Ultra-wide band device for access control reader system
The integration of an ultra-wideband module into access control systems addresses the challenges of secure and efficient authentication and authorization, enhancing security and reducing interference and fading issues.
Patent Information
- Application Number
- JP2025044169
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2019-09-27
- Filing Date
- 2025-03-19
- Publication Date
- 2025-06-12
- Estimated Expiration
- 2040-03-24
AI Technical Summary
Existing access control systems face challenges in providing secure and efficient authentication and authorization processes, particularly in environments where traditional credential methods may be inadequate.
The integration of an ultra-wideband (UWB) module into access control systems, which utilizes short, low-power pulses over a wide frequency spectrum for secure communication and ranging, enabling enhanced authentication and authorization processes.
The UWB module enhances the security and efficiency of access control systems by providing robust authentication and authorization mechanisms, reducing interference with other communication systems, and offering improved resistance to multipath fading.
Smart Images

Figure 2025089361000001_ABST
Abstract
Description
Technical Field
[0001] Embodiments of the present disclosure generally relate to access control systems, and more particularly, to embodiments of ultra-wideband (UWB) devices for access control systems.
Background Art
[0002] Physical access control covers various systems and methods for controlling access by people, for example, to protect an area or an asset. Physical access control is used to protect an area or the operation of a control mechanism, such as a physical or electronic / software control mechanism, that allows access to an asset in a protected state, and includes the identification of authorized users and / or devices (such as vehicles, drones, etc.) and the operation of gates, doors, or other mechanisms. A PACS may include a reader (such as an online or offline reader) that has the ability to hold authorization data and determine whether credentials (such as from a radio frequency identification (RFID) chip in a personal electronic device such as a card, fob, or mobile phone) from a credential or credential device are authorized for an actuator (such as a door lock, door opener, software control mechanism, alarm turn-off, etc.). In other examples, a PACS may include a host server to which a reader and / or an actuator (such as via a controller) are connected in a centrally managed configuration. In a centrally managed configuration, the reader can obtain credentials from a credential or credential device and transmit those credentials to the PACS host server. The host server can then determine whether the credentials authorize access to the protected area and, correspondingly, can instruct the actuator or other control mechanism.
Brief Description of the Drawings
[0003] A more detailed understanding can be obtained from the following description, which presents examples in the context of the following drawings where the same reference numerals are used across the drawings in relation to the same elements.
Figure 1
Figure 2
Figure 3A
Figure 3B
Figure 4
Figure 5A
Figure 5B
Figure 5C
Figure 5D
Figure 5E
Figure 5F
Figure 5G
Figure 6
[0004] Disclosed herein are embodiments of an ultra-wideband (UWB) module for an access control system. The UWB module is described herein in the context of a physical access control system (PACS), but can be used in any other type of access control system. UWB is a radio frequency (RF) technique that uses short, low-power pulses over a wide frequency spectrum. The pulses can be generated at levels of millions of times per second. The width of the frequency spectrum of a given UWB implementation generally exceeds the smaller of 500 megahertz (MHz) and 20 percent of the arithmetic center frequency of the frequency spectrum of the given UWB implementation.
[0005] UWB can be used for communication by encoding data via time modulation (e.g., pulse position encoding). Here, a symbol is defined by a pulse on a subset of time units from a set of available time units. Other examples of types of UWB encoding include amplitude modulation and polarity modulation. Wideband transmission tends to be more stable against multipath fading than carrier-based transmission techniques. Furthermore, the relatively small power of the pulse at any given frequency also tends to reduce interference with carrier-based communication techniques.
[0006] FIG. 1 shows an exemplary situation 100 in which a PACS according to at least one embodiment can be used. As shown in FIG. 1, a wall 102 houses a door 104 inside. In one exemplary situation, the protected area is located behind the door 104, and the door 104 has a lockable handle 106. When the lockable handle 106 is in an unlocked state, it grants access to the protected area, and when it is in a locked state instead, it prevents access to the protected area.
[0007] A reader system 108 is disposed near the handle 106 of the door 104. In one embodiment, the handle 106 must be in a locked state as its default state. The reader system 108 is operable to selectively place the handle 106 in an unlocked state in response to the presentation of an authorized credential housed within a credential device 112, and the credential device 112 can communicate with the reader system 108 via a wireless interface 110. In various different embodiments, the credential device 112 can be a key card, a fob, a mobile device (e.g., a smartphone), and / or any other suitable credential device having communication capabilities and credentials to implement the embodiments of the present disclosure, or can include this.
[0008] It should be understood that the present disclosure is applicable to a number of types of PACS used to protect a number of types of areas and / or other resources, assets, and / or the like similar thereto. The situation 100 of FIG. 1 is presented for purposes of illustration only, not limitation.
[0009] FIG. 2 shows an exemplary communication context 200 in which the PACS of FIG. 1 (e.g., including the reader system 108) according to at least one embodiment can operate. As shown in FIG. 2, the reader system 108 can be communicatively connected to the network 202 via a communication link 204. Further, the server 208 can be communicatively connected to the network 202 via a communication link 206. In the present disclosure, the communication link can include one or more wireless communication links and / or one or more wired communication links, and can include one or more intermediate devices such as an access point, a network access server, a switch, a router, a bridge, and / or the like. Further, the network 202 can be a data communication network such as an Internet Protocol (IP) network and / or one or more communication networks of any other type, or can include this.
[0010] The server 208 can perform one or more functions of the reader system 108 such as authorization, authentication, and / or the like. In some embodiments, the reader system 108 may be performing functions locally, perhaps as a stand-alone unit involving communication with one or more other devices, systems, servers, and / or the like, for example, via a Local Area Network (LAN). The server 208 can include a communication interface, a processor, and data storage that houses instructions executable by the processor to perform the functions of the server 208.
