Physical access control system with intent detection based on location estimation
Patent Information
- Application Number
- JP2025030960
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2019-03-25
- Filing Date
- 2025-02-28
- Publication Date
- 2026-09-14
- Estimated Expiration
- 2040-03-24
Smart Images

Figure 0007920337000001 
Figure 0007920337000002 
Figure 0007920337000003
Abstract
Description
[Technical Field]
[0001] Embodiments described herein generally relate to physical access control systems, and more specifically to physical access control systems having credential position sensing capability. [Background Art]
[0002] Physical access to an area, for example, passing through a doorway, can be controlled by an electronic physical access control system (PACS). A person may have a key card or a mobile device for presenting a credential to the PACS. The environment of a PACS may vary depending on the number of persons that may be permitted access and the number of entry points. For example, a company building may have a single entry point that permits entry access to all employees. Within the building, there may be a plurality of offices and dedicated meeting rooms that permit entry access to selected employees. Another example may be a hotel having many entry points for each room, where only selected individuals can access each room. [Brief Description of the Drawings]
[0003] [Figure 1] 1 illustrates an example of a user interacting with a PACS, according to some embodiments. [Figure 2A] 2 illustrates an example of a key device interacting with a PACS, according to some embodiments. [Figure 2B] 3 illustrates an example of a key device interacting with a PACS, according to some embodiments. [Figure 2C] 4 illustrates an example of a key device interacting with a PACS, according to some embodiments. [Figure 2D] 5 illustrates an example of a key device interacting with a PACS, according to some embodiments. [Figure 3] 6 illustrates an example of a person in direct proximity to three doorways, according to some embodiments. [Figure 4] An example of a person approaching three entrances / exits is shown in several embodiments. [Figure 5] The following flowcharts illustrate methods for restricting access to assets through several embodiments. [Figure 6] The following flowcharts illustrate methods for restricting access to assets using key devices, based on several embodiments. [Figure 7] The following flowcharts illustrate methods for restricting access to assets through several embodiments. [Figure 8] The following flowcharts illustrate methods for restricting access to assets through several embodiments. [Figure 9] The following flowcharts illustrate methods for restricting access to assets through several embodiments. [Figure 10] The following flowcharts illustrate methods for restricting access to assets through several embodiments. [Figure 11] This block diagram shows an example of a machine in which one or more embodiments may be implemented. [Modes for carrying out the invention]
[0004] In drawings that are not necessarily drawn to a consistent scale, similarity numbers indicate similar elements in different drawings. Similarity numbers with different subscripts may represent different examples of similar elements. The drawings generally illustrate, but are not limiting, the various embodiments described herein.
[0005] When people attempt to enter a secure area, they may become frustrated by the slow response of the security access mechanism (e.g., electronically controlled door locks) in unlocking the access point in response to their approach. For example, an employee may pass through a secure access point multiple times a day. Also, some conventional PACS systems require users to physically present their credentials (e.g., card / badge or mobile device) to a wall-mounted reader, which can be inconvenient or cause further unnecessary delays in certain situations, such as when the user's hands are full. Thus, a PACS that can identify users more easily and seamlessly (e.g., authenticate user permission to unlock the secure area) would provide a more user-friendly and preferable experience. Furthermore, users who enter using a PACS can find advantages such as the ability to preemptively verify credentials, such as the PACS unlocking the security access mechanism as the user approaches the access point, in order to determine the user's intent.
[0006] In some cases, the systems and methods described herein can provide a seamless experience by obtaining or receiving credentials from a user without requiring the user to actively present a device containing the credentials (e.g., a card or mobile device). That is, in some cases, the systems and methods described herein may include the automatic transmission of credentials to a reader (e.g., without active input from the user) when the user accesses the reader.
[0007] In some cases, the systems and methods described herein can perform various methods of detecting user intent so that the access point opens not only when a user with legitimate credentials is in a designated vicinity of the access point, but also when it is appropriately determined that an authenticated user intends to pass through the access point. A drawback of performing pre-emptive credential verification is that identifying false positives may lead to unlocking the secure access mechanism when it should not be unlocked (e.g., false intent detection). This is potentially problematic because it allows unauthorized persons to enter. For example, an authorized person may walk down a corridor and pass a secure access point. If the PACS misinterprets the person's approach to the secure access point, the PACS may unlock the secure access mechanism. Even though the person has passed through the door, another person may enter through the secure access point while the secure access mechanism is unlocked.
[0008] Wireless PACS systems have generally utilized wireless communication technologies such as radio frequency identification (RFID) and near-field communication (NFC), as well as personal area network (PAN) technologies such as IEEE 802.15.1 and Bluetooth Low Energy (BLE). These technologies may have drawbacks for seamless user experience and access. For example, the range of NFC is limited, so credential exchange typically does not occur until the user attempts to gain access (e.g., standing in front of a door and holding a key card to a reader). The transfer of credentials to the reader and the response from the host server can take several seconds, resulting in user frustration. Furthermore, users are often required to, for example, remove their key card or access device from their pocket and place it on or near the reader before initiating the process.
[0009] BLE devices have a range of several tens of meters (e.g., 10-20 meters). Therefore, when a user approaches a reader, credential exchange can be performed. PAN standards may feature secure handshakes, encryption, and preferred energy profiles for discovery and data transmission. However, PAN standards do not perform precise physical tracking of the device (e.g., ranging, positioning). Therefore, it can be difficult for a reader to determine, without further evidence, that the user's intention is to actually access a secure area. Further evidence may include touching a doorknob and fiddling with a key device. However, this is still not an ideal user experience compared to simply walking to a reader and obtaining permission to access a secure area.
[0010] Ultra-wideband (UWB) radio communication protocols can be used for communication by encoding data via time modulation (e.g., pulse position coding). In UWB, symbols are specified by pulses emitted in a subset of time units from a set of available time units. Other examples of UWB coding may include amplitude modulation and polarity modulation. Wideband transmission tends to be more resistant to multipath attenuation than carrier-based transmission techniques. Furthermore, because the pulse output is weak at any given frequency, interference with carrier-based communication techniques tends to be reduced.
[0011] UWB can be used in radar applications and can perform localization with accuracy down to tens of centimeters. Because absorption and reflection can vary at different frequencies in pulses, it can detect both surface and occluded (e.g., covered) features of an object. In some cases, localization can provide not only range or distance but also the angle of incidence.
[0012] Physical access control may include, for example, multiple systems and methods for governing people's access to a secure area. Physical access control may include activating gates, doors, or other equipment used to identify authorized users or devices (e.g., vehicles, drones) and secure the area. PACS may include readers (e.g., online or offline readers) that hold authorization data and may be able to determine whether the provided credentials are authorized to control actuators (e.g., door locks, door openers, alarm deactivation). Online readers or systems may include network or internet-connected systems that determine authorization. Offline readers or systems may be self-sufficient systems that do not connect to any external resources. For example, residential PACS may be offline.
[0013] A PACS may include a host server to which readers and actuators are connected (e.g., via a controller) in a centralized management configuration. In a centralized management configuration, readers can obtain credentials from key devices (e.g., cards, fobs, or radio frequency identification (RFID) chips in personal electronic devices such as mobile phones) and pass these credentials to the PACS host server. The host server can determine whether the credentials grant access to a secure area and instruct the actuator accordingly.
