Security installations and authentication tokens therefor

The security installation authentication token, with an adhesive sticker or case for mobile phones, addresses the challenge of user authentication by transmitting encrypted signals through an integrated circuit with ferrite material to reduce interference, ensuring reliable operation and convenience.

WO2025141191A1PCT designated stage expired Publication Date: 2025-07-03VERISURE SARL
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2024/088634
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-30
Filing Date
2024-12-30
Publication Date
2025-07-03

AI Technical Summary

Technical Problem

Existing security monitoring systems face challenges in conveniently authenticating users at access devices, particularly when battery power is insufficient or when metal components interfere with antenna performance.

Method used

A security installation authentication token in the form of an adhesive sticker or case for mobile phones, equipped with an antenna and integrated circuit, which transmits an encrypted authentication response via the antenna, and includes ferrite material to reduce interference from metal components.

Benefits of technology

Provides convenient user authentication without requiring a special app, ensures reliable operation even with low battery power, and minimizes interference from metal surfaces, enhancing security system functionality.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2024088634_03072025_PF_FP_ABST
    Figure EP2024088634_03072025_PF_FP_ABST
Patent Text Reader

Abstract

Provided is a security installation authentication token (300), the token in the form of an adhesive sticker for adhesive attachment to a carrier object, the carrier object optionally a mobile phone, the adhesive sticker comprising an adhesive layer (302), and a substrate sheet (304) carrying an antenna (306a, 306b) and an integrated circuit (308) coupled to the antenna, the integrated circuit configured to be electrically powered by a signal received via the antenna and to transmit an authentication response via the antenna Also provided is a security installation authentication token, the token in the form of a case or housing for mounting to or receiving a mobile phone that has its own housing, the case or housing carrying an antenna and an integrated circuit coupled to the antenna, the integrated circuit configured to be electrically powered by a signal received via the antenna and to transmit an authentication response via the antenna.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Security installations and authentication tokens therefor

[0002] Technical field

[0003] The present invention relates to security installations to secure at least part of a perimeter of premises and to monitor premises, techniques for authenticating a user desiring to access the security installation, and to methods performed by the system and by controllers of the system.

[0004] Background

[0005] Security installations that are or include security monitoring systems for monitoring premises, often referred to as alarm systems, typically provide a means for detecting the presence and / or actions of people at the premises, and reacting to detected events. Commonly such systems include sensors to detect the opening and closing of doors and windows to provide a secure perimeter to the premises, creating one or more protected interior spaces, movement detectors to monitor spaces (both within and outside buildings) for signs of movement, microphones to detect sounds such as breaking glass, and image sensors to capture still or moving images of monitored zones. Such systems may be self-contained, with alarm indicators such as sirens and flashing lights that may be activated in the event of an alarm condition being detected. Such installations typically include a control unit (which may also be termed a central unit), generally mains powered, that is coupled to the sensors, detectors, cameras, etc. (“nodes”), and which processes received notifications and determines a response. The central unit may be linked to the various nodes by wires, but increasingly is instead linked wirelessly, rather than by wires, since this facilitates installation and may also provide some safeguards against sensors / detectors effectively being disabled by disconnecting them from the central unit. Similarly, for ease of installation and to improve security, the nodes of such systems typically include an autonomous power source, such as a battery power supply, rather than being mains powered.

[0006] As an alternative to self-contained systems, a security monitoring system may include an installation at a premises, domestic or commercial, that is linked to a remote Central Monitoring Station (CMS) where, typically, human operators manage the responses required by different alarm and notification types. In such centrally monitored systems, the central unit at the premises installation typically processes notifications received from the nodes in the installation, and notifies the Central Monitoring Station of only some of these, depending upon the settings of the system and the nature of the detected events. In such a configuration, the central unit at the installation is effectively acting as a gateway between the nodes and the Central Monitoring Station. Again, in such installations the central unit may be linked by wires, or wirelessly, to the various nodes of the installation, and these nodes will typically be battery rather than mains powered.

[0007] Such security monitoring systems contribute to the safety and wellbeing of occupants of the protected premises, as well as safeguarding articles within the protected perimeter - which may of course not simply be limited to a house or dwelling, but may also extend to the grounds of the house, protected by a boundary fence and gate, for example.

[0008] One technical challenge is how to conveniently authenticate a user at an access device of an installation.

