Method and system for access control using near field communication

The access control system uses RF signal communication and motion sensors to quickly and securely authorize users by verifying intent, addressing multiple user challenges and improving response times in Bluetooth-based access control.

JP7728157B2Active Publication Date: 2025-08-22AXIS
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
JP2021192813
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2020-12-22
Filing Date
2021-11-29
Publication Date
2025-08-22
Estimated Expiration
2041-11-29

AI Technical Summary

Technical Problem

Existing access control systems face challenges with multiple users, limited security features, and slow response times, particularly in Bluetooth-based solutions where connection times can exceed 10 seconds and lack effective authorization methods.

Method used

An access control system that uses radio frequency signal communication to automatically connect mobile devices to a control unit upon proximity, utilizing received signal strength and motion sensor data to verify the association of the user's intent, enabling quick and secure authorization without separate access devices, and allowing for multiple device monitoring and prioritization.

Benefits of technology

The system provides rapid, secure access control by verifying user intent through combined signal strength and motion data, ensuring only authorized users can initiate actions, and efficiently managing multiple connected devices to enhance security and response times.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007728157000001
    Figure 0007728157000001
  • Figure 0007728157000002
    Figure 0007728157000002
  • Figure 0007728157000003
    Figure 0007728157000003
Patent Text Reader

Abstract

To provide a method and a system for access control improved for access control regarding many users, safety, and response time.SOLUTION: In an access control system 100 that is connected to mobile devices with use of radio frequency communications, a control unit 110 sends a motion status request to connected mobile devices 120-122 and a non-connected device 123 in response to a generated event. Each mobile device estimates a probability that a user of the connected mobile device is a user who gives a request on the basis of received signal intensity data and human sensor data collected from a human sensor included in the mobile device, and sends an indication of the probability as a reply to the control unit. The control unit determines whether or not to carry out an action based on the indication of the probability that the connected mobile device is associated with the event.SELECTED DRAWING: Figure 1a
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] Embodiments herein relate to methods and systems for access control using short-range wireless communication. In particular, the present invention relates to determining whether to arrange to perform an action in response to a request in an access control system comprising an access control unit and one or more mobile devices. [Background technology]

[0002] A system using short-range wireless communication for access control typically includes a control unit and a mobile device. The short-range wireless communication between the mobile device and the control unit may be performed, for example, via Bluetooth, Bluetooth Low Energy (BLE), Zigbee, Wi-Fi, radio frequency identification (RFID), etc. Current solutions for access control, for example, at door stations, using Bluetooth wireless communication are one-to-one solutions in which a secure Bluetooth connection between the control unit and the mobile device is set up after the mobile device user presses a button on the door station or the mobile device. The connection time is then up to 10 seconds, which makes the opening process much longer than opening a door using an RFID badge and reader.

[0003] Other products use Bluetooth access control solutions with one-to-one secure connections; for example, a mobile device automatically connects when it receives a Hello message sent from a door station. As an additional password for the door-opening command, the user moves the mobile device in a predetermined pattern that is detected by a motion sensor in the mobile device. If the movement pattern is correct, the mobile device sends an OK to the door station, which opens the door.

[0004] Patent Document 1 discloses a method for controlling access in a system having a mobile device associated with a user and an access control device. The mobile device and the access control device are configured to wirelessly communicate with each other. The method compares received signal strength over time with a previously determined reference signal strength profile. By determining signal strengths over time and comparing them to the determined reference signal strength profile, it is possible to distinguish between a first situation in which a user is approaching an office door with the intention of entering the office space and a second situation in which a user is approaching the office door with the intention of passing by the office door in a hallway. The method also compares motion sensor data with the reference value. The movement pattern of the mobile device is used to obtain more accurate timing for controlling the access control device to avoid or at least reduce unwanted delays or wait times for the user.

[0005] Patent Document 2 discloses a wireless access control system including a remote access device and an electronic lock. The electronic lock communicates with the remote access device. The electronic lock controls the ability to lock and unlock a door on which the electronic lock is located. The electronic lock determines when the remote access device is within a predetermined distance from the lock so that the lock can be unlocked. In one embodiment, to determine whether the remote access device is actually in a position to access the lock, the wireless access control system determines the radio signal strength of an access request from the remote access device. A controller of the remote access device determines whether the radio signal strength is greater than a predetermined value. If so, a signal is sent from the wireless access control system to the remote access device. The remote access device determines the radio signal strength of the signal from the wireless access control system, and permission to control the lock is granted only if the remote access device determines that the remote signal strength of the signal from the wireless access system is above a predetermined threshold.

[0006] However, there are problems associated with multiple users of an access control system: for example, there may be more mobile devices trying to connect to a control unit than the control unit can handle.

[0007] Furthermore, current solutions for access control have limited security features or are relatively slow to respond. For example, some solutions use a received signal strength indicator (RSSI) threshold to determine proximity to an access unit and then grant access to anyone in close proximity. Some solutions omit RSSI monitoring altogether and simply grant access to anyone who presses a button on an access application (app) within a mobile device. [Prior art documents] [Patent documents]

[0008] [Patent Document 1] European Patent Application Publication No. 3477600 A1 [Patent Document 2] International Publication No. 2015 / 023737 Brochure Summary of the Invention [Problem to be solved by the invention]

[0009] In view of the above, it is an object of the embodiments herein to provide improved methods and systems for access control with respect to multiple users, security, and response time.

[0010] According to one aspect of an embodiment herein, the object is achieved by a method performed in an access control system. The access control system may be a system for controlling access to a physical or logical area or resource. The method is for determining whether to arrange to perform an action in response to an event occurring in the access control system. The access control system comprises a control unit connected to one or more mobile devices using radio frequency signal communication. Respective access applications are installed on the one or more mobile devices. The access applications communicate with the control unit and may execute or arrange for the mobile devices to execute an action in response to communication with the control unit. For example, the access applications may execute or arrange for the mobile devices to execute some of the following actions:

[0011] An event represents a request to arrange for a control unit to perform an action, and the control unit controls access to physical or logical areas or resources depending on the event that has occurred.

[0012] In some embodiments, the action performed is to provide access to a physical resource, such as opening any type of lock, e.g., locking a door, lid, window, etc. In some other embodiments, the action is to provide access to a logical resource, such as a database, the contents of a logical area, or a protected device.

[0013] A request for an action to be performed may be given by a user of a mobile device located near the control unit. The request may be given, for example, by pressing a button or touching a touchscreen on or at the control unit, by activating an IR detector on or located at the control unit, or by detecting noise with a microphone on or at the control unit. The request may be given anonymously. The request may be a command to gain access to a physical area, the contents of a logical area, a protected device, or a protected resource controlled by the control unit.

[0014] The request may be given by a user authorized to cause the action, or by someone who is not: having a mobile phone connected to the control unit may in itself mean that the user is authorized to cause the action, or having a mobile phone connected may only be a first authorization level that leads to a check of a second authorization level (whether or not the action is allowed to be caused).

[0015] The user of the mobile device may be a person or an object carrying the device. The user of the mobile device may have access rights associated with resources controlled by the control unit. The user of the mobile device may be located in physical proximity to the mobile unit when the method is performed.

[0016] The access control system further comprises a radio frequency transceiver. The method includes transmitting, by the radio frequency transceiver, a radio frequency signal to be used for measuring received signal strength by one or more connected mobile devices.

[0017] The control unit transmits an operation status request to a connected mobile device among the one or more connected mobile devices in response to an event that has occurred.

[0018] The method further comprises determining an indication of a probability that the connected mobile device is associated with the event. Determining the indication of the probability is based on received signal strength data and motion sensor data of the connected mobile device. The received signal strength data is measured by the connected mobile device for radio frequency signals transmitted during a first predetermined period before the motion state request is received from the control unit. The received signal strength may be an indication of a signal energy level or signal power level received at a receiver of the mobile device. Examples of the received signal strength measure used may be a received signal strength indicator (RSSI) or a received channel power indicator (RCPI).

[0019] The motion sensor data is collected from a motion sensor included in the connected mobile device during a second predetermined period before the motion status request is received from the control unit. The motion sensor may be, for example, a sensor that measures linear acceleration in up to three axes, such as an accelerometer, a sensor that measures rotation, such as a gyroscope, a sensor that measures air pressure, such as a barometer, or a sensor that measures orientation, such as a compass.

[0020] The control unit further determines whether to arrange for the connected mobile device to perform an action based on an indication of the probability associated with the event.

[0021] According to a further aspect of the embodiments herein, the object is achieved by an access control system configured to perform the above method. The access control system includes a control unit and one or more mobile devices. The mobile devices may be any one of a mobile phone, a tablet, a laptop, a key fob, a smart watch, or a smart bracelet. The control unit may be any unit that controls access to a physical area, a logical area, a protected device, or a protected resource.

[0022] In other words, according to embodiments herein, one or more mobile devices are connected to a control unit. The one or more mobile devices may be automatically connected to the control unit, for example, when they are within reach of the control unit. In some embodiments herein, when a mobile device is connected to a control unit, a secure communication channel is established between the mobile device and the control unit. Furthermore, the connection of a mobile device can mean that the mobile device has been pre-authorized to initiate an action, i.e., the user of the mobile device is authorized to initiate the action and is an authorized user of the service provided by the control unit. With this authentication, the control unit is arranged to execute the request requested by the mobile user. However, the automatic connection merely sets up a communication channel, while all security requirements, authorization, and encryption are handled later when required.

[0023] A request for an action to be performed, such as a door open command, can be made by, for example, pressing a button on or at the control unit or touching a touchscreen. Furthermore, the request can be made by a user authorized to cause the action, or by someone not authorized to cause the action, such as a user of an unauthenticated, unpaired, or unbonded mobile device, or by a user without a mobile device, or a user with a mobile device but without an access application. A request can also be made by a user of a paired but unconnected mobile device, which can occur when the maximum number of connections to the control unit has been reached. When the control unit registers an event or obtains an indication of an event that is the result of a request made by someone, a verification process is performed to determine whether one of the connected mobile devices is associated with the event—in other words, whether it was a user of one of the connected mobile devices that made the corresponding request—and to determine whether the requested action, such as opening a door, should be arranged. The control unit initiates this verification process by sending a motion state request to one or more connected mobile devices. A corrected estimate may be calculated for each of one or more connected mobile devices based on the received signal strength and motion sensor data to estimate the probability that the connected mobile device is associated with the event, in other words, the probability that the user of the connected mobile device is the user who generated the request. An action may then be determined based on the indication of the probability that the connected mobile device is associated with the event. If the indication of the probability for the connected mobile device indicates that it is the user of the connected mobile device that provided the request with the intent to open the door, the action may be to perform the requested action, for example, to open the door.Also, if the indication of the probabilities of all connected devices indicates that none of the users of the connected devices has granted the request, the action may be to not perform the requested action, i.e., not open the door. Additionally, the control unit may decide to disconnect at least one connection between the mobile device and the control unit to allow other paired or coupled mobile devices to connect to the control unit, since the request may be granted by a user of a paired but unconnected mobile device. By disconnecting at least one connection, the paired mobile device can connect to the control unit, allowing the user of the mobile device to trigger the action by requesting it.

