Visual presentation of target readers using ble
BLE direction finding and channel sounding techniques in access control systems address inaccuracies in RSSI-based proximity detection, ensuring secure and efficient access control by determining the correct reader and reducing resource wastage.
Patent Information
- Application Number
- PCT/EP2025/071192
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-08-01
- Filing Date
- 2025-07-23
- Publication Date
- 2026-02-05
Smart Images

Figure EP2025071192_05022026_PF_FP_ABST
Abstract
Description
VISUAL PRESENTATION OF TARGET READERS USING BLEPRIORITY APPLICATION
[0001] This application claims priority to Indian Provisional Patent Application Serial Number 202411058401, filed on August 1, 2024, the disclosure of which is incorporated by reference herein in its entirety.BACKGROUND
[0002] Access control readers are widely used in various settings to control access to restricted areas. These readers are typically connected to a server that manages access control policies and configurations. In order to securely communicate with such readers, user devices employ various encryption protocols and exchange credentials.SUMMARY
[0003] In some aspects, the techniques described herein relate to a method including: determining a direction that a user device is pointing relative to locations of each of a plurality of access control readers; identifying an individual access control reader of the plurality of access control readers that corresponds to the direction that the user device is pointing; presenting, on a graphical user interface (GUI) of the user device, visual representations of the locations of the plurality of access control readers; and in response to identifying the individual access control reader that corresponds to the direction that the user device is pointing, visually indicating an individual visual representation in the GUI corresponding to the individual access control reader. As discussed below, the individual access control reader can be identified using direction as well as the distance from the user device. For distance measurement, the disclosed techniques use Bluetooth Channel Sounding (in some approaches) and the distance can be displayed to a user on the GUI. Different readers can be visually distinguished in the GUI based on their respective distances from the user device.
[0004] In some aspects, the techniques described herein relate to a method, further including: automatically transmitting a credential from the user device to the individual access control reader in response to identifying the individual access control reader that corresponds to the direction that the user device is pointing, the credential being associated with access to a resource protected by the individual access control reader.
[0005] In some aspects, the techniques described herein relate to a method, further including: enabling access to the resource protected by the individual access control reader based on the credential.
[0006] In some aspects, the techniques described herein relate to a method, wherein the resource includes a physical resource, and wherein the individual access control reader includes a physical access control system (PACS) reader.
[0007] In some aspects, the techniques described herein relate to a method, wherein the resource includes a logical resource, and wherein the individual access control reader includes a logical access control system (LACS) reader.
[0008] In some aspects, the techniques described herein relate to a method, further including: receiving, by the user device, a plurality of signals from the plurality of access control readers, wherein the direction is determined based on the plurality of signals.
[0009] In some aspects, the techniques described herein relate to a method, wherein the plurality of signals include Bluetooth Low Energy (BLE) signals.
[0010] In some aspects, the techniques described herein relate to a method, further including: determining a position in three-dimensional (3D) space based on at least one of BLE Direction Finding or BLE Channel Sounding processes.
[0011] In some aspects, the techniques described herein relate to a method, wherein the direction is determined based on analysis of an angular phase shift in the plurality of signals received in the plurality of frequencies by the user device from the plurality of the access control readers.
[0012] In some aspects, the techniques described herein relate to a method, wherein each of the plurality of access control readers includes a plurality of antennas, and wherein the individual access control reader simultaneously transmits a packet by the plurality of antennas of the individual access control reader, further including: determining an angle of departure of the user device relative to the individual access control reader based on respective times when the packet is received by the user device from the plurality of antennas of the individual access control reader.
[0013] In some aspects, the techniques described herein relate to a method, further including: transmitting, by the user device, a plurality of signals to the plurality of access control readers, wherein the direction is determined based on the plurality of signals.
[0014] In some aspects, the techniques described herein relate to a method, wherein each of the plurality of access control readers includes a plurality of antennas, further including: determining an angle of arrival of the user device relative to the individual access control reader based on respective times when the packet is received by the plurality of antennas of the individual access control reader.
[0015] In some aspects, the techniques described herein relate to a method, wherein each of the plurality of access control readers is located at a different height relative to the user device, the visual representations representing the different heights of the plurality of access control readers.
[0016] In some aspects, the techniques described herein relate to a method, further including: presenting, in the GUI, an image that depicts the plurality of access control readers, wherein the visual representations are overlaid on respective ones of the plurality of access control readers depicted in the image.
[0017] In some aspects, the techniques described herein relate to a method, further including: receiving input that selects the individual access control reader; and transmitting a credential to the individual access control reader in response to receiving the input.
[0018] In some aspects, the techniques described herein relate to a method, further including: restricting transmission of a credential to one of the plurality of access control readers based on the direction that the user device is pointing.
[0019] In some aspects, the techniques described herein relate to a method, further including: preventing transmission of the credential to a particular access control reader of the plurality of access control readers in response to determining that the direction that the user device is pointing fails to intersect the location of the particular access control reader. Specifically, in some aspects, the techniques described herein relate to a method, further including: preventing transmission of the credential to a particular access control reader of the plurality of access control readers in response to determining that the distance between the access control reader of the plurality of access control readers and the user device is greater than the distance between another access control reader of the plurality of access control readers, when both of them are located in the same direction that the user device is pointing.
[0020] In some aspects, the techniques described herein relate to a method, further including: animating the individual visual representation or visually distinguishing theindividual visual representation from other visual representations in the plurality of visual representations to visually indicate the individual visual representation.
[0021] In some aspects, the techniques described herein relate to a system including: one or more processors coupled to a memory including non-transitory computer instructions that, when executed by the one or more processors, cause the one or more processors to perform operations including: determining a direction that a user device is pointing relative to locations of each of a plurality of access control readers; identifying an individual access control reader of the plurality of access control readers that corresponds to the direction that the user device is pointing; presenting, on a graphical user interface (GUI) of the user device, visual representations of the locations of the plurality of access control readers; and in response to identifying the individual access control reader that corresponds to the direction that the user device is pointing and the distance from the user device, visually indicating an individual visual representation in the GUI corresponding to the individual access control reader.BRIEF DESCRIPTION OF THE DRAWINGS
[0022] FIG. 1 is a block diagram of an example access control system, according to some examples.
[0023] FIG. 2 illustrates an example diagram of an access control reader, according to some examples.
[0024] FIG. 3 illustrates an example diagram of a GUI of the user device, according to some examples.
[0025] FIG. 4 is a flowchart illustrating example operations of the access control system, according to some examples.
[0026] FIG. 5 is a block diagram illustrating an example software architecture, which may be used in conjunction with various hardware architectures herein described.
