Computer-implemented method, device and system for controlling and certifying access to a home
The method and device use biometric and positional data to verify and certify access to homes, addressing the issue of identity verification in existing systems by ensuring secure and reliable access records through blockchain technology.
Patent Information
- Application Number
- PCT/ES2025/070018
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-01-17
- Filing Date
- 2025-01-17
- Publication Date
- 2025-07-24
AI Technical Summary
Existing access control systems for homes lack reliable verification of the identity of individuals due to the transferable nature of security devices, such as passwords and cryptographic keys, making it impossible to guarantee the identity of the person accessing the home.
A method and device that utilize biometric and positional data to verify the identity of an individual within a specific location, generating a data set that is transmitted to a second device for certification, potentially using blockchain technology for decentralized and immutable record-keeping.
Enhances security by ensuring the identity and location of the person accessing the home are verified simultaneously, providing a reliable and tamper-proof record of access, reducing storage costs and computational vulnerabilities.
Smart Images

Figure ES2025070018_24072025_PF_FP_ABST
Abstract
Description
[0001] COMPUTER, DEVICE, AND SYSTEM IMPLEMENTED METHOD FOR CONTROLLING AND CERTIFYING ACCESS TO A HOME
[0002] FIELD OF INVENTION
[0003] The present invention falls within the field of home automation and access control for people in certain areas. More specifically, the invention falls within the field of controlling and certifying access for people in areas such as, for example, homes. The present invention relates to computer-implemented methods, devices, systems, and software that allow controlling access for people to certain areas, preferably allowing spatial and temporal certification of that access, preferably in an unalterable and reliable manner.
[0004] BACKGROUND
[0005] The regular or occasional use of homes has increasingly greater legal, tax, and other implications.
[0006] For years, improvements have been made to automated people control systems in areas such as parking lots, buildings, and even homes, to achieve not only improved detection and identification of people entering these areas but also improvements in enabling the certification of such access.
[0007] Examples of these access control procedures and systems would be those described in patent CN108632254A, relating to a method and access control system for a domestic environment that allows the identification of owner users and visitors and keeps a record of the accesses of both profiles using blockchain technology, or those described in patent US20170279801 A1, relating to a system and method for providing verification of the identity of people, based on various biometric data, also through the use of blockchain technology.
[0008] A serious disadvantage of the aforementioned state-of-the-art solutions is the linking of blockchain digital identities to natural persons, and the fact that these individuals are the owners and possessors of the keys that enable the necessary security mechanisms to be implemented in the information exchange processes that occur during access control to homes. Thus, due to the possession of security keys by users, while secure access control is possible, it is not possible to certify or guarantee the identity of the person or persons accessing the device. This could be any other person who has legitimately or unlegitimately received these security keys.
[0009] Another disadvantage of existing solutions is that security mechanisms (e.g., passwords, cryptographic keys, smartphones, NFC cards, etc.) are or could be in the hands of users. Because these mechanisms are easily transferable, the identity of the person entering a home cannot be guaranteed.
[0010] It would be advisable to improve state-of-the-art solutions to increase the security of the control and certification carried out.
[0011] DESCRIPTION OF THE INVENTION
[0012] The present invention relates to computer-implemented methods, devices, systems, and software. Aspects of the present invention allow, for example, the control and certification of access to an area such as a dwelling at a given instant or time period, i.e., spatiotemporally. Access may be granted, for example, by at least one authorized person in a given dwelling; the at least one person may be authorized by being registered in an access control device or system.
[0013] A first aspect of the invention relates to a method for controlling and certifying access to a home, the method comprising the following steps performed by a first device in the home: obtaining at least one biometric data of a person; performing a biometric identification by comparing this at least one biometric data of the person with at least one predetermined biometric data recorded in the first device, the at least one predetermined biometric data being representative of a predetermined person and; obtaining at least one positioning data from the first device; performing a positional identification by comparing this at least one positioning data with at least one predetermined positioning data recorded in the first device, the at least one predetermined positioning data being representative of the home and;generating a data set when predetermined requirements are met, which at least include: the biometric identification performed corresponds to the predetermined person; and the positional identification corresponds to the dwelling; the generated data set being at least identifying the person and a location of the first device, and the data set comprising an instant or time period in which the person was identified with the biometric identification; and transmitting the generated data set to a second device for certified registration of the data set, the transmission being through a data connection of the first device.
[0014] In this way, the first device is capable of performing and carrying out an access check of a person in a home, verifying both the person's biometric identity and the positional identity of the home, linking these identifications over time, and also through a digital record certified by the second device.
[0015] In certain embodiments, this second device is a node or element of a blockchain network, thus allowing access records of registered users who are authorized for one or several of the registered homes to be managed and stored in a decentralized manner, for example, through smart contracts.
[0016] In some embodiments, the predetermined requirements further comprise that the biometric identification and the positional identification are performed within a predetermined period of time not exceeding one minute. Preferably, in some embodiments, the predetermined period of time is not more than thirty seconds, or fifteen seconds, or ten seconds, or five seconds. More preferably, in some embodiments, the predetermined period of time is half a second or zero seconds, i.e., the identifications are performed simultaneously.
[0017] The shorter the time period for making the identifications, the greater the certainty with which the certified record made is accurate and representative of the person's position at the specific location of the positional identification.
[0018] The method may further comprise generating, by the first device, at least one piece of data indicative of erroneous identification when at least one of the predetermined requirements is not met. This data indicative of erroneous identification may take various forms or formats, such as visual, audio, or message data.
[0019] If the at least one piece of data indicative of erroneous identification has been generated, the method may comprise the first device performing at least one of: providing a human-perceptible signal indicative of erroneous identification; and / or transmitting the at least one piece of data indicative of erroneous identification to a second device and / or a third device.
[0020] The transmission of that at least one piece of data indicative of erroneous identification to a second device and / or a third device may be performed via a data connection of the first device, typically a wireless connection.
