is biometric data from the mobile device. Such biometric data may be heart rate data that can be used to authenticate a host or visitor. The first and second credential may be used for multi-factor authentication of the host or visitor.

[0023] Where the term “resource controller” is used herein, it means a device configured to control access to a restricted physical resource. The resource controller is positioned to communicate with a credential reader. Furthermore, the resource controller may include, or communicate with, locking means configured to unlock access to the restricted physical resource to grant access to authorized persons, and to lock access to that restricted physical resource to prevent unauthorized persons from accessing that restricted physical resource. For example, if the restricted physical resource is a building or a room, the resource controller may be a door station including a credential reader, and the locking means may be a door lock.

[0024] Where the term “visitor” is used in this disclosure, it means any person who may request access to a restricted physical resource. Thus, a visitor may be a consumer, a person attempting to enter a restricted physical resource, or a person attempting to use it. Throughout this disclosure, the term “visitor” is used, but it should be understood that other terms such as consumer, requester, accesser, or user are equally applicable.

[0025] According to a second aspect of the present invention, the above objective is achieved by an access control system for handling access to a restricted physical resource. The access control system includes a first credential reader associated with a first restricted physical resource and configured to communicate with a first resource controller that controls access to the first restricted physical resource. The first credential reader is configured to receive initiating credentials for access requests that grant one or more visitors access to the first restricted physical resource, to inform the first resource controller about each received visitor credential, and to receive visitor credentials for each visitor to whom access has been requested. Furthermore, the access control system includes a second credential reader configured to communicate with the first resource controller and to receive finalizing credentials for access requests that grant one or more visitors access to the first restricted physical resource. The first resource controller is configured to allow a visitor to access a physical resource that is restricted to the first access when the visitor's visitor credentials are presented to the first credential reader.

[0026] According to a third aspect of the present invention, the above objective is achieved by a non-temporary computer-readable medium storing computer code instructions that, when executed by a device having processing capabilities, are adapted to carry out the method of the first aspect.

[0027] Second and third embodiments may generally have the same features and advantages as the first embodiment. Embodiments of the present invention are defined in the appended dependent claims. It should be further noted that the present invention relates to all possible combinations of features disclosed herein, unless otherwise expressly stated.

[0028] The above and further objects, features, and advantages of the present invention will be better understood through the following illustrative and non-limiting detailed description of embodiments of the present invention with reference to the accompanying drawings. Here, the same reference numerals are used for similar components.

Brief Description of the Drawings

[0029] [Figure 1] Schematically shows an access control system according to an embodiment. [Figure 2] An embodiment of an access control system is schematically shown as a centralized system including an access controller. [Figure 3] An embodiment of an access control system is schematically shown as a distributed system without an access controller. [Figure 4] It is a flowchart of a method for handling access to a physically restricted resource according to an embodiment. [Figure 5] It is a flowchart of a method for changing the access rights of a visitor to a physically restricted resource according to an embodiment.

Modes for Carrying Out the Invention

[0030] Before entering the detailed description of embodiments of the present invention, the following simple illustrative description is shown to provide a general understanding of the present invention.

[0031] Generally, the advantage of an access control system is whether the host can easily and dynamically grant access rights to new visitors and modify the granted access rights. According to the embodiments disclosed herein, the host may grant a visitor access to a particular set of resources for a specific period or on a specific day. The set of resources available to the visitor may be dynamically expanded and reduced. This gives the host a flexible way to automatically configure access control for visitors without knowing anything about how to configure the access control system in that way. For example, the host holds credentials that grant him / her the right to dynamically grant access to other credentials held by the visitor. To grant the visitor access to a particular resource, the host may initially present, for example, his / her credentials to a credential reader located at the physical resource where access is restricted. This may be seen as initiating a request to grant access. The host credentials may be configured with a command to inform the card reader that all credentials presented to the card reader after the host credentials have been presented, for example, all visitor credentials, are granted access to a specific restricted physical resource. Alternatively, the access control system may be configured to grant access to all credentials presented to the credential reader after the host credentials have been presented. Access may be valid for a specific period or for a specific number of accesses. Visitor credentials received by the credential reader may be added to a queue for addition to the access control system. Once all visitor credentials have been presented, for example, swiped, the host finalizes the request to grant access by presenting, for example, swiping the same or a different credential to the same or a different credential reader included in the access control system. The access control system recognizes this final credentials and adds these visitor credentials to the credentials authorized to grant access to the restricted physical resource.

[0032] When a visitor attempts to access a physical resource with restricted access, they present their credentials to a credential reader located at that resource, thereby granting them access to the restricted physical resource.

[0033] When a host guides visitors through a building, they may, in the manner described above, grant those visitors access to physical resources within the building that are otherwise restricted in access, as they reach them during their tour of the building. Those visitors can then access those restricted physical resources even without the host's escort. If a host realizes they have forgotten to grant a visitor access to a particular restricted physical resource, they can simply return to the credential reader at that resource and repeat the process of granting access to the visitor using the visitor's credentials.

[0034] A visitor may have access to a restricted physical resource that has been modified or removed by the same or similar procedure. For example, a host presents its credentials, and possibly another, to a credential reader at the restricted physical resource; then the host presents the visitor credentials that will be removed from access to that restricted physical resource; and finally the host presents its credentials, and possibly another, to the credential reader. Because the visitor credentials are known to the access control system, the access control system recognizes that a change in the visitor's access is being made. Preferably, one of the host credentials is accompanied by information about the desired change to be made. In response to receiving this information, the access control system performs the requested change. If this information is to remove the visitor from access, then the visitor's visitor credentials will be removed from access, and even if the visitor presents its visitor credentials to the credential reader, access to the restricted physical resource will be denied. If this information concerns a change in the period during which access should be permitted to a visitor, then the information regarding that visitor will be updated with the new period, and the visitor will only be permitted access to the physical resources whose access is restricted during that new period.

[0035] The host can use a credential reader to add and / or modify the right to access physical resources that are otherwise restricted, thus simplifying the handling of access rights.

[0036] The present invention will be described in further detail below with reference to the accompanying drawings. Hereinafter, embodiments of the present invention are shown.

[0037] Figure 1 schematically shows an exemplary embodiment of the access control system 100. The exemplary access control system 100 includes one or more resource controllers 101 and one or more credential readers 102. In the example shown herein, one or more credential readers 102 are associated with each of the restricted access physical resources 104 and are arranged to communicate with each of the resource controllers 101 configured to control access to each of the restricted access physical resources 104. In this disclosure, the restricted access physical resources 104 may be referred to as “restricted access resources” or simply “resources”.

