Method and system for data use / access control

The location-dependent data access system using a LAD with UWB and RTLS authentication addresses vulnerabilities in traditional data security by ensuring access is restricted to authorized locations, enhancing security and control.

WO2026003507A1PCT designated stage Publication Date: 2026-01-02FINLAY ALAN PATRICK
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
PCT/GB2025/051392
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2025-03-20
Filing Date
2025-06-24
Publication Date
2026-01-02

AI Technical Summary

Technical Problem

Existing data access and use security measures, such as password protection, are vulnerable to compromise by malicious entities, necessitating improved location-dependent control to enhance data security.

Method used

Implementing a location-dependent data access system using a location authorization device (LAD) with a locator module and security module, leveraging ultra-wideband (UWB) technology and real-time location systems (RTLS) to ensure data access is restricted to authorized locations, authenticated through fingerprinting of the RTLS to prevent unauthorized access.

Benefits of technology

Enhances data security by ensuring access is limited to authorized locations, improving control and management of data access, and preventing unauthorized use, even when traditional security measures are compromised.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure GB2025051392_02012026_PF_FP_ABST
    Figure GB2025051392_02012026_PF_FP_ABST
Patent Text Reader

Abstract

Disclosed herein is a computer-implemented method of authorising the use / access of data, the method comprising: using a location system, that is a substantial real time location system, to determine the location of an intended use / access of data by a computing device; authenticating the location system; obtaining one or more permitted locations in which the use / access of the data is allowed; and authorising the intended use / access of the data by the computing device only if the location system is authenticated and that the computing device is in one of the one or more permitted locations; wherein authenticating the location system comprises: measuring one or more characteristics of the location system; and authenticating the location system in dependence on a comparison of the measured one or more characteristics to one or more fingerprints of the location system.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] METHOD AND SYSTEM FOR DATA USE / ACCESS CONTROL

[0002] Field

[0003] Embodiments of the invention relate to the provision of location dependent data use / access. Embodiments ensure that a user can only use / access data if the user is in an authorised location when using / accessing the data. The user is prevented from using / accessing the data if the user attempts to use / access the data from a location that is not authorised for data use / access. A preferred implementation of embodiments is for improving the security of digital assets, such as cryptocurrencies and / or a non- fungible tokens. Advantageously, the control of data use / access is greatly improved.

[0004] Background

[0005] There are many different types of confidential data that needs to be securely protected so that its use and access is restricted to authorised persons. Examples of such confidential data include: trade secrets, patient records, medical test results, customer data, financial data, payment processing data, transaction history data, engineering data, scientific experiment results, electronic component characterisation results, approved vendor lists, bills of materials, approved manufacturer lists, recipe data, confidential algorithms, source code, private images, metallurgical formulae, chemical ingredient data, invention disclosures, crypto assets, non-fungible tokens, cryptocurrency and other private and / or commercially sensitive data.

[0006] It is known to protect data by using a password to restrict access to the data. The data may not be encrypted, but a user may first be required to enter a password before being able to access the data. Alternatively, the data may be stored in an encrypted state so that only authorised users with the password for decrypting the data can use the data.

[0007] A problem with password protection is that the security of the data is immediately compromised if the password ever becomes known by a malicious entity. For example, an authorised user may decide to act maliciously, or the password may be somehow obtained by a malicious entity.

[0008] There is a general need to improve the security of data access and use.

[0009] Summary

[0010] Aspects of the invention are set out in the appended independent clauses. Further aspects and preferred embodiments are defined in the dependent clauses. Any aspects, embodiments and examples of the present disclosure which do not fall under the scope of the appended clauses do not form part of the invention and are merely provided for illustrative purposes.

[0011] List of Figures

[0012] Embodiments of the present disclosure will now be described by way of non limitative example with reference to the accompanying drawings, of which:

[0013] Fig. 1 is a schematic diagram of an intangible asset storage medium sensing system according to an embodiment implemented in an industrial (or clinical or business) environment or premises;

[0014] Fig. 2 is a schematic diagram of a network according to an embodiment in an industrial environment;

[0015] Fig. 3 is a diagram of the steps performed to determine the location of an intangible asset storage medium tagging device according to an embodiment;

[0016] Fig. 4 is a schematic diagram of a storage medium tagging device according to an embodiment;

[0017] Fig. 5 is a schematic diagram of a node according to an embodiment;

[0018] Fig. 6 is a schematic diagram of an office (or datacentre) floor with a worker, a storage medium tagging device and multiple cameras and wireless transceivers according to an embodiment;

[0019] Fig. 7 is a schematic view of a storage medium tagging device and an item of electronic equipment incorporating the storage medium tagging device according to an embodiment;

[0020] Fig. 8 schematically shows a device according to an embodiment;

[0021] Fig. 9 schematically shows another embodiment.

[0022] Fig. 10 is a flowchart of a method of authorising the use / access of a digital asset according to an embodiment.

[0023] Fig. 11 is a flowchart of a method of authorising the use / access of a digital asset according to an embodiment.

[0024] Fig. 12 is a flowchart of a method of authorising the use / access of a digital asset according to an embodiment.

[0025] Description of Embodiments

[0026] Embodiments of the invention include the provision of location dependent data use / access. The location dependent data access only allows a user to use / access data if the user is in an authorised location when accessing the data. The user is prevented from using / accessing the data if the user attempts to use / access the data from a geographical location that is not authorised for data use / access. The location dependent data use / access of embodiments may be used in addition to other techniques for restricting access to data, such as standard password access and data encryption. Advantageously, the control of the use / access of data by users is greatly improved.

[0027] Embodiments also include monitoring and tracking the location of data sources and devices for accessing data sources. Advantages include improved control, tracing and management of data sources and data access.

[0028] Embodiments are described in detail below.

[0029] Figure 8 schematically shows a device 800 according to a first embodiment. The device 800, that may be a portable device, may be referred to as a location authorisation device (LAD) 800. The LAD 800 comprises a user interface 803, a processor 802, a memory 801, a security module 804 and a locator module 805.

[0030] The user interface 803 allows user interaction with the LAD 800. The user interface 803 may comprise standard features of a user interface of known portable devices. For example, the user interface 803 may comprise a touchscreen display and / or a keyboard.

[0031] The processor 802 may receive, process and send data to and from the user interface 803, memory 801, security module 804 and locator module 805.

[0032] The memory 801 may store both confidential data and non-confidential data. The non-confidential data stored in the memory 801 may include data required for the standard operation of the LAD 800, such as standard operating systems, Apps and default background images. The non-confidential data may be stored in an unencrypted state so that the processor 802 can process the non-confidential data without authorisation. The confidential data stored in the memory 801 may include personal and / or private data of the user. For example, the confidential data may include the user’s financial data, personal data, and / or medical data. The confidential data may be stored in an encrypted state. The processor 802 may only obtain decrypted confidential data for processing if the LAD 800 is in an authorised location.

[0033] The locator module 805 may be configured to obtain the location of the LAD 800. The locator module may provide the obtained location of the LAD 800 to the security module. The locator module 805 may use communications with a location system, external of the LAD 800, to obtain the location of the LAD 800. The location of the LAD 800 may be determined in the locator module 805, or determined in the external location system and then communicated to the locator module 805.

[0034] A preferred technology for determining the location of the LAD 800 by the locator module 805 is ultra-wideband (UWB). UWB is described by at least: https: / / www. inpixon.com / technology / standards / ultra- wideband#:~:text=Ultra%2Dwideband%2C%20or%20UWB%2C,between%20devices%20through%20 radio%20waves. (as viewed on 26thFebruary 2025). Further descriptions of the UWB technology that may be used in embodiments may be found in at least the International patent applications PCT / GB2019 / 052263 and PCT / GB2019 / 050932, the entire contents of which are incorporated herein by reference.

[0035] The locator module 805 is part of a location system for determining the location of the LAD 800. The location system of embodiments may be a real time location system (RTLS). The RTLS may be an indoor or outdoor location system such as Wi-Fi, UWB, Bluetooth, Bluetooth Low Energy, IEEE 805.15.4, LoraWAN, Mioty LPWAN, NFC, LTE, GPS, RFID or another type of contactless, wireless, acoustic or optical RTLS. The location system may comprise a plurality of nodes that are arranged in communication with the LAD 800. The nodes may also be arranged to communicate with each other and / or a central computer system. The communication between the nodes and the LAD 800 may be with high or low frequency radio wave communication. For example, the high frequency may be 2.4 GHz or Wi-Fi or Bluetooth, or the low frequency may be Lora WAN between approximately 800 and 950 MHz. Low frequency radio wave communication may provide the advantage that communication is less affected by the presence of structures, machinery, tubular or other steel obstructions in the environment, that may be an industrial or clinical environment, that may attenuate or reflect the signal. Alternatively, other forms of communication may be used. For example, visible light (e.g. Li-Fi) could be used for communication between the nodes and / or for communication between the LAD 800 and the nodes.

[0036] The location of the LAD 800 may be determined from the signals communicated between the LAD 800 and the nodes. In particular, Angle of Arrival (AoA), received signal strength, time of flight (TOF) and / or time difference of arrival (TDOA) techniques may be used to determine the location of the LAD 800. The calculation to determine the location may be performed in the LAD 800, one or more of the nodes, or in a central computer system of the RTLS. Alternatively, the calculations may be distributed amongst the LAD 800, the one or more of the nodes, and / or the central computer system of the RTLS. If the location is not determined on the LAD 800, then the location may be communicated to the LAD 800 and / or a determination that the LAD 800 is in an authorised location may be communicated to the LAD 800.

[0037] The RTLS may determine the actual geographical location of the LAD 800, such as is provided by, for example, altitude data together with longitude and latitude co-ordinates, GNSS / GPS data, and other known conventions for defining an actual geographical location in three dimensions. The actual geographical location may be determined by, for example, using the GPS system to verify the location of the RTLS. Alternatively, the RTLS may determine the location of the LAD 800 relative to the nodes of the RTLS and the RTLS may be authenticated.

[0038] Authentication of the RTLS is required so that the RTLS cannot be spoofed. That is to say, for security reasons, the location of the LAD 800 needs to be determined relative to the nodes of an RTLS that provides the correct location of the LAD 800 to the LAD 800. It is important to prevent a malicious operator of an RTLS from providing an incorrect location to the LAD 800 with the intention of tricking the LAD 800 into determining that it is in a different location from its actual location. By performing an authentication process of the RTLS, it can be determined that the locations provided by the RTLS can be trusted and the RTLS is not is a maliciously operated copy of a genuine RTLS.

[0039] Embodiments include a number of different techniques for generating a fingerprint of the RTLS that may be used to authorise the RTLS. The LAD 800 may determine to only use the locations determined by the RTLS if the RTLS is authorised by its fingerprint. If an RTLS cannot be authorised by its fingerprint, then the location of the LAD 800 determined by the RTLS cannot be used to authorise data access / use by the LAD 800.

[0040] When an RTLS is installed, an initial calibration process may be performed for determining a fingerprint of the RTLS. The fingerprint, that may also be referred to as a signature, comprises one or more recorded characteristics of the RTLS that are difficult, and preferably impossible, for a maliciously operated RTLS to replicate. An RTLS may only be able to provide an authorised location of the LAD 800 if the current characteristics of the RTLS can be measured and confirmed to be as expected given the record of the characteristics of the RTLS in the fingerprint of the RTLS.

[0041] In embodiments, a number of different characteristics of an RTLS may be used to generate a fingerprint of the RTLS.

[0042] The characteristics may include measurements obtained from wireless communications within the RTLS, such as communications between the nodes of the RTLS and / or communications with the LAD 800. These characteristics include the levels and / or properties of the background noise, signal-to-noise ratio, received signal strength, emissions data, radio frequency spectrum data, radio frequency reflection data, attenuation data, jitter data, harmonics data, interference data, and other electro-magnetic characteristics that may be measured and that provide a representation of the RTLS that is specific to its implementation and / or location. For example, in wireless communications between the nodes of the RTLS, a node may both receive signals from nodes, referred to as LOS nodes, that it is in line-of-sight communication with and also reflected signals from nodes, referred to as NLOS nodes, that it is not in line-of-sight communication with. The characteristic may be the ratio of signal strengths between the LOS nodes and the NLOS nodes. The characteristics may include a determination of the relative locations of the nodes of the RTLS. The relative locations of the nodes of the RTLS may be determined from wireless communications between the nodes of the RTLS. For example, multilateration, triangulation and / or ranging communications, such as two-way ranging or time difference of arrival, may be used to determine the relative distances between the nodes of the RTLS. The relative distances between nodes of the RTLS would not normally change during the lifetime of the RTLS and so any measured change of the measured relative distances may be evidence of tampering or spoofing of the RTLS network. The measurements of the wireless signals used for the wireless communications may include measurements of time difference of arrival, phase difference of arrival and / or angle of arrival. Angle of arrival may be used to filter out signal reflections when using time difference of arrival and / or two-way ranging to measure the relative distances between the nodes of the RTLS.

[0043] The characteristics may include measurements obtained from wired communications within the RTLS, such as communications along wires / cables / fibres between the nodes of the RTLS. The nodes of the RTLS may be connected to each other by wires / cables / fibres (e.g. Ethernet or fibre optic cables). The characteristics, that may be determined from signals communicated along the wires / cables / fibres, may include the lengths of the wires / cables / fibres and / or attenuation of the wires / cables / fibres. A change in wires / cables / fibres length, or the transmission line properties of the wires / cables / fibres (such as that caused by a kink in the wires / cables / fibres), may be detected and used as an indication that the RTLS has been tampered with or spoofed. Other measurable characteristics of the wired network that may an indication that the RTLS has been tampered with, or spoofed, include wire / cable / fibre breaks and broken connections.

[0044] The characteristics may be dependent on the physical environment of the RTLS. These characteristics include altitude data, magnetometer data, barometric data, and data from inertial sensors, gyroscopes and IMUs. Each node of the RTLS may be configured to measure one or more properties of its physical environment. For example, each node may comprise a magnetometer that obtains magnetometer data that is a measurement of the Earth’s magnetic field at the location of the node of the RTLS.

[0045] The characteristics may be dependent on the initial calibration or set-up of the RTLS. For example, the characteristics may include the entire operating time of each node of the RTLS since the RTLS was first set-up and / or maintained by authorised person.

[0046] The fingerprint of the RTLS may comprise a record of only one of the above-characteristics. However, the fingerprint of the RTLS preferably comprises a plurality of the above characteristics. For example, the fingerprint may comprise data on all of: signal-to-noise ratio and emissions (obtained from measurements of wireless communications within the RTLS), the relative locations of the nodes of the RTLS (obtained from wireless communications between the nodes of the RTLS), the lengths and / or attenuation of the cables within the RTLS (obtained from measurements of wired connections within the RTLS), and altitude and magnetic field (obtained from measurements by sensors within each node of the RTLS).

[0047] Embodiments are not restricted to the fingerprint of the RTLS only being determined in an initial calibration process. Embodiments include the characteristics of the RTLS being determined continuously, or repeatedly, during the operation of the RTLS. The re-determined characteristics may be used to generate a dynamic fingerprint of the RTLS that includes the most recently measured characteristics of the RTLS. An advantage of creating a dynamic fingerprint of the RTLS is that some of the characteristics of the environment of the RTLS may change over time. A dynamic fingerprint, that is derived from an initially determined fingerprint for the RTLS in a supervised calibration process, includes such changes to the characteristics. The dynamic fingerprint is therefore an indication of the expected current characteristics of the RTLS that can be used to authenticate the RTLS.

[0048] In particular, some of the above-described characteristics that are measurements obtained from wireless communications within the RTLS may change over time. For example, a new object in the environment may change the signal reflections in the environment and nodes of the RTLS that were in line-of-sight communication with each other may no longer be in line-of-sight communication with each other. The new object may change the background noise, that may include the signal reflections, and the signal-to-noise characteristic of the communications within the RTLS. Such characteristics may be repeatedly re-measured so that any changes are recorded in the most recent fingerprint.

[0049] In particular, at least some of the characteristics that are measurements obtained from wireless communications within the RTLS, such as the levels and / or properties of the background noise and signal-to-noise ratio, may be measured as part of an initial calibration process of the RTLS that generates an initial fingerprint of the RTLS. These properties of wireless communications within the RTLS may be repeatedly re-measured, such as continuously or periodically, and a new / updated fingerprint generated based on the most recently obtained measurements.

[0050] Characteristics of the RTLS that are not expected to substantially change over the lifetime of the RTLS are not re-determined and are the same for all fingerprints of the RTLS. Examples of such static characteristics may include the relative location of the nodes, the altitude of the nodes and the Earth’s magnetic field strength.

[0051] The characteristics stored in the fingerprint of the RTLS may be used to authenticate the RTLS. In particular, when an RTLS is used to determine the location of a LAD 800, each of the characteristics stored in the fingerprint of the RTLS may also be measured and compared with the fingerprint. If each of the currently measured characteristics are consistent with the expected characteristics that are stored in the fingerprint, then a determination may be made to authenticate the RTLS. However, if any of the currently measured characteristics are inconsistent with those in the fingerprint, then a determination to not authenticate the RTLS may be made.