[0009] Embodiments of the present invention seek to provide enhanced security monitoring systems, devices, and corresponding apps, methods and other implementations that improve the scope of security monitoring systems to address aspects of the problem of how to conveniently authenticate a user desiring to access the security installation, as well as providing new functionality and methods.

[0010] Summary of the invention

[0011] According to a first aspect, there is provided a security installation authentication token, the token in the form of an adhesive sticker for adhesive attachment to a carrier object, the carrier object optionally a mobile phone, the adhesive sticker comprising an adhesive layer, and a substrate sheet carrying an antenna and an integrated circuit coupled to the antenna, the integrated circuit configured to be electrically powered by a signal received via the antenna and to transmit an authentication response via the antenna.

[0012] Such an authentication token can be attached to, for example, a user’s mobile telephone, to provide a convenient manner of authentication at a security installation, without requiring a special software application or virtual token in the user’s mobile telephone itself. A mobile telephone is convenient because, often, a user will have his or her mobile telephone to hand quickly, for example, more quickly than looking for, for example, a set of keys. Providing the token as a discreet adhesive sticker can also make the token more readily available than running an app or finding and displaying a virtual token; moreover, such a token will also permit access to the protected premises even in the event that the battery of the mobile phone or other carrying device has insufficient power to enable an installed app or the like to be used.

[0013] Preferably, the token comprises ferrite material in a layer over one face of the antenna of the token, for screening the antenna of the token from interference. This can enable the token to be adhered to a metal, or metal containing, carrier object, such as a mobile telephone, without the metal interfering significantly with the antenna performance. In some examples, the ferrite material may be positioned in a layer between the antenna and the adhesive. Additionally or alternatively, the ferrite material may be positioned at least partly within an adhesive layer.

[0014] According to a second aspect, there is provided a security installation authentication token, the token in the form of a case or housing for mounting to or receiving a mobile phone that has its own housing, the case or housing carrying an antenna and an integrated circuit coupled to the antenna, the integrated circuit configured to be electrically powered by a signal received via the antenna and to transmit an authentication response via the antenna.

[0015] In a token according to the second aspect, the case or housing may have an inner face that in use faces the mobile phone when housed or received in the case, and an outer face that is exposed in use, the antenna being positioned between the inner and outer faces. Optionally a ferrite layer is provided between the antenna and the inner face, for screening the antenna from interference.

[0016] In the illustrated embodiment, the layer of ferrite material comprises a clearance at the position of the integrated circuit. The integrated circuit can be positioned to be at least partly inside the clearance.

[0017] The security installation authentication token may further comprise a protective encapsulation deposited over the integrated circuit and a neighbouring portion of the substrate, the encapsulation positioned to be at least partly within the (or a) clearance of the layer of ferrite material. Such arrangements can provide a low profile device, such that the ferrite material does not significantly increase the thickness. The height of the integrated circuit and / or encapsulation is accommodated at least partly within the thickness of the ferrite material.

[0018] In some embodiments, the clearance comprises an aperture in the layer of ferrite material.

[0019] In any of the designs of the first aspect, the integrated circuit may be configured to store a secret key, and to generate an encrypted authentication signal using the secret-key. The encryption may optionally use (i) a symmetric -key algorithm, for example, Rijndael encryption, or (ii) an asymmetric-key algorithm. An encrypted authentication signal is more secure than a non-encrypted signal, because it is significantly more difficult to mimic or replicate. Depending on the installation, where the authentication token is in the form of a sticker it may be intended to be removable and re-usable. The adhesive may be of a type that is peelable and re-sealable. Alternatively, the authentication token sticker may be intended for adhesive attachment only once. In that case the adhesive may be of a single-use type that is not re-adherable for re-use. The authentication token sticker may also include a frangible portion intended to break when the token is (e.g. forcibly) removed, the frangible portion thereafter rendering the authentication token inoperable. For example, the frangible portion may be part of the antenna track, or it may part of a guard track.

[0020] In a third aspect there is provided a kit comprising an authentication token according to the first aspect, and (e.g. printed) instructions indicating at least one of: (i) recommended placement sites for placement of the adhesive sticker on a mobile telephone; and / or (ii) placement sites on a mobile telephone at which to avoid placing the adhesive sticker.

