Systems, methods and devices for access control

A long-range RFID protocol for access control systems addresses congestion by verifying and tracking credentials at a distance, enhancing throughput and efficiency in high-traffic areas.

JP2025183323APending Publication Date: 2025-12-16ASSA ABLOY AB
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2025149816
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2018-11-02
Filing Date
2025-09-10
Publication Date
2025-12-16

AI Technical Summary

Technical Problem

Radio frequency identification (RFID)-based access control systems face congestion issues during high throughput operations due to the need for credentials to be within a short distance of the reader, causing delays and inefficiencies in large facilities or mass transit access points.

Method used

Implementing a long-range protocol that allows credential verification and tracking at a greater distance, delaying access control decisions until the credential is within a desired threshold distance, and using multiple readers connected via a communication network to manage concurrent credentials.

Benefits of technology

Enhances throughput by allowing credential verification and tracking at a distance, reducing congestion and improving operational efficiency in high-traffic environments while maintaining security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025183323000001_ABST
    Figure 2025183323000001_ABST
Patent Text Reader

Abstract

To provide an access control system for improving the throughput in high-traffic operations while maintaining a high level of security.SOLUTION: An access control system may comprise a credential including credential data, and at least one reader. The at least one reader is configured to receive the credential data over a link. The at least one reader is configured to verify that the credential is valid based on the credential data, mark the credential as valid, and track a location of the credential relative to the at least one reader. The at least one reader is configured to make or delay an access control decision for the credential based on the location of the credential.SELECTED DRAWING: Figure 1A
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] SUMMARY OF THE INVENTION The exemplary embodiments relate to systems, methods, and devices for access control. [Background technology]

[0002] Radio frequency identification (RFID)-based access control systems typically involve a user presenting a credential (e.g., an access card) containing credential data to a reader. This action is sometimes referred to as "tapping" the credential against the reader. The credential data on the credential is then read by the reader using a short-range RFID protocol such as near field communication (NFC) or ISO 14443A / B. Using these short-range protocols, the reader must be within a short distance, or tap distance (e.g., a few centimeters), from the reader to read the credential data. If the credential is a mobile phone, the credential is activated before tapping by unlocking the phone or applying an additional authentication process such as fingerprint recognition. Tapping the credential against a reader and / or activating the credential before bringing it close to the reader can create congestion issues during high throughput operations, such as access points in large facilities (e.g., sports stadiums) or mass transit (e.g., subway) access points. Summary of the Invention

[0003] At least one exemplary embodiment is directed to an access control method, apparatus and / or system that improves throughput in high traffic operations while maintaining a high level of security.

[0004] According to at least one example embodiment, an access control system may include a credential including credential data and at least one reader. The at least one reader is configured to receive the credential data over a link. The at least one reader is configured to verify that the credential is valid based on the credential data and mark the credential as valid and track the location of the credential relative to the at least one reader. The at least one reader is configured to make or delay an access control decision for the credential based on the location of the credential.

[0005] In at least one exemplary embodiment, the at least one reader is configured to delay making an access control decision for the credential if the location indicates that the credential is not within a first distance of the at least one reader, and the at least one reader is configured to make an access control decision for the credential if the location indicates that the credential is within the first distance.

[0006] In at least one exemplary embodiment, at least one reader or credential can establish a link when the credential enters communication range of the at least one reader. Further, the at least one reader and credential can perform mutual authentication over the link before the at least one reader receives the credential data. Alternatively or additionally, the at least one reader and credential can perform a secure read operation, where the communication range corresponds to a second distance from the at least one reader that is greater than the first distance.

[0007] In at least one exemplary embodiment, the communication range is based on the transmission / reception range of at least one reader and credential and the operating frequency of the protocol used to establish the link.

[0008] In at least one exemplary embodiment, the at least one reader is configured to determine a communication range based on an environment surrounding the at least one reader. In at least one example embodiment, the access control system may further include at least one accessor that denies or grants access to a zone associated with the at least one reader based on an access control decision by the at least one reader. The at least one reader is configured to activate the at least one accessor if the credential is within a third distance of the at least one reader or the at least one accessor. The third distance may be less than or equal to the first distance.

[0009] In at least one exemplary embodiment, the at least one reader stops tracking the credential and terminates the link when the credential enters the zone through at least one access mechanism or when the credential leaves the communication range.

[0010] In at least one exemplary embodiment, at least one reader is configured to track the location of the credential based on received signal strength from the credential. In at least one exemplary embodiment, at least one reader is configured to track the location of the credential by periodically pinging the credential to keep the link open.

[0011] In at least one exemplary embodiment, at least one reader is configured to track the location of the credential by receiving a broadcast signal from the credential, which may include a token belonging to the credential to identify the credential to the at least one reader.

[0012] In at least one exemplary embodiment, at least one reader is configured to stop tracking credentials if the number of credentials being tracked by the at least one reader exceeds a threshold and if another unauthenticated credential is closer to the at least one reader than the tracked credential.

[0013] In at least one exemplary embodiment, the at least one reader is a plurality of readers communicating with each other over a communications network, wherein a first reader of the plurality of readers that marks and tracks the credential notifies the remainder of the plurality of readers that the credential is marked and tracked, enabling the remainder of the plurality of readers to track the credential.

[0014] In at least one exemplary embodiment, the remainder of the plurality of readers analyzes communications between the first reader and the credential and / or monitors communication traffic to enable the remainder of the plurality of readers to make access control decisions for the credential.

[0015] At least one example embodiment includes a method for access control. The method includes establishing a wireless link with a credential. The credential includes credential data. The method may further include receiving the credential data over the wireless link. The method may include verifying that the credential is valid based on the credential data, and marking the credential as valid and tracking the location of the credential relative to at least one reader. The method may include making or delaying an access control decision for the credential based on the location of the credential.

[0016] In at least one exemplary embodiment, making or delaying an access control decision may include delaying an access control decision if the location indicates that the credential is not within a first distance of at least one reader, and making an access control decision for the credential if the location indicates that the credential is within the first distance.

[0017] In at least one exemplary embodiment, the establishing step may include establishing a wireless link when the credential enters a communication range of the at least one reader, the communication range corresponding to a second distance from the at least one reader that is greater than the first distance, the communication range being based on a transmit / receive range of the at least one reader and the credential. The method may further include performing mutual authentication between the credential and the at least one reader.

[0018] In at least one exemplary embodiment, the method may further include determining an interaction range based on an environment surrounding the at least one reader. In at least one exemplary embodiment, the method may further include stopping tracking of the credential and terminating the link once the credential has entered through an access mechanism under the control of the at least one reader.

[0019] According to at least one exemplary embodiment, the reader includes a first communication interface for wireless communication, a processor, and memory containing instructions that, when executed by the processor, cause the processor to establish a link with a credential using the first communication interface if the credential is within a first distance of the reader, the credential including credential data. The instructions cause the processor to verify that the credential is valid based on the credential data, and to mark the credential as valid and track the location of the credential relative to the reader. The instructions cause the processor to make or delay an access control decision for the credential based on whether the location of the credential indicates that the credential is within a second distance from the reader, the second distance being less than the first distance.

[0020] According to at least one example embodiment, the reader may further include a second communication interface for communicating with a plurality of other readers. The instructions include instructions for causing the processor to share information of the credential with the plurality of other readers to enable the plurality of other readers to make access control decisions or take over a link to the credential from the first communication interface. The instructions may include instructions for causing the processor to authenticate the credential over the link and, if authentication is successful, receive credential data over the link.

[0021] Various aspects of exemplary embodiments are described below with reference to the drawings, which are schematic illustrations of idealized configurations. While particular circuit configurations and circuit elements are described herein, it should be recognized that the exemplary embodiments are not limited to the circuit configurations and / or circuit elements shown and described below. In particular, it should be recognized that circuit elements of a particular type or function can be substituted with one or more other circuit elements to achieve similar functionality without departing from the scope of the exemplary embodiments.

[0022] Illustrative embodiments will be described with reference to the accompanying drawings, which are not necessarily drawn to scale. Of course, it should be recognized that the present invention is not necessarily limited to the specific embodiments described below. [Brief explanation of the drawings]

[0023] [Figure 1A] FIG. 1 illustrates a block diagram of an access control system in accordance with at least one example embodiment. [Figure 1B] FIG. 1 illustrates a block diagram of an access control system in accordance with at least one example embodiment. [Figure 2] FIG. 1 is a block diagram of a wearable device (or credential) in accordance with at least one exemplary embodiment. [Figure 3] 1 illustrates a block diagram of a mobile device (or credential) in accordance with at least one example embodiment. [Figure 4] FIG. 1 illustrates a block diagram of a reader in accordance with at least one exemplary embodiment. [Figure 5] 1 illustrates various stages of a credential accessing a reader in accordance with at least one exemplary embodiment. [Figure 6] 1A and 1B in accordance with at least one exemplary embodiment. [Figure 7] 1 illustrates a method in accordance with at least one example embodiment. [Figure 8] 1 illustrates a method in accordance with at least one example embodiment. [Figure 9] 1 illustrates a method in accordance with at least one example embodiment. [Figure 10] 1 illustrates a method in accordance with at least one example embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0024] In general, an identity / access control transaction has several phases. 1) establishing communications (e.g., establishing a transport protocol link and a session between the credential and the reader); 2) (optional) establishing a security protocol, e.g., a cryptographic protocol based on mutual authentication, to ensure that the credential communicates only with trusted readers (and not with risky readers designed to steal the credential (access rights)) and that the reader communicates with trusted credentials; 3) reading the credential, which may include transmitting the credential data; 4) verifying that the access credential is authentic (e.g., verifying the cryptographic signature, decrypting the credential data, etc.); 5) making an identification or access-based decision on the reader itself or by an access control system connected to the reader (e.g., the reader sends the decrypted access rights or verified credential to an access control system, which then makes an access decision based on the contents of the credential, e.g., if the specific identity of the credential is on a whitelist that defines who can enter a particular zone controlled by the reader). In related art access control systems, these steps occur when the credential comes within range of the reader (less than approximately 8 centimeters from the reader) (i.e., while a person "taps" the credential against the reader).

