Trajectory and Intent Prediction
The trajectory and intent prediction system addresses the challenge of inaccurate user trajectory and intent prediction in access control by using machine learning to generate precise predictions, ensuring secure and efficient activation of intended access devices.
Patent Information
- Application Number
- JP2023535892
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2020-12-14
- Filing Date
- 2021-12-07
- Publication Date
- 2026-01-09
- Estimated Expiration
- 2041-12-07
Smart Images

Figure 0007796749000001 
Figure 0007796749000002 
Figure 0007796749000003
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to trajectory and intent prediction. [Background technology]
[0002] Trajectory prediction plays an important role in many tasks, such as intelligent access control systems. It is generally defined as predicting the position of a mobile agent (e.g., a person, vehicle, or mobile device) at each time step within a given future time interval based on multiple partial trajectories observed over a period of time. Summary of the Invention
[0003] In some aspects, a method is provided, the method comprising: one or more processors receiving observed trajectories of a user and user behavior information about the user; processing the observed trajectories using machine learning techniques to generate a plurality of predicted trajectories, the machine learning techniques being trained to establish relationships between a plurality of training observed trajectories and a plurality of training predicted trajectories; generating the plurality of predicted trajectories; adjusting the plurality of predicted trajectories based on the user behavior information to determine a user's intention to operate a target access control device; determining that the target access control device is within a threshold range of a given predicted trajectory of the plurality of predicted trajectories; and performing processing associated with the target access control device in response to determining that the target access control device is within a threshold range of a given predicted trajectory of the plurality of predicted trajectories.
[0004] In some aspects, the target access control device includes a lock associated with a door, and performing the process includes unlocking the door. In some aspects, the method includes establishing a wireless communication link between a user's mobile device and the target access control device, exchanging authentication information over the wireless communication link, and performing the process after determining that the user is authorized to access the target access control device based on the authentication information.
[0005] In some aspects, the method includes determining, based on the authentication information, that the user is authorized to access the target access control device before performing the operation, and delaying performing the operation after determining that the user is authorized until it is determined that the target access control device is within the threshold range of the given predictive trajectory of the plurality of predictive trajectories.
[0006] In some aspects, the method includes determining, based on the authentication information, that the user is authorized to access the target access control device before performing the operation, and in response to determining that the target access control device is outside the threshold range of the given predictive trajectory of the plurality of predictive trajectories, preventing the operation from being performed after determining that the user is authorized.
[0007] In some aspects, the machine learning technique comprises a conditional variational autoencoder. In some aspects, adjusting the plurality of predicted trajectories based on the user behavior information includes processing the observed trajectory and the user behavior information with the conditional variational autoencoder to generate the plurality of predicted trajectories, each of the plurality of predicted trajectories associated with a respective likelihood indicating the likelihood that the user will move along the corresponding predicted trajectory.
[0008] In some aspects, the machine learning technique comprises a variational autoencoder. In some aspects, adjusting the plurality of predicted trajectories based on the user behavior information includes combining the user behavior information with the plurality of predicted trajectories output by the variational autoencoder, each of the plurality of predicted trajectories being associated with a respective likelihood indicating the likelihood that the user will move along the corresponding predicted trajectory.
[0009] In some aspects, the method includes processing the combined user behavior information and the plurality of predicted trajectories with a second machine learning technique, the second machine learning technique being trained to establish relationships between the plurality of training user behavior information and a plurality of predicted intentions to operate a plurality of access control devices.
[0010] In some aspects, the method further comprises encoding observed trajectories of the user, wherein the machine learning techniques are applied to the encoded observed trajectories of the user. In some aspects, the method includes determining whether the received user behavior information meets minimum parameters for user behavior information.
[0011] In some aspects, the method includes causing the target access control device to perform the process in response to determining that the received user behavior information meets the minimum parameters of the user behavior information.
[0012] In some aspects, the method includes preventing the target access control device from performing the operation in response to determining that the received user behavior information does not meet the minimum parameters of the user behavior information.
[0013] In some aspects, the minimum parameters include threshold amounts of specified types of user behavior information. In some aspects, the method includes generating the user behavior information by encoding a feature vector, wherein generating the user behavior information includes at least one of monitoring the user's physical movements, monitoring the user's stride length, identifying multiple time periods and multiple locations where the user activates multiple different types of access control devices, identifying other client devices and other types of access control devices within range of the user when a given access control device is activated by the user, and identifying other users who are typically within the user's own social network.
[0014] In some aspects, the machine learning technique includes a first machine learning technique, and the method further comprises generating the user behavior information by a second machine learning technique, the second machine learning technique being trained to establish a relationship between training user behavior information and predicted user behavior information; and generating the user intention to operate the target access control device by a third machine learning technique, the third machine learning technique being trained to establish a relationship between training user behavior information associated with a set of trajectories and predicted user intention to operate a plurality of access control devices.
[0015] In some embodiments, each of the first, second, and third machine learning techniques is trained end-to-end. In some aspects, a system is provided, the system comprising one or more processors coupled to a memory including non-transitory computer instructions that, when executed by the one or more processors, cause the system to perform a plurality of processes, the plurality of processes including receiving observed trajectories of a user and user behavior information about the user; processing the observed trajectories with a machine learning technique to generate a plurality of predicted trajectories, the machine learning technique being trained to establish relationships between a plurality of training observed trajectories and a plurality of training predicted trajectories; generating the plurality of predicted trajectories; adjusting the plurality of predicted trajectories based on the user behavior information to determine a user's intent to operate a target access control device; determining that the target access control device is within a threshold range of a given predicted trajectory of the plurality of predicted trajectories; and performing a process associated with the target access control device in response to determining that the target access control device is within a threshold range of a given predicted trajectory of the plurality of predicted trajectories.
[0016] In some aspects, a non-transitory computer-readable medium is provided, the non-transitory computer-readable medium including non-transitory computer-readable instructions for performing a plurality of processes, the plurality of processes including receiving observed trajectories of a user and user behavior information about the user; processing the observed trajectories with a machine learning technique to generate a plurality of predicted trajectories, the machine learning technique being trained to establish relationships between a plurality of training observed trajectories and a plurality of training predicted trajectories; generating the plurality of predicted trajectories; adjusting the plurality of predicted trajectories based on the user behavior information to determine a user's intent to operate a target access control device; determining that the target access control device is within a threshold range of a given predicted trajectory of the plurality of predicted trajectories; and performing a process associated with the target access control device in response to determining that the target access control device is within a threshold range of a given predicted trajectory of the plurality of predicted trajectories. [Brief explanation of the drawings]
[0017] [Figure 1] FIG. 1 is a block diagram of an exemplary access control system, according to some embodiments. [Figure 2] FIG. 2 illustrates an exemplary access control system based on trajectory prediction, according to an exemplary embodiment. [Figure 3A] FIG. 3A is a block diagram of an example trajectory and intent prediction system that may be deployed within the access control system of FIG. 1, according to some embodiments. [Figure 3B] FIG. 3B is a block diagram of an exemplary trajectory and intent prediction system that may be deployed within the access control system of FIG. 1, according to some embodiments. [Figure 3C] FIG. 3C is a block diagram of an exemplary trajectory and intent prediction system that may be deployed within the access control system of FIG. 1, according to some embodiments. [Figure 4]FIG. 4 is an exemplary database that may be located within the systems of FIGS. 1, 2, and 3A-C, according to some embodiments. [Figure 5] FIG. 5 is a flowchart illustrating exemplary processes of an access control system according to an exemplary embodiment. [Figure 6] FIG. 6 is a block diagram illustrating an example software architecture that may be used in conjunction with the various hardware architectures described herein. [Figure 7] FIG. 7 is a block diagram illustrating several components of a machine, in accordance with some illustrative embodiments. DETAILED DESCRIPTION OF THE INVENTION
[0018] Exemplary methods and systems for trajectory and intent prediction-based access control systems (e.g., physical or logical access control systems) are described. In the following description, for purposes of explanation, numerous specific details are set forth in order to provide a thorough understanding of the exemplary embodiments. However, it will be apparent to one skilled in the art that embodiments of the present invention may be practiced without these specific details.
[0019] In a typical access control system, a user carries a physical card or device that contains a set of credentials (e.g., authentication information). Such credentials are exchanged with an access device (e.g., an electronic door lock) when the physical card or device is brought within approximately 20 centimeters of the access device. At that point, the access device determines whether the credentials authorize the user to access the access device, and if so, the access device grants access (e.g., unlocks the door lock). While such systems generally work well, they require the user to be in close proximity to the access device in order to activate it. This can result in variable latency when activating the device, which can be frustrating for the user.
[0020] As mobile devices become commonplace, they can be programmed to hold the same set of credentials as commonly used physical cards. These mobile devices can communicate with access devices over longer distances, such as using the Bluetooth Low Energy (BLE) communication protocol. For example, a mobile device can transmit credentials over a range of up to 100 meters to exchange with an access device. In such cases, the access device can be activated when the user is at a greater distance from the access device than if the user were using a physical card or device. In this way, when the user finally reaches the access device, the access device has already received and authenticated the credentials and granted or denied access to the user. When the user reaches the device, no further action from the user is required to activate the device (e.g., the user does not need to bring a physical card into proximity with the access device).
[0021] However, these other approaches to exchanging credentials via BLE introduce another problem. Namely, when multiple access devices are present within range of the BLE communication protocol, credentials may be exchanged for devices that the user does not intend to activate. For example, there may be multiple electronic door locks within range of a user's mobile device to which the user has credentials to access. However, the user may only intend to unlock or activate one of the multiple electronic door locks. As another example, a user may pass by a given door or access control device that the user is authorized to access, but may not intend to pass through or activate the given door or access control device. In such cases, identifying the user's trajectory can play an important role in determining which of the multiple correct access devices to activate and the user's intention with respect to activating such device.
[0022] A typical trajectory prediction system takes a few steps of an observed trajectory as input and generates several consecutive positions in a future timeline. These typical trajectory prediction systems can provide a set of trajectories predicted to lie within a user's travel path. Most traditional and current methods for future trajectory prediction aim to build a single model that can handle predictions for many users. This approach is very limited because human movement is inherently unique and dynamic. Furthermore, the way one user holds a phone may be very different from the way another user holds a phone. For example, some users prefer to hold their mobile device in their hands. This means that when such users walk, they swing their arms, thereby displacing the mobile device back and forth, resulting in very noisy two-dimensional (2D) or three-dimensional (3D) position coordinates. Other users may have their phone in their front or back pocket. Furthermore, users have different stride lengths based on their height or their general walking preferences. Thus, while typical trajectory prediction systems that rely on user location generally work well to predict multiple future trajectories, they typically do not consider user specificity and therefore lack accuracy requirements, preventing them from being accurately applied in the case of credential exchange and access device control.