[0027] FIG. 6 is a block diagram illustrating components of a machine, according to some examples.DETAILED DESCRIPTION
[0028] Example methods and systems for performing access control with direction determination are described. In the following description, for purposes of explanation, numerous specific details are set forth in order to provide a thorough understanding ofthe examples. It will be evident, however, to one of ordinary skill in the art that examples of the disclosure may be practiced without these specific details.
[0029] Received Signal Strength Indicator (RS SI) is a metric used by various wireless communication systems, including Wi-Fi and Bluetooth, to estimate the power level that a receiving device gets from the signal of a specific transmitter. In the context of access control systems, RSSI can be employed to determine the proximity of a user to a particular access control reader. By measuring the strength of the signal from a user's device, such as a smartphone or RFID tag, the system can infer which reader is closer to the user, potentially streamlining the process of granting access based on proximity. However, the use of RSSI for determining proximity in access control systems presents several challenges and inefficiencies, primarily due to the inherent lack of accuracy in RSSI measurements. RSSI values can be significantly affected by various environmental factors such as physical obstacles (walls, doors), human bodies, and interference from other wireless devices. This variability can lead to inaccurate determinations of which access control reader is closer to the user.
[0030] This lack of precision can have direct implications for security. For instance, if an access control system mistakenly identifies a user as being closer to a secure entry point when they are actually not, it could erroneously grant access to an unauthorized individual who happens to be closer to the door. Conversely, a legitimate user might be denied access if the RSSI readings incorrectly show them as being further away from the door. Such scenarios not only compromise security but also undermine user trust in the system's reliability. Moreover, the inaccuracies in proximity detection can lead to a waste of system resources. In environments where access control readers are closely spaced, such as in large office buildings with multiple entry points, the RSSI fluctuations can cause the system to repeatedly engage multiple readers for a single access attempt. In addition, "Channel Sounding" features such as "Two Way Ranging" can be used by the reader / phone to accurately measure the distance between itself and the phone / reader. However, while this measurement is continuous and secure and cannot be spoofed it wastes resources and battery power. This not only increases the wear and tear on the hardware but also consumes more power and processing resources, as the system has to handle and analyze data from multiple readers instead of focusing on the single, correct one. Additionally, the system might need to process and log numerous erroneous access attempts, further straining the database and storage resources.
[0031] The present disclosure provides a security mechanism to address these issues. Specifically, the disclosed examples provide an intelligent solution, which can determine a direction to which a user device is pointing or heading. The disclosed examples can then communicate a credential to a particular access control device that corresponds to the direction of the user device. Specifically, the disclosed techniques determine a direction that a user device is pointing relative to locations of each of a plurality of access control readers, such as using BLE signals. The disclosed techniques identify an individual access control reader of the plurality of access control readers that corresponds to the direction that the user device is pointing and with the distance between the access control reader and the user device. The disclosed techniques also determine the distance between each of a plurality of access control readers and the user device, such as using BLE signals. The disclosed techniques present, on a graphical user interface (GUI) of the user device, visual representations of the locations of the plurality of access control readers. The disclosed techniques, in response to identifying the individual access control reader that corresponds to the direction that the user device is pointing and the distance between them, visually indicate an individual visual representation in the GUI corresponding to the individual access control reader.
[0032] This can be a solution for securely detecting and validating the intent of the user to open the door. With direction finding and Channel sounding processes of BLE, the reader can detect the direction of the user device and the distance of it from the reader, which can be used to ascertain whether the user is casually walking towards the door or is having the intention of opening the door. Once intent is determined, it can be used for various actions by the access control system, such as opening the door or any other activities. Since a reader enabled with direction finding and channel sounding can track the direction and / or distance of the user device, this can be used as one of the factors to determine "tail gating," which is an unauthorized person gaining access through a door opened by an authorized person, by following the later in a physically close manner.
[0033] FIG. 1 is a block diagram showing an example system 100, according to various examples. The system 100 can be an access control system that includes a client device 120 (e.g., a user device, such as a smartphone or electronic card containing one or more credentials), one or more access control devices 110 that control access to a protected asset, such as through a lockable door, or to a secure resource, such as an electronic file, and a server / controller 140 that are communicatively coupled over a network 130 (e.g.,LAN, WAN such as the Internet, WiFi, BLE, ultra-wideband (UWB) communication protocol, telephony network, or other wired or wireless communication protocols).
[0034] The client device 120 and the access control devices 110 can be communicatively coupled via electronic messages (e.g., packets exchanged over the Internet, BLE, UWB, WiFi Direct, Near-Field Communication (NFC), or any other protocol). While FIG. 1 illustrates a single access control device 110 and a single client device 120, it is understood that a plurality of access control devices 110 and a plurality of client devices 120 can be included in the system 100 in other examples. For example, the system 100 can include a plurality of access control devices 110 all within a close proximity to each other, such as within the same room or within 10 or 20 meters of each other. In such cases, the client device 120 may need to access an individual one of the many access control device 110 that are all in close proximity to each other. The disclosed techniques can automatically identify the individual one of the many access control devices 110 that the client device 120 intends to access or send a credential to based on a position in 3D space of the access control device 110 and direction towards which the client device 120 is pointing towards. This can be performed using one or more BLE techniques, including BLE Direction Finding or BLE Channel Sounding processes. In some cases, the client device 120, access control devices 110 and server / controller 140 can share the same network. In some cases, the client device 120, access control devices 110 and server / controller 140 can be coupled over different networks. For example, the client device 120 and access control device 110 can communicate via BLE, while access control device 110 communicates with server / controller 140 using another network, not coupled with the client device 120 connection network, such as the Internet or WiFi.
[0035] As used herein, the term “client device” may refer to any machine that interfaces to a communications network (such as network 130) to exchange credentials with an access control device 110, the server / controller 140, another client device 120, or any other component to obtain access to the asset or resource protected by the access control device 110. In some examples, the client device 120 can additionally or alternatively communicate directly with, e.g., an access control device or another client device 120, such as using BLE, BLE Channel Sounding processes, and / or BLE direction finding processes. The client device 120 can include or store one or more credentials which canbe provided to the access control device 110 for obtaining access to a protected physical or logical asset or resource.
[0036] In some cases, some or all of the components and functionality of the server / controller 140 can be included in the client device 120 and / or the access control device 110. A client device 120 may be, but is not limited to, a mobile phone, desktop computer, laptop, portable digital assistant (PDA), smart phone, a wearable device (e.g., a smart watch), tablet, ultrabook, netbook, laptop, multi-processor system, microprocessor-based or programmable consumer electronics, physical card, or any other communication device that a user may use to access a network.