[0014] To address the issues associated with intent identification, position estimation techniques (e.g., using secure UWB ranging) can be combined with PAN discovery and key exchange. The key device and reader can coordinate secure ranging using PAN techniques. This may include the reader providing a secret (e.g., a scrambled time stamp (STS)) used to mark ranging messages to prevent impersonation. The key device can provide credentials during the same PAN session while the secret is shared. The reader can decrypt the credentials as it normally would, except that the credentials are cached until an intent trigger occurs, or it may prepare them separately.
[0015] The reader can physically estimate the location of the key device using UWB. In some cases, UWB is activated after the secret has been shared to conserve energy, which may be useful for battery-powered readers or key devices.
[0016] Using UWB to pinpoint the physical location of key devices can be more accurate than other techniques, achieving accuracy down to tens of centimeters, thus providing the distance and direction to the reader. This accuracy surpasses the approximately 10-meter accuracy of PAN when readers are not interconnected. The precision of UWB accuracy allows for obtaining details necessary to determine user intent. For example, several zones may be defined, such as ranges of different distances from the reader, to understand user intent from different perspectives. Furthermore, the tracking accuracy enables a precise model that can identify intent from user movement. Thus, the reader can classify user movement as likely approaching the reader or simply walking past, etc.
[0017] An intent threshold or an intent trigger may be set. When the likelihood of an intent exceeds the intent threshold, the intent trigger can initiate a series of events, such as activating the reader for cached credentials. In the case of an offline reader, the reader can control an actuator (for example, the lock of an unlocked door lock). In a centrally managed PACS, the reader may forward the credential to a host server that operates (for example, sends the credential to a controller for determination, and further activates the door lock as appropriate).
[0018] By implementing the systems and methods described herein, a user's credential can be provided to a reader using a first transmission or exchange with a key device via a communication protocol that has long-range ranging capability or, in some cases, lower accuracy (e.g., BLE, Wi-Fi). These credentials can be stored in a cached location within the reader until and unless it is determined in a second transmission or exchange with the key device via a communication protocol with improved accuracy and precision (e.g., UWB) that the user actually intends to enter the secured area (e.g., open the door where the reader is installed). Once the user's intent is determined, the reader may then release the credential (sometimes referred to as PACS bits) for processing, such as sending the credential to the controller, to determine the user's access permission, or directly unlock the door (e.g., in an offline reader). This two-step authentication sequence can reduce the computation time that may lead to a delay (also referred to as waiting time) in door opening for the user. According to this method, authentication and communication between the reader and the key device have actually already been completed by the time the system determines that the user intends to enter the door and the user has arrived at the door.
[0019] In some embodiments, if an intention trigger does not occur within a certain period of time, or a trigger contrary to the intention occurs, such as moving in a direction away from the reader, the cached credentials may be erased. This may be performed because many credentials may be cached in the reader, however, potentially a smaller subset of the cached credentials may actually be used in the authentication process (e.g., based on an intention predicted later).
[0020] In some examples, for example using an offline reader, when the reader identifies whether a credential permits access to a security-protected area, if it is determined that the credential does not permit access to the security-protected area, the credential is not cached. Also, UWB position estimation may not be activated in some cases.
[0021] In some embodiments, the reader may include continuous authentication of credentials. The persistence may be based on a timeout value. The length of time for which credentials are stored, or the persistence thereof, depends on the timeout value. If the timeout is extremely long, the necessity to re-exchange PAN credentials is reduced.
[0022] For example, suppose the key device is within the PAN range of the reader. The reader can cache the PACS ID (e.g., a 26-bit PACS in legacy systems) read from the credentials provided by the key device. A seed for time-based one-time password (TOTP) technology is generated by the reader and shared with the key device via the PAN. The UWB distance measurement received from the key device includes the TOTP, which the reader verifies. If the UWB distances the key device close enough (within a few meters) to the reader or another target (e.g., the center of a door), the reader sends the cached PACS ID to the host server. The host server triggers the door to open. The reader may then delete the cached PACS ID. Alternatively, if the UWB does not distance the key device after a certain timeout period (e.g., 5 minutes), the TOTP is invalid. The key device must then connect to the reader to obtain a new TOTP. Additionally, PAN authentication may expire after a certain authentication timeout period (for example, several hours).
[0023] When using secure UWB position estimation, all involved readers may require a secure seed or secret for distance measurement, such as an STS, in order for the system to function effectively. For example, several readers may be connected (e.g., via BLE, a mesh network, etc.) to distribute the same secret to all involved readers. This potentially reduces the need to exchange STS between each reader and the key device. Furthermore, this shared exchange can exchange cached PACS IDs (e.g., from one initial reader to which the key device is connected) with all readers. In this way, one credential and STS exchange is required per key device.
[0024] A collaborative PACS, whether centrally managed or offline, can coordinate multiple readers within the PACS using a gateway device. While the gateway is performing credential caching, intent determination, and credential transfer to the host server, or instructing actuators to operate, readers can function as remote radio heads to the gateway. A collaborative PACS enables UWB location determination of key devices using one or more connected readers. In some examples, the gateway can load balance the UWB location estimation process. This can be useful in situations where key devices are densely concentrated, such as in ticketing speed gates.
[0025] In some embodiments, the credentials sent to the reader may include encoded or encrypted information such as SEOS® credentials by HID Global, MIFARE® DESFire® credentials by NXP, or FeliCa® credentials by Sony, stored in a key device. The reader can decode or obtain various information from the credentials received from the key device and provide this information to an access server (e.g., a controller) to determine permission for the user, such as access permission. In some cases, the reader can decode the credentials, obtain access control identification information (e.g., PACS bits) about the user, and send this to the controller to determine whether the user has permission to access the controlled area or system they are attempting to access.
[0026] Figure 1 shows an example 100 of a user interacting with PACS according to several embodiments. The entrance / exit 105 can be secured by an electronic lock controlled via PACS. PACS uses a reader 110 to receive credentials from a user 115 who wishes to enter the entrance / exit 105.
[0027] When user 115 approaches the entrance / exit 105 and the reader 110, the reader communicates with user 115's key device via first wireless communication 120. The first wireless communication 120 may be low-power communication such as BLE. The first wireless communication 120 may have the capability to communicate with the key device over longer distances, but may not be able to perform position estimation and distance measurement of the key device. The reader 110 can receive credentials and other identification information from the key device using the first wireless communication 120. The reader 110 may cache the credentials or transmit the credentials to a PACS verification system that can determine whether user 115 is likely to enter the entrance / exit 105.
[0028] As user 115 continues to approach the entrance / exit 105 and the reader 110, a second wireless communication 125 begins to communicate with user 115's key device. The second wireless communication 125 may be a higher-power and more advanced communication such as UWB. The second wireless communication 125 may include position estimation and ranging to track user 115's movements. The second wireless communication 125 can track user 115 and determine whether user 115's intention is to enter the entrance / exit 105 using factors such as user 115's speed. For example, if user 115 does not intend to enter the entrance / exit 115, their speed may remain constant. Conversely, if user 115 intends to enter the entrance / exit 105, user 115 will slow their pace as they approach the entrance / exit 105 and reach for the doorknob.