[0025] At least one exemplary embodiment suggests to the user that, using a long-range protocol that allows the reader to read the credential at a greater distance (e.g., several meters or tens of meters), the user defer at least some of the steps described above until the user holding the credential still has access to the reader. For example, some or all of steps 1-4 described above can be performed immediately as soon as the credential enters the engagement range of the reader, which may be a distance greater than a tap distance of several centimeters.

[0026] When using long-range protocols for access control, it may be desirable for an access point / mechanism that allows a user access to a zone (e.g., door / turnstile, green light / red light, etc.) to not mechanically "activate" too far from the door, potentially allowing an unverified user to access the zone. To address this issue, at least one exemplary embodiment proposes inserting another step between steps 4 and 5 above. For example, once the credential is verified in step 4, the system may perform another step that marks the credential as valid and track the credential as it moves within the reader's communication range. Using knowledge of the tracking, the system may delay making an access control decision for the tracked credential until the credential is within a desired threshold distance (e.g., 2 meters) of the reader. If the decision is to grant access to the approaching credential, the access mechanism is activated, allowing the user to enter.

[0027] In at least one exemplary embodiment, if a connection remains open, the credential can be tracked based on the ongoing transport protocol connection. For example, an exemplary embodiment can analyze packets sent by the credential to a reader using a packet-based protocol such as Bluetooth Smart (BLE) or Wi-Fi. At least one exemplary embodiment includes tracking the credential with respect to one or more readers using the credential's RSSI, potential angle of arrival, and / or time of flight characteristics.

[0028] For example, when supporting an existing Bluetooth credential, the reader can "ping" the credential by reading some existing data or attempting to read non-existent data at regular intervals. The ping simulates to the credential that the reader is still continuing the transaction with the credential, so that the credential does not drop its connection with the reader.

[0029] Exemplary embodiments include different ways of "marking" a credential or credential-carrying device as valid. For example, at least one exemplary embodiment includes marking a transport protocol media access control (MAC) address, which is useful when the established link is an open session and the MAC address of the credential does not change during the open session. Another exemplary embodiment includes marking a TCP / IP protocol IP address and / or other network protocol identifier that can be used at least temporarily to uniquely or nearly uniquely identify the credential. Yet another exemplary embodiment includes marking a session identifier of the session established between the credential and the reader. In another example, the reader can grant an "access token," one-time password (OTP), or the like to a device that the reader can read at a desired distance. In yet another embodiment, the reader 112 can send a temporary key to the credential, which can then be used at the reader side for key proof of ownership protocols (e.g., as a challenge response based on the temporary key or as a cryptography or signature from which the credential was generated).

[0030] In at least one exemplary embodiment, a credential may be provided with an access token, which may then be broadcast (advertised) with the credential. A reader then scans / listens for advertisements containing the access token to mark and track the credential. In at least one exemplary embodiment, the advertisement changes over time and includes a time-calculated cipher and a temporary key assigned as described above. One such example is using a truncated time-based one-time password (TOTP) cipher in the advertisement, which changes the cipher periodically (e.g., every 30 seconds).

[0031] In at least one exemplary embodiment, each reader may have a maximum number of potential concurrent credentials that it can track, where if the reader detects a closer, unauthorized credential, the reader may "dump" or ignore the more distant credential in favor of handling the closer credential first.

[0032] In at least one exemplary embodiment, multiple readers are connected to one another. This occurs either through a traditional connection with an endpoint that forwards all messages to all readers, or by using a message broker architecture paradigm. Here, exemplary embodiments employ message queues, whereby all readers at a particular entrance or zone can subscribe to the same entrance queue (e.g., "stadium / entrance"). Then, when a reader has a connection or marking event, it publishes the event and associated data to the queue, and all readers that subscribe or listen to the queue "listen" to the queue and therefore receive the connection / marking event. Here, exemplary embodiments can use Message Queuing Telemetry Transport (MQTT) as the message broker.

[0033] In at least one exemplary embodiment, the readers are connected using wireless mesh technology. The following is an example of operation involving multiple readers using a Bluetooth Smart based credential and Bluetooth MAC address based marking: In this example, the first reader (Reader B) performs all steps described above, including "marking," to maintain connection with the credential.

[0034] Reader B then publishes a marking event to the message broker, including the MAC address. The operation may include additional low-level wireless protocol-based information, such as the Bluetooth channel hopping scheme employed for the particular connection.

[0035] Other readers receive the marking event and begin searching or tracking valid "marked" credentials. One option is to search or sniff Bluetooth communications, searching for specific packets sent consecutively by the credential still present at reader B. If another reader (reader A) detects the marked credential as "open" in close range (e.g., decision range), i.e., valid for initiating a positive access control decision, reader A will make an access control decision for the credential previously verified by reader B.

[0036] In another exemplary embodiment, reader B can publish all information that would allow reader A to actually "take over" direct communication with the credential.

[0037] 1A is a block diagram illustrating an access control system 100 that authenticates a user 102 via a wearable device 104 according to at least one exemplary embodiment. In one exemplary embodiment, the access control system 100 includes at least one reading device (or reader) 112 (e.g., 112A, 112B, ... 112N), at least one wearable device 104, and at least one portable / mobile device (or credential) 108. The reader 112 may include an access data memory 116. The access data memory 116 may be configured to store access information, identification data, rules, program instructions, and / or other data associated with the execution of access operations of the access control system 100. In some embodiments, the reader 112 may be configured to communicate with the access data memory 116 via a communication network 128. The access data memory 116 may be located remotely from the reader 112, locally, and / or locally and remotely. The access data memory 116 may be located in the access server 120 .

[0038] The wearable device 104 and / or the mobile device 108 may be configured to communicate with the reader 112 via one or more wireless communication connections. These one or more wireless communication connections may include communication via at least one of a conventional wireless protocol, a proximity-based wireless communication protocol, Bluetooth®, BLE, infrared, voice, NFC, ultra-wide band (UWB), RF, and other wireless communication networks and / or protocols. In some cases, communication between the wearable device 104 and the reader 112 may be established automatically when the wearable device 104 enters the active zone of the interrogating reader 112. In one embodiment, the active zone of the reader 112 may be defined as the three-dimensional space in which the strength of the RF signal emitted by the reader 112 exceeds the sensitivity threshold of the wearable device 104 and in which the strength of the RF signal emitted by the wearable device 108 exceeds the sensitivity threshold of the reader 112.

[0039] In at least one exemplary embodiment, the wearable device 104 and / or the mobile device 108 may be configured to communicate with the reader 112 and / or the access server 120 via a communication network 128. The communication network 128 may include communication via a wireless network, a wireless communication network, Zig-Bee, GSM, CDMA, Wi-Fi, and / or via at least one of other communication networks and / or protocols as provided herein.

[0040] In at least one exemplary embodiment, authentication may be required between the wearable device 104 and the reader 112 before further communication is possible. Additionally or alternatively, authentication may be required between the wearable device 104 and the mobile device 108 before further communication is possible. In either case, the further communication may provide for communication in which access control information (e.g., keys, codes, credential data, etc.) is shared. In at least one exemplary embodiment, authentication may be provided via one-way or two-way authentication. Examples of authentication include, but are not limited to, simple authentication based on a site code, trusted data format, shared secret, and / or the like. As will be appreciated, the access control information may be more sensitive and require more stringent verification, for example, via encrypted access control information exchange.