[0021] In this way, the first device can notify the person that there has been an error in the identification. In some embodiments, the method further comprises configuring the first device, and this configuring the first device comprises the following steps performed by the first device: obtaining at least one biometric data of the person and storing the at least one obtained biometric data to record the at least one predetermined biometric data of the predetermined person; and obtaining, while the first device is in the dwelling, positioning data from the first device and storing the obtained positioning data to record the predetermined positioning data.
[0022] Thanks to this configuration, the first device is linked to a person and a place, using at least one predetermined biometric data of the person and at least one predetermined positioning data representative of the place, the place being the person's home. Thus, during access logs, it is possible to verify that both conditions are met against these predetermined data.
[0023] In some embodiments, the method further comprises the following steps performed by the first device: obtaining data from the dwelling; and performing an identification of the dwelling, the identification of the dwelling comprising comparing the obtained data with predetermined data about the dwelling recorded on the first device.
[0024] In these embodiments, the predetermined requirements further comprise that the dwelling identification meets at least one predetermined dwelling requirement registered in the first device.
[0025] In some of these embodiments, the predetermined requirements include that biometric identification, positional identification, and residence identification are performed within a predetermined period of time. In some embodiments, the predetermined period of time is as described above for various embodiments, i.e., no more than one minute, thirty seconds, fifteen seconds, ten seconds, five seconds, half a second, or zero seconds.
[0026] Housing data may include at least one of: geometric data, volumetric data, or visual (i.e., optical) data based on machine learning algorithms.
[0027] In some embodiments, the home data is obtained by one or more of: an optical sensor, LiDAR, radar, one or more ultra-wide-angle (UWB and / or UWC) antennas, a time-of-flight (i.e., time-of-flight) sensor, photogrammetry, beaconing, or positioning from fixed points, among others. In some embodiments, the home data is generated by the first device, which is configured to process measurements to generate the home data.
[0028] In certain embodiments, configuring the first device comprises obtaining, by the first device while at the home, home data and storing the obtained home data to record the predetermined home data.
[0029] In this way, an additional link is established with home data, such as an image of the home's interior from the first device. This home data, which is established as default during the setup of the first device, serves as a reference for any subsequent verification of the home's interior. In this sense, the use of home data to generate the dataset increases the certainty with which the certified record is accurate and representative of the person in a specific location.
[0030] In some embodiments, the at least one biometric may be obtained as at least one of: facial recognition, eye recognition, fingerprint recognition, voice recognition, vein recognition, palm recognition, anatomical or biological recognition, multimodal recognition, behavioral recognition (e.g., one or more of: gait and movement pattern, speech and vocal traits, specific body movements, interactions with devices, and / or other traits), recognition of any other physical or physiological characteristic, or a combination thereof. In this way, the first device is versatile and may be adapted to different forms of biometrics. An advantage of using biometrics via facial recognition is that simultaneously, or quasi-simultaneously, the first device may take an image of the person whose facial biometrics are being read, and have this image registered with the user.
[0031] In some embodiments, the method further comprises the following steps performed by the first device: obtaining a data connection identification data from the first device; and performing an identification of the data connection, the identification of the data connection comprising a comparison of the obtained data connection identification data with a predetermined data connection identification data recorded on the first device.
[0032] In these embodiments, the predetermined requirements further comprise that the data connection identification meets at least one predetermined data connection requirement registered on the first device.
[0033] Advantageously, an additional verification linked to the data connection of the first device is performed. According to some embodiments, the method further comprises requesting, from the second device, one or more sets of data associated with the person, which are transmitted by the first device to the second device.
[0034] In some embodiments, the method further comprises processing, by the first device, one or more obtained and / or recorded data (e.g., biometric data, positioning data, housing data, data connection data) to generate one or more processed data by means of a cryptographic function, e.g., hash. The one or more processed data are digital fingerprints of the processed data. In some of these embodiments, the method further comprises transmitting, by the first device, the one or more processed data through a data connection of the first device. The one or more processed data may be transmitted to the second device, or to a third device (e.g., a server comprised in a system that also comprises the first device and / or the second device).
[0035] In some embodiments of the invention, the first device is a hardware module.
[0036] A second aspect of the invention relates to a device comprising means for carrying out a method according to the first aspect of the invention. In some embodiments, the means comprise, at least, at least one memory, at least one processor, communication means such as, for example, a wireless or wired data communication module, and one or more sensors for measurements that can be used, for example, for biometric identification and / or positional identification. In some cases, the communication means can be used, without or with the cooperation of sensors, to perform positional identification.
[0037] A third aspect of the invention relates to a system comprising means for carrying out a method according to the first aspect of the invention. In some embodiments, the system comprises at least one device. In some embodiments, the system comprises a plurality of devices. The device or devices may be, for example, devices according to the second aspect of the invention.
[0038] A fourth aspect of the invention relates to a computer program comprising instructions that, when executed by at least one processing device, cause the at least one processing device to perform a method according to the first aspect of the invention. In some embodiments, a non-transitory storage medium readable by a processing device comprises the computer program or computer program instructions.
[0039] Aspects of the present invention allow the presence of a specific person to be established in a given dwelling at specific times or periods of time. The person whose presence is being established, monitored, and certified must be biometrically identified by the first device while said first device is located in a specific, predetermined location. When the necessary requirements for correctly identifying the person in the dwelling are met, a data set indicative of this purpose is generated, allowing for certification of the person's presence. The present invention may be used in alarm systems installed in buildings and properties.
[0040] The certification may be certified by transmitting such data set to the second device. The second device provides, directly or indirectly, a digital logbook. To this end, the second device may be connected to or form part of a computer network with a set of electronic devices such as, for example, servers, computers, storage memories, databases, etc., that provide the necessary means to provide the digital logbook. The computer network may be centralized or decentralized. The computer network may function as or be part of an entity that certifies that the information (e.g., data sets transmitted by the first device) is authentic, both in content and in the time at which it was generated by the first device and / or received by the second device.In other embodiments, however, the second device provides the digital logbook, in which case the second device functions as or is a certifying authority. Certification may be carried out, for example, but not limited to, by means of qualified time stamps.