[0029] The PACS can use data received from the reader 110 via a second wireless communication 125 to determine the likelihood or probability that user 115 intends to pass through the doorway 105. The determination may be a calculation using the received data, or the received data may be provided to a fixed model or an evolutionary model. If the determined probability of intent exceeds a predetermined threshold, the PACS may unlock the door to allow user 115 to enter the doorway 105 seamlessly. The threshold may vary depending on the accuracy of the probability determination and the level of security required for the doorway 105. For example, a conference room may have a threshold of 50% intent probability because there is no risk even if it is unlocked due to a false positive. However, the threshold for a door in a research lab for new product development may be 90% of the intent probability. Furthermore, the threshold can be changed for each user by associating additional information, such as, but not limited to, access rights and access history, using user credentials available to the system.
[0030] Figures 2A to 2D show examples 200 of key devices interacting with a PACS according to several embodiments. The PACS example 200 includes an access point 205 secured by a reader 210 and a lock 215. The reader includes a cache 220 that stores credentials and other data received from the key device. The reader 210 communicates with an access control unit 225. The access control unit 225 may be a server connected to a local internal network. The access control unit 225 may be a remote system connected via the Internet to manage access to multiple locations.
[0031] In Figure 2A, key devices A230, B235, and C240 are within the BLE range (as an example of low-energy wireless communication) of the reader 210. When establishing a connection with the reader 210, each of key devices A230, B235, and C240 provides credentials to the reader 210.
[0032] In Figure 2B, the reader 210 can perform preliminary authentication of credentials. For example, the reader 210 may include a blacklist or whitelist to make an immediate decision regarding the tracking of key devices. Using UWB for ranging and position estimation provides additional information about the movement of key devices, but at the same time requires more energy. Therefore, it may be advantageous if a determination is made as to whether or not to track the key device. In Example 200 of Figure 2B, the reader 210 determines that key device B235 does not have the credentials to access entrance / exit 205. Therefore, since key device B235 is not permitted to access entrance / exit 205, the reader 210 does not rangefinder key device B235 using UWB.
[0033] In some embodiments, the reader 210 can transmit credentials to the access control unit 225 for authorization. If the access control unit 225 determines that the credentials associated with the key device grant access to the entrance / exit 205 associated with the reader 210, the access control unit 225 can provide the reader 210 with a token for those credentials. The reader 210 can store each token along with each credential. Similarly, in this embodiment, if the reader 210 does not receive a token, the credentials are deleted and the key device, such as the key device B235, is not tracked.
[0034] In some embodiments, the reader 210 can cache the credentials initially received via BLE. The reader 210 can retain the credentials in the cache until a distance measurement using UWB occurs. When the key device enters a certain range, the reader 210 can release the credentials for authentication by the access control unit 225 or the authentication server.
[0035] In Figure 2C, key devices A230 and C240 are closer to the reader 210, allowing UWB to be used for communication. UWB enables position estimation or distance measurement. Position information of key devices A230 and C240 is provided to the reader 210. This position information can be used to determine the user's intention regarding each key device. Position information can be derived from UWB by performing distance detection, etc.
[0036] In Figure 2D, key devices A230 and C240 continue to move, and their respective positional information is provided to the reader 210 via UWB communication. Key device C240 is moving away from the reader 210, and therefore it is determined that key device C240 has little intention to enter the entrance / exit 205. The reader 210 can continue to track key device C240 until it moves out of range. The reader 210 may have high battery and hardware sensitivity to monitor power and processing usage. This may include immediately deleting credentials from the cache when it is determined that the credentials are no longer needed, such as when the intention falls below a certain threshold. Managing credentials stored in the cache based on the trustworthiness or intent of the person accessing the entry point may be essential for a PACS managing a set of entry gates, such as a row of revolving gates. This type of entry point may receive a large number of credentials at a given time, such as an entry point to a subway or sports arena.
[0037] The key device A230 is continuously approaching the entrance / exit 205, and therefore the intention of the key device A230 to access the entrance / exit 205 is high. The reader 210 can release the token of the key device A230 to the access control unit 225. Upon receiving the token, the access control unit 225 sends an unlock command to the door lock 215, allowing the person holding the key device A230 to easily and without delay enter the entrance / exit 205. If no token is provided, the reader can send the credentials of the key device A230 to the access control unit 225 to unlock the door lock 215. In the case of an offline system, the reader 210 can directly control the door lock 215 and send an unlock command directly to the door lock 215.
[0038] Many factors can be used to determine when the reader 210 should send a release to the access control unit 225, such as when a token is sent. If the entrance / exit 205 is in a secure area, the intent or probability of accessing the entrance / exit 205 must be extremely high, and therefore a high threshold must be set to prevent the entrance / exit 205 from being opened unintentionally. Other factors, such as the frequency with which people access the entrance / exit 205, or known situational data, such as a meeting about to start in the room containing the entrance / exit 205, may contribute to determining the intent threshold.
[0039] For security purposes, the reader 210 can generate a session key for communication with a key device such as the key device A230. For example, both the reader 210 and the key device A230 may have counters. These counters can be hashed as part of the session key. To track the movement of the key device A230, the reader 210 continuously communicates with the key device A230 to determine the distance. With each communication, the reader 210 or the key device A230 can increment the count value of its respective hashed counter. The session key is therefore changed with each communication to prevent malicious attacks, while the reader 210 and the key device A230 can communicate continuously because they can each recognize the correct content of the count and decrypt the hash.
[0040] Identifying the intent of a person attempting to enter an entrance can be used to facilitate the process of authenticating credentials and unlocking the entrance, so that the person is guided in a seamless and uninterrupted manner. The above explanation focused on identifying intent for a single entrance. As seen in the examples in Figures 3 and 4, identifying intent becomes difficult when there are multiple entrances and multiple readers.
[0041] Figure 3 shows an example 300 of a person 335 directly approaching three entrances / exits according to several embodiments. Person 335 can approach a pair of entrances / exits directly in front of them. It would be difficult for each reader 310, reader 320, and reader 330 to identify which entrance / exit 305, entrance / exit 315, and entrance / exit 325 person 335 intends to enter. For example, if readers 310, reader 320, and reader 330 only use distance measurement, person 335 will be within the same relative range from the readers. By identifying the position of person 335 and continuously estimating the position of person 335 (via their key device), the direction of movement of person 335 may be obtained. The reader can use the determined direction to identify the arrival angle 340. The arrival angle 340 can be used to determine which of the multiple entrances / exits the person 335 intends to enter.
[0042] Figure 4 shows an embodiment 400 of a person 435 approaching three entrances / exits according to several embodiments. Person 435 can approach a pair of entrances / exits lined up on one side of person 435, as if person 435 were walking down a corridor in an office building. For each of entrances / exits 405, 415, and 425, it would be difficult for each reader 410, reader 420, and reader 430 to identify which entrance 335 person 335 intends to enter. Even if person 435 is at different distances from each of readers 410, reader 420, and reader 430, person 435 may stop at any of the entrances / exits.
[0043] When person 435 moves down the corridor and passes a reader, for example, when they pass reader 430 in example 400, entrance 425 can be immediately excluded from a set of entrances that may have been intended to be entered. This frees up the cache of reader 430 and changes the probability that person 435 intended to enter entrance 405 or entrance 415.