[0041] In at least one exemplary embodiment, the reader 112 can be configured to request access control information from the wearable device 104 and / or the mobile device 108. This access control information can be used to validate the wearable device 104 and / or the mobile device 108 that applies to the reader 112. The validation can include referencing information stored in the access data memory 116 or some other memory associated with the wearable device 104 and / or the mobile device 108. Typically, the reader 112 is associated with a particular physical or logical asset (e.g., a door preventing access to a secure room, a computer lock protecting sensitive information or computer files, a lock on a vault, etc.). In one embodiment, the wearable device 104 and / or the mobile device 108 can be validated via one or more elements of the access control system 100. Once the wearable device 104 and / or the mobile device 108 is authenticated, credential information (or credential data) associated with the wearable device 104 and / or the mobile device 108 can be validated. During processing, the reader 112 may generate a signal that enables the wearable device 104 to perform the result of the interrogation (e.g., lock / unlock a locking mechanism, allow / disallow movement of a monitored item, suspend it, activate an alarm system, provide access to a computer system, provide access to a particular document, etc.). Alternatively, the access server 120 or some other system back-end element may generate such a signal. In at least one exemplary embodiment, the mobile device 108 and the reader 112 may be connected to the access server 120 via different communication channels. The access server 120 may control the operation of the reader 112 via a first channel (e.g., a wired channel) based on an information exchange with the mobile device 108 via a second channel (e.g., a wireless channel) that is different from the first channel.

[0042] According to at least one example embodiment, the reader 112 can collect access control information associated with the wearable device 104 before an access control decision can be made. For example, the reader 112 can request credential information stored on the wearable device 104 to validate the wearable device 104. The validity of the wearable device 104 can be based on the validity of the associated mobile device 108, or vice versa. In one embodiment, upon verifying the credential information stored on the wearable device 104, the reader 112 generates a signal to interrogate the wearable device 104 and / or the mobile device 108 (e.g., lock / unlock a locking mechanism, allow / disallow movement of a monitored item, suspend it, activate an alarm system, provide access to a computer system, provide access to a particular document, etc.). As described above, the access server 120 and / or the reader 112 can generate such signals.

[0043] The access server 120 may include a processor, memory, and one or more input / output terminals. The memory of the access server 120 may be used in connection with the execution of application programs or instructions by the processor, or may be used for temporary or long-term storage of program instructions and / or data. By way of example, the memory may include RAM, DRAM, SDRAM, or other solid-state memory. Additionally or alternatively, the access server 120 may be in communication with an access data memory 116. Similar to the memory of the access server 120, the access data memory 116 may include solid-state memory or devices. The access data memory 116 may include a hard disk drive or other random access memory.

[0044] In at least one exemplary embodiment, the reader 112 can be configured to communicate with one or more devices via a communications network 128. For example, the reader 112 can communicate with the wearable device 104 and / or the mobile device 108 via the communications network 128. In particular, the communication can enable back-end authentication and / or provide notifications from the reader 112 to the mobile device 108. The communications network 128 can include any type of known communications medium or collection of communications media and can transfer messages between endpoints using any type of protocol. The communications network 128 can include wired and / or wireless communications technologies. The Internet is one example of a communications network 128 comprising an Internet Protocol (IP) network of many computers, computing networks, and other communications devices located worldwide and connected by many telephone systems and other means. Other examples of communications network 128 include, but are not limited to, a Plain Old Telephone System (POTS), an Integrated Services Digital Network (ISDN), a Public Switched Telephone Network (PSTN), a Local Area Network (LAN), a Wide Area Network (WAN), a Session Initiation Protocol (SIP) network, a Voice over Internet Protocol (VoIP) network, a cellular network, RS-232, similar networks used in access control systems between readers and control panels, and any type of packet-switched or circuit-switched network known in the art.It should also be appreciated that communications network 128 need not be limited to any one type of network, but instead can include many different networks and / or network types. Furthermore, communications network 128 can include many different communications media, such as coaxial cable, copper cable / wire, fiber optic cable, antennas for transmitting / receiving wireless messages, and combinations thereof.

[0045] In some embodiments, the access control system 100 may include at least one communication device 124. The communication device 124 may include, but is not limited to, a cell phone, a smartphone, a smartwatch, a softphone, a telephone, an intercom device, a computer, a tablet, a mobile computer, an alarm, a bell, a notification device, a pager, and / or other devices configured to convert received electrical and / or communication signals. In one embodiment, the communication device 124 may be used to receive communications sent from the wearable device 104 via the reader 112.

[0046] Figure 1B illustrates an access control system 100 in accordance with at least one exemplary embodiment. It should be appreciated that Figure 1B is the same as Figure 1A, except that it does not include the wearable device 104. For the sake of brevity, a full description of Figure 1B will not be provided here.

[0047] 2, a block diagram illustrating a wearable device 104 is shown in accordance with at least one exemplary embodiment. The wearable device 104 may include one or more components, such as a memory 204, a processor 208, antennas 212A-N, a communication module 216, a wearable sensor 220, a motion sensor 224, and a position sensor 228. In some embodiments, the wearable device 104 may further include a power module. The processor 208 may be an application specific integrated circuit (ASIC), a microprocessor, a programmable controller, or the like.

[0048] The memory 204 of the wearable device 104 may be used in connection with the execution of application programs or instructions by the processor 208, or may be used for temporary or long-term storage of program instructions and / or data. The memory 204 may include executable functions used by the processor 208 to cause other elements of the wearable device 104 to run. In one embodiment, the memory 204 may be configured to store credential information (or credential data) and / or access control information. For example, the credential information / access control information may include, but is not limited to, a unique identifier, manufacturer identification information, passwords, keys, encryption schemes, transmission protocols, etc. By way of example, the memory 204 may include RAM, DRAM, SDRAM, or other solid-state memory.

[0049] The one or more antennas 212A-N may be configured to enable wireless communication between the wearable device 104 and the reader 112 and / or the mobile device 108. As will be appreciated, the antennas 212A-N may be configured to operate using one or more wireless communication protocols and operating frequencies, including but not limited to Bluetooth, NFC, Zig-Bee, GSM, CDMA, Wi-Fi, UWB, RF, etc. For example, the antennas 212A-N may be RF antennas and thus capable of transmitting RF signals over free space to be received by the reader 112 having an RF transceiver. One or more of the multiple antennas 212A may be driven or operated by a dedicated antenna driver 214.

[0050] In some embodiments, the wearable device 104 may include a power module. The power module may be configured to provide power to operate portions of the wearable device 104. The power module may store power in a capacitor in the power module. In one embodiment, when an RF field is present, electronic elements in the power module may store energy in a capacitor and shut down. This configuration may ensure that the wearable device 104 is energized while minimizing any impact on the reading distance. While the wearable device 104 may be configured to passively receive power from the electric field of the reader 112, it should be appreciated that the wearable device 104 may provide its own power. For example, the power module may include a battery or other power source that provides power to portions of the wearable device 104.

[0051] The wearable device 104 may include a communications module 216 configured to communicate with one or more different systems or devices, either remote or local to the wearable device 104. Thus, the communications module 216 can send and receive messages from other wearable devices 104, mobile devices 108, readers 112, communications devices 124, access servers 120, access control systems, or other systems. In at least one exemplary embodiment, the communicated information can be provided to or exchanged with other elements within the wearable device 104.

[0052] Exemplary embodiments of the wearable device 104 may include at least one wearable sensor 220. In particular, the wearable sensor 220 may be configured to detect attachment and / or detachment of the wearable device 104 to the user 102. For example, the wearable device 104 may include a clasp (e.g., similar to the clasps on watch bands, bracelets, earrings, necklaces, etc.) that must be opened to attach and / or detach the wearable device 104 to the user 102. Operation of the clasp can be detected by the wearable sensor 220 of the wearable device 104. Other examples of the wearable sensor 220 may include, but are in no way limited to, a contact sensor, a switch, a proximity sensor, etc. and / or combinations thereof.

[0053] In at least one exemplary embodiment, the wearable device 104 may employ one or more sensors 220, 224, 228 configured to sense information corresponding to a state of the wearable device 104. The wearable sensors 220 may include, but are not limited to, one or more biometric sensors (e.g., heart rate, body temperature and / or fever symptoms, blood pressure, etc.), capacitive sensors, optical sensors, temperature sensors, pressure sensors, contact sensors, combinations thereof, etc. In at least one exemplary embodiment, the processor 208 of the wearable device 104 can receive the sensor information and determine whether the wearable device 104 is being worn by the user 102, whether the wearable device 104 has been removed from the user 102, whether any disruption to the wearing of the wearable device 104 has been detected (e.g., whether the wearable device 104 has been continuously worn and / or removed by the user 102, the associated timing, etc.). For example, a biometric sensor of the wearable sensor 220 may detect a biometric characteristic (e.g., heart rate, blood pressure, body temperature, skin contact data, etc.) associated with the user 102 wearing the wearable device 104. The biometric characteristic may be used to determine the state of the wearable device 104 (e.g., whether it is being worn, etc.) and / or to determine an attribute of the user 102 wearing the wearable device 104 (e.g., through a comparison of the collected biometric characteristic with a baseline characteristic stored in memory and associated with the user 102, etc.).

