Trajectory and intent prediction
The system addresses inefficiencies in access control by using machine learning to predict user trajectories and intentions, ensuring secure and efficient long-range access control.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- ASSA ABLOY AB
- Filing Date
- 2025-12-23
- Publication Date
- 2026-04-14
AI Technical Summary
Existing access control systems face challenges in accurately predicting user trajectories and intentions, leading to inefficiencies and potential security breaches due to the need for close proximity credential exchange and the inability to differentiate between intended and unintended access device activation.
A system that utilizes machine learning techniques to process observed user trajectories and behavior information, generating predicted trajectories and intentions, allowing for long-range access control by determining if the access device is within the predicted trajectory and aligned with user intent.
Enables seamless and secure access control by predicting user trajectories and intentions, reducing latency and improving user experience by allowing access without requiring close proximity interaction.
Smart Images

Figure 2026065010000001_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to trajectory and intention prediction.
Background Art
[0002] Trajectory prediction plays an important role in many tasks such as intelligent access control systems. This is generally defined as predicting the position of a movable agent (e.g., a person, vehicle, or mobile device) at each time step within a given future time interval based on a plurality of partial trajectories observed over a period of time.
Summary of the Invention
[0003] In some aspects, a method is provided, the method comprising one or more processors receiving an observed trajectory of a user and user behavior information about the user, processing the observed trajectory by machine learning techniques to generate a plurality of predicted trajectories, wherein the machine learning techniques are trained to establish a relationship between a plurality of training observed trajectories and a plurality of training predicted trajectories, generating the plurality of predicted trajectories, adjusting the plurality of predicted trajectories based on the user behavior information to determine a user intention to operate a target access control device, determining that the target access control device is within a threshold range of a given predicted trajectory of the plurality of predicted trajectories, and in response to determining that the target access control device is within a threshold range of a given predicted trajectory of the plurality of predicted trajectories, performing a process associated with the target access control device.
[0004] In some aspects, the target access control device comprises a lock associated with a door, and performing the process comprises unlocking the door. In some embodiments, the method includes establishing a wireless communication link between the user's mobile device and the target access control device, exchanging authentication information over the wireless communication link, and performing the process after determining, based on the authentication information, that the user is authorized to access the target access control device.
[0005] In some embodiments, the method includes determining, based on the authentication information, that the user is authorized to access the target access control device before performing the process, and delaying the execution of the process after determining that the user is authorized until it is determined that the target access control device is within the threshold range of the given predicted trajectory among the plurality of predicted trajectories.
[0006] In some embodiments, the method includes determining, based on the authentication information, that the user has been granted permission to access the target access control device before performing the process, and preventing the user from performing the process after determining that they have been granted permission, in response to determining that the target access control device is outside the threshold range of the given predicted trajectory among the plurality of predicted trajectories.
[0007] In some embodiments, the machine learning technique includes a conditional variational autoencoder. In some embodiments, adjusting the plurality of predicted trajectories based on the user behavior information includes processing the observed trajectory and the user behavior information by the conditional variational autoencoder to generate the plurality of predicted trajectories, each of which is associated with a likelihood indicating the possibility that the user will move along the corresponding predicted trajectory.
[0008] In some embodiments, the machine learning technique includes a variational autoencoder. In some embodiments, adjusting the plurality of predicted trajectories based on the user behavior information includes associating the user behavior information with the plurality of predicted trajectories output by the variational autoencoder, each of which of the plurality of predicted trajectories is associated with a corresponding likelihood of the user moving along the predicted trajectory.
[0009] In some embodiments, the method includes processing the associated user behavior information and the plurality of predicted trajectories with a second machine learning technique, the second machine learning technique being trained to establish relationships between a plurality of trained user behavior information and a plurality of predicted intentions that activate a plurality of access control devices.
[0010] In some embodiments, the method further comprises encoding the user's observation trajectory, and the machine learning technique is applied to the user's encoded observation trajectory. In some embodiments, the method includes determining whether the received user behavior information satisfies the minimum parameters of the user behavior information.
[0011] In some embodiments, the method includes causing the target access control device to perform the process in response to the determination that the received user behavior information satisfies the minimum parameters of the user behavior information.
[0012] In some embodiments, the method includes preventing the target access control device from performing the process in response to determining that the received user behavior information does not satisfy the minimum parameters of the user behavior information.
[0013] In some embodiments, the minimum parameters include threshold amounts for a specified number of types of user behavior information. In some embodiments, the method includes generating the user behavior information by encoding a feature vector, the generation of the user behavior information includes at least one of monitoring the user's physical movements, monitoring the user's stride, identifying multiple time periods and locations in which the user activates multiple different types of access control devices, identifying other client devices and other types of access control devices within the user's range when a given access control device is activated by the user, and identifying other users who would normally be in the user's own social network.
[0014] In some embodiments, the machine learning technique includes a first machine learning technique, the method comprising generating user behavior information by a second machine learning technique, the second machine learning technique being trained to establish a relationship between trained user behavior information and predicted user behavior information; and generating user intent to activate a target access control device by a third machine learning technique, the third machine learning technique being trained to establish a relationship between trained user behavior information associated with a set of trajectories and predicted user intent to activate a plurality of access control devices.
[0015] In some embodiments, each of the first, second, and third machine learning techniques is trained end-to-end. In some embodiments, a system is provided, comprising one or more processors coupled to memory containing non-temporary computer instructions, the non-temporary computer instructions, when executed by the one or more processors, cause a plurality of processes, the plurality of processes including receiving a user's observation trajectory and user behavior information about the user; processing the observation trajectory by a machine learning technique to generate a plurality of predicted trajectories, the machine learning technique being trained to establish relationships between a plurality of trained observation trajectories and a plurality of trained predicted trajectories; adjusting the plurality of predicted trajectories based on user behavior information to determine the user's intention to activate a target access control device; determining that the target access control device is within a threshold range of a given predicted trajectory among the plurality of predicted trajectories; and performing a process associated with the target access control device in response to the determination that the target access control device is within a threshold range of a given predicted trajectory among the plurality of predicted trajectories.
[0016] In some embodiments, a non-temporary computer-readable medium is provided, the non-temporary computer-readable medium includes non-temporary computer-readable instructions for performing a plurality of operations, the plurality of operations including receiving a user's observation trajectory and user behavior information about the user; processing the observation trajectory by a machine learning technique to generate a plurality of predicted trajectories, the machine learning technique being trained to establish relationships between a plurality of trained observation trajectories and a plurality of trained predicted trajectories; adjusting the plurality of predicted trajectories based on user behavior information to determine the user's intention to activate a target access control device; determining that the target access control device is within a threshold range of a given predicted trajectory among the plurality of predicted trajectories; and performing an operation associated with the target access control device in response to the determination that the target access control device is within a threshold range of a given predicted trajectory among the plurality of predicted trajectories. [Brief explanation of the drawing]
[0017] [Figure 1] Figure 1 is a block diagram of an exemplary access control system according to several embodiments. [Figure 2] Figure 2 shows an exemplary access control system based on trajectory prediction, according to an exemplary embodiment. [Figure 3A] Figure 3A is a block diagram of an exemplary trajectory and intent prediction system that may be placed within the access control system of Figure 1, according to several embodiments. [Figure 3B] Figure 3B is a block diagram of an exemplary trajectory and intent prediction system that may be placed within the access control system of Figure 1, according to several embodiments. [Figure 3C] Figure 3C is a block diagram of an exemplary trajectory and intent prediction system that may be placed within the access control system of Figure 1, according to several embodiments. [Figure 4]Figure 4 is an exemplary database that can be placed within the systems of FIGS. 1, 2, and 3A - C according to some embodiments. [Figure 5] Figure 5 is a flowchart showing exemplary processes of an access control system according to an exemplary embodiment. [Figure 6] Figure 6 is a block diagram showing an exemplary software architecture that can be used in conjunction with the various hardware architectures described herein. [Figure 7] Figure 7 is a block diagram showing multiple components of a machine according to some exemplary embodiments. **DETAILED DESCRIPTION**
[0018] Exemplary methods and systems for an access control system (e.g., a physical or logical access control system) based on trajectory and intent prediction are described. In the following description, for the purpose of providing a complete understanding of the exemplary embodiments, numerous specific details are set forth. However, it will be apparent to those skilled in the art that the various embodiments of the present invention may be practiced without these specific details.
[0019] In a typical access control system, the user carries a physical card or device containing a set of credentials (e.g., authentication information). These credentials are exchanged with an access device (e.g., an electronic door lock) when the physical card or device is brought within approximately 20 centimeters (close proximity) of the access device. At that point, the access device determines whether the credentials grant the user permission to access the device, and if so, it allows access (e.g., unlocks the door). While such a system works well overall, the need for the user to be very close to the access device in order to activate it can result in varying latency when activating the device, potentially causing frustration for the user.
[0020] If multiple mobile devices become commonplace, such mobile devices can be programmed to hold the same set of credentials as commonly used multiple physical cards. These mobile devices can communicate with access devices over longer distances, for example, by using the BLE (Bluetooth Low Energy) communication protocol. For example, a mobile device can transmit and exchange credentials with an access device over a range of up to 100 meters. In such a case, the access device can be activated when the user is at a greater distance from it than when using a physical card or device. In this way, when the user finally reaches the access device, the access device has already received and authenticated the credentials and has granted or denied access to the user. No further action from the user is required to activate the device when the user reaches it (for example, the user does not need to bring a physical card close to the access device).
[0021] However, these other techniques for exchanging credentials via BLE introduce another problem. That is, if there are multiple access devices within the range of the BLE communication protocol, the credentials can be exchanged with a device that the user did not intend to activate. For example, there may be multiple electronic door locks within the range of a user's mobile device that has the credentials for the user to access. However, the user may only intend to unlock or activate one of the multiple electronic door locks. As another example, the user may pass by a given door or access control device for which the user has been granted access rights, but may not intend to pass through or activate the given door or access control device. In such cases, identifying the user's trajectory can play an important role in determining which of the multiple correct access devices to activate and the user's intent regarding activating such a device.