[0038] One or more resource controllers 101 are generally referred to using reference number 101. The same is true when referring to only one of them, if it is not important to focus on a particular one. If the first, second, third, and fourth resource controllers are to be distinguished, then reference numbers followed by one, two, three, or four prime symbols (') are used, respectively. Thus, the reference number used for the first resource controller is 101', and the reference number used for the fourth resource controller is 101''''. The same is true for other reference numbers used here.

[0039] The resource controller 101 and the credential reader 102 may be contained within a single device and may be located very close to each other, but they may also be located far apart from each other, as long as they are arranged to communicate with each other.

[0040] In Figure 1, the first credential reader 102' is associated with the first restricted access physical resource 104', which in this example is floor level A of the building. As shown in the illustration, the first credential reader 102' is located at the outside entrance of the office on floor level A. The second credential reader 102'' is associated with the second restricted access physical resource 104'', which is exemplified as a repository for highly confidential documents, and the third credential reader 102'''' is associated with the third restricted access physical area 104''', which is exemplified as office space.

[0041] In the example shown here, the first, second, and third resource controllers 101', 101'', and 101''' are located on the first, second, and third restricted access physical resources 104', 104'', and 104'''' respectively, and communicate with one of the first, second, and third credential readers 102', 102'', and 102''' each. The first, second, and third resource controllers 101', 101'', and 101''' are configured to control access to the first, second, and third restricted access physical resources 104', 104'', and 104'''' respectively, based on the credentials received by one of the first, second, and third credential readers 102', 102'', and 102''' each. However, it should be understood that there does not need to be a one-to-one relationship between each resource controller, each credential reader, and each physical resource with restricted access. For example, one resource controller may be connected to multiple credential readers, and some of those credential readers may be associated with the same physical resource with restricted access.

[0042] One or more credential readers 102 are configured to read credentials and send each read credential to the resource controller 101 associated with it. The resource controller 101 may begin comparing the received credentials with the credentials included in a set of authorized credentials associated with the restricted physical resource 104. This comparison may be performed by the resource controller 101 or by an access controller, such as an access controller 118 connected to communicate with the resource controller 101, as described below. If a match is found, the resource controller 101 grants access to the restricted physical resource 104 to the visitor associated with the read credentials. Permission to enter the room may be granted, for example, by unlocking a locked door. If no match is found with the credentials, the resource controller 101 prevents the visitor associated with the read credentials from accessing the restricted physical resource 104, for example, by keeping a locked door locked.

[0043] In some embodiments, the credential reader 102 is configured to convert the read credentials into a Wiegand ID and send the Wiegand ID to the associated resource controller 101. In such embodiments, a set of authorized credentials associated with the restricted physical resource 104 includes a Wiegand ID, and the resource controller 101 or access controller 118 compares the received Wiegand ID with the Wiegand ID included in that set of authorized credentials. If a match is found, the visitor is granted access to the restricted physical resource 104; on the other hand, if no match is found, they are prevented from accessing the restricted physical resource 104.

[0044] As described above, each of the one or more restricted physical resources 104 may be a restricted area such as a building, room, office, or outdoor environment, or, depending on the current access control situation, each may be a restricted facility such as an electric vehicle charging station or computer-controlled equipment. As schematically shown in Figure 1, the illustrated access control system 100 also includes a fourth restricted physical resource 104'''' which is an electric vehicle charging station. In this example, the charging station is provided with a fourth resource controller 101'''' and a fourth credential reader 102''''.

[0045] Figure 1 also schematically illustrates two hosts 106, for example, a first host 106' and a second host 106'', and a visitor 110. This number of hosts is given as an example only, and it should be understood that this number of hosts could be just one host or more than two hosts. One or more hosts 106 are hosts to a number of visitors 110 who are granted access to the restricted physical resource 104. Anyone authorized to grant visitors access to the restricted physical resource 104 can be a host. Therefore, where the term “host” is used in this disclosure, it means any person authorized to grant visitors access to the restricted physical resource. For example, if the restricted physical resource is an office, the host may be an employee of that office who is authorized to grant visitors access to that office or a space within that office. As another example, if the physical resource with restricted access is an electric vehicle charging station, the host could be an attendant at the charging station who is authorized to grant access to the charging station so that a visitor, for example, the driver of an electric vehicle, can charge their electric vehicle.

[0046] When one or more visitors 110 are granted access to a restricted physical resource 104, a credentials 108 to initiate the access request is received by a first credential reader 102' associated with the first restricted physical resource 104'. The credentials 108 to initiate the access request are presented to the first credential reader 102' by a host 106, for example, the first host 106' or the second host 106''. The receipt of the credentials 108 to initiate the access request initiates a request to grant one or more visitors 110 access to the first restricted physical resource 104. Subsequently, the first credential reader 102 receives visitor credentials 112 for each visitor for whom access has been requested. This means that for each visitor to be granted access, each visitor's credentials must be presented to the first credential reader 102'. Once all visitor credentials 112 are presented, the request to grant access to those visitors is finalized by inputting a credential 108' to finalize the access request into the access control system 100. The credential 108' to finalize the access request is received by a second credential reader 102'' which is configured to communicate with the first resource controller 101'. The credential 108' to finalize the access request is presented to the second credential reader 102 by a host 106, for example, the first host 106' or the second host 106''. In some scenarios where a group of visitors has two hosts, one of the hosts 106, for example, the first host 106', may present the credentials 108 to the first credential reader 102' to initiate an access request, and the other host, for example, the second host 106'', may present the credentials 108' to the second credential reader 102'' to finalize the access request.

[0047] The first resource controller 101' is configured to allow visitor 110 to access the first restricted physical resource 104' after the request granting access has been finalized, provided that visitor 110's visitor credentials 112 are presented to the first credential reader 102'.

[0048] It should be understood that the second credential reader 102'' may be the same credential reader as the first credential reader 102'. Therefore, the first and second credential readers 102', 102'' may be a single credential reader. This may be the case when host 106 initiates and finalizes an access request using a single credential reader. For example, host 106 and visitor 110 may walk through a building containing several restricted physical resources 104. When they arrive at a restricted physical resource 104 where visitor 110 is granted access, host 106 presents the credential 108 that initiates the access request to the credential reader 102 located at the restricted physical resource 104. The host then presents the visitor credentials 112 of all visitors who are granted access to the same credential reader 102, followed by the credential 108' that finalizes the access request. Next, the received visitor credentials are added to a set of authorized credentials associated with the restricted access physical resource 104. When the visitor later presents his / her visitor credentials 112 to the credentials reader 102, the visitor is permitted to access the restricted access physical resource 104. Once access to one restricted access physical resource 104 is granted, the host 106 and the visitor 110 may continue their tour of the building on foot and may be similarly granted the right to access other restricted access physical resources 104.