[0037] The access control device 110 can include an access reader device (also referred to as an access control reader) connected to a secur e / protected resource (e.g., a door locking mechanism or backend server) that controls the secure / protected resource (e.g., door locking mechanism). The resource associated with the access control device 110 can include a door lock, an ignition system for a vehicle, or any other device that grants or denies access to a physical component or that can be operated to grant or deny access to the physical component. The access control device 110 can implement various additional BLE functionalities, such as BLE direction finding and / or BLE Channel Sounding Processes. For example, in the case of a door lock, the access control device 110 can deny access, in which case the door lock remains locked and the door cannot be opened; or can grant access, in which case the door lock becomes unlocked to allow the door to be opened. As another example, in the case of an ignition system, the access control device 110 can deny access, in which case the vehicle ignition system remains disabled and the vehicle cannot be started; or can grant access, in which case the vehicle ignition becomes enabled to allow the vehicle to be started.
[0038] Physical access control covers a range of systems and methods to govern access, for example by people, to secure areas or secure assets. Physical access control includes identification of authorized users or devices (e.g., vehicles, drones, etc.) and actuation of a gate, door, or other facility used to secure an area, or actuation of a control mechanism, e.g., a physical or electronic / software control mechanism, permitting access to a secure asset. The access control device 110 may form part of a physical access control system (PACS), which can include a reader (e.g., an online or offline reader) that may hold authorization data (also referred to access control information) and can be capable of determining whether credentials (e.g., from credential or key devices such as radiofrequency identification (RFID) chips in cards, fobs, or personal electronic devices such as mobile phones) are authorized for an actuator or control mechanism (e.g., door lock, door opener, software control mechanism, turning off an alarm, etc.), or a PACS can include a host server to which readers and actuators are connected (e.g., via a controller) in a centrally managed configuration.
[0039] In centrally managed configurations, readers can obtain credentials from credential or key devices (e.g., from one or more client devices 120) and pass those credentials to the PACS host server or headend system. The readers can send the credentials over a wired or wireless link. The host server then determines whether the credentials authorize access to the secure area or secure asset (or resource) and commands the actuator or other control mechanism accordingly by sending an allow / deny message back to the reader again over the wired or wireless link. While examples in physical access control are used herein, the disclosure applies similarly to logical access control system (LACS) use cases (e.g., logical access to personal electronic devices, logical access to personal online or electronic accounts or documents, etc.).
[0040] In general, the access control device 110 can include one or more of a memory, a processor, one or more antennas, a communication module, a network interface device, a user interface, a display, and a power source or supply. The memory of the access control device 110 can be used in connection with the execution of application programming or instructions by the processor of the access control device 110, and for the temporary or long-term storage of program instructions or instruction sets and / or credential or authorization data, such as credential data, credential authorization data, or access control data or instructions. For example, the memory can contain executable instructions that are used by the processor to run other components of access control device 110 and / or to make access determinations based on credential or authorization data.
[0041] The memory of the access control device 110 can include a transitory or non- transitory computer-readable medium. The computer-readable medium can be, for example, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device. More specific examples of suitable computer-readable medium include, but are not limited to, an electrical connection having one or more wires or a tangible storage medium such as a portable computerdiskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), Dynamic RAM (DRAM), any solid-state storage device in general, a compact disc read-only memory (CD-ROM), or other optical or magnetic storage device. Computer-readable media includes, but is not to be confused with, computer-readable storage medium, which is intended to cover all physical, non-transitory, or similar examples of computer-readable media.
[0042] The processor of the access control device 110 can correspond to one or more computer processing devices or resources. For instance, the processor can be provided as silicon, as a Field Programmable Gate Array (FPGA), an Application-Specific Integrated Circuit (ASIC), any other type of Integrated Circuit (IC) chip, a collection of IC chips, or the like. As a more specific example, the processor can be provided as a microprocessor, Central Processing Unit (CPU), or plurality of microprocessors or CPUs that are configured to execute instructions sets stored in an internal memory and / or memory of the access control device 110.
[0043] The antenna of the access control device 110 can correspond to one or multiple antennas and can be configured to provide for wireless communications between access control device 110 and a credential or key device (e.g., client device 120). The antenna can be arranged to operate using one or more wireless communication protocols and operating frequencies including, but not limited to, the IEEE 802.15.1, Bluetooth, BLE, NFC, ZigBee, Global System for Mobile communications (GSM), Code Division Multiple Access (CDMA), Wi-Fi, RF, UWB, and the like. By way of example, the antenna(s) can be RF antenna(s), and as such, may transmit / receive RF signals through free-space to be received / transferred by a credential or key device having an RF transceiver.
[0044] The antenna or antennas of the access control device 110 can be used to perform an angle of arrival approach and / or angle of departure approach for determining a direction to which a user device (e.g., client device 120) is pointing towards or a path of the user device. For example, as shown in the diagram 200 of FIG. 2, a user device 212 (e.g., client device 120) can transmit one or more signals and / or packets to each of many readers (e.g., access control device 110) to determine a direction that the user device 212 is pointing towards using an angle of arrival approach.
[0045] Specifically, Bluetooth Low Energy (BLE) direction finding is a technology that enhances the location services capabilities of standard BLE by enabling more precise positioning and direction detection. This technology primarily relies on two methods: Angle of Arrival (Ao A) and Angle of Departure (AoD). In the AoA approach 210, the device whose location (e.g., the user device 212) is being determined transmits a signal 240 containing a specific sequence known as a Constant Tone Extension (CTE). The receiving device (e.g., the reader 230), equipped with multiple antennas 232 and 234, captures this signal 240. By measuring or analyzing the angular phase shift or phase difference of the incoming signal 240 across these antennas 232 and 234, the reader 230 can determine the angle from which the signal is arriving. This angle information can then be used to triangulate the position of the transmitting device relative to the reader 230. This position can then be shared with the user device 212 for display on a GUI of the user device 212.
[0046] In some cases, in the AoD approach 220, the roles are reversed. The reader 230 with multiple antennas transmits the signal simultaneously using different antennas (e.g., the same packet is sent by each antenna using a respective signal 250 and 252). The receiving device (e.g., the user device 212), which can have a single antenna, receives these signals 250 and 252. The transmitting device sends the signals 250 and 252 in such a way that it varies systematically across its antennas, embedding directional information in the signals themselves or in a single signal. The user device 212 uses this information to determine the angle at which the signals 250 and 252 were sent, aiding in the localization process. This can then be used to determine the direction towards which the user device 212 is pointing, and the user device 212 can present this information on the GUI of the user device 212.