[0041] In some embodiments, the second device comprises storage memory and / or a database, preferably configured for immutable recording of data.
[0042] In some embodiments, the second device is connected to or part of a computing network. In some embodiments, the computing network is configured using distributed ledger technology. In some embodiments, the computing network is based on blockchain technology, such as blockchain.
[0043] The control and certification, preferably reliable, of access by authorized persons into homes is based on two stages in some embodiments. In a first stage, the first device within the home is configured. In this configuration, information is exchanged between the first device; an electronic device, which in some examples is carried by the user who may be registered in the system, such as a smartphone, a wearable device (e.g., smart watch, smart bracelets, body sensors, etc.), a fixed or mobile IoT ("Internet of Things") device, a hardware device in the home; and a server that manages the registration and authentication of users and homes registered in the system. In some cases, this configuration also involves the exchange of information through a blockchain network.The server can act as the administrator for any smart contracts during blockchain transactions.
[0044] In some embodiments, the method further comprises registering the user(s) and the dwelling in an application of a system comprising the first device. After registering and configuring the first device, an access registration phase as described above may be performed. Users perform registrations that prove their presence in said dwelling.
[0045] In some embodiments, a digital identity of a second device, which in some embodiments is part of a computer network (centralized or decentralized) that provides a digital logbook, is granted to the first device, which is the one located in the home. The first device, which may operate autonomously and may not require the intervention of third parties (i.e., persons other than the person or persons to be identified and certify their presence) for its configuration and activation, may interact with computer programs of the second device, for example, but not limited to, smart contracts for digital logbook transactions and for signing digital transactions with its own keys, which are inaccessible to anyone, including the person themselves, thus guaranteeing the veracity and integrity of the records.
[0046] Associating a digital identity with the first device, such as a hardware module, offers, in some cases, greater security by avoiding errors or vulnerability gaps introduced by human intervention and, in turn, can offer lower computational costs by simplifying encryption schemes.
[0047] The present invention can increase security and reduce storage costs compared to state-of-the-art solutions, especially when, in some embodiments, cryptographic hash functions are used, which are fixed-length strings, which allow them to be stored and transmitted to another device (e.g., the second device, a third device, a system server, etc.), including devices with distributed ledger technologies such as blockchain networks at a minimum computational cost and which, at the same time, being irreversible digital objects, ensure the privacy of user data.
[0048] In some embodiments, blockchain technology is used as a technological infrastructure for the immutable, persistent, and traceable storage of physical evidence generated within a home, both of the home itself (reference coordinates, interior images, etc.) and of the users attempting to gain access (biometric data). In this sense, the second device is part of a computational network that provides a blockchain-based digital ledger.
[0049] In the context of the present invention, access means any access and / or use and / or presence in the dwelling.
[0050] The different aspects and embodiments defined above can be combined with each other, provided they are compatible with each other.
[0051] Additional advantages and features of the present invention will become apparent from the detailed description which follows and will be particularly pointed out in the appended claims.
[0052] BRIEF DESCRIPTION OF THE FIGURES
[0053] To complete the description and to provide a better understanding of the invention, a set of drawings is provided. The aforementioned drawings constitute an integral part of the description and illustrate preferred embodiments of the invention, which should not be construed as limiting the scope of the invention but merely as examples of how the invention can be embodied. The drawings comprise the following figures:
[0054] Figure 1 is a schematic of a system according to some embodiments of the invention.
[0055] Figure 2 is a view showing a possible installation of the first device, e.g. a hardware module, within a dwelling registered in a system according to some embodiments of the invention.
[0056] Figure 3 is a block diagram of the elements that make up the first device of a system according to some embodiments of the invention.
[0057] Figure 4 is a schematic diagram of a configuration phase of a method according to some embodiments of the invention.
[0058] Figure 5 is a step diagram of an access registration phase of a method according to some embodiments of the invention.
[0059] Figure 6 is a step-by-step diagram of a method according to some embodiments of the invention.
[0060] DETAILED DESCRIPTION OF THE INVENTION
[0061] The present invention relates to a method for controlling and certifying, for example, in a reliable manner, the access of people to homes 5, by using a digital registry book such as, for example, one or more blockchain networks 6 that allow the decentralized administration and storage of smart contracts 7 of access records of registered users who are authorized for one or several of the homes 5 that have been registered.
[0062] As shown in Figure 1, in a possible implementation example of the invention, a system 1 is provided comprising the following elements:
[0063] A server 4.
[0064] A hardware module 3, arranged in a housing 5, typically inside the housing 5.
[0065] An electronic device 2 of a user, such as a smartphone.
[0066] A blockchain network 6.
[0067] Server 4, typically located remotely, is responsible for managing user registrations, as well as the registration of one or more homes linked to those users. Server 4 is also typically in contact with the blockchain network 6 to manage the registration of smart contract users 7.
[0068] In some embodiments, user and housing registrations can be performed directly on the blockchain network 6, without the need for server 4, allowing the application to be more decentralized. In such a case, the blockchain network 6 itself can be used as a database for managing user and / or housing data.
[0069] Hardware module 3 is an electronic device that can be implemented under different physical architectures. This hardware module 3 is located inside the registered dwelling 5; each hardware module 3 can be associated with one or more users. Hardware module 3 is responsible for recording accesses by authorized users, and for this purpose, data related to these accesses by authorized users is sent to the blockchain network 6, so that the record of authorized access is certified. As part of the access record, hardware module 3 is responsible for performing verifications related to the geolocation of dwelling 5 and verifying the identity of registered users, usually through biometrics. In this example, this hardware module 3 is responsible for notifying users of an intrusion when it is not in dwelling 5.As part of the tasks typically performed by this hardware module 3, it is also responsible for digitally signing messages using a private key unique to said hardware module 3, as will be explained later.
[0070] Verification relating to the geolocation of the homes 5 can be highly precise, and incorporate, among others, recognition patterns of the home 5 itself, such as point patterns or geometry of walls, furniture, columns, etc., using artificial intelligence algorithms or similar, as well as volumetric space recognition systems or those based on the emission and reception of waves.