[0021] This aspect of the invention appreciates a technical problem that it is undesirable for the adhesive sticker to be positioned such that the antenna overlaps an NFC antenna of the mobile telephone. Overlapping may result in interference that prevents one or both the authentication token, and the NFC function of the mobile telephone, from functioning. The instructions may be generic for several models of mobile telephone, or the instructions may indicate different placement positions for different models of mobile telephone.

[0022] Optionally printed instructions could be provided for each of a plurality of different phone makes / models. Optionally a visual placement guide may be provided, e.g. via a website (e.g. accessed via a QR-code or the like provided with the sticker) that a user can visit, and enter a phone’s make / model to get guidance, optionally visual guidance for example in the form of video instructions or other pictorial guidance. The QR code or other code could for example be in an instruction sheet, or printed on the peel-off protection film initially covering the adhesive on the rear of the sticker.

[0023] Additionally or alternatively, an app could be provided that a user can install on the mobile telephone or other device, the app being provided with access to the phone’s or other device’s NFC antenna, and using the phone ’s / device’s NFC antenna, measure either NFC signal communication with the sticker, or with another NFC device with the sticker in place (but not stuck down - e.g. with the adhesive still protected by a protective film) so that user can manually choose a non-interfering or least-interfering position.

[0024] A closely related aspect also provides a mobile telephone comprising an NFC antenna, and an authentication token according to any preceding aspect, the token adhered to the case of the mobile telephone at a position such that the antenna of the token does not overlap the NFC antenna of the mobile telephone.

[0025] According to a further aspect, there is provided a security installation authentication token, the token formed on or in a cover for a mobile phone or other portable wireless transmit / receive unit, the cover being configured to be releasably mounted to the mobile phone or other portable wireless transmit / receive unit (i.e. to or about the native cover or housing of the device), the cover including an antenna and an integrated circuit coupled to the antenna, the integrated circuit configured to be electrically powered by a signal received via the antenna and to transmit an authentication response via the antenna.

[0026] The cover may include an inner face that in use lies adjacent the outer surface of the (native case or housing) of the mobile telephone or other WTRU device, the cover further including a layer of ferrite material positioned between the inner face and the antenna of the case. That is, the case may have an inner face and an outer face, the antenna lying between the inner and outer faces, and a ferrite layer being provided between the inner face and the antenna. The ferrite material would reduce radio signal interference between the NFC antenna of the case and the NFC antenna(s) in the phone.

[0027] The cover may be formed in one piece and include a recess into which the mobile phone or other portable wireless transmit / receive unit can be received, and optionally the cover is formed from or includes a resilient material whose resilience serves to retain the cover to the mobile phone or other portable wireless transmit / receive unit.

[0028] Alternatively, the cover may be made of two or more parts (e.g. co-operating parts) which may be secured together (e.g. that clip or otherwise fasten together) about the housing of the phone or other device, to at least partially enclose the mobile phone or other portable wireless transmit / receive unit.

[0029] The cover may include a generally planar part that in use covers, in whole or in part, a rear face of the mobile phone or other portable wireless transmit / receive unit, the antenna being formed on or in the generally planar part.

[0030] According to a further aspect there is provided an NFC “token” (which could be a sticker, or a tag (e.g. a passive key-fob) or a cover substantially as previously described) which communicates with an NFC reader of a security and / or alarm system using an encrypted NFC protocol (a processor in the token using a stored secret key to process a challenge and / or to encrypt the NFC token code, and to transmit a message without directly transmitting the key.

[0031] A further aspect of the invention provides apparatus comprising: an authentication token according to any of the above; and a security installation for protecting a premises, the security installation having a disarmed state and at least one armed state, the security installation comprising: an access device comprising a wireless transceiver for communicating wirelessly with the token when the token is brought close to the access device, wherein the security installation is configured to determine whether an authentication signal received from the token is authentic, for requesting one or more of: setting of the security installation in an armed state; setting of the security installation in a disarmed state; setting an electronically controlled door-lock to a locked state; setting an electronically controlled door- lock to an unlocked state.

[0032] The security installation may optionally be configured to store a respective secret key for each authentication token with which the security installation is intended to authenticate.

[0033] The security installation may further comprise a central unit communicating with the access device, and wherein the central unit stores a list of permissions associated with a respective authentication token.