[0024] An advantage of embodiments herein is that requested activities can be triggered quickly and securely without the requester needing a separate access control device, such as an RFID card. Another advantage is that the user of the mobile device does not need to interact with the mobile device, so the mobile device can remain in the user's pocket. An advantage of automatically connecting each paired mobile device when within range of the control unit is that when the user of the mobile device issues a request, such as a door open command, the connection is already set up and there is no delay in opening the door. In other words, because the connected mobile device is already connected, the control unit can quickly respond to the request by, for example, performing the requested action. For example, if a request is issued by a user from a paired mobile device that is already connected to the control unit, for example, by pressing a button or touching a screen on the mobile device, the request is sent to the control unit, and the control unit, knowing that the request came from a paired, and thereby pre-authorized, mobile device, arranges for the requested action, such as opening a door, without further analysis. However, if a request is given to the control unit, for example, by pressing a button on or at the control unit or touching a touchscreen, the control unit must be able to determine whether the request was given by a user of the connected mobile device, i.e., by a user whose mobile device is connected to the control unit. Several mobile devices may be connected to the control unit at the same time, some of which may belong to users who have not given a request to the control unit and do not, for example, want access to a door controlled by the control unit. By sending a motion state request and then determining whether the connected mobile device will perform an action in response to the event based on an indication of the probability associated with the event, the control unit can verify whether the request was given by a user of the connected mobile device who intends to open the door.In this way, the requested action can be arranged in a secure manner. Furthermore, using the motion data to improve the evaluation of the RSSI data provides additional security so that the control unit does not decide to perform an action on a user who is not associated with the event, for example, a user who has placed their mobile device on a table or in a bag but is still close to the control unit.

[0025] Embodiments herein monitor the behavior of users of connected mobile devices and arrange access for those who actually have the intent and right to access. Embodiments herein also prevent the control unit from performing a requested action by someone unauthorized, or by an authorized user of a mobile device that is located near a control unit with an active connection but whose user has not requested the action, or by an authorized user of a mobile device that is passing by the door and not approaching the door when a request is given to the control unit by another person.

[0026] Embodiments herein also allow for monitoring many mobile devices at once and prioritizing them, for example, by disconnecting selected connections. By disconnecting selected connections, such as connections to inactive or simply passing mobile devices, incoming users can be connected more quickly.

[0027] Thus, embodiments herein provide improved methods and systems for access control for multiple users, security, and response time.

[0028] Example embodiments will now be described in more detail with reference to the accompanying drawings. [Brief explanation of the drawings]

[0029] [Figure 1a] 1 is a block diagram illustrating an access control system in which embodiments herein may be implemented. [Figure 1b]FIG. 10 is a block diagram illustrating a further access control system in which embodiments herein may be implemented. [Figure 2] 1 is a flowchart illustrating a method performed by a control unit for access control according to embodiments herein. [Figure 3] 1 is a flowchart illustrating a method performed by a mobile device for access control according to embodiments herein. [Figure 4] 1 is a flowchart illustrating a method performed by a control unit and a mobile device for access control according to embodiments herein. [Figure 5a] 10 is a flowchart illustrating a further method performed by a control unit and a mobile device for access control according to embodiments herein. [Figure 5b] FIG. 2 is a signaling diagram illustrating a method for handling a radio frequency connection between a control unit of an access control system and a mobile device according to embodiments herein. [Figure 6] FIG. 1 is a block diagram illustrating a control unit in which methods according to embodiments herein may be implemented. [Figure 7] 1 is a block diagram illustrating a mobile device in which methods according to embodiments herein may be implemented. DETAILED DESCRIPTION OF THE INVENTION

[0030] 1a and 1b are block diagrams illustrating two embodiments of an access control system 100 in which embodiments herein for determining whether to arrange to perform an action in response to an event generated in the access control system may be implemented.

[0031] As shown in both Figures 1a and 1b, the access control system 100 comprises a control unit 110 exemplified as a door station for controlling access to a physical area, such as, for example, opening / unlocking or keeping closed and / or locked any type of lock, e.g., lock 111a of a door 111b, lid, window, etc., in response to a generated event.

[0032] However, the control unit 110 may also control access to logical resources, such as logical areas or databases, protected devices, or protected resources in response to events. The control unit 110 may, for example, grant or deny access to the contents of a database or logical area, protected devices, or protected resources. To control access to a physical area, the control unit 110 may be, for example, an intelligent door station, a simple keypad, a card reader, or a per-door command receiver connected to a remotely located intelligent access control device. As shown in FIG. 1a, the control unit 110 may include a radio frequency transceiver 112 having wireless short-range communication capabilities for communicating with one or more mobile devices using radio frequency signal communication. The control unit 110 may further include a request receiving unit 113, such as a button to press, a touch screen, an IR detector, or a microphone, as also shown in FIG. 1a. The control unit 110 may further include a startup module that can be arranged to perform requested operations, as well as memory and a processor not shown in either FIG. 1a or FIG. 1b. Additionally, processing and storage means external to the control unit 110 may also be used by the access control system 100. For example, a cloud service or web server may perform some of the following operations described as being performed by the control unit 110.

[0033] In the embodiment shown in FIG. 1b, the radio frequency transceiver 112 and the request receiving unit 113 are external to and connected to the control unit 110. Because received signal strength measurements of signals transmitted from the radio frequency transceiver 112 are used to determine whether a mobile device is associated with an event generated by the request receiving unit 113, the radio frequency transceiver 112 and the request receiving unit 113 should, in any case, be close to each other to implement the embodiments described herein. Close to each other can mean, for example, that the distance between these two units should not be greater than the resolution or mean positioning error of the received signal strength measurements. Such mean positioning error may be, for example, on the order of 1 to 5 meters in state-of-the-art BLE solutions. Furthermore, if the radio frequency transceiver 112 is external to the control unit 110, the radio frequency transceiver 210 is preferably located close to the control unit 110.

[0034] The control unit 110 may further be connected, for example wirelessly or by wire, to the door 111b or, as shown in Figures 1a and 1b, to the lock 111a of the door 111b. The control unit 110, the radio frequency transceiver 112, and the request receiving unit 113 may each be located near an object, such as the lock 111a of the door 111b, that is controlled by the access control system 100.

[0035] The access control system 100 further comprises one or more connected mobile devices 120-122 shown in FIGS. 1a and 1b and / or a respective access application installed on the one or more connected mobile devices 120-122. The respective access application can communicate with the control unit 110 and can execute or arrange for each of the one or more connected mobile devices 120-122 to perform an action in response to communication with the control unit 110. For example, the access application can execute or arrange for each of the one or more connected mobile devices 120-122 to perform some of the following actions: (a) execute a program for each of the one or more connected mobile devices 120-122; (b) execute a program for each of the one or more connected mobile devices 120-122; (c) execute a program for each of the one or more connected mobile devices 120-122; (d) execute a program for each of the one or more connected mobile devices 120-122; (e) execute a program for each of the one or more connected mobile devices 120-122; (f) execute a program for each of the one or more connected mobile devices 120-122; (g) execute a program for each of the one or more connected mobile devices 120-122; (h) execute a program for each of the one or more connected mobile devices 120-122; (i) execute a program for each of the one or more connected mobile devices 120-122; (j) execute a program for each of the one or more connected mobile devices 120-122; (k ... For example, each access application may arrange for a cloud service or web server to perform the following operations:

[0036] In addition to the connected mobile devices 120-122, FIGS. 1a and 1b also show unconnected mobile devices 123 in the vicinity of the access control system 100. FIGS. 1a and 1b further show arrows pointing away from some of the connected mobile devices 120-122 and away from the unconnected mobile devices 123. Each arrow indicates the direction of movement of the respective mobile device 120-123. One of the mobile devices is not associated with an arrow, meaning that the mobile device is stationary, i.e., its velocity is zero. Each of the connected mobile devices 120-122 may be, for example, a mobile phone, laptop, tablet, key fob, smartwatch, or smart bracelet. A user of the mobile device may request access to the physical domain, the content of the logical domain, a protected device, or a protected resource. Each connected mobile device 120-122 may also have wireless short-range communication capabilities and may include a radio frequency transceiver, memory, and processor for communicating with the control unit 110 using radio frequency signal communication. Each of the connected mobile devices 120-122 is associated with a user.

[0037] The short-range wireless communication between each mobile device 120-122 and the control unit 110 may be performed, for example, via Bluetooth (registered trademark), BLE, Zigbee, Wifi, RFID, Ultra-Wideband (UWB), FeliCa (registered trademark), ANT+, Z-Wave, or via infrared or ultrasonic communication.

[0038] A mobile device, such as a connected mobile device 120-122, may automatically connect to the control unit 110 when it is within reach of the control unit 110. Some examples of when a mobile device is within range of the control unit 110 are when the mobile device detects or receives a Hello message sent by the control unit 110 using Bluetooth®, or when the distance between the respective mobile device and the control unit 110 is less than a threshold distance, e.g., 1 meter, which may be measured using location services, a global positioning system (GPS), or an indoor location system. Distance measurement may also be achieved by analyzing wireless communication characteristics, e.g., via time of flight, or some other method combining such analysis with phase difference. Such distance measurement may be performed, for example, using UWB. Mobile device motion sensor data may also be used to determine when each mobile device automatically connects to the control unit 110. For example, if the first mobile device 120 is stationary, or if its motion sensor data is below a threshold, or if it is moving away from the control unit 110, etc., according to some embodiments, the first mobile device 110 does not automatically connect to the control unit 110.

[0039] In the embodiments herein, several mobile devices may be connected simultaneously, which allows for a faster response to event generation. However, the pre-pairing step is optional. One way to resolve the connection step is the pairing process, which can be described as a setup configuration to achieve authorization to enable automatic connection. This pairing does not necessarily imply authorization for any further operation.

[0040] Another way to solve the connection step is to perform the connection authorization every time the mobile device is close enough to the control unit 110 but before the user of the mobile device generates an event by request.