[0023] The disclosed embodiments provide an intelligent solution that can accurately predict a user's future locations and determine the user's intent, enabling an access control system to provide a proactive and seamless experience for users while maintaining high security. The disclosed embodiments provide a trajectory prediction system that predicts a user's trajectory based on past and current user behavior information as well. Based on the predicted trajectory or a given set of predicted trajectories and user behavior information, a given access device is activated if it is within range of the trajectory and the user is authorized for access (as determined by a long-range exchange of credentials, such as via BLE). As an example, a given access device (e.g., a door lock) can first communicate with the user's mobile device via a specific communication protocol (e.g., BLE) to exchange authorization data (e.g., credentials). Then, if a given access device is determined to be within the user's predicted trajectory and the user normally accesses or activates that device during the current day / time, or has a preference to activate that device over another device in the user's vicinity, the given access device is commanded to activate (e.g., a door lock is unlocked). In this way, when the user reaches the given access device, the given access device is ready to activate without the user having to bring an access card into proximity with the given access device.
[0024] In some embodiments, disclosed embodiments provide systems and methods for performing long-range access control based on trajectory and intent prediction. According to disclosed embodiments, an observed trajectory of a user and user behavior information about the user are received. The disclosed embodiments process the observed trajectories using machine learning techniques to generate a plurality of predicted trajectories. The machine learning techniques can be trained to establish relationships between the plurality of training observed trajectories and the plurality of training predicted trajectories. The disclosed embodiments adjust the plurality of predicted trajectories based on the user behavior information to determine the user's intent to operate the target access control device. The disclosed embodiments perform processing associated with the target access control device in response to determining that the target access control device is within a threshold range of a given predicted trajectory of the plurality of predicted trajectories.
[0025] 1 is a block diagram illustrating an example system 100 in accordance with various exemplary embodiments. System 100 may be an access control system that includes client devices 120, one or more access control devices 110 that control access to assets or resources protected, such as through lockable doors, and an authentication management system 140 communicatively coupled via a network 130 (e.g., the Internet, BLE, ultra-wideband (UWB) communication protocols, telephone networks).
[0026] Ultra-wideband (UWB) is a radio frequency (RF) technique that uses short, low-power pulses across a wide frequency spectrum. The pulses are on the order of millions of individual pulses per second. The width of the frequency spectrum is typically greater than 500 megahertz, or greater than 20 percent of the arithmetic center frequency.
[0027] UWB can be used for communications, such as by encoding data using time modulation (e.g., pulse position coding), where symbols are designated by pulses in some units of time out of a set of available units of time. Other examples of UWB coding may include amplitude modulation and / or polar modulation. Wideband transmissions tend to be more tolerant of multipath attenuation than carrier-based transmission techniques. Furthermore, because the power of the pulses is weaker at any given frequency, they tend to interfere less with carrier-based communication techniques.
[0028] UWB can be used in radar operations to provide localization with an accuracy of tens of centimeters. Because pulses can vary in absorption and reflection of different frequencies, it can detect both surface and occluded (e.g., covered) features of an object. In some cases, localization provides angle of incidence in addition to range.
[0029] The client device 120 and the multiple access control devices 110 may be communicatively coupled using electronic messages (e.g., packets exchanged over the Internet, BLE, UWB, WiFi direct, or any other protocol). While FIG. 1 depicts a single access control device 110 and a single client device 120, it is understood that in other embodiments, multiple access control devices 110 and multiple client devices 120 may be included in the system 100. As used herein, the term “client device” may refer to any machine that interfaces to a communications network (such as network 130) to exchange credentials with the access control device 110, the authentication management system 140, another client device 120, or any other component to gain access to an asset or resource protected by the access control device 110. The client device 120 may use UWB to obtain location information and calculate the current trajectory of the client device 120.
[0030] In one embodiment, the client device 120 can provide current trajectory information to the authentication management system 140. In some embodiments, the access control device 110 can determine the current trajectory of the client device 120 and provide such information to the authentication management system 140. The client device 120 (alone or in combination with the access control device 110) collects various user behavior information from the user of the client device 120. Such user behavior information can include one or more of the user's physical movements, the user's stride length, the times and locations at which the user activates different types of access control devices 110, and any other client devices or multiple types of access control devices within the user's range when a given access control device is activated by the user. The various user behavior information can be stored and / or collected by the authentication management system 140. In some embodiments, the client device 120 (alone or in combination with the access control device 110) collects this information by monitoring the physical movements of the client device 120 and / or the user's stride length. In some implementations, at least some of the user behavior information is collected by client device 120 (alone or in combination with access control device 110) and / or authentication management system 140. Authentication management system 140 allows users to opt in or out of some or all of the collected user behavior information in order to preserve user privacy.
[0031] In some cases, some or all of the components and functionality of authentication management system 140 may be included on client devices 120 (e.g., any of the machine learning techniques described with respect to authentication management system 140 may be implemented on each client device 120). Any component that performs trajectory and intent prediction in system 100 may be implemented as a standalone component of any one of authentication management system 140, client devices 120, or access control devices 110. The functions of any component that performs trajectory and intent prediction in system 100 may be implemented in a distributed manner across any of authentication management system 140, client devices 120, and / or access control devices 110.
[0032] The authentication management system 140 predicts one or more trajectories using machine learning techniques based on the current trajectory. The authentication management system 140 also receives or obtains user behavior information and adjusts the predicted trajectory or trajectories based on the user behavior information (e.g., the authentication management system 140 concatenates the predicted trajectory with the user behavior information). In some implementations, the authentication management system 140 uses machine learning techniques to calculate a feature vector based on user behavior information associated with the user. In some implementations, the authentication management system 140 applies a machine learning model to the input current trajectory and the input user behavior information to generate predictions of one or more trajectories. Each trajectory may be associated with a specific or given probability that the user will take the path that follows that trajectory. The authentication management system 140 identifies the predicted trajectory with the highest probability. The authentication management system 140 then determines whether a given access control device 110 is within a specified range of the identified predicted trajectory. If so, the authentication management system 140 commands the given access control device 110 to grant access or perform the action; if not, the authentication management system 140 commands the given access control device 110 (which the user is authorized to access) to deny access or not perform the action.
[0033] The client device 120 may be, but is not limited to, a mobile phone, a desktop computer, a laptop, a personal digital assistant (PDA), a smartphone, a wearable device (e.g., a smart watch), a tablet, an ultrabook, a netbook, a laptop, a multiprocessor system, a microprocessor-based or programmable consumer electronics device, or any other communication device that a user may use to access a network.
[0034] The access control device 110 may include an access reading device that is connected to a physical resource (e.g., a door lock mechanism or a back-end server) and controls the physical resource (e.g., a door lock mechanism). The physical resource associated with the access control device 110 may include a door lock, a vehicle ignition system, or any other device that can operate to grant or deny access to a physical component. For example, in the case of a door lock, the access control device 110 may deny access, in which case the door lock remains locked and the door cannot be opened, or the access control device 110 may grant access, in which case the door lock is unlocked and the door can be opened. As another example, in the case of an ignition system, the access control device 110 may deny access, in which case the vehicle ignition system remains disabled and the vehicle cannot be started, or the access control device 110 may grant access, in which case the vehicle ignition is enabled and the vehicle can be started.
[0035] Access control covers a range of systems and methods for managing access, e.g., by people, to secured areas or assets. Access control includes the identification of authorized users or devices (e.g., vehicles, drones, etc.) and the activation of gates, doors, or other equipment used to secure an area, or the activation of control mechanisms, e.g., physical or electronic / software controls, to enable access to secured assets. The access control device 110 forms part of multiple access control systems (PACS), which can include readers (e.g., online or offline readers) that hold authorization data and can determine whether multiple credentials (e.g., from credential devices or key devices, such as cards, fobs, or radio frequency identification (RFID) chips in personal electronic devices such as mobile phones) are authorized for actuators or controls (e.g., door locks, door openers, software controls, turning off alarms, etc.), or can include a host server to which readers and actuators are connected (e.g., via a controller) in a centrally managed configuration. In a centralized configuration, a reader can obtain credentials from a credential or key device and pass those credentials to a PACS host server. The host server then determines whether the credentials grant authorization to access a secured area or asset and commands actuators or other control mechanisms accordingly. While examples of physical access control are used herein, the present disclosure applies equally to logical access control system (LACS) use cases (e.g., logical access to personal electronic devices, passenger identification in transportation services, access and asset control in unmanned checkout stores, etc.).
[0036] For example, wireless PACS utilizing wireless communication between a reader and a credential or key device can use RFID or personal area network (PAN) technologies such as IEEE 802.15.1, Bluetooth, Bluetooth Low Energy (BLE), near field communications (NFC), ZigBee, GSM, CDMA, and Wi-Fi. Many of these technologies have several drawbacks for a seamless user experience. For example, because NFC has a very short range, credential exchange typically does not occur until the user is in close proximity to a secured area or asset and attempts to gain access. The transfer of the credential to the reader and the response by the reader or host server can take several seconds, resulting in user frustration. Furthermore, the user typically must remove the device, for example, from a pocket, and place it at or near the reader to initiate the transaction.
[0037] On the other hand, BLE devices have a range of tens of meters (e.g., 10–20 meters). Therefore, when a user approaches a reader, credential exchange can occur. However, BLE and many other PAN standards do not provide precise physical tracking of devices (e.g., ranging, location, etc.). Therefore, it can be difficult for a reader to determine without further evidence of intent whether the user's intent is to actually access a secured area or asset. For example, it is problematic if an authorized user simply passes a reader in a hallway and a door is unlocked or opened. Evidence of intent may include touching a door handle, gesturing a key device, etc. However, this may not be an ideal user experience compared to simply walking up to a reader and being granted access to a secured area without any further action or interaction on the user's part.
[0038] To address one or more of these or other issues, location estimation technology (e.g., using secure UWB ranging) can be used and combined with PAN discovery and key exchange. UWB location estimation technology can be more accurate than some conventional technologies, achieving accuracy, for example, on the order of tens of centimeters. UWB location estimation technology can provide both the range and direction of a credential or key device relative to a reader. This accuracy far exceeds the approximately 10-meter accuracy of technologies such as BLE when readers are not linked. The precision of UWB can be a useful tool for seamlessly determining a user's intent (e.g., whether the user is attempting to access a secured area or asset or simply passing by) and their current or predicted trajectory. For example, several zones may be defined, e.g., near the reader, at the reader, etc., to understand the user's intent from different perspectives. Additionally or alternatively, tracking accuracy can help provide an accurate model that can identify intent from the user's movement or direction of movement. Thus, the reader can classify the user's movement as, for example, likely approaching the reader or simply walking past.