[0011] FIG. 3A shows an exemplary architecture 300 of a reader system 108 according to at least one embodiment. As shown in FIG. 3A, reader system 108 may include a reader 302 and a UWB module 304 communicatively connected to each other via a communication link 306. The communication link 306 may be wired or wireless. In one example, the communication link 306 is a BLE communication link. In some embodiments, the reader 302 is equipped and configured to use wireless communication such as NFC and / or Bluetooth (registered trademark) (e.g., Bluetooth Low Energy (registered trademark) (BLE)) to communicate with a credential device and to selectively place the handle 106 in an unlocked state in response to the presentation of an authorized credential included within the credential device (e.g., credential device 112).
[0012] The reader 302 can include a wireless communication interface to communicate according to NFC, BLE, and / or the like, and may also include a wired communication interface to communicate according to a Universal Serial Bus (USB) connection, an Ethernet (registered trademark) connection, and / or the like. Further, the reader 302 may include a processor and a data storage including instructions executable by the processor to perform the functions of the reader 302.
[0013] In some embodiments, the reader 302 is installed and in use before the UWB is connected as an add-on module. In other embodiments, the reader 302 and the UWB module 304 are installed together as (or as at least a part of) the reader system 108. The UWB module 304 can be connected via a communication link 306 to an existing hardware port (or an expansion port, expansion slot, or the like) of the reader 302. In some embodiments, the communication link 306 is or includes a data cable. Further details regarding an exemplary architecture of the UWB module 304 are provided below in connection with FIGS. 5A-5G.
[0014] In one example, a user carrying a credential device can approach the reader system 108. When the credential device arrives within the threshold range of the reader system 108, the credentials can be exchanged, for example, by using Bluetooth Low Energy (BLE). This credential exchange can be coordinated, for example, using the reader 302. The reader 302 can then establish a secret, such as a scrambled timestamp (STS), with the credential device to enable ranging using UWB communication. The UWB ranging can be performed, for example, using the UWB module 304. This can operate upon receipt of data from the reader 302. The data can include identifiers of credentials such as STS, PACS-ID, and the like. By using ranging, one or more of the reader 302 or the UWB module 304 can be used to derive the user's intent to identify an intended trigger. Once the intended trigger is identified, the reader 302 can grant the credentials to allow access to the user.
[0015] The UWB module may include a battery 308 or other types of local power sources including an energy harvester, a capacitor, and the like. The battery 308 can be used to supply power for the UWB module 304 so that the UWB module 304 does not need to receive power from the reader system 108, the door lock battery, or any other external power source. This can save power for the reader system 108 and may be advantageous because it is easier to replace the battery in the detachable UWB module than any other battery in the reader system 108.
[0016] FIG. 3B shows another exemplary architecture 350 of the reader system 108 according to at least one embodiment. As shown in FIG. 3B, the reader system 108 may include a reader 352 that may include a UWB module 354 that itself includes a battery 356 (e.g., as an on-board module, component, or the like). In one embodiment, the UWB module 354 is implemented as an integrated circuit (IC) plugged into the substrate (e.g., the main motherboard) of the reader 352.
[0017] Generally, the reader 352 can be similar to the reader 302 of FIG. 3A, and thus, a detailed description is omitted here. Similar to the architecture 300 described above in connection with FIG. 3A, in the case of the architecture 350 of FIG. 4, the reader 352 can also be a pre-installed reader in a state where the UWB module 354 is added later, or the reader 352 and the UWB module 354 may be associated with a common co-installation as the reader system 108 (or at least a part thereof).
[0018] FIG. 4 shows another exemplary architecture 400 of the reader system 108. The reader system 108 includes a reader 400 and a UWB module 402 configured to communicate over a communication link 404. The communication link may be wired or wireless. For example, the reader 400 can be configured to communicate with the UWB module 402 using BLE. The reader 400 includes a controller 406, antennas 408a - 408c, a secure element 410, an NFC-IC 412, an RFID IC 414, a sensor 416, a flash memory 418, a keypad 420, and interfaces 422 and 424. The controller 406 may be a BLE-SoC microcontroller or any other type of control circuit. The controller 406 may be capable of NFC communication through the NFC-IC 412 and the antenna 408a. The controller may be capable of BLE communication using the antenna 408b and may also be capable of RFID communication through the RFID-IC 414 and the antenna 408c. The interfaces 422 and 424 may be Wiegand interfaces and RS485 interfaces or any other interface type. The secure element 410 can be configured to cache protected state data such as STS, PACS-ID, and the like. The components of the reader 400 can be housed within a first housing.
[0019] The UWB module 402 includes a controller 426, antennas 428a and 428b, a battery 430, a secure element 432, and a UWB front end 434. Also, the controller 426 may be a BLE-SoC microcontroller, or any other type of control circuit. The battery 430 can be used to supply power for the UWB module 402 so that the UWB module does not need to be powered by a reader power supply, a lock power supply, or any other power source. The controller 426 may have the ability to perform UWB communication through the UWB front end 434, and the UWB front end 434 may be any circuit configured to package and receive UWB messages for transmission and reception through the antennas 428a and 428b. The secure element 432 can be configured to cache protected state data such as STS, PACS-ID, and the like. The components of the UWB module 402 may be described in more detail later in relation to FIGS. 5A-5G below. The components of the UWB module 402 can be housed in a second housing separate from the reader 400.
[0020] In one example, a user carrying a credential device can approach a reader 400. When the credential device arrives within the threshold range of the reader system 108, the controller 406 can exchange credentials with the credential device using BLE through the antenna 408b. Next, the controller 406 can establish a secret such as a scrambled timestamp (STS) with the credential device to enable ranging using UWB communication. The UWB ranging can be performed, for example, by the controller 426 of the UWB module 402. This can operate upon receipt of data from the controller 406. The data can include identifiers of credentials such as STS, PACS-ID, and the like. By using ranging, one or more of the controllers 406 and 426 can be used to derive the user's intent to identify an intended trigger (such as movement to a specific location). Once the intended trigger is identified, the controller 406 can grant credentials to allow the user access.