[0041] As described above, upon automatically connecting to the control unit 110, each connected mobile device 120-122 may be bound or paired to the control unit 110 through a pairing process. When two devices are paired, they may share their addresses, names, and profiles, and typically store them in memory. They may also share a common secret key, which allows them to be bound or paired whenever they come together in the future.

[0042] Pairing typically requires an authentication process in which a user must verify the connection between the devices. The flow of the authentication process varies and typically depends on the interfacing capabilities of one device or the other.

[0043] Below is an example of the door station pairing process: The door station sends an encryption key and authentication identification (ID) to the mobile device. The user launches the Mobile Access app on their mobile device and enters pairing mode. In pairing mode, the mobile app scans for available door stations to pair with. The user selects the correct door station and enters the pairing PIN code. The pairing PIN must be generated by the door station and provided to the user in some form. Any known pairing method can be applied to the selected RF communication method. Encryption keys and authorization IDs are exchanged after the door station verifies the pairing PIN. It is the mobile device's authorization ID that contains the access rights to open the door, for example.

[0044] After this pairing process, the mobile device is bound or paired to the door station. When the mobile device reaches the door station, it can begin the following pre-authentication process. Connect to a door station. Establish a secure communication channel with the door station using the encryption key received during pairing.

[0045] If pairing, i.e., authentication, does not occur before automatic connection, it may occur either at the time of connection or at the time of request, e.g., when a button is pressed and the control unit 110 determines who pressed it. This may be, for example, when the control unit 110 makes an authorization call to an access rights database.

[0046] In some embodiments herein, no pairing, authentication, or encryption keys are used at all. Instead, the mobile device 120 may connect when it is within range of the control unit 110, with any security checks then occurring following the event.

[0047] It is known that when devices connect to each other, for example in a Bluetooth® piconet, a master-slave relationship exists between the two devices. One of the devices is the master and the other device is the slave. According to some embodiments herein, the control unit 110 can function as the master, and according to some other embodiments, each of the mobile devices 120-122 can function as a master.

[0048] To demonstrate a method for determining whether to perform an action in response to an event generated in an access control system 100 according to an embodiment of the present specification, an exemplary scenario of access control to a physical area where the radio frequency communication is BLE (Bluetooth Low Energy) is described below in relation to FIG. 1a.

[0049] A control unit 110 in the form of a BLE-enabled door station controlling access to a door 111b, e.g., a project office room, is located within an office environment. Within the office environment, there are several mobile devices 120-122 in the form of mobile phones with access apps, all of which are paired with the door station 110 and have valid credentials, e.g., valid pre-certification, verifying that they are granted access to the project office room. There are also mobile devices in the office environment with access apps that are not paired with the door station, i.e., do not have valid credentials and therefore do not have access to the project office room. The mobile devices 120-122 may be carried by the user or may be placed on a desk or in a bag within the office environment.

[0050] When within range of the control unit 110, a paired mobile device 120 automatically connects to the control unit 110 and a secure communication channel over Bluetooth is established with the control unit 110. A user of the mobile device can request the control unit 110 to perform an action, such as a door open command. The request may be made by pressing a button or touching a screen included in the access control system 100, for example, on the control unit 110 or in the control unit 102, or by any of the other methods described above.

[0051] The request may be generated by a user authorized to cause the action, but may also be generated by someone other than the user, such as a user of an unauthenticated, unauthorised, unpaired or unbound mobile device, or a user without a mobile device, or a user with a mobile device but without the access app. The request at or on the control unit 110 may also be given by a user of a paired but unconnected mobile device, which may occur when the maximum number of connections to the control unit 110 has been reached. If a user of an unauthenticated or unpaired mobile device, or a user without a mobile device or access app at all, presses a button or touches a screen on the control unit 110, the door should not open. If a user of a paired but not yet connected mobile device presses a button or touches a screen on the control unit 110 or on the control unit 210, the request should result in the door being opened.

[0052] The problem that arises in this scenario is how the control unit 110 should verify that the user who gave the door open command on the control unit 110 is an authorized user with a paired mobile device that has a valid certificate, and how the control unit 110 should decide whether to open the door.

[0053] When the control unit 110 receives an event as a result of a request made by someone at or on the control unit 110, a verification process is required to determine whether it is the user of a connected mobile device or a user of a paired but unconnected mobile device making the request and to decide whether the requested action, e.g., opening a door, should be performed.

[0054] A method for solving the above problem will be described below with reference to the flowchart shown in FIG. 2 and with further reference to the access control system shown in FIGS. 1a and 1b. The flowchart in FIG. 2 illustrates a method for determining whether to perform an action in response to an event generated in the access control system 100. The problem is solved by determining whether to arrange to perform an action in response to an event generated in the access control system 100. The event indicates a request for the control unit 110 to arrange to perform an action. The event generated in the access control system 100 can be the result of a request made by a user of a mobile device 120. In some embodiments, the mobile device user is a user of one of one or more connected mobile devices 120-122. In other embodiments, the mobile device user is a user of a non-connected mobile device 123. Although the method is described below with respect to a connected mobile device 120, the method can be applied to multiple connected mobile devices 120-122, in parallel or serially.

[0055] As mentioned above, the access control system comprises a control unit 110 connected to one or more mobile devices 120-122 using radio frequency signal communication.

[0056] 2 may be performed in the following exemplary order: In other examples, the order may differ from that described below. The method may include the following operations:

[0057] Operation 201 The control unit 110 arranges for the transmission of radio frequency signals used to measure received signal strength by one or more connected mobile devices 120-122. For example, in some embodiments, the control unit 110 controls the radio frequency transceiver 112 to transmit radio frequency signals used to measure received signal strength by one or more connected mobile devices 120-122. In some embodiments, the unit that actually transmits the RF signals, such as the radio frequency transceiver 112, is not necessarily included in the control unit 110 as shown in FIG. 1a, but is instead connected to, controlled by, and optionally located in close proximity to the control unit 110 as shown in FIG. 1b. As mentioned above, since the determination of the probability that a connected mobile device 120 is associated with an event is based on the RF signals transmitted from the transceiver 112, it may be important that the radio frequency transceiver 112 is located close to the request receiving unit 113.

[0058] These RF signals are used to determine an indication of the probability that a particular connected mobile device 120 of the one or more connected mobile devices 120-122 is associated with an event generated in operation 202 below, as described in operation 204 below.

[0059] Operation 202 Then, at some point, someone generates an event that indicates a request to arrange for the control unit 110 to perform an action. For example, a user of a connected mobile device 120 generates an indication of a request to open door 111b.

[0060] As described above, in some embodiments, the request to arrange for the control unit 110 to perform an action includes a request to grant access to a physical domain, a logical domain, a protection device 111a, 111b, or a protected resource. In these embodiments, determining whether to arrange for the action to be performed in response to the generated event includes determining whether to grant access to the physical domain, the logical domain, the protection device 111a, 111b, or a protected resource.

[0061] operation 203 The control unit 110 initiates the verification process upon generation of the event by sending a respective motion status request to a respective one of the one or more connected mobile devices 120-122. The control unit 110 may send the respective motion status request to each of the connected mobile devices 120-122 or to selected ones of the connected mobile devices 120-122, but not to at least one of them.

[0062] Before sending the motion status request, the control unit 110 may obtain an indication of the event or may register the event, which may be the case if the event is generated in a separate unit such as the request receiving unit 113.

[0063] The control unit 110 transmits an operation status request to the connected mobile device 120 among the one or more connected mobile devices 120 to 122 in response to the event that has occurred.

[0064] The motion status request serves as a trigger for the connected mobile device 120 to compile received signal strength data and motion sensor data to be used to determine an indication of the probability that the connected mobile device 120 is associated with the event in a subsequent operation 204. In some embodiments, the motion status request requests the connected mobile device 120 to respond with an indication of the probability that the connected mobile device 120 is associated with the event.

[0065] operation 204 Both the control unit 110 and the connected mobile device 120 may determine an indication of the probability that the connected mobile device 120 will be associated with the event.

[0066] As described above, determining the indication of probability is based on received signal strength data, such as RSSI, and motion sensor data, such as accelerometer data or angular velocity data, of the connected mobile device 120. The received signal strength data is measured by the connected mobile device 120 for radio frequency signals transmitted during a first predetermined period before the motion state request is received from the control unit 110. In other words, the received signal strength data is derived by the mobile device 120 from measurements of the transmitted radio frequency signals.

[0067] The motion sensor data is collected from the motion sensors included in the connected mobile devices 120 during a second predetermined period of time before the motion status request is received from the control unit 110. The second predetermined period of time may be different from the first predetermined period of time. Note that, although not shown in Figures 1a and 1b, each connected mobile device 120-122 may include a respective motion sensor.

[0068] By determining an indication of probability based on both received signal strength data and motion sensor data, increased accuracy of the determination is achieved, as compared to, for example, determining the probability based solely on received signal strength data. For example, motion sensor data may be used to correct the estimate of probability based on received signal strength data, as described in more detail below.

[0069] In some embodiments, determining the indication of probability comprises calculating an estimate indicative of the probability that the connected mobile device 120 is associated with the event based on the received signal strength data. The estimate may include, for example, an estimated time to reach the request receiving unit 113 or the radio frequency transceiver 112. As mentioned above, if the radio frequency transceiver 112 is external to the control unit 110, the radio frequency transceiver 220 is preferably located near the control unit 110.

[0070] In other embodiments, the estimate includes an estimated distance to reach the control unit 110, possibly in combination with an estimated speed, such as an estimated constant speed. In yet other embodiments, the estimate includes an estimated increase in signal strength reaching the control unit 110.

[0071] Determining the indication of the probability may further comprise calculating a corrective motion factor based on the motion sensor data and adjusting the estimate with the corrective motion factor to obtain a corrected estimate indicative of the probability.

[0072] In some embodiments, the corrected estimate corresponds to a corrected estimated time to reach the radio frequency transceiver 112. Calculating the corrected estimated time to reach the radio frequency transceiver 112 then comprises calculating an estimated time for the mobile device 120 to reach the control unit 110 based on the received signal strength data, calculating a corrective motion factor based on the motion sensor data, and adjusting the estimated time by the motion factor to obtain the corrected estimated time. For example, the estimated time may be divided by the motion factor, as described in more detail below. In other embodiments, the estimated time may be multiplied by the motion factor.