[0049] Alternatively, the first and second credential readers 102, 102' may be two separate credential readers associated with the first restricted access physical resource 104', both of which are configured to communicate with the first resource controller 101'. This may be, for example, the first restricted access physical resource 104' being a room with two entrance doors. In such a case, the first credential reader 102' may be located at the first door, and the second credential reader 102'' may be located at the second door. Host 106 may present the credentials 108 initiating the access request and one or more visitor credentials 112 to the first credential reader 102' at the first door, and then walk through the room to the second door. At the second door, the host presents the credentials 108' finalizing the access request to the second credential reader 102''. This finalizes a request granting access to the room to one or more visitor credentials 112, and those visitor credentials are added to a set of authorized credentials for the room. This set of authorized credentials is preferably accessible by both the first and second credential readers 102', 102'', so that a visitor 110 can enter the room through one of those doors after presenting his / her visitor credentials to the credential readers 102', 102' located at that door.

[0050] Figure 1 also schematically illustrates how one or more resource controllers 101 are connected to communicate with a client 116 and / or an access controller 118 which may be connected to the network 114 via the network 114. The client 116 and / or access controller 118 may be located on-premises, i.e., in the same geographical location, as one or more restricted access physical resources 104, or geographically separated from one or more restricted access physical resources 104, i.e., at a distance from the geographical location(s) of one or more restricted access physical resources 104. Furthermore, the client 116 and access controller 118 may be located in separate geographical locations. There are many combinations of wireless and wired communication models that can be used for communication between the resource controller 101 and the network 114, and between the network 114 and the client 116 and / or access controller 118, and it should be understood that Figure 1 is merely one example.

[0051] Client 116 may have a display from which an operator, such as an administrator, can view information about visitors and hosts, the access rights granted to visitors, and information about one or more restricted physical resources accessed by a particular visitor. The operator may also be able to view the hosts that granted access to the visitor. Generally, client 116 is also connected to an access controller 118, where granted access rights may be stored and / or further processed. Client 116 may be used, for example, by an operator issuing control commands from client 116 to control the operation of resource controller 101. Furthermore, client 116 may be used by an operator to grant, revoke, and modify access rights. The operator may also use client 116 to group credential readers associated with restricted physical resources that visitors should have the same access rights to.

[0052] The access controller 118 may be a server configured to store and manage several sets of approved credentials issued to an individual. Such sets are also referred to here as the set of authorized credentials. In some access control systems, the access controller is called the access control server. In some embodiments, the access controller 118 is implemented as a management software module (MSM) configured to store and manage these sets of approved credentials issued to an individual.

[0053] Client 116 and / or access controller 118 may also be configured to communicate directly or indirectly with one or more resource controllers 101 via the network 114.

[0054] The access control system 100 may be deployed in various ways. The network topology of the access control system 100 may be, for example, centralized, decentralized, or distributed.

[0055] Figure 2 schematically shows an exemplary embodiment of an access control system 100, which is a centralized system including an access controller 118. As shown herein, the access controller 118 is centrally located in the access control system 100, and a plurality of resource controllers 101, for example, first, second, third, and fourth resource controllers 101', 101'', 101'''', 101'''' are arranged to communicate with the access controller 118. One or more resource controllers 101 are arranged to communicate with one or more credential readers 102 and are configured to control access to one or more restricted physical resources 104.

[0056] Figure 3 schematically shows an exemplary embodiment of the access control system 100 as a distributed system without an access controller 118. In this example, all resource controllers 101 are connected to communicate with one another. It should be understood that the access control system 100 may be a decentralized system (not shown) without an access controller 118. In a decentralized system, one of the resource controllers may be a master resource controller to which all the other resource controllers are connected for communication. In such a case, the other resource controllers may be called slave resource controllers.

[0057] In the examples shown in Figures 2 and 3, the resource controller 101 is shown as a rectangle, the credential reader 102 is shown as a square, and the physical resource 104 with restricted access is shown as a circle.

[0058] Furthermore, in Figures 2 and 3, the first resource controller 101' is configured to communicate with the first credential reader 102' and two second credential readers 102'', for example, the first second credential reader 102''-1 and the second second credential reader 102''-2. Both the first credential reader 102' and the first second credential reader 102''-1 are associated with the first restricted access physical resource 104', while the second second credential reader 102''-2 is associated with the second restricted access physical resource 104''. It should be understood that two separate credential readers may be associated with one identical restricted access physical resource. For example, this may be the case when a single building has two entrances, and each credential reader associated with that building is located at each entrance. It should be understood that a single resource controller may control access to several physical resources that have restricted access.

[0059] Furthermore, one or more other resource controllers, for example, a second resource controller 101'', a third resource controller 101''', and a fourth resource controller 101'''', are configured to communicate with one or more other credential readers associated with one or more other restricted access physical resources. For example, the second resource controller 101'' may be configured to communicate with one or more third credential readers 102'''' associated with one or more third restricted access physical resources 104'''.

[0060] The method for handling access to restricted physical resources, as performed by the access control system 100, is described below with reference to the flowchart in Figure 4. It should be understood that the method shown in Figure 4 may be performed by separate parts of the access control system 100, some of these actions may be arbitrary, and the actions may be performed in a different appropriate order.

[0061] Action 402 involves a first credential reader 102' associated with a first restricted access physical resource 104' receiving a credential 108 that initiates an access request, initiating a request to grant one or more visitors access to the first restricted access physical resource 104'. The first credential reader 102' is configured to communicate with a first resource controller 101' that controls access to the first restricted access physical resource 104'. As described above, a host 106, for example, the first host 106' or the second host 106'', presents the credential 108 that initiates the access request to the first credential reader 102', thereby allowing the first credential reader 102' to receive the credential that initiates the access request, for example, by reading or scanning it. This initiates a request to grant one or more visitors access to the first restricted access physical resource 104'. The first credential reader 102' may inform the first resource controller 101' that it is about to initiate a request to grant access.

[0062] In action 404, the first credential reader 102' receives visitor credentials 112 for each visitor for whom access has been requested. As also described above, a host 106, for example, the first host 106' or the second host 106'', presents the visitor credentials 112 for each visitor to the first credential reader 102', thereby receiving each visitor credential by, for example, reading or scanning it. Thus, by presenting the visitor credentials 112 sequentially, for example, one by one to the first credential reader 102', multiple visitor credentials 112 that grant them the same access to the first restricted physical resource 104' can be entered into the access control system 100 in a simple and efficient manner.

[0063] In action 406, a second credential reader 102'', which is configured to communicate with the first resource controller 101'', receives a credential finalizing access request 108'' which finalizes the request to grant one or more of those visitors 110 access to the first access-restricted physical resource 104''.