[0039] When an intent trigger occurs, the reader may act based on the credentials exchanged, for example, via PAN technology. In the case of an offline reader, e.g., a reader not connected to a control panel or host server, the reader may directly control an actuator or other control mechanism (e.g., a lock on an unconnected door). In a centralized PACS, the (online) reader may forward the credentials to a control panel or host server to act upon.
[0040] Generally, the access control device 110 may include one or more of a memory, a processor, one or more antennas, a communication module, a network interface device, a user interface, and a power source or power circuitry.
[0041] The memory of the access control device 110 can be used in connection with the execution of application programming or instructions by the processor of the access control device 110, and for temporary or long-term storage of program instructions or instruction sets and / or credential or authorization data, such as credential data, credential authorization data, or access control data or instructions. For example, the memory can include executable instructions used by the processor to operate other components of the access control device 110 and / or to make access decisions based on the credential or authorization data. The memory of the access control device 110 can include computer-readable media, which can be any medium that can contain, store, communicate, or transfer data, program code, or instructions used by or in connection with the access control device 110. The computer-readable medium can be, for example, but not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device. More specific examples of suitable computer-readable media include, but are not limited to, an electrical connection having one or more wires, or a tangible storage medium such as a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a dynamic RAM (DRAM), any solid-state storage device, a common compact disc read-only memory (CD-ROM), or other optical or magnetic storage device. Computer-readable media should not be confused with, but includes, computer-readable storage media, which is intended to cover all physical, non-transitory, or similar embodiments of computer-readable media.
[0042] The processor of the access control device 110 may correspond to one or more computer processing devices or resources. For example, the processor may be provided as silicon, a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), any other type of integrated circuit (IC) chip, a collection of IC chips, etc. As a more specific example, the processor may be provided as a microprocessor, a central processing unit (CPU), or multiple microprocessors or CPUs configured to execute an instruction set stored in the internal memory and / or memory of the access control device 110. The access control device may also encapsulate multiple sensing devices, with or without antennas.
[0043] The antenna of the access control device 110 may correspond to one or more antennas and may be configured to provide wireless communication between the access control device 110 and a credential or key device (e.g., client device 120). The antenna may be configured to operate using one or more wireless communication protocols and operating frequencies, including, but not limited to, IEEE 802.15.1, Bluetooth, Bluetooth Low Energy (BLE), Near Field Communication (NFC), ZigBee, GSM, CDMA, Wi-Fi, RF, UWB, etc. By way of example, the one or more antennas may be one or more RF antennas and thus capable of transmitting / receiving RF signals over free space that are received / transmitted by a credential or key device having an RF transceiver. In some examples, at least one antenna is an antenna designed or configured to transmit and / or receive UWB signals (referred to herein simply as a “UWB antenna”), such that a reader can communicate with the client device 120 using UWB technology.
[0044] The communication module of the access control device 110 may be configured to communicate with one or more different systems or devices, either remote or local to the access control device 110, such as one or more client devices 120 and / or an authentication management system 140, according to any suitable communication protocol.
[0045] The network interface device of the access control device 110 includes hardware that enables communication with one or more client devices 120 and / or other devices, such as the authentication management system 140, over a communications network, such as the network 130, using any one of several transport protocols (e.g., Frame Relay, Internet Protocol (IP), Transmission Control Protocol (TCP), User Datagram Protocol (UDP), Hypertext Transfer Protocol (HTTP), etc.). Example communications networks may include a local area network (LAN), a wide area network (WAN), a packet data network (e.g., the Internet), a mobile phone network (e.g., a cellular network), a Plain Old Telephone (POTS) network, a wireless data network (e.g., the IEEE 802.11 family of standards known as Wi-Fi®, the IEEE 802.16 family of standards known as WiMax®), the IEEE 802.15.4 family of standards, a peer-to-peer (P2P) network, etc. In some examples, a network interface device may include an Ethernet port or other physical jack, a Wi-Fi card, a network interface card (NIC), a cellular interface (e.g., antennas, filters, and associated circuitry), etc. In some examples, a network interface device may include multiple antennas to communicate wirelessly using at least one of Single-Input Multiple-Output (SIMO), Multiple-Input Multiple-Output (MIMO), or Multiple-Input Single-Output (MISO) techniques.
[0046] The user interface of the access control device 110 may include one or more input devices and / or display devices. Examples of suitable user input devices that may be included in a user interface include, but are not limited to, one or more buttons, a keyboard, a mouse, a touch-sensitive surface, a stylus, a camera, a microphone, etc. Examples of suitable user output devices that may be included in a user interface include, but are not limited to, one or more LEDs, an LED panel, a display screen, a touch screen, one or more lights, a speaker, etc. It should be understood that a user interface may also include combined user input and user output devices, such as a touch-sensitive display, etc.
[0047] Network 130 may include or operate with an ad-hoc network, an intranet, an extranet, a virtual private network (VPN), a local area network (LAN), a wireless network, a wireless LAN (WLAN), a wide area network (WAN), a wireless WAN (WWAN), a metropolitan area network (MAN), BLE, UWB, the Internet, a portion of the Internet, a portion of the public switched telephone network (PSTN), a plain old telephone service (POTS) network, a cellular telephone network, a wireless network, a Wi-Fi network, another type of network, or a combination of two or more such networks. For example, the network or portion of the network may comprise a wireless or cellular network, and the connection may be a code division multiple access (CDMA) connection, a global system for mobile communications (GSM) connection, or other type of cellular or wireless connection. In this example, the coupling may implement any of single-carrier radio transmission technology (1xRTT), Evolutionary Data Optimization (EVDO) technology, General Packet Radio Service (GPRS) technology, Enhanced Data Rates for GSM Evolution (EDGE) technology, Third Generation Partnership Project (3GPP) including 3G, Fourth Generation Wireless (4G) networks, Fifth Generation Wireless (5G) networks, Universal Mobile Telecommunications System (UMTS), High Speed Packet Access (HSPA), Worldwide Interoperability for Microwave Access (WiMAX), Long Term Evolution (LTE) standards, others defined by various standards bodies, other short-range or long-range protocols, various types of data transfer technologies, etc.
[0048] In one example, when client device 120 approaches access control device 110 (e.g., comes within range of a BLE communication protocol), client device 120 transmits its credentials over network 130. In some cases, the credentials may be selected from multiple credentials based on the current geographic location of client device 120. For example, multiple credentials each associated with a different geographic location may be stored on client device 120. When client device 120 comes within a certain distance (e.g., within 10 meters) of a geographic location associated with one of the multiple credentials, client device 120 retrieves the associated credential from local memory.
[0049] In one example, the client device 120 provides the credentials directly to the access control device 110. In such a case, the access control device 110 communicates the credentials with the authentication management system 140. The authentication management system 140 of FIG. 1 includes an authentication system 142 and a trajectory and intent prediction system 144. The authentication management system 140 may further include the components described with respect to FIGS. 6 and 7, such as a processor and a memory storing instructions that, when executed by the processor, cause the processor to control functions of the authentication management system 140.
[0050] The authentication management system 140 searches a list of credentials stored in the authentication system 142 to determine whether the received credential matches multiple credentials from a list of credentials authorized to access a secured asset or resource (e.g., a door or secured area) protected by the access control device 110. In response to determining that the received credential is authorized to access the access control device 110, the authentication management system 140 accesses the trajectory and intent prediction system 144 to determine whether the trajectory of the client device 120 is predicted to be within a specified range (e.g., 2 meters) of the access control device 110 and whether user behavior information indicates the user's intent to follow a given trajectory and / or activate a given access control device 110, as described in more detail below. When the trajectory and intent prediction system 144 indicates to the authentication management system 140 that the client device 120 is predicted to follow a trajectory that is within a specified range of the access control device 110 and that the user behavior information indicates a user intent to access or activate the device 110, the authentication management system 140 instructs the access control device 110 to perform an action to grant access for the client device 120 (e.g., instructing the access control device to unlock a door).
[0051] In another example, the client device 120 provides credentials to the authentication management system 140. The authentication management system 140 searches a list of credentials stored in the authentication system 142 to determine whether the received credentials match credentials from a list of credentials authorized to access a secured asset or resource (e.g., a door or secured area) protected by the access control device 110. In response to determining that the received credentials are authorized to access the access control device 110, the authentication management system 140 accesses the trajectory and intent prediction system 144 to determine whether the trajectory of the client device 120 is predicted to be within a specified range (e.g., 2 meters) of the access control device 110 and whether user behavior information indicates the user's intent to follow a given trajectory and / or activate a given access control device 110, as described in more detail below. When the trajectory and intent prediction system 144 indicates to the authentication management system 140 that the client device 120 is predicted to follow a trajectory that is within a specified range of the access control device 110, and that the user behavior information indicates a user intent to follow a given trajectory and / or operate a given access control device 110, the authentication management system 140 instructs the access control device 110 (associated with the received credentials and within a geographic distance of the client device 120) to perform an action that grants access to the client device 120 (e.g., instructing the access control device to unlock a door).
[0052] In one example, the trajectory and intent prediction system 144 is implemented locally on the access control device 110. In such a case, the access control device 110 locally determines to grant / deny access for the client device 120 based on hard coded range or threshold distance information. In another example, the trajectory and intent prediction system 144 is implemented on the client device 120 and provides the trajectory and intent prediction to the access control device 110. The access control device 110 then determines whether the client device 120 is within a range associated with the access control device 110 and grants / denies access for the client device 120.
[0053] The trajectory and intent prediction system 144 trains one or more machine learning techniques implemented by the authentication management system 140 to predict one or more trajectories for the client device 120 based on the observed trajectory and a set of user behavior information.
[0054] In one embodiment, the trajectory and intent prediction system 144 implements a first machine learning technique that receives a feature vector indicative of a user's current trajectory and adjusts predictions of one or more predicted trajectories based on a set of user behavior information. The predicted trajectories are input to an intent prediction machine learning technique that indicates a prediction as to whether the user intends to activate an access control device within the range of the predicted trajectory.