[0044] PACS can attempt to monitor the movement speed of person 435. In such situations, a person's movement speed is relatively constant until just before arriving at their intended exit, at which point their pace may decrease. This type of movement information can be used to identify the intended exit. A neural network can be trained using movement data that shows how a person moves down a corridor and how their movement changes with respect to the exit they enter. The neural network can identify the intended exit by using PACS in combination with position data provided by a reader via UWB.
[0045] In Example 400, the PACS can use contextual data to identify the intended exit. For example, the PACS can access the company's calendar system. The PACS can identify that a meeting will soon begin in the room corresponding to exit 415. Therefore, while it is not possible to determine the intended exit of person 435 solely by movement, the PACS can use the calendar to determine that person 435's intention is to enter exit 415. The accuracy of the intention can be further improved by the PACS accessing the people invited to the meeting and matching person 435's attributes (from their key device) against the list of invitees.
[0046] Another scenario in this example is when the entrances 405, 415, and 425, each equipped with readers 410, 420, and 430, are located in a hotel corridor. Identifying a visitor's intent would not be easy, as the visitor is likely to have credentials corresponding to only one entrance. Therefore, as a visitor walks down the hotel corridor, the PACS can predict the visitor's intent, even before the visitor enters the reader area of their room, because the PACS can identify that the visitor has access credentials to only one entrance / room.
[0047] PACS can access communication systems such as email, instant messaging, and short message service (SMS) that can provide information used to determine which entrance / exit a person intends to enter. For example, if John sends Bob an instant message asking him to meet in lab B, when Bob approaches an entrance / exit to the lab, PACS can recognize that Bob intends to enter lab B at John's request.
[0048] Different types of entrances or entry points may vary in how intent is used and when the reader transmits a release to the access control system. For example, an entry point may be a revolving gate, and if there is a long queue for the revolving gate, the identification of the intended revolving gate may not occur until the person enters the revolving gate. Types of entrances or entry points may include manual locks, automatic locks, manual doors, automatic doors, revolving gates, transfer speed gates, parking gates, or elevators.
[0049] The timing of credential release and door unlocking may be determined by data received via ranging and position estimation performed by the UWB. Intent may vary depending on the radius of the distance from the reader. Different entry environments may alter the timing described above. For example, in an open office space with multiple secure doorways, the key device may wait until it reaches a specific doorway before releasing the credentials, as the presence of multiple secure doorways makes it impossible to determine the intent with a sufficiently high probability. Conversely, if there are no other doors for the person to access, the front door lock of a house may unlock well before the person arrives at the front door.
[0050] The key device may be a mobile device such as a smartphone or tablet. The smartphone or other device may include different types of sensors capable of providing information to the PACS. As the key device communicates with the reader and PACS via BLE and UWB wireless connections, data collected from the key device's sensors can be transmitted to the reader and PACS. The key device may include sensors such as a gyroscope, accelerometer, barometer, global positioning system (GPS), microphone, and camera. The key device can collect information from communication protocols such as Wi-Fi and BLE. The data provided by these sensors and communication protocols can be used to determine the relative position, movement, and velocity of the key device.
[0051] Sensor data can provide information to determine the intentions of a person holding a key device. For example, PACS can determine that a key device is rapidly approaching an entrance. Using data from gyroscopes and accelerometers, PACS can identify that a person is running. Different actions can be taken based on the determination that a person is running. In one situation, if a person has credentials for only one entrance, PACS can unlock the door early, as the person is likely to arrive at the door faster than if they were walking. In another situation, if a person has credentials for multiple meeting rooms, but PACS uses a calendar system to identify that a meeting in one meeting room started 10 minutes ago, PACS can determine that this meeting room is the intended destination based on the fact that the person is running.
[0052] Data stored on a mobile device and data on the mobile device's current functions can be transmitted to the PACS and used to determine intent. If the PACS is not connected to a calendar system, the mobile device can provide information from the calendar or reminders on the mobile device. For example, a person living in an apartment building may share childcare responsibilities with another resident and have access to each other's residences. The person may have a reminder to pick up the other resident's child from school, and this reminder can be used to identify the person's intention to enter the other resident's residence.
[0053] The current function of a mobile device, such as whether a person is making a call or playing a game on it, can be transmitted to the PACS (Picture Archiving and Communication System). For example, if a person is walking down a corridor while playing a game on their mobile device, it can be determined that they have little intention of entering a conference room.
[0054] Cameras, noise sensors (microphones), and environmental sensors such as thermometers and barometers can be used to provide information to the PACS to identify intent. For example, a camera can be used to help identify which turntable the user intends to enter. Outdoor temperature can influence a user's route or habits. For example, if two entrances / exits are close to each other but one leads outdoors, the PACS can determine that the outdoor entrance / exit is more likely to be the intended entrance / exit if the outdoor temperature is currently below freezing.
[0055] PACS may be connected to additional systems that do not require a key device for access and that indicate signs of human behavior likely to continue attempting to enter entrances controlled by PACS. This may include Internet of Things (IoT) devices. Examples of human-interactive devices and systems that can provide PACS with signs of intent and behavioral patterns may include garage door openers, thermostats, smart lighting, televisions, and household appliances.
[0056] PACS can predict and identify the intentions of users accessing entrances and exits using a neural network trained on user habits. This may include identifying various actions or connections that a user may be performing, such as using their mobile device. For example, an office may have a gym for people to use. Tara may pass by the gym door and reader several times a day as part of her normal weekday routine. However, when Tara uses the gym, she is usually listening to music with Bluetooth earbuds. Using this data, the PACS neural network can identify that if Tara is using earbuds, she typically intends to enter the gym, but if not, her intention to enter is extremely low.
[0057] A PACS neural network can be trained using each user's habits to identify common user behaviors and sequences of actions that can be used to identify intended entrances and entry points. For example, a typical day for a person might include entering a building access point, entering an access point on a building floor, and then accessing a secure room. Some of these access points may have multiple options, such as floors having different doors for different tenants. Habit data may include other data to identify changes in habits. For example, the above habits might be those the person has when they arrive at the office in the morning. However, at lunchtime, the person might return with their lunch and go to the cafeteria through a different entrance on the floor.
[0058] A trained neural network can be used to identify the intentions of unknown or new users. For example, a new employee has just started working, so specific habit data for that employee does not exist. A PACS neural network identifies that the employee is an accountant and therefore uses trained data for other accountants to identify the intentions of this new employee.
[0059] PACS can receive data about other applications and functions that the user runs on their mobile device. For example, a user may have Wi-Fi connected lighting in an office or conference room. The user may turn on the lights on their mobile device before arriving at the entrance to such a room. Using this behavioral data, PACS can identify that the user intends to enter the room.
[0060] The PACS neural network can combine multiple factors to identify the intentions of a person entering an entrance / exit and the timing of releasing credentials to enter. For example, it can determine if a user's normal routine may be affected by temperature.
[0061] The reader can perform preliminary authentication when BLE receives credentials to determine whether the credentials provided by the key device should be authenticated, and whether further communication with the key device, such as distance measurement using UWB, should be performed. If the reader can determine through rough verification that the provided credentials are not authenticated, the power and processing costs for distance measurement of the key device using UWB are reduced.
[0062] Preliminary authentication can be performed using a blacklist or a whitelist. Blacklists and whitelists may include conditional elements such as time restrictions. For example, a building may restrict access at night, and therefore a whitelist including only security and maintenance from 8:00 PM to 6:00 AM might be used.