[0022] A typical trajectory prediction system takes a few steps of observed trajectory as input and generates several consecutive positions within a future timeline. These typical trajectory prediction systems can provide a set of trajectories predicted to be within a user's movement path. Most conventional and current methods of future trajectory prediction aim to build a single model that will deal with predictions for many users. Such an approach is highly limited because human movement is inherently unique and dynamic. Also, how one user holds their phone can be very different from how another user holds their phone. For example, some users prefer to hold their mobile device in their hand. This means that when such a user walks, they swing their arm, thereby displacing the mobile device back and forth, resulting in a lot of noise in the two-dimensional (2D) or three-dimensional (3D) position coordinates. Other users may have their phone in their front pocket or back pocket. Also, users will have different strides based on their height or their general preferences regarding walking. Therefore, while typical trajectory prediction systems that depend on the user's location generally work well for predicting multiple future trajectories, they typically do not take user specificity into account and thus lack accuracy requirements, preventing them from being accurately applied in the case of credential exchange and access device control.
[0023] Multiple embodiments disclosed provide intelligent solutions that can accurately predict multiple future locations of a user and determine the user's intent, enabling access control systems to provide users with a proactive and seamless experience while maintaining high security. Multiple embodiments disclosed also provide a trajectory prediction system that predicts a user's trajectory based on past and present user behavior information. Based on the predicted trajectory or a given set of predicted trajectories and user behavior information, the system activates a given access device if it is within the trajectory range and the user is authorized to access it (as determined by long-range exchange of credentials, such as via BLE). As an example, a given access device (e.g., a door lock) can first communicate with the user's mobile device via a specific communication protocol (e.g., BLE) to exchange authorization data (e.g., credentials). Next, if it is determined that a given access device is within the range of the user's predicted trajectory, and the user typically accesses or activates that device during the current day / time, or has a preference for activating that device over another device in the user's vicinity, the given access device is commanded to activate (e.g., a door lock is unlocked). In this way, once the user reaches the given access device, the device is ready to activate without the user needing to bring their access card close to the device.
[0024] In some embodiments, the disclosed embodiments provide systems and methods for performing long-range access control based on trajectories and intent predictions. According to the disclosed embodiments, observed trajectories of a user and user behavior information about the user are received. The disclosed embodiments process the observed trajectories using machine learning techniques to generate a plurality of predicted trajectories. The machine learning techniques can be trained to establish relationships between a plurality of training observed trajectories and a plurality of training predicted trajectories. The disclosed embodiments adjust the plurality of predicted trajectories based on user behavior information to determine the user intent to activate a target access control device. In response to determining that the target access control device is within a threshold range of a given predicted trajectory among the plurality of predicted trajectories, the disclosed embodiments perform processing associated with the target access control device.
[0025] Figure 1 is a block diagram showing exemplary system 100 in various exemplary embodiments. System 100 may be an access control system including a client device 120, one or more access control devices 110 that control access to assets or resources protected through lockable doors, etc., and an authentication management system 140 that is communicably coupled over a network 130 (e.g., the Internet, BLE, ultra-wideband (UWB) communication protocol, telephone network).
[0026] Ultra-wideband (UWB) is a radio frequency (RF) technique that uses short, low-power pulses across a wide frequency spectrum. These pulses are on the order of millions per second. The frequency spectrum width is typically greater than 500 megahertz or 20 percent of the arithmetic center frequency.
[0027] UWB can be used for communication by encoding data using time modulation (e.g., pulse position coding). Here, multiple symbols are specified by multiple pulses in a subset of available units of time. Other examples of UWB coding may include amplitude modulation and / or polarity modulation. Broadband transmission tends to be more resistant to multipath attenuation than carrier-based transmission techniques. Furthermore, because the pulse output is weak at any given frequency, interference with carrier-based communication techniques tends to be reduced.
[0028] UWB can be used in radar applications that enable localization with accuracy down to the tens of centimeters. Because absorption and reflection can vary at different frequencies in pulses, it can detect both surface and occluded (e.g., covered) features of an object. In some cases, localization can provide not only distance but also the angle of incidence.
[0029] The client device 120 and multiple access control devices 110 can be coupled together in a communicative manner using electronic messages (e.g., packets exchanged over the Internet, BLE, UWB, WiFi Direct, or any other protocol). Figure 1 shows a single access control device 110 and a single client device 120, but it will be understood that in other embodiments, multiple access control devices 110 and multiple client devices 120 may be included in the system 100. As used herein, the term “client device” can refer to any machine that interfaces to a communication network (such as network 130) to exchange credentials with the access control device 110, the authentication management system 140, another client device 120, or any other component in order to obtain access to an asset or resource protected by the access control device 110. The client device 120 can use UWB to obtain location information and calculate the current trajectory of the client device 120.
[0030] In one embodiment, the client device 120 can supply current trajectory information to the authentication management system 140. In some embodiments, the access control device 110 can determine the current trajectory of the client device 120 and supply such information to the authentication management system 140. The client device 120 (alone or in combination with the access control device 110) collects various user behavior information from the user of the client device 120. Such user behavior information may include the user's physical movement, the user's stride length, the time and location in which the user activates different types of access control devices 110, and one or more other client devices or multiple types of access control devices within the user's range when a given access control device is activated by the user. Various user behavior information may be stored and / or collected by the authentication management system 140. In some embodiments, the client device 120 (alone or in combination with the access control device 110) collects this information by monitoring the physical movement of the client device 120 and / or the user's stride length. In some implementations, at least some user behavior information is collected by the client device 120 (either alone or in combination with the access control device 110) and / or the authentication management system 140. The authentication management system 140 allows the user to opt in or opt out of some or all of the collected user behavior information in order to maintain user privacy.
[0031] In some cases, some or all of the components and functions of the authentication management system 140 can be included in the client devices 120 (for example, any of the machine learning techniques described with respect to the authentication management system 140 can be implemented on each client device 120). Any component that performs trajectory and intent prediction in system 100 may be implemented as a standalone component of any one of the authentication management system 140, client devices 120, or access control devices 110. Multiple functions of any component that performs trajectory and intent prediction in system 100 may be implemented in a distributed manner across any of the authentication management system 140, client devices 120, and / or access control devices 110.
[0032] The authentication management system 140 predicts one or more trajectories using machine learning techniques based on the current trajectory. The authentication management system 140 also receives or acquires user behavior information and adjusts the predicted one or more trajectories based on the user behavior information (for example, the authentication management system 140 concatenates the predicted trajectories with the user behavior information). In some implementations, the authentication management system 140 uses machine learning techniques to compute a feature vector based on user behavior information associated with the user. In some implementations, the authentication management system 140 applies a machine learning model to the input current trajectory and input user behavior information to generate predictions of one or more trajectories. Each trajectory may be associated with a specific probability or a given probability that the user will take that path. The authentication management system 140 identifies the predicted trajectory with the highest probability. The authentication management system 140 then determines whether a given access control device 110 is within a specified range of the identified predicted trajectories. If so, the authentication management system 140 commands the given access control device 110 to grant access or perform an action; otherwise, the authentication management system 140 commands the given access control device 110 (which the user is authorized to access) to deny access or not perform an action.
[0033] The client device 120 may be, but is not limited to, a mobile phone, desktop computer, laptop, personal digital assistant (PDA), smartphone, wearable device (e.g., smartwatch), tablet, ultrabook, netbook, laptop, multiprocessor system, microprocessor-based or programmable consumer electronics, or any other communication device that a user may use to access the network.
[0034] The access control device 110 may be connected to a physical resource (e.g., a door lock mechanism or a backend server) and may include an access reading device that controls the physical resource (e.g., a door lock mechanism). The physical resource associated with the access control device 110 may include a door lock, a vehicle ignition system, or any other device that can allow or deny access to a physical component, or act to allow or deny access to a physical component. For example, in the case of a door lock, the access control device 110 may deny access, in which case the door lock remains locked and the door cannot be opened, or the access control device 110 may grant access, in which case the door lock is unlocked and the door can be opened. As another example, in the case of an ignition system, the access control device 110 may deny access, in which case the vehicle ignition system remains disabled and the vehicle cannot be started, or the access control device 110 may grant access, in which case the vehicle ignition is enabled and the vehicle can be started.
[0035] Access control encompasses a range of systems and methods for managing access, for example, by people, to a secure area or asset. Access control includes identifying authorized users or devices (e.g., vehicles, drones, etc.) and activating gates, doors, or other equipment used to protect the area, or control mechanisms, such as physical or electronic / software control mechanisms, to enable access to the secure asset. The access control device 110 forms part of multiple access control systems (PACS), which may include readers (e.g., online or offline readers) that hold authorization data and can determine whether multiple credentials (e.g., from credential devices or key devices such as radio frequency identification (RFID) chips in personal electronic devices such as cards, fobs, or mobile phones) are authorized for an actuator or control mechanism (e.g., turning off a door lock, door opener, software control mechanism, alarm, etc.), or the PACS may include a host server to which the readers and actuators are connected (e.g., via a controller) in a centrally managed configuration. In a centralized management configuration, a reader can retrieve credentials from a credential or key device and pass those credentials to a PACS host server. The host server then determines whether the credentials grant permission to access a secure area or asset and instructs an actuator or other control mechanism accordingly. While several examples of physical access control are used herein, this disclosure applies equally to use cases of logical access control systems (LACS), such as logical access to personal electronic devices, passenger identification in transportation services, and access and asset control in unmanned payment stores.
[0036] For example, wireless PACS, which utilizes wireless communication between a reader and a credential or key device, can use RFID or personal area network (PAN) technologies such as IEEE 802.15.1, Bluetooth®, BLE (Bluetooth Low Energy), near field communications (NFC), ZigBee, GSM, CDMA, and Wi-Fi. Many of these technologies have several drawbacks regarding a seamless user experience. For example, because the range of NFC is very short, credential exchange usually does not occur until the user is very close to the secure area or asset and attempts to gain access. Transferring credentials to the reader and the response from the reader or host server can take several seconds, resulting in user frustration. Furthermore, the user usually needs to, for example, take the device out of their pocket and place it near the reader to begin processing.
[0037] On the other hand, BLE devices have a range of several tens of meters (e.g., 10-20 meters). Therefore, when a user approaches a reader, credential exchange can be performed. However, BLE and many other PAN standards do not provide precise physical tracking of the device (e.g., ranging, location). Therefore, it can be difficult for a reader to determine whether the user's intention is to actually access a secure area or asset without further evidence of intent. For example, it would be problematic if a door were unlocked or opened simply by an authorized user walking past a reader in a hall. Evidence of intent may include touching a doorknob or gesturing a key device. However, this would not be an ideal user experience compared to a situation where the user simply walks to a reader and obtains access to a secure area without taking any further action or interaction.