[0071] The registered user can interact with the hardware module 3 through the electronic device 2, which acts as an interface between the user and said hardware module 3 and with other components of the system 1. The electronic device 2 is typically provided with at least one or several input / output interfaces, such as a touch screen, a keyboard, or a natural language recognition interface. The electronic device 2 is provided with the following components: a power supply battery; a microprocessor; a hard drive; and means for electronic communications. In this way, the electronic device can interact with other elements of the system to register users, to activate the dwelling 5 (or dwellings), and to receive notifications about the operation and status of the system 1.
[0072] Server 4 includes a database. According to one example of the invention, each user can register in system 1 by entering the following information fields, which are typically stored in the database: a. Name and surname of the user. b. Email address and contact telephone number. c. Photos of the front and back of the user's ID card. d. One or more dwellings 5 that said user is authorized to access. e. Type of plan contracted for the control and detection of the dwellings mentioned in point d) above within the system. f. Biometric data of the authorized person. In addition to the biometric data, an image of the user's face is obtained (for example, by taking a photo) for the initial configuration process of hardware module 3. g. The time interval in which a new access registration is allowed in dwelling 5 that the user is authorized to access.Typically, this time interval for a new registration is set to 24 hours.
[0073] The information fields indicated under points a-g are for illustrative purposes only. It may be the case that not all information fields are required to register as a user. For example, information fields e-g may not be mandatory and / or may be set by default.
[0074] The user's facial image is transmitted to server 4, where it is stored. Its hash is then calculated and stored on the blockchain network 6. This allows its integrity to be verified at any point in time, without compromising or exposing this sensitive user data.
[0075] Inside the dwelling 5 registered in the system 1, the hardware module 3 is arranged. As shown in Figure 3, in a possible implementation example, this hardware module comprises the following physical and / or logical components:
[0076] - a persistent memory 8 for the storage of digital data;
[0077] - an access register switch 9, or touch interface, or button, for user interaction with the hardware module;
[0078] - una o vahas camas 10;
[0079] - one or more biometric data collection modules 11 of persons that may incorporate identity fraud prevention systems or mechanisms, proof of life or anti-spoofing. This biometric data collection module 11 contains suitable means for capturing facial, fingerprint, ocular or any other physical or physiological characteristic biometric data of the authorized user, such as voice;
[0080] - a motion sensor 12, based on infrared, capacitive, magnetic, ultrasonic or any other type of technology;
[0081] - a power module 13, formed by a battery system that supplies the module with low voltage (for example, less than 5 V) and direct current;
[0082] - a virtual cryptographic function module 14, physically supported by a microprocessor integrated, in turn, by a microcontroller 16; this virtual cryptographic function module 14 implements a random number generator which, in combination with the microcontroller 16, is responsible for both the generation of cryptographic keys and the generation of fingerprints based on hash algorithms; this cryptographic function module is preferably a high-security cryptographic module, such as a hardware security module (HSM), TPM, TEE, SE, etc. capable of generating and storing data securely and inaccessibly;
[0083] - one or several communications modules 15, with physical and logical means that allow establishing wireless communications such as, for example, under the 802.11, Bluetooth and GSM / UMTS / LTE standards and, also, client-server communications in distributed networks such as, for example, under the HTTP, HTTPS, JSON-RPC, SMTP, SSL, SSH, FTP protocols;
[0084] - the microcontroller 16, in which the microprocessor is integrated;
[0085] - one or more LED devices 17 to indicate the operating status of the hardware module 3;
[0086] - a high-precision geopositioning module 18, responsible for geopositioning using a geopositioning technology such as GPS, GSM, GNSS, GLONASS, Galileo, BeiDou, EGNOS or other satellite-based geopositioning technologies, or Wi-Fi-based positioning technologies, or ultrasound positioning technology, or by cellular triangulation, or by Bluetooth or Bluetooth Low Energy (BLE) beacons, etc.
[0087] - a virtual blockchain transaction module 19, integrated into the microcontroller 16, which is responsible for building and encoding the blockchain transaction objects whose data are, for example, the method and / or parameters of the smart contract 7 recipient of said transaction, and which may also include data related to the verification of the successful access record of the person in the home 5.
[0088] - an ignition switch 20.
[0089] In an exemplary embodiment of the method for controlling and certifying access to a dwelling 5, the method records the accesses of the authorized user in the dwelling 5; typically, this access record is performed at a specific iteration, which may be once a day (i.e., for example, every 24 hours, or as established in information field g).
[0090] Initial setup phase
[0091] After the user has registered and verified, for example, by means of the electronic device 2 through an application on the server 4, the possibility of configuring the hardware device 3 in the home 5 is enabled. Normally through a wireless connection, the hardware module 3 receives from the electronic device 2, for example, through an application on the electronic device 2, a registration identifier of the user and the home 5, which allows verifying that it is possible to carry out the configuration and establishing an information storage location on the server 4.
[0092] This wireless connection between the electronic device 2 (e.g., a mobile phone or smartphone) and the hardware module 3 can be established via Wi-Fi, in which case the hardware module 3 is automatically configured in Wi-Fi access point mode. An access logging application installed on the user's electronic device 2 detects the name of the Wi-Fi network (SSID) and connects to the Wi-Fi network of the hardware module 3.
[0093] Using electronic device 2, the user enters the credentials for the home's WIFI network 5 into the access registration application on their device, and hardware module 3 connects to said WIFI network. If the connection is successful, the credentials for the home's WIFI network 5 are stored in persistent memory 8 of hardware module 3. Other data, such as the registration period (the time interval during which a new registration is permitted, typically set to 24 hours) and the number of residents in home 5, are also transferred to hardware module 3. During the initial configuration phase, the user performs a biometric registration with hardware module 3 using proof-of-life techniques, thus preventing the use of images, videos, photographs, etc.For example, biometric enrollment can be performed with measurements from one or more of the following: RGB camera, IR camera, RGB and IR camera, 3D camera, video camera, LiDAR sensor, optical sensor, capacitive sensor, ultrasonic sensor, microphone, etc.