[0034] Description of Figures

[0035] Embodiments of the invention will now be described, by way of example only, with reference to the accompanying drawings, in which:

[0036] Figure 1 is a schematic drawing showing a front elevation of stylised building with an external space which is monitored by a security monitoring system according to an embodiment of the invention;

[0037] Figure 2 is a schematic part plan view of premises protected by a security monitoring system, together with other elements of the system;

[0038] Figure 3 is a schematic rear view of a user device (mobile telephone) and a kit including an adhesive sticker authentication token and placement instructions;

[0039] Figure 4 is a schematic section view illustrating functional layers of the authentication token;

[0040] Figure 5 is a schematic plan view looking at a portion of the authentication token layers from the arrows 5-5 of Figure 4; and

[0041] Figure 6 is a schematic perspective view of the antenna and integrated circuit arrangement within the authentication token.

[0042] Specific description

[0043] Figure 1 shows a view of the front of a premises 100 protected by a security monitoring system according to an aspect of the present invention. The premises, here in the form of a house, have an exterior door, here front door, 102. The door gives access to a protected interior space. The security monitoring system secures at least part of a perimeter to the premises 100, and the door constitutes an exterior closure 102 in the secure perimeter giving access to a protected interior space 200 of the premises. A lock 104 on the exterior door is optionally electrically controlled so that it can be locked and unlocked remotely.

[0044] To the side of the door, on the facade of the house, is a first video camera in the form of a video doorbell 106 which looks out from the facade of the premises so that anyone approaching the door along the path 108 can be seen, and in particular when a visitor stands at the door their face should clearly be visible. The video doorbell includes an actuator, e.g. a push button, for a visitor to indicate their presence at the closure. The video doorbell also includes an audio interface to enable bidirectional audio communication with a visitor at the closure 102.

[0045] As is conventional, the video doorbell preferably includes an infrared light source to illuminate whatever is in front of the video doorbell. Optionally, as shown, the facade of the house also carries an external access device 110, for example a keypad, by means of which a user can manually authenticate himself (or herself) for disarming the security monitoring system, and unlocking the lock 104. Also shown is an optional second video camera 112 which is coupled to a presence and / or movement detector 114. The detector may optionally be a thermal detector, for example a PIR sensor. The second video camera 112 may be arranged when the security monitoring system is armed, to capture video of the front of the house and the private area, e.g. the garden, in front of the house and signal an alarm event to a controller of the security monitoring system. As with the doorbell camera, the second video camera is preferably provided with an audio interface 116 to enable bidirectional audio communication with anyone observed by the second video camera. Although the first video camera is illustrated in the form of a video doorbell, the first video camera may additionally or alternatively have the features described above for the second video camera, whether or not plural video cameras are used. Also, although the access device 110 is illustrated to be distinct from the video doorbell 106, in some embodiments, the access device 110 and the video doorbell 106 may be integrated (e.g. incorporated one within the other, or together).

[0046] Figure 2 is a schematic part plan view of a premises 100 protected by security monitoring system according to an aspect of the invention, together with other elements of the system, corresponding generally to the premises of figure 1. The front door 102, with electrically controlled lock 104, leads into the protected interior space 200 of the premises. Each of the windows 202, and the rear door 204 is fitted with a sensor 206 to detect when they are opened. Each of the sensors 206 includes a radio transceiver to report events to a controller, or central unit, 208 of the security monitoring system (which may, as shown be located at the protected premises, but which may equally be located remote from the premises - the nodes and the controller 208 communicating for example using a3G loT protocol (such as NB-IoT, LTE-M, CAT-MI) or other LPWAN protocol).

[0047] If one of the sensors 206 is triggered when the system is armed, a signal is sent to the central unit 208 which in turn may signal an alarm event to a remote central monitoring station 210. The central unit 208 is connected to the remote central monitoring station 210 via the Internet 212, either via a wired or a wireless connection.

[0048] Also wirelessly coupled to the central unit 208 are the video doorbell 106, the electrically controlled lock 104, and if present the second video camera 112, its associated presence and / or movement detector 114 (although the latter may be integral with the second video camera 112) and the audio interface 116. These items, and the sensors 206, are preferably coupled to the central unit 208 using transceivers operating in the industrial scientific and medical (ISM) bandwidths, for example a sub-gigahertz bandwidth such as 868 MHz, or using e.g. LPWAN protocol if the controller 208 is located remote from the installation. The communications between the nodes and the controller, and vice versa, are encrypted preferably using shared secret keys.