[0038] To address one or more of these or other problems, position estimation techniques (e.g., using secure UWB ranging) can be employed and combined with PAN discovery and key exchange. UWB position estimation techniques can be more accurate than some conventional techniques, achieving accuracy, for example, to the degree of tens of centimeters. UWB position estimation techniques can provide both the range and orientation of the credentials or key device relative to the reader. This accuracy far surpasses the approximately 10-meter accuracy of BLE, etc., when readers are not interconnected. The precision of UWB accuracy can be a useful tool for seamlessly determining user intent (e.g., whether the user is attempting to access a secure area or asset, or simply passing by) and the user's current or predicted trajectory. For example, several zones may be defined, for example, near the reader, or at the reader, to understand user intent from different perspectives. Additionally or alternatively, tracking accuracy can help provide an accurate model that can identify intent from user movement or the direction of user movement. Therefore, the reader can classify the user's movements, for example, whether they are likely to be approaching the reader or simply walking past it.
[0039] When an intentional trigger occurs, the reader may operate based on credentials exchanged, for example, via PAN technology. In the case of an offline reader, for example, one not connected to a control panel or host server, the reader may directly control an actuator or other control mechanism (e.g., a door lock that is not connected). In a centrally managed PACS, an (online) reader may transfer credentials to the control panel or host server on which it acts.
[0040] Generally, the access control device 110 may include one or more of the following: memory, a processor, one or more antennas, a communication module, a network interface device, a user interface, and a power supply or power supply circuit.
[0041] The memory of the access control device 110 may be used in connection with application programming or execution of instructions by the processor of the access control device 110, and for temporary or long-term storage of credential or authorization data such as program instructions or instruction sets and / or credential data, credential authorization data, or access control data or instructions. For example, the memory may include executable instructions used by the processor to operate other components of the access control device 110 and / or to make access decisions based on credential or authorization data. The memory of the access control device 110 may include computer-readable media, which may be any medium that contains, stores, communicates, or transfers data, program code, or instructions used by or in connection with the access control device 110. Computer-readable media may be, for example, but not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices. More specific examples of suitable computer-readable media include, but are not limited to, electrical connections having one or more wires, or tangible storage media such as portable computer diskettes, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), dynamic RAM (DRAM), any solid-state storage device, common compact disk read-only memory (CD-ROM), or other optical or magnetic storage devices. Computer-readable media also includes computer-readable storage media intended to cover all physical, non-temporary, or similar embodiments of computer-readable media, though these should not be confused.
[0042] The processor of the access control device 110 can correspond to one or more computer processing devices or resources. For example, the processor can be provided as silicon, such as a field-programmable gate array (FPGA), an application-specific integrated circuit (ASIC), any other type of integrated circuit (IC) chip, or a collection of IC chips. More specifically, the processor can be provided as a microprocessor, a central processing unit (CPU), or multiple microprocessors or CPUs configured to execute the internal memory and / or instruction set stored in the memory of the access control device 110. The access control device also encapsulates multiple sensing devices, with or without antennas.
[0043] The antenna of the access control device 110 may correspond to one or more antennas and may be configured to provide wireless communication between the access control device 110 and a credential device or key device (e.g., client device 120). The antenna may be configured to operate using one or more wireless communication protocols and operating frequencies, including but not limited to IEEE 802.15.1, Bluetooth, Bluetooth Low Energy (BLE), Near Field Communication (NFC), ZigBee®, GSM®, CDMA, Wi-Fi, RF, UWB, etc. For example, one or more antennas may be one or more RF antennas and thus capable of transmitting / receiving RF signals that are received / transmitted by a credential or key device having an RF transceiver over free space. In some examples, at least one antenna is an antenna designed or configured to transmit and / or receive UWB signals (hereinafter referred to as a “UWB antenna”) so that a reader can communicate with the client device 120 using UWB technology.
[0044] The communication module of the access control device 110 can be configured to communicate with one or more different systems or devices, which may be remote or local to the access control device 110, such as one or more client devices 120 and / or an authentication management system 140, according to any appropriate communication protocol.
[0045] The network interface device of the access control device 110 includes hardware that enables communication with one or more client devices 120 and / or other devices such as the authentication management system 140 over a communication network such as network 130, using one of several transport protocols (e.g., Frame Relay, Internet Protocol (IP), Transmit Control Protocol (TCP), User Datagram Protocol (UDP), Hypertext Transfer Protocol (HTTP), etc.). Exemplary communication networks may include local area networks (LANs), wide area networks (WANs), packet data networks (e.g., the Internet), mobile phone networks (e.g., cellular networks), POTS (Plain Old Telephone) networks, wireless data networks (e.g., the IEEE 802.11 standard family known as Wi-Fi®, the IEEE 802.16 standard family known as WiMax®), the IEEE 802.15.4 standard family, and peer-to-peer (P2P) networks. In some examples, a network interface device may include an Ethernet® port or other physical jack, a Wi-Fi card, a Network Interface Card (NIC), or a cellular interface (e.g., antennas, filters, and associated circuitry). In some examples, a network interface device may include multiple antennas to wirelessly transmit signals using at least one of the following techniques: Single-Input Multiple-Output (SIMO), Multiple-Input Multiple-Output (MIMO), or Multiple Input Single Output (MISO).
[0046] The user interface of the access control device 110 may include one or more input devices and / or display devices. Suitable user input devices that may be included in the user interface include, but are not limited to, one or more buttons, a keyboard, a mouse, a touch-sensitive surface, a stylus, a camera, a microphone, etc. Suitable user output devices that may be included in the user interface include, but are not limited to, one or more LEDs, an LED panel, a display screen, a touchscreen, one or more lights, a speaker, etc. It should also be understood that the user interface may include a combination of user input and user output devices, such as a touch-sensitive display.
[0047] Network 130 includes, or may operate with, an ad hoc network, an intranet, an extranet, a virtual private network (VPN), a local area network (LAN), a wireless network, a wireless LAN (WLAN), a wide area network (WAN), a wireless WAN (WWAN), a metropolitan area network (MAN), BLE, UWB, the Internet, part of the Internet, part of the Public Switched Telephone Network (PSTN), a plain old telephone service (POTS) network, a cellular telephone network, a wireless network, a Wi-Fi® network, another type of network, or a combination of two or more such networks. For example, a network or part of a network may comprise a wireless or cellular network, and the coupling may be a code division multiple access (CDMA) connection, a global system for mobile communications (GSM®) connection, or another type of cellular or wireless coupling. In this example, the coupling may implement any of the following: single-carrier radio transmission technology (1xRTT), evolutionary data optimization (EVDO) technology, general packet radio service (GPRS) technology, enhanced data rate for GSM® evolution (EDGE) technology, the 3G Partnership Project (3GPP®) including 3G, 4G networks, 5G networks, Universal Mobile Telecommunications System (UMTS), High Speed Packet Access (HSPA), WiMAX (Worldwide Interoperability for Microwave Access), Long Term Evolution (LTE) standards, other standards defined by various standards organizations, other short-range or long-range protocols, and various types of data transfer technologies.
[0048] In one example, when client device 120 approaches access control device 110 (for example, entering the range of the BLE communication protocol), client device 120 transmits its credentials over network 130. In some cases, the credentials may be selected from multiple credentials based on the current geographical location of client device 120. For example, client device 120 may store multiple credentials, each associated with a different geographical location. When client device 120 enters a certain distance (for example, within 10 meters) from a geographical location associated with one of the multiple credentials, client device 120 retrieves the associated credentials from local memory.
[0049] In one example, the client device 120 directly supplies credentials to the access control device 110. In such a case, the access control device 110 communicates the credentials with the authentication management system 140. The authentication management system 140 in Figure 1 includes an authentication system 142 and a trajectory and intent prediction system 144. The authentication management system 140 may further include several components described with respect to Figures 6 and 7, such as a processor and memory that store several instructions that cause the processor to control several functions of the authentication management system 140 when executed by the processor.
[0050] The authentication management system 140 searches the list of credentials stored in the authentication system 142 to determine whether the received credentials match any of the credentials from the list of credentials authorized to access a secure asset or resource (e.g., a door or a secure area) protected by the access control device 110. In response to determining that the received credentials are authorized to access the access control device 110, the authentication management system 140 accesses the trajectory and intent prediction system 144 to determine, as will be described in more detail below, whether the trajectory of the client device 120 is predicted to be within a specified range (e.g., 2 meters) of the access control device 110, and whether the user behavior information indicates the user's intent to follow a given trajectory and / or activate a given access control device 110. When the trajectory and intent prediction system 144 predicts that the client device 120 will follow a trajectory within a specified range of the access control device 110, and that user behavior information indicates a user intent to access or activate the device 110, the authentication management system 140 instructs the access control device 110 to perform an action that grants access to the client device 120 (for example, instructing the access control device to unlock the door).
[0051] In another example, client device 120 provides credentials to authentication management system 140. Authentication management system 140 searches a list of credentials stored in authentication system 142 to determine whether the received credentials match any of the credentials from a list of credentials authorized to access a secure asset or resource (e.g., a door or secure area) protected by access control device 110. In response to determining that the received credentials are authorized to access access control device 110, authentication management system 140 accesses trajectory and intent prediction system 144 to determine whether the trajectory of client device 120 is predicted to be within a specified range (e.g., 2 meters) of access control device 110, and whether the user behavior information indicates the user's intent to follow a given trajectory and / or activate a given access control device 110, as will be described in more detail below. When the trajectory and intent prediction system 144 predicts that the client device 120 will follow a trajectory within a specified range of the access control device 110, and that user behavior information indicates a user intent to follow a given trajectory and / or to operate a given access control device 110, the authentication management system 140 commands the access control device 110 (associated with the received credentials and located within the geographical distance of the client device 120) to perform an action that grants access to the client device 120 (for example, commanding the access control device to unlock a door).
[0052] In one example, the trajectory and intent prediction system 144 is implemented locally on the access control device 110. In such a case, the access control device 110 locally determines whether to grant or deny access to the client device 120 based on hardcoded range or threshold distance information. In another example, the trajectory and intent prediction system 144 is implemented on the client device 120 and provides the trajectory and intent prediction to the access control device 110. The access control device 110 then determines whether the client device 120 is within the range associated with the access control device 110 and grants or denies access to the client device 120.