[0055] In another embodiment, the trajectory and intent prediction system 144 implements a first machine learning technique that receives a feature vector indicative of a user's current trajectory and predicts one or more trajectories based on the current trajectory. The predicted one or more trajectories are combined or otherwise associated with a feature vector indicative of user behavior information. In some cases, the feature vector indicative of user behavior information is determined or provided by another machine learning technique. The predicted trajectory combined with the feature vector indicative of user behavior information is input to an intent prediction machine learning technique that provides a prediction regarding whether the user intends to activate an access control device within the range of the predicted trajectory.
[0056] In another embodiment, the trajectory and intent prediction system 144 implements a first machine learning technique that receives a feature vector indicative of a user's current trajectory and a feature vector indicative of user behavior information and predicts one or more trajectories based on the current trajectory and the feature vector indicative of the user behavior information. In some cases, the predicted one or more trajectories are also linked or otherwise combined with the feature vector indicative of the user behavior information. In some cases, the feature vector indicative of the user behavior information is determined or provided by another machine learning technique. The predicted trajectory linked to the feature vector indicative of the user behavior information is input to an intent prediction machine learning technique that indicates a prediction regarding whether the user intends to activate an access control device within the range of the predicted trajectory.
[0057] To train the machine learning techniques, the trajectory and intent prediction system 144 processes multiple pairs of observed current trajectories and / or user behavior information to be trained and corresponding ground-truth trajectories and user behavior information. The ground-truth trajectories represent multiple subsequent trajectories that follow one or more observed trajectories. For example, the ground-truth trajectories represent a second segment of a trajectory that follows a first segment of a trajectory. The ground-truth user behavior information represents a feature vector that includes a set of features present and / or missing from the input dataset of user behavior information.
[0058] The disclosed machine learning techniques may be implemented by any combination of neural networks, such as long-short-term memory neural networks (LSTMs), autoencoders, variational autoencoders, conditioned variational autoencoders, convolutional neural networks, radial basis networks, deep feedforward networks, recurrent neural networks, gated recurrent units, denoising autoencoders, sparse autoencoders, Markov chains, Hopfield networks, Boltzmann machines, deep belief networks, deep convolutional networks, deconvolutional neural networks, generative adversarial networks, liquid state machines, extreme learning machines, echo state networks, deep residual networks, support vector machines, Korhonen networks, or any combination thereof.
[0059] The trajectory and intent prediction system 144 obtains a specified range of activation or operation of the access control device 110. For example, the trajectory and intent prediction system 144 obtains a unique identifier of the access control device 110 and searches one or more access control device range(s) 430 stored in the database 400 (FIG. 4) to identify and retrieve the range associated with the unique identifier of the access control device 110. Different access control devices 110 or types of access control devices 110 may be associated with different ranges of activation or operation, each stored with its respective unique identifier in one or more access control device range(s) 430. In some instances, the one or more access control device ranges 430 store a device type along with each range. In such situations, the device type, rather than the unique identifier, is used to retrieve the associated range from the one or more access control device ranges 430. The trajectory and intent prediction system 144 determines whether the predicted trajectory falls within a specified range of the access control device 110 and whether the intent prediction indicates the user intent to activate the access control device 110. If so, the trajectory and intent prediction system 144 instructs the authentication management system 140 to wake up or activate the access control device 110 to grant access to the client device 120.
[0060] In another example, the trajectory and intent prediction system 144 is implemented locally on the access control device 110. In such a case, the access control device 110 is hard programmed with a corresponding range of activations (e.g., a range stored in the access control device range 430 for the access control device 110). The trajectory and intent prediction system 144 implemented on the access control device 110 determines whether the predicted trajectory falls within the hard-coded range. If so, the trajectory and intent prediction system 144 causes the access control device 110 to grant access for the client device 120. In another example, the trajectory and intent prediction system 144 is implemented on the client device 120 and provides the trajectory and intent prediction to the access control device 110. The access control device 110 then determines whether the client device 120 is within a range associated with the access control device 110 and grants / denies access for the client device 120.
[0061] In some cases, the trajectory and intent prediction system 144 does not have access to range information, but simply provides a predicted trajectory or set of predicted trajectories to the authentication management system 140, the client device 120, and / or the access control device 110. These devices then collectively or individually make a determination as to whether the predicted trajectory is within a threshold range.
[0062] FIG. 2 illustrates an exemplary access control system 200 based on trajectory and intent prediction, according to an exemplary embodiment. For example, a user 210 may carry a client device 120 (not shown), such as a mobile device or phone. The client device 120 (or the access control device 110) may collect a set of observed 2D and / or 3D coordinates 230. The client device 120 (or the access control device 110) may calculate the user's current trajectory. The client device 120 (alone or in combination with the access control device 110) also collects a set of user behavior information about the user, such as the user's stride length and / or the user's physical movements. The client device 120 (alone or in combination with the access control device 110) may also collect the time periods and locations at which the client device 120 is used to operate various access control devices 110. Using this information, trained machine learning techniques can determine or derive the user's intentions or preferences regarding operating certain access control devices 110. In some cases, the access control device 110 stores identifiers of multiple client devices 120 that operate the access control device 110 and multiple time periods during which various client devices 120 operate the access control device 110. This user behavior information is then aggregated into profiles for each of the client devices 120 to generate user behavior information associated with each client device 120.
[0063] In one example, client device 120 may determine that two access control devices 220 and 222 are within a specified range of client device 120. For example, each of access control devices 220 and 222 is within range of BLE communication with client device 120. In response, client device 120 retrieves credentials for both access control devices 220 and 222 and transmits those credentials to authentication management system 140. Authentication management system 140 determines that client device 120 is authorized to access both access control devices 220 and 222. In response to determining that access is authorized, authentication management system 140 delays granting access to a particular access control device for access control device 220 or 222 until client device 120 is determined to be moving along a predicted trajectory that is within a particular range 250 of the respective access control device 220 or 222.
[0064] In another example, there may be a single access control device 110 that secures access to an area protected by a single access control device 110. In such a case, the user's intent to enter the secured area is determined before instructing the access control device 110 to grant access for a given client device 120. Specifically, a determination is made as to whether the user's predicted trajectory will fall within range of the access control device 110 before instructing the access control device 110 to grant access for the client device 120.
[0065] For example, client device 120 (or access control device 110) provides an observed current trajectory to trajectory and intention prediction system 144. Client device 120 (alone or in combination with access control device 110) also provides user behavior information about a user associated with client device 120. In another example, access control device 110 provides an observed current trajectory to trajectory and intention prediction system 144. Access control device 110 can provide user behavior information about a user associated with client device 120, independently or in combination with client device 120.
[0066] The trajectory and intent prediction system 144 predicts one or more trajectories based on the current trajectory and user behavior information. The trajectory and intent prediction system 144 then identifies a predicted trajectory 240 along which the client device 120 is predicted to travel. In response to determining that the predicted trajectory 240 is within range of the first access control device 220, the trajectory and intent prediction system 144 instructs the authentication management system 140 to cause the first access control device 220 to grant access to the client device 120 (e.g., the first access control device 220 is instructed to perform an action such as unlocking an electronic door lock). In response to determining that the predicted trajectory 240 does not fall within range of the second access control device 222, the trajectory and intent prediction system 144 instructs the authentication management system 140 to cause the second access control device 222 to deny access to the client device 120 (e.g., the second access control device 222 is instructed to remain locked even though multiple credentials of the client device 120 are authorized to access the second access control device 222). In some cases, the predicted trajectory falls within range of both the first and second access control devices 220 and 222. However, the trajectory and intent prediction system 144 predicts (e.g., based on user behavior information) the user's intent to activate the first access control device 220. In such a case, the trajectory and intent prediction system 144 instructs the authentication management system 140 to cause the first access control device 220 to grant access to the client device 120 (e.g., the first access control device 220 is instructed to perform an action such as unlocking an electronic door lock) and to cause the second access control device 222 to deny access to the client device 120.
[0067] 3A-3C are block diagrams of an exemplary trajectory and intent prediction system 144 that may be deployed within the access control system of FIG. 1 , according to some embodiments. Training input 310 includes model parameters 312 and training data 320, which may include paired training data sets 322 (e.g., input-output training pairs) and constraints 326. The model parameters 312 include or provide parameters or coefficients for corresponding machine learning models among the machine learning models. During training, these parameters 312 are adapted based on the input-output training pairs of the training data 320. After the parameters 312 are adapted (post-training), the parameters are used by trained models 360 to run the trained machine learning (ML) models on a new set of data 370.
[0068] The training data 320 includes multiple constraints 326 that may define constraints for a given trajectory and user behavior information. The paired training data 320 may include multiple sets of input-output pairs 322, such as multiple pairs of multiple training observed trajectories and training user behavior information with corresponding multiple training predicted trajectories (ground truth trajectories). The multiple ground truth predicted trajectories represent multiple actual trajectories at one or more future time points following the observed trajectories and a set of user behavior information at multiple earlier time points. For example, the observed trajectory and user behavior measurements may be obtained at a first time point for a first leg of a route. The ground truth predicted trajectory represents the actual observed trajectory at a second time point for a second leg following the first leg.
[0069] Some components of the training input 310 may be stored separately in a different off-site facility or facilities than other components of the training input 310. The paired training data 320 may include multiple pairs of training user behavior information and corresponding training feature vectors of user behavior information (ground truth user behavior information). The paired training data 320 may include multiple pairs of training predicted trajectories associated with the user behavior information and training intents (ground truth intents) to activate the corresponding access control devices. The multiple ground truth intents are generated by collecting information indicating whether a given access device 110 was activated when a trajectory associated with certain user behavior information was observed.
[0070] Training one or more machine learning models 330 trains one or more machine learning techniques based on multiple sets of input-output pairs of paired training data 322. For example, training model 330 may train a first set of ML model parameters 312 by minimizing a loss function based on one or more ground truth measurements. In particular, the first set of ML model parameters 312 may be applied to a training set of observed current trajectories conditioned on a set of user behavior information to estimate a predicted trajectory. In some implementations, a derivative of the loss function is calculated based on a comparison of the estimated predicted trajectories with the ground truth trajectories, and the first set of ML model parameters are updated based on the calculated derivative of the loss function. The first set of ML model parameters may be applied to a first machine learning technique (e.g., a conditioned variational autoencoder) to generate a first prediction given new data 370.
[0071] As another example, training the model 330 may train the second set of ML model parameters 312 by minimizing a loss function based on one or more ground truth measurements. In particular, the second set of ML model parameters 312 may be applied to a training set of observed user behavior information to estimate a feature vector indicative of the user behavior information. In some implementations, a derivative of the loss function is calculated based on a comparison of the estimated user behavior information with the ground truth user behavior information, and the second set of ML model parameters are updated based on the calculated derivative of the loss function. The second set of ML model parameters may be applied to a second machine learning technique (e.g., a neural network) to generate a second prediction given new data 370.