[0047] Bluetooth Channel Sounding uses a known technique called phase-based ranging (PBR) to perform high accuracy distance measurement. In PBR, two devices can measure the distance between them by estimating the phase offset or phase difference between a received unmodulated signal and a local oscillator (LO) signal. Multi-carrier phase ranging systems measure the phase difference between the received unmodulated signal and the LO signal at multiple RF frequencies to generate measured phase difference versus frequency curve, that is in turn used to determine the distance between the two devices.
[0048] A communication module or communication component of the access control device 110 can be configured to communicate according to any suitable communications protocol with one or more different systems or devices, either remote or local, to access control device 110, such as one or more client devices 120 and / or server / controller 140. In some cases, the communication module of the access control device 110 is configured to perform the disclosed authentication protocol securely.
[0049] In some cases, the communication module uses a same wired or wireless link between the access control device 110 and the server / controller 140 for all the communication modes. In some cases, the communication module uses one wired or wireless link between the access control device 110 and the server / controller 140 to communicate access control information and uses a different wired or wireless link to communicate or receive configuration information updates from the server / controller 140 over the IP communication mode.
[0050] The network interface device of the access control device 110 includes hardware to facilitate communications with other devices, such as a one or more client devices 120 and / or server / controller 140 (e.g., a PACS server), over a communication network, such as network 130, utilizing any one of a number of transfer protocols (e.g., frame relay, IP, transmission control protocol (TCP), user datagram protocol (UDP), hypertext transfer protocol (HTTP), etc.). Example communication networks can include a local area network (LAN), a wide area network (WAN), a packet data network (e.g., the Internet), mobile telephone networks (e.g., cellular networks), Plain Old Telephone (POTS) networks, wireless data networks (e.g., IEEE 802. 11 family of standards known as WiFi, IEEE 802.16 family of standards known as WiMax), IEEE 802.15.4 family of standards, and peer-to-peer (P2P) networks, among others. In some examples, the network interface device can include an Ethernet port or other physical jack, a Wi-Fi card, a Network Interface Card (NIC), a cellular interface (e.g., antenna, filters, and associated circuitry), or the like. In some examples, the network interface device can include a plurality of antennas to wirelessly communicate using at least one of singleinput multiple-output (SIMO), multiple-input multiple-output (MIMO), or multiple-input single-output (MISO) techniques.
[0051] A user interface of the access control device 110 can include one or more input devices and / or display devices. Examples of suitable user input devices that can be included in the user interface include, without limitation, one or more buttons, akeyboard or keypad, a mouse, a touch-sensitive surface, a stylus, a camera, a microphone, etc. Examples of suitable user output devices that can be included in the user interface include, without limitation, one or more LEDs, an LCD panel, a display screen, a touchscreen, one or more lights, a speaker, and so forth. It should be appreciated that the user interface can also include a combined user input and user output device, such as a touch-sensitive display or the like.
[0052] The network 130 may include, or operate in conjunction with, an ad hoc network, an intranet, an extranet, a virtual private network (VPN), a LAN, a wireless network, a wireless LAN (WLAN), a WAN, a wireless WAN (WWAN), a metropolitan area network (MAN), BLE, UWB, the Internet, a portion of the Internet, a portion of the Public Switched Telephone Network (PSTN), a POTS network, a cellular telephone network, a wireless network, a Wi-Fi® network, another type of network, or a combination of two or more such networks. For example, a network or a portion of a network may include a wireless or cellular network and the coupling may be a CDMA connection, a GSM connection, or other type of cellular or wireless coupling. In this example, the coupling may implement any of a variety of types of data transfer technology, such as Single Carrier Radio Transmission Technology (IxRTT), Evolution- Data Optimized (EVDO) technology, General Packet Radio Service (GPRS) technology, Enhanced Data rates for GSM Evolution (EDGE) technology, third Generation Partnership Project (3GPP) including 3G, fourth generation wireless (4G) networks, fifth generation wireless (5G) networks, Universal Mobile Telecommunications System (UMTS), High Speed Packet Access (HSPA), Worldwide Interoperability for Microwave Access (WiMAX), Long Term Evolution (LTE) standard, others defined by various standard setting organizations, other short range or long range protocols, or other data transfer technology. Other protocols for use by the access control devices can include Open Supervised Device Protocol (OSDP) and Wiegand.
[0053] In an example, as the client device 120 approaches the access control device 110 (e.g., comes within range of a BLE communication protocol), the client device 120 transmits credentials of the client device 120 over the network 130. In some cases, the credentials can be selected from a plurality of credentials based on a current geographical location of the client device 120. For example, multiple credentials each associated with a different geographical location can be stored on the client device 120. When the client device 120 comes within a certain distance of a geographical locationassociated with one of the credentials (e.g., within 10 meters), the client device 120 retrieves the associated credentials from local memory.
[0054] In one example, the client device 120 provides the credentials directly to the access control device 110. In such cases, the access control device 110 communicates the credentials with the server / controller 140. The server / controller 140 in FIG. 1 includes an authorization system 142. The server / controller 140, client device 120, and / or the access control device 110 can further include elements described with respect to FIGS. 5 and 6, such as a processor and memory, having instructions stored thereon, that when executed by the processor, causes the processor to control the functions of the server / controller 140, client device 120, and / or the access control device 110.
[0055] The server / controller 140 searches a list of credentials stored in the authorization system 142 to determine whether the received credentials match credentials from the list of authorized credentials for accessing a secure asset or resource (e.g., door or secure area) protected by the access control device 110. In response to determining that the received credentials are authorized to access the access control device 110, the server / controller 140 instructs the access control device 110 to perform an operation granting access for the client device 120 (e.g., instructing the access control device 110 to unlock a lock of a door).
[0056] In some examples, prior to granting access to the resource protected by the access control device 110, the access control device 110 and / or the server / controller 140 can perform operations to verify that the client device 120 is oriented and / or pointing in a direction that corresponds to a location of the access control device 110. This can be performed before, substantially simultaneous with, and / or after verifying that the credentials received from the client device 120 are authorized to access the asset or resource.
[0057] In some cases, the access control device 110 and / or the server / controller 140, in response to establishing a secure communication session with the client device 120 and / or in response to receiving the credential from the client device 120, can initiate a process to determine a direction and / or distance of the client device 120. For example, as shown in FIG. 2, there may exist multiple access control devices 110, 230 close to each other (e.g., within 10 or 20 meters of each other). In such cases, rather than sending the credentials and potentially obtaining access to a resource protected by each of the access control devices 110, only the access control device 110 in a location corresponding to adirection and / or at a specific distance from the client device 120, 212 receives the credential to enable access to the protected resource. In some cases, as discussed in FIG. 3 below, a ray is drawn from the current location of the client device 120 towards the determined direction at which the client device 120 is pointing. A determination is made as to which of the multiple access control devices 110 is in a location that intersects the ray or is within a threshold distance of the ray. The access control device 110 that is determined to be in the location that intersects the ray or is within the threshold distance of the ray, is selected as the access control device 110 that corresponds to the direction of the client device 120 and is provided with the credential by the client device 120 to enable access to the resource protected by the selected access control device 110.