[0053] The trajectory and intent prediction system 144 trains one or more machine learning techniques implemented by the authentication management system 140 to predict one or more trajectories for the client device 120 based on the observed trajectory and a set of user behavior information.
[0054] In one embodiment, the trajectory and intent prediction system 144 receives a feature vector representing the user's current trajectory and implements a first machine learning technique that adjusts the prediction of one or more predicted trajectories based on a set of user behavior information. The predicted trajectories are input to an intent prediction machine learning technique that provides a prediction about whether the user intends to activate an access control device within the range of the predicted trajectory.
[0055] In another embodiment, the trajectory and intent prediction system 144 receives a feature vector representing the user's current trajectory and implements a first machine learning technique that predicts one or more trajectories based on the current trajectory. The predicted one or more trajectories are associated with or otherwise combined with a feature vector representing user behavior information. In some cases, the feature vector representing user behavior information is determined or provided by another machine learning technique. The predicted trajectories associated with the feature vector representing user behavior information are input into an intent prediction machine learning technique that predicts whether the user intends to activate an access control device within the range of the predicted trajectory.
[0056] In another embodiment, the trajectory and intent prediction system 144 receives a feature vector representing the user's current trajectory and a feature vector representing user behavior information, and implements a first machine learning technique that predicts one or more trajectories based on the current trajectory and the feature vector representing user behavior information. In some cases, the predicted one or more trajectories are also associated with or otherwise combined with a feature vector representing user behavior information. In some cases, the feature vector representing user behavior information is determined or provided by another machine learning technique. The predicted trajectories associated with the feature vector representing user behavior information are input into an intent prediction machine learning technique that makes a prediction about whether the user intends to activate an access control device within the range of the predicted trajectory.
[0057] The trajectory and intent prediction system 144 processes multiple pairs of observed current trajectory and / or user behavior information to be trained, and corresponding ground-truth trajectories and user behavior information, in order to train machine learning techniques. A ground-truth trajectory represents multiple subsequent trajectories that follow one or more observed trajectories. For example, a ground-truth trajectory shows a second segment of a trajectory following a first segment of the trajectory. Ground-truth user behavior information represents a feature vector containing a set of features that are present in and / or missing from the input dataset of user behavior information.
[0058] The disclosed machine learning techniques can be implemented by any combination of neural networks, such as Long-Short Term Memory Neural Networks (LSTMs), autoencoders, variational autoencoders, conditioned variational autoencoders, convolutional neural networks, radial basis networks, deep feedforward networks, recurrent neural networks, gated recurrent units, denoising autoencoders, sparse autoencoders, Markov chains, Hopfield networks, Boltzmann machines, deep belief networks, deep convolutional networks, deconvolutional neural networks, generative adversarial networks, liquid state machines, extreme learning machines, echo state networks, deep residual networks, support vector machines, Korhonen networks, or any combination thereof.
[0059] The trajectory and intent prediction system 144 retrieves a specified range for the activation or operation of the access control device 110. For example, the trajectory and intent prediction system 144 retrieves the unique identifier of the access control device 110 and searches one or more access control device ranges 430 stored in the database 400 (Figure 4) to identify and retrieve the range associated with the unique identifier of the access control device 110. Multiple different access control devices 110 or multiple types of access control devices 110 can be associated with different ranges of activation or operation, each stored within one or more access control device ranges 430 along with its respective unique identifier. In some cases, one or more access control device ranges 430 store the device type along with each range. In such situations, the device type is used to retrieve the associated range from one or more access control device ranges 430, rather than the unique identifier. The trajectory and intent prediction system 144 determines whether the predicted trajectory falls within a specified range of the access control device 110, and whether the intent prediction indicates a user intent to activate the access control device 110. If so, the trajectory and intent prediction system 144 instructs the authentication management system 140 to activate or launch the access control device 110 in order to grant access to the client device 120.
[0060] In another example, the trajectory and intent prediction system 144 is implemented locally on the access control device 110. In such an example, the access control device 110 is hard programmed with the corresponding range of activation (for example, the range stored in the access control device range 430 for the access control device 110). The trajectory and intent prediction system 144 implemented on the access control device 110 determines whether the predicted trajectory falls within the hardcoded range. If so, the trajectory and intent prediction system 144 causes the access control device 110 to grant access to the client device 120. In yet another example, the trajectory and intent prediction system 144 is implemented on the client device 120 and provides the trajectory and intent prediction to the access control device 110. The access control device 110 then determines whether the client device 120 is within the range associated with the access control device 110 and grants / denies access to the client device 120.
[0061] In some cases, the trajectory and intent prediction system 144 does not access range information, but simply supplies a predicted trajectory or a set of predicted trajectories to the authentication management system 140, client devices 120, and / or access control devices 110. These devices then make decisions collectively or individually regarding whether the predicted trajectories fall within a threshold range.
[0062] Figure 2 shows an exemplary access control system 200 based on trajectory and intent prediction according to an exemplary embodiment. For example, a user 210 may carry a client device 120 (not shown), such as a mobile device or telephone. The client device 120 (or access control device 110) may collect a set of observed 2D and / or 3D coordinates 230. The client device 120 (or access control device 110) may calculate the user's current trajectory. The client device 120 (alone or in combination with the access control device 110) also collects a set of user behavior information about the user, such as the user's stride length and / or the user's physical movements. The client device 120 (alone or in combination with the access control device 110) may also collect the time periods and locations in which the client device 120 is used to activate various access control devices 110. Using this information, a trained machine learning technique can determine or derive the user's intent or preference regarding activating several access control devices 110. In some cases, the access control device 110 stores identifiers of multiple client devices 120 that activate the access control device 110, and multiple time periods during which various client devices 120 activate the access control device 110. This user behavior information is then aggregated into a profile for each client device 120 to generate user behavior information associated with each client device 120.
[0063] In one example, client device 120 can determine that two access control devices 220 and 222 are within a specified range of client device 120. For example, each of access control devices 220 and 222 is within range of BLE communication with client device 120. In response, client device 120 reads the credentials of both access control devices 220 and 222 and sends those credentials to the authentication management system 140. The authentication management system 140 determines that client device 120 is authorized to access both access control devices 220 and 222. In response to determining that client device 120 is authorized to access, the authentication management system 140 delays granting access to a specific access control device 220 or 222 until it determines that client device 120 is moving along a predicted trajectory within a specific range 250 of each access control device 220 or 222.
[0064] In another example, there may be a single access control device 110 that ensures access to an area protected by that single access control device 110. In such a case, the user's intention to enter the secure area is determined before issuing a command to the access control device 110 to grant access to a given client device 120. Specifically, before issuing a command to the access control device 110 to grant access to the client device 120, a determination is made as to whether the user's predicted trajectory falls within the range of the access control device 110.
[0065] For example, the client device 120 (or access control device 110) supplies the observed current trajectory to the trajectory and intent prediction system 144. The client device 120 also supplies user behavior information about the user associated with the client device 120 (either alone or in combination with the access control device 110). In another example, the access control device 110 supplies the observed current trajectory to the trajectory and intent prediction system 144. The access control device 110 can supply user behavior information about the user associated with the client device 120, either independently or in combination with the client device 120.
[0066] The trajectory and intent prediction system 144 predicts one or more trajectories based on the current trajectory and user behavior information. The trajectory and intent prediction system 144 then identifies a predicted trajectory 240 to which the client device 120 is predicted to move. In response to determining that the predicted trajectory 240 is within range of the first access control device 220, the trajectory and intent prediction system 144 instructs the authentication management system 140 to allow the first access control device 220 to access the client device 120 (for example, the first access control device 220 is instructed to perform an action such as unlocking an electronic door lock). In response to determining that the predicted trajectory 240 does not fall within the range of the second access control device 222, the trajectory and intent prediction system 144 instructs the authentication management system 140 to deny access to the client device 120 from the second access control device 222 (for example, the second access control device 222 is instructed to remain locked even if multiple credentials of the client device 120 are authorized to access the second access control device 222). In some cases, the predicted trajectory falls within the range of both the first and second access control devices 220 and 222. However, the trajectory and intent prediction system 144 predicts the user intent to activate the first access control device 220 (for example, based on user behavior information). In such cases, the trajectory and intent prediction system 144 instructs the authentication management system 140 to have the first access control device 220 grant access to the client device 120 (for example, the first access control device 220 is instructed to perform an action such as unlocking an electronic door lock), and the second access control device 222 deny access to the client device 120.
[0067] Figures 3A to 3C are block diagrams of exemplary trajectory and intent prediction systems 144 that may be placed within the access control system of Figure 1 according to several embodiments. The training input 310 includes a plurality of model parameters 312 and training data 320, which may include a plurality of paired training datasets 322 (e.g., a plurality of input-output training pairs) and a plurality of constraints 326. The plurality of model parameters 312 include or provide parameters or coefficients of corresponding machine learning models among a plurality of machine learning models. During training, these parameters 312 are adapted based on a plurality of input-output training pairs of training data 320. After the plurality of parameters 312 have been adapted (post-training), the plurality of parameters are used by the plurality of trained models 360 to run the plurality of trained machine learning (ML) models on a new set of data 370.
[0068] The training data 320 includes several constraints 326 that can define constraints on a given trajectory and user behavior information. A pair of training data 320 may include multiple input / output pairs 322, such as multiple pairs of multiple training observed trajectories and training user behavior information, and multiple training predicted trajectories (ground truth trajectories) corresponding to them. Multiple ground truth predicted trajectories represent multiple actual trajectories at one or more future points in time following the observed trajectory, and a set of user behavior information at multiple earlier points in time. For example, the observed trajectory and user behavior measurements may be obtained at a first point in time for a first section of the path. The ground truth predicted trajectory represents the actual observed trajectory at a second point in time for a second section following the first section.
[0069] Some components of the training input 310 may be stored separately in an off-site facility or multiple facilities that differ from other components of the training input 310. Paired training data 320 may include multiple pairs of training user behavior information and corresponding training feature vectors of user behavior information (ground truth user behavior information). Paired training data 320 may include multiple pairs of training predicted trajectories linked to user behavior information and training intents (ground truth intentions) that activate the corresponding access control device. Multiple ground truth intentions are generated by collecting information indicating whether a given access device 110 was activated when a trajectory linked to certain user behavior information was observed.