[0063] Preliminary authentication can be performed by regular expression matching and similar pattern recognition. The reader can receive credentials via BLE communication with the key device. The reader can determine whether the received credentials are in the correct format sequence using a regular expression of the format sequence of the credentials accepted by the reader for entry. If incorrect, the reader can discard the credentials and stop communication with the key device. For example, credentials accepted by the reader for entry may be in the format sequence of the letter "K" followed by six digits. If the provided credentials are in the format sequence of the letter "WX" followed by seven digits, the reader will ignore the credentials and will not cache or authenticate them, including stopping all communication or ranging to conserve power and processing.
[0064] PACS can activate additional precautions against access to a secure doorway based on the people near a person attempting to access it, such as preventing tailgaters (for example, people attempting to gain access by following an authorized person). If PACS identifies an unauthorized key device near an authorized key device, not only is the threshold for identifying intent increased, but the doorway will only be unlocked if the authorized key device is very close to the doorway. The same applies when cameras are used in conjunction with PACS and people without key devices are near a person with an authorized key device.
[0065] Figure 5 shows flowcharts illustrating methods 500 for restricting access to an asset according to several embodiments. Method 500 can be used to restrict access to an asset when the asset is a physical location such as a room, building, or house. Method 500 can also be used to restrict access to an asset when the asset is an electronic device such as a computer, computer network, or smartphone, or a specific device such as an automated teller machine.
[0066] Method 500 includes an operation 502 to establish a first connection with a key device, for example, a connection between the key device and a reader. The first connection may be NFC such as RFID, or PAN technology such as IEEE 802.15.1, Wi-Fi, or BLE. The key device may be a physical card having an integrated circuit that stores information such as credentials and information about the holder of the key device. The key device may be a mobile device such as a smartphone. The mobile device may include an application that manages the interface with the reader, or may include a secure element.
[0067] Method 500 includes an operation 504 to receive user credentials via a first connection. Once the first connection between the reader and the keying device is established, the keying device can transmit credentials, for example, user credentials, to the reader. Method 500 may include an operation to store the credentials in the reader's cache memory. The credentials may also be stored in other memory or transmitted to another computer system and stored in the memory of that system.
[0068] Method 500 includes an operation 506 for establishing a second connection with a key device. The second connection may be a UWB. Method 500 may include an operation for maintaining the position or location of the key device using the second connection. The position or location can be determined using distance detection. The operation for establishing the second connection with the key device may occur based on interaction with the key device using the first connection.
[0069] Method 500 may include an action to authenticate the user credentials associated with the credentials for accessing the asset. Authentication may include sending the credentials to an authorized authenticator. Method 500 may include an action to receive a confirmation instruction from an authentication service and grant access to the asset.
[0070] Method 500 includes an operation 508 that provides credentials to an access controller. Providing credentials to the access controller may include an operation that transfers credentials from cache memory. Providing credentials to the access controller may be based on a determination that the user intends to access the asset. The access controller may include a physical access control system controller.
[0071] Method 500 may include an operation to determine the estimated location of a key device using a second connection when determining that a user intends to access an asset. The estimated location may be a position, location, or distance from a reader detected via UWB. Method 500 may include an operation to calculate the probability that a user will access an asset using a set of estimated location points. Method 500 may include an operation to determine that the probability exceeds a predetermined threshold. The threshold can be adjusted depending on the type of asset and security access, so that a higher probability threshold may be set for high-security assets and a lower probability threshold for low-security assets.
[0072] Method 500 may include receiving a confirmation instruction from an access controller and granting access to the asset. For example, the user may be confirmed by credentials to have access to the asset. The asset may be an entrance or exit, a secure entry point, or an electronic device.
[0073] Method 500 may include the action of removing credentials from cache memory. Removal of credentials from cache memory may be based on the receipt of an instruction that the user is not authorized to access the asset. For example, the reader may receive an instruction that the credentials cannot be verified and the user cannot access the asset. Removal of credentials from cache memory may be based on the loss of a second connection to the key device. For example, if the key device moves out of range of the second connection, this can indicate that the key device (and the user) are no longer near the reader, and therefore have little intention of accessing the asset, and thus the credentials are removed from cache memory. Removal of credentials from cache memory may be based on the passage of a predetermined time. For example, if the key device is not used to access the asset within a predetermined time from the time the second connection was established, the credentials may be removed from cache memory. This may be done to conserve memory and resources. The user may be asked to take action, such as placing the key device on the reader, in order to transfer the credentials again and attempt to access the asset.
[0074] Figure 6 shows a flowchart illustrating a method 600 for restricting access to an asset using a key device, according to several embodiments. Method 600 can be used to restrict access to an asset when the asset is a physical location such as a room, building, or house. Method 600 can also be used to restrict access to an asset when the asset is an electronic device such as a computer, computer network, or smartphone.
[0075] Method 600 includes operation 502 to establish a first connection between the key device and the reader when the key device enters a first connection range. The first connection may be, for example, a PAN via BLE. Method 600 also includes operation 604 to provide the reader with user-associated credentials from the key device using the first connection.
[0076] Method 600 includes an operation 606 for establishing a second connection between a key device and a reader. The second connection may be a UWB. The second connection is based on the key device entering the second connection range. For example, a UWB does not measure distances as far as a BLE. The key device can first establish a connection with the reader via a BLE. When the key device approaches the reader and enters the range of the UWB, the key device and the reader can establish a second connection via the UWB. The distance or position of the key device can be determined via the UWB.
[0077] Method 600 includes operation 608, which provides credentials from the reader to the authorization service. The reader may transmit credentials to receive authorization for the user of the key device to access the asset. Method 600 includes operation 610, which allows the reader to receive confirmation of the credentials from the authorization service. If the credentials do not grant permission to access the asset, the reader may receive a rejection from the authorization service.
[0078] Method 600 includes an operation 612 in which the reader sends a command to the access controller granting access to the asset. This command may be to unlock the doorway or to unlock it for use with electronic equipment. Providing credentials to the access controller may be based on the determination that the user intends to access the asset. When determining that the user intends to access the asset, Method 600 may include an operation in which the reader uses a second connection to determine a set of estimated position points for the key device. This can be done by distance detection using UWB. Method 600 may include an operation in which the reader calculates the probability that the user will access the asset using the set of estimated position points and determines that the probability exceeds a predetermined threshold.
[0079] The determination that a user intends to access an asset may be based in part on sensor data collected from the key device's sensors. For example, the key device's GPS may provide location information, or the key device's accelerometer may provide movement information, such as whether the user is running.
[0080] Figure 7 shows a flowchart illustrating a method 700 for restricting access to an asset according to several embodiments. Method 700 includes an operation 702 for receiving a first message from a wireless key device associated with a user using a first wireless connection. The PACS can receive the first message at a reader regarding a secure access point. The first message may include user credentials. The first wireless connection may be NFC such as RFID, or PAN technology such as IEEE 802.15.1 and BLE.
[0081] Method 700 includes operation 704 of receiving a set of messages from a wireless key device using a second wireless connection. The second wireless connection may be UWB. The set of messages may be a series of communications between the reader and the key device. The communications may include a seed or hashed counter to ensure security and prevent impersonation of the key device.