[0058] In some examples, the client device 120 presents a GUI 300 shown in FIG. 3. The GUI 300 can include visual representations (e.g., icons) representing physical locations of each access control device 110. For example, the GUI 300 can present a current position indicator 324 representing the current location of the client device 120. The GUI 300 can determine the angle or orientation of each access control device 110 of the many access control devices 110 that are close to each other using the direction finding of the BLE, such as based on BLE signals received from the access control devices 110. The client device 120 can also determine a distance between the client device 120 and each access control device 110, such as using BLE Channel Sounding.
[0059] Using this information about the distance between the client device 120 and each access control device 110 and the angle of the client device 120 relative to a location of each access control device 110, the GUI 300 can position a first visual representation 312 of a first reader or access control device, a second visual representation 314 of a second reader or access control device, and a third visual representation 316 of a third reader or access control device in respective locations on the GUI 300. The client device 120 can draw a ray 330 from the current position indicator 324 along the direction that has been determined to which the client device 120 is pointing. The client device 120 can determine that the ray 330 intersects a location of the third reader or is within a threshold proximity of intersecting the location of the third reader. In response, the client device 120 can present the third visual representation 316 with a different visual indicator (e.g., in a different color or can animate by bouncing the third visual representation 316 up and down repeatedly to visually distinguish the third visual representation 316) than the first visual representation 312 and the second visualrepresentation 314. This informs the user about which of the many access control devices 110 the client device 120 will transmit the credential to gain access to the protected resource. Also, any access control device 110 that is not on the path of the ray 330 can be prevented from receiving the credential. For example, if the first visual representation 312 corresponds to the first reader that is not in a location intersected by the ray 330 (e.g. is in a location that fails to intersect the ray 330), the client device 120 prevents or restricts transmitting the credential associated with the first reader. This improves security and avoid unlocking resources that are not intended to be accessed by the user.
[0060] In some examples, a camera of the client device 120 can capture an image or video of an environment, such as using a rear-facing camera of the client device 120. The image or video can depict at least partially the plurality of access control devices 110 (e.g., the first reader, the second reader, and the third reader). The image or video can be presented in the GUI 300. The GUI 300 can then overlay the first visual representation 312, second visual representation 314, and third visual representation 316 on the image or video at the positions of the first, second and third readers that are depicted in the image or video.
[0061] In some examples, the GUI 300 can receive input that taps or selects one or more of the first visual representation 312, second visual representation 314, and third visual representation 316. In response, the GUI 300 identifies one or more access control devices 110 corresponding to the one or more visual representations that have been selected. The GUI 300 can then retrieve the corresponding credentials and transmit those credentials to the identified one or more access control devices 110.
[0062] In some cases, the plurality of access control device 110 can be at different vertical heights at the same location or at different locations. For example, the access control device 110 can correspond to individual lockers in a locker assembly. The GUI 300 can include altitude or height information corresponding to each of the access control devices 110. For example, access control devices 110 at a first height can be presented with a visual representation having a first color, and access control devices 110 at a second (higher or lower) height can be presented with a visual representation having a second color. This allows the user to select a particular access control device 110 to communicate with even though the access control device 110 may be at the same physical location as another access control device 110 but at a different height.
[0063] In some cases, the server / controller 140 coupled to a plurality of access control devices 110 may receive a credential from the client device 120 through one of the coupled access control devices 110 and also receive during the secure communication session, one or more instances of direction and / or distance information of the client device 120. The controller determines whether the received credential is authorized to access any of the coupled access control devices and also determines the user’s intent to access based on which one of those access control devices corresponds to the received direction and / or distance information of the client device 120. The controller then grants access to the access control device corresponding to the received direction and / or distance information and based on the credential. In some cases, the client device may provide subsequent updated direction and / or distance information in the same secure communication session and the controller may update its access determination by granting access to the client device corresponding to the updated direction and / or distance information and denying access to the prior client device 120. In some cases, during the secure communication session, the client device may be repeatedly polled for or may loop transmission of its current direction and / or distance information for the controller to receive.
[0064] FIG. 4 is a flowchart illustrating an example process or method 400 of the access control system 100, according to some examples. The process or method 400 may be embodied in computer-readable instructions for execution by one or more processors such that the operations of the process or method 400 may be performed in part or in whole by the functional components of the system 100; accordingly, the process or method 400 is described below by way of example with reference thereto. However, in other examples, at least some of the operations of the process or method 400 may be deployed on various other hardware configurations. Some or all of the operations of process or method 400 can be in parallel, out of order, or entirely omitted.
[0065] At operation 401, the server / controller 140 (e.g., a PACS server), the access control device 110, and / or client device 120 determine a direction that the client device 120 is pointing relative to locations of each of a plurality of access control readers (e.g., access control devices 110), as discussed above. The server / controller 140 (e.g., a PACS server), the access control device 110, and / or client device 120 can also determine a distance between the client device 120 and the access control device 110. The direction and / or distance information can be computed using BLE Channel Sounding and BLEdirection finding to identify a 3D position of the access control device 110. This can be used in environments where doors have two access control readers, one for ingress and another for egress. In such cases, readers can be placed on either sides of the wall besides the door, both will be at the same direction with respect to the client device 120. In this scenario, the system can differentiate between them only by using distance (e.g., obtained by the BLE Channel Sounding).
[0066] At operation 402, the client device 120 identifies an individual access control reader of the plurality of access control readers that corresponds to the direction that the client device 120 is pointing, as discussed above.
[0067] At operation 403, the client device 120 presents, on a GUI of the user device, visual representations of the locations of the plurality of access control readers, as discussed above.
[0068] At operation 404, the client device 120, in response to identifying the individual access control reader that corresponds to the direction that the client device 120 is pointing, visually indicates an individual visual representation in the GUI corresponding to the individual access control reader, as discussed above.
[0069] FIG. 5 is a block diagram illustrating an example software architecture 506, which may be used in conjunction with various hardware architectures herein described. FIG. 5 is a non-limiting example of a software architecture and it will be appreciated that many other architectures may be implemented to facilitate the functionality described herein. The software architecture 506 may execute on hardware such as machine 600 of FIG. 6 that includes, among other things, processors 604, memory 614, and I / O components 618. A representative hardware layer 552 is illustrated and can represent, for example, the machine 600 of FIG. 6. The representative hardware layer 552 includes a processing unit 554 having associated executable instructions 504. Executable instructions 504 represent the executable instructions of the software architecture 506, including implementation of the methods, components, and so forth described herein. The hardware layer 552 also includes memory and / or storage devices memory / storage 556, which also have executable instructions 504. The hardware layer 552 may also comprise other hardware 558. The software architecture 506 may be deployed in any one or more of the components shown in FIG. 1.