[0054] The motion sensor 224 may include one or more gyroscopes, accelerometers, transducers, and / or other mechanical sensing elements each configured to sense forces and / or motion associated with the wearable device 104. The sensed motion of the wearable device 104 may be compared to known motion profiles stored in the memory 204 or other associated memory via the processor 208 of the wearable device 104 in determining the state of the wearable device 104. For example, a particular motion of the wearable device 104 may indicate that the wearable device 104 is being worn by a user 102. In one embodiment, the sensed motion of the wearable device 104 may be compared to the sensed motion of an associated mobile device 108 (or vice versa) to generate a comparison result. The association of mobile devices 108 may be between wearable devices 104 and / or between users 102 having wearable devices 104. In either case, the comparison result may indicate a similarity between the motion of the wearable device 104 and the motion of the mobile device 108 over time. Similar motion comparison results between the wearable device 104 and the mobile device 108 can be used to continuously authenticate the user 102. Additionally, the wearable device 104, the mobile device 108, and / or the reader 112 can use the motion comparison results (or simply the sensed motion information) to assist in making entry or exit decisions for the mobile device 108 and / or the wearable device 104. Dissimilar motion comparison results between the wearable device 104 and the mobile device 108 can be used to disable or stop continuous authentication for the user 102. In one embodiment, continuous authentication can be interrupted, stopped, and / or denied if extreme motion is detected on one device (e.g., the wearable device 104 or the mobile device 108) but not on the other device.

[0055] The wearable device 104 may include one or more position sensors 228. The position sensors may be configured to determine the geographic position and / or location of the wearable device 104. In one embodiment, the position may be based on Global Positioning System (GPS) data provided by a GPS module of the wearable device 104. In some embodiments, the position of the wearable device 104 may be provided based on cell tower data, Wi-Fi information, iBeacon information, and / or some other location information provided by the location module and / or communications module 216 of the wearable device 104. The position of the mobile device 108 may be determined in a similar, if not identical, manner to determining the position of the wearable device 104. Location information is not always available within a structure, such as a building; however, where available, the position information provided by one or more position sensors 228 may be used to perform entry or exit determination of the wearable device 104 and / or mobile device 108.

[0056] FIG. 3 illustrates a block diagram of a mobile device 108 according to at least one exemplary embodiment. The mobile device 108 may correspond to any type of electronic device, and as the name suggests, electronic devices may, of course, be portable. As some examples, the mobile device 108 may correspond to a mobile phone or smartphone carried by a user. Other examples of the mobile device 108 include, but are not limited to, wearable devices (e.g., eyeglasses, watches, shoes, clothing, jewelry, bracelets, stickers, etc.). The mobile device 108 may include a key vault 312 that stores one or more keys, as shown in FIGS. 1A / 1B and 3. The keys (or credential data) may be communicated to the reader 112 in association with the holder of the mobile device 108 attempting to access an asset protected by the reader 112. As an example, the mobile device 108 may be presented to the reader 112 by the user 102 or holder of the mobile device 108.

[0057] When NFC is used as the communication channel, the respective interfaces / antennas of the reader 112 and the mobile device 108 are inductively coupled, at which point the reader and / or mobile device 108 can authenticate or mutually authenticate each other. Following authentication, the reader 112 can request one or more keys from the mobile device 108, or the mobile device 108 can provide one or more keys to the reader 112. Upon receiving a key from the mobile device 108, the reader 112 can analyze the key to determine whether the key is valid and, if valid, allow the holder / user of the mobile device 108 access to the asset protected by the reader 112. It should be appreciated that the mobile device 108 can alternatively or additionally be configured to analyze information received from the reader 112 in connection with making access control decisions and / or in connection with determining whether to provide a key to the reader 112. Examples of techniques that a mobile device 108 can utilize to make its own access control decisions are described in more detail in U.S. Pat. No. 8,074,271 to Davis et al. and U.S. Pat. No. 7,706,778 to Lowe, both of which are incorporated herein by reference in their entireties.

[0058] When using BLE or some other non-inductive protocol (e.g., Wi-Fi) for the communication channel, the reader 112 and the mobile device 108 may perform a discovery routine before pairing or otherwise connecting with each other to establish a communication channel. However, after establishing the communication channel, the reader 112 and the mobile device 108 may authenticate each other and exchange relevant information, such as keys, to enable access control decisions to be made. If a positive access control decision is made (e.g., the key is determined to be valid and the mobile device 108 is authorized to access the asset protected by the reader 112), the reader 112 may initiate one or more actions to allow the holder / user 102 of the mobile device 108 to access the asset protected by the reader 112.

[0059] The mobile device 108 is shown as including computer memory 304 that stores, among other elements, one or more operating systems (O / S) 308 and a key repository 312. The mobile device 108 is also shown as including a processor 316, one or more drivers 320, a user interface 324, a reader interface 328, a network interface 332, and a power module 336. Suitable examples of the mobile device 108 include, but are not limited to, smartphones, PDAs, laptops, PCs, tablets, netbooks, wearable devices, etc.

[0060] The memory 304 may correspond to any type of non-transitory computer-readable medium. In some embodiments, the memory 304 may include volatile or non-volatile memory and a controller for the memory. Non-limiting examples of memory 304 available on the mobile device 108 include RAM, ROM, buffer memory, flash memory, solid-state memory, or variations thereof.

[0061] The O / S 308 may correspond to one or more operating systems. The nature of the O / S 308 may depend on the hardware of the mobile device 108 and the form factor of the mobile device 108. The O / S 308 may be considered a processor-executable application stored in the memory 304. The O / S 308 is a particular type of general-purpose application that allows other applications stored in the memory 304 (e.g., a browser, an email application, an SMS application, etc.) to utilize the various hardware elements and drivers 320 of the mobile device 108. In some embodiments, the O / S 308 may include one or more APIs that enable applications to interact with particular hardware elements of the mobile device 108. Additionally, the O / S 308 may provide mechanisms for browsing and accessing the various applications stored in the memory 304 and other data stored in the memory 304.

[0062] The processor 316 may correspond to one or more microprocessors housed within the housing of the mobile device 108 along with the memory 304. In some embodiments, the processor 316 incorporates the functionality of the user equipment's central processing unit (CPU) into a single integrated circuit (IC) or several IC chips. The processor 316 may be a versatile, programmable device that accepts digital data as input, processes the digital data according to instructions stored in its internal memory, and provides the results as output. Because of its internal memory, the processor 316 implements sequential digital logic. Like most known microprocessors, the processor 316 can perform operations on numbers and symbols represented in binary notation.

[0063] The drivers 320 correspond to hardware, software, and / or controllers that provide specific instructions to the hardware elements of the mobile device 108 so that they can perform those operations. For example, the user interface 324, the reader interface 328, and the network interface 332 may each have a dedicated driver 320 that provides the appropriate control signals to perform its operations. The drivers 320 may also include software or logic that ensures that the various hardware elements are controlled appropriately and according to the desired protocol. For example, the driver 320 for the reader interface 328 may be adapted to ensure that the reader interface 328 follows an appropriate proximity-based protocol (e.g., BLE, NFC, UWB, infrared, ultrasonic, IEEE 802.11N, etc.) so that the reader interface 328 can communicate bidirectionally with the credential. Similarly, the driver 320 for the network interface 332 may be adapted to ensure that the network interface 332 conforms to an appropriate network communication protocol (e.g., TCP / IP (at one or more layers of the OSI model), UDP, RTP, GSM, LTE, Wi-Fi, etc.) so that the network interface 332 is capable of bidirectional communication over the communications network 128. As will be appreciated, the driver 320 may also be configured to control wired hardware elements (e.g., USB drivers, Ethernet drivers, etc.).

[0064] The user interface 324 may include one or more user input devices and / or one or more user output devices. Examples of suitable user input devices that may be included in the user interface 324 include, but are not limited to, buttons, keyboards, mice, touch-sensitive surfaces, pens, cameras, microphones, etc. Examples of suitable user output devices that may be included in the user interface 324 include, but are not limited to, display screens, touch screens, lights, speakers, etc. It should be appreciated that the user interface 324 may include devices that combine user input and user output devices, such as a touch-sensitive display.

[0065] The reader interface 328 may correspond to hardware that facilitates communication of credential data with the mobile device 108. The reader interface 328 may include a Bluetooth interface (e.g., an antenna and associated circuitry), a Wi-Fi / 802.11N interface (e.g., an antenna and associated circuitry), an NFC interface (e.g., an antenna and associated circuitry), a UWB interface (e.g., an antenna and associated circuitry), an infrared interface (e.g., an LED, a photodiode, and associated circuitry), and / or an ultrasonic interface (e.g., a speaker, a microphone, and associated circuitry). In some embodiments, the reader interface 328 is provided specifically to facilitate proximity-based communication with the credential over one or more communication channels.

[0066] The network interface 332 may include hardware that facilitates communication with other communication devices over the communication network 128. As described above, the network interface 332 may include an Ethernet port, a Wi-Fi card, a network interface card (NIC), a cellular interface (e.g., an antenna, filters, and associated circuitry), etc. The network interface 332 may be configured to facilitate a connection between the mobile device 108 and the communication network 128, and may further be configured to encode and decode communications (e.g., packets) according to a protocol utilized by the communication network 128.