[0094] The biometric record is stored as default biometric data in persistent memory 8 of hardware module 3, preferably using high-security encryption. In this regard, the biometric record can be stored using a cryptographic key generated randomly and securely in a cryptographic module 14. In this way, it is possible to perform biometric identification of the user at each access record, checking whether the biometric data obtained by hardware module 3 corresponds to the default biometric data.If the biometric identification is successful, the initial configuration of the hardware module 3 continues; otherwise, the configuration of the hardware module 3 may be restarted, the hardware module 3 may be temporarily or indefinitely locked until it receives a reboot instruction or a summary of its functions, and / or a notification of unsuccessful biometric identification may be recorded (and optionally transmitted). In addition to capturing at least one biometric data item of the user, a photograph of the user's face is taken during the initial configuration phase, preferably within a short period of time, and more preferably simultaneously.This photo—which may correspond to the image of the default biometric data in the case of facial biometrics—is stored on server 4, and a fingerprint of said photo may be stored on a second device such as the blockchain or other network, in case the second device is part of or connected to a network that generates a digital ledger.
[0095] The hardware module 3 obtains at least one piece of information about its position, for example, by making a request via an application programming interface such as, but not limited to, the Google Maps API, to obtain positioning data; this geolocation data, assuming it is performed correctly, is stored (typically in the form of coordinates) in the persistent memory 8 as predetermined and representative positioning data for the dwelling 5 in which the hardware module 3 is located.
[0096] That is, in the initial configuration phase, hardware module 3 is linked to the user and to the home 5.
[0097] The hardware module 3, through a cryptographic functions module 14 thereof, generates a random 256-bit private cryptographic key, which consists of a number between 1 and (2 256 -1), expressed as a 64-character hexadecimal string. This private key is stored encrypted in the cryptographic function module 14, preferably in persistent memory, or in persistent memory 8 of the hardware module 3, in a manner inaccessible to third parties. The private key grants the device its identity or unique character and allows it to digitally sign data transactions, thereby verifying the origin and integrity of the information and preventing all types of fraud.
[0098] Hardware module 3 derives the public key from the private key using public-key cryptography, such as RSA or elliptic curve algorithms. If the secp256k1 elliptic curve algorithm is used, the public key consists of a 512-bit number expressed as a 128-character hexadecimal string.
[0099] The use of this elliptic curve makes the key pair compatible with the cryptography of the blockchain network used, allowing hardware module 3 to communicate with them.
[0100] Subsequently, the previously generated public key, as well as the obtained coordinates, are sent to server 4.
[0101] The fingerprints are obtained from the previously obtained geographic coordinates and the registered biometric image using a cryptographic hash function. If the KECCAK-256 hash algorithm is used, a 256-bit hexadecimal string is generated that uniquely and unambiguously represents the image of the biometric record of the authorized user for dwelling 5 where said hardware module 3 is located and its geographic coordinates. Other hash algorithms such as SHA-256 or SHA-512 can also be used.
[0102] A registration request is sent from server 4 to smart contract 7 of blockchain network 6, including in said request the generated public key, at least the fingerprint of the photo and optionally of the registered biometric data, a fingerprint of the identifying data of the interior of the home 5 (for example, image or images of the interior of the home) and the fingerprint of the geographic coordinates of the home 5. This information is stored immutably over time in said blockchain network 6, preserving the privacy of the user and their data thanks to the irreversible nature of the hash function.
[0103] When server 4 detects a new incoming transaction in smart contract 7, said server 4 sends to the electronic device 2 of the person authorized to access home 5, a message confirming the success of the identification and the generation of a new presence record in home 5. Access registration phase of users in the home
[0104] The access registration phase is considered normal system operation. 1. The user performs access registrations that prove their presence in the home. 5. The time interval in which the user can perform registrations is defined in the initial configuration phase and is set to 24 hours by default. Hardware module 3 indicates that the device is open for registration by means of the green LED 17 on hardware module 3.
[0105] First, the user presses the access registration switch 9, indicating that he or she wishes to register his or her access to the dwelling 5.
[0106] The biometric capture module 11 of the hardware module 3 performs the biometric recognition of the user and the high-precision geopositioning module 18 reads the position, comparing it with the reference coordinates stored in the persistent memory 8 of the hardware module 3.
[0107] If the identity of the user is recognized and the coordinates correspond to the reference coordinates, the hardware module 3 sends, digitally signing using a public key, RSA or elliptic curve algorithm, a blockchain transaction object to be sent to the blockchain network, which contains, among other data, the public address, the method and the parameters of said method. The hardware module 3 sends a transaction to the blockchain network with proof of access, such as, for example, image data, coordinates, results of learning algorithms, as well as digital fingerprints thereof and sends it to the blockchain network 6, to the server 4, or to both.
[0108] In some systems based on elliptic curve cryptographic algorithms, the digital signing and sending of the blockchain transaction object is done as follows:
[0109] - The blockchain transaction object is encoded in a binary string using the Recursive-Length Prefix (RLP) standard and is then received and interpreted for the execution of operations in the smart contract 7.
[0110] - The transaction object is signed using a digital signature algorithm, resulting in three signature components: v, r, and s. The digital signature is obtained by applying this signature algorithm to the cryptographic hash of the transaction object and the private key of the issuer or signer.
[0111] - Three components (numeric values expressed as hexadecimal strings) are generated: v, r, s. The r and s components are two integer values in the range [1, n-1], where n is the order of the elliptic curve, while v takes one of two values, indicating which of the two possible public keys associated with the digital signature is correct. The r and s components are 32-byte strings, while the v component is a single-byte element. The concatenation of the three, which results in the digital signature, is a string of 65 bytes or 130 characters. The digital signature is characterized by the r and s value pair.
[0112] - Finally, a transaction request is sent to the blockchain network 6, for which a direct connection is established with a node of the network, with the recipient being the public address of the smart contract 7 of access records, sending the information of the transaction object through a client-server communications protocol such as, for example, the JSON-RPC protocol.