[0052] A process for determining if the RTLS is authorised may be performed automatically in response to the process for determining the location of the LAD 800 by the RTLS being requested, performed, started or completed. Alternatively, or additionally, the process for determining if the RTLS is authorised may be automatically performed repeatedly and frequently. The process of checking that the RTLS is authorised may be performed continuously. For example, characteristics may be measured continuously and the RTLS only authorised if all of the current measurements are consistent with the expected characteristics in fmgerprint(s). If any of the continuously measured characteristics are not consistent with the expected characteristics in fmgerprint(s), then the RTLS is not authorised.

[0053] The fingerprint used to authenticate the RTLS may be an initially determined fingerprint during an initial calibration process of the RTLS. The fingerprint may alternatively, or additionally, be a dynamic fingerprint of the RTLS as described above.

[0054] Embodiments also include using more than one fingerprint to authenticate the RTLS. In particular, if the RTLS is not authenticated by the most recent fingerprint, then attempts to authenticate the RTLS may be made with one or more of the previous fingerprints. For example, there may be a machine or obstacle (e.g. a door or hatch) in the environment of the RTLS. The measured wireless characteristics, such as background noise caused by reflected signals, may substantially change in dependence on whether or not the obstacle is present (e.g. a door is open or closed) or if a machine is operating. Fingerprints of the RTLS may be determined in all states of the obstacle and / or machine. The most recently obtained fingerprint may be unable to authenticate the RTLS if the state of the obstacle and / or machine has changed since the fingerprint was obtained. However, the RTLS may still be authenticated by an earlier fingerprint that was obtained with the obstacle and / or machine in the same state as its current state.

[0055] Embodiments also include generating a historical record that includes all measurements that have been made of the characteristics of the RTLS. A historical record may be included within each fingerprint. When authenticating an RTLS, the current measurements of the characteristics may be compared with the historical record in the most recent fingerprint. The RTLS may then be authenticated if the current measurements of the characteristics are consistent with previous measurements of the characteristics that are included in the historical record.

[0056] Embodiments include the RTLS authenticating itself in a self-test. In particular, each node of the RTLS may obtain measurements of the current characteristics of the RTLS and perform its own comparison of the characteristics with the fingerprint. The RTLS may then authenticate itself only if every node of the RTLS determines that the currently measured characteristics of the RTLS are consistent with the fingerprint. The RTLS may only be able to provide authenticated locations to the LAD 800 if the RTLS has successfully self-authenticated itself at substantially the same time as when the locations of the LAD 800 are determined.

[0057] The self-test of the RTLS may be performed automatically in response to the process for determining the location of the LAD 800 by the RTLS being requested, performed, started or completed. Alternatively, or additionally, the self-test of the RTLS may be automatically performed repeatedly and frequently. The self-test of the RTLS may be performed continuously. For example, characteristics may be measured continuously and the RTLS only authorised if all of the current measurements are consistent with the expected characteristics in fmgerprint(s). If any of the continuously measured characteristics are not consistent with the expected characteristics in fmgerprint(s), then the RTLS is not authorised.

[0058] The self-test of the RTLS may comprise the nodes of the RTLS using mutual authentication and / or zero trust architecture techniques to authenticate each other. Known mutual authentication techniques are described here: https: / / en.wikipedia.org / wiki / Mutual_authentication (as viewed on 16 June 2025). In mutual authentication techniques, separate devices use cryptographic keys, such a public and private keys, to authenticate each other. Known zero trust architecture techniques as described here: https: / / en.wikipedia.org / wiki / Zero_trust_architecture (as viewed on 16 June 2025). With zero trust architecture techniques, each node of the RTLS does not trust each of the other nodes by default. Instead the nodes only trust each other after authentication processes between the nodes have been successfully performed. Mutual authentication techniques, that may be based on cryptographic techniques, may be used for the authentication processes between the nodes.

[0059] Embodiments differ from known techniques by the authentication processes between nodes being based on one or more of the above-described characteristics of the RTLS, that may be included in a fingerprint of the RTLS, as well as cryptographic processes. In particular, the data in communications between the nodes for authentication of the nodes may be dependent on both one or more measured characteristics of the RTLS and also cryptographic keys of the nodes. For example, in addition to the public key of each node being used in communications with the nodes for authentication of the nodes, the same communications may include data on one or more of: signal-to-noise ratio and emissions (obtained from measurements of wireless communications within the RTLS), the relative locations of the nodes of the RTLS (obtained from wireless communications between the nodes of the RTLS), the lengths and / or attenuation of the cables within the RTLS (obtained from measurements of wired connections within the RTLS), and altitude and magnetic field (obtained from measurements by sensors within each node of the RTLS). The nodes may only authenticate each other, and thereby authenticate the RTLS, if the measured characteristics of the RTLS may be verified by the nodes in addition to the cryptographic based verification processes being successfully completed.

[0060] Each fingerprint may be obtainable by each node of the RTLS and / or a central control system of the RTLS. Each fingerprint may be stored in a central control system of the RTLS. Additionally, or alternatively, each fingerprint may be stored in one or more, such as all, nodes of the RTLS. Each fingerprint may be certified by each node of the RTLS. Each fingerprint of the RTLS may be generated / stored using blockchain technologies. In particular, the nodes and, optionally, a central control system of the RTLS, may use blockchain technologies to authenticate each other and thereby authenticate the RTLS.

[0061] Embodiments include other techniques for additionally, or alternatively, determining a fingerprint, that may be a dynamic fingerprint, of the RTLS. Lor example, other sensors such as Inertial Measurement Units (IMUs) may be used. IMUs may comprise 3 -axis gyroscopes, 3 -axis accelerometers and / or magnetometers. An IMU may be used to obtain one or more of gravitational, barometric pressure / altitude, magnetometer, or compass orientation data at the location of the RTLS that is a fingerprint of the specific location of the RTLS. This fingerprint may be recorded and stored, and used to authenticate the RTLS and / or authenticate locations determined by the RTLS.

[0062] Embodiments include the LAD 800 further comprising an IMU. The data obtained by the IMU may be used in addition to the communications within the RTLS to improve the accuracy of, and / or verify, the determined location of the LAD 800. The IMU data may also allow the location of the LAD 800 to be determined substantially continuously, even if the LAD 800 enters a blind spot of the RTLS where the RTLS in unable to reliably communicate with the LAD 800.

[0063] Embodiments also include the RTLS using other technologies to determine and / or verify the location of the LAD 800. Lor example, a video camera system may be used and image / video analytics used to determine the location of the LAD 800 from the recorded images / video. Accordingly, the location of the LAD 800 may be independently determined using different technologies.

[0064] The RTLS may determine the location of the LAD 800 with an accuracy of approximately 0.5 metres, and preferably with an accuracy of 0.1 meters or less.

[0065] The security module is configured to control access to the confidential data in the memory. The security module may store, and / or be able to generate, one or more passwords, or keys, for decrypting the encrypted confidential data in the memory. The security module may also store, or be configured to obtain, a list of one or more locations where access to the confidential data is authorised. Each authorised location may be a region or zone with a defined shape and volume. Lor example, an authorised location may be a specific desk in a room that is defined in three dimensions by the shape of the desk and the height of the room that he desk is in.

[0066] Although not shown in Eigure 8, the LAD 800 may comprise further modules to those described above.

[0067] The operation of the LAD 800 is described below.

[0068] The LAD 800 may be usable for functions that do not require access to confidential data. The processor 802 may retrieve non-confidential data from the memory 801, that is not encrypted, and process the non-confidential data as required to run standard Apps. Such Apps may, for example, obtain and display to the user publicly available data, such as free weather reports or share prices. Functions that do not require access to confidential data may be performed with the LAD 800 in any location and the functionality of the LAD 800 is not dependent on the location of the LAD 800.

[0069] The LAD 800 may also be usable for functions that do require access to the encrypted confidential data stored in the memory.

[0070] The LAD 800 may have one or more standard forms of security for restricting access to the LAD 800 and / or the confidential data stored on the LAD 800. For example, to operate the LAD 800, the LAD 800 may read the face or fingerprint of the user to verify that the user has authorised access to the LAD 800. To then start the process of accessing confidential data stored on the LAD 800, the user may additionally need to enter a password into the LAD 800. As an additional form of security, the processor 802 is unable to decrypt the encrypted confidential data unless the LAD 800 is in an authorised location.

[0071] When access to the encrypted confidential data is required, the processor 802 may send a request for a password, or key, for decrypting the encrypted confidential data to the security module 804. The security module 804 may then send a request for the location of the LAD 800 to the location module 805. The location module 805 may determine, or obtain, the location of the LAD 800. The location is preferably determined using RTLS including UWB technologies. The location module 805 may send the determined location to the security module 804. The security module 804 may obtain data on one or more authorised locations where the use of confidential data is allowed. The security module 804 may compare the received location with the obtained data on one or more authorised locations to determine if the LAD 800 is in an authorised location.

[0072] If the security module 804 determines that the LAD 800 is not in an authorised location, then the security module 804 does not provide the processor 802 with the password, or key, for decrypting the encrypted confidential data. The LAD 800 is therefore unable to successfully perform functions that require access to the confidential data.

[0073] If the security module 804 determines that the LAD 800 is in an authorised location, then the security module 804 may provide the processor 802 with the password, or key, for decrypting the encrypted confidential data. The processor 802 may use the password, or key, to decrypt the encrypted confidential data and then perform functions that require access to the confidential data. This ensures that the confidential data may only be used by the LAD 800 when the LAD 800 is in an authorised location.

[0074] The security module 804 may provide a key, such as a private key or password, to the processor that is time limited so that there is a strict time duration, and / or for frequent validation of LAD 800 presence in an authorised location, during which it can be used. For example, the key may only be usable for 5 minutes from when it is provided to the processor 802. Before the key expires, the security module 804 may determine whether the LAD 800 is still in an authorised location. If the LAD 800 is not in an authorised location, then the security module 804 may not provide a further key to the processor 802 and the processor 802 may be unable to decrypt and use the confidential data. However, if the LAD 800 is still in an authorised location, then the security module 804 may provide a new usable, but time limited key to the processor so that the processor 802 may continue to decrypt and use the confidential data. This ensures that the processor 802 soon losses access to the confidential data if the LAD 800 leaves an authorised location.

[0075] Embodiments also include alternative techniques for providing the processor 802 with decrypted confidential data when the LAD 800 is in an authorised location. For example, when the LAD 800 is in an authorised location, the encrypted confidential data may be transferred from the memory to the security module 804. The security module 804 may decrypt the encrypted confidential data and provide the decrypted confidential data to the processor 802 for use. The security module 804 may receive substantial real time location data from the locator module 805 and determine, substantially in real time, whether the LAD 800 is still in an authorised location. So long as the security module determines that the LAD 800 is in an authorised location, the security module 804 may continue to decrypt the encrypted confidential data and provide the decrypted confidential data to the processor 802 for use. However, as soon as the security module 804 determines that the LAD 800 is not in an authorised location, the security module 804 may cease to provide decrypted confidential data to the processor 802. Advantageously, time limited keys are not required to prevent the processor 802 from using confidential data when the LAD 800 is not in an authorised location. The key for decrypting the data is also always retained within the security module 804.

[0076] The memory 801 may store different types of confidential data and each type of confidential data may require a different password, or key, to decrypt it. The security module 801 may store all of the passwords, or keys, required for decrypting each type of confidential data. The security module 801 may also store data on one or more authorised locations for each type of confidential data. The one or more authorised locations may differ between the different types of confidential data. For example, a first type of confidential data may be specific medical records of the user and the authorised locations for the first type of confidential data may be known locations of medical practices, such as hospitals and doctor’s surgeries. A second type of confidential data may be cryptocurrency owned by the user and the authorised locations for the second type of confidential data may be known secure locations such as vaults, safes or locations of financial service providers, such as banks. In this example, the LAD 800 is able to access the specific medical records of the user if they are required by a doctor in a hospital, but not in other locations that are not authorised for the specific medical records. Similarly, the LAD 800 is able to access the user’s cryptocurrency in a bank where financial transactions may be made in a secure and highly controlled environment such as a gallery, bank vault or safe, but not in other locations that are not authorised for the user’s cryptocurrency or non-fungible tokens (NFTs).

[0077] In a preferred implementation of the first embodiment, the LAD 800 is a portable crypto wallet. An example of a supplier of known crypto wallets is Ledger, see https: / / www.ledger.com / (as viewed on 27thFebruary 2025). For a user to access a known crypto wallet, a password and / or other user verification technology may be used. For example, the crypto wallet may read and verify the user’s face and / or fingerprint.

[0078] The present implementation of the first embodiment differs from known portable crypto wallets by further comprising a locator module 805 and security module 804 for determining if the crypto wallet is in an authorised location. As described above, in addition to the standard user verification techniques of a known crypto wallet, the crypto wallet of the present implementation of the first embodiment may also only allow at least some of the operations of the crypto wallet if the crypto wallet is in an authorised location. For example, the authorised locations of the crypto wallet may be specific authorised safes, vaults or banks. The cryptocurrency stored in the crypto wallet may only be used, or transferred out of the crypto wallet, if the crypto wallet is currently verified as being within an authorised location such as a bank. Advantageously, this greatly reduces the risk of the user being forced to use their cryptocurrency against their will. For example, an intruder within the user’s home would not be able to force the user to make a cryptocurrency transfer from the user’s home.

[0079] In another preferred implementation of the first embodiment the LAD 800 may store other types of digital assets than cryptocurrency, and in particular may store non-fungible tokens (NFTs). Embodiments include using blockchain technologies to record location data in the digital assets. The record may include the location of a use of, such as a transaction with, the digital asset as well as a signature, or other identifier, of the location system used to determine the location. Blockchain technologies may be used to authenticate the location system and / or record transactions / uses in a blockchain ledger. The location system may be authenticated by, for example, the nodes of the location system and / or a central computer system using blockchain technologies to authenticate each other. The digital assets may only be usable in authenticated locations that are stored on the LAD 800. If the calculation steps required to determine the location of the LAD 800 are distributed amongst nodes of the RTLS then these may be recorded using blockchain technologies for digital assets stored on the LAD 800. In addition, the location of the LAD 800 may be continuously, or periodically, determined and recorded using blockchain technologies for the digital assets. The RTLS may provide a Proof of Location (POL) of the LAD 800. The identity of the RTLS, and identities of the plurality of nodes and / or central computer system in the RTLS, may be recorded in the blockchain record of each location determination. As described earlier, the RTLS may have its own fingerprint, or signature, that allows the RTLS to be authenticated. The fingerprint may be recorded using blockchain technologies and used to authenticate each location determined by the RTLS.

[0080] In another implementation of the first embodiment, the LAD 800 may be a company computer, such as a laptop computer, smart phone or tablet as is typically used by personnel at a workplace. As described above, the computer may comprise a locator module 805 and a security module 804. A memory in the computer may store confidential data, such as commercially sensitive data of the user’s company. The authorised locations that the computer needs to be in for the confidential data to be accessed may be specific storage, racks, offices, or specific desks, or specific floors within the workplace. Advantageously, embodiments allow a company to control where employees are able to use commercially sensitive data of the company. This greatly reduces the risk of harm to the company by potentially malicious activity of a member of its personnel.

[0081] In another implementation of the first embodiment, the LAD 800 may be a company computer, such as a laptop computer, or tablet as is typically used by personnel at a workplace. As described above, the computer may comprise a locator module and a security module. The computer may be configured to communicate with a server system that may store confidential data, such as commercially sensitive data, of the user’s company. The security module 804 may be configured to only permit the computer to access confidential data on the server system if the security module 804 can verify that the computer is in an authorised location. The authorised locations that the computer needs to be in for the confidential data to be accessed may be specific offices, or specific desks, or specific floors within the workplace. The confidential data may be stored in the server system in an encrypted state. The security module 804 may store a password, or key, that is required for decrypting the confidential data and only allow the computer to use the password, or key, to decrypt the confidential data if the computer is in an authorised location.

[0082] Figure 9 schematically shows another implementation of the first embodiment. The LAD 800 comprises a security module 804, processor 802 and locator module 805 as described earlier. A difference to the previous implementations of the first embodiment is that the LAD 800 is separable from the memory 801 that stores the confidential data. As shown in Figure 9, the LAD 800 comprises a first interface port and a second interface port. The second interface port is for communications between the LAD 800 and the memory 801 storing confidential data. The first interface port is for communications between the LAD 800 and an external computing system. The external computing system can only access data in the memory 801 with communications through the LAD 800. The LAD 800 may be, for example, a tag, dongle, USB or other such device. The memory 801 may be, for example, a server system, hard drive or mobile device.

[0083] The LAD 800 may operate substantially as described above for other implementations of the first embodiment. That is to say, the locator module 805 may provide the security module 804 with the location of the LAD 800 and the security module 804 may only allow the password, or key, for decrypting encrypted data in the memory 801 to be used when the LAD 800 is in an authorised location. Advantageously, the present implementation of the first embodiment allows the security of data in memories, such as servers, to be easily improved by securing the LAD 800 to each memory. For example, the authorised locations of use of a server may only be within specific server rooms, or specific rack within a server room, of a building. When the server is correctly located in an authorised server room, the LAD 800 allows the encrypted data on the server to be decrypted. However, the LAD 800 prevents the encrypted data on the server from being decrypted if the server is taken out of the server room or server rack. The LAD 800 may be, for example, a tag that can be retrofitted to existing servers.