[0067] The power module 336 may include a power converter that converts AC power from an internal power source (e.g., a battery) and / or an externally supplied source into DC power used to power various elements of the mobile device 108. In some embodiments, the power module 336 may also include some implementation of surge protection circuitry that protects elements of the mobile device 108 from power surges.

[0068] FIG. 4 illustrates a block diagram of reader 112 in accordance with at least one example embodiment. When NFC is used for the communication channel between the mobile device 108 and the reader 112, the interface / antenna of the reader 112 and the mobile device 108 are inductively coupled, at which point the reader and / or mobile device 108 can authenticate or mutually authenticate each other. Following authentication, the reader 112 can request one or more keys from the mobile device 108, or the mobile device 108 can provide one or more keys to the reader 112. Upon receiving a key from the mobile device 108, the reader 112 can analyze the key to determine whether the key is valid and, if valid, allow the holder / user of the mobile device 108 access to assets protected by the reader 112. For example, the reader 112 can include a key vault 412 that stores one or more keys. The keys (or credential data) can correspond to keys or credential data also stored in the key vault 312 of the mobile device 108. The keys in the key vault 412 can be used by the reader 112 to make access control decisions. For example, if a key received from a mobile device 108 matches a key in the key vault 412, the reader 112 can allow the user 102 holding the mobile device 108 to access the asset secured by the reader 112.

[0069] If the communication channel between the mobile device 108 and the reader 112 uses BLE or some other non-inductive protocol (e.g., Wi-Fi), the reader 112 and the mobile device 108 may perform a discovery routine before pairing or otherwise connecting with each other to establish a communication channel. However, after establishing the communication channel, the reader 112 and the mobile device 108 may authenticate each other and exchange relevant information, such as keys, to enable access control decisions to be made. If a positive access control decision is made (e.g., the key is determined to be valid and the mobile device 108 is authorized to access the asset protected by the reader 112), the reader 112 may initiate one or more actions to allow the holder / user 102 of the mobile device 108 to access the asset protected by the reader 112.

[0070] Reader 112 is shown to include computer memory 404 that stores, among other elements, one or more operating systems (O / S) 408 and a key repository 412. Reader 112 is also shown to include a processor 416, one or more drivers 420, a system interface 424, a reader interface 428, a network interface 432, and a power module 436.

[0071] The memory 404 may correspond to any type of non-transitory computer-readable medium. In some embodiments, the memory 404 may include volatile or non-volatile memory and a controller for the memory. Non-limiting examples of memory 404 available to the reader 112 include RAM, ROM, buffer memory, flash memory, solid-state memory, or variations thereof.

[0072] O / S 408 may correspond to one or more operating systems. The nature of O / S 408 may depend on the hardware of reader 112 and the form factor of reader 112. O / S 408 may be viewed as a processor-executable application stored in memory 404. O / S 408 is a particular type of general-purpose application that allows other applications stored in memory 404 (e.g., a browser, an email application, an SMS application, etc.) to utilize the various hardware elements of reader 112 and drivers 420. In some embodiments, O / S 408 may include one or more APIs that enable application interaction with particular hardware elements of reader 112. Additionally, O / S 408 may provide mechanisms for browsing and accessing the various applications stored in memory 404 and other data stored in memory 404.

[0073] The processor 416 may correspond to one or more microprocessors housed within the housing of the reader 112 along with the memory 404. In some embodiments, the processor 416 incorporates the functionality of a user device's central processing unit (CPU) into a single integrated circuit (IC) or several IC chips. The processor 416 may be a versatile, programmable device that accepts digital data as input, processes the digital data according to instructions stored in its internal memory, and provides the results as output. Because of its internal memory, the processor 416 implements sequential digital logic. Like most known microprocessors, the processor 416 can perform operations on numbers and symbols represented in binary notation.

[0074] The drivers 420 correspond to hardware, software, and / or controllers that provide specific instructions to the hardware elements of the reader 112 so that they can perform those operations. For example, the system interface 424, the reader interface 428, and the network interface 432 may each have a dedicated driver 420 that provides the appropriate control signals to perform its operations. The drivers 420 may also include software or logic that ensures that the various hardware elements are controlled appropriately and according to a desired protocol. For example, the driver 420 for the reader interface 428 may be adapted to ensure that the reader interface 428 follows the appropriate protocol so that the reader interface 428 can bidirectionally communicate with the mobile device 108. The driver 420 for the system interface 424 may be adapted to ensure that the system interface 424 follows the appropriate protocol so that the system interface 424 can bidirectionally communicate with the system interfaces 424 of other readers 112. Similarly, driver 420 for network interface 432 may be adapted to ensure that network interface 432 complies with an appropriate network communications protocol (e.g., TCP / IP (at one or more layers of the OSI model), UDP, RTP, GSM, LTE, Wi-Fi, etc.) so that network interface 432 is capable of bidirectional communications over communications network 128. As will be appreciated, driver 420 may also be configured to control wired hardware elements (e.g., USB drivers, Ethernet drivers, etc.) associated with interfaces 424, 428 and / or 432.

[0075] The system interface 424 may include hardware that facilitates communication with system interfaces of other readers 112 to create a reader network. The system interface 424 may include an Ethernet port, a Wi-Fi card, a network interface card (NIC), a cellular interface (e.g., antenna, filters, and associated circuitry), etc. The system interface 424 may be configured to facilitate coupling between system interfaces of other readers 112. The connections may be between readers 112 and / or with the communication network 128. The system interface 424 may further be configured to encode and decode communications (e.g., packets) according to protocols utilized by the reader 112 and / or the communication network 128.

[0076] System interface 424 may also include one or more user input devices and / or one or more user output devices. Examples of suitable user input devices that may be included in system interface 424 include, but are not limited to, buttons, keyboards, mice, touch-sensitive surfaces, pens, cameras, microphones, etc. Examples of suitable user output devices that may be included in system interface 424 include, but are not limited to, display screens, touch screens, lights, speakers, etc. It should be appreciated that system interface 424 may also include a combination of user input and user output devices, such as a touch-sensitive display.

[0077] The reader interface 428 may correspond to hardware that facilitates communication of credential data with the mobile device 108. The reader interface 428 may include a Bluetooth interface (e.g., an antenna and associated circuitry), a Wi-Fi / 802.11N interface (e.g., an antenna and associated circuitry), an NFC interface (e.g., an antenna and associated circuitry), a UWB interface (e.g., an antenna and associated circuitry), an infrared interface (e.g., an LED, a photodiode and associated circuitry), and / or an ultrasonic interface (e.g., a speaker, a microphone and associated circuitry). In some embodiments, the reader interface 428 is provided specifically to facilitate proximity-based communication with the credential over one or more communication channels.

[0078] The network interface 432 may include hardware that facilitates communication with other communication devices over the communication network 128. As described above, the network interface 432 may include an Ethernet port, a Wi-Fi card, a network interface card (NIC), a cellular interface (e.g., an antenna, filters, and associated circuitry), etc. The network interface 432 may be configured to facilitate a connection between the mobile device 108 and the communication network 128, and may further be configured to encode and decode communications (e.g., packets) according to a protocol utilized by the communication network 128.

[0079] 5 illustrates the stages of a credential 108 accessing a reader 112 in the system 100. As shown in FIG. 5, in the first stage 1, the credential 108 is out of range of the system 100. In this stage, there is no communication between the reader 112 and the credential 108. However, the reader 112 and / or the credential 108 may actively attempt to connect with other devices. For example, the reader 112 may "listen" for requests by the credential 108 to establish a connection with the reader 112.

[0080] In a second phase 2, the credential 108 enters the communication range of the reader 112. During this phase, the reader 112 establishes a link (or session) with the credential 108. For example, the reader 112 initiates the establishment of a link with the credential 108 when the credential 108 enters the communication range of the reader 112. In at least one exemplary embodiment, the communication range is based on the transmit / receive range of the reader 112 and / or the credential 108. The communication range may further be based on the operating frequency of the protocol used to establish the link between the reader 112 and the credential 108. In at least one exemplary embodiment, the reader 112 is configured to determine the communication range based on the environment surrounding the reader 112. For example, the reader 112 may perform any number of known operations to determine the level of interference surrounding the reader 112 (e.g., using time of flight (ToF) principles, channel estimation techniques, etc.). The reader 112 may periodically re-evaluate the environment surrounding the reader 112 and adjust its communication range based thereon (e.g., increasing or decreasing transmit power, ignoring or accepting connection requests by credentials 108 within a threshold distance of the reader 112, etc.). Additionally or alternatively, the reader 112 may determine its communication range based on other factors, such as the number of credentials 108 within communication range of the reader 112. For example, if the number of credentials 108 within communication range of the reader 112 exceeds a threshold, the reader 112 may reduce its communication range (e.g., temporarily reducing transmit power, ignoring credentials 108 that are farther than a threshold distance from the reader 112, etc.). It should be understood that the threshold distances and timings discussed above may be design parameters established based on experience and / or preference.

[0081] In addition to establishing a link between the reader 112 and the credential 108, the second stage may also include performing mutual authentication between the reader 112 and the credential 108. The second stage may further include the reader 112 receiving credential data from the credential 108, verifying the credential data, marking the credential 108 as valid based on the credential data, and tracking the location of the credential 108. During the second stage, the reader 112 delays making access control decisions for the credential 108.