[0073] When the corrected estimate is calculated, determining an indication of the probability may comprise comparing the corrected estimate, which indicates the probability that the connected mobile device 120 is associated with the event, to a predetermined threshold value corresponding to the predetermined probability that the connected mobile device 120 is associated with the event. For example, the corrected estimate may be a corrected estimated time to reach the control unit that reaches 5 seconds. The corrected estimated time may be compared to a threshold value of 10 seconds. A time below the threshold time is associated with a high probability, which may be indicated, for example, with "yes" or a 95% probability or the like.

[0074] In some embodiments, determining an indication of the probability based on the received signal strength data and the motion sensor data comprises calculating, by connected mobile device 120, a corrected estimate based on the received signal strength data and the motion sensor data. The method may then further comprise sending, by connected mobile device 120, the indication of the probability and / or the corrected estimate to control unit 110 in response to a motion status request. Responding to a motion status request is further described below in connection with operation 205.

[0075] When the control unit 110 sends a motion status request to a plurality of connected mobile devices 120-122 of the one or more connected mobile devices 120-122, determining an indication of a probability may comprise determining a respective indication of a probability that a respective one of the plurality of connected mobile devices 120-122 is associated with the event. In such an embodiment, determining whether to arrange to perform an action described below in operation 206 comprises determining whether to arrange to perform an action based on the respective indication of the probability. For example, the control unit 110 may decide to arrange to perform an action in response to a first positive response to the plurality of motion status requests. The method may then stop processing further responses, or the method may continue processing further responses.

[0076] Details of operation 204 are described below. Upon receiving a motion status request, a corrected estimate may be calculated for each of one or more connected mobile devices 120-122 based on the received signal strength data and the motion sensor data to estimate the probability that the user of the connected mobile device is the user making the request. The corrected estimate may also be referred to as a composite value because it is based on both the received signal strength data and the motion sensor data.

[0077] The received signal strength may be measured by each of the connected mobile devices 120-122 on a radio frequency signal transmitted by the control unit 110, for example, a Bluetooth beacon transmitted by the control unit 110. The received signal strength may be measured over a period of time and then averaged to generate a received signal strength indicator (RSSI). The RSSI may be generated periodically, for example, every second or every other second.

[0078] The received signal strength may be measured as a power level metric over a period of time by each of the connected mobile devices 120, 121, 122, for example, on a radio frequency channel between the control unit 110 and each of the connected mobile devices 120-122, to generate a received channel power indicator (RCPI).

[0079] The received signal strength measured by each of one or more connected mobile devices 120-122 during a first predetermined time period is analyzed. The first time period may be, for example, 10 seconds before a motion state request is received from the control unit 110. The objective is to determine whether the user of the mobile device 120 was approaching or walking away from the control unit 110, or whether the received signal strength was constant during the first time period before the event was generated, e.g., the last 10 seconds. A potential requesting user is someone who is approaching the control unit 110 during the first predetermined time period.

[0080] An estimated time (e.g., in seconds) to reach the radio frequency transceiver 112 may be calculated for each of the connected mobile devices 120-122 based on the received signal strength. The estimated time indicates the duration for the connected mobile device to reach the control unit 110. The estimated time may indicate a time from a known specific time, such as the time of transmission of the motion status request, or the time of receipt of the motion status request, or a time with a predetermined offset to either of the above times.

[0081] The estimated time may be calculated for each connected mobile device 120-122 and each time each connected mobile device 120-122 receives a motion status request from the control unit 110. For example, the estimated time may be calculated based on a linear model in which the relationship between received signal strength indicator values ​​and time may be defined as r = a + b, where r is the received signal strength indicator (RSSI) and t is time. If the value of a is positive, the connected mobile device 120 is approaching the control unit 110. A negative value of a means that the connected mobile device 120 is moving away. If a is close to 0, there is no motion. Therefore, the parameters a and b may be considered to be an estimated constant velocity. The parameters a and b may be estimated, for example, using "weighted ridge regression" and multiple RSSI values ​​determined from received signal strength data collected over a first predetermined period, e.g., 10 seconds, before the motion status request from the control unit 110 is received. The calculated a and b parameters may be considered to be average values ​​over the first predetermined time period, especially if a constant velocity is assumed.

[0082] If constant movement, as defined by a constant speed, is assumed, and an RSSI value of Rt=-55 is used as the RSSI value at which the connected mobile device 120 reaches the control unit 110, the time to reach the radio frequency transceiver 112 may be calculated as the time to hit, th, determined as th=(Rt-b) / a, e.g., in seconds. The time, th, is therefore an estimate of how many seconds it would take to reach the threshold, Rt, if the movement remained constant, i.e., the duration for the connected mobile device 120 to reach the control unit 110.

[0083] To improve verification of the origin of the generated event, motion sensor data from one or more motion sensors, e.g., an accelerometer and / or gyroscope, included in the connected mobile device 120 is taken into account to provide a corrected estimate based on both signal strength and the motion sensor data. The motion sensor data may be collected for a second predetermined time period, e.g., 5 seconds, before the motion status request from the control unit 110 is received by the connected mobile device 120.

[0084] The corrected estimate may be a motion-compensated th value calculated for each connected mobile device 120-122 and each time the connected mobile device 120 receives a motion status request from the control unit 110 by using the collected motion sensor data. The a parameter in the above linear model may be adjusted by the calculated probability p_movement that the connected mobile device 120 is moving, using known methods, so that a_compensated = p_movement * a. Using Rt = -55, which is the RSSI value when the connected mobile device 120 reaches the control unit 110, a motion-compensated th value indicating the motion-compensated duration for the connected mobile device 120 to reach the control unit 110 is calculated as th_compensated = (Rt - b) / a_compensated. This calculation can result in a first connected mobile device 120, which may not be moving or may be moving only at a low speed or low acceleration, being subject to a larger increase in the estimated time to reach the radio frequency transceiver 112 during a second predetermined time period than a second connected mobile device 121, where collected motion sensor data indicated that the second connected mobile device 121 was moving more, for example, at a higher speed, or with a higher acceleration, or with a higher angular velocity. The motion-compensated th value can be used by the connected mobile device 120 to make a determination as to whether the user of a particular connected mobile device 120 is likely to have granted a request by comparing it to an appropriate threshold T. If the compensated th value for a connected mobile device 120 is higher than T, it is unlikely that the user of the connected mobile device 120 issued a request. If th_compensated is lower than T, the likelihood is high.

[0085] Motion sensor data may be collected from one or more motion sensors in the connected mobile device 120, for example, in one-second segments, for the five seconds before the request is received, and analyzed to determine a motion coefficient. The motion coefficient may indicate the degree of change in the motion of the connected mobile device 120, for example, how much the motion of the connected mobile device 120 has increased or decreased. For example, the degree of change in motion may be described by a change in velocity. Such a change in velocity may be related to the acceleration or angular velocity measured by the motion sensor. The motion coefficient may be provided as a percentage, for example, with 0% representing stable stillness and 100% representing a significant increase in motion.

[0086] The corrected estimate may be calculated based on the estimated time and the motion factor. That is, the corrected estimate may be a motion-compensated time estimate determined by adjusting the estimated time from the RSSI calculation above with the motion factor. The corrected estimate may be proportional to the received signal strength and inversely proportional to the motion sensor data.

[0087] According to some embodiments herein, the corrected estimate may be calculated by dividing the estimated time derived from the RSS data by a motion factor. Some examples are shown below: A shift factor of 50% provides a 100% increase in the estimated RSS time, i.e., corrected estimated time RSS / 0,50 = 2 * estimated time from RSS. A shift factor of 75% provides a 33% increase in the estimated RSS time, i.e. corrected estimated time RSS / 0,75 = 1,33 * estimated time from RSS. A shift factor of 100% leaves the estimated time from RSS unchanged, i.e., corrected estimated time RSS / 1.00 = estimated time from RSS.

[0088] Thus, the corrected estimate indicates the probability that the request will be granted by the user of the connected mobile device. If the corrected estimate for a connected mobile device 120 is less than a threshold value, e.g., 10 seconds, it is determined that the user of that particular connected mobile device 120 is likely to have granted the request. In that case, the response to the motion status request is a positive response indicating, for example, "Yes, it's likely that my user granted the request." If the connected mobile device 120 is stationary on a desk, its motion factor may be 0%, but the RSS value may still be changing, perhaps due to another person moving between the mobile device and the control unit 110. The estimated time from the RSS may then be significantly increased by the motion factor, resulting in a corrected estimate greater than 10 seconds, indicating that the user of this connected mobile device 120 is unlikely to have granted the request. In this case, the response to the motion status request is negative, for example, "No, it's unlikely that my user granted the request."

[0089] The corrected estimate based on received signal strength and motion sensor data may be calculated in any other suitable manner, for example as a motion-compensated distance or a motion-compensated quality indication. The corrected estimate may directly indicate the probability that a request will be given by a user of connected mobile device 120, or it may be compared to a predetermined value, where the predetermined value is selected to correspond to the method used to calculate the corrected estimate.

[0090] As described above, the corrected estimates may be calculated by each of one or more connected mobile devices 120-122. The corrected estimates may also be calculated by control unit 110 for each of one or more connected mobile devices 120-122.

[0091] operation 205 In response to the motion state request from control unit 110, control unit 110 may receive an indication of the probability, or a corrected estimate. In some embodiments, the received corrected estimate comprises an estimate based on received signal strength data and a motion factor based on motion sensor data. Thus, control unit 110 may calculate the corrected estimate based on the received estimate and the motion factor, for example, by applying the methods described above in connection with the description of operation 204.

[0092] When the control unit 110 receives an indication of a probability from the connected mobile device 120, the control unit 110 may base its decision of whether to arrange to perform an action directly on the received indication of the probability.

[0093] On the other hand, if the control unit 110 receives a corrected estimate from the connected mobile device 120, the control unit may first determine an indication of the probability based on the corrected estimate and then decide whether to arrange to perform an action. The determination of the indication of the probability may be performed as described above in relation to action 204.

[0094] In yet some other embodiments, control unit 110, in response to the motion state request, receives received signal strength data and motion sensor data from connected mobile device 120. Then, determining an indication of the probability that connected mobile device 120 is associated with the event based on the received signal strength and motion sensor data comprises calculating, by control unit 110, a corrected estimate based on the received signal strength data and the motion sensor data.

[0095] However, because the connected mobile device 120 has direct access to both the signal strength data and the motion sensor data, it may be advantageous to have the connected mobile device 120 calculate a corrected estimate, or at least an estimate and a motion coefficient, and then transmit the estimate and motion coefficient, and / or the corrected estimate, and / or an indication of the probability that the connected mobile device 120 is associated with the event, to the control unit 110, which then uses the response from the connected mobile device 120 to decide whether or not to perform an action.