[0082] Method 700 includes an operation 706 that uses a second wireless connection to identify a set of estimated location points of a wireless key device for a set of messages. The PACS can use communication technology such as UWB to identify the location of the key device or to measure the distance between the key device and the reader or a set of readers.
[0083] Method 700 includes an action 708 that determines, based on a set of position estimation points, that the user intends to physically access a secure access point. The secure access point may be one of several secure access points within range of a second wireless connection. Method 700 includes further actions that determine, based on trajectory calculations from a set of position estimation points, that the user intends to physically access a secure access point from several secure access points.
[0084] Method 700 includes further actions of calculating the probability that a user has physically accessed a secure access point using a set of position estimation points and determining whether that probability exceeds a predetermined threshold. For example, a reader can identify multiple distance radii from the reader. The probability increases each time the key device is determined to be within progressively closer range. The probability may decrease if the key device is determined to have stopped within one of several distances or if the key device has moved to a more distant distance. A predetermined threshold can be used to determine whether the probability or intention has become sufficiently high to open the secure access point. The threshold may depend on factors such as the security level of the area being accessed (i.e., a conference room or development laboratory), the number of other access points nearby, and the frequency of a particular key device accessing the secure access point.
[0085] Method 700 includes an action 710 that sends a command to unlock a secure access point. Secure access points include many types, such as doorways, turntables, through gates, elevators, and parking arms. Unlocking a secure access point includes any applicable method for each type of secure access point that ensures restricted access is not restricted to the holder of the key device.
[0086] Method 700 includes further actions of sending credentials to an authorization service. The authorization service may be provided near the reader, such as within a residence. The authorization service may be connected to the reader via a network or the Internet and provide credential authorization to multiple locations or access points. The authorization service may be built into the reader. Method 700 includes further actions of receiving an instruction from the authorization service indicating that the user has been granted authorization to access a secure access point. The authorization service may verify the credentials and send an instruction back to the reader indicating whether the holder of the credentials has been granted authorization to enter the secure access point.
[0087] Figure 8 shows a flowchart illustrating a method 800 for restricting access to an asset according to several embodiments. Method 800 includes an operation 802 for receiving credentials from a key device associated with a user using a first wireless connection. The first wireless connection may be NFC such as RFID, or PAN technology such as IEEE 802.15.1 and BLE.
[0088] Method 800 includes an operation 804 for verifying credentials by preliminary authentication of an asset. Preliminary authentication may be performed on the reader side or on a device near the reader. Preliminary authentication may include a step of identifying that the credentials contain a pattern using pattern matching. The pattern may be defined using a regular expression. Method 800 includes an operation for verifying credentials by preliminary authentication by comparing the credentials with a whitelist of multiple credentials. The whitelist may be applied in the preliminary authentication based on time. For example, the whitelist may identify groups of people who are permitted to enter an office building at night and on weekends.
[0089] Method 800 includes operation 806 for establishing a second wireless connection with a key device in response to verification of credentials by preliminary authentication. The second wireless connection may be UWB. The PACS can use communication technology such as UWB to identify the location of the key device or to measure the distance between the key device and the reader or a set of readers.
[0090] Method 800 includes sending credentials to an authorization service and receiving instructions from the authorization service that the user has been granted permission to access the asset. Preliminary authentication is performed to help filter out credentials that might be automatically rejected by the authorization service for not conforming to the correct format or pattern. This reduces the time and processing required to send and authenticate such credentials. Method 800 includes an action 808 that provides a command to grant access to the asset.
[0091] Figure 9 shows a flowchart illustrating a method 900 for restricting access to an asset according to several embodiments. Method 900 includes an operation 902 for receiving asset credentials from a key device associated with a user using a first wireless connection. The first wireless connection may be NFC such as RFID, or PAN technology such as IEEE 802.15.1 and BLE.
[0092] Method 900 includes operation 904 for storing credentials in a memory cache. The PACS can cache credentials for future authentication in memory, such as the memory of a reader, in case a user intends to enter an asset. The intent threshold for authenticating credentials may be lower than the intent threshold for unlocking access to the asset. For example, if a user moves towards an entrance, the PACS may determine that there is a 60% probability that the user intends to enter the entrance and send credentials to the authentication service. If the user continues to move towards the door, the probability may change to 90%, so the reader sends a command to unlock the entrance.
[0093] Method 900 includes an operation 906 for establishing a second wireless connection with a key device. The second wireless connection may be UWB. The PACS can use communication technology such as UWB to identify the location of the key device or to measure the distance between the key device and the reader or a set of readers.
[0094] Method 900 includes an operation 908 that requests confirmation of credentials from an authorization service in response to establishing a second wireless connection with a key device. The authorization service may be provided in the vicinity of the reader, such as within a residence. The authorization service may be connected to the reader via a network or the Internet to provide authorization of credentials to multiple locations or entry points. The authorization service may be integrated into the reader.
[0095] Method 900 includes an operation 910 to receive a confirmation token from an authorization service. The confirmation token may be used to send to the authorization service or access control service to indicate that the provided credentials have been verified. Method 900 includes an operation 912 to store the confirmation token in a cache.
[0096] Method 900 may further include an operation to determine, using a second wireless connection, that the key device is within a first ranging radius of a plurality of ranging radii, which extend from the reader of the wireless key device. The PACS can identify distance ranges from the reader. For example, the PACS may specify three ranges: a first range within a radius of 1.52 m (5 feet) from the reader, a second range within a radius of 1.52 m to 3.05 m (5 to 10 feet) from the reader, and a third range within a radius of 3.05 m to 4.57 m (10 to 15 feet) from the reader.
[0097] Method 900 may further include an operation to determine, using a second wireless connection, that the key device is within a second ranging radius of a plurality of ranging radii, the second ranging radius being closer to the wireless key device reader than the first ranging radius. From the above example using three different distances, the PACS can use UWB to determine that the key device was originally within a third range but has moved into a second range.
[0098] Method 900 may further include the operation of calculating the probability that the user intends to physically access the asset based on the determination that the wireless key device is within a second ranging radius. From the example above, the key device has moved from a greater distance to a closer distance, and therefore the probability that the user is moving towards the reader is higher.
[0099] Method 900 may further include an action to determine that the probability has exceeded a predetermined threshold. Method 900 may further include an action to send a confirmation token to the access control service. Based on the probability of exceeding the threshold, the PACS may send a confirmation token to the access control service indicating that the asset should be unlocked. Method 900 may further include an action to receive a command granting access to the asset. The authorization service and the access control service may be built into the PACS, network-connected to the PACS, or be separate services to the PACS.
[0100] Method 900 may further include an operation to determine, using a second wireless connection, that the key device is within a second ranging radius of a plurality of ranging radii, wherein the second ranging radius is further from the wireless key device reader than the first ranging radius. From the above example using three different distances, the PACS can use UWB to determine that the key device was originally within the second range but has moved further away and entered the third range.
[0101] Method 900 may further include the action of removing the verification token and credentials from the cache. As in the example above, the key device is moving from a closer range to a farther range, increasing the probability that the user does not intend to access the assets, and therefore the stored information such as credentials and verification tokens is removed from the cache.