[0021] Figures 5A - 5G collectively show an exemplary UWB module architecture 500 according to at least one embodiment (e.g., UWB module 304 of FIG. 3A, UWB module 354 of FIG. 3B, UWB module 402 of FIG. 4, and / or the like). In one embodiment, the UWB module architecture 500 is implemented as one or more circuit boards on which one or more of the described components are present. In other embodiments, a distributed architecture can be used. Further, note that some specific components, connections, and the like are presented in a particular configuration within the architecture 500 illustrated and described in connection with FIGS. 5A - 5G. This is for illustrative purposes only and not a limitation. In various embodiments, different components and / or different connections can be used in different configurations, and some components can be omitted in some embodiments. Further, some components can be combined. In addition to or instead of this, the functions of one or more components can be distributed across multiple components or combined in different ways. Various different input voltages, crystal oscillators, connectors, integrated circuits, and / or the like can be used in different embodiments. Various components related to debugging can be omitted in some embodiments.
[0022] FIG. 5A shows a first portion 500A of an exemplary UWB module architecture 500 according to at least one embodiment. The first portion 500A has voltages V inext , V in , V inreader , and V usbIt includes a voltage configuration 501. It also includes a voltage regulator configuration 502, which includes a first step-down regulator (from 4 - 17V to 3V3), a low-noise regulator (from 3V3 to 1V8), and a second step-down regulator (from 4 - 17V to 1V8). The first step-down regulator is V in and is connected to the second step-down regulator at the first connection and to the input voltage 3V3 at the second connection. The low-noise regulator is connected between the input voltage 3V3 and 1V8 RF . The second step-down regulator is connected between V in and 1V8. The first step-down regulator and the second step-down regulator can each be an LT®8607 manufactured by Analog Devices®, Inc., which has its headquarters in Norwood, Massachusetts. The low-noise regulator can be an LT®3045 from Analog Devices®.
[0023] Also, it includes a third step-down regulator (from 6 - 17V to 5V) connected between V in and 5V wi-fi . The third step-down regulator can be disabled when USB-powered due to insufficient power. The third step-down regulator can be an LT®8607 from Analog Devices®, and in at least one embodiment, it is only activated when the UWB module is supplied via an external power source.
[0024] As a general matter, the UWB module can be powered, by way of example, through an external supply voltage or through UWB. In some examples where USB is used as the power source, the on-board 5V regulation (i.e., the third step-down regulator used in some embodiments for an external Wi-Fi module) is powered on and off because the current consumption would potentially exceed the USB standard. Thus, in at least some embodiments, the use of a Wi-Fi expansion module or any other expansion board with 5V supplied would justify the use of an external power source.
[0025] The first part 500A further includes a micro-USB element 504 connected to the input voltage Vusb, and to ground, and further connected to the data link 505. In one embodiment, the Wi-fi function is not powered by USB, and USB only powers the BLE and UWB circuits.
[0026] Figure 5B shows a second part 500B of an exemplary UWB module architecture 500 according to at least one embodiment. In the embodiment shown, the second part 500B includes a BLE system-on-chip (SoC) 506, a RevE expansion debug pin header 517, a RevE expansion connector 519, a general debug pin header 520, and an ESP32-WROOM expansion connector 522. In one embodiment, RevE refers to the hardware revision of a reader such as an iCLASS-SE reader manufactured by HID (registered trademark) Global Corporation, which has its headquarters in Austin, Texas.
[0027] The ESP32-WROOM expansion connector 522 can provide connection options for the ESP32 module designed for Wi-fi connection and, for example, could be configured to operate at a maximum current requirement of 500 mA at 5V. The ESP32-WROOM expansion module provides Wi-fi capabilities to the RevE reader, thereby making the reader a transparent reader over Wi-fi, and may include an adapter board for the ESP32-WROOM module and the RevE expansion connector (e.g., Hirose connector). A programming adapter (e.g., VCOM via FTDI for Hirose connector) can relatively enable the loading of the firmware. The Wi-fi module could be plug-coupled within this programming adapter.
[0028] The BLE-SoC 506 could be the NRF52840 manufactured by Nordic Semiconductor (registered trademark) with its headquarters in Trondheim, Norway. In one embodiment, the BLE-SoC 506 includes at least one on-board antenna. In at least one embodiment, the BLE-SoC 506 is the core microcontroller for the UWB module having the exemplary architecture 500. In some embodiments, both the reader and the UWB module (also referred to as the platform) use Nordic's NRF52840 as their respective core microcontrollers. In the embodiments of the UWB module of the present disclosure, Nordic's NRF52840 functions not only as the core controller of the UWB module but also as the BLE interface used to set up a protected UWB ranging session. The exemplary pin / peripheral assignments for the NRF52840 used as the BLE-SoC 506 in at least one alignment are shown in Table 1 at the end of this detailed description.
[0029] The BLE-SoC506 is connected to both the input voltage 3V3 and the 32 MHz crystal oscillator, and is connected not only to the data link 505, but also to the data links 507, 508, 509, 510, 511, 512, 513, 514, 515, and 516. The data link 507 is connected to an optional display and to the RevE extended debug pin header 517, which in turn is connected to the RevE extended controller 519 via the data link 518. The UWB module can be powered via the RevE extended connector 519 in embodiments where the UWB module is used as an add-on module for a reader. In some examples, the UWB module is powered via a dedicated power connector. The data link 508 is connected to the general debug pin header 520, which in turn is connected to the ESP32Wroom extended connector 522 via the data link 521. The RevE extended connector 519 is connected to both the input voltage V inreader and ground, while the ESP32Wroom extended connector 522 is connected to both the input voltage 5V wi-fi and ground.