[0070] In the example architecture of FIG. 5, the software architecture 506 may be conceptualized as a stack of layers where each layer provides particular functionality.For example, the software architecture 506 may include layers such as an operating system 502, libraries 520, frameworks / middleware 518, applications 516, and a presentation layer 514. Operationally, the applications 516 and / or other components within the layers may invoke API calls 508 through the software stack and receive messages 512 in response to the API calls 508. The layers illustrated are representative in nature and not all software architectures have all layers. For example, some mobile or special purpose operating systems may not provide a frameworks / middleware 518, while others may provide such a layer. Other software architectures may include additional or different layers.
[0071] The operating system 502 may manage hardware resources and provide common services. The operating system 502 may include, for example, a kernel 522, services 524, and drivers 526. The kernel 522 may act as an abstraction layer between the hardware and the other software layers. For example, the kernel 522 may be responsible for memory management, processor management (e.g., scheduling), component management, networking, security settings, and so on. The services 524 may provide other common services for the other software layers. The drivers 526 are responsible for controlling or interfacing with the underlying hardware. For instance, the drivers 526 include display drivers, camera drivers, BLE drivers, UWB drivers, Bluetooth® drivers, flash memory drivers, serial communication drivers (e.g., Universal Serial Bus (USB) drivers), Wi-Fi® drivers, audio drivers, power management drivers, and so forth depending on the hardware configuration.
[0072] The libraries 520 provide a common infrastructure that is used by the applications 516 and / or other components and / or layers. The libraries 520 provide functionality that allows other software components to perform tasks in an easier fashion than to interface directly with the underlying operating system 502 functionality (e.g., kernel 522, services 524 and / or drivers 526). The libraries 520 may include system libraries 544 (e.g., C standard library) that may provide functions such as memory allocation functions, string manipulation functions, mathematical functions, and the like. In addition, the libraries 520 may include API libraries 546 such as media libraries (e.g., libraries to support presentation and manipulation of various media format such as MPREG4, H.264, MP3, AAC, AMR, JPG, PNG), graphics libraries (e.g., an OpenGL framework that may be used to render two-dimensional (2D) and three-dimensional (3D) in a graphic content on a display), database libraries (e.g., SQLite that may providevarious relational database functions), web libraries (e.g., WebKit that may provide web browsing functionality), and the like. The libraries 520 may also include a wide variety of other libraries 548 to provide many other APIs to the applications 516 and other software components / devices.
[0073] The frameworks / middleware 518 (also sometimes referred to as middleware) provide a higher-level common infrastructure that may be used by the applications 516 and / or other software components / devices. For example, the frameworks / middleware 518 may provide various graphic user interface functions, high-level resource management, high-level location services, and so forth. The frameworks / middleware 518 may provide a broad spectrum of other APIs that may be utilized by the applications 516 and / or other software components / devices, some of which may be specific to a particular operating system 502 or platform.
[0074] The applications 516 include built-in applications 538 and / or third-party applications 540. Examples of representative built-in applications 538 may include, but are not limited to, a contacts application, a browser application, a book reader application, a location application, a media application, a messaging application, and / or a game application. Third-party applications 540 may include an application developed using the ANDROID™ or IOS™ software development kit (SDK) by an entity other than the vendor of the particular platform, and may be mobile software running on a mobile operating system such as IOS™, ANDROID™, WINDOWS® Phone, or other mobile operating systems. The third-party applications 540 may invoke the API calls 508 provided by the mobile operating system (such as operating system 502) to facilitate functionality described herein.
[0075] The applications 516 may use built-in operating system functions (e.g., kernel 522, services 524, and / or drivers 526), libraries 520, and frameworks / middleware 518 to create UIs to interact with users of the system. Alternatively, or additionally, in some systems, interactions with a user may occur through a presentation layer, such as presentation layer 514. In these systems, the application / component "logic" can be separated from the aspects of the application / component that interact with a user.
[0076] FIG. 6 is a block diagram illustrating components of a machine 600, according to some examples, able to read instructions from a machine-readable medium (e.g., a machine-readable storage medium) and perform any one or more of the methodologies discussed herein. Specifically, FIG. 6 shows a diagrammatic representation of themachine 600 in the example form of a computer system, within which the instructions 610 (e.g., software, a program, an application, an applet, an app, or other executable code) for causing the machine 600 to perform any one or more of the methodologies discussed herein may be executed.
[0077] As such, the instructions 610 may be used to implement devices or components described herein. The instructions 610 transform the general, non-programmed machine 600 into a particular machine 600, such as the client device 120, access control device 110, or server / controller 140, programmed to carry out the described and illustrated functions in the manner described. In alternative examples, the machine 600 operates as a standalone device or may be coupled (e.g., networked) to other machines. In a networked deployment, the machine 600 may operate in the capacity of a server machine or a client machine in a server-client network environment, or as a peer machine in a peer-to-peer (or distributed) network environment. The machine 600 may comprise, but not be limited to, a server computer, a client computer, a personal computer (PC), a tablet computer, a laptop computer, a netbook, a set-top box (STB), a personal digital assistant (PDA), an entertainment media system, a cellular telephone, a smart phone, a mobile device, a wearable device (e.g., a smart watch), a smart home device (e.g., a smart appliance), other smart devices, a web appliance, a network router, a network switch, a network bridge, or any machine capable of executing the instructions 610, sequentially or otherwise, that specify actions to be taken by machine 600. Further, while only a single machine 600 is illustrated, the term "machine" shall also be taken to include a collection of machines that individually or jointly execute the instructions 610 to perform any one or more of the methodologies discussed herein.
[0078] The machine 600 may include processors 604, memory / storage 606, and I / O components 618, which may be configured to communicate with each other such as via a bus 602. In an example, the processors 604 (e.g., a CPU, a reduced instruction set computing (RISC) processor, a complex instruction set computing (CISC) processor, a graphics processing unit (GPU), a digital signal processor (DSP), an ASIC, a radiofrequency integrated circuit (RFIC), another processor, or any suitable combination thereof) may include, for example, a processor 608 and a processor 612 that may execute the instructions 610. The term “processor” is intended to include multi-core processors 604 that may comprise two or more independent processors (sometimes referred to as “cores”) that may execute instructions 610 contemporaneously. Although FIG. 6 showsmultiple processors 604, the machine 600 may include a single processor with a single core, a single processor with multiple cores (e.g., a multi-core processor), multiple processors with a single core, multiple processors with multiple cores, or any combination thereof.