[0102] Method 900 may further include an action to determine that no response has been received from the key device within a predetermined time. If the PACS sends a message, the timer can be started. If the PACS receives a response from the wireless key device, the timer can be canceled. If the timer times out, the PACS can determine, based on the determined timeout period, that the wireless key device is no longer within range and therefore the probability that the user intends to access the asset is extremely low. Method 900 may further include an action to remove the confirmation token and credentials from the cache based on the fact that the confirmation token and credentials are no longer needed.
[0103] Figure 10 shows a flowchart illustrating a method 1000 for restricting access to an asset according to several embodiments. Method 1000 includes an operation 1002 for receiving user credentials from a key device associated with the user using a first wireless connection. The first wireless connection may be NFC such as RFID, or PAN technology such as IEEE 802.15.1 and BLE.
[0104] Method 1000 includes operation 1004 for establishing a second wireless connection with a key device. The second wireless connection may be UWB. The PACS can use communication technology such as UWB to identify the location of the key device or to measure the distance between the key device and the reader or multiple readers.
[0105] Method 1000 includes an action 1006 that determines whether a user intends to access an asset based on a dataset introduced and generated from a second wireless connection. The PACS can use UWB to determine location information from the second wireless connection. The second wireless connection may include information from a key device, such as sensor data from sensors on the key device. The dataset may include both data provided by the key device and data introduced from the second wireless connection that can be used to determine the user's intent.
[0106] Method 1000 may include, when determining that a user intends to access an asset, the operation to determine the probability that the user intends to access the asset using the dataset and a trained machine learning model. The trained machine learning model is trained using a dataset collected from multiple users. The dataset may include movement data of multiple users within the asset's range. The dataset may include movement data from multiple users. Information received from the wireless key device may include user movement data collected from the wireless key device's accelerometer.
[0107] For example, a machine learning model can be trained using location and movement data showing how different people move towards and approach a specific asset or secure access point, as well as data showing when people do not enter the secure access point. This training enables the machine learning model to recognize how people move and the angle at which they approach when their intention is to enter the secure access point. The dataset may include time timestamps, and users can timestamp their datasets. Including time in training the machine learning model allows it to exhibit different patterns and behaviors based on time. For example, people may be less likely to access a secure access point during lunchtime.
[0108] Determining whether a user intends to access an asset may involve using data received from a calendar system. Method 1000 may further include an action to identify a calendar system event associated with the asset. For example, the calendar system may indicate that a meeting is taking place in a room attached to a secure access point. Method 1000 may further include an action to identify an instruction that a user will attend the event. The calendar system may provide a list of meeting attendees, and the PACS may identify that the user is one of the attendees, thereby increasing the probability that the user intends to enter the secure access point. Method 1000 includes an action 1008 to send a command granting access to the asset.
[0109] Figure 11 shows a block diagram of an exemplary machine 1100 capable of performing any one or more of the techniques (e.g., methods) described herein. In several alternative embodiments, machine 1100 may operate as a standalone device or be connected to other machines (e.g., networked). In a networked configuration, machine 1100 can operate as a server machine, a client machine, or both in a server / client network environment. In one example, machine 1100 can operate as a peer machine in a peer-to-peer (P2P) (or other distributed) network environment. Machine 1100 may be a personal computer (PC), a tablet PC, a set-top box (STB), a personal digital assistant (PDA), a mobile phone, a web device, a network router, a switch or bridge, or any machine capable of executing (sequentially or separately) commands specifying the actions to be taken by the machine. Furthermore, although only a single machine is illustrated, the term “machine” should be understood to include any group of machines that individually or collectively perform a set (or set) of instructions that perform any one or more of the methods described herein, including, for example, cloud computing, software as a service (SaaS), and other computer cluster configurations.
[0110] Several examples may include, or be operated by, logic or a number of elements or mechanisms, as described herein. A circuit set is a collection of circuits implemented on a tangible entity (e.g., a simple circuit, gate, logic, etc.) including hardware. The components of a circuit set may be flexible over time and with respect to the variability of the underlying hardware. A circuit set includes components that can perform specified operations individually or collaboratively during operation. In one example, the hardware of a circuit set may be designed immutably (e.g., hardwired) to perform a particular operation. In one example, the hardware of a circuit set may include variably connected physical elements (e.g., execution units, transistors, simple circuits, etc.) that include a computer-readable medium that has been physically modified (e.g., magnetic, electrical, movable arrangement of immutable massed particles, etc.) to encode instructions for a particular operation. When connecting physical elements, the underlying electrical properties of the hardware elements may be changed, for example, from an insulator to a conductor, or vice versa. The instruction allows embedded hardware (e.g., an execution unit or load mechanism) to generate components of a set of circuits within the hardware via variable connections to execute multiple parts of a particular operation during operation. Thus, when the device is operating, the computer-readable medium is communicatively coupled to other elements of the circuit set components. In one example, any one of the physical elements may be used in multiple components of multiple circuit sets. For example, during operation, an execution unit may be used at one point in a first circuit of a first set of circuits, and at a different point in time by a second circuit within the first set of circuits, or by a third circuit within the second set of circuits.
[0111] The machine (e.g., a computer system) 1100 may include a hardware processor 1102 (e.g., a central processing unit (CPU), a graphics processing unit (GPU), a hardware processor core, a field-programmable gate array (FPGA), or any combination thereof), main memory 1104, and static memory 1106), some or all of which can communicate with each other via an interlink (e.g., a bus) 1108. The machine 1100 may further include a display device 1110, an alphanumeric input device 1112 (e.g., a keyboard), and a user interface (UI) navigation device 1114 (e.g., a mouse). In one example, the display device 1110, the input device 1112, and the UI navigation device 1114 may be touchscreen displays. The machine 1100 may also include a storage device (e.g., a drive unit) 1116, a signal generating device 1118 (e.g., a speaker), a network interface device 1120, and one or more sensors 1121, such as a Global Positioning System (GPS) sensor, a compass, an accelerometer, or other sensors. The machine 1100 may also include an output controller 1128 for communicating with or controlling one or more peripheral devices (e.g., a printer, a card reader, etc.) via a series (e.g., Universal Serial Bus (USB)), parallel, or other wired or wireless (e.g., infrared (IR), near-field communication (NFC), etc.) connection.
[0112] The storage device 1116 may include a machine-readable medium 1122 on which data structures or one or more sets of instructions 1124 (e.g., software) are stored that perform or use any one or more of the methods or functions described herein. The instructions 1124 may also reside fully or at least partially in main memory 1104, static memory 1106, or hardware processor 1102 while being executed by machine 1100. In one example, the machine-readable medium may consist of one or any combination of the hardware processor 1102, main memory 1104, static memory 1106, or storage device 1116.
[0113] Although the machine-readable medium 1122 is shown as a single medium, the term “machine-readable medium” may include a single or multiple mediums configured to store one or more instructions 1124 (e.g., a centralized or distributed database, and / or associated caches and servers).
[0114] The term “machine-readable medium” may include any medium capable of storing, encoding, or transporting instructions executed by machine 1100, and capable of storing, encoding, or transporting data structures used by or associated with any one or more of the methods of the Disclosure, or that cause machine 1100 to execute such instructions. Examples of non-limiting machine-readable mediums include solid memory and optical and magnetic media. In one example, a mass-bearing machine-readable medium includes a machine-readable medium having a plurality of particles having an immutable (e.g., stationary) mass. Therefore, a mass-bearing machine-readable medium is not a transient propagation signal. Specific examples of mass-bearing machine-readable mediums may include non-volatile memory such as semiconductor memory elements (e.g., electrically programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM)) and flash memory devices, magnetic disks such as internal hard disks and removable disks, magneto-optical disks, and CD-ROMs and DVD-ROMs.