[0072] As another example, the model training 330 may train the third set of ML model parameters 312 by minimizing a loss function based on one or more ground truth measurements. In particular, the second set of ML model parameters 312 may be applied to a training set of user behavior information coupled with multiple predicted trajectories to estimate a predicted intention to operate the access control device. In some implementations, a derivative of the loss function is calculated based on a comparison of the estimated predicted intention to operate the access control device with the ground truth intention to operate the access control device, and the third set of ML model parameters are updated based on the calculated derivative of the loss function. The third set of ML model parameters may be applied to a third machine learning technique (e.g., a neural network) to generate a third prediction given new data 370.
[0073] The first, second, and / or third ML models may all be stored on the same device (e.g., on client device 120, on access control device 110, or centrally on authentication management system 140). In some cases, a particular ML model of the first, second, and / or third ML models may be implemented by a particular device (e.g., on client device 120, on access control device 110, or centrally on authentication management system 140), while another ML model of the first, second, and third ML models is implemented by a different device (e.g., on client device 120, on access control device 110, or centrally on authentication management system 140).
[0074] By minimizing the loss function for the plurality of sets of training data trains, model parameters 312 of the corresponding plurality of ML models are adapted or optimized. In this manner, the ML models are trained to establish relationships between the plurality of training data (e.g., observed trajectories, observed user behavior information, combined trajectories and user behavior information) and the corresponding plurality of predicted training data (e.g., predicted trajectories, predicted user behavior information, predicted intention to operate the access control device).
[0075] In one implementation, these ML models are trained according to supervised learning techniques to estimate trajectories from training observed trajectories and user behavior information. In such cases, to train the ML model, multiple training observed trajectories and user behavior information are retrieved along with their corresponding training predicted or estimated trajectories. For example, the training observed trajectories and user behavior information are retrieved from training data 410 stored in database 400 (FIG. 4). The ML model is applied to a first set of training observed trajectories and user behavior information to estimate a given set of trajectories. The set of training observed trajectories and user behavior information can be used to train the ML model using the same parameters, and can range from a particular training observed trajectory and user behavior information to the full range of training observed trajectories and user behavior information. In some implementations, the output or results of the ML model are used to calculate or predict the first set of predicted trajectories.
[0076] The first set of predicted trajectories is applied to a loss function, and a gradient or derivative of the loss function is calculated based on an expected or ground truth set of predicted trajectories. Updated parameters of the ML model are calculated based on the gradient or derivative of the loss function. For example, the parameters of the ML model are included in the trained machine learning techniques 420 of the database 400. The ML model is then applied to a second set of training observed trajectories and user behavior information using the updated parameters to again estimate a given set of predicted trajectories, and the predicted trajectories are applied to the loss function for comparison with their corresponding ground truth predicted trajectories. The parameters of the ML model are again updated, and this iteration of the training process continues for a specified number of iterations or epochs, or until a given convergence criterion is met.
[0077] After the machine learning model is trained, new data 370 including one or more observed trajectories and user behavior information may be received. The trained machine learning techniques may be applied to the new data 370 to generate generated results 380 including multiple predicted trajectories along with their corresponding likelihoods that the user will follow a path along each respective trajectory.
[0078] 3B shows one implementation 301 of the trajectory and intent prediction system 144 that may be provided within the system of FIG. 1 . An observed trajectory may be received from the client device 120. The observed trajectory is processed by a trajectory encoder 371 to generate a feature vector corresponding to a current trajectory. The feature vector corresponding to the current trajectory is input to a trained trajectory prediction model 361. The trained trajectory prediction model 361 may operate using the first set of model parameters 312 and may implement a conditional variational autoencoder. Any other type of neural network or machine learning technique may similarly be used as the trained trajectory prediction model 361. The trained trajectory prediction model 361 also receives user behavior information from a trained user behavior information model 362. The trained user behavior information model 362 is configured to receive a set of user behavior information (e.g., encoded as a vector) and generate a feature vector indicative of the user behavior information. In one example, the trained trajectory prediction model 361 and the trained user behavior information model 362 are trained end-to-end.
[0079] The trained trajectory prediction model 361 processes the feature vector corresponding to the current trajectory and the feature vector indicative of user behavior information to predict one or more trajectories. The multiple predicted trajectories can be processed by another machine learning technique (not shown) to determine the user's intent to operate an access control device within range of one or more of the one or more trajectories. In response to determining that the user intends to operate an access control device within range of one or more of the one or more trajectories after authorizing the user's credentials to access the access control device within range of the client device 120, the trajectory and intent prediction system 144 commands the access control device within range of the client device 120 to grant access or perform an operation (e.g., unlock a door lock).
[0080] 3C shows one implementation 302 of the trajectory and intention prediction system 144 that may be provided within the system of FIG. 1. Observed trajectories may be received from the client device 120. The observed trajectories are processed by a trajectory encoder 371 to generate a feature vector corresponding to a current trajectory. The feature vector corresponding to the current trajectory is input to a trained trajectory prediction model 361. The trained trajectory prediction model 361 may operate using the first set of model parameters 312 and may implement a variational autoencoder. Any other type of neural network or machine learning technique may similarly be used as the trained trajectory prediction model 361. The trained trajectory prediction model 361 processes the feature vector corresponding to the current trajectory and predicts one or more trajectories. These predicted one or more trajectories are provided to a concatenator 392. In some instances, the trained trajectory prediction model 361 processes the feature vector corresponding to the current trajectory and a feature vector indicative of user behavior information to predict one or more trajectories. These one or more trajectories (predicted based on the current trajectory and a feature vector indicative of user behavior information) are provided to a concatenator 392 .
[0081] The trained user behavior information model 362 is configured to receive a set of user behavior information (e.g., encoded as a vector) and generate a feature vector indicative of the user behavior information. The feature vector indicative of the user behavior information is also provided to the concatenator 392. In some embodiments, the trained user behavior information model 362 may output a result or feature vector that indicates a very low confidence score for the generated result (e.g., the user behavior information does not meet minimum parameters of the user behavior information). This may be the case when an insufficient amount of user behavior information (e.g., less than a threshold amount of specified types of user behavior information, such as the time of day when different types and locations of access devices are activated, the user's stride length, the user's physical movement, whether the user is carrying the client device 120 or has the device in their pocket, the user's identity when the access control device is activated, etc.) has been collected for a given user. In such a situation, multiple predictions and multiple trajectories regarding user intent may be assigned very low probabilities, preventing access to access control devices within range of the client device 120, even if multiple credentials of the client device 120 are authorized to access the access control devices.
[0082] As an example, if a user recently added a new key to an electronic door lock, a training period may need to be performed to generate a feature vector that indicates user behavior with a high level of confidence. Once a feature vector that indicates user behavior with a high level of confidence is achieved, an intent prediction can be provided with a high level of probability, and access control devices within range of the client device 120 may be commanded to be activated (e.g., unlocked) if the client device 120's credentials are authorized to access the access control devices. That is, there may be a training period associated with each new set of credentials or keys added by the user to the client device 120 to access the corresponding access control devices. During this period, the access control devices may only be accessed and activated by the client device 120 using a short-range communication protocol (e.g., NFC), such as within 20 centimeters. After training of the trained user behavior information model 362 is complete for the newly added credentials, the access control devices may be accessed and activated by the client device 120 using a long-range communication protocol (e.g., BLE), such as within 10 meters.
[0083] In one example, the concatenator 392 combines (e.g., adjusts) one or more trajectories (predicted based only on the current trajectory) based on a feature vector indicative of user behavior information. In another example, the concatenator 392 combines (e.g., adjusts) one or more trajectories (predicted based on the current trajectory and based on the feature vector indicative of user behavior information) based on a feature vector indicative of user behavior information. The combined results by the concatenator 392 are provided to the trained intent prediction model 363. The concatenator 392 can be implemented as any device that combines, multiplies, aggregates, sums, and / or generates a single representation from multiple input datasets.
[0084] The trained intent prediction model 363 determines the user's intent to activate an access control device within one or more trajectories of the one or more trajectories. The trained intent prediction model 363 may also be an end-to-end trained neural network. The trained intent prediction model 363 is trained to output a prediction regarding whether the user intends to activate a given access control device within the client device 120 (e.g., based on the set of predicted trajectories as conditioned by a feature vector indicative of user behavior information). The trained intent prediction model 363 may output an intent (e.g., yes or no) regarding whether the user has activated or intends to activate the given access control device, along with a probability indicating the likelihood that the user will activate the access control device. After authorizing the user's credentials to access access control devices within range of the client device 120, in response to determining with a certain probability greater than a threshold probability that the user intends to activate an access control device within range of one or more of the one or more trajectories, the trajectory and intent prediction system 144 commands the access control device within range of the client device 120 to grant access or perform an action (e.g., unlock a door lock).
[0085] In one example, the trained intent prediction model 363 is trained to predict a user's intent to activate an access control device during a certain time of day and when the user is within range of one or more other client devices 120. That is, the trained user behavior information model 362 may provide a time period (e.g., 9:00 AM and 5:00 PM) during which a particular access control device is activated by a user and a set of identifiers of other client devices 120 within a certain range (e.g., 5 meters) of the client device 120 when the access control device is activated. The trained intent prediction model 363 may identify access control devices within the range of the user's predicted trajectory and determine that the current time is within a specified threshold for the 9:00 AM or 5:00 PM time period. In such a case, in conjunction with the social network information included in the user behavior information, the trained intent prediction model 363 also determines whether other client devices having identifiers matching the set of identifiers are within a specified range of the client device 120. If so, the trained intent prediction model 363 may determine that the user has a very high intent to operate the access control device (e.g., 90%) and cause the access device to grant access to the user. The trained intent prediction model 363 may also determine that another access control device within range of the multiple predicted trajectories has a very low intent to be activated by the user (e.g., less than 10%) (e.g., because the user has not activated that device during a particular time period in the past and while within range of a set of identifiers of other client devices 120) and cause the access device to deny access to the user, even though the user has credentials to access or operate the access device.
[0086] In some embodiments, user behavior data is collected over time after one or more of the multiple trained models are implemented in a system including multiple client devices 120. In this case, the user behavior model (e.g., trained user behavior information model 362) and the trajectory model (e.g., trained trajectory prediction model 361) are decoupled. This may be because the user behavior model is not available due to a lack of training data. In this case, only the trajectory model is used to perform trajectory prediction and cause the access device to grant or deny access to the user. In such a situation, the user behavior model includes a classifier that receives user behavior information (e.g., stride length, time of day, preferences, social network information, target door(s)) as input and outputs a probability of the user's intent to access a given access device. This probability is then combined with the trajectory probability to generate a prediction of the user's intent to operate the given access device.