[0079] The memory / storage 606 may include a memory 614, such as a main memory, or other memory storage, database, and a storage unit 616, both accessible to the processors 604 such as via the bus 602. The storage unit 616 and memory 614 store the instructions 610 embodying any one or more of the methodologies or functions described herein. The instructions 610 may also reside, completely or partially, within the memory 614, within the storage unit 616, within at least one of the processors 604 (e.g., within the processor’s cache memory), or any suitable combination thereof, during execution thereof by the machine 600. Accordingly, the memory 614, the storage unit 616, and the memory of processors 604 are examples of machine-readable media.
[0080] The I / O components 618 may include a wide variety of components to receive input, provide output, produce output, transmit information, exchange information, capture measurements, and so on. The specific I / O components 618 that are included in a particular machine 600 will depend on the type of machine. For example, portable machines such as mobile phones will likely include a touch input device or other such input mechanisms, while a headless server machine will likely not include such a touch input device. It will be appreciated that the I / O components 618 may include many other components that are not shown in FIG. 6. The I / O components 618 are grouped according to functionality merely for simplifying the following discussion and the grouping is in no way limiting. In various examples, the I / O components 618 may include output components 626 and input components 628. The output components 626 may include visual components (e.g., a display such as a plasma display panel (PDP), a LED display, a LCD, a projector, or a cathode ray tube (CRT)), acoustic components (e.g., speakers), haptic components (e.g., a vibratory motor, resistance mechanisms), other signal generators, and so forth. The input components 628 may include alphanumeric input components (e.g., a keyboard, a touch screen configured to receive alphanumeric input, a photo-optical keyboard, or other alphanumeric input components), point-based input components (e.g., a mouse, a touchpad, a trackball, a joystick, a motion sensor, or other pointing instrument), tactile input components (e.g., a physical button, a touch screen that provides location and / or force of touches or touch gestures, orother tactile input components), audio input components (e.g., a microphone), and the like.
[0081] In further examples, the I / O components 618 may include biometric components 639, motion components 634, environmental components 636, or position components638 among a wide array of other components. For example, the biometric components639 may include components to detect expressions (e.g., hand expressions, facial expressions, vocal expressions, body gestures, or eye tracking), measure biosignals (e.g., blood pressure, heart rate, body temperature, perspiration, or brain waves), identify a person (e.g., voice identification, retinal identification, facial identification, fingerprint identification, or electroencephalogram based identification), and the like. The motion components 634 may include acceleration sensor components (e.g., accelerometer), gravitation sensor components, rotation sensor components (e.g., gyroscope), and so forth. The environmental components 636 may include, for example, illumination sensor components (e.g., photometer), temperature sensor components (e.g., one or more thermometer that detect ambient temperature), humidity sensor components, pressure sensor components (e.g., barometer), acoustic sensor components (e.g., one or more microphones that detect background noise), proximity sensor components (e.g., infrared sensors that detect nearby objects), gas sensors (e.g., gas detection sensors to detection concentrations of hazardous gases for safety or to measure pollutants in the atmosphere), or other components that may provide indications, measurements, or signals corresponding to a surrounding physical environment. The position components 638 may include location sensor components (e.g., a GPS receiver component), altitude sensor components (e.g., altimeters or barometers that detect air pressure from which altitude may be derived), orientation sensor components (e.g., magnetometers), and the like.
[0082] Communication may be implemented using a wide variety of technologies. The I / O components 618 may include communication components 640 operable to couple the machine 600 to a network 637 or devices 629 via coupling 624 and coupling 622, respectively. For example, the communication components 640 may include a network interface component or other suitable device to interface with the network 637. In further examples, communication components 640 may include wired communication components, wireless communication components, cellular communication components, NFC components, Bluetooth® components (e.g., Bluetooth® Low Energy), Wi-Fi® components, and other communication components to provide communication via othermodalities. The devices 629 may be another machine or any of a wide variety of peripheral devices (e.g., a peripheral device coupled via a USB).
[0083] Moreover, the communication components 640 may detect identifiers or include components operable to detect identifiers. For example, the communication components 640 may include RFID tag reader components, NFC smart tag detection components, optical reader components (e.g., an optical sensor to detect one-dimensional bar codes such as Universal Product Code (UPC) bar code, multi-dimensional bar codes such as Quick Response (QR) code, Aztec code, Data Matrix, Dataglyph, MaxiCode, PDF417, Ultra Code, UCC RSS-2D bar code, and other optical codes), or acoustic detection components (e.g., microphones to identify tagged audio signals). In addition, a variety of information may be derived via the communication components 640, such as location via Internet Protocol (IP) geo-location, location via Wi-Fi® signal triangulation, location via detecting a NFC beacon signal that may indicate a particular location, and so forth.Glossary:
[0084] " CLIENT DEVICE" in this context refers to any machine that interfaces to a communications network to obtain resources from one or more server systems or other client devices or that communicates directly with such other devices or server systems. A client device may be, but is not limited to, a mobile phone, desktop computer, laptop, PDA, smart phone, tablet, ultrabook, netbook, laptop, multi-processor system, microprocessor-based or programmable consumer electronics, game console, STB, or any other communication device that a user may use to access a network.
[0085] "COMMUNICATIONS NETWORK" in this context refers to one or more portions of a network that may be an ad hoc network, an intranet, an extranet, a VPN, a LAN, a BLE network, a UWB network, a WLAN, a WAN, a WWAN, a MAN, the Internet, a portion of the Internet, a portion of the PSTN, a POTS network, a cellular telephone network, a wireless network, a Wi-Fi® network, another type of network, or a combination of two or more such networks. For example, a network or a portion of a network may include a wireless or cellular network and the coupling may be a CDMA connection, a GSM connection, or other type of cellular or wireless coupling. In this example, the coupling may implement any of a variety of types of data transfer technology, such as IxRTT, EVDO technology, GPRS technology, EDGE technology, 3GPP including 3G, 4G networks, UMTS, HSPA, WiMAX, LTE standard, othersdefined by various standard setting organizations, other long range protocols, or other data transfer technology.