[0030] Figure 5C shows a third portion 500C of an exemplary UWB module architecture 500 according to at least one embodiment. In the illustrated embodiment, the third portion 500C includes a mode selector 523, which can be a low-profile DIP switch, or can include and can be a double switch that enables a developer to identify and / or define several (e.g., four) different operating modes of a UWB module having the exemplary UWB module architecture 500. The different operating modes can include, by way of example, a RevE extended mode, a stand-alone mode, a Wi-fi mode, and a debug mode. The mode selector 523 is connected to the data link 509. The mode selector 523 enables a single firmware image to be developed for these and other multiple operating modes. In one embodiment, the mode selector 523 is a CVS-02TB manufactured by NIDEC Copal Electronics located in Torrance, California.
[0031] Also, in the illustrated embodiment, the third portion 500C includes a secure element 524, an embedded video engine 526, a backlight driver 530, and a display connector 528. As indicated by the boundary 525 of the substrate / printed circuit board (PCB), the secure element 524 can be a PCB separate from the main board of the UWB module architecture 500, or can be present on top of it. The data link 510 is connected to both the secure element 524 and the embedded video engine 526. The secure element 524 can be, or can include, a Secure Access Module (SAM). In one embodiment, the secure element 524 is an ST33-ARM-SC330 secure microcontroller manufactured by STMicroelectronics (registered trademark), headquartered in Geneva, Switzerland.
[0032] The embedded video engine 526 could be the FT811 Embedded Video Engine (EVE) manufactured by Future Technology Devices International Limited, which has its headquarters in Glasgow, Scotland, United Kingdom. In at least one embodiment, the presence of the embedded video engine 526 on the board helps to offload the main microcontroller (i.e., the BLE-SoC 506). The embedded video engine 526 can be wired-connected to drive an external display in RGB mode and to control the backlight driver 530. The embedded video engine 526 is connected to the input voltage 3V3 and is also connected to the backlight driver 530 via the data link 529 and to the display controller 528 via the data link 527. The backlight driver 530 is connected to the display controller 528 via the data link 531. In the illustrated embodiment, the backlight driver 530 is the FAN5333, a dedicated LED controller manufactured by Fairchild Semiconductor, a related company of ON Semiconductor, which has its headquarters in Phoenix, Arizona. In one embodiment, the backlight driver 530 is used to control the display backlight. The shutdown pin of the backlight driver 530 is controlled by the embedded video engine 526 via Pulse Width Modulation (PWM) to enable dimming in one embodiment.
[0033] The display connector 528 is connected to the input voltage 3V3 and is further connected to the BLE SoC 506 via the data link 532. The display connector 528 can be compatible with the DT024C TFT and DT024C TFT-TS displays of Displaytech, and the latter supports touch control. These are examples of external thin-film transistor (TFT) displays designed to be supported by the disclosed UWB module architecture, but other displays can be used instead. The display connector 528 can be a dedicated flat flex connector (FFC). In one embodiment, the supported display has a pixel resolution of 320×240 and a size of 2.4 inches. The supported display can use the ILI9341 controller from ILI Technology Corporation in Taiwan.
[0034] FIG. 5D shows a fourth portion 500D of an exemplary UWB module architecture 500 according to at least one embodiment. In the illustrated embodiment, the fourth portion 500D includes a group of Arduino-compatible expansion headers 535, and a JTAG (Joint Test Action Group) connector 533 connected to the data link 516, and a flash memory 534 connected to the data link 515 and also connected to the input voltage 3V3. In one embodiment, the flash memory 534 can be an MX25L flash memory module manufactured by Macronix International Co., Ltd. having its headquarters in Taiwan. In one embodiment, the specific component used is the MX25L1606EXCI-12G. The flash memory 534 can be used for storage of firmware images or other data. The capacity of the flash memory 534 can be, for example, 2MB. In one embodiment, a similar flash memory module is used in a reader to which the present UWB module is operably connected. The flash memory 534 and / or the flash memory module in the reader can be connected to a Queued Serial Pheripheral Interface (QSPI) to enable flash access while still maintaining the use of a general Secure Pheripheral Interface (SPI) interface.
[0035] The JTAG connector 533 can be an FTSH-105-01-F-DV-K manufactured by Samtec, Inc. which has its headquarters in New Albany, Indiana. The JTAG connector 533 can be configured to operate in the Serial Wire (SW) mode, which is an operating mode for the JTAG port where only two pins, TCLK and TMS, are used for communication. The third pin can optionally be used to trace data. The JTAG pins and the SW pins are shared. In one embodiment, in relation to the pins of the JTAG connector 533, TCLK is SWCLK (Serial Wire Clock), TMS is SWDIO (Serial Wire Debug Data Input / Output), TDO is SWO (Serial Wire Trace Output), and TDI is NC. Multiple JTAG connectors can be used on the substrate of the UWB module having the exemplary architecture 500 described herein.
[0036] FIG. 5E shows a fifth portion 500E of an exemplary UWB module architecture 500 according to at least one embodiment. In the embodiment shown, the fifth portion 500E includes a first level shifter 536, a second level shifter 539, a UWB integrated circuit chip debug pin header 538, a Secure Element (SE) SPI pin header 543, an SE debug pin header 541, and an SE 542.
[0037] The first-level shifter 536 can be an 8-bit bidirectional voltage level translator TXB0108 manufactured by Texas Instruments Incorporated, which has its headquarters in Dallas, Texas. TXB0108 is used in at least one embodiment for general-purpose I / O and SPI communication. In one embodiment, the core reset signal of TXB0108 is used to control the output enable of the first-level shifter 536. This enables both SE542 and the UWB-IC 551 in Figure 5F described later to be connected to the external circuit when the core reset line is pulled Low, which can be implemented, for example, via the BLE-SoC-EX06 or via the pin header. The first-level shifter 536 is connected to the data link 514 and to the data link 537, which in turn is connected to the debug connector 538. In one embodiment, the data link 537 includes an SPI bus that uses integrated configuration interface (UCI) commands for unprotected ranging and UWB-IC configurations.