[0087] In some embodiments, the user behavior model receives as input multiple doors or multiple access control devices instead of a single door or access control device. In this case, the user behavior model outputs a probability of the user's intent to activate each of the multiple access control devices. That is, for each access control device, a probability is output indicating the likelihood that the user will activate that access control device. This probability is combined with the trajectory probability to determine the user's intent to access a given one of the multiple access control devices or not access any at all. In some embodiments, the combination of the trajectory and the probability output by the user behavior model is generated as a weighted average of the predictions made by the two models (the trained user behavior information model 362 and the trained trajectory prediction model 361). The weights can be configurable by a system administrator and / or can dynamically change automatically over time as more user behavior data is collected and the model becomes more accurate.
[0088] 5 is a flowchart illustrating an example operation of process 500 of access control system 100, according to an example embodiment. Process 500 may be embodied in computer-readable instructions executed by one or more processors, such that the operations of process 500 may be performed in part or in whole by multiple functional components of system 100, and therefore process 500 is described below by way of example with reference thereto. However, in other embodiments, at least some of the operations of process 500 may be deployed on various other hardware configurations. Some or all of the operations of process 500 may be parallel, out of order, or omitted entirely.
[0089] In operation 501, the authentication management system 140 receives an observed trajectory of a user and user behavior information about the user. For example, the authentication management system 140 receives a current trajectory and a set of user behavior information about the client device 120 (e.g., the user's physical movements, the user's stride length, preferences for accessing specific access devices at specific times of day, the user's social network, such as who the user is around at different times or days of the week, the user's preferences for opening specific doors in a specific order, etc.).
[0090] In operation 502, the identity management system 140 processes the observed trajectories with a machine learning technique to generate a plurality of predicted trajectories, the machine learning technique being trained to establish a relationship between the plurality of training observed trajectories and the plurality of training predicted trajectories. For example, the trained trajectory prediction model 361 processes the current trajectory to generate predictions of one or more trajectories.
[0091] In operation 503, the authentication management system 140 adjusts multiple predicted trajectories based on the user behavior information to determine the user's intent to activate the target access control device. For example, the trained trajectory prediction model 361 processes the current trajectory conditioned on the user behavior information and adjusts the prediction of one or more trajectories.
[0092] In operation 504, the authentication management system 140 determines that the target access control device is within a threshold range of a given predicted trajectory among the plurality of predicted trajectories. For example, the authentication management system 140 determines that the position of the first access control device 220 has a range 250 that is within one or more predicted trajectories.
[0093] In operation 505, the authentication management system 140 performs an action associated with the target access control device in response to determining that the target access control device is within a threshold range of a given predictive trajectory of the plurality of predictive trajectories. For example, the authentication management system 140 instructs the access control device 220 to grant access to the client device 120 (e.g., by unlocking an electronic door lock). In some cases, the authentication management system 140 bypasses the access control device 110 and takes direct control of a locked or secured resource.
[0094] FIG. 6 is a block diagram illustrating an exemplary software architecture 606 that may be used in conjunction with the various hardware architectures described herein. FIG. 6 is a non-limiting example of a software architecture, and it will be understood that many other architectures may be implemented to enable the functionality described herein. The software architecture 606 may execute on hardware such as the machine 700 of FIG. 7 , which includes, among other things, a processor 704, a memory 714, and input / output (I / O) components 718. A representative hardware layer 652 is shown, which may represent, for example, the machine 700 of FIG. 7 . The representative hardware layer 652 includes a processing unit 654 having associated executable instructions 604. The executable instructions 604 represent executable instructions of the software architecture 606, including implementations of the methods, components, etc. described herein. The hardware layer 652 also includes a memory and / or storage device memory / storage 656 that also has the executable instructions 604. The hardware layer 652 may also include other hardware 658. The software architecture 606 may be deployed in any one or more of the components shown in FIG.
[0095] In the example architecture of FIG. 6 , the software architecture 606 can be conceptualized as a stack of layers, with each layer providing specific functionality. For example, the software architecture 606 can include multiple layers, such as an operating system 602, multiple libraries 620, multiple frameworks / middleware 618, multiple applications 616, and a presentation layer 614. In operation, the multiple applications 616 and / or other components within those layers can invoke API calls 608 through the software stack and receive messages 612 in response to the API calls 608. The illustrated multiple layers are representative in nature, and not all software architectures have all layers. For example, some mobile or dedicated operating systems may not provide multiple frameworks / middleware 618, while others may provide such layers. Other software architectures may include additional or different layers.
[0096] The operating system 602 may manage multiple hardware resources and provide multiple common services. The operating system 602 may include, for example, a kernel 622, multiple services 624, and multiple drivers 626. The kernel 622 may act as an abstraction layer between the hardware layer and other software layers. For example, the kernel 622 may be responsible for memory management, processor management (e.g., scheduling), component management, networking, security configuration, etc. The multiple services 624 may provide other common services to the other software layers. The multiple drivers 626 are responsible for controlling or interfacing with basic hardware. For example, the multiple drivers 626 may include a display driver, a camera driver, a BLE driver, a UWB driver, a Bluetooth driver, a flash memory driver, a serial communication driver (e.g., a Universal Serial Bus (USB) driver), a Wi-Fi driver, an audio driver, a power management driver, etc., depending on the hardware configuration.
[0097] Libraries 620 provide a common infrastructure used by application 616 and / or other components and / or layers. Libraries 620 provide functions that allow other software components to perform tasks more easily than by directly interfacing with underlying operating system 602 functions (e.g., kernel 622, services 624, and / or drivers 626). Libraries 620 may include system libraries 644 (e.g., the C standard library), which may provide functions such as memory allocation functions, string manipulation functions, mathematical functions, etc. Additionally, libraries 620 may include API libraries 646, such as a media library (e.g., a library supporting the presentation and manipulation of various media formats such as MPREG4, H.264, MP3, AAC, AMR, JPG, PNG, etc.), a graphics library (e.g., an OpenGL framework, which may be used to render two-dimensional and three-dimensional graphical content on a display), a database library (e.g., SQLite, which may provide various relational database functions), and a web library (e.g., WebKit, which may provide web browsing functions). The libraries 620 may also include a wide variety of other libraries 648 to provide many other APIs to the applications 616 and other software components / devices.
[0098] The frameworks / middleware 618 (sometimes referred to as middleware) provide a higher-level common infrastructure that can be used by the applications 616 and / or other software components / devices. For example, the frameworks / middleware 618 may provide various graphic user interface functionality, high-level resource management, high-level location services, etc. The frameworks / middleware 618 may provide a wide range of other APIs, some of which may be specific to a particular operating system 602 or platform, that can be utilized by the applications 616 and / or other software components / devices.
[0099] The plurality of applications 616 includes built-in applications 638 and / or third-party applications 640. Examples of representative built-in applications 638 may include, but are not limited to, a contacts application, a browser application, a book reader application, a location application, a media application, a messaging application, and / or a game application. The third-party applications 640 may include applications developed using the ANDROID™ or IOS™ software development kit (SDK) by an entity other than the vendor of a particular platform, and may be mobile software running on a mobile operating system such as IOS™, ANDROID™, WINDOWS™ Phone, or other mobile operating systems. The third-party applications 640 may invoke API calls 608 provided by a mobile operating system (such as operating system 602) to enable the functionality described herein.
[0100] Applications 616 may use built-in operating system functionality (e.g., kernel 622, services 624, and / or drivers 626), libraries 620, and frameworks / middleware 618 to create a UI for interacting with users of the system. Alternatively or additionally, in some systems, user interaction may occur through a presentation layer, such as presentation layer 614. In these systems, application / component "logic" can be separated from the aspects of the application / component that interact with the user.
[0101] 7 is a block diagram illustrating components of a machine 700 capable of reading instructions from a machine-readable medium (e.g., a machine-readable storage medium) and performing any one or more of the methodologies described herein, according to some exemplary embodiments. Specifically, FIG. 7 illustrates a schematic diagram of the machine 700 in the exemplary form of a computer system within which instructions 710 (e.g., software, programs, applications, applets, apps, or other executable code) may be executed to cause the machine 700 to perform any one or more of the methodologies discussed herein.
[0102] Thus, the instructions 710 can be used to implement the devices or components described herein. The instructions 710 transform a general, unprogrammed machine 700 into a specific machine 700 programmed to perform the functions described and illustrated in the manner described. In alternative embodiments, the machine 700 may operate as a standalone device or may be coupled (e.g., networked) to other machines. In a networked arrangement, the machine 700 may operate in the capacity of a server or client machine in a server-client network environment, or as a peer machine in a peer-to-peer (or distributed) network environment. The machine 700 may include, but is not limited to, a server computer, a client computer, a personal computer (PC), a tablet computer, a laptop computer, a netbook, an STB, a PDA, an entertainment media system, a mobile phone, a smartphone, a mobile device, a wearable device (e.g., a smart watch), a smart home device (e.g., a smart appliance), other smart devices, a web appliance, a network router, a network switch, a network bridge, or any machine capable of sequentially or otherwise executing the instructions 710 that specify the operations performed by the machine 700. Additionally, although only a single machine 700 is illustrated, the term "machine" is also intended to include a collection of machines that individually or jointly execute instructions 710 to perform any one or more of the methodologies described herein.
[0103] Machine 700 may include processor 704, memory / storage 706, and I / O components 718, which may be configured to communicate with each other via bus 702, etc. In one embodiment, processor 704 (e.g., a central processing unit (CPU), a reduced instruction set computing (RISC) processor, a complex instruction set computing (CISC) processor, a graphics processing unit (GPU), a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a radio frequency integrated circuit (RFIC), another processor, or any suitable combination thereof) may include processor 708 and processor 712, which may execute instructions 710, for example. The term "processor" is intended to include multi-core processor 704, which may include two or more independent processors (sometimes referred to as "cores") capable of simultaneously executing instructions. While FIG. 7 shows multiple processors 704, machine 700 may include a single processor with a single core, a single processor with multiple cores (e.g., a multi-core processor), multiple processors with a single core, multiple processors with multiple cores, or any combination thereof.