[0082] In a third phase 3, the credential 108 enters the decision range of the reader 112 (or an access mechanism under the control of the reader 112). The decision range may correspond to a distance from the reader 112 at which the reader 112 makes an access control decision for the credential 108 and controls an access control mechanism (e.g., a door) to allow or deny access to a secured asset or zone by the reader 112. In at least one example embodiment, the reader 112 makes an access control decision for the credential 108 once the credential 108 enters the decision range, but delays activation of the access control mechanism until the credential 108 enters another range (e.g., an access range) that is closer to the reader 112 than the decision range. The communication protocol used for communication between the credential 108 and the reader 112 while the credential 108 is within the determination range of the reader 112 may be the same as or different from the protocol used for communication between the credential 108 and the reader 112 while the credential 108 is within the communication range of the reader 112. For example, a Bluetooth or BLE protocol may be used for communication between the credential 108 and the reader 112 while the credential 108 is within the communication range of the reader 112, whereas a UWB or NFC protocol may be used for communication between the credential 108 and the reader 112 while the credential 108 is within the determination range of the reader 112.

[0083] FIG. 6 illustrates an exemplary operation of the system 100 of FIGS. 1A and 1B, where the system 100 includes multiple readers 112 and multiple credentials 108. As shown in FIG. 6, the system 100 also includes multiple credentials 108, including readers 112A-C and a selected credential 108S. FIG. 6 further illustrates a reader controller 600 that enables communication with and / or control of the readers 112A-C, for example, via a communication network compatible with each system interface 424. The reader controller 600 may include a message broker that may be Message Queueing Telemetry Transport (MQTT) compliant and compatible with ISO standard ISO / IEC PRF20922. The reader controller 600 may correspond to a local or remote server having storage and processing capabilities. In at least one exemplary embodiment, the reader controller 600 is included in the access server 120.

[0084] 6 assumes an exemplary operation including multiple readers 112A-C using at least the Bluetooth protocol, e.g., Bluetooth Smart-based credentials and Bluetooth MAC address-based marking, along with any other communication protocols as needed. In this example, reader 112B performs all of the operations of step 2 of FIG. 5 for a selected credential 108S, including the marking operation to maintain the connection between credential 108S and reader 112B.

[0085] The reader 112B then publishes a marking event containing the MAC address of the credential 108S to the reader controller 600. The operation may include additional low-level wireless protocol-based information, such as the Bluetooth channel hopping scheme employed for the particular connection.

[0086] As shown in FIG. 6, other readers 112A, 112C subscribe to the reader controller 600 to receive notification of the marking event and begin tracking the "marked" valid credential 108S. One option is for the readers 112A, 112C to analyze and / or monitor communications between the credential 108S and the reader 112A to detect that the credential 108S has been marked and is being tracked. For example, the readers 112A, 112C can monitor and / or analyze Bluetooth communications to look for specific packets that the credential 108S continuously transmits while still connected to the reader 112B. Tracking or ranging of the credential 108S can alternatively or additionally be performed using a communication protocol different from that used to authenticate and / or mark the credential 108S. For example, a Bluetooth or BLE protocol may be used for authenticating and / or marking the credential 108S, whereas a UWB protocol may be used for tracking or ranging the credential 108S.

[0087] If reader 112A detects that the marked credential in close proximity is valid, reader 112A makes an access control decision for credential 108S that has already been verified by reader 112B. The access control decision for credential 108S may be performed using the same or a different communication protocol than that used for authentication and / or marking, and the same or a different communication protocol than that used for tracking or ranging credential 108S. For example, Bluetooth or BLE and / or UWB protocols may be used for authentication, marking, and / or ranging credential 108S, while NFC or UWB protocols may be used for access control decisions. Thus, as described above, when multiple readers 112A-C communicate with each other over a communications network, the first reader 112B of the multiple readers that marked and tracked the credential 108S may notify the rest of the multiple readers 112A, 112C that the credential 108S is marked and tracked, enabling the rest of the multiple readers 112A, 112C to track the credential 108S.

[0088] Additionally or alternatively, the remainder of the multiple readers 112A, 112C monitor and / or analyze communications between the first reader 112B and the credential 108S to enable the readers 112A, 112B to make access control decisions for the credential 108S.

[0089] In at least one example embodiment, reader 112B publishes all information so that 112A can directly take over communication with credential 108S (e.g., reader 112B relinquishes control of credential 108S and reader 112A begins tracking and publishing information for credential 108S). For example, reader 112B publishes information about the session between reader 112B and credential 108S so that reader 112A can take over the session.

[0090] FIG. 7 illustrates a method 700 according to at least one example embodiment. As shown in FIG. 7, the method begins with operation 700 and ends with operation 768. It should be understood that the method may include additional operations not shown. Furthermore, the operations of the method may be performed in a different order than shown, if desired. In the case of system 100, the method may be performed by one or more of the elements shown in FIGS. 1A-6 and described above. Accordingly, FIG. 7 will be described with reference to FIGS. 1A-6.

[0091] In operation 704, the method determines whether the credential 108 is within range of at least one reader 112. For example, the credential 108 searches for nearby readers 112 by checking for broadcast signals from the readers 112 and / or from an access server 120 that is in communication with the reader 112 and the credential 108. If no readers 112 are nearby, the method continues to check whether the credential 108 is within range.

[0092] If a reader is nearby, the method establishes a link (i.e., a wireless link) with the credential 108 via a first communications network that enables wireless communication. For example, the credential 108 may initiate link establishment with the reader 112 when the credential 108 enters communication range. In another example, at least one reader 112 initiates link establishment when the credential 108 enters communication range of the at least one reader. Link establishment may include establishing a transport protocol link and session between the at least one reader 112 and the credential 108, which may include exchanging various request and authorization response messages between the at least one reader 112 and the credential 108 according to a protocol used in the first communications network. According to at least one example embodiment, the communication range is based on the transmission / reception range of the at least one reader 112 and / or the credential 108. Additionally or alternatively, the communication range may be based on the operating frequency of the protocol used to establish the link, the environment surrounding the at least one reader, and / or other factors, as described above with reference to FIG.

[0093] In at least one exemplary embodiment, a wireless link between the credential 108 and the access server 120 is established and maintained over a wireless network such as Wi-Fi, LTE, etc., while a separate link (e.g., a wired link such as an RS-422 link) is established between the access server 120 and at least one reader 112. In this case, the access server 120 can mark / track the credential 108, manage the operation of the system 100 according to the process of Figure 7 for the credential 108, and notify the reader 112 of access control decisions.

[0094] In operation 712, the method performs mutual authentication between the credential 108 and at least one reader 112 over the link. The mutual authentication operation may include any known method for authenticating two devices. For example, the authentication operation may adhere to communication protocols / standards using Fast Identity Online Universal Second Factor (FIDO U2F), FIDO 2.0 (Client to Authenticator Protocol (CTAP)), Open Authentication Initiative (OATH), public key infrastructure (PKI), personal identity verification (PIV), open protocol for access control, identification, and ticketing with privacy (OPACITY), etc.

[0095] In operation 716, the method determines whether the mutual authentication was successful. If not, the method terminates the link in operation 720. If mutual authentication is successful at operation 716, the method proceeds to operation 724, where credential data is received over the link. For example, the credential 108 sends the credential data over the link to at least one reader 112. Mutual authentication is considered successful if the at least one reader 112 establishes itself as a trusted reader for the credential 108, and the credential establishes itself as a trusted credential 108 for the at least one reader 112. As mentioned above, the credential data may include one or more keys (e.g., unique keys) or other data stored in key vault 312 and / or 412.

[0096] In operation 728, the method includes verifying that the credential 108 is valid based on the credential data. For example, at least one reader 112 compares the credential data received from the credential 108 with the credential data stored in the key vault 412. If there is no match, the credential 108 is determined to be invalid and the method proceeds to operation 732 to terminate the link. If there is a match, the credential 108 is determined to be valid and the method proceeds to operation 736. Validating the credential data may additionally or alternatively include verifying biometric information of the user of the credential 108 to ensure that the user is an authorized user of the credential 108. The biometric information can be verified on the credential 108 (e.g., facial recognition, fingerprint detection, etc.) if the remaining elements of the access control system 100 do not have knowledge of the biometric information.

[0097] In operation 736, the method marks the credential 108 as valid and tracks the location of the credential 108. According to at least one exemplary embodiment, the method includes making or delaying an access control decision for the credential 108 based on the location of the credential 108 (see operations 740-748). According to at least one exemplary embodiment, the location of the credential is tracked relative to at least one reader 112. In at least one exemplary embodiment, only one reader 112 tracks the location of the credential 108. In at least one other exemplary embodiment, multiple readers 112 track the location of a single credential 108 or are informed of the location by a single reader 112 (e.g., via reader controller 600).