[0049] The security monitoring system may also include other sensors within the protected interior space, such as an interior video camera 214 and associated movement detector 216 (which again may be integral with the camera 214), and each of the interior doors 218 may also be provided with a sensor 206 to detect the opening / closing of the door. Also shown in figure 2 are a user device 220, as will be described later, and a public land mobile network (PLMN) by means of which the central monitoring station 210, and the central unit 208, may communicate with the user device 220.

[0050] Operation of the security monitoring system may be controlled by one or more of: the controller 208, the remote monitoring station 210. For example, the remote monitoring station 210, if provided, may receive one or more signals from any of the first camera and / or video doorbell 106, the second camera 112, the access device (keypad) 110, the sensors 206 and / or 520 (e.g. via a LPWAN protocol such as one of the 3GPP loT protocols). The remote monitoring station 210 may transmit commands for controlling any one or more of: the arm state of the alarm system (e.g. armed or unarmed); commanding a tripped alarm state to be signalled by the alarm system (e.g. by triggering one or more sirens to generate alarm noise); commanding a lock state of the door lock 104 (e.g. locked or unlocked), commanding operation of one or more functions of the video doorbell 106, commanding operation of one or more cameras to transmit images to the remote monitoring unit. Communication with the remote monitoring station 210 may pass through the controller 208, as described above. In other embodiments without the remote monitoring station 210, or should communication with the remote monitoring station 210 be interrupted, operation of the alarm system may be controlled by the controller 208. In yet other embodiments, the controller 208 may be omitted, and the individual peripheral devices may communicate directly with the remote monitoring station 210.

[0051] User device 220 is here shown as a mobile telephone (e.g. smartphone), although of course it could be almost any kind of electronic device, such as a laptop or desktop computer, a tablet such as an iPad, a smart watch, or even a television.

[0052] In accordance with the principles of one aspect of the invention, an authentication token 300 is provided for permitting a user to conveniently authenticate, wirelessly, at the access device.

[0053] As best seen in Fig. 3, the authentication token 300 is provided in the form of an adhesive sticker, for adhesive attachment to a suitable carrier object, for example the user device (mobile telephone) 220. In Figure 3, the authentication token 300 is attached to the rear face of a mobile telephone 220.

[0054] Referring to Figures 4 to 6, the authentication token 300 comprises an adhesive layer sheet 304 carrying an antenna 306a, 306b (collectively 306), and an integrated circuit 308 coupled electrically to the antenna 306. In the present example, the antenna 306 includes tracks 306a and 306b on both sides of the substrate 304, and connected by one or more through-connections. The tracks 306a and / or 306b form a spiral coil (Figure 6) having a generally round profile except for an indentation to accommodate a through-connection. In one example, the coil is formed primarily by a spiral track 306a on one side (e.g. face) of the substrate 304, and a return connection from an exterior edge to an interior edge of the spiral is provided by a bridging track 306b on the opposite side (e.g. face) of the substrate 304

[0055] Also in the present embodiment, the adhesive sticker comprises a layer 310 of ferrite material, positioned to one side (on one face) of the antenna 306. Here, the ferrite layer 310 is positioned on or towards the adhesive face. The ferrite layer 310 may be a discrete layer of material between the antenna 306 and the adhesive layer 302 as shown in Figure 4, or it may be at least partly integrated into the adhesive layer. The ferrite material reduces electromagnetic interference with any metal in the carrier object (mobile telephone) 220, which might otherwise hinder operation of the antenna 306.

[0056] In order to maintain a low profile, the ferrite layer 310 includes a clearance 312, optionally an aperture, at the position of the integrated circuit 308. The integrated circuit 308 and / or an encapsulation material 314 over the integrated circuit 308, is positioned to be at least partly received within the clearance 312. Such an arrangement can accommodate the height of the integrated circuit 308 and / or encapsulation 314 at least partly within the thickness of the ferrite material layer 310, thereby avoiding the ferrite material from significantly adding to the thickness of the token 300. The clearance 312 may be offset with respect to a geometric centre of the ferrite layer and / or the antenna. Additionally or alternatively, the clearance may be larger in size than the size of the integrated circuit and / or the encapsulation material, but not so large that the antenna 306 is substantially uncovered.