[0064] As also described above, host 106, for example, the first host 106' or the second host 106'', presents the credentials 108' for finalizing the access request to the second credential reader 102'', thereby the second credential reader 102'' receives the credentials 108' for finalizing the access request, for example, by reading or scanning it. This finalizes the request to grant one or more visitors access to the first restricted physical resource 104'. The first credential reader 102', which is included in or connected to the first resource controller 101', may inform the first resource controller 101' that the request to grant that access has been finalized and of the one or more visitor credentials 112 that were received. As a result, the first resource controller 101 has knowledge of the visitor credentials 112 and, when one of the visitor credentials 112 is presented to the first credential reader 102', it can grant access to the first access-restricted physical resource 104'.

[0065] As described above, the procedure of presenting credentials to a credential reader simplifies the process of initiating a request to grant access to a resource to one or more visitors, sending visitor credentials to be used by those visitors when access to that resource is requested, and similarly, finalizing the request.

[0066] As described below, the first certificate reader 102' and the second certificate reader 102'' may be one of the following: one identical certificate reader or two separate certificate readers.

[0067] Therefore, the first and second credential readers 102', 102'' may be a single credential reader 102 configured to receive both the credential 108 that initiates an access request and the credential 108' that finalizes the access request.

[0068] Alternatively, the first and second credential readers 102', 102'' are separate credential readers configured to communicate with the first resource controller 101'. The separate first and second credential readers 102', 102'' may be configured to receive both the credential 108 that initiates an access request and the credential 108' that finalizes the access request, but in a given access request scenario, one of them receives the credential 108 that initiates the access request and the other receives the credential 108' that finalizes the access request. The separate first and second credential readers 102', 102'' may be located in two separate locations on the first access-restricted physical resource 104'. This may be the case if the first access-restricted physical resource 104' has two points from which it is accessible. For example, these two points may be two doors to an area with restricted access. Alternatively, a first credential reader 102' may be located in a first restricted physical resource 104', and a second credential reader 102'' may be located in a second restricted physical resource 104'' controlled by a first resource controller 101'. This may be a restricted passageway where the first restricted physical resource 104' leads to a second credential reader 102'' located in the second restricted physical resource 104''.

[0069] When initiating and finalizing a request to grant access, the same credentials or two separate credentials may be presented to the credential reader and received thereby. Thus, the credentials 108 that initiates the access request and the credentials 108' that finalizes the access request may be one of the following: a single access credential associated with the first host 106' or the second host 106'', or two separate access credentials, each associated with only one person on either the first host 106' or the second host 106''. The first host 106' and the second host 106'' are authorized to grant one or more visitors 110 access to the first restricted physical resource 104'.

[0070] Access request credentials, namely the credentials 108 for initiating an access request and the credentials 108' for finalizing the access request, are associated with a host, for example, a first host 106' or a second host 106'', and are uniquely associated with that host in order to enable authentication of that host.

[0071] Furthermore, the credentials 108 that initiate an access request or the credentials 108' that finalize an access request may be received along with an indication of the total amount of permitted access to the first restricted physical resource 104' that is granted to one or more visitors 110.

[0072] An indication of the total amount of permitted access may be given to the credential reader as a separate entry after the credential that initiates or finalizes the access request has been received. For example, after presenting the credential that initiates or finalizes the access request, the host may: *123*1400#, this grants visitors access to the resource until 14:00 on the same day. *124*10#, this grants the visitor 10 days of access to the resource during business hours. *125*03 / 12#, This means visitors will be allowed access to the resource until December 3rd. You can enter strings like these, but these are just a few examples.

[0073] The string may be entered into a credential reader having some kind of keyboard or keypad.

[0074] Alternatively, an indication of the total amount of permitted access may be included in the credentials 108, 108' that initiate or finalize the received access request. Whenever such credentials are received by the credential reader 102, the credential reader 102 also receives the default total amount of permitted access. A host may have default or pre-configured credentials 108, 108' that initiate or finalize access requests to grant a specific total amount of access to a particular physical resource for which access is restricted. For example, the credential 108, 108' that initiate or finalize access requests for a host may be pre-configured to grant a visitor access to a hotel room for a specific number of days, and to grant that visitor access to the spa section for two hours each day. Furthermore, the credentials 108, 108' used to initiate or finalize access requests may be presented to the credential reader 102 multiple times, in a multiple corresponding to the number of times the credentials 108, 108' have been presented, in order to increase the total amount of access. Therefore, if the credentials 108, 108' used to initiate or finalize access requests are pre-configured to grant access for only one day, the host can present the credentials 108, 108' five times to grant the visitor a total amount of access for five days.

[0075] The total amount of permitted access may be given as one or more periods specifying only a certain number of times per day and / or a certain number of days over which access should be permitted. Alternatively or additionally, the total amount of permitted access may include the amount of usage or number of times access should be permitted. Of course, the total amount of permitted access may be other than those described above, depending on the physical resources being accessed and access restricted.

[0076] Multi-factor authentication In some embodiments, multi-factor authentication is performed, for example, multi-factor authentication of a host such as a first host 106' or a second host 106''. The term multi-factor authentication (MFA) encompasses two-factor authentication (2FA) and other multi-factor authentication techniques. MFA is an electronic authentication method in which the user is granted access to a physical resource whose access is restricted only after the successful presentation of two or more pieces of evidence (also called elements) to the authentication mechanism. The pieces of evidence are here referred to as credentials, and these may be knowledge, e.g., something only the user knows; possessions, e.g., something only the user possesses; and inherent traits, e.g., something only the user has.

[0077] In embodiments including multi-factor authentication, a first credential reader 102' or a second credential reader 102'' receives at least one first host credential 108a' associated with a first host 106', or at least one second host credential 108a' associated with a second host 106''.

[0078] Next, the first resource controller 101' or access controller 118 authenticates the first host 106' based on at least one first host credential 108a', which is a combination of at least one of the credential 108 that initiates the access request and the credential 108' that finalizes the access request.

[0079] Alternatively, the first resource controller 101' or access controller 118 authenticates the second host 106'' based on at least one second host credential 108a'', which is a combination of at least one of the credential 108 that initiates the access request and the credential 108' that finalizes the access request.

[0080] For example, at least one first host credential 108a' may include one or more credential certificates configured to authenticate a first host 106', and at least one second host credential 108a'' may include one or more credential certificates configured to authenticate a second host 106''.