[0098] Exemplary embodiments include different methods of marking the credential 108 as valid in operation 736. For example, at least one exemplary embodiment includes marking the transport protocol MAC address of the credential 108, which may be useful if the established link is a public session and the MAC address of the credential 108 does not change during the public session. Another exemplary embodiment includes marking the TCP / IP protocol IP address and / or other network protocol identifier that can be used to uniquely or substantially uniquely identify the credential based at least on time. Yet another exemplary embodiment includes marking a session identifier of the session established between the credential and the reader. In another example, the reader 112 can provide an “access token,” one-time password (OTP), or the like, to a device that the reader 112 can read at a desired distance. In yet another example, the reader 112 can send a temporary key to the credential, which can then be used at the reader for key proofing in a possession protocol (e.g., as a challenge response based on the temporary key or as a cryptographic or signature generated by the credential).

[0099] Exemplary embodiments include different methods of tracking the credential 108 in operation 736. For example, operation 736 may include at least one reader 112 tracking the location of the credential based on a received signal strength indication (RSSI) from the credential 108. The stronger the RSSI from the credential 108, the closer the credential 108 is to the reader 112 during the sensing operation. Tracking may additionally or alternatively include tracking the credential 108 with respect to one or more readers 112 using an estimate of the credential 108's potential angle of arrival (e.g., using triangulation with multiple antennas or multiple readers) and / or time-of-flight characteristics (and in exemplary embodiments with multiple antennas or multiple readers, additionally using, for example, trilateration or multilateration techniques).

[0100] In at least one exemplary embodiment, the credential 108 can be tracked based on an ongoing transport protocol connection if the connection remains open. Here, exemplary embodiments can analyze packets sent by the credential 108 to the reader 112 using a packet-based protocol such as Bluetooth Smart (BLE) or Wi-Fi. For example, process 736 includes at least one reader 112 periodically pinging the credential 108 to keep the link open (e.g., trackable). For example, the reader 112 can “ping” the credential 108 by attempting to read some existing data or even some non-existent data at regular intervals. The ping simulates to the credential 108 that the reader 112 is still transacting with the credential 108 and therefore will not close the connection with the reader 112.

[0101] Still further, process 736 may include at least one reader 112 tracking the location of the credential 108 by receiving a broadcast signal from the credential 108. The broadcast signal may include a token belonging to the credential 108 to identify the credential to at least one reader 112. For example, the credential 108 may be assigned an access token, which may then be broadcast (advertised) by the credential 108. The reader 112 would then scan / listen for advertisements containing the access token to mark and track the credential 108. In at least one exemplary embodiment, the advertisements change over time, including a time-based calculated encryption and a temporary key assigned as described above. One such example is using a rounded time-limited one-time password (TOTP) encryption for advertisements, where the encryption is changed periodically (e.g., every 30 seconds).

[0102] The communication protocol used for communication between the credential 108 and the reader 112 during credential validation (e.g., operation 728) may be the same as or different from the protocol used for communication between the credential 108 and the reader 112 that tracks or ranges the credential 108 to determine whether the credential 108 is within a decision range (e.g., operation 740). For example, a Bluetooth or BLE protocol may be used for communication between the credential 108 and the reader 112 during credential validation, while a UWB or NFC protocol may be used for communication between the credential 108 and the reader 112 to determine whether the credential is within a decision range.

[0103] Although not explicitly shown, it should be understood that the method may include, between operations 736 and 740, operations including stopping tracking of a credential 108 if the number of credentials 108 being tracked by the at least one reader 112 is above a threshold and if another unauthenticated credential 108 is closer to the at least one reader 112 than the tracked credential. It should be understood here that the at least one reader 112 then performs the operation of Figure 7 on the unauthenticated credential 108. This may cause the at least one reader 112 to prioritize nearby credentials 108, further improving throughput at the access point.

[0104] At operation 740, the method includes determining whether the credential 108 is within a determination range of at least one reader 112. Here, as noted in the description of Figure 5, the determination range may correspond to a first distance from the at least one reader 112, and the communication range may correspond to a second distance greater than the first distance from the at least one reader. Both the determination range and the communication range may be design parameters selected based on empirical evidence, the capabilities and / or preferences of one or more communication protocols used for communication at the communication and determination ranges.

[0105] If the location of the credential 108 indicates that the credential 108 is not within the decision range (i.e., the first distance) of the at least one reader 112, the method proceeds to operation 744, where the at least one reader 112 delays making an access control decision for the credential 108. The method then returns to operation 740 to continue checking whether the credential 108 is within the decision range.

[0106] If, at operation 740, the location indicates that the credential is within the decision range, the method proceeds to operation 748, where at least one reader 112 makes an access control decision for the credential 108. The access control decision may be performed by the reader 112 itself or by an access control system connected to the reader 112. For example, the reader 112 or the access control system compares the verified credential data with a whitelist (e.g., stored in the reader or access control system) to determine whether the credential 108 is permitted to access a zone secured by the reader 112.

[0107] The communication protocol used for communication between the credential 108 and the reader 112 during credential validation (e.g., operation 728) may be the same as or different from the protocol used for communication between the credential 108 and the reader 112 for making the access control decision (e.g., operation 748). For example, a Bluetooth or BLE protocol may be used for communication between the credential 108 and the reader 112 during credential validation, while an NFC protocol may be used for communication between the credential 108 and the reader 112 for making the access control decision. Similarly, the communication protocol used for tracking or ranging the credential 108 to determine whether the credential 108 is within a decision range (e.g., operation 740) may be the same as or different from the protocol used for communication between the credential 108 and the reader 112 for making the access control decision (e.g., operation 748). For example, a Bluetooth (e.g., BLE) or UWB protocol may be used to track or range the credential 108 to determine whether the credential 108 is within a decision range, while an NFC protocol may be used to communicate between the credential 108 and the reader 112 for access control decisions.

[0108] In operation 752, the method includes determining whether the access control decision is a positive access control decision. If not, the method proceeds to operation 756, where access to the credential 108 is denied before terminating the link in operation 764. If so, the method proceeds to operation 760, where access to the credential 108 is permitted. For example, the at least one reader 112 controls at least one access mechanism (e.g., a door, turnstile, etc.) to deny or permit access to the zone protected by the at least one reader. The method then proceeds to operation 764, where the link is terminated. According to at least one exemplary embodiment, the at least one reader 112 stops tracking the credential 108 and terminates the link once the credential 108 enters the zone through the at least one access mechanism. The process may include at least one reader 112 tracking the credential 108 until the credential 108 exceeds a threshold value of at least one accessor, at which point tracking is stopped and the link between the credential and the at least one reader 112 is terminated. The threshold value may be defined at a desired distance from the secured side of the at least one accessor associated with the zone.

[0109] In at least one exemplary embodiment, the method continues with operation 748 and includes determining whether the credential 108 is within an access range of at least one access mechanism (i.e., reader 112) before granting or denying access to the zone. That is, the reader 112 makes an access control decision for the credential 108 when the credential 108 enters a decision range, but delays initiation of the access control mechanism until the credential 108 enters another range (e.g., an access range) that is closer to the access mechanism and / or reader 112 than the decision range. This access range may be a design parameter set based on empirical evidence, communication protocol capabilities and / or preferences for the access range.

[0110] FIG. 8 illustrates a method according to at least one example embodiment, in which at least one reader 112 is capable of communicating with a credential 108 using at least Bluetooth (e.g., BLE) and NFC protocols. The method determines whether the credential 108 is within range of the at least one reader 112 in operation 800, and establishes a link between the at least one reader 112 and the credential 108 in operation 804 when the credential 108 is within range of the at least one reader 112. Similar to the method of FIG. 7, but without further detailed description, the method of FIG. 8 may also include mutual authentication and / or credential validation in operation 808. As part of operation 808, the at least one reader 112 may grant or generate and grant an access token, such as an OTP, associated with a session to the credential 108. The processes 804, 808 may be completed using a communication network established between the credential 108 and at least one reader 112 using the Bluetooth (e.g., BLE) protocol.

[0111] The method then includes, at operation 812, the user 102 of the credential 108 "tapping" or otherwise bringing the credential close (e.g., within NFC range) to at least one reader 112 to establish a link between the at least one reader 112 and the credential 108 using the NFC protocol. At operation 816, by communicating with the at least one reader 112 using the NFC protocol, the credential 108 can provide the at least one reader 112 with an access token (e.g., an OTP previously provided to the credential 108 by the at least one reader 112 using the Bluetooth protocol). At operation 820, the at least one reader 112 compares the access token received from the credential 108 using the NFC protocol with the access token previously sent by the at least one reader 112 to the credential 108. If the access tokens match, at operation 824, the at least one reader 112 can grant the user access. If the access tokens do not match, then in operation 828, at least one reader 112 may deny access to the user.

[0112] In some exemplary embodiments, as an alternative (or in addition) to using an NFC-enabled reader to enable the NFC protocol, an NFC tag 132 (see FIG. 1B ) may be used. The NFC tag 132 may be located or placed within the determination and / or access range. The NFC tag 132 may or may not be communicatively coupled to one or more readers 112 and / or the communication network 128.