[0096] operation 206 The control unit 110 then decides whether to arrange to perform an action based on an indication of the probability that the connected mobile device 120 is associated with the event.

[0097] Determining whether to arrange for the connected mobile device 120 to perform an action based on an indication of a probability associated with an event may include determining to perform the action if the indication of a probability associated with the event by the connected mobile device 120 satisfies a predetermined condition, such as being greater than a predetermined threshold probability.

[0098] In other embodiments, the control unit 110 determines not to perform the action if the indication of the probability that the connected mobile device 120 is associated with the event does not meet a predetermined condition or if there is no response from the connected mobile device 120 to the motion status request within a time limit.

[0099] Operation 207a The requested action may be performed in response to a decision when the control unit 110 determines whether to arrange to perform the action. For example, the door 111b may be unlocked or unlocked and opened if the control unit determines to perform the action. This may be, for example, when the connected mobile device 120 sends a response to the motion status request, and the response includes an indication that the connected mobile device 120 is likely to be associated with the event. For example, the response may include a corrected estimated time that is less than a certain time limit, such as less than one second.

[0100] On the other hand, if the control unit 110 decides not to perform an action, the control unit 110 may, for example, keep the door 111b locked.

[0101] If the corrected estimate of a connected mobile device indicates that its user granted the request, an action to perform the requested action, e.g., open a door, may be determined. If the corrected estimates of all connected devices indicate that none of the users of the connected devices granted the request, a decision may be made not to perform the requested action, e.g., not to open a door. Because the request may have been granted by a user of a non-connected mobile device, an action may also be determined: to disconnect at least one connection between the mobile device and the control unit 110 to allow another mobile device to connect to the control unit 110. By disconnecting one connection, the mobile device can connect to the control unit 110, allowing the user of the mobile device to trigger the action.

[0102] Operation 207b If it is determined not to perform the action, the method may further include disconnecting the connection between the connected mobile device 120 and the control unit 110, or disconnecting each connection between each of the one or more connected mobile devices 120-122 and the control unit 110. In other words, the control unit 110 may disconnect the connected mobile device 120 from the control unit 110, or disconnect all of the one or more connected mobile devices 120-122 from the control unit 110. Disconnecting the connections, or in other words, disconnecting the connected mobile devices 120-122, may be advantageous in a scenario where the maximum number of connections on the control unit 110 is used by the connected mobile devices 120-122, but none of the users of the connected mobile devices 120-122 have generated an event in the access control system 100. Alternatively, the request may have been given by a user of an unconnected mobile device 123. By disconnecting the connected mobile device 120-122, i.e., by disconnecting the connected mobile device 120-122, the control unit 110 allows other unconnected mobile devices to connect to the control unit 110, and the search for the connected mobile device 120 associated with the event can then continue.

[0103] Next, an embodiment will be briefly described from the perspective of the connected mobile device 120. FIG. 3 presents a flowchart of a method performed by the connected mobile device 120. As described above, the access application of the connected mobile device 120 may execute or arrange for the connected mobile device 120 to perform some of the following operations. In some embodiments, the respective access application arranges a cloud service or web server to perform the following operations. The following operations may refer, for example, to receiving a radio frequency signal transmitted by the access control system 100 used to measure received signal strength, and / or receiving a motion state request from the control unit 110, and / or determining an indication of probability, and / or transmitting the indication of probability and / or a corrected estimate to the control unit 110.

[0104] operation 301 As mentioned above, the connected mobile device 120 receives radio frequency signals transmitted by the access control system 100 which are used to measure the received signal strength.

[0105] operation 302 When an event is generated in the access control system, the connected mobile device 120 receives a motion status request from the control unit 110 .

[0106] operation 303 As mentioned above, the connected mobile device 120 may determine an indication of the probability. This may be done according to the embodiments described above in connection with operation 204. For example, the connected mobile device 120 may calculate a corrected estimate based on received signal strength data and motion sensor data and then determine an indication of the probability based on the corrected estimate. The corrected estimate may be compared to a threshold, such as a threshold time to reach the radio frequency transceiver 112, and a corresponding indication of the probability may be determined based on the comparison with the threshold.

[0107] operation 304 As described above, for example, in connection with operation 205, in some embodiments, when connected mobile device 120 calculates the corrected estimate based on received signal strength data and motion sensor data, connected mobile device 120 sends an indication of the probability and / or the corrected estimate to control unit 110. Connected mobile device 120 sends the indication of the probability and / or the corrected estimate in response to a motion status request received from control unit 110.

[0108] In some other embodiments, connected mobile device 120 transmits received signal strength data and motion sensor data to control unit 110. Control unit 110 then determines an indication of probability based on the received signal strength data and the motion sensor data. Determining an indication of probability by control unit 110 may, in this case, include calculating a corrected estimate based on the received signal strength data and the motion sensor data.

[0109] As mentioned above, there are different alternatives for how the connected mobile device (120) decides whether to arrange to perform an action based on an indication of a probability associated with an event, depending on where the indication of the probability is determined, and also depending on where the corrected estimate is calculated, and also depending on what the response to the motion status request contains.

[0110] For example, if the corrected estimates are calculated by each of one or more connected mobile devices 120-122, the method may further include the following operations shown in FIG.

[0111] Operation 401 In response to the motion status request, each of the one or more connected mobile devices 120-122 may send a response to the control unit 110 based on its corrected estimate.

[0112] To provide a response, connected mobile device 120 may evaluate whether the corrected estimate satisfies a predetermined condition, such as when the resultant value is inversely proportional to the motion sensor data, or when the corrected estimate adjusted by the motion sensor data is less than a predetermined threshold, such as 10 seconds.

[0113] Alternatively, for example, if motion sensor data is provided such that when adjusted by the motion sensor data, the corrected estimate is proportional to the motion sensor data, the predetermined condition may be met when the combined value is greater than a predetermined threshold.

[0114] Each of the connected mobile devices 120-122 may send an acknowledgement to the control unit 110 if its corrected estimate satisfies a predetermined condition.

[0115] Each of the connected mobile devices 120-122 may send a negative response to the control unit 110, or may not send any response, if its corrected estimate does not meet the predetermined condition.

[0116] According to some embodiments herein, the connected mobile device 120 may send an acknowledgement with permission to cause the action. The authorization may be a certificate that the connected mobile device 120 received during an initialization phase indicating that the user of the connected mobile device 120 has the right to access a resource controlled by the control unit 110, e.g., to open a door.

[0117] As already mentioned, in other embodiments, the connected mobile device 120 is already authorized to access the resource when connecting to the control unit 110. Again, authorization may have been received during the initialization phase. In still other embodiments, the control unit 110 performs an authorization verification before performing the requested action according to actions 250, 251, or 243.

[0118] Since only one message is sent, sending an acknowledgment with a grant takes approximately the same time as simply sending an acknowledgment.

[0119] Operation 402 The control unit 110 checks whether any response has been received from one or more of the connected mobile devices 120-122.

[0120] operation 403 If a positive response is received, the control unit 110 arranges to perform the requested action, such as granting access to a physical area, e.g., opening a door, or granting access to the contents of a logical area, a protected device, or a protected resource.

[0121] If the corrected estimates are calculated by the control unit 110, instead of operations 231, 232, and 251, the method may include the following operations shown in FIG.

[0122] operation 501 In response to a status request, the connected mobile device 120 sends its received signal strength data and motion sensor data to the control unit 110 .

[0123] operation 502 The control unit 110 receives received signal strength and motion sensor data sent from one or more connected mobile devices 120-122 and calculates corrected estimates for each of the one or more connected mobile devices 120-122.

[0124] operation 503 The control unit 110 compares each of the corrected estimates with a predetermined threshold value. If the corrected estimates from the connected mobile device 120 satisfy a predetermined condition, the control unit 110 determines that the user of the connected mobile device 120 has granted the request and arranges to perform the requested action, for example granting access to a physical area, such as opening a door, or granting access to the contents of a logical area, a protected device, or a protected resource.

[0125] If no response is received, or only negative responses are received, or all corrected estimates do not satisfy the predetermined condition, the method may further include the following operations.

[0126] operation 504 If no response or a negative response is received from the connected mobile device 120, or if the corrected estimate does not meet a predetermined condition, the control unit 110 may terminate the connection between the connected mobile device 120 and the control unit 110 to allow another mobile device to connect to the control unit 110. Terminating the connection may be advantageous because a request may be provided by an unconnected mobile device 123. By terminating the connection, the unconnected mobile device 123 may connect to the control unit 110, thereby enabling the control unit 110 to verify whether the request to initiate an action is the user of the previously unconnected mobile device 123. Terminating the connection between the connected mobile device 120 and the control unit 110 may mean that the physical radio frequency communication channel between the connected mobile device 120 and the control unit 110, established during the connection process, is dropped, released, or disconnected. The terminology may vary depending on the type of RF communication protocol used.

[0127] In some embodiments, the control unit 110 may terminate any of the connections between the control unit 110 and the connected mobile devices 120-122 based on an absent or negative response from the connected mobile device 120, or if a corrected estimate based on a response from the connected mobile device 120 does not satisfy a predetermined condition. That is, the control unit 110 does not necessarily terminate the connection of the connected mobile device 120 that responded.

[0128] In some other embodiments, the control unit 110 disconnects one or more connections if no response is received from any of the connected mobile devices 120-122, if only negative responses are received, or if each of the corrected estimates does not meet a predetermined condition.

[0129] According to some embodiments herein, disconnecting at least one connection may include disconnecting all of the connected mobile devices 120-122 if no response is received by the control unit 110, if only negative responses are received, or if the corrected estimate does not meet a predetermined condition. Even if positive responses are received and the control unit 110 is to perform an action, all of the mobile devices may be disconnected. In this way, power consumption of these mobile devices is reduced and other devices may be allowed to automatically connect to the control unit 110.

[0130] The disconnection may be initiated by the control unit 110, depending on the circumstances, for example, by allocating the physical radio frequency communication channel to another paired mobile device, for example, by returning the previously connected mobile device 120 to an unconnected state.

[0131] In addition to using motion sensor data to calculate corrected estimates, collected motion sensor data can also be used to determine when a mobile device should automatically connect to the control unit 110 as described above. For example, when a mobile device is stationary, it is assumed that the mobile device is resting on a desk and that its user is not interested in requesting the control unit 110 to perform an action. Therefore, the mobile device does not initiate the process to establish a connection. This conserves the battery life of the mobile device and also prevents available connections from being blocked with unuseful connections. This is important because both the control unit 110 and the mobile device itself may have a limited number of connections. Furthermore, by using received signal strength data and motion sensor data, the mobile device can determine whether to connect to the control unit 110 based on factors related to whether the user of the mobile device is likely to issue a request to the control unit 110 in the near future. This ensures that requested actions are performed quickly, since connection time can be omitted.