[0113] Smart contract 7 uses cryptographic calculations to verify that the signer of the incoming transaction corresponds to a registered identifier, i.e., to hardware 3 authorized for that dwelling 5 and that user. Again, cryptography-based operations, such as RSA or elliptic curve encryption, are used to derive or recover the public key from the transaction's digital signature. This is a mathematical and, therefore, deterministic method that completely prevents any attempt at fraud.
[0114] If the comparison of said signer with the identifiers registered in smart contract 7 returns a positive result, the transaction is included and an access log is created, leaving a record in the blockchain of a new record of presence in the home.
[0115] The user receives a notification of a new registration on his electronic device 2. This notification is sent from the application installed on the server 4.
[0116] The hardware module 3 can be configured to not allow new access registrations, for example, if an access registration has already been made during the established access registration period. In such a case, the hardware module 3 enters a low-power state and LED 17 turns off. The hardware module 3 can also enter a low-power state or not allow access registrations if the Wi-Fi connection is lost, or when the user of dwelling 3 temporarily leaves dwelling 3, typically disconnecting from the Wi-Fi network.
[0117] The proposed system allows detecting and recording intrusion attempts in dwelling 5.
[0118] The hardware module 3 is in a low-power state, and the motion sensor 12 of the hardware module 3 detects movement, in which case it proceeds to perform at least the following actions:
[0119] - Send a message to authorized users in apartment 5 about the entry of an unauthorized person.
[0120] - Activate the biometric data capture module 11 of the hardware module 3, which, if possible, captures the biometric data of the person attempting to access home 5 and who is not registered. - Activate camera 10 to take an image of the unauthorized person.
[0121] The hardware module 3 compares the captured biometric data with the preset biometric data. If no positive comparison is made, the communications module 15 of the hardware module 3 sends a message reporting an intrusion to the electronic device 2 of the user authorized to access said dwelling 5.
[0122] The present invention also relates to a computer program product comprising a computer-readable medium which, in turn, comprises coded instructions for controlling a microprocessor that reliably controls and certifies the access of users to dwellings.
[0123] In some embodiments, such as those in Figure 6, the invention relates to a method.
[0124] In the method, a first device, or one or more first devices, such as, for example, but not limited to, a hardware module 3, obtains 110 at least one biometric data from a person 5 while the first device is in a home. The first device may use a biometric capture module for this purpose. The first device also performs 120 a biometric identification using the at least one obtained biometric data 110. To perform 120 the biometric identification, the first device may compare, for example, the at least one obtained biometric data 110 with at least one predetermined biometric data (for example, previously registered in an initial configuration) of one or more persons registered in the first device to attempt to identify the person located near the first device.Biometric identification may be one or more of the following: facial, ocular, fingerprint, voice, venous, palmar, anatomical or biological, multimodal, behavioral, or other. Biometric identification may be correct, i.e., positive, when the similarity between the at least one biometric data obtained 110 is sufficiently consistent with that previously recorded, i.e., the differences between the biometric data are less than or equal to a predetermined threshold, this predetermined threshold being optionally configurable and may be zero.
[0125] The first device, or one or more first devices, obtains 130 at least one piece of positioning data from the first device, i.e., data indicative of the location of the device while the first device is in the home. The first device may use a high-precision geolocation module for this purpose. The first device also performs 140 positional identification using the at least one piece of positioning data obtained 130. To perform 140 the positional identification, the first device may compare, for example, the at least one piece of positioning data obtained 130 with at least one piece of predetermined positioning data (e.g., previously recorded in an initial configuration) of the first device to verify that the first device is located in the same location or a location very close to the one previously recorded.Positional identification can be correct when the difference between the obtained position data 130 and the previous one is not greater than a predetermined threshold, which can be zero.
[0126] Preferably, the obtaining 110, 130 of data for the identifications to be performed 120, 140 are carried out in a short period of time, for example, no more than one minute, and preferably as short as possible, in some cases simultaneously.
[0127] When at least the biometric identification and positional identification performed 120, 140 are correct, the first device, or one or more first devices, generates 150 a data set at least identifying the person and the location of the device. That is, the data set at least includes data that allows the person and their location to be identified by means of the location of the first device, and data that allows the instant or time period to be identified when the data set was generated 150 and / or the identifications 120, 140 were performed.
[0128] If at least one of the identifications performed 120, 140 is not correct, the first device may, for example, restart the data acquisitions 110, 130 and the identifications to be performed 120, 140 immediately, allowing another measurement of the person to be taken in case they can be better identified in the biometric identification or if another person is being attempted to be identified, or after a period of time, thus not allowing multiple consecutive attempts to try to overcome the checks performed by the first device. The operations to be performed when at least one of the identifications performed 120, 140 is not correct may be configured to establish the operating mode of the first device when such erroneous identifications occur one or multiple times in a given period of time.
[0129] Once the data set has been generated 150, the first device, or one or more devices, may transmit 160 the generated data set 150 and, optionally, previously generated data sets, to a second device. Receiving the data set(s) at said second device allows for a certified record of the data. Said second device may act as a certifying device, either directly, i.e., said second device records the data (e.g., in a storage memory, in a database, on its own network, etc.) and may provide it in the future upon a request requesting to know the presence of a specific person at specific times or periods; or indirectly, in which case the second device communicates the data set(s) to other devices that certify the data after it has been recorded.In this second case, the second device may be connected to, or be connected to, a distributed ledger technology network, for example. In both cases, the data sets may be included in a digital ledger.
[0130] Transmission 160 may be performed over a communication channel to which the first device performing transmission 160 is connected, temporarily or continuously.
[0131] For the purposes of this document, the terms "first," "second," or similar have been used to describe various elements, devices, or parameters. It should be understood that the elements, devices, or parameters should not be limited by these terms, since the terms are merely used to distinguish one element, device, or parameter from another. In this regard, for example, the first device could have been called the second device, and the second device could have been called the first device, or some other different designation, without departing from the scope of what is described in this document.