[0081] In embodiments including multi-factor authentication, host 106 is only permitted to grant access to a visitor or modify access to a visitor if authentication using at least two separate credentials of the host is successful. If the host cannot be authenticated, one or more visitor credentials 112 presented to the first credential reader 101' are not granted access. The use of various credentials in the authentication process increases the certainty that the person presenting the credentials is indeed the host, compared to the case where only one credential is used to authenticate host 106.

[0082] Add visitor credentials to access controller 118. In some embodiments, a request is sent to an access controller 118 in the access control system 100 to add each received visitor credential 112 to a first set of authorized credential certificates. The first set of authorized credential certificates is associated with a first access-restricted physical resource 104' and a first credential reader 102'. If it is desirable to centrally aggregate and store information about authorized visitor credential certificates in the access control system 100, such a request may be sent. Such embodiments include action 408. In action 408, in response to a second credential reader 102'' receiving a credential 108' for which an access request is finalized, the first resource controller 101' sends a first request to the access controller 118 in the access control system 100 to add each received visitor credential 112 to a first set of authorized credential certificates associated with a first access-restricted physical resource 104' and a first credential reader 102'.

[0083] In addition to each received visitor credential 112, the first request may also include a request to add information about the host 106, such as a credential or other host identification document that authenticates the host.

[0084] Action 410 may add each received visitor credential 112 to the first set of authorized credential certificates.

[0085] In embodiments including action 408, the access controller 118 adds each received visitor credential 112 to a first set of authorized credential certificates. If the first request includes any host information, such information may also be added to the first set of authorized credential certificates. The first set of authorized credential certificates may be stored in the access controller 118, for example, in memory contained within the access controller 118, or in memory configured to communicate with the access controller 118. This can be seen as the access controller 118 adding visitor credential certificates that grant access to the first restricted physical resource 104' to central storage, because the access controller 118 is centrally located in the access control system 100. Once the access controller 118 adds the visitor credential certificates to the first set of authorized credential certificates, the access controller 118 may verify to the first resource controller 101' that the addition of each received credential certificate was successful. This may be done by an access controller 118 that sends a confirmation to a first resource controller 101' confirming that each received visitor credential 112 has been added. The first resource controller 101' may retain an instance or copy of the first set of authorized credentials even if the addition is made by the access controller 118. This allows the first resource controller 101' to determine whether a received visitor credential is included in the first set of authorized credentials without communicating with the access controller 118. Thus, even if there is downtime in communication between the first resource controller 101 and the access controller 118, the first resource controller 101' can allow or deny a particular visitor access to a physical resource whose access is restricted.Furthermore, if either the first resource controller 101' or the access controller 118 needs to be replaced due to a malfunction or other reason, the other of those controllers may have a copy of the first set of authorized credentials and send an instance of that first set of authorized credentials to the new first resource controller or the new access controller.

[0086] Add the visitor credentials to the first resource controller 101'. Alternatively or additionally, in some embodiments, action 410 includes the first resource controller 101' adding each received visitor credential 112 to a first set of authorized credentials associated with the first restricted access physical resource 104' and the first credential reader 102', in response to the first resource controller 101' receiving the credential 108' for which the second credential reader 102'' finalizes the access request. In addition to the received visitor credential, information about host 106 may also be added to the first set of authorized credentials. The first set of authorized credentials may be stored in the first resource controller 101', for example, in memory contained within the first resource controller 101', or in memory configured to communicate with the first resource controller 101'. This may be seen as the visitor credential 112 that grants access to the first restricted access physical resource 104' being added to local storage by the first resource controller 101'. This is because the first resource controller 101' is typically located at or very close to the first physical resource 104' whose access is restricted. This may also be referred to as them being located at the edge of the access control system 100.

[0087] In embodiments where a credential 108 initiating an access request or a credential 108' finalizing an access request is received along with an indication of the amount of access permitted, the first resource controller 101' or access controller 118 adds each received visitor credential 112 to the first set of permitted credentials, along with the indicated total amount of access permitted for each visitor. Thus, the first set of permitted credentials may include not only information about the visitor credentials and information related to possible hosts, but also information about the amount of access permitted for each visitor.

[0088] A visitor should have the same access rights to one or more second restricted resources 104'' controlled by the first resource controller 101' as to the first restricted physical resource 104' controlled by the first resource controller 101'. In some embodiments, the first credential reader 102' belongs to a group of credential readers, which, in addition to the first credential reader 102', includes one or more second credential readers 102'' associated with one or more second access-restricted physical resources 104'' controlled by the first resource controller 101', and it may be determined that a visitor(s) should have the same access rights to one or more of those second access-restricted physical resources 104''. This may be the case for both embodiments including action 408 and embodiments not including action 408. Thus, visitor information contained in the first set of authorized credentials may be added to one or more second sets of authorized credentials associated with the second credential readers 102'' included in the group of credential readers. In such embodiments, action 410 may further include the first resource controller 101' or access controller 118 determining that the first credential reader 102' is included in a group of credential readers. The group of credential readers also includes one or more second credential readers 102'' associated with one or more second access-restricted physical resources 104'' to which one or more visitors 110 are permitted access. One or more second credential readers 102'' included in the group of credential readers are arranged to communicate with the first resource controller 101' which controls access to one or more second access-restricted physical resources 104'' to which one or more visitors 110 are permitted access.The first resource controller 101' or access controller 118 stores the information in the first set of authorized credentials relating to one or more visitors 110, in addition to one or more second sets of authorized credentials, where each second set of authorized credentials is associated with each second access restricted physical resource 104'' among one or more second access restricted physical resources 104'' and is associated with each second credential reader 102'' included in the credential reader of that group.

[0089] Action 412 may, in some embodiments, activate an indication that each received visitor credential 112 has been added in response to the first credential reader 102' or the second credential reader 102'' successfully adding one or more visitor credential 112. This may indicate to the host 106 that it has successfully added the visitor credential 112 of the visitor to whom he / she intends to grant access to its set of authorized credential 112. This indication may be a visible indication such as a light that lights up or flashes, or a text message displayed on a screen, an audible indication such as a beep, or a combination of a visible and an audible indication.

[0090] Action 414 allows the first resource controller 101' to access the first access-restricted physical resource 104' when the visitor 110's visitor credentials 112 are presented to the first credential reader 102'.

[0091] In some embodiments, action 414, which allows a visitor to access a first restricted physical resource 104', further includes allowing visitor 110 to access the first restricted resource 104' if the visitor's presented visitor credentials 112 are included in a first set of permitted credentials.

[0092] As described above, the second credential reader 102'' may be located at the first access-restricted physical resource 104'. In such a scenario, the first resource controller 101' may allow the visitor 110 to access the first access-restricted physical resource 104' when his / her visitor credentials 112 are presented to the second credential reader 102''.