[0084] In the first embodiment, confidential data is stored in a memory 801 in an encrypted state and the password, or key, for decrypting the confidential data is only usable if the LAD 800 that is accessing the data is in an authorised location.

[0085] In a second embodiment, confidential data is alternatively stored in a memory 801 in an unencrypted state. Access to the memory 801 storing the confidential data is controlled and only allowed if the computing device attempting to access the confidential data is in an authorised location. The access may be controlled by a password, or key, that is only usable when the computing device is in an authorised location. The computing device that attempts to access the confidential data may be the LAD 800 as described for the first embodiment.

[0086] Access to the confidential data in a memory 801, such as a server system, may be controlled by the security module 804. For example, the security module 804 may store a password, or key, that is required for all communications between a computer, that comprises the LAD 800, and the server system for accessing confidential data on the server system. The security module may only allow the computer to use the password, or key, for communications if the LAD 800 is in an authorised location. Alternatively, or additionally, the computer may need to run a specific program, such as an App, to access confidential data on the server system. The security module may store a password, or key, that is required for the program to run and only allow the computer to use the password, or key, if the LAD 800 is in an authorised location.

[0087] The second embodiment also includes a LAD 800 is separable from the memory that stores the confidential data. The LAD 800 may be substantially as shown in Figure 9 for the first embodiment and comprise a first interface port and a second interface port. The second interface port is for communications between the LAD 800 and the memory storing confidential data. The first interface port is for communications between the LAD 800 and an external computing system. The external computing system can only access data in the memory with communications through the LAD 800. The LAD 800 may be, for example, incorporated into a connector, integrated into a plug, a tag, dongle, USB or other such device. The memory may be, for example, a server system, hard drive or mobile device.

[0088] In operation, the locator module may provide the security module with the location of the LAD 800 and the security module may only allow the password, or key, for accessing the memory to be used when the LAD 800 is in a authorised location. Advantageously, the present implementation of the second embodiment allows the security of data in memories, such as servers, to be easily improved by securing the LAD 800 to each memory. For example, the authorised locations of use of a server may only be within specific server rooms of a building. When the server is correctly located in an authorised server room, the LAD 800 allows the data on the server to be accessed. However, the LAD 800 prevents data on the server from being access if the server is taken out of the server room. The LAD 800 may be, for example, a tag that can be retrofitted to existing servers.

[0089] In a further embodiment, the locator module may provide the security module with the location of the LAD 800 and the security module may only permit, or prompt for, user entry of the password, or key, for accessing the memory to be used when the LAD 800 is in an authorised location. In this manner, a layer of security is provided that is in addition to use of a password or key to access or decrypt confidential data.

[0090] In a third embodiment, the authorised locations of use of digital assets are stored within the digital assets. The digital assets may be cryptocurrencies and / or NFTs. As described for the first embodiment, the third embodiment includes using blockchain technologies to record location data in digital assets. The recorded location data may include the location of a use, such as a transaction, of the digital asset as well as a fingerprint, or other signature, of the RTLS. In the third embodiment, blockchain technologies are used to restrict the use of the digital assets to authorised locations that are recorded within their blockchain. That is to say, a digital asset may only be usable in authorised locations and the authorised locations are recorded within, and obtainable from, the blockchain for that specific digital asset. The locations where a digital asset may be used are therefore defined within the blockchain for the digital asset, and may not be stored on the computing device used to view / use the digital asset. When a user of a computing device, such as the LAD 800 according to embodiments, attempts to use a digital asset, the location of the computing device is determined. The computing device may obtain the authorised locations of use of the digital asset from the blockchain of the digital asset. The use of the digital asset is only possible if the computing device is in an authorised location of the digital asset when its attempt to use the digital asset is made.

[0091] In all embodiments, the use of data, that may be a digital asset, is dependent on the location of access, or use, of the data. When an attempt to access, or use data is made and the attempt fails due to the location not being authorised, then remedial action may be taken. In particular, embodiments include an alert being automatically sent to person of authority in the event of such a failed attempt to access, or use, data. For example, if the failed attempt was an employee attempting to access the confidential data of a company from an unauthorised location, then an email and / or text message may be automatically sent to the supervisor of the employee. Alternatively, if the failed attempt was an attempt to use cryptocurrency in an unauthorised location, then law enforcement authorities may be automatically notified and provided with the location of the failed attempt.

[0092] The determination of the location of a LAD 800 according to embodiments is performed at least every time the LAD 800 accesses, or uses, data that is protected according to the techniques of embodiments. The location of the LAD 800 may also be periodically determined at other times. Embodiments include recording all of the determined locations of the LAD 800 and sending these to a monitoring system. The monitoring system may then be used to track the location of the LAD 800. All of the determined locations of the LAD 800 may be recorded using blockchain technologies.

[0093] Advantages of embodiments include improved security and control of confidential data and other digital assets, and a layer of security is provided that is based on presence in an authorised location that is in addition to use of a password or key to access and / or decrypt confidential data.

[0094] Figure 10 is a flowchart of a method of authorising the use / access of a digital asset according to an embodiment.

[0095] In step 1001, the method starts.

[0096] In step 1003, the method comprises determining the location of an intended use / access of a digital asset.

[0097] In step 1005, the method comprises obtaining one or more authorised locations in which the use / access of the digital asset is authorised.

[0098] In step 1007, the method comprises authorising the intended use / access of the digital asset only if the location of the intended use / access is in one of the one or more authorised locations. In step 1009, the method comprises recording the determined location of intended use / access of the digital asset in the digital asset and / or a blockchain ledger.

[0099] In step 1011, the method comprises recording identification data of the system(s) used to determine each location of authorised use / access of the digital asset in the digital asset and / or a blockchain ledger.

[0100] In step 1013, the method ends.

[0101] Figure 11 is a flowchart of a method of authorising the use / access of a data according to an embodiment.

[0102] In step 1101, the method starts.

[0103] In step 1103, the method comprises using an ultra- wideband location system to determine the location of an intended use / access of data, wherein the location of the intended use / access of data is determined relative to the ultra-wideband location system and the method comprises authenticating the ultra-wideband location system.

[0104] In step 1105, the method comprises obtaining one or more authorised locations in which the use / access of the data is authorised.

[0105] In step 1107, the method comprises authorising the intended use / access of the data only if the location of the intended use / access is in one of the one or more authorised locations.

[0106] In step 1109, the method ends.

[0107] Figure 12 is a flowchart of a method of authorising the use / access of a data according to an embodiment.

[0108] In step 1201, the method starts.

[0109] In step 1203, the method comprises using an ultra- wideband location system to determine the location of an intended use / access of data, wherein the data is encrypted.

[0110] In step 1205, the method comprises obtaining one or more authorised locations in which the use / access of the data is authorised.

[0111] In step 1207, the method comprises authorising the intended use / access of the data, by allowing the password / key for decrypting the data to be used, only if the location of the intended use / access is in one of the one or more authorised locations.

[0112] In step 1209, the method ends.

[0113] Embodiments include a number of modifications to the techniques described above.

[0114] Embodiments include the locations determined by the RTLS, and the authorised locations for data use / access, being dynamic locations. That is to say, an authorised location may change over time and, for example, be defined relative to a moveable object. For example, the use a computer to access specific may only be authorised if the computer is in a specific vehicle, such as a vessel, car or aircraft. The current location of the vehicle may be determined, such as by an authorised RTLS, as well as an authorised location of the computer attempting the data use / access. The data use / access only allowed if the computer is within a region defined by the current location of the vehicle. This allows the use computers installed on vehicles to be restricted to the specific purposes of the vehicles. For example, a computer in a police van may only be allowed to access a police database when the computer is in the police van. The computer would be unable to access a police database if it was stolen from the van.

[0115] Embodiments include taking any remedial action when an attempt to access, or use, data is made and the attempt fails due to the location not being authorised. In particular, objects and / or equipment may be automatically controlled. For example, if an unauthorised attempt at data access / use is made, then the doors to the location may be automatically locked so that the person who attempted the data use / access is trapped until the authorities arrive. Another remedial action that may be taken in response to an unauthorised attempt at data access / use is to change the encryption state of the confidential data being accessed. For example, if the confidential data is already encrypted, then a higher level of encryption may be automatically applied, so that the data is more secure, and the password, or key, for decrypting the data provided to authorised persons. If the confidential data is not encrypted, because only access to the data is location dependent, then the confidential data may be encrypted and the password, or key, for decrypting the data provided to authorised persons. Another remedial action that may be taken in response to an unauthorised attempt at data access / use is to delete the confidential data so that it cannot ever be retrieved. This may be appropriate if an unauthorised attempt to access the data would only occur in the event of a security breach that justifies rendering the confidential data unobtainable to all parties.

[0116] Embodiments include the locations determined by the RTLS, and the authorised locations for data use / access, being defined in ether two dimensions or three dimensions. An authorised location may be defined in three dimensions when, for example, it is necessary to restrict the authorised location to a specific floor of a building. If an entire building or site is an authorised location, then the location may be defined in two dimensions.

[0117] Embodiments are described further below.

[0118] Described below are embodiments that relate to methods and devices for tracking intangible assets in a medical, social, commercial or industrial environment. The intangible assets referred to below may be the above-described confidential data, or any other type of data. The technologies described below may be further implementations of the above-described embodiments and / or implementations of alternative embodiments. Industrial, medical, government and commercial environments require free sharing of confidential information between people operating in close proximity. The confidential information may be sensitive and includes categories of intangible assets such as trade secrets, patient records, test results, customer data, banking information, payment processing, transaction history, engineering data, scientific results, test results, electronic component characterisation results, approved vendor lists, bills of materials, approved manufacturer lists, recipes, processes, methods, algorithms, firmware, source code, images, surface processes, coatings, metallurgical formulae, logos, trademarks, ingredients, chemical formulae, registered designs, patent applications, invention disclosures, patterns stock photography, original photographic negatives, crypto assets, non-fungible tokens, cryptocurrency and alloy composition or other commercially sensitive information. In accounting terms, businesses can capitalise research and development so that it becomes an intangible asset on a balance sheet. Research and development includes the generation of confidential information such as source code, formulae, recipes, processes, computer models, bill of materials, approved vendor lists, mechanical designs, fonts, logos, styles, graphic designs, other designs etc. which become intangible assets. These intangible assets can provide competitive advantages to a business and its products or services and therefore should not be shared outside a business. Indeed, an organisation may record trade secrets in a trade secret register, and retain those secrets securely. The organisation is obliged to keep this information confidential, and within an organisation such as a company or hospital, in some cases for regulatory, contractual or even legal reasons. Personnel working in the environment need to share information for efficient operation of the business or institution, therefore permitting collaboration and consultation between multiple individuals within the organisation is required but without permitting the information to leave that organisation in an unauthorised manner.

[0119] It would therefore be desirable to introduce a system to permit personnel working in the environment to exploit intangible assets by freely sharing confidential information within an environment, but to prevent free sharing of confidential information outside the institution or organisation by restricting access and sharing of that information to specific locations within the organisation such as certain floors, rooms, server rooms, data centres or offices within a building or complex. However, industrial or commercial environments can often represent a complex environment for communication between the different individuals permitting free access to data, with the risk of that confidential information leaving the organisation. For example, the environment may include servers, networks, mobile devices and portable mass storage devices such as USB peripherals or other electronics when easily permit transfer or communication not just between different parts of an organisation but also outside the organisation. Examples of such storage medium devices include Secure Digital (SD) Storage Cards, Flash Memory Cards, USB Flash Drives, Mass Storage devices which can be inserted into a server or personal computer and used to surreptitiously copy large amounts of confidential information and simply carry it out of any organisation, business or institution. Likewise, a server or laptop (incorporating a storage medium) may be removed to steal confidential information from an organisation’s premises, e.g. an office, hospital, laboratory, workshop, clinic, courtroom, prison, barracks, datacentre, cloud hosting site, server farm, local area network, ship or other vessel or platform, or a factory. The working environment may be ‘air-gapped’ to prohibit internet access and exfiltration of secret information, but free sharing and collaboration of that confidential information should be possible within the air-gapped network. Because access to this confidential information will be mainly shared inside a building a geolocation technology such as GNSS or GPS which requires a line of sight to a satellite constellation cannot be exploited. A location technology that locates indoors to office floor, corridor, room or even to the level of a desk or workstation is required.

[0120] It is therefore desirable to provide a method of restricting intangible assets within a premises that is capable of locating confidential information held on an electronic devices and permitting access to the confidential information in certain locations (e.g. on or in proximity to a server or computer in a particular room or office, or on certain floors) but restricting access to the confidential information in other locations (e.g. outside a building, floor or room or office, away from a desk or workstation).

[0121] A first aspect of the present disclosure relates to a method or system for determining the location of an intangible asset within a premises.

[0122] According to the first aspect of the present disclosure, there is provided a sensing method for intangible assets, confidential information such as data, in a commercial or industrial environment, the method comprising measuring the timing of signals between a tagging device associated with, or integrated or attached (or incorporated into) to a storage medium (e.g. in an electronic device such as a computer, handheld device or server, the storage medium capable of storing intangible assets may be electronic such as a flash memory device or optical memory storage device such as a DVD, Optical Disk, or CD) and a plurality of nodes located at predetermined locations in the industrial environment, calculating the location of the tagging device within the environment based on the measured timing of the signals determining if the location of the intangible asset stored on a storage medium is within a permitted location or zone in the environment and performing an operation in response thereto such permitting access to the intangible asset and / or decrypting confidential information. If the location of the storage medium tagging device that is attached or integrated with a storage medium containing an intangible asset such as confidential information is located outside a permitted zone or location then the information may be encrypted and / or access may not be permitted unless the storage medium tagging device is located in a permitted zone or location. The plurality of nodes form a network and the signals may be transmitted over the network. The nodes may be communicate by wireless, wired, or optical means, either through optical fibres connecting the nodes or by means of optical signals transmitted and received between the nodes. Signals may be transmitted between the nodes, and throughout the network, by optical means via optical fibres connecting nodes or as light transmitted by LEDs and detected by photodiodes at the nodes.

[0123] Measuring the times of flight may comprise transmitting outbound signals from the storage medium tagging device to the plurality of nodes, transmitting return signals from the plurality of nodes to the storage medium tagging device in response to the outbound signal and in respect of each node, measuring the total time of flight of the outbound signal and the time of flight of the return signal.

[0124] Measuring the time of flight may comprise transmitting an outbound signal from the storage medium tagging device to each of the plurality of nodes, measuring the times of arrival of the signal at each of the plurality of nodes from the storage medium tagging device and calculating the times of flight of the outbound signals from the measured times of arrival of the outbound signal.

[0125] The step of calculating the location of the storage medium may be performed by the storage medium tagging device.

[0126] The step of calculating the location of the storage medium may be performed by one or more of the plurality of nodes.

[0127] The step of determining if the location of the intangible asset stored on the storage medium falls within a permitted or restricted location or zone may be performed by the storage medium tagging device.

[0128] The step of determining if the location of the intangible asset falls within a permitted or restricted location or zone is performed by one or more of the plurality of nodes.

[0129] The permitted zone may be a predefined volume of space in the premises or commercial or industrial environment.

[0130] The permitted zone for an intangible asset may be associated with a region within a building, a room, a floor or an office, a piece of electronic equipment such as a printer with, a mass storage medium, or computer or server with an electronic storage medium, located in the working, scientific, commercial, clinical or industrial environment.

[0131] The method may further comprise measuring the times of flight of signals between a storage medium tagging device located in a room or on the piece of equipment and the plurality of nodes and calculating the location of the storage medium tagging device on a piece of equipment within the environment based on the measured times of flight of the signals wherein the restricted or permitted zone is based on the calculated location of the piece of equipment.

[0132] The method may further comprise receiving control information associated with the piece of equipment and updating the authorised / permitted or restricted zone based on the control information associated with the piece of equipment.

[0133] The method may further comprise determining if the location of intangible asset storage medium tagging device falls within a safe zone within the industrial environment and ceasing performance of the method in response thereto.

[0134] The method may further comprise determining whether the signals are failing to be passed between the intangible asset tagging device or storage medium tagging device and the wireless network and outputting a failure signal in response thereto.

[0135] The method may further comprise receiving the warning signal at the storage medium tagging device and the storage medium tagging device providing feedback to the storage medium on which the storage medium tagging device is located in response thereto. The warning signal may result in instructions to the storage medium to encrypt information, and / or restrict access to the storage medium to protect an intangible asset.

[0136] The method may further comprise receiving the warning signal at a control device and the control device displaying an alert to the user of the control device in response thereto.

[0137] The method may further comprise ceasing processing or operation of electronic equipment and / or re-encryption of information on storage media within the working, industrial environment in response to the warning signal. Likewise the system of the invention may be used to track and inventory the location of all electronic assets in an office or some other storage medium tagging devices that have been located with respect to nodes at fixed locations. In this manner the storage medium tagging devices may form an expanding locating mesh.