[0132] In this text, the words "comprise", "include" and their variants (such as "understanding", "including", etc.) should not be interpreted in an exclusive manner, that is, they do not exclude the possibility that what is described includes other elements, stages, etc.
[0133] Furthermore, the invention is not limited to the specific embodiments described above, but also encompasses, for example, variations that can be carried out by the average person skilled in the art (for example, in terms of the choice of components, modules, configuration, etc.), within the meaning of the claims.
Claims
CLAIMS 1. A method for controlling and certifying access to a dwelling (5), the method comprising the following steps performed by a first device (3) in the dwelling (5): obtaining at least one biometric data of a person; performing a biometric identification by comparing this at least one biometric data of the person with at least one predetermined biometric data recorded in the first device, the at least one predetermined biometric data being representative of a predetermined person and; obtaining at least one positioning data from the first device; performing a positional identification by comparing this at least one positioning data with at least one predetermined positioning data recorded in the first device, the at least one predetermined positioning data being representative of the dwelling and;generating a data set when predetermined requirements are met, which at least include: the biometric identification performed corresponds to the predetermined person; and the positional identification corresponds to the dwelling; the generated data set being at least identifying the person and a location of the first device, and the data set comprising an instant or time period in which the person was identified with the biometric identification; and transmitting the generated data set to a second device for certified registration of the data set, the transmission being through a data connection of the first device.
2. The method of claim 1, wherein the predetermined requirements further comprise that the biometric identification and positional identification are performed within a predetermined period of time.
3. The method of claim 2, wherein the predetermined time period is no more than one minute, and preferably is zero seconds.
4. The method of any one of the preceding claims, further comprising generating, by the first device, at least one piece of data indicative of erroneous identification when at least one of the predetermined requirements is not met.
5. The method of claim 4, further comprising, when the at least one piece of data indicative of erroneous identification has been generated: providing a human-perceptible signal indicative of erroneous identification; and / or transmitting the at least one piece of data indicative of erroneous identification to a second device and / or a third device, the transmission preferably being via a data connection of the first device.
6. The method of any one of the preceding claims, wherein the first device is configured, wherein the configuration of the first device comprises the following steps performed by the first device: obtaining at least one biometric data of the person and storing the at least one obtained biometric data to record the at least one predetermined biometric data of the predetermined person; and obtaining, while the first device is in the dwelling, positioning data from the first device and storing the obtained positioning data to record the predetermined positioning data.
7. The method of any one of the preceding claims, further comprising the following steps performed by the first device: obtaining data from the dwelling; and performing an identification of the dwelling, the identification of the dwelling comprising comparing the obtained data with predetermined data of the dwelling recorded on the first device; wherein the predetermined requirements further comprise that the identification of the dwelling meets at least one predetermined dwelling requirement recorded on the first device.
8. The method of claim 7, wherein the predetermined requirements comprise that the biometric identification, the positional identification, and the dwelling identification are performed within a predetermined period of time.
9. The method of any one of claims 7-8, wherein the housing data comprises at least one of: geometric data, volumetric data, or data based on machine learning algorithms or artificial intelligence models.
10. The method of any one of claims 7-9, wherein the first device is configured, wherein the configuration of the first device comprises obtaining, by the first device while in the dwelling, data of the dwelling and storing the obtained dwelling data to record the predetermined data of the dwelling.
11. The method of any one of the preceding claims, wherein the at least one biometric data of the person is obtained from at least one of: facial recognition, eye recognition, fingerprint recognition, voice recognition, venous recognition, palm recognition, anatomical or biological recognition, multimodal recognition, behavioral recognition, recognition of any other physical or physiological characteristic, or a combination of the above.
12. The method of any one of the preceding claims, wherein obtaining the at least one positioning data of the first device (3) is performed through a geopositioning mechanism via GPS, GSM, GNSS, GLONASS, Galileo, BeiDou, EGNOS or other satellite-based geopositioning technologies, or Wi-Fi-based positioning technologies, or ultrasound positioning technology, or by cellular triangulation, or by Bluetooth or Bluetooth Low Energy beacons, or a call to an application programming interface, and may optionally include elevation / altitude coordinates.
13. The method of any one of the preceding claims, wherein the first device obtains at least one biometric data of the person by means of at least one biometric data capture module (11) of people, the at least one biometric data capture module (11) comprising an identity fraud prevention mechanism, proof of life or anti-spoofing.
14. The method of any one of the preceding claims, wherein the recording of at least one biometric data of the person is performed by storing the at least one biometric data in the first device using high security encryption.
15. The method of any one of the preceding claims, further comprising the following steps performed by the first device: obtaining an identification data of the data connection of the first device; and performing an identification of the data connection, the identification of the data connection comprising a comparison of the identification data of the data connection obtained with a predetermined data connection identification data recorded on the first device; wherein the predetermined requirements further comprise that the data connection identification meets at least one predetermined data connection requirement recorded on the first device.
16. The method of any one of the preceding claims, wherein the first device is a hardware module.
17. The method of any one of the preceding claims, wherein the second device is a node or element of a blockchain network.
18. The method of any one of the preceding claims, further comprising registering users and / or homes for control and certification of access to a home.
19. The method of claim 18, wherein the second device, a server (4) or a blockchain network (6) is configured to register users and / or homes.