[0093] In some embodiments, visitor credentials 112 are added to a first set of authorized credentials along with the indicated total amount of authorized access. Subsequently, the first set of authorized credentials includes the total amount of authorized access for each visitor. In such embodiments, allowing visitor 110 to access a first restricted physical resource 104' further includes allowing visitor 110 to access the first restricted physical resource 104' only if the amount of authorized access is within the total amount of authorized access for the visitor. Furthermore, in such embodiments, the total amount of authorized access for a visitor may be updated with the remaining total amount of authorized access, if applicable. This update may be applicable, for example, when a visitor is granted permission to enter a room or building a certain number of times, and therefore the total amount of authorized access for a visitor must be updated with the remaining number of times each time the visitor enters that room or building. As another example, if a visitor is granted permission to access a charging station a certain number of times, or to use the charging station to charge his / her car by a certain amount of electricity, the total amount of permitted access for the visitor must be updated accordingly after each access to the charging station. Updating the total amount of permitted access may be done by a first resource controller 101' or access controller 118, depending on whether one of these two controls a first set of permitted credentials. However, if the total amount of permitted access is given as a period, for example, two days, it is not necessary to update the total amount of permitted access each time the visitor accesses the station, because the period does not change. In such cases, it may not be applicable to update the total amount of permitted access.

[0094] A visitor should have access rights to one or more third restricted resources 104'' controlled by the second resource controller 101'', similar to access rights to the first restricted physical resource 104' controlled by the first resource controller 101'. Under action 410 above, we described how the authorized credentials included in the first set of authorized credentials are added to one or more second sets of authorized credentials associated with one or more second access-restricted physical resources 104'' when those one or more second access-restricted physical resources 104'' are controlled by the first resource controller 101'. Actions 416 to 420 below describe how the authorized credentials included in the first set of authorized credentials are added to one or more third sets of authorized credentials associated with one or more third access-restricted physical resources 104'''' when those one or more third access-restricted physical resources 104'''' are controlled by one or more second resource controllers 101'' other than the first resource controller 101'.

[0095] Action 416 receives a credential 108 that initiates an access request, initiating a request for a third credential reader 102''' associated with the third restricted access physical resource 104''' to grant one or more visitors 110 access to the third restricted access physical resource 104''' in addition to the first restricted access physical resource 104'''. The third restricted access physical resource 104''' is configured to communicate with the third credential reader 102''' and is controlled by a second resource controller 101'' separate from the first resource controller 101''.

[0096] In action 418, the second resource controller 101'' sends a second request to the access controller 118, adding information about the visitor access previously granted using the credentials 108 that initiated the access request to the third set of authorized credentials associated with the third physical resource 104''' whose access is restricted.

[0097] When the second request is received by the access controller 118 within a predetermined period after the first request is received, the access controller 118 adds the previously added visitor access information to the second / third set of authorized credentials in action 420. The first request is sent as described in action 408 above.

[0098] The information to be added may be information about visitor credentials included in the first set of authorized credentials. Information about the total amount of access granted to each visitor may be added. Optionally, information about the host(s)¹⁶ granted access in the first set of authorized credentials may be added. Such host information may be related to the credentials used to authenticate that host.

[0099] Change visitor access permissions The methods used by the access control system 100 to handle access to restricted physical resources may include one or more additional actions relating to how to modify a visitor's access rights, as described above in relation to Figure 4. These actions are described below with reference to Figure 5. It should be understood that the methods shown in Figure 5 may be performed by separate parts of the access control system 100.

[0100] For example, in some first embodiments, some of these actions may be performed by a first or second credential reader 102', 102'' configured to communicate with a first resource controller 101'. This may be the case where the credential reader 102 used to grant access to a visitor is also used to modify the access rights granted to the visitor.

[0101] As another example, in some second embodiments, some of these actions may be performed by a second resource controller 101'' or by a third credential reader 102'''' which is not configured to communicate with the first resource controller 101'' but is configured to communicate with the second resource controller 101''. The second resource controller 101'' may be configured to communicate with, for example, an access controller 118 if the access control system 100 is a centralized system, or with the first resource controller 101' if the access control system 100 is a distributed system. Some second embodiments may be applicable when the credential reader used to grant access to a visitor and the credential reader used to modify the access rights granted to a visitor are separate credential readers.

[0102] Furthermore, it should be understood that some of these actions may be optional, and that the actions may be performed in a different, appropriate order.

[0103] Action 502 receives an access change initiation credentials 108'' which initiates a request to change a visitor's access to a physical resource 104' for which access is restricted in the first instance. In some first embodiments, a first or second credential reader 102', 102'' receives the access change initiation credentials 108''. In some second embodiments, a third credential reader 102'''' receives the access change initiation credentials 108''. The access change initiation credentials 108'' is received along with information about the changes to be made. For example, this information may relate to a new period for which access should be permitted, or a new total amount of access to be permitted. This may be when a previously given period has expired and a new period is required, or when the previously given total amount of permitted access has been consumed and a new total amount of permitted access is required. Alternatively, this information may relate to the removal of granted access. The access change initiation credentials 108'' may be the same credentials as the access request initiation credentials 108''. Therefore, a host may use the same credentials when initiating a request to grant access and when initiating a request to modify the granted access. When the same credentials are used, the access control system interprets them as the credentials to initiate an access request if the subsequent visitor credentials are unknown to the access control system, and as the credentials to initiate an access modification if the subsequent visitor credentials are known to the access control system.

[0104] In action 504, the visitor credentials 112 of the given visitor are received. In some first embodiments, a first or second credentials reader 102', 102'' receives the visitor credentials 112 of the given visitor. In some second embodiments, a third credentials reader 102'' receives the visitor credentials 112 of the given visitor.

[0105] Action 506 receives a credential certificate 108'''' to finalize the access change, which finalizes the request to modify the access of a given visitor. In some first embodiments, a first or second credential reader 102, 102' receives the credential certificate 108'''' to finalize the access change. In some second embodiments, a third credential reader 102'' receives the credential certificate 108'''' to finalize the access change. The credential certificate 108'''' to finalize the access change may be the same credential certificate 108' to finalize the access request. Thus, a host may use the same credential certificate when finalizing the request to grant access and when finalizing the request to modify the given access. As described above, the credential certificate 108 that initiates an access request and the credential certificate 108 that finalizes the access request may be the same credential certificate. Therefore, the credentials 108'' that initiate the access change and the credentials 108''' that finalize the access change may also be the same credentials as the credentials 108 that initiate the access request and the credentials 108 that finalize the access request.