[0138] The method may further comprising receiving a signal from a surveillance system including a camera, the signal including positional information of a further intangible asset storage medium (electronic or IT equipment such as a handheld device, connector, plug, server, laptop, mobile phone, printer, switch, router, access point, firewall or server) in the industrial environment, determining that the positional information of the further intangible asset storage medium does not correspond to the calculated location of the intangible asset storage medium tagging device within the industrial environment and outputting a warning signal in response thereto. The locations of storage medium tagging devices may be compared with objects detected and located by a surveillance system including a camera to determine if objects such as IT equipment are present and associated with a storage medium tagging device. In this manner the system can detect and track authorised IT equipment associated with storage medium tagging devices, and detect or track and alert to the presence of unauthorised IT equipment that has not been connected to or associated with a storage medium tagging device. The surveillance system could detect the presence of an object such as laptop on a desk, locate the laptop and compare its location with the location of storage medium tagging devices and determine if that laptop has been authorised and issue an alert via a user interface, text message or email to an appropriate user or administrator.

[0139] Further according to the first aspect of the present disclosure, there is provided an encryption system for a storage medium containing an intangible asset in an industrial environment, the system comprising a storage medium tagging device associated with (or located on) the storage medium and a plurality of nodes of a network located at predetermined locations in the industrial environment, the system being arranged to measure the timing signals (e.g. time of flight or time difference or phase difference) of signals between the storage medium tagging device and the plurality of nodes, calculate the location of the intangible asset on the storage medium within the industrial environment based on the measured times of flight of the signals and determine if the location of storage medium tagging device falls outside a permitted zone in the industrial environment and output a warning or password prompt or shut down or encryption signal in response thereto.

[0140] Securing intangible assets is achieved by means of encryption of storage medium location tags associated with storage media (such as flash memory or optical data storage) such that the intangible asset is encrypted outside of permitted zones (e.g. a rack, shelf, desk, storage bin or office) and decrypted when inside a permitted zone as defined by a real time location system. In this manner the system of the invention may be utilised to protect intangible assets from intellectual property theft or exfiltration. Unless the authorised RTLS network (e.g. authenticated UWB network) is present the storage medium tagging device is outside a permitted zone and the data stored on the storage medium is encrypted. The location of the storage medium tagging device is checked versus a permitted location (e.g. a rack, desk, office, compartment, floor, building or other authorised secure location) or zone for that data and the data is encrypted unless access to that data is from an authorised location or zone. The storage medium tagging device may be used to measure power consumption of a storage medium at a specific location (e.g. if integrated into a power supply) and in this manner to estimate the local carbon footprint of an electronic device with a storage medium, and in aggregate therefore the total carbon footprint of a data centre. The real time location system may be used to detect locations for an electronic device incorporating a storage medium and to track its movement throughout an industrial environment in real time. In this way the location for a storage medium, and therefore for intangible assets, may be tracked and inventoried in real time.

[0141] The system of the invention may be deployed at a secure data centre to track and secure intangible assets stored on storage medium and to prevent exfiltration of confidential information through theft of a storage medium. The only approved USB peripheral has an associated storage medium tagging which, unless present and in a permitted zone, cannot decrypt and access the data stored on a storage medium. Each storage medium is associated with a storage medium tagging device. Nodes may be mounted at defined locations for example rack mounted at known rack locations in a server area network or data centre, in 1U to 4U sized rack units or larger, or as a peripheral attached to a rack mounted unit (e.g. as a USB, Power over Ethernet device or integrated into a plugjack, connector, or power supply attached to a rack mounted unit, or integrated inside a rack mounted device) or the node may be integrated into the structure of the rack as part of its frame. The location of the storage medium tagging devices, and therefore the storage medium, is defined based on timing signals between the tagging device and nodes at predefined locations. The tagging device associated with a storage medium (e.g. a USB peripheral or dongle) may also function as a node once its location is defined with respect to nodes at predefined locations and in this manner storage medium tagging devices in a rack or row in a server farm may be located with respect to each other and a relatively small number of nodes at predefined locations (e.g. nodes integrated into server racks or other fixed infrastructure).

[0142] In a further embodiment of the invention, the method of the invention is used to secure digital assets such as non-fungible tokens (NFTs) or cryptocurrency on a storage medium that may only be decrypted in a permitted location. The method of the invention may also be utilised to treat intangible assets as NFTs, and to securely record their ownership and location, alongside authenticated transactions. A blockchain may be used to record the ownership and location of a digital asset, such as a NFT, and the RTLS may also be authenticated using a blockchain. In this manner a blockchain is used to secure and record NFTs by also recording the signature of the RTLS in the blockchain as part of the authentication process. The RTLS may be an indoor location system such as Wi-Fi, UWB, Bluetooth, RFID or some other wireless real time location system. The blockchain may be distributed among the nodes of the RTLS and the nodes will include processors that will process transactions, authenticate their location, authenticate the location system and record the transactions in the blockchain ledger. In this manner the method of the invention may be used to implement, for example, a vault, collection, museum, or Gallery within which NFTs may be accessed and viewed, but from which they may not be stolen. In this embodiment the storage medium tagging device is associated with a storage medium which may be a mass storage device such as USB flash memory device, an external disk drive, a digital wallet, a HDD caddy. The storage medium tagging device may be a USB dongle that is attached to a computer and associated with a HDD in that machine, or the storage medium tagging device may be integrated or incorporated into a USB flash memory device, an external disk drive, a digital wallet, or a HDD caddy and the storage medium tagging device is used to determine the location of the storage medium within an authenticated indoor location system, and if the location is within a permitted location, decrypt the digital asset at that location. The storage medium tagging device may be associated with, or incorporated into, a secure digital wallet such as that supplied by Ledger Technologies, Inc. (www^ and provide an additional level of security based on location within an authenticated indoor location system. The Proof of Location (POL) is used by a distributed blockchain to validate the location of the storage medium tagging device and authenticate the indoor location system used to determine its location. In this manner the POL is equivalent to the Proof of Work (POW) in a conventional blockchain. The POL may be obtained using the earlier described techniques for authorising an RTLS. In particular, the noise, signal strength, and other characteristics of the wireless communications between the nodes of the location system and / or with the storage medium tagging device may be used to authenticate the indoor location system used to determine the location of the storage medium tagging device. Proof of Stake (POS) can be operated as the storage medium staking some or all of its digital or intangible assets prior to authentication of the POL of its associated storage medium tagging device. The POS may be Proof of storage of an intangible asset, such as a NFT. Indeed, all Intangible Assets may be treated as NFTs. If the POL is not valid, then the storage medium may lose or ‘bum’ its staked intangible asset. Similarly, any node in the blockchain may ‘stake’ its digital assets (or Intangible Assets) in return for authenticating a transaction in a NFT by means of validating the POL of the storage medium and its associated storage medium tagging device. In this manner a secure and distributed blockchain ledger may be constructed to autonomously record and validate the possession and / or transactions of digital assets or intangible assets (such as NFTs) and also to secure them in addition based on POL by determining the location and authenticating the indoor location system used to determine their location is a permitted location. In return for POS of the digital or intangible asset stored on the storage medium, The nodes of the network validates the POL of the device, and authenticates the RTLS used to determine the device location. If the validated location is within a permitted location, the intangible assets on the storage medium may be decrypted. If outside a permitted location, or within a restricted location, the digital assets may be encrypted or indeed the digital asset may be burned by the nodes because of failure of Proof Of Stake. In this manner a blockchain for secure storage, transaction and processing of digital assets such as NFTs is conceived wherein the Proof of Work is equivalent to Proof of Location, and the Proof of Stake is equivalent to the Proof of Storage of digital asset in the blockchain ledger. This method could be exploited to secured store and transport highly valuable digital assets such as cryptocurrency or NFTs so that the Wallet incorporates a storage medium tagging device that permits access only in certain permitted locations or vaults. The RTLS location system or Indoor Location system, relying on a protocol such as Bluetooth, NFC, RFID, GNSS / GPS, LTE, LoraWAN, Wifi or UWB may be characterised by its noise as part of an initial calibration process and prior to its authentication. Noise can include received signal strength, emissions, radio frequency spectrum, radio frequency reflections, attenuation, jitter, harmonics, interference and other electro-magnetic characteristics that may be measured and that can representation of a particular network in a given location. Other sensors such as Inertial Measurement Units may be used alone or in combination with the radio signature to fingerprint a RTLS network. The IMU may include gravity, barometric pressure / altitude, magnetometer readings or compass orientation to future profile and fingerprint a RTLS network for future authentication as part of the method of the invention. This signature may be recorded and stored, and used as a fingerprint to authentic that indoor location system. This signature may be stored in the blockchain and interrogated as part of POL to authenticate a RTLS and a location.

[0143] The method of the invention permits the conversion of intangible assets to non-fungible tokens that may be stored securely digitally, transported securely and accessed and utilised only in approved locations. In this manner suitable intangible assets may be converted to NFTs that may be transacted, minimising counterparty risks and theft while permitting vast commerce in NFTs. The transactions so permitted make feasible accurate valuation and price discovery by objective economic and accounting standards. The intangible assets on balance sheets may be secured, located, allocated and transacted in a regulated and secure manner, supporting valuations and investment.

[0144] In a method relying on the invention an insurer, insurance broker or managing general agent (MGA), may advance an insurance policy that insures intangible assets such as cryptocurrency, NFTs, trade secrets against theft and infringement, as part of which the insured is obliged to use the device of the invention to secure to monitor, secure and track intangible assets in a working environment and only permit access, use and / or decryption in an authorised secure location such as a vault, safe or bank. The device of the invention in this manner mitigates risk of theft and therefore reduces claims on intangible asset, trade secret, or digital or crypto asset insurance policies due to losses. The device of the invention can be combined with a digital asset insurance policy to reduce claims and losses for the insurance provider, therefore increasing the profitability and economic feasibility of marketing intangible asset protection or intellectual property protection policies. As part of this method the insurance company, insurance broker or MGA analyses a potential insured based on the usual business metrics such as headcount and management accounts including turnover, market capitalisation or valuation, recent transactions (e.g. records from Companies House, or news media, or CrunchBase, Pitchbook etc.) and historic litigation (e.g. from a source such as LexisNexis). The MGA then computes a premium and proposes a policy, and takes a commission once the policy is placed with the underlying insurance syndicate. The policy includes terms and conditions obliging the insured to utilise the technology of the invention to monitor, locate, track, audit and secure intangible assets including intellectual property such as trade secrets within a working environment. The monitoring, tracking and location of access to these intellectual properties provides evidence in the event of a claim, and the device of the invention secures the intellectual property (such as trade secrets) against exfiltration and theft by encrypting them and only decrypting them when validated to be within an authorised or unrestricted area such as an office, floor, corridor, building, desk, hallway, corridor or server rack.

[0145] The various aspects of the disclosure and preferred features thereof may be combined in any combination.

[0146] Embodiments of the present disclosure will now be described by way of non-limitative example with reference to the accompanying drawings, of which:

[0147] Fig. 1 is a schematic diagram of an intangible asset storage medium sensing system implemented in an industrial (or clinical or business) environment or premises;

[0148] Fig. 2 is a schematic diagram of a network in an industrial environment;

[0149] Fig. 3 is a diagram of the steps performed to determine the location of an intangible asset storage medium tagging device;

[0150] Fig. 4 is a schematic diagram of a storage medium tagging device; and Fig. 5 is a schematic diagram of a node.

[0151] Fig. 6 is a schematic of an office (or datacentre) floor with a worker, a storage medium tagging device and multiple cameras and wireless transceivers; and

[0152] Fig. 7 is a schematic view of a storage medium tagging device and an item of electronic equipment incorporating the storage medium tagging device.

[0153] All the aspects of the present disclosure may be applied in a working environment such as an office floor, deck, bank, vault, gallery, museum, clinic, laboratory, legal practice, government or military facility or in a premises for research and development.

[0154] In all aspects of the present disclosure a storage medium tagging device attached to a storage medium containing intangible assets may be incorporated into suitable electronic equipment such as a computer, mobile device, personal device, watch, tablet, laptop, personal computer, RAID, server, router, network switchjack, port, connector, power supply, firewall, printer, scanner, fax, camera, scanner or server.

[0155] Fig. 1 shows a schematic diagram of an intangible asset sensing system implemented in an industrial environment 100. The industrial environment includes intangible assets 101, equipment 102 and other features 103. The equipment 102 may be servers, computers or mobile devices that represents a risk of exfiltration of intangible assets 101. The other features 103 may be stationary objects or walls that represent boundaries to physical use and access to, and use of, intangible assets 101. At least one of the equipment within the industrial environment 100 may incorporate or otherwise carry a storage medium tagging device 10, 30. The storage medium tagging device 10, 30 may be, or comprise, the earlier described LAD 800 of embodiments.

[0156] At least one of the pieces of equipment 102 within the industrial environment 100 may have a storage medium tagging device 30 attached. A plurality of gateways 20 (which form nodes of a network as described below), and may be the nodes of the earlier described RTLS of embodiments, may be located at predetermined locations in the industrial environment 100. A control device 40 may also be located in the industrial environment 100.

[0157] Fig, 2. shows a schematic diagram of the connections between the network located in the industrial environment 100. The control device 40 may be in communication with each of the gateways 20 for example over a wired network. Each of the gateways 20 may be in communication with one or more of the other gateways 20 over a wired network and with one or more of the storage medium tagging devices 10 and equipment devices 30 over a wireless communication network.

[0158] Calculate time of flight - determine location of storage medium tagging device - sense unauthorised access to intangible assets such as confidential information

[0159] A sensing method for locating an intangible asset 101 in an industrial environment 100 comprises measuring the times of flight of signals between a storage medium tagging device 10 associated with or located on the storage medium containing the intangible asset 101 and a wireless network, the wireless network comprising a plurality of gateways 20 located at predetermined locations in the industrial environment 100. The storage medium tagging device 10 and gateway 20 are discussed in greater detail below. The location of the storage medium 101 (and therefore the intangible asset) within the working environment 100 can be determined based on the time of flight of the signals sent between the intangible asset 101 and the wireless network made up of the gateways 20. Once the location of the intangible asset 101 within the industrial environment 100 has been determined, the location of the intangible asset 101 can be compared to a permitted zone within the industrial environment 100 and a warning signal can be output if the location of the intangible asset storage medium 101 and its attached storage medium tagging device 10 is determined to fall outside a permitted zone. The permitted zone is discussed in greater detail below.

[0160] An example of such a method is shown in Fig.3. In step 50a, the signals are transmitted between the storage medium tagging device 10 and the wireless network. In step 50b, the time of flight of the signals between the storage medium tagging device 10 and the wireless network is determined. In step 50c, the distances travelled by the signals and thus the location of the storage medium tagging device 10, (and therefore the storage medium handling the intangible asset to which the storage medium tagging device may be attached) within the industrial environment 100 may be determined. If this location falls outside a permitted zone in the working or industrial environment 100, a warning signal is output in step 50d. Optionally, remedial action may be taken based on the output of the warning signal in step 50e. The remedial action may include shutting down the operation of electronic equipment within the working or industrial location 100. The remedial action may alert the user or a supervisor monitoring the control device 40. The remedial action may involve providing a haptic, visual, message, email or audible alarm to the user or the supervisor monitoring the control device. For example, the remedial action may be the locking of a door, or activation of a klaxon or strobe light mounted in the working or industrial environment 100. The remedial action may involve the operation of equipment emergency encryption or interlocks to lock access to a storage medium.

[0161] Such a method may be advantageous as the remedial action in response to the warning signal can be used to alert the user to a data breach in the industrial environment 100 that they were not aware of. The remedial action may be used to directly alert the person to the presence of the breach. For example, the remedial action may comprise an audible alarm, text message or email. The warning signal may also be provided to the control device 40 that interfaces with the wireless network. The supervisor monitoring the control device 40 may then alert the appropriate user to the presence of the breach or take other action such as shutting down equipment, encrypting fdes, ceasing processing, interrupting internet communications, activating recording devices, activating cameras, locking doors or logging activity.

[0162] The wireless network and storage medium tagging device 10 may communicate using high or low frequency radio wave communication. The wireless network may be an ultra-wide band (UWB) network. The low frequency may be 2.4 GHz or Wi-Fi or Bluetooth or Lora WAN. Low frequency radio wave communication may provide the advantage that communication is less affected by the presence of machinery, tubular or other steel obstructions in the industrial or clinical environment 100 that may attenuate or reflect the signal.

[0163] Alternatively, other forms of communication may be used. For example, visible light (e.g. Li-Fi) could be used to communicate between the gateways 20 and the storage medium tagging device 101.

[0164] The various steps of the method may in general be performed on any one of the storage medium tagging device 10, the plurality of gateways 20, the equipment device 30 and the control device 40 in any combination.

[0165] Where subsequent processing steps are performed on different devices, then the result of one processing step may be communicated to another device using the wireless or wired communication networks in order to perform the next step. For example, the calculation of the time of flights of the signals may be performed on one of the plurality of gateways 20 and the result of the calculation may be transmitted to another one of the plurality of gateways 20 to calculate the distance between the devices associated with the signals and the location of the storage medium tagging device 10, thereby locating an intangible asset storage medium 101 in real time as it moves about the office, datacentre, floor, corridor or workspace, and locking / encrypting and unlocking / decrypting the storage medium as it moved outside and back into a permitted zone respectively.

[0166] The distribution of the steps between the devices may be selected based on a number of practical considerations such as reliability and redundancy, and the available power and processing capability on the different devices.