[0132] As mentioned above, the control unit 110 may also force the disconnection of at least one of the other connections, or may force the disconnection of all connections that returned a negative response, which may be done in order to open a new standby connection.

[0133] To prevent the ping-pong effect associated with disconnecting and reconnecting, reconnection of a currently disconnected, previously connected mobile device 120 may be prohibited for at least a certain period of time, such as a prohibition or backoff time period. For example, automatic reconnection may be prohibited during the prohibition period. Problems arise in such a scenario. For example, after a forced disconnection of a previously connected mobile device 120, a further request may be provided by the user of the previously connected mobile device 120 to arrange for the control unit 110 to perform an action. For example, the user of the previously connected mobile device 120 provides a command to unlock or open door 111b.

[0134] However, if the control unit 110 is limited to investigating whether to perform an action in response to a further event based on communication with the currently connected mobile device, the above problem not only may prevent a user of a previously connected, now forcibly disconnected mobile device 120 from reconnecting to the control unit 110 in the above manner, but also may result in the control unit 110 being unable to determine that the request was made by the user of the disconnected mobile device, resulting in the control unit 110 not performing the requested action if the request was made by the user of the disconnected mobile device.

[0135] In other words, there may be a back-off time to allow a previously connected mobile device 120 (including its applications) to automatically reconnect to the control unit 110, after which the previously connected mobile device is free to connect again to the control unit 110. However, such a back-off time stops a user of a previously connected mobile device 120 from requesting the control unit 110 to arrange to perform a requested action, e.g., arrange to open a door, within this back-off time.

[0136] Embodiments herein solve the above problem by allowing a previously connected mobile device 120 to reconnect based on an indication of whether a second event has been generated. Specifically, if the indication of whether a second event has been generated indicates that a second event has been generated, the previously connected mobile device 120 is allowed to reconnect during the backoff period. This solution may also include not allowing a previously connected mobile device 120 to reconnect during the backoff period if the indication of whether a second event has been generated indicates that a second event has not been generated.

[0137] The decision whether to allow a reconnection may be made, for example, both by the control unit 110 after receiving a reconnection attempt and by the previously connected mobile device 120 before the reconnection attempt. By having the previously connected mobile device 120 make the decision, fewer failed reconnection attempts will occur.

[0138] To enable the previously connected mobile device 120 to make a decision as to whether to allow the reconnection or not, and to prevent a reconnection attempt from being made when such an attempt should not be made, the control unit 110 may send, e.g., in a broadcast transmission, to the previously connected mobile device 120 an indication of whether a second event was generated or not. This may be implemented, for example, in the form of a value of an event counter.

[0139] Therefore, there is a fail-safe mechanism as described above to prevent the user of a previously connected mobile device 120 from stopping the control unit 110 from arranging to perform a requested action, e.g., arranging to open a door, within the back-off time.

[0140] In some embodiments, the control unit 110 maintains a counter of the number of times the door open command is initiated, and the value of this counter may be transmitted along with the Bluetooth Hello message.

[0141] If a previously connected mobile device 120 is forced to disconnect, it may not reconnect until the open door command counter is incremented, which means not before someone gives the open door command again or when the timer corresponding to the backoff time expires.

[0142] In the following, a method for solving the above problem will be explained in detail with reference to the signaling diagram presented in Figure 5b and with further reference to the access control system 100 shown in Figures 1a and 1b. The signaling diagram of Figure 5b shows a method for handling a radio frequency connection between the control unit 110 of the access control system 100 and the connected mobile device 120.

[0143] The method is illustrated by reference to Bluetooth® terminology, but the method is equally applicable to other radio frequency communication protocols.

[0144] Although the method is described below with respect to a connected mobile device 120, the method may be applied to multiple connected mobile devices 120-122 in parallel or serially.

[0145] As mentioned above, the access control system comprises a control unit 110 connected to one or more mobile devices 120-122 using radio frequency signal communication.

[0146] One or more of the following operations presented in Figure 5b may be performed in the following exemplary order: In other examples, the order may differ from that described below. The method may include the following operations:

[0147] operation 551 At some point, a radio frequency connection is established between the control unit 110 and the connected mobile device 120. In some embodiments herein, the connection is established automatically when the connected mobile device 120 is close enough to the control unit 110 to receive a Hello message.

[0148] operation 552 The control unit 110 can then keep track of the number of events generated so that the control unit 110 can make decisions regarding whether to allow a connected mobile device 120 to reconnect in the future when it becomes disconnected, and to prevent reconnection attempts from being made when such attempts should not be made. The tracking may be performed by an event counter, which may be given an initial value, e.g., zero, at some point.

[0149] operation 553 The control unit 110 may broadcast an indication of whether an event has been generated. For example, the control unit 110 may broadcast a counter value. The counter value may correspond to the number of events that have been generated.

[0150] An indication of whether an event has been generated may be broadcast in a Hello message sent by the control unit 110 using Bluetooth, for example.

[0151] A connected mobile device 120 may receive an indication of whether an event has been generated, for example, by a broadcast transmission from the control unit 110. For example, a connected mobile device 120 may receive a counter value.

[0152] operation 554 When a connected mobile device 120 receives an indication of whether an event has been generated, it may track the number of events generated. For example, the connected mobile device 120 may use the received counter value to start or update its own counter of events.

[0153] operation 555 The control unit 110 obtains an indication of a first event generated in the access control system 100 in response to a first request for the control unit 110 to arrange to perform an action.

[0154] An event generated in the access control system 100 may be the result of a request given by a user of a mobile device 120 of one or more mobile devices 120-123.

[0155] operation 556 The control unit 110 may adjust the counter of the event to a first counter value in response to the first event. Adjusting the counter may include, for example, incrementing the counter. The counter may be incremented by 1 in response to an event such as the first event.

[0156] operation 557 In some embodiments, the connected mobile device 120 obtains an indication of the first event. For example, the control unit 110 may broadcast the first counter value to be received by all mobile devices 120-122, including the connected mobile device 120, within the range of radio frequency communications used by the control unit 110 when communicating with the connected mobile devices 120-123.

[0157] An indication of the first event, such as the first counter value, may be broadcast in a Hello message sent by the control unit 110 using Bluetooth, for example.

[0158] In some embodiments, the indication of the first event includes a first counter value corresponding to the first event.

[0159] operation 558 In response to the first event, the connected mobile device 120 may adjust the event counter to a first counter value.

[0160] operation 559 Then, in response to the occurrence of the first event, the control unit 110 releases the radio connection between the mobile device 120 and the control unit 110. For example, the control unit 110 may release the radio frequency connection between the connected mobile device 120 and the control unit 110 to allow another mobile device to connect to the control unit 110. Release of the connection may be advantageous because a request may be provided by an unconnected mobile device 123. Release of the connection allows the unconnected mobile device 123 to connect to the control unit 110, thereby enabling the control unit 110 to verify whether the request to initiate an action is the user of the previously unconnected mobile device 123. Release of the radio frequency connection between the connected mobile device 120 and the control unit 110 may mean that the physical radio frequency communication channel between the connected mobile device 120 and the control unit 110, which was established during the connection process, is dropped, released, or disconnected. The disconnection may be initiated by the control unit 110, depending on the circumstances, for example, by allocating the physical radio frequency communication channel to another paired mobile device, for example, by returning the previously connected mobile device 120 to an unconnected state.

[0161] The mobile device 120 may be prohibited from reconnecting to the control unit 110 within a predetermined duration of disconnection unless a second event is generated during the predetermined duration.

[0162] In some embodiments herein, the disconnection by the control unit 110 is performed in response to an inability to determine which of one or more connected mobile devices 120-122 is associated with the event.

[0163] In some further embodiments herein, if the number of connected mobile devices is greater than the maximum number of mobile devices allowed to be simultaneously connected to the control unit 110, then the control unit 110 performs a disconnection.

[0164] In some further embodiments herein, the control unit 110 terminates the connection in response to being unable to determine which of one or more connected mobile devices 120-122 is associated with the event when the number of connected mobile devices is greater than the maximum number of mobile devices allowed to simultaneously connect to the control unit 110. That is, the above embodiments may be combined.

[0165] In some embodiments, the control unit 110 can terminate any of the connections, for example one or more of the connections, between the control unit 110 and the connected mobile devices 120-122.

[0166] The control unit 110 may select the radio frequency connection between a connected mobile device 120 and the control unit 122 to be released by selecting the connection to be released from among one or more connections between the control unit 110 and one or more connected mobile devices 120-110 based on which connection was established first.

[0167] In some other embodiments, the at least one connection to be disconnected may be selected based on an analysis of the distance and movement of the connected mobile devices 120-122, such that connected mobile devices that are farther away and / or less moving are disconnected first.

[0168] operation 560a The control unit 110 may start an inhibit timer in response to a disconnection from a previously connected mobile device 120. The inhibit timer may also be referred to as a backoff timer. If the inhibit timer is used and the previously connected mobile device 120 expires, the mobile device 102 is allowed to reconnect, for example, by automatically reconnecting when it is able to communicate with the control unit 110. For example, the previously connected mobile device 120 may be allowed to automatically reconnect upon receiving a Hello message from the control unit 110.

[0169] operation 560b Additionally, a previously connected mobile device 120 may start a prohibit timer in response to a disconnection from the previously connected mobile device 120.

[0170] operation 561 After the control unit 110 releases the connection, the control unit 110 obtains an indication of whether a second event has been generated in the access control system 100 in response to the second request for the control unit 110 to arrange to perform an action. For example, the control unit 110 may obtain an indication that a second event has been generated in the access control system 100 in response to the second request for the control unit 110 to arrange to perform an action. For example, a user of the previously connected mobile device 120 may have given a command to open door 111b at the request receiving unit 113.

[0171] operation 562 In response to a second event, ie, when a second event is generated, the control unit 110 may adjust the counter of the event to a second counter value.

[0172] operation 563 In some embodiments, the previously connected mobile device 120 obtains an indication of the second event. For example, the control unit 110 broadcasts information indicating whether the second event occurred. The control unit 110 may broadcast the indication of whether the second event was generated in response to a second request to arrange for the control unit 110 to perform an action.