20. The method of any one of the preceding claims, wherein: a) an initial configuration phase of the first device is performed, comprising the following steps: i. obtaining a registered user identifier; i. turning on the first device (3) inside the home (5); iii. sending, through an electronic device (2), credentials of a WIFI network of the home (5) to the first device (3), and connecting the first device to the WIFI network of the home (5); iv. storing in a persistent memory (8) of the first device (3) the user identifier and registration information from stage i, when the first device (3) connects to the WIFI network of the home (5); v. capturing biometric data of the user by means of a biometric data capture module (11), and storing said biometric data in the persistent memory (8); vi. capturing an image of an interior of the home (5) and storing said image in the persistent memory (8) and sending said image to a server (4); vii. obtaining geographic coordinates of the first device (3) and storing said geographic coordinates in the persistent memory (8); viii. generating a private cryptographic key on the first device (3) and storing said private key in the persistent memory (8); ix. generating a public cryptographic key on the first device (3) from the private key, said public key being compatible with a cryptographic method used in a blockchain network (6) to certify user access to the home (5); x. storing the private cryptographic key in encrypted form in the persistent memory (8); x¡. sending to the electronic device (2) and to the server (4) the geographic coordinates of stage vii and the public cryptographic key generated in stage ix; xii. generating on the server (4) a fingerprint from the biometric data recorded in stage v; xiii. generating on the server (4) a fingerprint from the image of the interior of the home (5) recorded in stage vi; xiv.generating on the server (4) a fingerprint of the geographic coordinates obtained in stage vii; xv. sending from the server (4) a registration request to the blockchain network (6), including in said request the public key generated in stage ix, the fingerprint of the biometric data recorded in stage xii, a fingerprint of the image of the interior of the dwelling (5) recorded in stage vi and the fingerprint of the geographic coordinates obtained in stage vii.
21. The method of claim 20, wherein step v is performed by pressing an access registration switch (9) of the first device, or after a time interval of a few seconds after capturing the biometric data, or by detecting motion by a motion sensor (12) of the first device (3).
22. The method of any one of claims 20-21, wherein step vi is performed by a camera (10) of the first device (3) after detecting a movement inside the home (5), or after an interval of seconds after pressing an access registration switch (9).
23. The method of any one of claims 20-21, further comprising, when in the dwelling (5) with the first device (3) configured according to phase a) an access attempt is made by a person not identified as registered: i. send an intrusion signal to the server (4); i. by means of a motion sensor (12) of the first device (3) activating a camera (10); iii. capturing at least one biometric data of the person not identified as registered who tries to access the home (5) by means of a biometric data capture module (11) of the first device (3), which module at least captures an image of the unidentified person; iv. comparing the at least one captured biometric data with at least one predetermined biometric data of one or more predetermined persons registered in the first device (3); v. transmitting, by means of a communications module (15) of the first device (3) when the comparison of the at least one captured biometric data has not recognized an identity of a person authorized for the home (5), a message informing one or more electronic devices (2) of users authorized to access the home (5) of an intrusion.
24. The method of any one of claims 20-23, wherein the registration information of the authorized users on the server (4) of a system (1) comprises: a) name and surname of the user; b) email and contact telephone number; c) photos of the front and back of his or her ID; d) one or more homes (5) that said user is authorized to access; e) type of plan contracted for the control and detection of the homes in the previous point d) within the system (1); f) biometric data of the authorized person, which will at least include a facial photo for the initial configuration process of the first device (3) in the system (1); and g) the time interval in which a new access registration is allowed in the home (5) in which the registered person is authorized to access.
25. The method of any one of claims 20-24, wherein the private key generated in step viii consists of a 256-bit or higher dimension cryptographic key, completely random, consisting of a number between 1 and (2 n - 1), where n is the dimension of the binary string representing the private key, expressed as a hexadecimal string.
26. The method of any one of claims 20-25, wherein an RSA or elliptic curve cryptographic algorithm is used to generate the public key of step ix.
27. The method of any one of claims 20-26, wherein the fingerprint generation is based on a cryptographic hash algorithm.
28. A device for controlling and certifying access to a home, the device comprising means for carrying out a method according to any one of the preceding claims.
29. The device of claim 28, wherein the means at least comprise: a hardware module adapted to be located inside a home (5), formed by physical and logical equipment comprising: a persistent memory (8) for storing digital data; an access registration switch (9); a camera (10); a module for capturing biometric data of people (11); a motion sensor (12); a power module (13); a cryptographic functions module (14); a communications module (15); a microcontroller (16); one or several LEDs to indicate an operating status (17) of the hardware module (3); a high-precision geopositioning module (18); a virtual blockchain transaction module (19) integrated in the microprocessor that is part of the microcontroller (16) and a power switch (20).
30. A system for controlling and certifying access to a home (5), comprising a device according to any one of claims 28-29.
31. The system of claim 30, further comprising: an electronic device (2) of a user authorized to access the home (5), formed by a user interface, comprising at least one power battery, a touch screen, a microprocessor, a hard disk, means for carrying out electronic communications, means for registering users, means for registering homes (5) of the authorized user and means for receiving notifications about an operation and status of the system (1); a server (4) comprising: a microprocessor integrated in a microcontroller (16); a database; a data storage device digital; means for performing cryptographic functions; means for conducting electronic communications; and means for conducting blockchain transactions.
32. The system of claim 31, wherein the device is the device of claim 29, and wherein the system further comprises at least one blockchain network (6), formed by an infrastructure to manage and store in a decentralized manner smart contracts (7) of access records of authorized users in registered homes (5).
33. The system of claim 32, wherein the communications module (15) of the device (3) allows establishing wireless communications such as, for example, under the 802.11, Bluetooth and GSM / UMTS / LTE standards and, also, client-server communications in distributed networks such as, for example, under the HTTP, HTTPS or JSON-RPC protocols.
34. The system of any one of claims 31-33, wherein the means for carrying out electronic communications of the server (4) allows establishing wireless communications such as, for example, under the 802.11, Bluetooth and GSM / UMTS / LTE standards and, likewise, client-server communications in distributed networks such as, for example, under the HTTP, HTTPS or JSON-RPC protocols.
35. A computer program comprising instructions that, when the program is executed by at least one processing device, cause the at least one processing device to carry out a method according to any one of claims 1-27.
36. Use of the system of any one of claims 30-34, or the computer program of claim 35, in alarm systems installed in buildings or properties.
Citation Information
Patent Citations
Access control method for smart home environment based on private blockchain
CN108632254A
Systems and methods for providing block chain-based multifactor personal identity verification
US20170279801A1
An Access Control Method for Smart Home Environments Based on Private Chains
CN108632254B
Intelligent access control management method based on block chain technology
CN113838240A
Control system for property management
ES1276114U