[0115] Instruction 1124 may further be transmitted or received via a communication network 1126 using a transmission medium via a network interface device 1120 that utilizes any one of many transport protocols (e.g., Frame Relay, Internet Protocol (IP), Transmit Control Layer Protocol (TCP), User Datagram Protocol (UDP), Hypertext Transfer Protocol (HTTP), etc.). Exemplary communication networks may include, in particular, local area networks (LANs), wide area networks (WANs), packet data networks (e.g., the Internet), mobile telephone networks (e.g., cellular networks), basic telephone service (POTS) networks, and wireless data networks (e.g., the IEEE 802.11 standard family known as Wi-Fi®, the IEEE 802.16 standard family known as WiMAX®, the IEEE 802.15.4 standard family), and peer-to-peer (P2P) networks. In one example, the network interface device 1120 may include one or more physical jacks (e.g., Ethernet®, coaxial cable, or telephone jack) or one or more antennas for connecting to the communication network 1126. In one example, the network interface device 1120 may include multiple antennas for wireless communication using at least one of the following technologies: single-input multiple-output (SIMO), multiple-input multiple-output (MIMO), or multiple-input single-output (MISO). The term “transmitting medium” includes any intangible medium that can store, encode, or carry instructions executed by machine 1100 and that includes digital or analog communication signals or other intangible mediums to facilitate communication of such software.
[0116] The above detailed description includes references to accompanying drawings that form part of the detailed description. The drawings illustrate, through drawing, specific embodiments that may be carried out. These embodiments are also referred to herein as “examples.” Such examples may include additional elements beyond those shown or described. However, the inventors also envision examples in which only the shown or described elements are provided. Furthermore, the inventors also envision examples using any combination or permutation of these shown or described elements (or one or more embodiments thereof) with respect to a particular example (or one or more embodiments thereof), or to other examples (or one or more embodiments thereof) shown or described herein.
[0117] All publications, patents, and patent documents referenced herein are cited in their entirety, as if they were cited individually. In the event of any inconsistency between the use herein and the cited documents as described above, the use of the cited references is intended to complement the use herein, and in the event of incompatible inconsistencies, the use herein shall prevail.
[0118] In this specification, the terms “a” or “an” are used to include one or more, independently of any other occurrence or use of “at least one” or “one or more,” as is common in the patent literature. In this specification, the term “or” is intended to be non-exclusive unless otherwise specified, i.e., “A or B” includes “A but not B,” “B but not A,” and “A and B.” In the appended claims, the terms “including” and “in which” are used as plain English equivalents to the terms “comprising” and “wherein,” respectively. Furthermore, in the following claims, the terms “including” and “comprising” are open, i.e., a system, apparatus, article, or process that includes multiple elements in addition to the elements listed following such terms is still considered to be within the scope of the claim. Furthermore, in the following claims, the terms "first," "second," and "third," etc., are used merely as labels and are not intended to impose numerical requirements on the objects in question.
[0119] The above description is for illustrative purposes only and is not intended to be limiting. For example, the above examples (or one or more of their embodiments) may be used in combination with each other. Those skilled in the art may use other embodiments by referring to the above description. The abstract is intended to allow readers to quickly confirm the nature of the technical disclosure and to understand that it is not intended to interpret or limit the scope or meaning of the claims. Furthermore, in the detailed description above, various features may be summarized in an easy-to-understand manner. This should not be interpreted as meaning that any disclosed feature that is not claimed is essential to any of the claims. Rather, the subject matter of the invention may be included in some features of a particular disclosed embodiment. Accordingly, the following claims are referenced in the detailed description and each claim stands alone as a separate embodiment. The scope of the embodiments should be determined in conjunction with the full scope of the equivalents to which these claims are effective, with reference to the appended claims.
Claims
1. A method for restricting access to an asset in an access control system, The steps include establishing a first wireless connection with a key device using a low-power communication protocol, The steps include receiving the user credentials of the key device via the first wireless connection, The steps include establishing a second wireless connection with the key device using ultra-wideband (UWB), A step of determining that a user intends to access the asset, the step of determining that a user intends to access the asset includes determining that a first probability calculated based on the location information of the key device obtained from the second wireless connection satisfies a first intention threshold, The steps include: granting access to the asset in response to determining that the result of the determination and the second probability calculated based on the location information of the key device obtained from the second wireless connection satisfy the second intent threshold; A method wherein the first intent threshold is lower than the second intent threshold.
2. The method according to claim 1, wherein the low-power communication protocol is Bluetooth® Low Energy.
3. The method according to claim 1, wherein the asset is a physical location.
4. The method according to claim 1, wherein the asset is an electronic device.
5. The steps include providing the aforementioned credentials to the authorization service for approval, The method according to claim 1, further comprising the step of receiving a confirmation instruction from the authorization service, wherein the confirmation instruction indicates whether the user has permission to access the asset based on the credentials.
6. The method according to claim 5, wherein the step of providing the credentials to the authorization service for authorization is performed in response to determining that the first probability calculated based on the location information of the key device obtained from the second wireless connection satisfies the first intent threshold.
7. The method according to claim 5, wherein the step of establishing the second wireless connection is performed in response to receiving the acknowledgment instruction from the authorization service.
8. The method according to claim 5, wherein the step of granting access to the asset is performed in response to receiving the confirmation instruction from the authorization service.
9. The method according to claim 5, wherein the authorization service is located near the reader that establishes the first and second wireless connections.
10. The method according to claim 5, wherein the authorization service is network-connected to readers that establish the first and second wireless connections.
11. The steps include storing the aforementioned credentials in cache memory, The method according to claim 1, further comprising the step of deleting the credentials from the cache memory based on the loss of the second wireless connection with the key device.
12. The steps include storing the aforementioned credentials in cache memory, The method according to claim 1, further comprising the step of deleting the credentials from the cache memory based on the elapsed time of a predetermined period of time.
13. A non-temporary machine-readable medium comprising instructions, wherein, when executed by at least one processor, the instructions cause the processor to perform the method according to any one of claims 1 to 12.
14. A method for restricting access to multiple assets in an access control system, The steps include establishing multiple first wireless connections with multiple key devices using a low-power communication protocol, The steps include receiving the credentials of individual users of the plurality of key devices via the first wireless connection, The steps include establishing multiple second wireless connections with the multiple key devices using ultra-wideband (UWB), A step of determining, for each user and individual asset, whether the user intends to access the individual asset, wherein determining whether the user intends to access the individual asset includes determining whether a probability calculated based on the location information of a key device corresponding to the user obtained from at least one of the plurality of second wireless connections satisfies an intent threshold for the individual asset, the intent threshold for the individual asset being based on the security level for the individual asset, and the intent thresholds for at least two of the plurality of assets being different, A method comprising the step of controlling access to the plurality of assets based on the determination for each user and individual asset.
Citation Information
Patent Citations
Passage management device
JP2007102405A
Image forming apparatus, authentication system, authentication method and program
JP2010277557A
Enhanced automotive passive entry
US20180234797A1