[0113] FIG. 9 illustrates a method according to at least one example embodiment using an NFC tag 132. In the method, at least one reader 112 can communicate with the credential 108 using at least Bluetooth (e.g., BLE) or a similar protocol. The method determines whether the credential 108 is within range of the at least one reader 112 in operation 900, and establishes a link between the at least one reader 112 and the credential 108 in operation 904 if the credential 108 is within range of the at least one reader 112. Similar to the method of FIG. 7, but without further detailed description, the method of FIG. 9 may also include mutual authentication and / or credential validation in operation 908. As part of operation 908, the at least one reader 112 can assign or generate and assign an access token to the credential 108. In this exemplary embodiment, the access token may be a static lock identifier (ID) that is programmed or stored in the NFC tag 132. Operations 904, 908 may be completed using a communication network established between the credential 108 and the at least one reader 112 using Bluetooth (e.g., BLE) or a similar protocol. The communication network established between the credential 108 and the at least one reader 112 may be maintained for subsequent operations.

[0114] The method then includes, at operation 912, the user 102 of the credential 108 "tapping" or otherwise bringing the credential close (e.g., within NFC range) to the NFC tag 132 to establish a link between the NFC tag 132 and the credential 108 using the NFC protocol. At operation 916, by communicating with the NFC tag 132 using the NFC protocol, the credential 108 can read or receive an access token (e.g., static lock ID) from the NFC tag 132. At operation 920, the credential 108 compares the access token (e.g., static lock ID) received from the NFC tag 132 using the NFC protocol with an access token (e.g., static lock ID) previously sent to the credential 108 by at least one reader 112 using Bluetooth (e.g., BLE) or a similar protocol. If the access tokens match, then in operation 924 the credential 108 communicates or transmits an "unlock" command using Bluetooth (e.g., BLE) or a similar protocol to the at least one reader 112. If the access tokens do not match, then in operation 928 the credential 108 does not send the "unlock" command to the at least one reader 112, but may send a separate command to the at least one reader 112 indicating that the access tokens do not match, although this is not required.

[0115] FIG. 10 illustrates another method according to at least one exemplary embodiment using an NFC tag 132. In this method, at least one reader 112 is capable of communicating with the credential 108 using at least Bluetooth (e.g., BLE) or a similar protocol. The method determines whether the credential 108 is within range of the at least one reader 112 in operation 1000, and establishes a link between the at least one reader 112 and the credential 108 in operation 1004 when the credential 108 is within range of the at least one reader 112. Similar to the method of FIG. 7, but without further detailed description, the method of FIG. 10 may also include mutual authentication and / or credential validation in operation 1008. As part of operation 1008, the at least one reader 112 may grant or generate and grant an access token to the credential 108. In this exemplary embodiment, the access token may be a dynamic token, such as an OTP, associated with a session. The method may also program or store a dynamic token (e.g., an OTP) in the NFC tag 132 in operation 1010. Alternatively, the NFC tag 132 may be programmed with an algorithm to determine the corresponding token or OTP. Operations 1004, 1008 may be completed using a communication network established between the credential 108 and the at least one reader 112 using Bluetooth (e.g., BLE) or a similar protocol. The communication network established between the credential 108 and the at least one reader 112 may be maintained for subsequent operations.

[0116] The method then includes, in operation 1012, the user 102 of the credential 108 "tapping" or bringing the credential close (e.g., within NFC range) to the NFC tag 132 to establish a link between the NFC tag 132 and the credential 108 using the NFC protocol. In operation 1016, communication with the NFC tag 132 using the NFC protocol enables the credential 108 to read or receive an access token (e.g., OTP) from the NFC tag 132. In operation 1020, the credential 108 compares the access token (e.g., OTP) received from the NFC tag 132 using the NFC protocol with an access token (e.g., OTP) previously sent to the credential 108 by at least one reader 112 using Bluetooth (e.g., BLE) or a similar protocol. If the access tokens match, then in operation 1024 the credential 108 communicates or sends an "unlock" command to the at least one reader 112 using Bluetooth (e.g., BLE) or a similar protocol. Alternatively, the credential 108 writes the "unlock" command to the NFC tag 132, and the command can be communicated to the at least one reader 112 or an access control system to grant the user access. If the access tokens do not match, then in operation 1028 the credential 108 may not send the "unlock" command to the at least one reader 112 or write the "unlock" command to the NFC tag 132, but may send another command to the at least one reader 112 indicating that the access tokens do not match, although this is not required.

[0117] Although the exemplary embodiments have been described with respect to operations involving a credential / mobile device 108, it should be understood that the same operations can be performed with respect to one or more wearable devices 104 or any other device having credential data and wireless communication capabilities.

[0118] In view of the above, it should be appreciated that the exemplary embodiments provide systems, methods, and apparatus that improve throughput in high-traffic access control operations while maintaining a high level of security. The exemplary embodiments may also provide improved system load balancing in that credential tracking can be spread evenly across multiple readers.

[0119] In one or more embodiments, the method may be performed using a processor executing machine-readable instructions that may be provided on a machine-readable medium, which may include non-transitory storage media such as RAM, ROM, buffer memory, flash memory, solid-state memory, etc., or variations thereof, or transient or transmission media such as signals transmitted over a network.

[0120] Throughout the above description, references to various elements as "first," "second," etc. should be understood to be non-limiting. That is, the terms "first," "second," etc. are used for convenience of description and are, in some cases, interchangeable. For example, an element referred to as a "first" may later be referred to as a "second," or vice versa, without limiting the illustrative embodiment.

[0121] Although specific details have been set forth in the above description to provide a thorough understanding of the embodiments, it will be understood by those skilled in the art that the embodiments may be practiced without these specific details. In other instances, well-known circuits, processes, algorithms, structures and techniques may not be shown in unnecessary detail so as not to obscure the embodiments.

[0122] Although the exemplary embodiments disclosed herein have been described in detail, it should be understood that the inventive concepts may be embodied and utilized in a variety of other ways, and the appended claims are intended to be construed to include such modifications except insofar as limited by the prior art.

Claims

1. 1. An access control system comprising: at least one reader, receiving credential data from the credential using a non-NFC communication protocol when the credential is within a first distance of the reader; verifying that the credentials are valid based on the credential data; providing a first access token to the credential using the non-NFC communication protocol; and receiving from the credential using the non-NFC communication protocol a command corresponding to an access control decision for the credential based on a comparison of the first access token and a second access token. an NFC tag configured to provide the second access token to the credential using an NFC protocol when the credential is within a second distance of the NFC tag, the second distance being shorter than the first distance.

2. The access control system of claim 1 , wherein the non-NFC communication protocol is a Bluetooth® communication protocol.

3. The access control system according to claim 2 , wherein the Bluetooth communication protocol is a BLE communication protocol.

4. The access control system of claim 1 , wherein the first access token includes a static lock identifier associated with the NFC tag.

5. The access control system of claim 4 , wherein the second access token includes a static lock identifier stored on the NFC tag.

6. The access control system of claim 1 , wherein the first access token comprises a dynamic token.

7. The access control system of claim 6 , wherein the second access token comprises a dynamic token stored on the NFC tag.

8. The access control system of claim 6 , wherein the NFC tag uses an algorithm to determine the second access token.

9. 1. A method for access control, comprising: receiving credential data from the credential at the reader using a non-NFC communication protocol when the credential is within a first distance of the reader; verifying that the credentials are valid based on the credential data; providing a first access token from the reader to the credential using the non-NFC communication protocol; making an access control decision for the credential based on a comparison of the first access token and a second access token, the second access token being communicated to the credential by the NFC tag using an NFC protocol if the credential is within a second distance of an NFC tag, the second distance being less than the first distance; Making an access control decision for the credential based on a comparison of the first access token and the second access token comprises: receiving a command from the credential at the reader after comparing the first access token and the second access token with the credential; and receiving a command from the credential at the reader based on a comparison of the first access token and the second access token with the credential.

10. 10. The method of claim 9, wherein making an access control decision for the credential based on a comparison of the first access token and a second access token comprises receiving from the credential at the reader the command based on the comparison of the first access token and the second access token by the credential.

11. The method according to claim 9 or 10, wherein the non-NFC communication protocol is a Bluetooth communication protocol.

12. The method of claim 11 , wherein the Bluetooth communication protocol is a BLE communication protocol.

13. The method of any one of claims 9 to 12, wherein the first access token comprises a static lock identifier associated with the NFC tag.

14. The method of claim 13 , wherein the second access token includes a static lock identifier stored on the NFC tag.

15. The method of any one of claims 9 to 12, wherein the first access token comprises a dynamic token.

16. The method of claim 15 , wherein the second access token comprises a dynamic token stored on the NFC tag.

17. The method of claim 15 , wherein the NFC tag uses an algorithm to determine the second access token.

Citation Information

Patent Citations

  • Method for managing beacon, terminal device, server and storage medium

    KR1020160026293A

  • Apparatus and method for measuring positions of devices

    KR1020170054862A

  • Hands-free fare gate operation

    US20180144563A1