[0070] Training one or more machine learning models 330 trains one or more machine learning techniques based on multiple sets of input-output pairs of paired training data 322. For example, training a model 330 may train a first set of ML model parameters 312 by minimizing a loss function based on one or more ground truth measurements. In particular, the first set of ML model parameters 312 may be applied to a training set of observed current trajectories conditioned on a set of user behavior information in order to estimate a predicted trajectory. In some implementations, the derivative of the loss function is calculated based on a comparison of the estimated predicted trajectory with the ground truth trajectory, and the first set of ML model parameters is updated based on the calculated derivative of the loss function. The first set of ML model parameters can be applied to a first machine learning technique (e.g., a conditioned variational autoencoder) so that, given new data 370, it can generate a first prediction.
[0071] As another example, training the model 330 may involve training a second set of ML model parameters 312 by minimizing a loss function based on one or more ground truth measurements. In particular, the second set of ML model parameters 312 may be applied to a training set of observed user behavior information to estimate feature vectors representing user behavior information. In some implementations, the derivative of the loss function is calculated based on a comparison between the estimated user behavior information and the ground truth user behavior information, and the second set of ML model parameters is updated based on the calculated derivative of the loss function. The second set of ML model parameters can then be applied to a second machine learning technique (e.g., a neural network) to generate a second prediction given new data 370.
[0072] As another example, training the model 330 may train a third set of ML model parameters 312 by minimizing a loss function based on one or more ground truth measurements. In particular, the second set of ML model parameters 312 may be applied to a training set of user behavior information associated with multiple predictive trajectories in order to estimate a predictive intention to activate an access control device. In some implementations, the derivative of the loss function is calculated based on a comparison of the estimated predictive intention to activate the access control device with the ground truth intention to activate the access control device, and the third set of ML model parameters is updated based on the calculated derivative of the loss function. The third set of ML model parameters can be applied to a third machine learning technique (e.g., a neural network) to generate a third prediction given new data 370.
[0073] The first, second, and / or third ML models can all be stored on the same device (for example, on client device 120, on access control device 110, or centrally on authentication management system 140). In some cases, a particular ML model among the first, second, and / or third ML models may be implemented by a specific device (for example, on client device 120, on access control device 110, or centrally on authentication management system 140), while other ML models of the first, second, and third ML models may be implemented by different devices (for example, on client device 120, on access control device 110, or centrally on authentication management system 140).
[0074] By minimizing the loss function across multiple sets of training data trains, the model parameters 312 of the corresponding ML models are adapted or optimized. In this way, these ML models are trained to establish relationships between multiple training data (e.g., observed trajectories, observed user behavior information, linked trajectories, and user behavior information) and the corresponding multiple predicted training data (e.g., predicted trajectories, predicted user behavior information, and predicted intentions to activate access control devices).
[0075] In one implementation, these ML models are trained according to supervised learning techniques to estimate trajectories from training observed trajectories and user behavior information. In such cases, multiple training observed trajectories and user behavior information are read out along with their corresponding training predicted or estimated trajectories to train the ML model. For example, the training observed trajectories and user behavior information are read out from training data 410 stored in database 400 (Figure 4). The ML model is applied to a first group of training observed trajectories and user behavior information to estimate the trajectories of a given set. This group of training observed trajectories and user behavior information can be used to train the ML model with the same parameters and can range from specific training observed trajectories and user behavior information to the entire range of training observed trajectories and user behavior information. In some implementations, the output or results of the ML model are used to compute or predict the predicted trajectories of the first group.
[0076] The first set of predicted trajectories is applied to a loss function, and the gradient or derivative of the loss function is calculated based on the expected set of predicted trajectories or ground truth set. Based on the gradient or derivative of the loss function, several updated parameters of the ML model are calculated. For example, several parameters of the ML model are included in the trained machine learning techniques 420 of database 400. The ML model is then applied to a second set of training observation trajectories and user behavior information using the updated parameters to re-estimate the predicted trajectories for a given set, and these predicted trajectories are applied to the loss function for comparison with their corresponding ground truth predicted trajectories. Several parameters of the ML model are updated again, and this training process iteration continues for a specified number of iterations or epochs, or until a given convergence criterion is met.
[0077] After the machine learning model has been trained, new data 370 containing one or more observed trajectories and user behavior information may be received. The trained machine learning technique can be applied to the new data 370 to generate a generated result 380 containing multiple predicted trajectories, along with their corresponding likelihoods, which represent the paths the user will take along each respective trajectory.
[0078] Figure 3B shows one implementation form 301 of the trajectory and intent prediction system 144 that may be provided within the system of Figure 1. Observed trajectories may be received from a client device 120. The observed trajectories are processed by a trajectory encoder 371 to generate a feature vector corresponding to the current trajectory. The feature vector corresponding to the current trajectory is input to a trained trajectory prediction model 361. The trained trajectory prediction model 361 can operate using a first set of model parameters 312 and can implement a conditional variational autoencoder. Any other type of neural network or machine learning technique may be used similarly as the trained trajectory prediction model 361. The trained trajectory prediction model 361 also receives user behavior information from a trained user behavior information model 362. The trained user behavior information model 362 is configured to receive a set of user behavior information (encoded, for example, as vectors) and generate a feature vector representing the user behavior information. In one example, the trained trajectory prediction model 361 and the trained user behavior information model 362 are trained end-to-end.
[0079] The trained trajectory prediction model 361 processes a feature vector corresponding to the current trajectory and a feature vector indicating user behavior information to predict one or more trajectories. The multiple predicted trajectories can be processed by another machine learning technique (not shown) to determine the user's intention to activate an access control device within the range of one or more of the trajectories. After granting the user's credentials permission to access an access control device within the range of the client device 120, the trajectory and intention prediction system 144, in response to determining that the user intends to activate an access control device within the range of one or more of the trajectories, commands the access control device within the range of the client device 120 to grant access or perform an action (for example, unlock the door lock).
[0080] Figure 3C shows one implementation form 302 of the trajectory and intent prediction system 144 that may be provided within the system of Figure 1. Observed trajectories may be received from a client device 120. The observed trajectories are processed by a trajectory encoder 371 to generate a feature vector corresponding to the current trajectory. The feature vector corresponding to the current trajectory is input to a trained trajectory prediction model 361. The trained trajectory prediction model 361 can operate using a first set of model parameters 312 and can implement a variational autoencoder. Any other type of neural network or machine learning technique may be used similarly as the trained trajectory prediction model 361. The trained trajectory prediction model 361 processes the feature vector corresponding to the current trajectory and a feature vector indicating user behavior information and predicts one or more trajectories. These predicted trajectories are fed to a concatenator 392. In some cases, the trained trajectory prediction model 361 processes the feature vector corresponding to the current trajectory and a feature vector indicating user behavior information and predicts one or more trajectories. One or more of these trajectories (predicted based on feature vectors representing the current trajectory and user behavior information) are supplied to the coupler 392.
[0081] The trained user behavior information model 362 is configured to receive a set of user behavior information (encoded, for example, as a vector) and generate a feature vector representing the user behavior information. The feature vector representing the user behavior information is also supplied to the coupler 392. In some embodiments, the trained user behavior information model 362 may output a result or feature vector that indicates a very low confidence score for the generated result (for example, the user behavior information does not meet the minimum parameters of the user behavior information). This may occur if an insufficient amount of user behavior information has been collected for a given user (for example, less than several specified types of threshold amounts such as the time of day when different types and locations of access devices are activated, the user's stride length, the user's physical movement, whether the user is carrying the client device 120 or has the device in their pocket, or who the user is when the access control device is activated). In such a situation, several predictions and several trajectories regarding user intent may be assigned very low probabilities, preventing access to the access control device within the client device 120's range, even if several credentials for the client device 120 are authorized to access the access control device.
[0082] For example, if a user has recently added a new key to an electronic door lock, there may be a training period that needs to be performed to generate a feature vector that accurately reflects the user behavior with a high level of confidence. Once a feature vector that accurately reflects the user behavior with a high level of confidence is achieved, intent prediction can be provided with a high probability, and an access control device within range of the client device 120 can be instructed to be activated (e.g., unlocked) if the credentials of the client device 120 grant it permission to access the access control device. That is, there may be a training period associated with each new set of credentials or keys added by the user to the client device 120 to access the corresponding access control device. During this period, the access control device can only be accessed and activated by the client device 120 using a short-range communication protocol (e.g., NFC) within 20 centimeters, etc. After training of the trained user behavior information model 362 for the newly added credentials is complete, the access control device can be accessed and activated by the client device 120 using a long-range communication protocol (e.g., BLE) within 10 meters, etc.
[0083] In one example, the coupler 392 combines (e.g., adjusts) one or more trajectories (predicted based only on the current trajectory) based on a feature vector representing user behavior information. In another example, the coupler 392 combines (e.g., adjusts) one or more trajectories (based on the current trajectory and predicted based on the feature vector representing user behavior information) based on a feature vector representing user behavior information. The combined results from the coupler 392 are fed into the trained intent prediction model 363. The coupler 392 can be implemented as any device that combines, multiplies, aggregates, sums, and / or generates a single representation from multiple input datasets.
[0084] The trained intent prediction model 363 determines the user's intention to activate the access control device within the range of one or more of one or more trajectories. The trained intent prediction model 363 may also be an end-to-end trained neural network. The trained intent prediction model 363 is trained to output a prediction about whether the user intends to activate a given access control device within the range of the client device 120 (based on a set of prediction trajectories, such as being adjusted by feature vectors representing user behavior information). The trained intent prediction model 363 may output an intention (e.g., yes or no) about whether the user will or intends to activate a given access control device, along with a probability indicating the likelihood that the user will activate the access control device. After granting the user's credentials permission to access access control devices within the range of client device 120, if the system determines that the user intends to activate an access control device within the range of one or more of one or more trajectories with a certain probability greater than a threshold probability, the trajectory and intent prediction system 144 commands the access control device within the range of client device 120 to grant access or perform an action (for example, unlock the door lock).