[0057] The encapsulation material 314, where provided, may be deposited over the integrated circuit 308 and a neighbouring zone of the substrate 304 and / or a track 306a of the antenna. The encapsulation material 314 may protect the integrated circuit, as well as aiding resistance to penetration by humidity and / or liquids.

[0058] The token 300 may comprise additional layers (not shown), for example, insulation and / or separation layers (or sheets or films). By way of example, a cover sheet 316 is illustrated as providing an exterior face of the token 300. Although in Fig. 4, all layers are illustrated to be generally coterminous at their extremities, this is merely for the sake of illustration. One or more layers may extend beyond a peripheral extremity of one or more other layers.

[0059] The integrated circuit 308 is configured to be electrically powered by a signal received via the antenna 306 and to transmit an authentication response via the antenna 306. In the present example, the integrated circuit 308 is configured to store a secret key, for example, unique to the individual token 300. The integrated circuit may be further configured to generate an encrypted authentication signal using the secret key. An encrypted authentication signal is more secure than a non-encrypted signal, because it can be significantly more difficult to mimic or replicate. Various types of encryption may be used. For example, The encryption may optionally use (i) a symmetric-key algorithm, for example, Rijndael encryption and / or Advanced Encryption Standard (AES) encryption, or (ii) an asymmetric-key algorithm. A symmetric-key algorithm can use the same secret key for both encryption and decryption. An asymmetric-key algorithm may instead use a public -private key pair.

[0060] When attaching the token 300 to a user device including, for example, its own NFC antenna 320, it can be important to position the token 300 with respect to the housing or case of the user device, such that the antenna 306 of the token 300 does not overlap that NFC antenna 320. Overlapping may interfere with operation of the NFC function of the user device, and / or may interfere with operation of the token 300. The ferrite material (if provided) may reduce interference affecting operation of the token 300, but the effect of the 10 ferrite material may nevertheless shield or block the NFC antenna of the user device.

[0061] The token 300 may be provided as part of a kit 324 that also includes instructions 322, e.g. printed instructions in a document or leaflet. The instructions 322 indicate at least one of: (i) recommended placement sites for placement of the adhesive sticker on a (particular) user device (e.g. mobile telephone); and / or (ii) placement sites at which to avoid placing the adhesive sticker on the user device (e.g. mobile telephone). The instructions 322 may be generic for several models of mobile telephone, or the instructions may indicate different placement positions for different models of mobile telephone.

[0062] Depending on the implementation, the authentication token 300 may be intended to be removable and re-usable. The adhesive 302 may be of a type that is peelable and re-sealable. Alternatively, the authentication token 300 may be intended for adhesive attachment only once. In that case the adhesive 302 may be of a single-use type that is not generally re- adherable for re-use. The authentication token 300 may also include a frangible portion intended to break when the token is (e.g. forcibly) removed, the frangible portion thereafter rendering the authentication token 300 inoperable. For example, the frangible portion may be part of the antenna track 306, or it may part of a guard track (not shown) also coupled to the integrated circuit.

[0063] The access device 110 of the installation comprises a wireless transceiver for communicating wirelessly with the token 300 when the token is brought close to the access device. The system, for example, the access device 110 and the central unit, is configured to determine whether an authentication signal received from the token 300 is authentic. For example, authentication may be needed and / or may enable, one or more of: setting of the security installation in an armed state; setting of the security installation in a disarmed state; setting an electronically controlled door-lock to a locked state; setting an electronically controlled door- lock to an unlocked state.

[0064] According to an aspect of the invention there is provided a system in which NFC data are read from a portable token (e.g. provided in a sticker or case applied to a carrier such as a mobile phone or other portable WTRU) and decrypted by a reader that is part of a security monitoring installation, and transmitted to a controller (e.g. a central unit) of the security monitoring installation, and / or optionally to a remote system back-end. The controller (e.g. CU) or back end having (or having access to) a master-list of NFC devices allowed to authenticate on a specific reader of an installation, and a master-list of permissions associated with the NFC token. Permission may be arm / disarm for an installation, and / or lock / unlock for an electronically controlled lock. Permission may be temporary only. Permissions may be deactivated if the NFC token is reported lost. In such a system a user presenting an NFC token to a reader may be given no indication of the arm state of the installation prior to authentication. The NFC token may also need to go through an enrolment process to be enrolled at an installation.