[0173] Correspondingly, obtaining an indication of whether the second event was generated may then comprise receiving an indication by previously connected mobile device 120. Thus, the indication of whether the second event was generated may be received in a message broadcast from control unit 110.

[0174] When the indication of the second event includes a counter value corresponding to the second event, broadcasting the indication of whether the second event was generated includes broadcasting the second counter value.

[0175] An indication of the second event, such as a second counter value, may be broadcast in a Hello message sent by the control unit 110 using, for example, Bluetooth.

[0176] operation 564 The previously connected mobile device 120 may adjust the event counter to a second counter value in response to a second event, i.e., if a second event is generated. That is, the previously connected mobile device 120 may adjust the event counter to a second counter value in response to a obtained indication of a second event. For example, the previously connected mobile device 120 may adjust the event counter to a second counter value if it receives a counter value from the control unit 110, such as a second counter value, that differs from a first counter value stored on the previously connected mobile device 120.

[0177] operation 565 In some embodiments, the previously connected mobile device 120 then determines whether to allow the mobile device 120 to reconnect to the control unit 110 based on an indication of whether a second event was generated.

[0178] Determining whether to allow mobile device 120 to reconnect to control unit 110 may include determining whether to send a connection request by mobile device 120. The connection request may be a reconnection request.

[0179] In some embodiments, determining whether to allow the mobile device 120 to reconnect to the control unit 110 is further based on comparing the duration since the disconnection to a predetermined duration since the disconnection. The predetermined period since the disconnection may be, for example, a backoff time or a prohibition time indicating a time during which the previously connected mobile device 120 is prohibited from reconnecting to the control unit 110. The determining may be performed within a predetermined time period. After the predetermined time period has elapsed, the previously connected mobile device 120 is free to reconnect, for example, without regard to an indication of whether a second event was generated.

[0180] The previously connected mobile device 120 determines to allow the mobile device 120 to reconnect to the control unit 110 if the indication of whether a second event has been generated indicates that a second event has been generated.

[0181] When the indication of the second event includes a counter value corresponding to the second event, determining whether to allow the mobile device 120 to reconnect to the control unit 110 includes determining to allow the mobile device 120 to reconnect to the control unit 110 based on the value of the event counter when the value of the event counter is adjusted to the second counter value.

[0182] operation 566 In some embodiments, the control unit 110 receives a connection request from the mobile device 120. The connection request may be received within a predetermined time from the release of the connection.

[0183] operation 567 In some embodiments, the control unit 110 determines whether to allow the mobile device 120 to reconnect to the control unit 110 based on an indication of whether the second event was generated. For example, the control unit 110 may determine whether to allow the mobile device 120 to reconnect to the control unit 110 when it receives a connection request from the mobile device 120. In some embodiments, the previously connected mobile device 120 connects to the control unit 110, and the control unit 110 again forces the mobile device 120 to disconnect.

[0184] In some embodiments, determining whether to allow mobile device 120 to reconnect to control unit 110 is further based on comparing the duration since disconnection to a predetermined duration since disconnection. The determining may be performed within a predetermined time period, which may be the backoff or prohibition time described above. Once the predetermined time period has elapsed, previously connected mobile device 120 is free to reconnect.

[0185] If the indication indicating whether a second event has occurred indicates that a second event has been generated, the control unit 110 determines to allow the mobile device 120 to reconnect to the control unit 110. The second event may have been generated within a predetermined time period.

[0186] When the indication of the second event includes a counter value corresponding to the second event, determining whether to allow the mobile device 120 to reconnect to the control unit 110 includes determining to allow the mobile device 120 to reconnect to the control unit 110 based on the value of the event counter when the value of the event counter is adjusted to the second counter value.

[0187] Enumerated exemplary embodiments of a method for handling a radio frequency connection between the control unit 110 and the mobile device 120 now follow.

[0188] 1. A method for processing a radio frequency connection between a control unit 110 of an access control system 100 and a mobile device 120, comprising: obtaining an indication of a first event generated in the access control system 100 in response to a first request to arrange for the control unit 110 to perform an action; obtaining an indication of whether a second event was generated in the access control system 100 in response to a second request to arrange for the control unit 110 to perform an action after the disconnection by the control unit 110; A method for determining whether to allow the mobile device 120 to reconnect to the control unit 110 based on an indication of whether the second event was generated.

[0189] 2. Determining whether to allow the mobile device 120 to reconnect to the control unit 110 The method of exemplary embodiment 1, comprising determining to allow the mobile device 120 to reconnect to the control unit 110 if the indication of whether the second event has been generated indicates that the second event has been generated.

[0190] 3. The method of exemplary embodiment 1 or 2, wherein the mobile device 120 is prohibited from reconnecting to the control unit 110 within a predetermined duration from the disconnection unless a second event is generated during the predetermined duration.

[0191] 4. The method of any one of exemplary embodiments 1 to 3, further comprising the control unit 110 broadcasting an indication of whether the second event has been generated.

[0192] 5. each representation of the first event and the second event includes a respective counter value corresponding to each event; adjusting an event counter to a first counter value in response to the first event; the control unit 110 broadcasts the first counter value; adjusting the counter to a second counter value if the second event is generated; The method of exemplary embodiment 4, wherein broadcasting the indication of whether the second event has been generated includes broadcasting the second counter value, and determining whether to allow the mobile device 120 to reconnect to the control unit 110 further includes determining, based on the value of the event counter, that the mobile device 120 will be allowed to reconnect to the control unit 110 if the value of the event counter is adjusted to the second counter value.

[0193] 6. The method of any of exemplary embodiments 1 to 5, further comprising receiving a connection request from the mobile device 120 by the control unit 110, and determining whether to allow the mobile device 120 to reconnect to the control unit 110, performed by the control unit 110.

[0194] 7. A method according to any one of exemplary embodiments 1 to 5, wherein obtaining an indication of whether a second event has been generated includes receiving an indication by the mobile device 120, wherein the indication of whether a second event has been generated is received in a message broadcast from the control unit 110, and determining whether to allow the mobile device 120 to reconnect to the control unit 110 includes determining whether to send a connection request by the mobile device 120.

[0195] 8. The method of any of exemplary embodiments 1-7, wherein the disconnection by the control unit 110 is performed in response to an inability to determine which of one or more connected mobile devices 120-122 is associated with the event.

[0196] 9. The method according to any one of exemplary embodiments 1 to 8, wherein the control unit 110 terminates the connection if the number of connected mobile devices is greater than the maximum number of mobile devices allowed to be simultaneously connected to the control unit 110.

[0197] 10. The method according to any of exemplary embodiments 1-9, wherein the event generated in the access control system 100 is the result of a request provided by a user of one of the one or more mobile devices 120-123.

[0198] 11. The method of any of exemplary embodiments 1-10, further comprising: selecting, by the control unit 110, the radio frequency connection between the mobile device 120 and the control unit 110 to be terminated by selecting the connection to be terminated from among one or more connections between the control unit 110 and one or more connected mobile devices 120-122 based on which connection was established first.

[0199] 12. An access control system 100 configured to perform a method according to any one of exemplary embodiments 1 to 11, the access control system 100 including a control unit 110 and a mobile device 120 configured to be connected to the control unit 110 using radio frequency signal communication.

[0200] 13. The access control system 100 of exemplary embodiment 12, wherein the mobile device 120 is any one of a mobile phone, a tablet, a laptop, a key fob, a smart watch, or a smart bracelet, the control unit 110 is any unit that controls access to a physical area, a logical area, a protection device, or a protected resource, and the access control system 100 is configured to generate an event in response to a request from a user of one of the mobile devices 120 requesting access to the content of the physical area, the logical area, the protection device, or the protected resource.

[0201] 14. A computer program 603, 703 comprising computer-readable code units that, when executed on the access control system 100, cause the access control system 100 to perform the method according to any of the exemplary embodiments 1-11.

[0202] 15. A method for processing a radio frequency connection between a control unit 110 of an access control system 100 and a mobile device 120, the method being performed by the control unit 110 of the access control system 100, the method comprising: obtaining an indication of a first event generated in the access control system 100 in response to a first request to arrange for the control unit 110 to perform an action; Disconnecting the radio frequency connection between the mobile device 120 and the control unit 110; The method includes broadcasting an indication of whether a second event has been generated in the access control system 100 in response to a second request to arrange for the control unit 110 to perform an action.

[0203] The method for determining whether to arrange to perform an action in response to a generated event may be implemented in any access control system for access control of a physical area, a logical area, a protected device, a protected resource, etc., such as the access control system 100 shown in Figures 1a and / or 1b. Accordingly, the access control system 100 is configured to determine whether to arrange to perform an action in response to a generated event. Accordingly, the access control system 100 is configured to perform at least the described embodiments by performing corresponding method actions as described above.

[0204] The generated event may be the result of a request issued by a user, requesting the control unit 110 to arrange access to a physical area, a logical area, a protected device, a protected resource, etc. As shown in Figures 1a and 1b, the access control system 110 comprises the control unit 110 and one or more connected mobile devices 120-122. As mentioned above, each of the one or more connected mobile devices 120-122 may be any one of a mobile phone, a tablet, a laptop, a key fob, a smart watch, or a smart bracelet.

[0205] The control unit 110 may be any unit that controls access to a physical domain, a logical domain, a protected device, or a protected resource.

[0206] An embodiment of the control unit 600 will be further described with reference to the schematic block diagram shown in Figure 6, and an embodiment of the connected mobile device 700 will be further described with reference to the schematic block diagram shown in Figure 7. The control unit 600 corresponds to the control unit 110 of Figures 1a and 1b, and the connected mobile device 700 corresponds to the connected mobile device 120 of Figures 1a and 1b.

[0207] The control unit 600 and the connected mobile device 700 may each comprise processing modules 601, 701 such as means for performing the methods described herein, which may be embodied in the form of one or more hardware modules and / or one or more software modules.

[0208] The control unit 600 and the connected mobile device 700 may further comprise a memory 602, 702, respectively. The memory may include, e.g., contain or store, instructions, e.g., in the form of a computer program 603, 703, which may comprise computer readable code units that, when executed on the control unit 600 and / or the connected mobile device 700, cause the control unit 600 and / or the connected mobile device 700 to perform the methods described above.

[0209] According to some embodiments herein, the control unit 600 and / or the connected mobile device 700 and / or the processing module 601, 701 includes a processing circuit 604, 704 as an example hardware module that may include one or more processors. Accordingly, the processing module 601, 701 may be embodied in the form of the processing circuit 604, 704 or "implemented" by the processing circuit 122, 123. Instructions may be executable by the processing circuit 604, 704, thereby causing the control unit 600 and / or the connected mobile device 700 to operate to perform the methods described above. As another example, the instructions, when executed by the control unit 600 and / or the connected mobile device 700 and / or the processing circuit 604, 704, may cause the control unit 600 and / or the connected mobile device 700 to perform the methods described above.