[0085] In one example, a trained intent prediction model 363 is trained to predict a user's intent to activate an access control device at a specific time of day and when the user is within range of one or more other client devices 120. Specifically, the trained user behavior information model 362 may provide the time periods (e.g., 9 AM and 5 PM) when a particular access control device is activated by the user, and a set of identifiers for other client devices 120 within a certain range (e.g., 5 meters) of the client device 120 at the time the access control device is activated. The trained intent prediction model 363 may identify access control devices within the range of the user's predicted trajectory and determine that the current time is within a specified threshold for the 9 AM or 5 PM time period. In such a case, in relation to social network information included in the user behavior information, the trained intent prediction model 363 may also determine whether multiple other client devices with multiple identifiers matching a set of identifiers are within a specified range of the client device 120. If so, the trained intent prediction model 363 determines that the user has a very high (e.g., 90%) intention to activate the access control device and allows the user to access that access device. The trained intent prediction model 363 can also determine that another access control device within a range of multiple prediction trajectories has a very low (e.g., less than 10%) intention to be activated by the user (e.g., because the device was not activated by the user during a specific time period in the past and when the user was within a set of identifiers for other client devices 120), and can cause the access device to deny the user access, even if the user has credentials to access or activate the access device.
[0086] In some embodiments, user behavior data is collected over time after one or more of several trained models are implemented in a system including several client devices 120. In this case, the user behavior model (e.g., a trained user behavior information model 362) and the trajectory model (e.g., a trained trajectory prediction model 361) are decoupled. This may be because the user behavior model is unavailable due to a lack of training data. In this case, only the trajectory model is used to perform trajectory prediction and cause the access device to grant or deny access to the user. In such a situation, the user behavior model includes a classifier that receives user behavior information (e.g., stride length, time, preferences, social network information, target door(s)) as input and outputs a probability of the user's intention to access a given access device. This probability is then combined with the trajectory probability to generate a prediction of the user's intention to activate a given access device.
[0087] In some embodiments, the user behavior model receives multiple doors or multiple access control devices as input, instead of a single door or access control device. In this case, the user behavior model outputs the probability of the user's intention to activate each of the multiple access control devices. That is, for each access control device, a probability is output indicating the likelihood that the user will activate that access control device. By combining this probability with the trajectory probability, the user's intention to access one of the multiple access control devices or not access any at all is determined. In some embodiments, the combination of the trajectory and the probability output by the user behavior model is generated as a weighted average of predictions made by two models (a trained user behavior information model 362 and a trained trajectory prediction model 361). The weights can be set by the system administrator and / or may automatically and dynamically change well over time as the user behavior data collected increases and the accuracy of the model improves.
[0088] Figure 5 is a flowchart illustrating the exemplary operation of process 500 of the access control system 100 according to an exemplary embodiment. Process 500 may be embodied in a plurality of computer-readable instructions executed by one or more processors such that a plurality of processes of process 500 can be executed partially or entirely by a plurality of functional components of the system 100, and thus process 500 is described below by reference as an example. However, in other embodiments, at least some of the plurality of processes of process 500 may be deployed on various other hardware configurations. Some or all of the plurality of processes of process 500 may be in parallel, out of order, or omitted entirely.
[0089] In process 501, the authentication management system 140 receives the user's observed trajectory and user behavior information about the user. For example, the authentication management system 140 receives the current trajectory and a set of user behavior information about the client device 120 (e.g., the user's physical movement, the user's stride length, preferences to access a specific access device at a specific time, the user's social networks such as who the user is around at different times or days of the week, and the user's preferences to open specific doors in a specific order).
[0090] In process 502, the authentication management system 140 processes the observed trajectories using machine learning techniques to generate multiple predicted trajectories, and the machine learning techniques are trained to establish relationships between multiple training observed trajectories and multiple training predicted trajectories. For example, the trained trajectory prediction model 361 processes the current trajectory to generate predictions for one or more trajectories.
[0091] In process 503, the authentication management system 140 adjusts multiple predicted trajectories based on user behavior information to determine the user's intent to activate the target access control device. For example, the trained trajectory prediction model 361 processes the current trajectory, conditional on the user behavior information, and adjusts the predictions of one or more trajectories.
[0092] In process 504, the authentication management system 140 determines that the target access control device is within a threshold range of a given predicted trajectory among a plurality of predicted trajectories. For example, the authentication management system 140 determines that the position of the first access control device 220 has a range 250 that falls within one or more predicted trajectories.
[0093] In process 505, the authentication management system 140, in response to determining that the target access control device is within a threshold range of a given predicted trajectory among a plurality of predicted trajectories, executes an action associated with the target access control device. For example, the authentication management system 140 instructs the access control device 220 to grant access to the client device 120 (for example, by unlocking an electronic door lock). In some cases, the authentication management system 140 bypasses the access control device 110 and directly controls the locked or secured resource.
[0094] Figure 6 is a block diagram illustrating an exemplary software architecture 606 that may be used in conjunction with various hardware architectures described herein. Figure 6 is a non-limiting example of a software architecture, and it will be understood that many other architectures may be implemented to enable the functions described herein. The software architecture 606 can run on hardware such as machine 700 in Figure 7, which includes a processor 704, memory 714, and input / output (I / O) components 718. A typical hardware layer 652 is shown, for example, machine 700 in Figure 7. The typical hardware layer 652 includes a processing unit 654 having a plurality of executable instructions 604. The plurality of executable instructions 604 represent a plurality of executable instructions of the software architecture 606, including implementations of methods, components, etc., described herein. The hardware layer 652 also includes a memory and / or storage device memory / storage 656, which also has a plurality of executable instructions 604. The hardware layer 652 may also include other hardware 658. The software architecture 606 can be deployed in any one or more of the components shown in Figure 1.
[0095] In the exemplary architecture of Figure 6, the software architecture 606 can be conceptualized as a stack of layers, each providing a specific function. For example, the software architecture 606 may include multiple layers such as an operating system 602, multiple libraries 620, multiple frameworks / middleware 618, multiple applications 616, and a presentation layer 614. Operationally, multiple applications 616 and / or other components within their layers can invoke API calls 608 through the software stack and receive messages 612 in response to API calls 608. The illustrated multiple layers are representative in nature, and not all software architectures have all of them. For example, some mobile or dedicated operating systems may not provide multiple frameworks / middleware 618, while others may. Other software architectures may include additional or different layers.
[0096] The operating system 602 may manage multiple hardware resources and provide multiple common services. The operating system 602 may include, for example, a kernel 622, multiple services 624, and multiple drivers 626. The kernel 622 can act as an abstraction layer between the hardware layer and other software layers. For example, the kernel 622 may be responsible for memory management, processor management (e.g., scheduling), component management, networking, security settings, etc. Multiple services 624 may provide other common services to other software layers. Multiple drivers 626 are responsible for controlling or interfaceing with basic hardware. For example, depending on the hardware configuration, multiple drivers 626 may include a display driver, camera driver, BLE driver, UWB driver, Bluetooth® driver, flash memory driver, serial communication driver (e.g., USB (Universal Serial Bus) driver), Wi-Fi® driver, audio driver, power management driver, etc.
[0097] Multiple libraries 620 provide a common infrastructure used by applications 616 and / or other components and / or layers. Libraries 620 provide functions that enable other software components to perform tasks more easily than directly interface with the functions of the basic operating system 602 (e.g., the kernel 622, multiple services 624, and / or multiple drivers 626). Multiple libraries 620 may include system libraries 644 (e.g., the C standard library) that may provide functions such as memory allocation functions, string manipulation functions, and mathematical functions. In addition, multiple libraries 620 may include API libraries 646 such as media libraries (e.g., libraries supporting the presentation and manipulation of various media formats such as MPREG4, H.264, MP3, AAC, AMR, JPG, PNG, etc.), graphics libraries (e.g., the OpenGL framework that can be used to render 2D and 3D graphics content on a display), database libraries (e.g., SQLite that can provide various relational database functions), and web libraries (e.g., WebKit that can provide web browsing functions). Multiple libraries 620 may also include a wide variety of other libraries 648 to provide many other APIs to multiple applications 616 and other software components / devices.
[0098] Multiple frameworks / middleware 618 (sometimes referred to simply as middleware) provide a higher-level common infrastructure that can be used by multiple applications 616 and / or other software components / devices. For example, multiple frameworks / middleware 618 may provide various graphical user interface functions, high-level resource management, high-level location services, etc. Multiple frameworks / middleware 618 may also provide a wide range of other APIs that can be used by multiple applications 616 and / or other software components / devices, some of which may be specific to a particular operating system 602 or platform.
[0099] Multiple applications 616 include built-in applications 638 and / or third-party applications 640. Typical examples of built-in applications 638 may include, but are not limited to, contact applications, browser applications, book reader applications, location-based applications, media applications, messaging applications, and / or game applications. Third-party applications 640 may include applications developed by entities other than the vendor of a particular platform using the ANDROID® or IOS® software development kit (SDK), and may be mobile software that runs on a mobile operating system such as IOS®, ANDROID®, WINDOWS® Phone, or other mobile operating systems. Third-party applications 640 may call API calls 608 provided by the mobile operating system (such as operating system 602) to enable the functions described herein.
[0100] Multiple applications 616 may create a UI for interacting with multiple users of the system, using built-in operating system functions (e.g., kernel 622, services 624, and / or drivers 626), multiple libraries 620, and multiple frameworks / middleware 618. Alternatively or additionally, in some systems, user interaction may occur via a presentation layer, such as a presentation layer 614. In these systems, the application / component "logic" can be separated from the application / component's aspects that interact with the user.
[0101] Figure 7 is a block diagram showing multiple components of a machine 700, in several exemplary embodiments, that can read multiple instructions from a machine-readable medium (e.g., a machine-readable storage medium) and execute any one or more of the methods described herein. Specifically, Figure 7 shows a schematic diagram of the machine 700 in an exemplary form of a computer system, in which instructions 710 (e.g., software, programs, applications, applets, or other executable code) can be executed to cause the machine 700 to execute any one or more of the methods discussed herein.