[0167] Time of flight - Direct TOP calculation

[0168] The method of determining the location of an intangible asset 101 in the industrial environment 100 may include a measurement of the time of flight that comprises transmitting a first signal between the storage medium tagging device 10 and the plurality of nodes at known locations called gateways 20, transmitting a second signal between the plurality of gateways 20 and the storage medium tagging device 10 in response to the first signal and measuring the time of flight of the first signal and the time of flight of the second signal. In this example, the calculation of the distances between the components and the position of the storage medium tagging device 10 may take place on the storage medium tagging device 10. There may be a processing delay between the receipt of the first signal by either of the storage medium tagging device 10 and the plurality of gateways 20 and transmission of the second signal from the storage medium tagging device 10 and the plurality of gateways 20. The length of the processing delay may be a known length that depends on the processing components of the storage medium tagging device 10 or the plurality of gateways 20.

[0169] The time of flight between the storage medium tagging device 10 and each of the plurality of gateways 20 may be calculated by subtracting the processing delay from the time between the transmission of the first signal and receipt of the second signal and dividing the result by two. The distance between the storage medium tagging device 10 and each of the plurality of gateways 20 may then be calculated by multiplying the time of flight by the speed of signal (the speed of light in the case of radio waves or light). The location of the storage medium tagging device 10 relative to at least one of the plurality of gateways 20 can then be determined by the intersection of the distances between the storage medium tagging device 10 and each of the plurality of gateways 20. As each of the gateways 20 is located at a known location within the datacentre, industrial or office environment 100, the location of the storage medium tagging device 10 (and thus the intangible asset storage medium 101 that the storage medium tagging device is located on) can be determined within the working or industrial environment. It is possible to determine the location of the storage medium tagging device 10 by communication between the storage medium tagging device 10 and three of the plurality of gateways 20. However, the accuracy of the determination may be increased by determining the distance between the storage medium tagging device 10 and four or more of the plurality of gateways 20.

[0170] Time of flight - TDOA calculation - storage medium tagging device receives or transmits The method of determining the location of an intangible asset 101 in an industrial or office environment 100 may include measuring the time of flight by a time difference on arrival calculation. The method may include transmitting a signal from each of the plurality of storage medium tagging devices 10 to the gateways 20, measuring the time of arrival of the signal at the storage medium tagging device 10 from each of the plurality of gateways 20 and calculating the difference between the time of arrival of each of the signals at the storage medium tagging device 10 to determine the time of flight of the signals. In this example, the calculation of the distances between the components and the position of the storage medium tagging device 10 may take place on the storage medium tagging device 10. Alternatively or additionally, the measuring of the time of flight may include transmitting a signal from the storage medium tagging device 10 to each of the plurality of gateways 20, measuring the time of arrival of the signal at each of the plurality of gateways 20 from the storage medium tagging device 10 and calculating the difference between the time of arrival of the signal at each of the plurality of gateways 20 to determine the time of flight of the signals. In this example, the calculation of the distances between the components and the position of the storage medium tagging device 10 may take place on one of the plurality of gateways 20.

[0171] Determining the time of flight of the signal using the difference in the time of arrival of the signals at the storage medium tagging device 10 or at each of the plurality of gateways 20 may improve the reliability and time response of the method because only one signal is required to be passed between the storage medium tagging device 10 and the plurality of gateways 20. The location of the intangible asset 101 may be determined with an accuracy of approximately 0.5 metres, and down to 0.1 meters.

[0172] Location of calculations

[0173] The storage medium tagging device 10 provided to the storage medium containing an intangible asset within the office or industrial environment will now be described in more detail. A schematic diagram of an example of a storage medium tagging device 10 is shown in Fig. 4. The storage medium tagging device 10 may include a processor 11, a wireless communication network interface 12, a wireless ranging network interface 16, a feedback unit 13, a battery 14 and a sensor unit 15. The processor 11 may implement the method shown in fig. 2. The calculation of the location of the intangible asset described above may performed by the processor 11. The determination of whether the location of the intangible asset falls within the permitted zone may be performed by the processor 11. The processor may comprise the earlier described processor 802, security module 804 and locator module 805 of embodiments.

[0174] The wireless communication network interface 12 implements the wireless communication network and is capable of communicating with other storage medium tagging devices 10 or gateways 20. The wireless communication network interface 12 may comprise a physical (PHY) layer, a media access control (MAC) layer and a network layer. The physical layer may include a radio frequency transceiver. The wireless communication network interface 12 may communicate using high frequency radio waves such as ultrawideband. Alternatively or additionally, the wireless communication network interface 12 may communicate using light (e.g. LiFi or via optical fibre). In this case, the physical layer may include a light emitting diode or another component for emitting light and a photodiode for detecting light.

[0175] The wireless communication network interface 12 may be arranged in accordance with the IEEE 802.15.4 technical standard which defines the operation of low-rate wireless personal area networks (LR-WPANs). An Ultra-wideband (UWB) transceiver configured to transmit and receive data using UWB signals and UWB communication protocol(s), such as protocols set forth by the FiRa Consortium. UWB may use low energy, short-range, high-bandwidth pulse communication over a relatively large portion of the radio spectrum. Thus, for example, an ultra-wideband signal / pulse may be established by a radio signal with fractional bandwidth greater than 20% and / or a bandwidth greater than 500 MHz. UWB communication may occur by using multiple frequencies (e.g., concurrently) in the frequency range from 3.1 to 10.6 GHz in certain examples. To transmit UWB signals consistent with present principles, the transceiver itself may include one or more Vivaldi antennas and / or a MIMO (multiple-input and multiple-output) distributed antenna system, for example. It is to be further understood that various UWB algorithms, time difference of arrival (TDoA) algorithms, and / or angle of arrival (AoA) algorithms, or phase difference of arrival (PDOA) may be used for the system to determine the distance to and location of another UWB transceiver on another device that is in communication with the UWB transceiver on the storage medium tagging device 10. The storage medium tagging device 10 may include a camera that gathers one or more images and provides the images and related input to the processor. The camera may be a thermal imaging camera, an infrared (IR) camera, a digital camera such as a webcam, a three-dimensional (3D) camera, and / or a camera otherwise integrated into the storage medium tagging device 10 and controllable by the processor to gather still images and / or video. Also, the storage medium tagging device 10 may include a global positioning system (GPS or GNSS) transceiver that is configured to communicate with at least one satellite to receive / identify geographic position information and provide the geographic position information to the processor when outside the building of the working environment.. The storage medium tagging device 10 may be achieved by means of an application running on a UWB enabled device such as a handheld device, personal digital assistant, a smartphone, tablet, computer or smartwatch. The application running on the processor of the UWB enabled device forms a storage medium tagging device 10 that is associated with a storage medium containing an intangible asset, and file access permissions and encryption may be applied depending on the location of the UWB enabled device within the working environment or datacentre, e.g. access to data is permitted in certain rooms 32 or floors, corridors, desks, server racks, trays, shelves of an office building, but not in others.

[0176] The wireless ranging network interface 16 is capable of sending and receiving ranging signals with other storage medium tagging devices 10 or gateways 20. The wireless ranging network interface 16 may comprise a physical (PHY) layer, a media access control (MAC) layer and a network layer. The wireless ranging network interface unit 16 may send ranging signals using high frequency radio waves. Alternatively or additionally, the wireless ranging network interface 16 may communicate using visible light. In this case, the physical layer may include a light emitting diode or another component for emitting light and a photodiode for detecting light.

[0177] In this example, the wireless communication network interface 12 and the wireless ranging network interface 16 are separate components of the storage medium tagging device 10 associated with a storage medium securing an intangible asset. However, a single wireless network interface may perform the function of both the wireless communication network interface 12 and the wireless ranging network interface 16.

[0178] The feedback unit 13 may provide feedback to the storage medium 101 or user carrying the storage medium tagging device 10 when the intangible asset storage medium 101 leaves a permitted zone. For example, the feedback unit 13 may vibrate or provide another form of haptic feedback to alert the user carrying the equipment incorporating the intangible asset storage medium. Alternatively or additionally, the feedback unit 13 may provide audible feedback such as an alarm to alert the user. The alarm may be audible via ear pieces, messages, emails or audible prompts. Alternatively or additionally, the feedback unit 13 may provide visual feedback. For example, the feedback unit may include an LED indicator which flashes when the storage media containing intangible assets 101 enters a restricted zone, or leaves a permitted zone, with an intangible asset. The LED indicator may be provided as a demountable accessory or a wireless accessory. The LED indicator may show the status of the storage medium tagging device 10. For example, the LED indicator may flash green every two seconds when the storage medium tagging device 10 is operating normally, flash red rapidly if a fault is detected, display blue when the storage medium tagging device 10 is charging or flash blue every 2 seconds if the storage medium tagging device 10 is on standby mode.

[0179] The battery 14 provides a power source for the other components of the storage medium tagging device 10. The battery 14 may be configured for wireless or contactless charging to allow the storage medium tagging unit 10 to be quickly and easily recharged. A wireless or contactless charger system may be provided for charging of the battery 14. The charging system may be contactless inductive charging or NFC. The charging system may be located within an authorised zone in the industrial environment 100. The charging system may be able to charge at least 6 storage medium tagging devices 10 at the same time.

[0180] Placing the storage medium tagging device 10 on the charger may cause the storage medium tagging device 10 to enter a standby mode which may de-authorise the storage medium tagging device 10 for entry into the industrial environment 100. The standby mode may deactivate the feedback unit 13 of storage medium tagging device 10. The standby mode may reduce the rate of transmissions from the storage medium tagging device 10.

[0181] The sensor unit 15 may contain additional sensors to provide further information about the intangible asset 101 wearing the storage medium tagging device 10. For example, the sensor unit 15 may include an accelerometer which may be used to calculate the rate of motion of the intangible asset 101 wearing the storage medium tagging device 10. If the accelerometer determines that the rate of motion of the asset has increased or decreased, the rate of determination of the location of the intangible asset 101 can be increased or decreased respectively to maintain the accuracy if the determination while minimising power consumption in the storage medium tagging device 10.

[0182] The sensor unit 15 may also contain additional sensors, such as an inertial measurement unit (IMU). This may incorporate 3 -axis gyroscopes, 3 -axis accelerometers, barometers and magnetometers. The output of the IMU may be ‘fused’ or combined with time of flight measurements to improve the accuracy, precision and stability of the location of the sensor unit 15 in the industrial environment. Algorithms processing IMU data and combining with time of flight measurements obtained either optically, using RF location, or both could be exploited to locate the device with precision, accuracy and stability. Moreover, the implementation of the IMU may be used to track the location of the device when the time of flight measurement, taken optically or by means of ultrawi deband (UWB) or RF or all three, is not possible due to a ‘blind spot’, reduced or attenuated signal or inadequate camera or RF coverage. In this manner, the IMU output may be used to ‘smooth’ the location of the individual or equipment without RF, UWB or optical measurements of time of flight. In addition, a magnetometer may be used to generate a ‘map’ or chart of an environment, particularly if it is largely or partially metallic or ferrous metals are present. This log of the magnetic fields present in the industrial environment may be used to locate the sensor unit 15 by means of vertices or a point-map or a chart of magnetic field distribution around a office or floor or workspace or some other partially metallic environment. In this manner the sensor unit may locate tags or equipment in the absence of an optical or radio signal and when time of flight measurements that are optical or radio-frequency are limited, incomplete or inaccurate. The device of the invention may combine time of flight measurements, by means of measuring the time of flight of optical and / or RF signals to a device from nodes, or vice versa, with IMU measurements of attitude, altitude, velocity, acceleration and magnetic field strength, and comparison with a map or chart of magnetic fields in an environment overlaid on a layout or plan view of an industrial environment. Additional filtering of IMU measurements may be requirement by means of Kalman filtering and to exclude the motion of a moving frame of reference such as on board a ship, aircraft or floating platform. The map or chart or log of magnetic field strength may be compared with IMU measurements to provide a location when there is no, or limited, optical or RF signal and a time of flight measurement would be inaccurate. The sensor unit 15 can switch between methods or weight the output of different measurement depending on variables such as field strength, signal levels and drift. The time of flight measurements may be used to correct for IMU drift once RF and / or optical signal levels are acceptable and provide and accurate location or fix.

[0183] The storage medium tagging device may further include a near field communication (NFC) unit. The NFC unit may be scanned to identify the storage medium tagging device 10. The NFC unit may be scanned as an intangible asset 101 equipped with a storage medium tagging device 10 enters or exits the working environment 100. The presence of intangible asset 101 within the industrial environment 100 can therefore be additionally tracked.

[0184] The storage medium tagging device 10 may be configured to fit within a port of the or circuit board of storage medium 101 were the storage medium tagging device 10 is located. Alternatively or additionally, the storage medium tagging device may have a lanyard or other method of attaching the storage medium tagging device 10 to the storage media 101. The storage medium tagging device 10 may be mounted inside IT equipment, for example as part of an electronic assembly. The storage medium tagging device 10 may be provided as part of a jack, connector, Ethernet plug, dongle or USB flash memory drive. The storage medium tagging device 10 may be located in the USB port or another port of intangible asset storage medium 101, or as a ‘dongle’ to permit unlocking or, along with a password or some other identification such as fingerprint or facial scanning, decryption of confidential data on a storage medium 101 in an authorised location. The storage medium tagging device 10 should be mounted in such a way that feedback from the feedback unit 13 such as a signal is sensed by the storage medium 101. The storage medium tagging device 10 may be manufactured from a chemically resistant plastic. The storage medium tagging device 10 may have a maximum size of 50mm x 120mm x 25mm. The storage medium tagging device 10 may have a maximum weight of 100 g. The battery life of the storage medium tagging device 10 may be 1 month and may be a minimum of 1 week. The recharge time of the storage medium tagging device 10 may be a maximum of 6 hours.

[0185] The gateways 20 located at a predetermined location within the industrial environment 100 will now be described in more detail. A schematic diagram of an example of a gateway 20 is shown in fig. 5. The gateway 20 may include each of the components that may be included in the storage medium tagging device 10 described above. For example, the gateway 20 may include a processor 21, a wireless communication network interface 22 a wireless ranging network interface 26, a feedback unit 23, a battery 24 and a sensor unit 25. In addition to this, the communication unit 22 may have a wired connection to other gateways or the external controller, such as an Ethernet connection. The battery 24 of the gateway may be replaced by a wired power connection. The battery 24 of the gateway 20 may be of a larger capacity than the storage medium tagging device 10. The gateway may include an optical communications device with a LED and photodiode or camera or other light sensitive detector.

[0186] The calculation of the location of the intangible asset 101 described above may be performed by one of the plurality of gateways 20. The determination if the location of the intangible asset 101 falls outside a permitted zone may be performed by one of the plurality of gateways 20.

[0187] The plurality of gateways 20 and / or the storage medium tagging device 10 may be in communication with the external controller 40, which may be a computer. The computer may receive information from the plurality of gateways 20 and / or the storage medium tagging device 10 on the location of the intangible asset 101 within the working environment 100. The computer may display the locations of the gateways 20 and / or the storage medium tagging devices 10 on a map of the working environment 100 to an operator displayed on a graphical user interface (GUI). The GUI may show a plan of the working environment 100. The GUI may provide positional data from all of the gateways 20 and / or storage medium tagging devices 10 and equipment devices 30. The GUI may display the different components of the system in different colours. The GUI may show the location of restricted and permitted zones. The GUI may also show detailed information for all of the devices, such as a serial number, battery level, signal level, permitted users and time since last communication. A storage medium or equipment name may be associated with a device serial number. The operator may issue commands to the plurality of gateways 20 and / or the storage medium tagging device 10 using the computer. For example, the operator may cause the feedback unit 13 of the storage medium tagging device 10 to activate.

[0188] The system may support at least thirty storage medium tagging devices 10, twelve gateways 20, twenty equipment devices 30, and 2 control devices 40.

[0189] Sensing exfiltration of intangible assets

[0190] The authorised or permitted zone will now be described in more detail. The permitted zone represents an area or volume within the working environment 100 which may be authorised for access to, and collaboration situations using, intangible assets if entered by a storage medium tagging devices 101. The permitted zone may be a predefined volume of space in the working environment 100. Alternatively or additionally, the permitted zone may be associated with a room, floor, desk, workspace, shelf, container, compartment, server rack, server farm or piece of equipment 102 located in the working environment 100. The location of the permitted zone may be fixed within the working environment 100. The location of the permitted zone may be defined at the control device 40 using the GUI. The location and direction of teams of people authorised to work with intangible assets may be taken into account when defining the permitted zone, and users may be assigned permissions to work in the permitted zone..

[0191] Permitted zones may exist at multiple sites, for example certain office floors or rooms in separate buildings in a campus or rows or racks in a datacentre, or at different geographical sites. Based on the location of the storage medium tagging device 101, intangible assets may be encrypted between permitted zones at different sites (e.g. when moving a server between racks or rows in a datacentre), and then decrypted permitting access to intangible assets (such as the confidential information, secrets, files and data) when the location of the storage medium tagging device 101 is located within another permitted zone.

[0192] The location of the permitted zone associated with the piece of equipment 102 may be determined by locating an equipment device 30 on the piece of equipment 102. The equipment device 30 may be the same in construction as the storage medium tagging device 10 discussed above. The maximum size of the equipment device 30 may be 100mm x 120mm x 125mm. The maximum weight of the equipment device 30 may be 500g. The battery of the equipment device 30 may be larger than the battery 14 of the storage medium tagging device 10. The minimum battery life of the equipment device 30 may be 2 months. The equipment device 30 may be mounted or attached to a piece of equipment 102 using a releasable clip, a bolt, connector, coupling, welding, adhesive or a magnetic attachment or insertion into a network port, Ethernet or USB port as a dongle or peripheral. The equipment device 30 may perform any of the functions of the storage medium tagging device 10 as discussed above.

