Method and a system for controlling the access of an object or a person in a safety area
The method and system for controlling access to safety areas around machines, using RTLS and a Two-Factor Authentication process, address the challenges of external sensor reliance, reducing costs and improving security and reliability.
Patent Information
- Application Number
- PCT/IB2024/062508
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-20
- Filing Date
- 2024-12-11
- Publication Date
- 2025-06-26
AI Technical Summary
Existing safety systems for controlling access to safety areas around machines require the use of external sensors in addition to real-time location systems (RTLS), which increases installation time, costs, and complexity while reducing reliability.
A method and system that utilize a real-time location system (RTLS) to implement a Two-Factor Authentication process, eliminating the need for external sensors by using RTLS tags with processors and unique identification information, and integrating an OTP algorithm for enhanced security.
The solution reduces installation time, costs, and complexity while improving reliability and security by eliminating the need for external sensors and enhancing the ability to distinguish between machines and humans, and to associate specific safety functions accordingly.
Smart Images

Figure IB2024062508_26062025_PF_FP_ABST
Abstract
Description
“METHOD AND A SYSTEM FOR CONTROLLING THE ACCESS OF AN OBJECT OR A PERSON IN A SAFETY AREA” DESCRIPTION Field of the invention
[0001] The present invention relates to a method and a system for controlling the access of an object or a person in a safety area of a machine according to an access policy, wherein the safety area is inside a zone monitored by a real-time location system (RTLS). Background art
[0002] Safety methods and systems for localizing an object or a person in a monitored zone and optionally trigger the muting function of the safety system to allow an authorized object or person to enter in a safety area, for example a hazard zone around a machine, are already known.
[0003] These methods and systems typically require that two independent conditions are satisfied in order to change the safety functions of the monitored zone.
[0004] For example, in US2021232102A1 the position of an object or person is determined by a real-time location system and by a spatially resolving sensor. The positions returned by both the RTLS and the sensor are then compared by a evaluation unit and, if the two positions match, the evaluation unit enables the muting of thesensor.
[0005] In other examples, the determination is performed on an unique identification information (ID) of the object or person. In this case, the unique identification information is detected independently by the RTLS and by an external ID identification sensor, for example a barcode reader.
[0006] Other solutions adopt a combination of the two methods above.
[0007] In any case, all the known methods and systems make use of external sensors. Summary of the invention
[0008] An object of the present invention is to provide a method and system for controlling the access of an object or a person in a safety area of a machine, which do not require the use of external sensors in addition to the real-time location system, thereby reducing the installation time, the production, installation and maintenance costs of the system, while improving at the same time its reliability.
[0009] Another object of the invention is to create a bridge between safety applications and security applications, by providing a method and a system able to distinguish, in secure way, between machines and humans, between machines and machines, and between humans andhumans, and to associate specific safety functions to the machine controller accordingly, and / or to change them.
[0010] The object is achieved with a method according to claim 1 and with a system according to claim 10. The dependent claims describe preferred embodiments of the invention. Brief description of the drawings
[0011] The features and advantages of the method and system according to the invention will be apparent from the description given below of preferred embodiments thereof, made by way of a non-limiting examples with reference to the appended drawings, wherein: - Figure 1 is a flow-chart of the method for controlling the access of an object or a person in a safety area of a machine, according to a general embodiment of the invention; - Figure 2 is a flow-chart of the first condition step of the Two-factor Authentication process, according to one embodiment; - Figure 3 is a flow-chart of the second condition step of the Two-factor Authentication process, according to one embodiment; - Figure 4 is a diagram of a system for controlling the access of an object or a person in a safety area of a machine, in a first embodiment according to theinvention; - Figure 5 is a diagram of a system for controlling the access of an object or a person in a safety area of a machine, in a second embodiment according to the invention. Detailed description of the invention
[0012] In the drawings, reference number 1 globally denotes a monitored zone. This monitored zone 1 is monitored by a real-time location system 10 (in the following, “RTLS”).
[0013] The RTLS 10 comprises a server 102 and a plurality of radio stations 104, also called “anchors”. Each radio station 104 is operatively connected to the server 102.
[0014] The RTLS 10 is configured to control the position of objects or persons 20, moving within the monitored zone 1. To this end, one or more tags 202 are attached to each object or person 20. Each tag 202 is configured to exchange data with the plurality of radio stations 104 each object or person 20.