[0065] Although certain embodiments have been described above, this is merely by way of example, and does not limit the scope of protection.

Claims

Claims1. A security installation authentication token, the token in the form of an adhesive sticker for adhesive attachment to a carrier object, the carrier object optionally a mobile phone, the adhesive sticker comprising an adhesive layer, and a substrate sheet carrying an antenna and an integrated circuit coupled to the antenna, the integrated circuit configured to be electrically powered by a signal received via the antenna and to transmit an authentication response via the antenna.

2. A token according to claim 1, comprising ferrite material in a layer over one face of the antenna, for screening the antenna from interference.

3. A token according to claim 2, wherein the ferrite material is positioned in a layer between the antenna and the adhesive.

4. A token according to claim 2 or 3, wherein the ferrite material is positioned at least partly within an adhesive layer.

5. A security installation authentication token, the token in the form of a case or housing for mounting to or receiving a mobile phone that has its own housing, the case or housing carrying an antenna and an integrated circuit coupled to the antenna, the integrated circuit configured to be electrically powered by a signal received via the antenna and to transmit an authentication response via the antenna.

6. A token as claimed in claim 5, wherein the case or housing has an inner face that in use faces the mobile phone when housed or received in the case, and an outer face that is exposed in use, the antenna being positioned between the inner and outer faces.

7. A token as claimed in claim 6, wherein a ferrite layer is provided between the antenna and the inner face, for screening the antenna from interference.

8. A token as claimed in any one of the preceding claims, wherein the layer of ferrite material comprises a clearance at the position of the integrated circuit.

9. A token according to claim 8, wherein the integrated circuit is positioned to be at least partly inside the clearance.

10. A token according to any preceding claim, further comprising a protective encapsulation deposited over the integrated circuit and a neighbouring portion of the substrate, the encapsulation positioned to be at least partly within the or a clearance of the layer of ferrite material.

11. A token according to claim 9 or 10, wherein the clearance comprises an aperture in the layer of ferrite material.

12. A token according to any preceding claim, wherein the integrated circuit is configured to store a secret key, and to generate an encrypted authentication signal using the secret-key.

13. A token according to claim 12, wherein the encryption uses (i) a symmetric key algorithm, for example, Rijndael encryption, or (ii) an asymmetric key algorithm.

14. A kit comprising an authentication token according to any of claims 1 to 4, or any of claims 8 to 13 as dependent on any of claims 1 to 4, and written instructions indicating at least one of: (i) recommended placement sites for placement of the adhesive sticker on a mobile telephone; and / or (ii) placement sites at which to avoid placing the adhesive sticker on the mobile telephone.

15. A mobile telephone comprising an NFC antenna, and an authentication token according to any preceding claim, the token secured to the case of the mobile telephone at a position such that the antenna of the token does not overlap the NFC antenna of the mobile telephone.

16. Apparatus comprising: an authentication token according to any of claims 1 to 13; and a security installation for protecting a premises, the security installation having a disarmed state and at least one armed state, the security installation comprising:an access device comprising a wireless transceiver for communicating wirelessly with the token when the token is brought close to the access device, wherein the security installation is configured to determine whether an authentication signal received from the token is authentic, for requesting one or more of: setting of the security installation in an armed state; setting of the security installation in a disarmed state; setting an electronically controlled door-lock to a locked state; setting an electronically controlled door- lock to an unlocked state.

17. Apparatus according to claim 16, wherein the security installation is configured to store a respective secret key for each authentication token with which the security installation is intended to authenticate.

18. Apparatus according to claim 16 or 17, wherein the security installation comprises a central unit communicating with the access device, and wherein the central unit stores a list of permissions associated with a respective authentication token.

Citation Information

Patent Citations

  • Intelligent traffic card functional module stuck on mobile electronic equipment

    CN203825655U

  • Sticker with built-in RF communication module

    KR200372017Y1

  • Payment skin with contactless chip

    US20100148928A1

  • Payment-enabled mobile telephone assembly

    US20120122520A1

  • Wireless Bidirectional Communications between a Mobile Device and Associated Secure Element using Inaudible Sound Waves

    US20130203345A1