[0193] The equipment device 30 may be located on any piece of equipment 102 that may represent a storage medium for intangible asset 101 within the working environment. In the example of an office, the equipment device 30 may be located on equipment including a printer, firewall, network switch or server, computer, Wi-Fi access point and router. Multiple equipment devices 30 may be provided at different ports on a piece of equipment 102.

[0194] The time of flight of signals between the equipment device 30 located on the piece of equipment 102 (such as IT equipment) and the wireless network may be measured and the location of the piece of equipment 102 within the industrial environment 100 may be calculated based on the time of flight of the signals. The permitted zone may be based on the location of the piece of equipment 102. Control information associated with the piece of equipment 102 may also be obtained. The control information may be signals provided to the equipment 102 to operate switches, motors or actuators that cause the piece of equipment to operate or shut down 102. Alternatively or additionally, the control information may be measurements of the motion of the piece of equipment 102. The permitted zone may also be based on the control information associated with the piece of equipment 102.

[0195] The permitted zone does not necessarily define a single continuous area or volume. Separate regions of the permitted zone may be associated with different pieces of equipment 102 or other conditions within the working environment 100. For example, the storage medium tagging device 10 may encrypt intangible assets between permitted zones around different pieces of equipment 102, like a desktop computer, and decrypt intangible assets stored on storage media once within the storage medium tagging device 10 is located within another permitted zone around a piece of equipment 102, such as a printer. The permitted zone may be divided into different sub-zones depending on the level of access associated with a particular part of the permitted zone. For example, part of the zone associated with a piece of equipment 102 may be divided into an inner zone and an outer zone, where the inner zone defines a region closer to the piece of equipment 102 than the outer zone. The response of the system may be different depending on which sub zone that the location of the storage medium 101 is determined to be in. For example, the system may cause the storage medium tagging device 10 to encrypt intangible assets when the location of the storage medium 101 is determined to be in the outer zone. The system may then additionally activate an audible alarm and password protect the storage medium when the location of the storage medium tagging device

[0196] 101 moves outside inner zone. The size of the permitted zone associated with a piece of equipment

[0197] 102 may change if a piece of equipment 102 is in motion. For example, the size of the permitted zone may increase if the piece of equipment 102 is in motion. For example, if a worker is moving a laptop, server or flash memory device and its associated storage medium tagging device 10 from one room to another, or from one floor or building to another.

[0198] The remedial action may also vary depending on if the piece of equipment 102 is in motion. For example, when the piece of equipment 102 is in motion, a warning may be provided to the user of the control device 40 via the GUI. In this example, the warning indicates to the user to not initiate motion of the piece of equipment when storage medium tagging devices 101 are present in the permitted zone. When the equipment 102 is not in motion, a warning may not be provided to the user within the permitted zone. This may prevent distraction if storage medium tagging devices 101 are regularly within the permitted zone when the equipment 102 is not in motion. The remedial action may vary depending on the rate of motion of the piece of equipment 102. The remedial action may be password protecting, locking, ceasing processing, encrypting or shutting the piece of equipment 102 in a controlled manner to prevent corruption of the data on a piece of equipment 102. The remedial action may be shutting the piece of equipment 102 as quickly as possible, for example if it attempted to exfiltrate intangible assets 101 outside a permitted zone.

[0199] Permitted zones may be defined in two or three dimensions. For example, in two dimensions, a circular zone or polygon may be defined around a piece of equipment 102 or an equipment device 30. In three dimensions, a spherical danger zone may be defined around a piece of equipment 102. The zone may also be based on the movement path of a piece of equipment 102.

[0200] The storage medium tagging device 10, gateways 20 and equipment device 30 may also interface directly with pieces of equipment 102. The signal output if an intangible asset 101 is located outside a permitted zone may activate equipment access controls, encryption or password prompts.

[0201] Other features

[0202] A restricted zone may be defined within the industrial environment 100. The safe zone may be defined in the same way as the permitted zone, except that the permitted zone represents an area of the industrial environment 100 where an intangible asset 101 is unlikely to be secure. When the location of an intangible asset 101 is determined to fall within the restricted zone within the industrial environment 100, transmission of data from the storage medium associated with the storage medium tagging device 10 maybe stopped or even destroy confidential data. Other active functions of the storage medium associated with storage medium tagging device 10 may also be deactivated. Performing this reduction of operation of the storage medium tagging device 10 when the intangible 101 enters the restricted zone may reduce power consumption and extend the battery life of the storage medium tagging device 10.

[0203] Operation of the pieces of equipment 102 may also be based on when the location of the intangible asset 101 is determined to fall within the authorised zone. For example, operation of pieces of equipment 102 motors, actuators or switches may started once the location of the intangible asset 101 is determined to fall outside the restricted zone. Different parts or sections of the zone may be associated with different pieces of equipment 102. The operation of the storage medium tagging device 10 within the working environment 100 may also be tracked and controlled by determining that signals are not passing between the storage medium tagging device 10 and the wireless network and outputting a signal indicating that the location of the intangible asset 101 cannot be determined. This may occur if the battery 14 of the storage medium tagging device 10 has run out or a component of the storage medium tagging device 10 has broken. Operations in the working environment 100 may be shut down in response to the signal to allow the location of the intangible asset 101 with the nonoperative storage medium tagging device 10 to be located and issued with a working storage medium tagging device 10.

[0204] Any of the storage medium tagging device 10, gateways 20 and equipment device 30 may perform self-diagnostic tests at regular intervals. A self-diagnostic test of the storage medium tagging device 10 may be performed in response to the intangible asset 101 moving into a selfcheck zone within the working environment 100. A self-diagnostic test on any of the storage medium tagging device 10, gateways 20 and equipment device may be initiated from the control device 40. The self-diagnostic test may be initiated using the GUI. Any faults detected may be transmitted to the control device 40 and displayed to a user by the GUI. The control device 40 may log each warning signal generated by the system, for example for review at data security briefings. Self-diagnostic tests may include checking location, battery level, the signal level between different devices, whether a device is missing and whether the location of a device is unknown or if the determination of the location of the device has become unreliable or out of bounds. For example, if a storage medium tagging device 10 or an equipment device 30 is determined to be moving at an unexpectedly high speed, the determination of the location may be deemed unreliable. The location of the equipment device 30 may be compared to the control information associated with piece of IT equipment 102 on which the equipment device 30 is mounted. The feedback unit 13 of the device may also be tested. The test of the feedback unit 13 may familiarise the user with the haptic, audible or visual alarm provided by the feedback unit 13. Any of the components of the self-diagnostic tests may also be performed as part of a pre-use test. When issued with a storage medium tagging device 10, personnel may take the storage medium tagging device to a test zone in the working environment 100. The pre-use test may be performed in the test zone.

[0205] Camera system

[0206] The safety sensing system may be used in parallel with a surveillance system including one or more cameras. Such a surveillance system may detect the location of persons or equipment from images captured by the camera(s) using image analysis (e.g. comparison of at least one image for the presence or absence of an object, identification of the object as a piece of equipment or a human). Thus the surveillance system may determine if the location of the equipment or electronic device is outside a permitted zone in the working or industrial environment and output a warning signal in response thereto.

[0207] In addition, the safety sensing method implemented in the safety sensing system may further comprise receiving a signal from the surveillance system including positional information of a further equipment or electronic device in the industrial environment 100, determining that the positional information of the further IT equipment or electronic device does not correspond to the calculated location of the storage medium tagging device 10 within the industrial environment and outputting a warning signal in response thereto (i.e. alert to presence of an unauthorised, or untagged, piece of equipment). The presence of unauthorised IT equipment that has not been associated with a storage medium tagging device 10 in the working or industrial environment 100 may therefore be detected. In response to the warning signal, any of the remedial actions discussed above, for example the sounding of alarms, sending or emails or messages, or the stopping of network traffic or processing, or formatting of a storage medium or deletion of confidential data or data transfer to equipment 102 may be taken.

[0208] The positional information obtained from the surveillance system may also be used together with positional information calculated using the timing of the signals to improve the accuracy of calculation of the location of the storage medium tagging device within the intangible asset tracking system.

[0209] There will now be described an example of a surveillance system 200 employing cameras. The surveillance system 200 is arranged as follows.

[0210] The surveillance system 200 may be arranged as follows.

[0211] A device monitors the access to intangible assets stored in working environments and in storage media in or alongside IT equipment. The storage medium tagging device tracks motion and location of confidential information and may be integrated into electronic equipment or associated with fixed and portable storage media. The storage medium tagging device may combine radio frequency wireless communications with optical communications using a modulated light. The light may be a LED, or laser, acoustic or other emitter of visible or near-visible wavelengths such as UV or Infrared. The primary feature of the light is to warn colleagues of the presence of an unauthorised electronic device in a restricted zone, to alert workers to data theft and to interact with detector mechanisms such as cameras or photodetectors acting as a redundant communications method to complement radio frequency communications from and to the storage medium tagging device.

[0212] The light source may be detected using at least one camera, or photodetector, and messages received by means of detecting and monitoring modulation of the at least one light source. Similarly, the light source may modulate in time, colour or wavelength to transmit information at relatively high bandwidths. The modulated light source based on a LED or laser source may convey information about location, speed, acceleration and unique identifiers such as name, serial number and system log. The modulated light source has high contrast so that it may be detected by a camera even in the presence of direct sunlight, fog or poor lighting conditions.

[0213] More than one camera mounted at a known location and detecting the light source of the device, or a 360 camera, or some combination of cameras may be used to triangulate the exact location of the storage medium tagging device from more than one camera using known camera location, focal length and angle. Measurement of the angle of incident emitted light at each camera can be used to calculate the location of the electronic device, and therefore the intangible asset storage medium, rapidly and with a high degree of accuracy and precision. The location, in combination with time, can be used to determine the velocity and acceleration of the storage medium tagging device, and similarly the modulation of the light source can be used to transmit information such as velocity, acceleration, angle and identity. The location and velocity can be used, via an interface, to interlock or adjust the activity of IT equipment to avoid unauthorised access to confidential information and data exfiltration by physical means. The use of a light source such as a LED can overcome limitations of camera technology such as strong background lighting, glare, low or poor contrast, direct sunlight, fog, mist, rain and steam or smoke. Likewise, multiple modulated light sources may be used in the device to ensure redundancy and dirt, coatings, grease etc. To avoid distraction the light source may use an invisible wavelength such as UV or IR or some combination of wavelengths.

[0214] The storage medium tagging device incorporates a power supply, such as a battery, and may also incorporate radio-frequency wireless communications, a light source that may be modulated, such as a LED, and means for locating the device with a high degree of precision and accuracy by means of indoor real-time location or geolocation coupled with a locating and correction mechanism such as triangulation by means of radio frequency wireless transmissions from a network of beaconing wireless gateways.

[0215] The modulated light source may flash at known intervals in order to identify the source. The flashing light may be phase locked with an image detection device such as a camera so that by locking the imaging detection to the frequency of the flashing light a far higher signal to noise ratio may be achieved. High radio frequency transmissions may be exploited to locate the device to within 10 centimetres. Low power radar (e.g. UWB radar) may be used to detect or locate the presence of an object, machine or person in proximity.

[0216] Alternatively, rather than a modulated light source such as a flashing LED, a retroreflector mounted on the device or person or PPE may be used (as simple as a reflecting strip that is common on PPE suits and workwear). The retroreflector system often reflects a modulated light source and dramatically helps improve contrast in the presence of strong light or poor contrast. When coupled with a global shutter camera a very high signal to noise may be achieved. There are many variants on this technique. Some, depend on fdtering by wavelength or frequency and others depend on phase coding and coherent optical detection, or even modulating a retroreflector or making it wavelength specific.

[0217] A retroreflector bounces light back in the direction it came from. This can provide a superior signal to noise than a simple, or modulating, light source on the device since only a light source very close to the camera provides a very bright reflection whereas the same light source at some distance away may be a signal hundreds, or thousands, of times weaker. The light from the light source or retroreflector may be coupled with a detector or camera and their phases locked so that you take one image with the light on and one with the light off. In this manner, the difference in intensity between the two images from the retroreflector with the source light on and off (reflected and reflected respectively) will be very substantial. This helps makes light reflected from a retroflector visible even in direct sunlight. Contrast can be improved further by putting a narrow band optical filter in front of the camera. This stops most of the sun light but allow your light source through. You can have white light retroreflectors which reflect all wavelengths of visible, and near IR. You can also use coloured retroreflectors. Multiple lights sources can modulate at different rates. In the type of system this is less of an issue, because they are likely to be spatially separate, but may be useful when devices or people are co-located. Finally, it is possible to modulate the retroreflector. For example, by putting an LED shutter in front of it. This can be used to confirm the identity of a specific retro reflector.

[0218] The retroflector may be triggered by a light, or an array of lights, co-located or in the vicinity of the camera. The light may be flashing, and the camera or detector may be synchronised with the flashing light to improve signal to noise ratios. The phase of the light may be locked to the phase of the camera to exclude extraneous sources of light, such as background light, overhead lighting, lamps, reflections or direct sun light. Personal protective equipment includes boots, gloves, hard hats and overalls and may commonly incorporate reflecting strips. These strips may be retroreflective, or it not, may be upgraded, replaced or complimented with retroreflective surfaces or devices or strips on all clothing or equipment including QR codes, boots, hats, gloves and overalls. The system includes flashing sources of light, cameras or other suitable array detectors, and retroreflective surfaces or devices or strips mounted or incorporated into all objects such that, even if one surface is missing, another surface will be detected by the system. Additionally, the retroreflector may be encoded (e.g. reflect a particular wavelength, or omit a particular wavelength, or filter the received light to emit at a particular frequency or the strip may include filtering to adsorb certain wavelengths and emit others, such as a QR code or pattern, or colour) to identify a particular individual, piece of equipment or object when triggered by the modulated light source. The modulated light source may use a wavelength that is invisible to the human eye, such as near infra-red (NIR), mounted as a cluster of NIR LEDs around a camera, and that modulate at a frequency that is synchronised with the frequency of detection of the camera, and that is reflected by the retroreflectors mounted or incorporated onto the objects or IT equipment, or carried by the person on the office floor or around the building.

[0219] The retroflecting device or material or surface may be incorporated into surfaces as a removal device, as a sticker on IT equipment, as a retroreflective QR code on equipment, or sewn into materials, or as epaulettes etc. Likewise, it may be added to equipment and other objects around the floor or room. The retroreflector would be selected to have an aspect ratio, or surface area, to ensure that although it may be partially obscured by dirt or other objects, the remainder of the retroreflector is visible to the camera or other suitable detector synchronised to modulated or flashing light source triggering the retroreflector. Likewise, multiple retroreflective strips, stickers or labels may be added to the storage medium location device 10 and / or to the IT equipment and storage devices of interest.

[0220] In one embodiment, the storage medium location device 10 may be combined with the synchronous camera detection of retroreflective surfaces. Cameras mounted around an area or zone of operations may be used to synchronously identify personnel, or objects, by detecting light reflected by retroreflective surfaces, stickers, strips or materials or devices mounted on IT equipment, portable electronic devices and / or machinery. The camera is connected to a computer or processor and detects the object or machine by synchronously imaging illuminating and reflected light and comparing images recorded with and without illumination. The detected objects (e.g. IT equipment, portable electronic devices, anything with storage media) may be compared using the computer with storage medium tagging devices 10 associated with objects located by means of radio frequency triangulation using long wave or ultrawi deband RF location. If the objects detected by synchronous imaging of retroflected light are among those objects that are detected by means of storage medium tagging devices 10 using radio-frequency triangulation then no alarm is sounded and mitigating action, such as password protection and / or encryption of storage media in a given area in proximity to unauthorised equipment, may not be required. If, on the other hand, the machines detected by synchronous imaging of retroflected light are not among those detected by means of RF triangulation of storage medium tagging devices 10, then an alarm may be sounded and mitigating action may be required. In this manner, a system may be provided that alarms when unauthorised (i.e. untagged with a storage medium tagging device) equipment enters into a zone or defined area. Authorised personnel and equipment will carry a retroreflector(s) as well as RF triangulation storage medium tagging devices 10 for location and confirmation of identity, whereas all other persons and equipment will carry a retroreflector alone.

[0221] The retroreflector may be mounted in the most convenient manner such as a badges, sticker or label or tie, bag, or all of these. This retroreflector may be a spot, or strip, sticker, badge, cover, plate, brand, stitching, or strand of material or some combination of the above or surfaces and shapes that may be incorporated into the object such that it is permanently attached and may be visible from all angles. The retroreflective material may be wavelength specific such that it corresponds to the light emitted by the detection system and reflects only when illuminated and back in the direction of illumination. The images collected by the collection system may be processed and compared to eliminate noise and only record reflected light. The persons or objects so identified may be compared with the location of RF triangulated or wirelessly located storage medium tagging devices 10 associated with storage media and intangible assets to determine which IT equipment is present in a given area and which is authorised to be present in that area so as to trigger or cancel an alarm.