[0102] Accordingly, instruction 710 may be used to implement the devices or components described herein. Instruction 710 translates a general unprogrammed machine 700 into a specific machine 700 programmed to perform the described and illustrated functions in the described manner. In alternative embodiments, machine 700 may operate as a standalone device or be coupled to other machines (e.g., networked). In a networked configuration, machine 700 may operate as a server machine or client machine in a server-client network environment, or as a peer machine in a peer-to-peer (or distributed) network environment. Machine 700 may include, but is not limited to, a server computer, a client computer, a personal computer (PC), a tablet computer, a laptop computer, a netbook, an STB, a PDA, an entertainment media system, a mobile phone, a smartphone, a mobile device, a wearable device (e.g., a smartwatch), a smart home device (e.g., a smart appliance), other smart devices, a web appliance, a network router, a network switch, a network bridge, or any machine capable of sequentially or otherwise executing instruction 710 specifying the actions performed by machine 700. Furthermore, although only a single machine 700 is illustrated, the term “machine” shall also be interpreted to include a set of machines that individually or collectively perform instruction 710 to carry out any one or more of the methods described herein.
[0103] Machine 700 may include a processor 704, memory / storage 706, and I / O components 718, which may be configured to communicate with each other via a bus 702, etc. In one embodiment, the processor 704 (e.g., a central processing unit (CPU), a reduced instruction set computing (RISC) processor, a composite instruction set computing (CISC) processor, a graphics processing unit (GPU), a digital signal processor (DSP), an ASIC (application-specific integrated circuit), a radio frequency integrated circuit (RFIC), another processor, or any suitable combination thereof) may include, for example, processors 708 and 712 capable of executing instruction 710. The term “processor” is intended to include a multicore processor 704 which may have two or more independent processors (sometimes called “cores”) capable of executing instructions simultaneously. Figure 7 shows multiple processors 704, but machine 700 may include a single processor having a single core, a single processor having multiple cores (e.g., a multicore processor), multiple processors having a single core, multiple processors having multiple cores, or any combination thereof.
[0104] The memory / storage 706 may include a memory 714 such as main memory or other memory storage, instructions 710, and a storage unit 716, both of which are accessible to the processor 704 via a bus 702, etc. The storage unit 716 and the memory 714 store instructions 710 that embody any one or more of the methods or functions described herein. The instructions 710 may also reside, fully or partially, in the memory 714, in the storage unit 716, in at least one of the processor 704 (e.g., in the processor's cache memory), or in any suitable combination thereof, while being executed by the machine 700. Thus, the memory 714, the storage unit 716, and the memory of the processor 704 are examples of machine-readable media.
[0105] The I / O component 718 may include a wide variety of components for receiving inputs, providing outputs, generating outputs, transmitting information, exchanging information, capturing measurements, etc. The specific I / O component 718 included in a particular machine depends on the type of machine 700. For example, portable devices such as mobile phones are likely to include touch input devices or other such input mechanisms, while headless server machines are unlikely to include such touch input devices. It will be understood that the I / O component 718 may include many other components not shown in Figure 7. The I / O component 718 is grouped according to function simply to simplify the following description, and this grouping is by no means limiting. In various embodiments, the I / O component 718 may include output components 726 and input components 728. The output component 726 may include visual components (e.g., displays such as plasma display panels (PDPs), light-emitting diode (LED) displays, liquid crystal displays (LCDs), projectors, or cathode ray tubes (CRTs)), auditory components (e.g., speakers), tactile components (e.g., vibration motors, resistance mechanisms), and other signal generators. The input component 728 may include alphanumeric input components (e.g., keyboards, touchscreens configured to accept alphanumeric input, photo-optical keyboards, or other alphanumeric input components), point-based input components (e.g., mice, touchpads, trackballs, joysticks, motion sensors, or other pointing devices), tactile input components (e.g., physical buttons, touchscreens that provide the position and / or force of touch or touch gestures, or other tactile input components), and voice input components (e.g., microphones).
[0106] In further embodiments, the I / O component 718 may include a wide variety of other components, such as a biometric component 739, a motion component 734, an environmental component 736, or a position component 738. For example, the biometric component 739 may include components that detect facial expressions (e.g., hand expressions, facial expressions, voice expressions, gestures, or eye tracking), measure biosignals (e.g., blood pressure, heart rate, body temperature, sweating, or electroencephalography), and identify people (e.g., voice recognition, retinal recognition, facial recognition, fingerprint recognition, or electroencephalography-based recognition). The motion component 734 may include acceleration sensor components (e.g., accelerometers), gravity sensor components, rotation sensor components (e.g., gyroscopes), and the like. The environmental component 736 may include, for example, a lighting sensor component (e.g., a photometer), a temperature sensor component (e.g., one or more thermometers that detect ambient temperature), a humidity sensor component, a pressure sensor component (e.g., a barometer), an acoustic sensor component (e.g., one or more microphones that detect background noise), a proximity sensor component (e.g., an infrared sensor that detects nearby objects), a gas sensor (e.g., a gas detection sensor that detects the concentration of harmful gases for safety or measures airborne pollutants), or other components that can provide displays, measurements, or signals corresponding to the surrounding physical environment. The position component 738 may include a position sensor component (e.g., a GPS receiver component), an altitude sensor component (e.g., an altimeter or barometer that detects air pressure from which altitude can be derived), a compass sensor component (e.g., a magnetometer), and the like.
[0107] Communication can be implemented using a wide variety of technologies. The I / O component 718 may include a communication component 740 capable of operating to connect the machine 700 to the network 737 or device 729 via couplings 724 and 722, respectively. For example, the communication component 740 may include a network interface component or another suitable device for interface connection with the network 737. In further embodiments, the communication component 740 may include a wired communication component, a wireless communication component, a cellular communication component, a near-field communication (NFC) component, a Bluetooth® component (e.g., Bluetooth® Low Energy), a Wi-Fi® component, and other communication components that provide communication via other modalities. Device 729 may be another machine or a wide variety of peripheral devices (e.g., peripheral devices connected via USB).
[0108] Furthermore, the communication component 740 may include components that can detect identifiers or are capable of operating to detect identifiers. For example, the communication component 740 may include a radio frequency identification (RFID) tag reader component, an NFC smart tag detection component, an optical reader component (e.g., an optical sensor for detecting one-dimensional barcodes such as Universal Product Code (UPC) barcodes, QR (Quick Response) codes, Aztec codes, Data Matrix, Dataglyph, MaxiCode, PDF417, Ultra Code, UCC RSS-2D barcodes, and other optical codes), or an acoustic detection component (e.g., a microphone for identifying tagged audio signals). In addition, various types of information can be derived through the communication component 740, such as location via Internet Protocol (IP) geolocation, location via Wi-Fi® signal triangulation, and location by detection of NFC beacon signals that may indicate a specific location.
[0109] <Glossary> In this context, “carrier signal” refers not only to any intangible medium capable of storing, encoding, or carrying temporary or non-temporary instructions for machine execution, but also to digital or analog communication signals or other intangible medium for facilitating the communication of such instructions. Temporary or non-temporary instructions may be transmitted or received over a network by using a transmission medium via a network interface device, or by using any one of a number of well-known transport protocols.
[0110] In this context, “client device” refers to any machine that interfaces to a communications network in order to obtain resources from one or more server systems or other client devices. A client device may be, but is not limited to, a mobile phone, desktop computer, laptop, PDA, smartphone, tablet, ultrabook, netbook, laptop, multiprocessor system, microprocessor-based or programmable consumer electronics, game console, set-top box, or any other communications device that a user may use to access the network.
[0111] In this context, “communication network” means one or more parts of a network, which may be an ad hoc network, intranet, extranet, virtual private network (VPN), LAN, BLE network, UWB network, wireless LAN (WLAN), WAN (wide area network), wireless WAN (WWAN), metropolitan area network (MAN), Internet, part of the Internet, part of the public switched telephone network (PSTN), POTS (plain old telephone service) network, cellular telephone network, wireless network, Wi-Fi® network, another type of network, or a combination of two or more such networks. For example, a network or part of a network may comprise a wireless or cellular network, and the coupling may be a code division multiple access (CDMA) connection, a global system for mobile communications (GSM®) connection, or other types of cellular or wireless coupling. In this example, the coupling may implement any of the following: single-carrier radio transmission technology (1xRTT), evolutionary data optimization (EVDO) technology, general packet radio service (GPRS) technology, enhanced data rates for GSM Evolution (EDGE) technology, the 3G Partnership Project (3GPP®), including 3G, 4G, Universal Mobile Telecommunications System (UMTS), High Speed Packet Access (HSPA), WiMAX (Worldwide Interoperability for Microwave Access), LTE (Long Term Evolution) standards, protocols defined by various standardization bodies, other long-distance data transfer technologies, and various types of data transfer technologies.
[0112] In this context, “machine-readable medium” means a component, device, or other tangible medium capable of temporarily or permanently storing instructions and data, and may, but is not limited to, random-access memory (RAM), read-only memory (ROM), buffer memory, flash memory, optical media, magnetic media, cache memory, other types of storage (e.g., erasable programmable read-only memory (EEPROM)), and / or any suitable combination thereof. The term “machine-readable medium” should be interpreted as comprising a single medium or multiple media (e.g., a centralized or distributed database, or associated caches and servers) capable of storing instructions. The term “machine-readable medium” is also considered to comprise any medium or combination of multiple media capable of storing instructions for machine execution (e.g., code), such that when the instructions are executed by one or more processors of the machine, the machine causes the machine to execute one or more of the methodologies described herein. Thus, “machine-readable medium” means a single storage device, as well as a “cloud-based” storage system or storage network comprising multiple storage devices. The term "machine-readable medium" excludes the signal itself.
[0113] In this context, “component” refers to a device, physical entity, or logic whose boundaries are defined by other technologies that provide function or subroutine calls, branching points, application programming interface APIs, or partitioning or modularization of specific processing or control functions. Components can be combined through interfaces with other components to perform machine operations. A component is a packaged, functional hardware unit designed to be used together with other components, and is often part of a program that performs a particular function among its related functions. A component can constitute either a software component (e.g., code embodied in a machine-readable medium) or a hardware component. A “hardware component” is a tangible unit capable of performing a specific operation and can be configured or arranged in a specific physical manner. In various exemplary embodiments, one or more computer systems (e.g., a standalone computer system, a client computer system, or a server computer system) or one or more hardware components of a computer system (e.g., a processor or a group of processors) may be configured by software (e.g., an application or application portion) as a hardware component that operates to perform a specific operation as described herein.