[0106] Information regarding the changes to be made may be provided as a separate entry given to the credential reader after the credential to initiate or finalize the access change is received. For example, after presenting the credential to initiate or finalize the access change, the host may enter a string. Alternatively, an indication of the total amount of permitted access may be included in the received credential to initiate or finalize the access change 108'', 108''''. Each time such a credential is received by the credential reader, the credential reader also receives the default changes to be made. The credential to initiate or finalize the access change 108'', 108'''' may be predetermined or pre-configured to change access to a physical resource whose access is restricted by a specific amount, either up or down. For example, the credential to initiate or finalize the access change 108'', 108'''' may be pre-configured to change access rights by a specific number of days or hours, e.g., increasing or decreasing them, or to change the date on which access is permitted. As another example, the credentials 108'', 108''' used to initiate or finalize an access change may be pre-configured to revoke access rights.

[0107] Action 508 sends a request from the second resource controller 101'' to the access controller 118 or to the first resource controller 101'' to change a given visitor's access to the first restricted physical resource 104'. For example, in a centralized system, the access controller 118 may store a first set of authorized credentials, and therefore the access controller 118 needs to be informed of the requested change, while the first resource controller 101' needs to be informed if the access control system 100 is a distributed system.

[0108] Action 510 updates the first set of authorized credentials with the requested change in the access of a given visitor to the first restricted physical resource 104. In some first embodiments, the first resource controller 101' or access controller 118 updates the first set of authorized credentials. In some second embodiments, the access controller 118 updates the first set of authorized credentials. The access controller 118 may update the first set of authorized credentials directly or indirectly by sending the update to the first resource controller 101' that updates the first set of authorized credentials.

[0109] Embodiments also relate to an access control system 100 for handling access to a restricted physical resource. The access control system 100 includes a first credential reader 102' which is associated with a first restricted physical resource 104' and is configured to communicate with a first resource controller 101' which controls access to the first restricted physical resource 104'. The first credential reader 102' It is configured to receive a credentials 108 that initiates an access request, which grants one or more visitors access to a first restricted physical resource 104'. The system is configured to receive a visitor credentials certificate 112 for each visitor who requests access.

[0110] Furthermore, the access control system 100 includes a second credential reader 102'' configured to communicate with a first resource controller 101' and to receive a credential finalizing access request 108' that finalizes a request to grant one or more visitors 110 access to a first access-restricted physical resource 104'.

[0111] Furthermore, the first resource controller 101' is configured to allow a visitor 110 to access a first access-restricted physical resource 104' when the visitor's visitor credentials 112 are presented to the first credential reader 102'.

[0112] Embodiments also relate to non-temporary computer-readable media that store computer code instructions adapted to perform one of the actions described in this disclosure when executed by a device having processing capabilities.

[0113] As described above, the access control system 100, for example, one or more components of the access control system 100, may be configured to implement methods for handling access to the physical resource 104 whose access is restricted. For this purpose, the access control system 100 may include circuits configured to perform the various actions described in this disclosure.

[0114] In hardware implementations, this circuit may be dedicated to performing one or more of these actions, and may specifically be designed to do so. This circuit may be in the form of one or more integrated circuits, such as one or more application-specific integrated circuits or one or more field-programmable gate arrays. For illustrative purposes, the access control system 100 may therefore include circuitry that, when in use, receives access request initiation credentials 108 to initiate a request granting one or more visitors access to the first access-restricted physical resource 104'. The access control system 100 may further include circuitry that, when in use, receives visitor credentials 112 for each visitor whose access has been requested. Furthermore, the access control system 100 may, when in use, receive access request finalization credentials 108' to finalize the request granting one or more visitors 110 access to the first access-restricted physical resource 104'. The access control system 100 may further include a circuit that, when in use, allows a visitor 110 to access a physical resource 104' whose access to a first restricted resource when the visitor's visitor credentials 112 is presented to the first credential reader 102'.

[0115] In a software implementation, this circuit may instead be in the form of one or more processors, such as one or more microprocessors, that cause the access control system 100 to perform one or more of the actions disclosed herein in association with computer code instructions stored on a (non-temporary) computer-readable medium, such as non-volatile memory. Examples of non-volatile memory include read-only memory, flash memory, ferroelectric random-access memory (RAM), magnetic computer storage devices, optical disks, and the like. In the case of software, each of the above actions may therefore correspond to a part of a computer code instruction stored on a computer-readable medium, which, when executed by one or more processors, causes the access control system 100 to perform any of the methods disclosed herein.

[0116] It will be understood that a combination of hardware and software implementations is also possible. This means that some actions are performed in hardware, while others are performed in software.

[0117] Those skilled in the art will understand that the above embodiments can be modified in many ways, and the advantages of the present invention, as shown in the above embodiments, can still be used. The present invention should therefore not be limited to the embodiments shown herein, but should be defined solely by the claims. Furthermore, as those skilled in the art will understand, the embodiments shown herein can also be combined.

Claims

1. A method for handling access to a physical resource with restricted access, which is performed in an access control system (100), comprising: Receiving (402), by a first certificate reader (102') associated with a first physically restricted resource (104'), a certificate (108) starting an access request, wherein the certificate (108) starting the access request is for one or more visitors to start a request for access to the first physically restricted resource (104'), and the first certificate reader (102') is arranged to communicate with a first resource controller (101') controlling access to the first physically restricted resource (104'), receiving (402) the certificate (108) starting the access request; Receiving, by the first certificate reader (102'), a visitor certificate (112) for each visitor for whom access is requested, and notifying (404) the first resource controller (101') of each received visitor certificate (112); Receiving (406), by a second certificate reader (102'') arranged to communicate with the first resource controller (101), a certificate (108') finalizing the access request, wherein the certificate (108') finalizing the access request is for the one or more visitors (110) to finalize the request for access to the first physically restricted resource (104'), receiving (406) the certificate (108') finalizing the access request; Authorizing (414), by the first resource controller (101'), the visitor (110) to access the first physically restricted resource (104') when the visitor certificate (112) of the visitor (110) is presented to the first certificate reader (102'); A method comprising the above.

2. The first certificate reader (102') and the second certificate reader (102'') are: The same single certificate reader; One of two separate credential readers and The method according to claim 1, which is one of them.

3. The credential (108) that initiates the access request and the credential (108') that finalizes the access request are A single access credential associated with the first host (106') or the second host (106''), and Two separate access credentials, each of which is associated with only one of the first host (106') and the second host (106''), and Is one of them, The first host (106') and the second host (106'') are granted the right to provide the one or more visitors (110) with access to the physical resource (104') to which the first access is restricted. The method according to claim 1.

4. In response to the second credential reader (102'') receiving the credential (108') that finalizes the access request, the first resource controller (101') further includes adding each received visitor credential (112) to a first set of permitted credentials associated with the physical resource (104') to which the first access is restricted and the first credential reader (102') (410). The method according to claim 1.