[0222] In a further embodiment of the device of the invention the optical detection method incorporates optical flow technology. An optical flow sensor, or an array or ‘globe’ mounted array, of optical flow sensors, is mounted on the device and utilised to capture a sequence of images of its surroundings. Images taken periodically, or images captures after a trigger such as movement detected by on-board accelerometers and / or IMU, by a CCD or some other imaging device to determine by how much the person or machine on which the device is mounted has moved relative to fixed features around the device and in the field of view of the optical flow sensor or sensors. The optical flow sensors may capture sequential images of prominent features such as lights, or modulating lights or flashing or coloured LEDs, floors, machines or other high-contract features inside a premises or around an office. The optical flow technology is exploited to locate the device by tracking movement of features in a series of sequential or periodic images. The optical flow sensor, or sensor array, could be mounted on a stationary surface with a view of a moving surface or the other way around. When the surface moved under the sensor the amount of movement could be measured by matching the images obtained from the sensor. The optical flow sensor or sensor array may exploit celestial navigation techniques to determine the location, velocity and movement of the device either at the device or remotely from the device. Likewise, the optical flow sensor or array or ‘globe’ may be mounted remotely, around the perimeter of the region containing the devices, personnel and machinery, and utilised to capture a series of sequential images to detect movement of prominent features such as lights, LEDs or retroreflected light to determine the location of machines, personnel and devices inside the region. Optical flow technology is widely used in wireless or corded optical mice with personal computers and is beginning to be used in drones and other autonomous flight machines because of widespread availability of generic, cheap, low- power consumption optical flow technology components and devices. The optical flow device or sensor detects relative motion between the person or machine onto which it is attached and some fixed feature such as a light or fixed surface of a rigid structure around the person or machine. Sequences of images are captured by a CCD imaging device or some optical detection device and compared to measure relative movement. The optical flow sensor may be mounted on the IT equipment, storage medium tagging devices 10 associated with storage media containing intangible assets 101, or some fixed or moving component of the machine or person to be detected and used to measure changes in angular rotation and / or axial orientation and / or position of a device, person of a machine. The optical flow sensor may be an application specific device that incorporates MEMS accelerometers, gyroscopes, hall effect sensors and processing on the same die. Integrated processing circuits may be implemented with the optical flow sensor to minimise power consumption. The optical flow sensor may incorporate a light source, such as a LED or solid-state laser, to periodically capture sequential images of a proximate surface or remote feature such as illumination lights inside a drilling derrick. The imaged surface in close proximity may be the flooring, or fixed surfaces, or lights, or a rigid structure, and these multiple sequential images may be processed to determine movement of optical flow sensor with respect to the proximate or remote surface. The device of the invention, incorporating an optical flow sensor, may determine and measure relative movement of a machine or person in this manner. The period of image capture may be frequent, up to milliseconds, minutes or even hours apart. Alternatively, the image capture frequency may be adjusted or intermittently triggered dynamically based on shock, vibration, motion, changes in magnetic flux, conductivity, magnetic field, movement, or changes in orientation detected by accelerometers, gyroscopes or inertial measurement units (IMUs).

[0223] The device of the invention may incorporate at least one optical flow sensor and may be mounted on a person or machine in a location such that clear, sequential images of a prominent proximate or remote feature or features may be captured. The device mounted on an item of IT equipment such as the dongle or plug of the storage medium tagging devices 10 and may capture images of the floor or ceiling and thereby determine movement and location of the storage medium tagging devices 10. Similarly, mounted on a storage medium tagging devices 10 in the port of a piece of IT equipment and looking downward at the floor the device may capture images of the deck to determine motion and location. Finally, an array or globe of optical flow sensors mounted on storage medium tagging devices 10 may look out at prominent features inside an office, floor, corridor, server rack or around a datacentre building and track them to determine motion and location. The optical flow sensor array may a detachable or optional peripheral to the primary device of the invention or integrated inside it. The output of the optical flow sensor may be combined with other sensor outputs from IMU, RF triangulation, optical location, machine vision, ultra-wideband, optical and / or RF time of flight location and image processing to produce a weighted location based on a suitable algorithm such as Kalman filtering.

[0224] A further advantage of incorporating an optical flow sensor, or array of optical flow sensors for example mounted on three axes, is that a direct measurement of velocity may be taken. This is advantageous since velocity measured using an IMU is the result of an integration of an acceleration measured using an accelerometer. A direct measurement of velocity using an optical flow sensor will have less noise than a result from integration of an acceleration measurement, particularly due to noise and drift from accelerometers. The effects of drift may be eliminated in this fashion since it is not based on an integration of potentially already noisy results and a ‘clean’ velocity measurement can be exploited in an algorithm to compute location with greater accuracy and precision, lower errors - for example in ‘blind-spots’ where RF coverage is limited. The velocity measurement taken using an optical flow sensor, or sensors, may be combined with IMU results to correct the IMU results for drift and noise. Likewise, measurements of angular rotation or orientation taken using optical flow sensors may be used to correct drift in gyroscopic measurements of orientation taken using an IMU, or drift from gyroscopic measurements taken using a MEMS-based IMU in particular. The storage medium tagging device 10 of the invention, with optical flow sensors, may be used to track storage media moving along a corridor or around an office or walkway with lighting at regular intervals or locations, for example, by measuring velocity and orientation exploiting optical flow techniques.

[0225] A key factor in an optical flow implementation is the ability to measure distances where the optical flow of a feature or object is registered. One or multiple optical flow sensors facing in multiple directions would ideally measure unknown distances to the walls / ceiling / floor etc. An example of a successful implementation of optical flow sensor tech is in downward facing cameras on drones, ideally used with an altimeter to calibrate the altitude and therefore the estimated speeds. The advantage is that using optical flow sensing is that it delivers a direct measurement of velocity and does not rely on integration of acceleration to obtain velocity which may be noisy since acceleration can include G. Optical flow can generate low noise measurements of velocity and rotation to correct solid-state gyroscopes which may be susceptible to drift. Finally, optical flow sensing could generate lower errors and better accuracy, and reduce the need for plural wireless location beacons or gateways, thus reducing infrastructure and widening coverage.

[0226] The use of more than one optical flow sensors in the storage medium tagging device 10, at a known distance apart, could be used to determine the depth or distance of an object. A further advantage of more than one camera or optical flow sensor imaging devices is redundancy in the event one is damaged or the lens is covered or obscured by dirt or obstacles. Stereo-cameras may be used for optical flow sensing of velocity and orientation of the storage medium tagging device 10 by gauging the depth of an object which is tracked by means of optical flow.

[0227] A downward facing camera (or cameras at a known distance apart) integrated into the storage medium tagging device 10 that is associated with a storage medium, or piece of IT equipment incorporating storage media (for example), may be connected as a peripheral or dongle to a port or some other piece of equipment could provide a good additional source of speed and rotation data which have different characteristics from both the UWB locations and the IMU data, which should mean it adds useful info to the Kalman Filter. The height from the floor is constrained to the height of the IT equipment - and this can be calibrated by knowing the height of the storage point and using air pressure change to estimate how far above that storage point it gets lifted to at the start of motion, or probably more practically we can use the speed when RF triangulation data is available to calibrate for height. Once known, optical flow should give a good estimate of velocity. Similarly, optical flow sensors may be used as a visual gyroscope - and this manner the device of the invention may be augmented by optical flow to serve as an optical IMU. There are off-the-shelf chips / boards targeted at drones - the PX4FLOW Smart Camera board. In the example shown at there is a very good looking tracking result from flying a drone along a path at 1.5m altitude, which is a similar use case. Critical factors to exploitation of an optical flow sensor as an IMU include: Mounting the camera so it can see the floor past the equipment. The office environment is generally well lit and floors are patterned. The advantage of optical flow is that it provides a useful independent source of data to a Kalman Filter, and can give accuracy in the working environment then it should have advantages over the IMU in some respects (measures velocity rather than acceleration, so less problems with integrating noise or components of gravity). The storage medium tagging device 10 for tracking, real-time location-encrypting and protecting intangible assets 101 contained in electronic storage media incorporates a processor and sensors for monitoring motion such as 3 -axis accelerometers, inclinometers, proximity sensors, electromagnetic sensors, gyroscopes, RF ID ultrawideband RF location, low-power radar and altimeters. Temperature, pressure and heart rate may also be monitored for logging of health or sensor condition.

[0228] Fig. 6 shows a storage media tagging device 10, 203 incorporating a storage medium that contains an intangible asset 101, or connected to and associated with a piece of equipment incorporates a storage medium that contains an intangible asset 101, that may accurately and precisely locate and track the position of a storage medium storing an intangible asset 101 by means of triangulation of emissions from a modulating light source, or retroreflected from retroflectors on the device, and detected from multiple cameras 204, 205 and 206 at known locations, or by means of triangulation of radio frequency emissions by multiple wireless receivers 207, 208 and 209 at known locations. An application of the storage medium tagging device 10, 203 of the invention is automated intangible asset tracking and data inventory that may include tracking of general location around the entire business. This may be deployed as a mobile ‘dynamic’ monitoring solution that could be moved into zones of temporary work (i.e. board meeting, customer visit, demonstration etc.), or permanently throughout a business when personnel 201, that may be required to wear a jacket 202, or other wearable 202, that comprises one or more storage medium tagging devices 10, 203, arrive for work and are assigned a storage medium tagging device 10, 203 for the duration of their stay as part of an automated intangible asset tracking solution. The system could provide a real-time inventory of intangible assets, their locations and uses. This could form part of an auditing or valuation task. The device of the invention may be exploited for tracking and moving in areas in a building other than a certain floor. The device may form part of an automated intangible asset tracking system, while having little or no RF triangulation infrastructure or gateways in different locations around the office (i.e. car park, machinery rooms, etc) where a precise location may not be required but you know that a storage medium tagging device 10, 203 is either THERE or NOT THERE.

[0229] Fig. 7 shows a storage medium tagging device 203 for locating an intangible asset on a storage medium 203 that incorporates a power supply 203a, a processor 203b, a modulated light source 203c such as a LED or retroreflector and a wireless radio transceiver 203d. The storage medium tagging device 203 may be incorporated into an item of IT equipment such as a flash memory device, computer, mass storage device, IT peripheral, plug, connector jack or dongle.

[0230] The intangible asset tracking system 200 employing cameras described with reference to Figs. 6 and 7 may be combined with the sensing system described above with reference to Figs. 1 to 5. The storage medium tagging device 10 may be combined with the storage medium device 203 or may be separately provided. Instead or as well, the respective detection systems may be combined.

[0231] Particular advantage is achieved by combining the outputs of any combination of the different detection systems described above which provide location of a storage medium or object storing an intangible asset. The combined output may provide more reliable detection of position. For example, because position is detected by different techniques, one or other of the techniques may be more effective due to local conditions around the of a storage medium or object with an intangible asset, which may vary as the of a storage medium or object moves around.

[0232] In one example, a wireless detection system, for example as used in the intangible asset sensing system described with reference to Figs. 1 to 6, with an optical detection system, for example as used in the intangible asset sensing system 200, including an optical detection system using a retroreflector (as a sticker or label) as described above. In that case, advantageously the wireless device and the retroreflector may be provided in predetermined relative positions to increase the accuracy of the combined detection result. In one example of this, the retroreflector may be provided on the storage medium tagging device 10 itself. In another example of this, the retroreflector and the wireless storage medium tagging device 10 may both be mounted to another object, for example an item of IT equipment handling or storing an intangible asset such as a server rack or desk, in the predetermined relative positions.

[0233] Embodiments include the following numbered clauses:

[0234] 1. An intangible asset tracking method for an intangible asset in an working environment, the method comprising: measuring the timing signal between a storage medium tagging device associated with a storage medium storing an intangible asset and a plurality of nodes located at predetermined locations in the working environment; calculating the location of the intangible asset within the industrial environment based on the measured timing of the signals; determining if the location of the intangible asset is within a permitted zone in the working environment and outputting a signal in response thereto.

[0235] 2. The method of clause 1, wherein plurality of nodes form a network of nodes and the signals are transmitted over the network.

[0236] 3. The method of clause 1 or 2, wherein measuring the timing signal comprises: collecting sequential signals using at least one sensor at the storage medium tagging device ; determining distances relative to the plurality of nodes from the storage medium tagging device ; and in respect of each node, measuring the location of the device.

[0237] 4. The method of any one of clauses 1 to 3, wherein the step of calculating the location of the storage medium storing an intangible asset is performed by the storage medium tagging device.

[0238] 5. The method of any one of clauses 1 to 4, wherein the step of calculating the location of the storage medium tagging device is performed by one or more of the plurality of nodes.

[0239] 6. The method of any one of clauses 1 to 5, wherein the step of determining if the location of the intangible falls within a permitted zone is performed by the storage medium tagging device.

[0240] 7. The method of any one of clauses 1 to 6, wherein the step of determining if the location of the intangible falls within a permitted zone is performed by one or more of the plurality of nodes.

[0241] 8. The method of any one of clauses 1 to 7, wherein the permitted zone is a predefined volume of space in the working environment.

[0242] 9. The method of any one of clauses 1 to 8, wherein the permitted zone is associated with a piece of equipment located in the working environment.

[0243] 10. The method of clause 9, further comprising: measuring the signals between an equipment device located on the piece of equipment and the plurality of nodes; and calculating the location of the piece of equipment within the working environment based on the measured signals of the nodes, and wherein the permitted zone is based on the calculated location of the piece of equipment.

[0244] 11. The method of clause 9 or 10, wherein the method further comprises receiving control information associated with the piece of equipment, and the permitted zone is based on the control information associated with the piece of equipment.

[0245] 12. The method of any one of clauses 1 to 11, wherein the method further comprises determining if the location of storage medium tagging device associated with a storage medium storing an intangible asset falls within a permitted zone within the industrial environment and ceasing performance of the method in response thereto.

[0246] 13. The method of any one of clauses 1 to 12, wherein the method further comprises determining whether the signals are failing to be passed between the storage medium tagging device and the wireless network and outputting an failure signal in response thereto.

[0247] 14. The method of any one of clauses 1 to 13, wherein the warning signal is received by the storage medium tagging device; and the storage medium tagging device provides a command to the storage medium on which the storage medium tagging device is located in response thereto.

[0248] 15. The method of any one of clauses 1 to 14, wherein the warning signal is received by a control device; and the control device displays an alert to the user of the control device in response thereto.

[0249] 16. The method of any one of clauses 1 to 15, wherein operation of equipment within the working environment is ceased in response to the warning signal.

[0250] 17. The method of any one of clauses 1 to 16, further comprising receiving a signal from a surveillance system including a camera, the signal including positional information of a further storage medium in the working environment; determining that the positional information of the further storage medium does not correspond to the calculated location of the storage medium tagging device within the working environment and outputting a warning signal in response thereto.

[0251] 18. An intangible asset sensing system for an intangible asset in an industrial environment, the system comprising a storage medium tagging device located on a storage medium storing an intangible asset and a plurality of nodes of a network located at predetermined locations in the industrial environment, the system being arranged to: measure the timing of signals between the storage medium tagging device and the plurality of nodes; calculate the location of the storage medium tagging device within the working environment based on the measured timing of the signals; and determine if the location of storage medium tagging device falls within a restricted zone in the industrial environment and output a signal in response thereto.

[0252] 19. A wireless device for locating an intangible asset, the device incorporating a processor, a power supply, an accelerometer and wireless communications and a modulated light source.

[0253] 20. The device of clause 19, whereby its location and position may be determined by means of ranging signals from nodes mounted at known positions and detecting the ranging signals from the nodes from multiple signals.

[0254] 22. A wireless device for locating an intangible asset, the device incorporating a processor, a power supply, an accelerometer and wireless radio communications and at least one retroreflector, reflecting light from a modulated light source and detected by a camera.

[0255] 23. A wireless device of clause 22, with at least one retroreflector, reflecting light from a light source and detected by a camera, whereby the retroreflector or light may be modulated or encoded to identify an object or storage medium.

[0256] 24. The device of any one of clauses 20 to 23, whereby its position may be determined by means of emissions using multiple optical detectors mounted at known positions and detecting the transmissions from the device.

[0257] 25. A storage medium tagging device for tracking the location of an intangible asset stored on a storage medium in a working environment by means of sensing of a timings signal from multiple nodes and incorporating a processor, a power supply and sensors for monitoring movement.

[0258] 26. The device of any one of clauses 20 to 25 wherein the power supply of the storage medium tagging device is replenished using energy scavenging from motion or vibration, or connection to a port of a piece of equipment, such as a USB peripheral or dongle.

[0259] 27. The device of any one of clauses 20 to 25, wherein the power supply is recharged or inductively charged.

[0260] 28. A method for detecting, securing and monitoring intangible assets in a defined zone or area, the method comprising: mounting a storage medium tagging device onto a first set of objects storing intangible assets; incorporating a storage medium tagging device on a set of objects storing intangible assets; mounting a storage medium tagging device on a set of objects storing intangible assets; locating the objects with timing signals from nodes at known locations; detecting objects using timing signals; locating objects incorporating storage medium tagging devices; comparing the location of the objects; and determining which objects are inside a defined zone or area.

[0261] 29. A method for detecting intangible assets in a defined zone or area, the method comprising: associating storage medium tagging devices with storage media or equipment storing intangible assets, measuring the ranging signals between a storage medium tagging device or equipment locating device located on the storage medium or equipment and a plurality of nodes located at predetermined locations in the working environment; calculating the location of the storage medium or equipment within the industrial environment based on the measured ranges from the nodes; determining the locations of intangible assets stored in storage media or equipment and determining if the location of the intangible asset is within a permitted or restricted zone in the working environment and outputting a signal in response thereto, and controlling switches, motors or actuators in response to the signal.