[0210] In view of the above, in one example, the access control system 100, including the control unit 600 and the connected mobile device 700, is provided for determining whether to arrange to perform an action in response to an event generated within the access control system 100. Again, the memory 602, 702 includes instructions executable by the processing circuitry 604, 704, whereby the control unit 600 and / or the connected mobile device 700 is operable to perform the method described above with respect to Figures 2 and 3. The method comprises transmitting, by the radio frequency transceiver 112, a radio frequency signal to be used for measuring received signal strength by one or more connected mobile devices 120-122. The method further comprises sending, by the control unit 110, a motion status request to the connected mobile device 120 of the one or more connected mobile devices 120-122 in response to the generated event.

[0211] The method further comprises determining 204 an indication of a probability that the connected mobile device 120 is associated with the event. Determining the indication of the probability is based on received signal strength data and motion sensor data of the connected mobile device 120. The received signal strength data is based on radio frequency signals measured by the connected mobile device 120 and transmitted during a first predetermined period before the motion status request is received from the control unit 110. The motion sensor data is collected from a motion sensor included in the connected mobile device 120 during a second predetermined period before the motion status request is received from the control unit 110.

[0212] The method further includes determining, by the control unit 110, whether to arrange for the connected mobile device 120 to perform an action based on an indication of the probability associated with the event.

[0213] In some embodiments, the control unit 600 and / or the connected mobile device 700 and / or the processing module 601, 701 may comprise, as exemplary hardware modules, one or more of a transceiver module 631, 731 for RF communication, a determination module 610, 710, and a calculation module 620, 720. In other examples, one or more of the exemplary hardware modules described above may be implemented as one or more software modules.

[0214] According to various embodiments described above, the transceiver module 631 of the control unit 110, 600 is configured to transmit radio frequency signals used to measure received signal strength by one or more connected mobile devices 120-122. The transceiver module 631, 731 may be further configured to transmit and / or receive motion status requests and responses to the motion status requests.

[0215] According to various embodiments described above, the determination module 610, 710 is configured to determine an indication of the probability that the connected mobile device 120, 700 is associated with an event.

[0216] The decision module 610 of the control unit is further configured to decide whether to arrange for the connected mobile device to perform an action based on an indication of the probability associated with the event.

[0217] Additionally, the calculation module 620, 720 may be configured to calculate an estimate indicative of a probability that the connected mobile device 120, 700 is associated with the event based on the received signal strength data, and may be further configured to calculate a corrective motion factor based on the motion sensor data, and to adjust the estimate with the corrective motion factor to obtain a corrected estimate indicative of the probability.

[0218] Furthermore, the processing module 601, 701 may comprise an input / output unit 606, 706. According to an embodiment, the input / output unit 606 of the control unit 600 may comprise a command receiving unit, for example a request receiving unit 113.

[0219] The control unit 600 may further comprise an activation module 630 that may be arranged to perform an action requested by a user of a connected mobile device 120-122. The activation module 630 may, for example, be arranged to unlock the lock 111a of the door 111b in response to a request to unlock the lock 111a.

[0220] The connected mobile device 700 may further include a motion sensor 750 for generating motion sensor data.

[0221] The control unit 600 and / or the connected mobile device 700 and / or the processing module 601, 701 may further comprise one or more of an acquisition module 640, 740 and an adjustment module 660, 760. The acquisition module 640, 740 may acquire an indication of whether an event has occurred. The adjustment module 660, 760 may adjust a counter for the event.

[0222] The decision module 610, 710 may be further configured to determine whether to allow the mobile device 120 to reconnect to the control unit 110 based on an indication of whether the second event was generated.

[0223] In summary, the access control system 100 and the method for determining whether to arrange to perform an action in response to a generated event described above have several advantages. Monitoring the behavior of users of connected mobile devices, making it possible to arrange access for those who actually have the intention to gain access and the correct access rights. Prevents anyone unauthorized from issuing a request on or at the control unit 110, 600, as well as the user of the mobile device from being given access, if the mobile device is near the control unit 110, 600 with an active connection, but the user has not issued a request. The requested access may be arranged in a secure manner: for example, the control unit 110, 600 initiates a verification process when a request is given to the control unit 110, 600 by sending a movement status request to all connected mobile devices and, based on the response, verifies whether the request is given by a user of a connected mobile device who has the intention and right to gain access. It allows monitoring many mobile devices at once and prioritizing them, thus allowing incoming users that exceed the maximum number of current connections to be connected, while inactive users or users that are simply passing through are disconnected, i.e., disconnected. The response time of the control unit 110, 600 following an event that occurs is reduced. This is achieved by connecting the mobile device when it is within range of the control unit 110, 600. If the event is the result of a request, for example in the form of pressing a button on or at the control unit 110, 600 or touching a touchscreen, given by a user of a mobile device that is already connected to the control unit 110, 600, the control unit 110, 120 quickly validates the request and arranges the requested action.

[0224] Where the word "comprise" or "comprising" is used, it shall be taken to mean open-ended, i.e. "consisting of at least".

[0225] The embodiments herein are not limited to the preferred embodiments described above. Various alternatives, modifications, and equivalents may be used. Therefore, the above embodiments should not be construed as limiting the scope of the present invention, which is defined by the appended claims.

Claims

1. A method for determining whether to arrange to perform an action in response to a generated event in an access control system (100), the access control system comprising a control unit (110) connected to a plurality of mobile devices (120-122) using radio frequency signal communication and further comprising a radio frequency transceiver (112), the event indicating a request for the control unit (110) to arrange to perform the action, the method comprising: transmitting (201), by the radio frequency transceiver (112), a radio frequency signal used to measure received signal strength by the plurality of connected mobile devices (120-122); transmitting (203), by the control unit (110) in response to the generated event, to each connected mobile device (120) of the plurality of connected mobile devices (120-122); determining (204), by the control unit (110) or each connected mobile device (120), an indication of a probability that each connected mobile device (120) will be associated with the event, the determining of the indication of probability being based on the received signal strength of each connected mobile device (120). the motion status request is based on received signal strength data and motion sensor data of each connected mobile device (120), the received signal strength data being based on radio frequency signals measured by each connected mobile device (120) and transmitted during a first predetermined time period before the motion status request is received from the control unit (110), and the motion sensor data being collected from a motion sensor (750) included in each connected mobile device (120) during a second predetermined time period before the motion status request is received from the control unit (110), the motion status request serving as a trigger for each connected mobile device (120) to compile the received signal strength data and motion sensor data used to determine an indication of a probability that each connected mobile device (120) is associated with an event; and the control unit (110) determines (206) whether to arrange to perform an action based on the indication of a probability that each connected mobile device (120) is associated with an event, the indication of a probability being determined by:a corrected motion factor based on motion sensor data; adjusting the corrected motion factor to obtain a corrected estimate of the probability; determining whether to arrange to perform an action based on the indication of the probability that the connected mobile device will be associated with the event; and determining to perform the action if the indication of the probability that the connected mobile device will be associated with the event satisfies a predetermined condition, or determining not to perform the action if the indication of the probability that the connected mobile device will be associated with the event does not satisfy the predetermined condition or if a response to the motion status request from the mobile device is not received within a time limit; wherein determining the indication of the probability includes comparing the corrected estimate of the probability that the connected mobile device will be associated with the event to a predetermined threshold value corresponding to the predetermined probability that the connected mobile device will be associated with the event.

2. 2. The method of claim 1, wherein determining the probabilistic indication based on the received signal strength data and the motion sensor data includes calculating, by the connected mobile devices (120), a corrected estimate based on the received signal strength data and the motion sensor data, and further comprising transmitting (304), by each connected mobile device (120) to the control unit (110) the probabilistic indication and / or the corrected estimate in response to a motion status request from the control unit (110).

3. 3. The method of claim 1, further comprising receiving, by the control unit, received signal strength data and motion sensor data from the connected mobile device in response to the motion status request, and wherein determining an indication of the probability that the connected mobile device is associated with the event based on the received signal strength data and the motion sensor data comprises calculating, by the control unit, a corrected estimate based on the received signal strength data and the motion sensor data.

4. 2. The method of claim 1, wherein the corrected estimate corresponds to a corrected estimated time to reach the radio frequency transceiver (112), and calculating the corrected estimated time includes calculating an estimated time for each connected mobile device (120) to reach the radio frequency transceiver (112) based on received signal strength data, calculating a corrective motion factor based on motion sensor data, and adjusting the estimated time by the corrective motion factor to obtain the corrected estimated time.

5. 5. The method of claim 4, wherein the compensation motion factor indicates a measure of a change in the motion of the connected mobile device (120).

6. The method of claim 1 , wherein the motion sensor data includes acceleration data and / or rotational rate data.

7. 2. The method of claim 1, wherein the request for the control unit (110) to arrange to perform an action comprises a request to grant access to a physical domain, a logical domain, a protected device (111a, 111b), or a protected resource, and determining whether to arrange to perform an action in response to the generated event comprises determining whether to grant access to the physical domain, the logical domain, the protected device (111a, 111b), or the protected resource.

8. 2. The method of claim 1, wherein if it is determined not to perform the action, the method further comprises: terminating (207b) the connection between the connected mobile device (120) and the control unit (110); or terminating (207b) a respective connection between each of the plurality of connected mobile devices (120-122) and the control unit (110).

9. 10. The method of claim 1, wherein the event generated in the access control system (100) is the result of a request provided by a user of the mobile device (120).

10. 10. The method of claim 1, wherein the motion status request instructs the connected mobile device (120) to respond with an indication of probability in conjunction with the event.

11. 10. An access control system (100) configured to perform the method of claim 1, comprising: a control unit (110) configured to be connected to a plurality of connected mobile devices (120-122), each one of the plurality of connected mobile devices (120-122) being one of a mobile phone, a tablet, a laptop, a key fob, a smart watch, or a smart bracelet; and the control unit (110) being any unit that controls access to a physical area, a logical area, a protected device, or a protected resource.

Citation Information

Patent Citations

  • A method for controlling access in a system comprising a portable device associated with a user and an access control device

    EP3477600A1

  • Distance-based association

    JP2012044679A

  • Position estimation via proximate fingerprints

    JP2016148682A

  • Electronic key system

    JP2017128926A

  • Multi-sensor passive keyless functionality

    US20200349781A1