[0015] In one embodiment, each tag 202 is a RFID tag.
[0016] However, the term “tag” includes any wireless device readable by the RTLS through the radio stations 104. For example, a tag may be also implemented with Beacon, GPS, Wi-Fi, Ultra-wide Band technologies.
[0017] Each tag 202 has a processor.
[0018] Each tag 202 is also uniquely identified by a unique identification information (ID).
[0019] At least one machine 30, for example a robot, is located inside, or close to, the monitored zone 1.
[0020] The machine 30 is controlled by a machine’s controller 32. The machine’s controller 32 is operatively connected to the server 102 of the RTLS 10.
[0021] At least one safety area 34 is defined at least partially around, or close to, the machine 30. The access to the safety area 34 is controlled by at least one safety device 36, for example a laser scanner, a safety radar, a safety light curtain or more in general any ESPE designed to guarantee safe operations of the hazardous machine. The safety device 36 is operatively connected to the machine’s controller 32 and / or to the server 102 of the RTLS 10.
[0022] RTLS server 102, tags 202 and machine’s controller 32 are configured to implement a Two-Factor Authentication process, which will be further disclosed below.
[0023] If the Two-factor Authentication process is successful, the safety functions of the safety area 34 can be changed and, for example, the object or person 20 can access the safety area 34.
[0024] For example, if the Two-factor Authentication process is successful, the safety device 36 is disabled, or muted, or its safety function(s) modified.
[0025] According to a general aspect of the invention, the method implementing the Two-Factors Authentication process comprises a first condition checking step 50 and a second condition checking step 60 (Figure 1).
[0026] As mentioned above, if both the first condition checking step 50 and the second condition checking step 60 are satisfied, the Two-Factors Authentication process is successful and safety functions of the safety area can be changed (step 70).
[0027] In one embodiment, if the first condition checking step 50 is satisfied, the second condition checking step 60 is performed. Otherwise, the process ends (step 55).
[0028] If the second condition checking step 60 is satisfied, the safety functions of the safety area can be changed. Otherwise, the process ends (step 65).
[0029] Figure 2 is a flow-chart showing an example of the first condition checking step 50.
[0030] In the first condition checking step 50, a position of each tag 202 is detected by the RTLS system (step 502) and compared with an expected position (step 504). If the detected position does not match with theexpected position, the process ends.
[0031] In the first condition checking step 50, the unique identification information (ID) of the tag 202 is detected (step 502a) by the RTLS system and compared with an expected unique identification information (step 504a).
[0032] If the detected ID does not match with the expected ID, the process ends.
[0033] In one embodiment, the check of the position of the tag is carried out by detecting, by the RTLS server 102, whether the tag is inside a respective identification zone 40, which is different from the safety area 34, defined for example by the radio stations 104 of the RTLS.
[0034] For example, the identification zone 40 is a geofenced zone, but it can be also a physically delimited zone.
[0035] In one embodiment, the check of the unique identification information (ID) is carried out by verifying whether the unique identification information matches an approved unique identification information according to the access policy.
[0036] For example, such access policy of the tags is defined into a database logically and functionally separated from the RTLS server 102, but accessible ondemand by it.
[0037] In one embodiment, the second condition checking step 60 is carried out only if the first condition checking step 50 is satisfied.
[0038] The second condition checking step 60 implements an OTP algorithm based on a challenge-response OTP between the machine’s controller 32 and the processor of each tag 202.
[0039] In one embodiment, illustrated in the flow- chart of figure 3, the challenge-response OTP between the machine’s controller and the processor of each tag requires that a private key is associated to each tag 202 (step 600), the private key being shared with, or communicated to, the machine’s controller 32.
[0040] This association of a private key to each tag 202 may include, in a possible embodiment, that the tag itself is designed as a private key.
[0041] As, in one embodiment the challenge-response OTP algorithm provides generating, by the controller of the machine 32, an OTP for each tag 202 (step 602).
[0042] The OTP is received be the tag 202 (step 604).
[0043] Then, the processor of the tag 202 applies a cryptographic function to the OTP using the private key. An encrypted OTP is thus obtained (step 606).
[0044] The encrypted OTP is sent back to the machine’scontroller 32 (step 608).
[0045] The machine’s controller 32 applies the cryptographic function to each generated OTP using the same private key used by the respective tag (step 610).
[0046] Then, the controller of the machine 32 compares each received encrypted OTP with the respective encrypted generated OTP (step 612).