[0038] The second-level shifter 539 can include both the 8-bit bidirectional voltage level translator TXB0108 and the PCA9306DCUR bidirectional voltage level translator, both manufactured by Texas Instruments Incorporated. PCA9306DCUR is a dedicated 2-bit bidirectional I 2 C level shifter. In one embodiment, PCA9306DCUR is the I for SE542 2It is used for the C interface. The second-level shifter 539 is also connected to the data link 513 and to the data link 540, which in turn is connected to both the NXP-SE debug connector 541 and the NXP secure element (SE) 542. In one embodiment, the NXP-SE debug connector 541 can be used for external device connection in order to update the NXP applet (e.g., the Secure Element Management Service (SEMS) agent).
[0039] In one embodiment, the first-level shifter 536 and the second-level shifter 539 are used because the UWB-IC 551 described below in Figure 5F is designed for a mobile device and thus has limited supply voltage support only for 1.8V in particular. Due to this, the interface to the UWB-IC 551 in the present disclosure experiences a voltage level shift. In one alternative, it is possible to use a host controller operating at 1.8V, or the I / O voltage of the host processor could also be supplied by 1.8V. The advantage of the architecture shown is that it enables an interface with an external device. Also, the cross-switching ability of the BLE-SoC 506 (in embodiments using the nRF52840) results in flexible peripheral allocation on any of the external interfaces, thereby relatively reducing the advantage of using a level shifter for its pins.
[0040] SE542 is connected to the SE-SPI pin header 543 via the data link 544 and is itself connected to the input voltage IV8 and to ground. Also, being connected to the SE-SPI pin header 543 via the data link 544 and to both the second level shifter 530 and the NXP-SE debug connector 541 via the data link 540, in addition, SE542 is also connected to the input voltage 3V3, the input voltage 1V8, and the data link 545. In one embodiment, SE542 supports reliable ranging. SE542 can be a Java (registered trademark) Card SE with an NFC front end. In at least one embodiment, SE542 is an SN110U, which is a single-chip secure element and NFC controller manufactured by NXP Semiconductors (registered trademark) N.V. having its headquarters in Eindhoven, Netherlands. In one embodiment, NFC is designed for integration within a mobile device that is compatible with the NFC Forum, EMVCo, and ETSI / SWP.
[0041] FIG. 5F shows a sixth portion 500F of an exemplary UWB module architecture 500 according to at least one embodiment. In the embodiment shown, the sixth portion 500F includes not only the above-described UWB-IC 551, but also a first matching circuit 553, a radar port 555, a first RF switch 558, a first surface acoustic wave (SAW) bandpass filter 560, a second matching circuit 562, a first antenna port 564, a second RF switch 567, a second SAW bandpass filter 569, a third matching circuit 571, a second antenna port 575, a fourth matching circuit 546, a third antenna port 548, and a BLE antenna 550.
[0042] In at least one embodiment, the UWB551 can be an SR100T, which is a secure high-precision ranging chipset manufactured by NXP Semiconductors (registered trademark) N.V., like the SN110U that can be used as an SE542. In one embodiment, the SR100T is a fully integrated single-chip impulse radio ultra-wideband (IR-UWB) low-energy transceiver IC compliant with the HRP-UWB-PHY of IEEE802.15.4. It is designed for reliable ranging applications in a mobile environment. It supports the 6.0GHz to 8.5GHz super high frequency (SHF) UWB band for worldwide use. It has not only a programmable transmitter output power of up to 12dBm but also a fully coherent receiver for maximum range and accuracy. It integrates all relevant RF components (e.g., matching network, balun), and it complies with the FCC and ETSI-UWB spectrum masks. It uses a supply voltage of 1.8V + / - 7%.
[0043] In addition, the SR100T also supports arrival angle (AoA) measurement and has integrated I / Q phase and amplitude mismatch compensation. Its form factor is a 3.8 mm × 3.1 mm 68-pin wafer-level chip scale package (WLCSP) package with a 0.35 mm pitch. This includes, for security purposes, 128 kB of code RAM, 129 kB of data RAM, 64 kB of ROM, and a 32-bit processor of ARM® Cortex-M33 with ARM® TrustZone technology and S-DMA. The SR100T further has a BSP32 CoolFlux SubSystem with a 200 MHz clock, 32 kB of code RAM, and 2 × 16 kB of data RAM. Also, the SR100T has a first received data link 566, a second received data link 556, and a transmitted data link 552, operating frequencies of 250 MHz, 500 MHz, and 1000 MHz, 2 × 4 kB of RAM for a channel estimator, and 4 × 32 kB of RAM for RF data logging.
[0044] As shown in FIG. 5F, the UWB551 has an input voltage of 1V8 RF connected to an input voltage of 1V8, a first crystal oscillator (37.768 kHz), a second crystal oscillator (38.4 MHz), data links 537, 545, 547, a transmitted data link 552, a first received data link 566, a second received data link 556, data link 557, and data link 565.
[0045] The UWB-IC551 can be regarded as being connected to two RF pipelines, namely a first RF pipeline and a second RF pipeline. The first RF pipeline includes a first RF switch 558, a first SAW bandpass filter 560, a second matching circuit 562, and a first antenna port 564. The second RF pipeline includes a second RF switch 567, a third SAW bandpass filter 569, a third matching circuit 571, and a second antenna port 574.
[0046] In the illustrated embodiment, the UWB-IC 551 is connected to a first matching circuit 553 via a transmission data link 552, which also connects the UWB-IC 551 to a first RF switch 558. The first matching circuit 553 is connected to a radar port 555 via a data link 554, which corresponds to a radar interface that can be used in connection with various embodiments. UWB can be used in laser operation, thereby providing position measurement accuracy on the scale of several tens of centimeters. Due to the likely variable absorption and reflection of different frequencies within the pulse, both the surface of the object and the features of the shielded (e.g., covered) can be detected. In some cases, the position measurement provides the angle of incidence in addition to the distance.