5. In response to the second credential reader (102'') receiving the credential (108') that finalizes the access request, the first resource controller (101') sends a first request to the access controller (118) included in the access control system (100) to add each received visitor credential (112) to a first set of permitted credentials associated with the physical resource (104') to which the first access is restricted and the first credential reader (102') (408); and Adding each received visitor credential (112) to the first set of permitted credentials by the access controller (118) (410); and The method according to claim 1, further comprising.

6. In response to successfully adding one or more of the visitor certificates (112), further including activating an indication (412) by the first certificate reader (102') or the second certificate reader (102'') indicating that each received visitor certificate (112) has been added, the method according to claim 4.

7. Saying yes to the visitor (110) accessing the physically restricted resource (104') where the first access is restricted (414) further includes allowing the visitor (110) to access the restricted resource (104') where the first access is restricted when the presented visitor certificate (112) of the visitor is included in the first set of permitted certificates, the method according to claim 4.

8. The certificate (108) starting the access request or the certificate (108') finalizing the access request is received together with an indication of the total amount of permitted access to the physically restricted resource (104') where the first access is restricted for the one or more visitors (110), Saying yes to adding each received visitor certificate (112) to the first set of permitted certificates (410) further includes adding the indicated total amount of the permitted access for each visitor, Saying yes to the visitor (110) accessing the physically restricted resource (104') where the first access is restricted (414) further includes allowing the visitor (110) to access the physically restricted resource (104) where the first access is restricted only if the amount of access permitted is within the total amount of the permitted access of the visitor, The method further includes updating, if applicable, the total amount of the permitted access of the visitor with the remaining total amount of the permitted access, The method according to claim 7.

9. Receiving, by the first credential reader (102') or the second credential reader (102''), a credential (108'') for initiating an access change that initiates a request to change the visitor's access to a physical resource (104') whose first access is restricted (502); Receiving, by the first credential reader (102') or the second credential reader (102''), the visitor's visitor credential (112) provided (504); Receiving, by the first credential reader (102') or the second credential reader (102''), a credential (108''') for finalizing an access change that finalizes the request to change the provided visitor's access (506); Updating the first set of permitted credentials with the requested change to the provided visitor's access (510); The method according to claim 4, further comprising.

10. Said adding each received visitor credential (112) to the first set of permitted credentials (410) comprises: Determining, by the first resource controller (101') or the access controller (118), that the first credential reader (102') is included in a group of credential readers, the group of credential readers also including one or more second credential readers (102'') arranged to communicate with the first resource controller (101'), the one or more second credential readers (102'') being associated with one or more second physically restricted resources (104'') to which the one or more visitors (110) are permitted access; Adding, by the first resource controller (101') or the access controller (118), information stored in the first set of permitted credentials regarding the one or more visitors (110) to one or more second sets of permitted credentials; further comprising; Here, each permitted certificate of the second set is associated with each physically restricted resource (104'') where the one or more second accesses are restricted, and is associated with each second certificate reader (102'') included in the group of the certificate readers. The method according to claim 4. **Claim 11**: A third certificate reader (102''') associated with a physically restricted resource (104''') with restricted third access causes the one or more visitors (110) to start a request for access to the physically restricted resource (104''') with restricted third access in addition to the physically restricted resource (104') with restricted first access. Receiving a certificate (108) for starting the access request (416), where the physically restricted resource (104''') with restricted third access is arranged to communicate with the third certificate reader (102'''), and is controlled by a second resource controller (101'') different from the first resource controller (101'), receiving a certificate (108) for starting the access request (416), and sending, by the second resource controller (101''), a second request to the access controller (118) to add information regarding the visitor access previously added using the certificate (108) for starting the access request to the third set of permitted certificates associated with the physically restricted resource (104''') with restricted third access (418); when the second request is received by the access controller (118) within a predetermined period from the reception of the first request, adding, by the access controller (118), the information regarding the visitor access previously added to the third set of permitted certificates (420); The method according to claim 5, further comprising. **Claim 12** Receiving (502) a certificate of authorization (108'') to initiate a request to change the visitor's access to a physical resource (104') whose first access is restricted, by the third certificate reader (102'''); Receiving (504) the visitor's certificate of authorization (112) provided by the third certificate reader (102'''); Receiving (506) a certificate of authorization (108''') to finalize the request to change the provided visitor's access to the physical resource (104') whose first access is restricted, by the third certificate reader (102'''); Sending (508) by the second resource controller (101'') to the access controller (118) or to the first resource controller (101'), the request to change the provided visitor's access to the physical resource (104') whose first access is restricted; Updating (510) by the access controller (118) or the first resource controller (101') the first set of permitted certificates with the requested change of access of the provided visitor (110) to the physical resource (104') whose first access is restricted; The method according to claim 11, further comprising. **Claim 13** Receiving, by the first certificate reader (102') or the second certificate reader (102''), at least one first host certificate of authorization (108a) associated with a first host (106') or at least one second host certificate of authorization (108a') associated with a second host (106''); By the first resource controller (101') or the access controller (118), Authenticating the first host (106') based on the at least one first host certificate of authorization (108a) in combination with at least one of the certificate of authorization (108) to initiate the access request and the certificate of authorization (108') to finalize the access request, or authenticate the second host (106'') based on at least one second host certificate (108a') in combination with at least one of the certificate (108) for initiating the access request and the certificate (108') for finalizing the access request The method according to claim 1, further comprising: [

14. ] An access control system (100) for handling access to a physically restricted resource, comprising: a first certificate reader (102'), which is associated with a first physically restricted resource (104') and is arranged to communicate with a first resource controller (101') that controls access to the first physically restricted resource (104'), and the first certificate reader (102') is configured to receive a certificate (108) for initiating an access request, where the certificate (108) for initiating the access request is for one or more visitors to initiate a request for access to the first physically restricted resource (104'), receive a visitor certificate (112) for each visitor for whom access has been requested and is further configured to notify the first resource controller (101') of each received visitor certificate (112) and the access control system (100) further comprises: a second certificate reader (102''), which is arranged to communicate with the first resource controller (101') and is configured to receive a certificate (108') for finalizing the access request, where the certificate (108') for finalizing the access request is for the one or more visitors (110) to finalize the request for access to the first physically restricted resource (104') The first resource controller (101') is configured to permit a visitor (110) to access a physical resource (104') to which the first access is restricted when the visitor's visitor credential (112) is presented to the first credential reader (102'). An access control system (100).

15. A non-transitory computer-readable medium storing computer code instructions adapted to implement the method according to any one of claims 1 to 13 when executed by a device having processing capabilities.