[0047] In one embodiment, each OTP is exchanged between the controller of the machine 32 and the processor of the tag 202 through the RTLS infrastructure, that is, through the RTLS server 102 and radio stations 104.
[0048] In one embodiment, if the first condition of the Two-factor authentication process is satisfied, the server of the RTLS 102 triggers a request signal towards the controller of the machine 32 requesting the execution of the OTP algorithm.
[0049] This request signal may include an indication of each tag to be authenticated and / or of the respective private key to be used.
[0050] In one embodiment, if the object or person 20 is provided with at least two tags 202, the tags are located on spatially distanced portions of the object or person 20. In this case, the check of the position of each tag is carried out with respect to respective,spatially different, identification zones 40 inside the monitored zone.
[0051] The present invention is also related to a system for controlling the access of an object or a person 20 in a safety area of a machine according to an access policy.
[0052] The system includes the RTLS 10, one or more tags 202 suitable for being attached to an object or person 20, a machine’s controller 32, and at least one safety device 36, for example a safety laser scanner, a safety radar, a safety light curtain and more in general any kind of ESPE designed for safe protection of the hazardous machines.
[0053] The one or more tags 202 are suitable for being attached to the object or person 20. Each tag 202 is configured to exchange data with the plurality of radio stations 104, includes a processor and is uniquely identified by a unique identification information (ID).
[0054] The machine’s controller 32 is configured to control the machine and is operatively connected to the server of the RTLS 102.
[0055] The at least one safety device 36 is suitable for controlling the access to a safety area 34 and is operatively connected to the server of the RTLS 102 and / or to the machine’s controller 32.
[0056] The RTLS server 102, the tags 202 and the machine’s controller 32 are configured to implement the Two-Factor Authentication process described above.
[0057] Figure 4 shows an example of the system for controlling the access of an object 20 in a safety area 34 of a machine 30 according to an access policy, wherein the object is provided with one tag 202.
[0058] In the monitored zone, an identification zone 40 is defined.
[0059] The RTLS server 102 checks whether tag 202 is inside Identification zone 40.
[0060] The RTLS server 102 also checks whether the unique identification information (ID) of tag 202 matches with an approved one to enter the safety area 34.
[0061] As explained above, the combination of the above two events at the same time (position of tag 202, ID of tag 202), both verified by the RTLS system, is the first step of the Two-Factors Authentication process. If (and only if) this first step is successful, the RTLS server 102 triggers a signal towards the machine’s controller on a safe line, for example a EtherCAT line. By means of this signal, the RTLS server requires to the controller of the machine to generate an OTP code.
[0062] For example, the machine’s controller 32 generates the following code:
[0063] OTP = 12345
[0064] The machine’s controller 32 then sends to the RTLS server 102 such OTP code (for example through the same EtherCAT line). The OTP code is then sent back from the RTLS server 102 to tag 202 (for example through the radio stations or anchors 104).
[0065] Tag 202 receives its OTP code and its internal processor performs a certain transformation function (for example a cryptographic function) on this OTP code (for example, reverses the order of the digits). The new code OTP-R generated by the tag is, in this case, OTP-R = 54321.
[0066] The tag 202 then sends this transformed (i.e. encrypted) OTP-R code to the RTLS server 102.
[0067] The RTLS server 102 then sends the transformed code OTP-R to the machine’s controller 32. The machine’s controller 32 compares the transformed code OTP-R with the original OTP code that it had previously generated.
[0068] More precisely, the machine’s controller 32 applies to the generated OTP code the same transformation function applied by the processor of tag 202, so as to compare the transformed generated OTP code with the transformed OTP-R code received from the RTLS server 102.
[0069] If the two transformed codes match (in this case, OTP-R is the reverse of OTP code-A), then the Two-Factor Authentication is complete and successful.
[0070] Safety functions on the safety device and / or of the robot based on the (now safe and secure) ID of the tag can be changed.
[0071] Figure 5 shows the system according to another embodiment, in which the object 20 is provided with two tags 202, TAG_A and TAG_B. These two tags must be detected inside two respective, preferably spatially distinct, identification zones 40, in this example called ID-A, ID-B.
[0072] RTLS server 102 checks whether it detects TAG_A inside the respective identification zone ID-A.
[0073] Furthermore, RTLS server checks whether the unique identification information IDAof TAG_A matches with an approved one to enter the safety area 34.