[0104] Memory / storage 706 may include memory 714, such as main memory or other memory storage, instructions 710, and a storage unit 716, all of which are accessible to processor 704, such as via bus 702. Storage unit 716 and memory 714 store instructions 710 that embody any one or more of the methods or functions described herein. Also, instructions 710 may reside, completely or partially, within memory 714, within storage unit 716, within at least one of processors 704 (e.g., within a processor's cache memory), or any suitable combination thereof during their execution by machine 700. Thus, memory 714, storage unit 716, and the memory of processor 704 are examples of machine-readable media.
[0105] I / O components 718 may include a wide variety of components for receiving input, providing output, generating output, transmitting information, exchanging information, capturing measurements, etc. The particular I / O components 718 included in a particular machine will depend on the type of machine 700. For example, a portable device such as a mobile phone will likely include a touch input device or other such input mechanism, while a headless server machine will likely not include such a touch input device. It will be understood that I / O components 718 may include many other components not shown in FIG. 7 . I / O components 718 are grouped according to function merely to simplify the following description, and this grouping is in no way limiting. In various embodiments, I / O components 718 may include output components 726 and input components 728. Output components 726 may include visual components (e.g., a display such as a plasma display panel (PDP), light-emitting diode (LED) display, liquid crystal display (LCD), projector, or cathode ray tube (CRT)), auditory components (e.g., speakers), tactile components (e.g., vibration motors, resistive mechanisms), other signal generators, etc. Input components 728 may include alphanumeric input components (e.g., a keyboard, a touchscreen configured to receive alphanumeric input, a photo-optical keyboard, or other alphanumeric input component), point-based input components (e.g., a mouse, touchpad, trackball, joystick, motion sensor, or another pointing device), tactile input components (e.g., physical buttons, a touchscreen that provides the position and / or force of a touch or touch gesture, or other tactile input component), audio input components (e.g., a microphone), etc.
[0106] In further embodiments, the I / O component 718 may include a biometric component 739, a motion component 734, an environmental component 736, or a position component 738, among a wide variety of other components. For example, the biometric component 739 may include components for detecting facial expressions (e.g., hand expressions, facial expressions, vocal expressions, gestures, or eye tracking), measuring biosignals (e.g., blood pressure, heart rate, body temperature, sweat, or brain waves), identifying people (e.g., voice identification, retinal identification, face identification, fingerprint identification, or brainwave-based identification), etc. The motion component 734 may include an acceleration sensor component (e.g., an accelerometer), a gravity sensor component, a rotation sensor component (e.g., a gyroscope), etc. The environmental components 736 may include, for example, a lighting sensor component (e.g., a light meter), a temperature sensor component (e.g., one or more thermometers that detect ambient temperature), a humidity sensor component, a pressure sensor component (e.g., a barometer), an acoustic sensor component (e.g., one or more microphones that detect background noise), a proximity sensor component (e.g., an infrared sensor that detects nearby objects), a gas sensor (e.g., a gas detection sensor that detects concentrations of harmful gases or measures pollutants in the air for safety purposes), or other components that may provide an indication, measurement, or signal corresponding to the surrounding physical environment. The position component 738 may include a location sensor component (e.g., a GPS receiver component), an altitude sensor component (e.g., an altimeter or barometer that detects air pressure from which altitude can be derived), an orientation sensor component (e.g., a magnetometer), etc.
[0107] Communication may be achieved using a wide variety of technologies. I / O component 718 may include a communication component 740 operable to couple machine 700 to network 737 or device 729 via coupling 724 and coupling 722, respectively. For example, communication component 740 may include a network interface component or another suitable device for interfacing with network 737. In further embodiments, communication component 740 may include a wired communication component, a wireless communication component, a cellular communication component, a near-field communication (NFC) component, a Bluetooth® component (e.g., Bluetooth® Low Energy), a Wi-Fi® component, and other communication components that provide communication via other modalities. Device 729 may be another machine or any of a wide variety of peripheral devices (e.g., a peripheral device connected via USB).
[0108] Further, the communications component 740 may detect an identifier or may include a component operable to detect an identifier. For example, the communications component 740 may include a radio frequency identification (RFID) tag reader component, an NFC smart tag detection component, an optical reader component (e.g., an optical sensor for detecting one-dimensional barcodes such as Universal Product Code (UPC) barcodes, multidimensional barcodes such as QR (Quick Response) codes, Aztec codes, Data Matrix, Dataglyph, MaxiCode, PDF417, Ultra Code, UCC RSS-2D barcodes, and other optical codes), or an acoustic detection component (e.g., a microphone for identifying tagged audio signals). Additionally, various information may be derived via the communications component 740, such as location via Internet Protocol (IP) geolocation, location via Wi-Fi signal triangulation, location by detection of NFC beacon signals that may indicate a particular location, etc.
[0109] <Terminology> "Carrier signal" in this context refers to any intangible medium capable of storing, encoding, or carrying transitory or non-transitory instructions for execution by a machine, as well as including digital or analog communication signals or other intangible media for facilitating communication of such instructions. Transitory or non-transitory instructions may be sent or received over a network using any one of a number of well-known transfer protocols using a transmission medium via a network interface device.
[0110] A "client device," in this context, refers to any machine that interfaces with a communications network to obtain resources from one or more server systems or other client devices. A client device may be, but is not limited to, a mobile phone, desktop computer, laptop, PDA, smartphone, tablet, ultrabook, netbook, laptop, multiprocessor system, microprocessor-based or programmable consumer electronics, game console, set-top box, or any other communications device that a user may use to access a network.
[0111] A "communications network" in this context refers to one or more portions of a network, which may be an ad-hoc network, an intranet, an extranet, a virtual private network (VPN), a LAN, a BLE network, a UWB network, a wireless LAN (WLAN), a wide area network (WAN), a wireless WAN (WWAN), a metropolitan area network (MAN), the Internet, a portion of the Internet, a portion of the public switched telephone network (PSTN), a plain old telephone service (POTS) network, a cellular telephone network, a wireless network, a Wi-Fi network, another type of network, or a combination of two or more such networks. For example, a network or portion of a network may comprise a wireless or cellular network, and the connection may be a code division multiple access (CDMA) connection, a global system for mobile communications (GSM) connection, or other type of cellular or wireless connection. In this example, the coupling may implement any of the following: single-carrier radio transmission technology (1xRTT), Evolution-Data Optimized (EVDO) technology, General Packet Radio Service (GPRS) technology, Enhanced Data rates for GSM Evolution (EDGE) technology, Third Generation Partnership Project (3GPP) including 3G, Fourth Generation Wireless Networks (4G), Universal Mobile Telecommunications System (UMTS), High Speed Packet Access (HSPA), Worldwide Interoperability for Microwave Access (WiMAX), Long Term Evolution (LTE) standards, protocols defined by various standards bodies, other long-distance data transfer technologies, various types of data transfer technologies, etc.
[0112] In this context, "machine-readable medium" refers to a component, device, or other tangible medium capable of temporarily or permanently storing instructions and data, and may comprise, but is not limited to, random access memory (RAM), read-only memory (ROM), buffer memory, flash memory, optical media, magnetic media, cache memory, other types of storage (e.g., erasable programmable read-only memory (EEPROM)), and / or any suitable combination thereof. The term "machine-readable medium" should be interpreted to comprise a single medium or multiple media (e.g., centralized or distributed databases or associated caches and servers) capable of storing instructions. The term "machine-readable medium" should also be considered to comprise any medium, or combination of media, capable of storing instructions (e.g., code) for execution by a machine, such that the instructions, when executed by one or more processors of the machine, cause the machine to perform any one or more of the methodologies described herein. Thus, "machine-readable medium" refers to a single storage device or device, as well as a "cloud-based" storage system or storage network comprising multiple storage devices or devices. The term "machine-readable medium" excludes the signal itself.
[0113] A "component" in this context refers to a device, physical entity, or logic with boundaries defined by function or subroutine calls, branch points, application programming interface (API), or other techniques that provide partitioning or modularization of specific processing or control functions. Components can be combined through interfaces with other components to perform machine processing. A component may be a packaged functional hardware unit designed for use with other components and may be part of a program that typically performs specific functions among related functions. A component may constitute either a software component (e.g., code embodied in a machine-readable medium) or a hardware component. A "hardware component" is a tangible unit capable of performing specific operations and may be configured or arranged in a specific physical manner. In various exemplary embodiments, one or more computer systems (e.g., standalone computer systems, client computer systems, or server computer systems) or one or more hardware components of a computer system (e.g., a processor or group of processors) may be configured by software (e.g., an application or application portion) as a hardware component that operates to perform specific operations as described herein.
[0114] A hardware component may also be implemented mechanically, electronically, or any suitable combination thereof. For example, a hardware component may comprise dedicated circuitry or logic permanently configured to perform specific operations. A hardware component may be a special-purpose processor, such as a field-programmable gate array (FPGA) or an ASIC. A hardware component may also comprise programmable logic or circuitry temporarily configured by software to perform specific operations. For example, a hardware component may comprise software executed by a general-purpose processor or another programmable processor. Once configured by such software, the hardware component is no longer a general-purpose processor, as it becomes a specific machine (or a specific component of a machine) uniquely tailored to perform the function for which it was configured. It will be appreciated that the decision to implement a hardware component mechanically, in dedicated permanently configured circuitry, or in temporarily configured circuitry (e.g., configured by software) may be driven by cost and time considerations. Thus, the phrase "hardware component" (or "hardware-implemented component") should be understood to encompass a tangible entity that is physically constructed, permanently configured (e.g., hardwired), or temporarily configured (e.g., programmed) to operate in a particular manner or to perform particular operations described herein. Considering embodiments in which the hardware components are temporarily configured (e.g., programmed), each of the hardware components need not be configured or instantiated at any one instance. For example, if the hardware components consist of a general-purpose processor that is configured by software to be a special-purpose processor, the general-purpose processor may be configured at different times as different special-purpose processors (e.g., with different hardware components).The software may accordingly configure, for example, a particular processor or group of processors to be particular hardware components at one instance of time, while configuring different hardware components at a different instance of time.
[0115] Hardware components can provide information to and receive information from other hardware components. Thus, the described hardware components can be considered to be communicatively coupled. When multiple hardware components exist contemporaneously, communication can be achieved by signal transmission between or among two or more of the hardware components (e.g., via appropriate circuits and buses). In embodiments in which multiple hardware components are configured or instantiated at different times, communication between such hardware components may be achieved, for example, through the storage and retrieval of information in memory structures accessed by the multiple hardware components. For example, a hardware component can not only perform an operation but also store the output of that operation in a communicatively coupled memory device. Another hardware component can then retrieve and process the stored output at a later date by accessing the memory device.