[0047] As described above, in the first RF pipeline, the UWB-IC 551 is connected to a first RF switch 558 via a transmission data line 552. Also, the UWB-IC 551 is connected to the first RF switch 558 via a second reception data link 556 and a data link 557. The input voltage 1V8 RF The first RF switch 558, which is further connected to, can be XMSSJR6G0BA, which is manufactured by Murata Manufacturing Co., Ltd. having its headquarters in Kyoto, Japan. The first RF switch 558 is connected to a first SAW band-pass filter 560 via a data link 559, which in turn is connected to a second matching circuit 562 via a data link 561. The second matching circuit 562 is connected to a first antenna port 564 via a data link 563, which in turn is connected to a first external UWB antenna in at least one embodiment.
[0048] In the second RF pipeline, the UWB-IC 551 is connected to a second RF switch 567 via a data link 565 and also via a first reception data link 566. Also, the UWB-IC 551 is connected to the input voltage 1V8 RFand is connected to ground. Also, the second RF switch can be XMSSJR6G0BA. And the second RF switch 567 is connected to the second SAW bandpass filter 569 via the data link 568, which in turn is connected to the third matching circuit 571 via the data link 570. And the third matching circuit 571 is connected to the second antenna port 574 via the data link 572, which in at least one embodiment is connected to a second external UWB antenna.
[0049] Any suitable number of external UWB antennas can be used in various embodiments. In embodiments where a third external UWB antenna is deployed in the context of the disclosed exemplary architecture 500, a third RF pipeline is deployed to connect to the third external UWB antenna. Additionally, switches can be implemented to enable switching between antennas for different communication packets.
[0050] Also further shown in FIG. 5F is a fourth matching circuit 546 connected between the data link 512 and the data link 547, which is further connected to the third antenna port 548. The third antenna port 548 provides an optional connection to an external BLE antenna. In the embodiment shown, the third antenna port 548 is connected to the BLE antenna 550 via the data link 549, which can be a 2.4 GHz BLE antenna.
[0051] In at least one embodiment, for its RF interface, the UWB module of the present disclosure utilizes a U.FL connector manufactured by Hirose Electric Co., Ltd., which has its headquarters in Tokyo, Japan. These RF interfaces include a radar port 555 that can be connected to a radar antenna, a first antenna port 564 that can be connected to a first external UWB antenna, a second antenna port 574 that can be connected to a second external UWB antenna, and a third antenna port 548 that can be connected to an (external) BLE antenna 550. The U.FL connector is a miniature RF coaxial connector for radio frequency signals that is commonly used in applications where space is limited. These are often used not only in laptop mini PCI cards but also in mobile phones. Cables manufactured by Hirose Electric Co., Ltd. can also be used. In some embodiments, Hirose X.FL connectors are used. In addition to other differences, the X.FL connector has a rating for use at higher frequencies than the U.FL connector.
[0052] FIG. 5G shows a seventh portion of an exemplary UWB module architecture 500 according to at least one embodiment. In the illustrated embodiment, the seventh portion includes a channel impulse response (CIR) debug connector 575, which is connected to the data link 547. In some embodiments, the CIR debug connector 575 is used in connection with the pins (of the UWB-IC 551 as described above in FIG. 5F) used for SPI communication to access the CIR data acquired by the UWB-IC 551. This CIR data can be used for analog debugging of ranging applications (e.g., analog performance debugging, null estimation, and / or the like). The CIR is used to find the actual distance between two UWB devices (e.g., the UWB module 304 and the credential device 112), i.e., the actual first path. It should be further noted that the maximum detectable delta between the first path and the strongest path is referred to as the dynamic range. Thus, the actual first path represents an important debugging parameter in connection with ranging applications.
[0053] FIG. 6 shows a block diagram of an exemplary machine 600 in which any one or more of the techniques (e.g., methods) described herein can operate. The examples described herein can include, or can operate by means of, logic or some components or mechanisms within machine 600. A circuit (e.g., a processing circuit) is a collection of circuits implemented within a physical entity of machine 600 that includes hardware (e.g., simple circuits, gates, logic, etc.). Circuit membership can be flexible over time. A circuit includes members that can perform defined operations when operating alone or in combination. In some examples, the hardware of a circuit can be designed in an invariant manner (e.g., wired) to perform a particular operation. In some examples, the hardware of a circuit can include physically changeable components (e.g., execution units, transistors, simple circuits, etc.) connected in a changeable manner that includes a machine-readable medium physically altered to encode instructions for a particular operation (e.g., a magnetically electrically movable arrangement of invariant mass particles, etc.). When connecting physical components, the electrical properties underlying the hardware components can be changed, for example, from an insulator to a conductor, or vice versa. Instructions enable an embedded hardware (e.g., an execution unit or a loading mechanism) to generate members of a circuit within the hardware via a variable connection to perform a portion of a particular operation when operating. Thus, in some examples, a machine-readable medium element is part of a circuit or communicatively coupled to other components of the circuit when the device is operating. In some examples, any of the physical components can be used within members of multiple circuits. For example, during operation, an execution unit can be used within a first circuit of a first circuit configuration at one point in time and reused at a different point in time by a second circuit within the first circuit configuration or by a third circuit within the second circuit. Further examples of these components in relation to machine 600 follow.
[0054] In some embodiments, machine 600 can operate as a stand-alone device or can be connected to other machines (e.g., network-connected). In a network-connected deployment, machine 600 can operate within the capabilities of a server machine, a client machine, or both a server-client network environment. In some examples, machine 600 can function as a peer machine in a peer-to-peer (P2P) (or other distributed) network environment. Machine 600 can be a personal computer (PC), tablet PC, set-top box (STB), personal digital assistant (PDA), cellular telephone, web appliance, network router, switch or bridge, or any machine capable of executing instructions (sequential or otherwise) that specify operations to be executed by that machine. Further, although only a single machine is shown, the term "machine" shall be construed to include any collection of machines that individually or jointly execute a set of one or more instructions to perform any one or more of the methodologies described herein such as cloud computing, software as a service (SaaS), other computer cluster configurations.