[0074] In addition, RTLS server checks whether it detects TAG_B inside the respective identification zone ID-B.
[0075] Furthermore, RTLS server checks whether the unique identification information IDBof TAG_B matches with an approved one to enter the safety area 34.
[0076] To verify if the IDs of the two tags are authorized to enter the safety area, the RTLS server 102 may access a database, in which the access policy is stored.
[0077] The combination of the above four events at the same time (position of TAG_A, IDAof TAG_A, position of TAG_B, IDBof TAG_B), all verified by the RTLS system, is the first step of the Two-Factors Authentication process. If (and only if) this first step is successful, the RTLS server 102 triggers a signal towards the machine’s controller 32 to request the controller to generate two OTP codes, one per each tag, OTP-A and OTP-B.
[0078] For example, the controller of the machine generates the following two codes:
[0079] OTP-A = 12345
[0080] OTP-B = 67890
[0081] The machine’s controller 32 sends to the RTLS server 102 such codes (for example using the same EtherCAT line). The OTP codes OTP-A, OTP-B are then sent back from the RTLS server 102 to TAG_A and TAG_B (for example through the radio stations or anchors).
[0082] TAG_A receives its OTP-A code and its internal processor performs a certain transformation function (for example a cryptographic function) on this code (for example, reverses the order of the digits). The new code generated by tag TAG_A is OTP-AR, in this case = 54321.
[0083] TAG_B receives its OTP-B code and its internal processor performs a certain transformation function (for example a cryptographic function), for example the sametransformation function of TAG_A, on this code (for example, reverses the order of the digits). The new code generated by tag TAG_B is OTP-BR, in this case = 09876.
[0084] The two tags TAG_A, TAG_B then send the respective transformed code to the RTLS server.
[0085] The RTLS server then sends the transformed codes OTP-AR, OTP-BR to the machine’s controller 32. The machine’s controller 32 compares the transformed codes with the original OTP-A, OTP-B codes that it had previously generated.
[0086] More precisely, the machine’s controller 32 applies to the generated OTP codes the same transformation function applied by the tags, so as to compare the transformed generated OTP codes with the transformed OTP codes received from the RTLS server.
[0087] If each pair of the two transformed codes match (in this case, OTP-AR is the reverse of OTP-A and OTP-BR is the reverse of OTP-B), then the Two-Factor Authentication is complete and successful.
[0088] Safety functions on the laser scanner and / or of the robot based on the (now safe and secure) ID of the tags can be changed.
[0089] This second embodiment requires more hardware and software resources, but has a higher level of security compared to the first embodiment with a singletag.
[0090] From the description above, it is clear that the method and system according to the invention achieve the intended objects.
[0091] In particular, the two independent conditions required to allow to change the safety functions of the system are met without the use of dedicated sensors other than the RTLS system. Both security and safety are improved, while the complexity of the system, the installation and maintenance time and costs are reduced.
[0092] A person skilled in the art may make modifications and adaptations to the embodiments of the method and system according to the invention, replacing elements with others functionally equivalent so as to satisfy contingent requirements while remaining within the scope of protection of the following claims.
[0093] Each of the characteristics described as belonging to a possible embodiment may be realized independently of the other embodiments described.
Claims
Claims 1. Method for controlling the access of an object or a person (20) in a safety area (34) of a machine (30) according to an access policy, wherein the safety area (34) is at least partially inside or closed to a monitored zone monitored by a RTLS (10) (“real-time location system”), and wherein the object or the person (20) is provided with one or more tags (202) readable by the RTLS, the method implementing a Two-Factors Authentication process comprising: a) a first condition checking step (50) of the Two- Factors Authentication process, in which both a position of each tag (202) and a unique identification information identifying each tag (202) are detected by the RTLS and compared with an expected position and with an expected unique identification information; b) a second condition checking step (60) of the Two- Factors Authentication process, which is carried out only if the first condition is satisfied and which implements an OTP algorithm based on a challenge-response OTP between a machine’s controller (32) and a processor of each tag (202); c) if the Two-Factors Authentication process is successful, changing at least a safety function of the safety area (34).
2. Method according to claim 1, wherein step a) comprises the sub-step of: a1) detecting (502), by the RTLS, whether each tag (202) is inside a respective identification zone (40), the identification zone being different from the safety area (34).