[0262] Embodiments also include the following numbered clauses:

[0263] 1. A method of authorising the use / access of data, the method comprising: determining the location of an intended use / access of data; obtaining one or more authorised locations in which the use / access of the data is authorised; and authorising the intended use / access of the data only if the location of the intended use / access is in one of the one or more authorised locations.

[0264] 2. The method according to clause 1, wherein the data comprises a digital asset.

[0265] 3. The method according to clause 2, wherein the digital asset is generated using blockchain technologies and / or exists within a blockchain ledger.

[0266] 4. The method according to clause 2 or 3, wherein the digital asset comprises cryptocurrency and / or a non-fungible token.

[0267] 5. The method according to any of clauses 2 to 4, wherein, when the intended use / access of the digital asset is authorised, the method further comprises recording the determined location of intended use / access of the digital asset in the digital asset and / or a blockchain ledger.

[0268] 6. The method according to clause 5, further comprising recording the locations of all authorised uses / access of the digital asset in the digital asset and / or a blockchain ledger.

[0269] 7. The method according to any of clauses 2 to 6, further comprising recording identification data of the system(s) used to determine each location of authorised use / access of the digital asset in the digital asset and / or a blockchain ledger. 8. The method according to any of clauses 2 to 7, the method further comprising using the digital asset to obtain the one of the one or more authorised locations.

[0270] 9. The method according to any of clauses 2 to 8, the method further comprising obtaining the one or more authorised locations from the computing device making the intended use / access of the digital asset

[0271] 10. The method according to any of clauses 2 to 9, wherein the intended use / access of digital asset is made by a computing device that is a cryptowallet.

[0272] 11. The method according to any preceding clause, further comprising using a location system, that is a substantial real time location system, to determine the location of the intended use / access of data.

[0273] 12. The method according to clause 11, wherein the location system is an ultra- wideband communications system, and the method comprises using ultra-wideband communications between the location system and a computing device, that is making the intended use / access of the data, to determine the location of the intended use / access of the data.

[0274] 13. The method according to clause 11 or 12, wherein the determined location of the intended use / access of data includes the actual geographical location of the intended use / access of data.

[0275] 14. The method according to any of clauses 11 to 13, further comprising: determining the location of the intended use / access of data relative to the location system used to determine the location of the intended use / access of data; and authenticating the location system.

[0276] 15. The method according to clause 14, further comprising measuring characteristics of the location system; and using the measured characteristics to authenticate the location system.

[0277] 16. The method according to any of clauses 11 to 15, wherein the location system comprises a plurality of nodes for determining the location of the intended use / access of the digital asset, the method comprising authenticating the location system through communications between the nodes; and / or the location system comprises a central control system and the method comprises authenticating the location system through communications between the nodes and the central control system.

[0278] 17. The method according to clause 16, further comprising the nodes, and optionally the central control system, using blockchain technologies to authenticate each other.

[0279] 18. The method according to any of clauses 11 to 17, the method further comprising: determining the location of the intended use / access of data in the computing device making the intended use / access of the data; and / or determining the location of the intended use / access of data in the location system.

[0280] 19. The method according to any of clauses 11 to 18, further comprising using a plurality of location systems to determine the location of the intended use / access of the data; wherein the location determination technologies used by the plurality of location systems include two or more of the detection of reflected light from the location of the intended use / access of the data, video / image(s) analysis of video / image(s) captured by camera(s), radio communications, inertial measurements and magnetic field measurements.

[0281] 20. The method according to any of clauses 11 to 19, the method further comprising determining the location of the computing device making the intended use / access of the data using both the location system and an inertial measurement unit comprised by the computing device.

[0282] 21. The method according to any of clauses 11 to 20, the method further comprising: providing the determined location of the computing device making the intended use / access of the data to a monitoring system; and tracking the location of the computing device by the monitoring system.

[0283] 22. The method according to any preceding clause, wherein the data is encrypted and the method further comprises only allowing the password / key for decrypting the data to be used if the intended use / access of the data is authorised. 23. The method according to any preceding clause, wherein access to the data requires a password / key and the method further comprises only allowing the password / key for accessing the data to be used if the intended use / access of the data is authorised.

[0284] 24. The method according to any of clauses 22 or 23, wherein the password / key is time limited.

[0285] 25. The method according to any of clauses 22 to 24, further comprising monitoring the presence of the computing device making the intended use / access of the data in an authorised location; and preventing use of the password / key if the computing device is not in an authorised location.

[0286] 26. The method according to any preceding clause, wherein: there are a plurality of different data types for use / access; each data type has one or more authorised locations where the use / access of the data of that data type is authorised; and the obtained one or more authorised locations are dependent on the data type.

[0287] 27. The method according to any preceding clause, wherein the data types include one or more of trade secrets, patient records, medical test results, customer data, financial data, payment processing data, transaction history data, engineering data, scientific experiment results, electronic component characterisation results, approved vendor lists, bills of materials, approved manufacturer lists, recipe data, confidential algorithms, source code, private images, metallurgical formulae, chemical ingredient data, invention disclosures, crypto assets, non- fungible tokens, cryptocurrency and other private, confidential and / or commercially sensitive data.

[0288] 28. The method according to any preceding clause, wherein one or more authorised locations include the locations of: one or more specific buildings such as vaults, galleries, safes, museums, banks, hospitals, retail locations and private addresses; one or more specific rooms in a building such as offices and server rooms; one or more specific floors of a building; one or more specific desks in an office; one or more specific containers in an office; one or more specific work stations; and one or more specific server racks in a server room. 29. The method according to any preceding clause, wherein one or more authorised locations are define in three dimensions.

[0289] 30. The method according to any preceding clause, wherein one or more authorised locations are dynamic locations that change over time.

[0290] 31. A computing device for using / accessing data, wherein the computing device is configured for use in the method according to any of clauses 1 to 30.

[0291] 32. The computing device according to clause 31, wherein the computing device is a crypto wallet, tag, or integrated device.

[0292] 33. A location system for determining the location of a computing device for using / accessing data, wherein the location system is configured for use in the method according to any of clauses 1 to 30.

[0293] 34. The location system according to clause 33, wherein the location system is an ultra- wideband communications system.

[0294] 35. A data use / access control system comprising: one or more computing devices according to any of clauses 31 or 32; and one or more location systems according to any of clauses 33 or 34.

[0295] Embodiments include a number of modifications and variations to the techniques described herein.

[0296] The flow charts and descriptions thereof herein should not be understood to prescribe a fixed order of performing the method steps described therein. Rather, the method steps may be performed in any order that is practicable. Although the present invention has been described in connection with specific exemplary embodiments, it should be understood that various changes, substitutions, and alterations apparent to those skilled in the art can be made to the disclosed embodiments without departing from the spirit and scope of the invention as set forth in the appended claims.

[0297] Methods and processes described herein can be embodied as code (e.g., software code) and / or data. Such code and data can be stored on one or more computer-readable media, which may include any device or medium that can store code and / or data for use by a computer system. When a computer system reads and executes the code and / or data stored on a computer-readable medium, the computer system performs the methods and processes embodied as data structures and code stored within the computer-readable storage medium. In certain embodiments, one or more of the steps of the methods and processes described herein can be performed by a processor (e.g., a processor of a computer system or data storage system). It should be appreciated by those skilled in the art that computer-readable media include removable and non-removable structures / de vices that can be used for storage of information, such as computer-readable instructions, data structures, program modules, and other data used by a computing system / environment. A computer-readable medium includes, but is not limited to, volatile memory such as random access memories (RAM, DRAM, SRAM); and non-volatile memory such as flash memory, various read-only-memories (ROM, PROM, EPROM, EEPROM), magnetic and ferromagnetic / ferroelectric memories (MRAM, FeRAM), phase-change memory and magnetic and optical storage devices (hard drives, magnetic tape, CDs, DVDs); network devices; or other media now known or later developed that is capable of storing computer-readable information / data. Computer- readable media should not be construed or interpreted to include any propagating signals.

Claims

Claims1. A computer-implemented method of authorising the use / access of data, the method comprising: using a location system, that is a substantial real time location system, to determine the location of an intended use / access of data by a computing device; authenticating the location system; obtaining one or more permitted locations in which the use / access of the data is allowed; and authorising the intended use / access of the data by the computing device only if the location system is authenticated and if the computing device is in one of the one or more permitted locations; wherein authenticating the location system comprises: measuring one or more characteristics of the location system; and authenticating the location system in dependence on a comparison of the measured one or more characteristics to one or more fingerprints of the location system.

2. The computer-implemented method according to claim 1, wherein the location system comprises a plurality of nodes for determining the location of the computing device.

3. The computer-implemented method according to claim 2, wherein the one or more characteristics include wireless characteristics that are determined in dependence on measurements of wireless communications between nodes of the location system.

4. The computer-implemented method according to claim 2 or 3, wherein the one or more characteristics include wireless characteristics that are determined in dependence on measurements of wireless communications between one or more nodes the location system and the computing device.

5. The computer-implemented method according to any of claims 2 to 4, wherein the wireless characteristics include the levels and / or properties of one or more of: background noise, signal- to-noise ratio, received signal strength, emissions data, radio frequency spectrum data, radio frequency reflection data, attenuation data, jitter data, harmonics data, interference data, and other electro-magnetic characteristics.

6. The computer-implemented method according to any of claims 2 to 5, wherein the one or more characteristics include the relative locations of nodes of the location system; and measuring one or more characteristics of the location system comprises determining the relative locations of the nodes in dependence on wireless communications between the nodes.

7. The computer-implemented method according to any preceding claim, wherein the one or more characteristics include characteristics that are determined in dependence on measurements of wired / cabled / fibre communications within the location system.

8. The computer-implemented method according to claim 7, wherein the characteristics include one or more of the lengths of one or more wires / cables / fibres within the location system and / or the attenuation of one or more wires / cables / fibres within the location system.

9. The computer-implemented method according to any preceding claim, wherein the one or more characteristics include one or more of measurements of altitude data, magnetometer data and barometric data.

10. The computer-implemented method according to any preceding claim, wherein the one or more characteristics include data from inertial sensors, gyroscopes and IMUs.

11. The computer-implemented method according to claim 2, or any claim dependent thereon, wherein the one or more characteristics include data on the entire operating time of each node of the location system.

12. The computer-implemented method according to any preceding claim, wherein each fingerprint includes a plurality of characteristics.

13. The computer-implemented method according to claim 12, wherein the plurality of characteristics included in the fingerprint include data on all of: the signal-to-noise ratio, the relative locations of the nodes of the location system, and the lengths of one or more wires / cables / fibres within the location system.

14. The computer-implemented method according to any preceding claim, further comprising redetermining one or more of the characteristics of the location system; and generating a new, or updated, fingerprint of the location system in dependence on the redetermined one or more characteristics.

15. The computer-implemented method according to claim 14, wherein the re-determined one or more characteristics include the background noise and / or signal-to-noise ratio.

16. The computer-implemented method according to any preceding claim, wherein authenticating the location system comprises comparing the measured one or more characteristics to a plurality of fingerprints of the location system.

17. The computer-implemented method according to any preceding claim, wherein each fingerprint comprises a historical record that includes past measurements of characteristics of the location system; and wherein authenticating the location system comprises comparing the measured one or more characteristics to the historical record.

18. The computer-implemented method according to any preceding claim, wherein the process for authenticating the location system is automatically performed: in response to the process for determining the location of the computing device by the location system being requested, performed, started or completed; repeatedly; and / or continuously.

19. The computer-implemented method according to any preceding claim, wherein the methodcomprises the location system authenticating itself.

20. The computer-implemented method according to any preceding claim, wherein the method comprises: performing mutual authentication techniques of the nodes with communications that are dependent on both one or more of the measured characteristics of the location system and also cryptographic keys of the nodes; authenticating the nodes in dependence on the mutual authentication techniques; and authenticating the location system only if all of the nodes of the location system are authenticated by the mutual authentication techniques.

21. The computer-implemented method according to claim 2, or any claim dependent thereon, wherein the process for authenticating the location system comprises: measuring, by each node of the location system, the current characteristics of the location system; and determining that the location system is authenticated in dependence on a comparison of the current characteristics determined at every node of the location system with the fingerprint.

22. The computer-implemented method according to any preceding claim, wherein the location system comprises a central control system; and each fingerprint is stored in the central control system.

23. The computer-implemented method according to claim 2, or any claim dependent thereon, wherein: each fingerprint is stored in one or more nodes of the location system; and / or the nodes of the location system use blockchain technologies to authenticate each other.

24. The computer-implemented method according to any preceding claim, wherein each fingerprintof the location system is generated / stored using blockchain technologies.

25. The computer-implemented method according to any preceding claim, further comprising: monitoring the state of the wires / cables / fibres and connections in the location system; and determining that the location system is not authorised in response to the detection of any breaks in the wires / cables / fibres or connections.

26. The computer-implemented method according to claim 2, or any claim dependent thereon, wherein the location system is an ultra-wideband communications system, the method comprising using ultra-wideband communications between the nodes and the computing device to determine the location of the computing device.

27. The computer-implemented method according to any preceding claim, further comprising a camera system, the method comprising using the camera system to record images and / or video of the computing device; and determining the location of the computing device in dependence on image / video analytics of the recorded images and / or video.

28. The computer-implemented method according to any preceding claim, wherein the data that the computing device intends to use / access comprises a digital asset.

29. The computer-implemented method according to claim 28, wherein the digital asset is generated using blockchain technologies and / or exists within a blockchain ledger.

30. The computer-implemented method according to claim 28 or 29, wherein the digital asset comprises cryptocurrency and / or a non-fungible token.

31. The computer-implemented method according to m any of claims 28 to 30, wherein, when the intended use / access of the digital asset is authorised, the method further comprises recording the determined location of intended use / access of the digital asset in the digital asset and / or a blockchain ledger.

32. The computer-implemented method according to claim 31, further comprising recording the locations of all authorised uses / access of the digital asset in the digital asset and / or a blockchain ledger.

33. The computer-implemented method according to any of claims 28 to 32, further comprising recording identification data of the authorised location system(s) used to determine each location of authorised use / access of the digital asset in the digital asset and / or a blockchain ledger.

34. The computer-implemented method according to any of claims 28 to 33, the method further comprising using the digital asset to obtain the one of the one or more permitted locations.

35. The computer-implemented method according to any of claims 28 to 34, the method further comprising obtaining the one or more authorised locations from the computing device making the intended use / access of the digital asset.

36. The computer-implemented method according to any of claims 28 to 35, wherein the intended use / access of digital asset is made by a computing device that is a cryptowallet.

37. The computer-implemented method according to any preceding claim, further comprising using a plurality of location systems to determine the location of the intended use / access of the data by the computing device; wherein the location determination technologies used by the plurality of location systems include two or more of the detection of reflected light from the location of the intended use / access of the data, video / image(s) analysis of video / image(s) captured by camera(s), radio communications, inertial measurements and magnetic field measurements.

38. The computer-implemented method according to any preceding claim, wherein the data that the computing device intends to use / access is encrypted and the method further comprises only allowing a password / key for decrypting the data to be used if the intended use / access of the data is authorised; and / or wherein access to the data requires a password / key and the method further comprises only allowing the password / key for accessing the data to be used if the intended use / access of the data is authorised.

39. The computer-implemented method according to any preceding claim, wherein: there are a plurality of different data types for use / access; each data type has one or more authorised locations where the use / access of the data of that data type is authorised; and the obtained one or more authorised locations are dependent on the data type.

40. The computer-implemented method according to claim 39, wherein the data types include one or more of trade secrets, patient records, medical test results, customer data, financial data, payment processing data, transaction history data, engineering data, scientific experiment results, electronic component characterisation results, approved vendor lists, bills of materials, approved manufacturer lists, recipe data, confidential algorithms, source code, private images, metallurgical formulae, chemical ingredient data, invention disclosures, crypto assets, non- fungible tokens, cryptocurrency and other private, confidential and / or commercially sensitive data.

41. The computer-implemented method according to any preceding claim, wherein one or more permitted locations include the locations of: one or more specific buildings such as vaults, galleries, safes, museums, banks, hospitals, retail locations and private addresses; one or more specific rooms in a building such as offices and server rooms; one or more specific floors of a building; one or more specific desks in an office; one or more specific containers in an office; one or more specific work stations; and one or more specific server racks in a server room.

42. A computing device for using / accessing data, wherein the computing device is configured for use in the computer-implemented method according to any of claims 1 to 41.

43. The computing device according to claim 42, wherein the computing device is a crypto wallet, tag, or integrated device.

44. A location system for determining the location of a computing device for using / accessing data, wherein the location system is configured for use in the method according to any of claims 1 to 41.

45. A data use / access control system comprising: one or more computing devices according to any of claims 42 or 43; and one or more location systems according to claim 44.

Citation Information

Patent Citations

  • Personnel safety sensing system

    WO2019186202A1

  • Personnel safety sensing

    WO2020044014A1

  • Secure data access

    GB2547453A

  • Location service for user authentication

    US20180167376A1

  • Resource sharing using device location tracking and blockchains

    US20190364046A1