[0055] A machine (e.g., a computer system) 600 can include a hardware processor 602 (e.g., a central processing unit (CPU), a graphics processing unit (GPU), a hardware processor core, or any combination thereof), a main memory 604, a static memory (e.g., firmware, microcode, basic input / output (BIOS), Unified Extensible Firmware Interface (UEFI), etc.) 606, and a mass storage 608 (e.g., a hard drive, a tape drive, flash storage, or other block device), and some or all of these can communicate with each other via an interlink (e.g., a bus) 630. The machine 600 can further include a display unit 610, an alphanumeric input device 612 (e.g., a keyboard), and a user interface (UI) navigation device 614 (e.g., a mouse). In some examples, the display unit 610, the input device 612, and the UI navigation device 614 can be a touch screen display. The machine 600 can further include a storage device (e.g., a drive unit) 608, a signal generation device 618 (e.g., a speaker), a network interface device 620, and one or more sensors 616 such as a global positioning system (GPS) sensor, a compass, an accelerometer, or other sensors. The machine 600 can include an output controller 628 such as a serial (e.g., Universal Serial Bus (USB), parallel, or other wired or wireless (e.g., InfraRed (IR), Near Field Communication (NFC), etc.) connection) to communicate with or control one or more peripheral devices (e.g., a printer, a card reader, etc.).
[0056] The registers of processor 602, main memory 604, static memory 606, or mass storage 608 can be, or can include, a machine-readable medium 622 on which one or more sets of data structures or instructions 624 (e.g., software) are stored that are implemented or utilized by any one or more of the techniques or functions described herein. Also, the instructions 624 can be wholly or at least partially present in any of the registers of processor 602, main memory 604, static memory 606, or mass storage 608 upon execution thereof by machine 600. In some examples, one or any combination of hardware processor 602, main memory 604, static memory 606, or mass storage 608 can constitute the machine-readable medium 622. The machine-readable medium 622 is shown as a single medium, but the term "machine-readable medium" can include a single medium or multiple media (e.g., a centralized database and / or associated caches and servers) configured to store one or more instructions 624.
[0057] The term "machine-readable medium" can include any medium having the ability to store, encode, or carry instructions for execution by a machine 600 and to cause the machine 600 to perform any one or more of the techniques of the present disclosure or to store, encode, or carry data structures used by or associated with such instructions. Examples of non-limiting machine-readable media can include semiconductor memory, optical media, magnetic media, and signals (e.g., radio frequency signals, other photon-based signals, acoustic signals, etc.). In some examples, a non-transitory machine-readable medium has a machine-readable medium having a plurality of particles with invariant (e.g., stationary) mass and thus is a composition. Thus, a non-transitory machine-readable medium is a machine-readable medium that does not include a transitory propagation signal. Specific examples of non-transitory machine-readable media can include non-volatile memory such as semiconductor memory devices (e.g., electrically programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), and flash memory), magnetic disks such as internal hard disks and removable disks, magneto-optical disks, and CD-ROM and DVD-RAM disks.
[0058] In some examples, the information stored on the machine-readable medium 622 or otherwise provided may represent instructions 624, such as the instructions 624 themselves, or a format from which the instructions 624 can be derived. This format from which the instructions 624 can be derived may include source code, encoded instructions (e.g., in a compressed or encrypted form), packaged instructions (e.g., split into multiple packages), or the like. The information representing the instructions 624 within the machine-readable medium 622 can be processed by the processing circuitry into instructions for implementing any of the operations described herein. For example, the step of deriving the instructions 624 from the information (e.g., processing by the processing circuitry) may include compilation, interpretation, loading, organization (e.g., dynamic or static linking), encoding, decoding, encryption, decryption, packaging, unpackaging, or other operations of the information into the instructions 624.
[0059] In some examples, the derivation of the instructions 624 may include the assembly, compilation, or interpretation (e.g., by the processing circuitry) of information to generate the instructions 624 from some intermediate or processed format provided by the machine-readable medium 622. The information can be combined, unpacked, and modified to generate the instructions 624 when provided as multiple parts. For example, the information may exist within multiple compressed source code packages (or object code, or binary executable code, etc.) on one or more remote servers. The source code packages can be encrypted while in transit over the network and, if necessary, decrypted, decompressed, assembled (e.g., linked), and compiled or interpreted (e.g., as libraries, stand-alone executable files, etc.) on a local machine and executed by the local machine.
[0060] Command 624 can be further transmitted or received on communication network 626 using a transmission medium via network interface device 620 that utilizes any of several transfer protocols (e.g., Frame Relay, Internet protocol (IP), Transmission Control Protocol (TCP), User Datagram Protocol (UDP), HyperText Transfer Protocol (HTTP), etc.). Exemplary communication networks can include, among other things, Local Area Networks (LANs), Wide Area Networks (WANs), packet data networks (e.g., the Internet), cellular telephone networks (e.g., cellular networks), Plain Old Telephone Service (POTS) networks, and wireless data networks (e.g., the IEEE 802.11 standard family referred to as Wi-Fi (registered trademark), the IEEE 802.16 standard family referred to as WiMax (registered trademark), the IEEE 802.15.4 standard family, peer-to-peer (P2P) networks). In some examples, network interface device 620 can include one or more physical jacks (e.g., Ethernet, coaxial, or telephone jacks) or one or more antennas to connect to communication network 626. In some examples, network interface device 620 can include multiple antennas to wirelessly communicate using at least one of single-input multiple-output (SIMO), multiple-input multiple-output (MIMO), or multiple-input single-output (MISO) techniques.The term "propagation medium" is to be construed to include any non-transitory medium that has the capability of storing, encoding, or carrying instructions for execution by the machine 600, and includes a digital or analog communication signal or other non-transitory medium for enabling such software communications. A propagation medium is a machine-readable medium.