3. Method according to claim 1 or 2, wherein step a) comprises the sub-step of: a2) checking (502a), by the RTLS, whether a unique identification information (ID) identifying each tag (202) matches an approved unique identification information according to the access policy.
4. Method according to any of the previous claims, wherein step b) comprises the sub-steps of: b1) associating (600) to each tag (202) a respective private key, or designing each tag as a private key, the private key being shared with, or communicated to, the machine’s controller of the machine; b1) generating (602), by the machine’s controller (32), a OTP for each tag (202); b2) receiving (604), by each tag (202), the respective OTP; b3) applying (606), by a processor of each tag (202), a cryptographic function to the OTP using the private key; b4) sending back (608) each encrypted OTP to themachine’s controller (32); b5) applying (610), by the controller of the machine, a cryptographic function to each generated OTP using the same private key used by the respective tag; b6) comparing (612), by the machine’s controller (32), each received encrypted OTP with the respective encrypted generated OTP.
5. Method according to any of the previous claims, wherein each OTP is exchanged between the machine’s controller (32) of the machine and the processor of each tag (202) through the RTLS.
6. Method according to any of the previous claims, wherein, if the first condition of the Two-factor authentication process is satisfied, the server (102) of the RTLS triggers a request signal towards the machine’s controller (32) requesting the execution of the OTP algorithm, the request signal including an indication of each tag to be authenticated and / or of the respective private key to be used.
7. Method according to any of the previous claims, wherein, if the object (20) is provided with at least two tags (202), the tags are located on spatially distanced portions of the object (20) and, in step a), the check of the position of each tag (202) is carried out with respect to respective, spatially different,identification zones (40) inside the monitored zone.
8. Method according to any of the previous claims, wherein the access to the safety area (34) of the machine (30) is protected by one or more safety devices (36) controlled by the server of the RTLS or by the machine’s controller (32), and wherein step c) of changing safety function(s) of the safety area (34) comprises muting the RTLS or muting the one or more safety devices (36).
9. Method according to any of the previous claims, wherein the identification zone (40) is a geofenced zone defined by the RTLS.
10. System for controlling the access of an object or a person (20) in a safety area (34) of a machine (30) according to an access policy, comprising: - a real-time location system, “RTLS”, comprising a server (102) and a plurality of radio stations (104), each radio station being operatively connected to the server (102); - one or more tags (202) suitable for being attached to the object or person (20), each tag being configured to exchange data with the plurality of radio stations (104), including a processor and being uniquely identified by a unique identification information (ID); - a machine’s controller (32) configured to control the machine (30) and operatively connected to the server(102) of the RTLS; - at least one safety device (36) suitable for controlling the access to the safety area (34) and operatively connected to the server (102) of the RTLS and / or to the machine’s controller (32), wherein: - the server (102) of the RTLS is configured to receive from the radio stations (104) information about the position of each tag (202) and the unique identification information (ID) of each tag (202) and to compare the detected position and the detected unique identification information with an expected position and with an expected unique identification information, respectively; - the machine’s controller (32) and the processor of each tag (202) are configured to implement a challenge- response OTP algorithm; - the machine’s controller (32) or the server (102) of the RTLS is further configured to change at least a safety function of the safety device (36) on the base of the results of the comparison between the detected position and the detected unique identification information with the expected position and with the expected unique identification information, respectively, and of the challenge-response OTP algorithm.
11. System according to claim 10, wherein a private keyis associated to each tag (202), and wherein the processor of each tag is configured to apply a cryptographic function to the OTP using the private key and to send the encrypted OTP to the server (102) of the RTLS.
12. System according to claim 11, wherein the machine’s controller (32) is configured to generate a OTP, apply a cryptographic function to each generated OTP using the same private key used by the respective tag (202), receive from each tag the encrypted OTP, compare each received encrypted OTP with the respective encrypted generated OTP.
13. System according to any of the claims 10-12, wherein the server (102) of the RTLS is further configured to send the machine’s controller (32) a request signal including an indication of each tag (202) to be authenticated and / or of the respective private key to be used.
14. System according to any of the claims 10-13, wherein the safety device (36) is a laser scanner or a safety radar or a safety light curtain.
Citation Information
Patent Citations
Safety system and method for localizing a person or object in a monitored zone using a safety system
US20210232102A1
Remote control of a mobile user device to access a physical area
US20200260226A1
Systems, methods, and devices for access control
US20210383624A1
User authentication at access control server using mobile device
US20230062507A1