[0116] A hardware component may initiate communication with an input or output device or operate on a resource (e.g., a collection of information). Various operations of the example methods described herein may be performed, at least in part, by one or more processors that are temporarily (e.g., by software) or permanently configured to perform the associated operations. Whether temporarily or permanently configured, such processors may constitute processor-implemented components that operate to perform one or more operations or functions described herein. As used herein, a "processor-implemented component" refers to a hardware component implemented using one or more processors. Similarly, the methods described herein may be at least in part processor-implemented, with a particular processor or processors being an example of hardware. For example, at least some of the operations of a method may be performed by one or more processors or processor-implemented components. Additionally, one or more processors may operate to support execution of the associated operations in a "cloud computing" environment or as "software as a service" (SaaS). For example, at least some of the operations may be performed by a group of computers (as an example of a machine including multiple processors), and these operations may be accessible over a network (e.g., the Internet) and through one or more appropriate interfaces (e.g., APIs). Certain performance of the operations may reside not only within a single machine, but also be distributed among processors deployed across multiple machines. In some exemplary embodiments, the processor or processor-implemented components may be located in a single geographic location (e.g., in a home environment, an office environment, or a server farm). In other exemplary embodiments, the processor or processor-implemented components may be distributed across multiple geographic locations.
[0117] "Processor" in this context means any circuit or virtual circuit (a physical circuit emulated by logic running on an actual processor) that manipulates data values in accordance with control signals (e.g., "commands," "opcodes," "machine code," etc.) as well as generating corresponding output signals that are applied to operate a machine. A processor may be, for example, a CPU, a RISC processor, a CISC processor, a GPU, a DSP, an ASIC, an RFIC, or any combination thereof. A processor may also be a multi-core processor having two or more independent processors (sometimes called "cores") capable of simultaneously executing instructions.
[0118] A "timestamp" in this context refers to a string of characters or coded information that identifies when a particular event occurred, providing, for example, a date and time, sometimes with an accuracy of a fraction of a second.
[0119] Changes and modifications can be made to the disclosed embodiments without departing from the scope of the disclosure. These and other changes or modifications are intended to be included within the scope of the disclosure, as set forth in the following claims.
[0120] Additionally, in the foregoing Detailed Description, it can be seen that various features are grouped together in a single embodiment for the purpose of streamlining the disclosure. This method of disclosure is not to be interpreted as reflecting an intention that the claimed embodiments require more features than are expressly recited in each claim. Rather, as the following claims reflect, inventive subject matter may lie in less than all features of a single disclosed embodiment. Accordingly, the following claims are hereby incorporated into the Detailed Description, with each claim standing on its own as a separate embodiment.
Claims
1. 1. A method comprising: one or more processors receiving an observed trajectory of a user and user behavior information about the user; processing the observed trajectories with a machine learning technique to generate a plurality of predicted trajectories, wherein the machine learning technique is trained to establish a relationship between a plurality of training observed trajectories and a plurality of training predicted trajectories, a first predicted trajectory of the plurality of predicted trajectories representing a first future path taken by the user from the observed trajectories, and a second predicted trajectory of the plurality of predicted trajectories representing a second future path taken by the user from the observed trajectories; adjusting the plurality of predicted trajectories based on user behavior information to determine a user's intent to operate a target access control device; determining that the target access control device is within a threshold range of a given predicted trajectory of the plurality of predicted trajectories; responsive to determining that the target access control device is within a threshold range of a given predicted trajectory of the plurality of predicted trajectories, performing processing associated with the target access control device.
2. the target access control device comprises a lock associated with a door; The method of claim 1 , wherein performing the action includes unlocking the door.
3. establishing a wireless communication link between a user's mobile device and the target access control device; exchanging authentication information over said wireless communication link; The method of claim 2 , further comprising: performing the action after determining that the user is authorized to access the target access control device based on the authentication information.
4. determining, based on the authentication information, that the user is authorized to access the target access control device before performing the operation; 4. The method of claim 3, further comprising delaying performing the action after determining that the user is authorized until the target access control device is determined to be within the threshold range of the given predictive trajectory of the plurality of predictive trajectories.
5. determining, based on the authentication information, that the user is authorized to access the target access control device before performing the operation; 5. The method of claim 3 or 4, further comprising: in response to determining that the target access control device is outside the threshold range for the given predictive trajectory of the plurality of predictive trajectories, preventing the user from performing the operation after determining that the user is authorized.
6. The method of any one of claims 1 to 5, wherein the machine learning technique comprises a conditional variational autoencoder.
7. adjusting the plurality of predicted trajectories based on the user behavior information, processing the observed trajectories and the user behavior information by the conditional variational autoencoder to generate the plurality of predicted trajectories; The method of claim 6 , wherein each of the plurality of predicted trajectories is associated with a respective probability indicating the likelihood that the user will travel along the corresponding predicted trajectory.
8. The method of any one of claims 1 to 7, wherein the machine learning technique comprises a variational autoencoder.
9. adjusting the plurality of predicted trajectories based on the user behavior information, combining the user behavior information with the plurality of predicted trajectories output by the variational autoencoder; The method of claim 8 , wherein each of the plurality of predicted trajectories is associated with a respective probability indicating the likelihood that the user will travel along the corresponding predicted trajectory.
10. processing the combined user behavior information and the plurality of predicted trajectories with a second machine learning technique; 10. The method of claim 8 or 9, wherein the second machine learning technique is trained to establish relationships between a plurality of training user behavior information and a plurality of predicted intentions to operate a plurality of access control devices.
11. encoding the observed trajectory of the user; The method of any one of claims 1 to 10, wherein the machine learning techniques are applied to encoded observed trajectories of the users.
12. The method of any one of claims 1 to 11, further comprising determining whether the received user behavior information meets minimum user behavior information parameters.
13. The method of claim 12 , further comprising causing the target access control device to perform the action in response to determining that the received user behavior information meets the minimum parameters of the user behavior information.
14. 14. The method of claim 12 or 13, further comprising preventing the target access control device from performing the operation in response to determining that the received user behavior information does not meet the minimum parameters of the user behavior information.
15. The method of any one of claims 12 to 14, wherein the minimum parameters comprise a threshold amount of specified types of user behavior information.
16. generating the user behavior information by encoding a feature vector; generating the user behavior information, monitoring the physical movements of said user; monitoring the user's stride length; specifying a plurality of time periods and a plurality of locations where the user will activate different types of access control devices; Identifying other client devices and other types of access control devices within range of a given access control device when the given access control device is activated by the user; 16. The method of any one of claims 1 to 15, comprising at least one of: identifying other users who are typically within the user's own social network.
17. the machine learning techniques include a first machine learning technique; generating the user behavior information by a second machine learning technique, the second machine learning technique being trained to establish a relationship between training user behavior information and predicted user behavior information; 10. The method of claim 1, further comprising: generating the user intention to operate the target access control device by a third machine learning technique, the third machine learning technique being trained to establish a relationship between training user behavior information associated with a set of trajectories and predicted user intentions to operate a plurality of access control devices.
18. 20. The method of claim 17, wherein each of the first, second, and third machine learning techniques is trained end-to-end.
19. 1. A system comprising: one or more processors coupled to a memory containing non-transitory computer instructions; The non-transitory computer instructions, when executed by the one or more processors, cause a plurality of processes to be performed; The plurality of processes include: receiving an observed trajectory of a user and user behavior information about said user; processing the observed trajectories with a machine learning technique to generate a plurality of predicted trajectories, wherein the machine learning technique is trained to establish a relationship between a plurality of training observed trajectories and a plurality of training predicted trajectories, a first predicted trajectory of the plurality of predicted trajectories representing a first future path taken by the user from the observed trajectories, and a second predicted trajectory of the plurality of predicted trajectories representing a second future path taken by the user from the observed trajectories; adjusting the plurality of predicted trajectories based on user behavior information to determine a user's intent to operate a target access control device; determining that the target access control device is within a threshold range of a given predicted trajectory of the plurality of predicted trajectories; performing processing associated with the target access control device in response to determining that the target access control device is within a threshold range of a given predictive trajectory of the plurality of predictive trajectories.
20. 1. A non-transitory computer-readable medium comprising non-transitory computer-readable instructions for performing a plurality of processes, the plurality of processes comprising: receiving an observed trajectory of a user and user behavior information about said user; processing the observed trajectories with a machine learning technique to generate a plurality of predicted trajectories, wherein the machine learning technique is trained to establish a relationship between a plurality of training observed trajectories and a plurality of training predicted trajectories, a first predicted trajectory of the plurality of predicted trajectories representing a first future path taken by the user from the observed trajectories, and a second predicted trajectory of the plurality of predicted trajectories representing a second future path taken by the user from the observed trajectories; adjusting the plurality of predicted trajectories based on user behavior information to determine a user's intent to operate a target access control device; determining that the target access control device is within a threshold range of a given predicted trajectory of the plurality of predicted trajectories; performing processing associated with the target access control device in response to determining that the target access control device is within a threshold range of a given predicted trajectory of the plurality of predicted trajectories.
21. 1. A method comprising: receiving a user observation trajectory for the user; processing the observed trajectories with a machine learning technique to generate a plurality of predicted trajectories, wherein the machine learning technique has been trained to establish relationships between a plurality of training observed trajectories and a plurality of training predicted trajectories; determining whether user behavior information is available; In response to determining that the user behavior information is not available, determining that a target access control device is within a given threshold range of the plurality of predicted trajectories generated based solely on the machine learning techniques; In response to determining that the user behavior information is available, adjusting the plurality of predicted trajectories based on user behavior information to determine a user's intent to operate a target access control device; determining that the target access control device is within a threshold range of a given predicted trajectory of the adjusted plurality of predicted trajectories; responsive to determining that the target access control device is within the threshold range, performing an action associated with the target access control device.
22. 22. The method of claim 21, wherein the user behavior information is output by a classifier that receives a plurality of user behaviors as input and outputs a probability of intent to access a given access control device.
23. 23. The method of claim 21 or 22, wherein the user behavior information is output by a classifier that receives a plurality of access control devices as input and outputs a probability of intent to access a given access control device of the plurality of access control devices.
24. Adjusting the plurality of forecast trajectories includes:
24. The method of claim 21, comprising calculating a weighted average of a prediction of a user's intention to access a given access control device provided by a user behavior classifier model and a prediction of a user's intention to access the given access control device provided by another machine learning technique based on the plurality of predicted trajectories.
Citation Information
Patent Citations
Physical access control systems with localization-based intent detection
US20200314651A1