[0114] Hardware components may also be implemented mechanically, electronically, or in any appropriate combination thereof. For example, a hardware component may have dedicated circuitry or logic permanently configured to perform a specific operation. A hardware component may be a special-purpose processor such as an FPGA (Field-Programmable Gate Array) or ASIC. Alternatively, a hardware component may have programmable logic or circuitry configured by software to perform a specific operation temporarily. For example, a hardware component may have software that runs on a general-purpose processor or other programmable processor. When configured by such software, the hardware component is no longer a general-purpose processor, as it becomes a specific machine (or a specific component of a machine) independently tuned to perform the configured function. It will be understood that the decision to implement a hardware component mechanically, in dedicated and permanently configured circuitry, or in temporarily configured circuitry (e.g., configured by software) may be made based on cost and time considerations. Therefore, the term “hardware component” (or “hardware implementation component”) should be understood to encompass tangible entities that are physically constructed, permanently configured (e.g., hardwired), or temporarily configured (e.g., programmed) in order to operate in a particular way or to perform a particular operation described herein. In consideration of embodiments where hardware components are temporarily configured (e.g., programmed), each hardware component does not need to be configured or instantiated in any single instance. For example, if hardware components consist of general-purpose processors configured by software to become special-purpose processors, the general-purpose processors may be configured as different special-purpose processors (e.g., to have different hardware components) at different times.The software may be configured accordingly, for example, to configure a particular processor or group of processors to constitute a specific hardware configuration in one instance of time, while configuring a different hardware configuration in a different instance of time.
[0115] Hardware components can provide information to other hardware components and receive information from other hardware components. Therefore, the described hardware components can be considered to be communicatively coupled. When multiple hardware components exist simultaneously, communication can be achieved by signal transmission between or within two or more hardware components (e.g., via appropriate circuits and buses). In embodiments where multiple hardware components are configured or instantiated at different times, communication between such hardware components may be achieved, for example, through the storage and retrieval of information in a memory structure accessed by the multiple hardware components. For example, one hardware component may not only perform an operation but also store the output of that operation in a communicatively coupled memory device. Another hardware component can then retrieve and process the stored output by accessing the memory device at a later date.
[0116] Hardware components can initiate communication with input or output devices, or they can operate on resources (e.g., collections of information). Various operations of the exemplary methods described herein may be performed at least partially by one or more processors that are configured, either temporarily (e.g., by software) or permanently, to perform the operations in question. Whether temporarily or permanently configured, such processors may constitute a processor implementation component that operates to perform one or more operations or functions described herein. As used herein, “processor implementation component” refers to a hardware component implemented using one or more processors. Similarly, the methods described herein may be at least partially processor-implemented, with a particular processor or a set of processors being an example of the hardware. For example, at least part of the operations of a method may be performed by one or more processors or processor implementation components. Furthermore, one or more processors may operate to support the performance of the operations in a “cloud computing” environment or as “software as a service” (SaaS). For example, at least part of an operation (behavior) may be performed by a group of computers (as an example of a machine containing multiple processors), and these operations may be accessible via a network (e.g., the Internet) and via one or more suitable interfaces (e.g., APIs). Certain performance aspects of an operation may reside not only within a single machine but also distributed among processors deployed across multiple machines. In some exemplary embodiments, the processor or processor implementation may be located in a single geographical location (e.g., a home environment, an office environment, or a server farm). In other exemplary embodiments, the processor or processor implementation may be distributed across multiple geographical locations.
[0117] In this context, "processor" means any circuit or virtual circuit (a physical circuit emulated by logic running on an actual processor) that not only manipulates data values according to control signals (e.g., "commands," "opcodes," "machine codes," etc.) but also generates corresponding output signals applied to operate a machine. A processor may be, for example, a CPU, RISC processor, CISC processor, GPU, DSP, ASIC, RFIC, or any combination thereof. A processor may also be a multicore processor having two or more independent processors (sometimes called "cores") that can execute instructions simultaneously.
[0118] In this context, "timestamp" refers to a string or encoded information that identifies when a particular event occurred, for example, providing the date and time, sometimes with a precision of a fraction of a second.
[0119] Modifications and alterations can be made to the disclosed embodiments without departing from the scope of this disclosure. These and other modifications are intended to be included within the scope of this disclosure, as set forth in the following claims.
[0120] In addition, as can be seen in the detailed description above, various features are combined into a single embodiment for the purpose of simplifying the disclosure. The method of disclosure should not be interpreted as reflecting an intention that the claimed embodiments require more features than are explicitly described in each claim. Rather, as reflected in the following claims, the subject matter of the invention may consist of fewer features than all the features of a single disclosed embodiment. Accordingly, the appended claims are incorporated into the detailed description in such a way that each claim stands alone as a separate embodiment.
Claims
1. A method for access control, One or more processors receive credentials for a user to access an access control device, To determine the confidence level of the user behavior model trained on the aforementioned user, If the confidence level falls below a threshold, access to the access control device is restricted to short-range communication protocols. Collect user behavior information during the training period, Updating the user behavior model based on the collected user behavior information, A method comprising: enabling access to the access control device using a long-range communication protocol in response to the updated user behavior model determining that it has achieved the confidence level above the threshold.
2. Receiving the observation trajectory of the aforementioned user, The system includes processing the observed trajectory using a machine learning model to generate a plurality of predicted trajectories, The method according to claim 1, wherein the first predicted trajectory among the plurality of predicted trajectories represents a first future path followed by the user from the observed trajectory, and the second predicted trajectory among the plurality of predicted trajectories represents a second future path followed by the user from the observed trajectory.
3. In order to determine the user's intention to activate the access control device, the plurality of predicted trajectories are adjusted based on the user behavior model, The access control device determines whether a given predicted trajectory among the plurality of predicted trajectories is within a threshold range. The method according to claim 2, further comprising: executing a process associated with the access control device in response to the access control device determining that a given predicted trajectory among the plurality of predicted trajectories is within a threshold range.
4. To establish a wireless communication link between the user's mobile device and the access control device, The exchange of authentication information via the aforementioned wireless communication link, The method according to claim 3, further comprising: determining, based on the authentication information, that the user has been granted permission to access the access control device, and then executing the process.
5. Before executing the above process, it is determined, based on the authentication information, that the user has been granted permission to access the access control device. The method according to claim 4, further comprising delaying the execution of the process after determining that the user is authorized until the access control device determines that the given predicted trajectory among the plurality of predicted trajectories is within the threshold range.
6. Before executing the above process, it is determined, based on the authentication information, that the user has been granted permission to access the access control device. The method according to claim 3, further comprising: preventing the user from executing the process after determining that they are authorized, in response to the access control device determining that a given predicted trajectory among the plurality of predicted trajectories is outside the threshold range.
7. Adjusting the multiple predicted trajectories based on the user behavior model is, The method according to claim 3, comprising processing the observed trajectory and user behavior information by a conditional variational autoencoder in order to generate the plurality of predicted trajectories.
8. Adjusting the multiple predicted trajectories based on the user behavior model is, The method according to claim 7, comprising linking the user behavior information with the plurality of predicted trajectories output by the conditional variational autoencoder.
9. The system further comprises processing the associated user behavior information and the multiple predicted trajectories with a second machine learning model. The method according to claim 8, wherein the second machine learning model is trained to establish relationships between a plurality of training user behavior pieces and a plurality of predicted intentions for activating a plurality of access control devices.
10. The system further comprises encoding the user's observation trajectory, The method according to claim 1, wherein the machine learning model is applied to the user's encoded observation trajectory.
11. The method according to claim 1, further comprising determining whether the received user behavior information satisfies the minimum parameters of the user behavior information.
12. The method according to claim 11, further comprising causing the access control device to execute processing in response to the determination that the received user behavior information satisfies the minimum parameters of the user behavior information.
13. The method according to claim 12, further comprising the action of preventing the access control device from executing the process in response to the determination that the received user behavior information does not satisfy the minimum parameters of the user behavior information.
14. The method according to claim 11, wherein the minimum parameters include threshold amounts for a specified number of types of user behavior information.
15. It further includes generating user behavior information by encoding feature vectors, Generating the aforementioned user behavior information means To monitor the physical movements of the aforementioned user, To monitor the stride length of the aforementioned user, Identifying multiple time periods and locations in which the user activates multiple different types of access control devices, Identifying other client devices and other types of access control devices within the user's scope when a given access control device is activated by the user. The method according to claim 1, comprising at least one of the following: identifying other users who would normally be present within the user's own social network.
16. Generating user behavior information using machine learning models, The method according to claim 1, further comprising generating a user intent to activate the access control device using an additional machine learning model.
17. It is a system, The system comprises one or more processors coupled to memory containing non-temporary computer instructions, wherein, when executed by the one or more processors, the non-temporary computer instructions cause a plurality of processes to be executed, and the plurality of processes are: The user receives credentials to access the access control device, To determine the confidence level of the user behavior model trained on the aforementioned user, If the confidence level falls below a threshold, access to the access control device is restricted to short-range communication protocols. Collect user behavior information during the training period, Updating the user behavior model based on the collected user behavior information, A system comprising: enabling access to the access control device using a long-range communication protocol in response to the updated user behavior model determining that it has achieved the confidence level above the threshold.
18. The aforementioned multiple processes are, Receiving the observation trajectory of the aforementioned user, The system includes processing the observed trajectory using a machine learning model to generate a plurality of predicted trajectories, The system according to claim 17, wherein the first predicted trajectory among the plurality of predicted trajectories represents a first future path followed by the user from the observed trajectory, and the second predicted trajectory among the plurality of predicted trajectories represents a second future path followed by the user from the observed trajectory.
19. The aforementioned multiple processes are, In order to determine the user's intention to activate the access control device, the plurality of predicted trajectories are adjusted based on the user behavior model, The access control device determines whether a given predicted trajectory among the plurality of predicted trajectories is within a threshold range. The system according to claim 18, further comprising: in response to the access control device determining that a given predicted trajectory among the plurality of predicted trajectories is within a threshold range, the system performs a process associated with the access control device.
20. A non-temporary computer-readable medium containing non-temporary computer-readable instructions for executing multiple processes, wherein the multiple processes are: The user receives credentials to access the access control device, To determine the confidence level of the user behavior model trained on the aforementioned user, If the confidence level falls below a threshold, access to the access control device is restricted to short-range communication protocols. Collect user behavior information during the training period, Updating the user behavior model based on the collected user behavior information, A non-transient computer-readable medium, including enabling access to the access control device using a long-range communication protocol in response to the updated user behavior model determining that it has achieved the confidence level above the threshold.