[0061] The foregoing description includes references to the accompanying drawings, which form a part of the detailed description. The drawings illustrate, by way of example, specific embodiments in which the invention may be practiced. Such embodiments are herein referred to as "examples." Such examples may include elements in addition to those illustrated and described. However, the inventors contemplate examples in which only the elements illustrated and described are provided. Further, the inventors contemplate examples in which any combination or permutation of elements illustrated or described in connection with a particular example (or one or more of its aspects) or other examples (or one or more of their aspects) illustrated or described herein is used.
[0062] As used herein, the terms "a" or "an" are used to include one or more, independent of any other instance or usage of "at least one" or "one or more", as is common in patent documents. As used herein, the term "or" is used to mean non-exclusive, or "A or B" includes "not B but A", "not A but B", and "A and B", unless otherwise notified. As used herein, the terms "including" and "in which" are used as plain English equivalents of the individual terms "comprising" and "wherein". Also, in the appended claims, the terms "comprising" and "including" are open-ended, i.e., a system, apparatus, article, composition, formulation, or process that includes elements in addition to those recited after these terms in the claims is still considered to be within the scope of that claim. Further, in the appended claims, terms such as "first", "second", and "third" are used only as labels and are not intended to impose numerical requirements on those objects.
[0063] The above description should be construed as illustrative and not restrictive. For example, the above examples (or one or more aspects thereof) can be used in combination with each other. For example, those skilled in the art can use other embodiments when referring to the above description. The abstract is provided to enable the reader to quickly identify the characteristics of the technical disclosure. It should be understood that this is not to be used to interpret or limit the scope or meaning of the claims. Also, in the above detailed description, various features can be grouped together to streamline the present disclosure. This should not be construed as intending that the disclosed features not claimed are essential to any of the claims. Rather, the subject matter of the present invention may lie in less than all of the features of a particular disclosed embodiment. Accordingly, the appended claims are hereby incorporated by reference into the detailed description as examples or embodiments, each claim standing on its own as a separate embodiment, and such embodiments are contemplated to be combinable with each other in various combinations or permutations. The scope of the present invention is to be determined with reference to the appended claims, along with the full scope of equivalents to which they are entitled.
Claims
1. A device connectable to a reader of an access control system, comprising: The antenna, a communications link configured to interface with the reader; an ultra-wideband (UWB) front-end circuit connected to the antenna for enabling UWB communications with the credential device; a controller connected to the UWB front-end circuit and configured to perform ranging for the credential device using the UWB communication upon receiving data related to the credential device from the reader via the communication link; a housing separate from the reader housing, the device housing housing containing the antenna, the UWB front-end circuitry, and the controller.
2. The apparatus of claim 1 , wherein the communication link is a wireless communication link.
3. The apparatus of claim 1 , wherein the communication link is a wired communication link.
4. The device of claim 1 , further comprising a secure element configured to cache secure data used to range the credential device.
5. The apparatus of claim 2 , wherein the controller is configured to communicate with the reader over the wireless communication link using Bluetooth® low energy.
6. The apparatus of claim 2 , wherein the controller is configured to communicate with the reader over the wireless communication link using Near Field Communication (NFC).
7. The device of claim 1 , wherein the communication link is configured to connect to an expansion port or expansion slot of the reader.
8. 8. The apparatus of claim 1, further comprising a local power supply contained within the housing of the apparatus and configured to provide power to the controller and the UWB front-end circuitry.
9. 8. An apparatus according to claim 1, wherein the controller and the UWB front-end circuitry receive power from the reader.
10. 8. Apparatus according to any one of claims 1 to 7, wherein the apparatus comprises an integrated circuit connectable to a circuit board of the reader.
11. 8. The apparatus of claim 1, further comprising a second antenna contained within the housing, the UWB front-end circuitry further connected to the second antenna to enable UWB communications.
12. 1. A method for adding ultra-wideband (UWB) ranging to an access control system, comprising: connecting an UWB module to a reader of the access control system via a communications link, the UWB module comprising: At least one antenna; a UWB front-end circuit coupled to the at least one antenna for enabling UWB communication with a credential device; a controller connected to the UWB front-end circuit and configured to perform ranging for the credential device using the UWB communication upon receiving data related to the credential device from the reader via the communication link; a housing separate from the reader housing, the UWB module housing containing the antenna, the UWB front-end circuitry, and the controller.
13. The method of claim 12 , wherein the UWB module is connected to the reader after installing the reader in the access control system.
14. 13. The method of claim 12, wherein the step of connecting the UWB module with the reader via the communications link comprises connecting the UWB module with the reader via a data cable.
15. 13. The method of claim 12, wherein the step of coupling the UWB module with the reader via a communications link comprises coupling the UWB module with the reader via a wireless communications link.
16. 16. The method of claim 15, wherein connecting the UWB module with the reader via the wireless communication link includes connecting the UWB module with the reader using Bluetooth low energy.
17. 16. The method of claim 15, wherein connecting the UWB module with the reader via the wireless communication link comprises connecting the UWB module with the reader using near field communication (NFC).
18. 13. The method of claim 12, wherein connecting the UWB module with the reader via the communication link comprises connecting the UWB module to an expansion port or expansion slot of the reader.
19. The method of claim 12 , wherein the UWB module further comprises a secure element configured to cache secure data used to range the credential device.
20. 20. The method of claim 12, wherein the UWB module further comprises a local power source contained within the housing of the UWB module and configured to provide power to the UWB module.
21. 20. The method of any one of claims 12 to 19, further comprising the step of providing power from the reader to the UWB module.
22. 20. The method of any one of claims 12 to 19, further comprising the step of connecting at least one of the UWB module and the reader with an access control host server via a second communication link.
Citation Information
Patent Citations
Portable terminal apparatus and key
JP2008205548A
Mobile device and reader for facilitating transaction
JP2018206355A
Method for managing communication between a contactless reader and a portable contactless device
US20190052314A1
Cited By
Systems, methods, and devices for access control
US12657972B2
Physical access control systems with localization-based intent detection
US12739636B2