[0086] "MACHINE-READABLE MEDIUM" in this context refers to a component, device, or other tangible media able to store instructions and data temporarily or permanently and may include, but is not limited to, RAM, ROM, buffer memory, flash memory, optical media, magnetic media, cache memory, other types of storage (e.g., Erasable Programmable Read-Only Memory (EEPROM)) and / or any suitable combination thereof. The term "machine-readable medium" should be taken to include a single medium or multiple media (e.g., a centralized or distributed database, or associated caches and servers) able to store instructions. The term "machine-readable medium" shall also be taken to include any medium, or combination of multiple media, that is capable of storing instructions (e.g., code) for execution by a machine, such that the instructions, when executed by one or more processors of the machine, cause the machine to perform any one or more of the methodologies described herein. Accordingly, a "machine-readable medium" refers to a single storage apparatus or device, as well as "cloud-based" storage systems or storage networks that include multiple storage apparatus or devices. The term "machine-readable medium" excludes signals per se.
[0087] " COMPONENT" in this context refers to a device, physical entity, or logic having boundaries defined by function or subroutine calls, branch points, APIs, or other technologies that provide for the partitioning or modularization of particular processing or control functions. Components may be combined via their interfaces with other components to carry out a machine process. A component may be a packaged functional hardware unit designed for use with other components and a part of a program that usually performs a particular function of related functions. Components may constitute either software components (e.g., code embodied on a machine-readable medium) or hardware components. A "hardware component" is a tangible unit capable of performing certain operations and may be configured or arranged in a certain physical manner. In various examples, one or more computer systems (e.g., a standalone computer system, a client computer system, or a server computer system) or one or more hardware components of a computer system (e.g., a processor or a group of processors) may be configured by software (e.g., an application or application portion) as a hardware component that operates to perform certain operations as described herein.
[0088] A hardware component may also be implemented mechanically, electronically, or any suitable combination thereof. For example, a hardware component may include dedicated circuitry or logic that is permanently configured to perform certain operations. A hardware component may be a special-purpose processor, such as a FPGA or an ASIC. A hardware component may also include programmable logic or circuitry that is temporarily configured by software to perform certain operations. For example, a hardware component may include software executed by a general-purpose processor or other programmable processor. Once configured by such software, hardware components become specific machines (or specific components of a machine) uniquely tailored to perform the configured functions and are no longer general-purpose processors. It will be appreciated that the decision to implement a hardware component mechanically, in dedicated and permanently configured circuitry, or in temporarily configured circuitry (e.g., configured by software) may be driven by cost and time considerations.Accordingly, the phrase "hardware component"(or "hardware-implemented component") should be understood to encompass a tangible entity, be that an entity that is physically constructed, permanently configured (e.g., hardwired), or temporarily configured (e.g., programmed) to operate in a certain manner or to perform certain operations described herein. Considering examples in which hardware components are temporarily configured (e.g., programmed), each of the hardware components need not be configured or instantiated at any one instance in time. For example, where a hardware component comprises a general-purpose processor configured by software to become a specialpurpose processor, the general-purpose processor may be configured as respectively different special-purpose processors (e.g., comprising different hardware components) at different times. Software accordingly configures a particular processor or processors, for example, to constitute a particular hardware component at one instance of time and to constitute a different hardware component at a different instance of time.
[0089] Hardware components can provide information to, and receive information from, other hardware components. Accordingly, the described hardware components may be regarded as being communicatively coupled. Where multiple hardware components exist contemporaneously, communications may be achieved through signal transmission (e.g., over appropriate circuits and buses) between or among two or more of the hardware components. In examples in which multiple hardware components are configured or instantiated at different times, communications between such hardwarecomponents may be achieved, for example, through the storage and retrieval of information in memory structures to which the multiple hardware components have access. For example, one hardware component may perform an operation and store the output of that operation in a memory device to which it is communicatively coupled. A further hardware component may then, at a later time, access the memory device to retrieve and process the stored output.
[0090] Hardware components may also initiate communications with input or output devices and can operate on a resource (e.g., a collection of information). The various operations of example methods described herein may be performed, at least partially, by one or more processors that are temporarily configured (e.g., by software) or permanently configured to perform the relevant operations. Whether temporarily or permanently configured, such processors may constitute processor-implemented components that operate to perform one or more operations or functions described herein. As used herein, "processor-implemented component" refers to a hardware component implemented using one or more processors. Similarly, the methods described herein may be at least partially processor-implemented, with a particular processor or processors being an example of hardware. For example, at least some of the operations of a method may be performed by one or more processors or processor-implemented components. Moreover, the one or more processors may also operate to support performance of the relevant operations in a "cloud computing" environment or as a "software as a service" (SaaS). For example, at least some of the operations may be performed by a group of computers (as examples of machines including processors), with these operations being accessible via a network (e.g., the Internet) and via one or more appropriate interfaces (e.g., an API). The performance of certain of the operations may be distributed among the processors, not only residing within a single machine, but deployed across a number of machines. In some examples, the processors or processor- implemented components may be located in a single geographic location (e.g., within a home environment, an office environment, or a server farm). In other examples, the processors or processor-implemented components may be distributed across a number of geographic locations.
[0091] "PROCESSOR" in this context refers to any circuit or virtual circuit (a physical circuit emulated by logic executing on an actual processor) that manipulates data values according to control signals (e.g., "commands," "op codes," "machine code," etc.) andwhich produces corresponding output signals that are applied to operate a machine. A processor may, for example, be a CPU, a RISC processor, a CISC processor, a GPU, a DSP, an ASIC, a RFIC, or any combination thereof. A processor may further be a multicore processor having two or more independent processors (sometimes referred to as "cores") that may execute instructions contemporaneously.ADDITIONAL DISCLOSURE AND EXAMPLES
[0092] Example 1 includes subject matter such as a method to operate an access control system, including: determining a direction that a user device is pointing relative to locations of each of a plurality of access control readers; identifying an individual access control reader of the plurality of access control readers that corresponds to the direction that the user device is pointing; presenting, on a graphical user interface (GUI) of the user device, visual representations of the locations of the plurality of access control readers; and in response to identifying the individual access control reader that corresponds to the direction that the user device is pointing, visually indicating an individual visual representation in the GUI corresponding to the individual access control reader.
[0093] In Example 2, the subject matter of Example 1 optionally including wherein the individual access control reader can be identified using direction as well as the distance from the user device.
[0094] In Example 3, the subject matter of any one of Examples 1-2, optionally including wherein Bluetooth Channel Sounding is used for distance measurement and the distance can be displayed to a user on the GUL
[0095] In Example 4, the subject matter of any one of Examples 1-3, optionally including wherein different readers can be visually distinguished in the GUI based on their respective distances from the user device.
[0096] In Example 5, the subject matter of any one of Examples 1-4, optionally including automatically transmitting a credential from the user device to the individual access control reader in response to identifying the individual access control reader that corresponds to the direction that the user device is pointing, the credential being associated with access to a resource protected by the individual access control reader
[0097] In Example 6, the subject matter of one or any combination of Examples 1-5 optionally including enabling access to the resource protected by the individual access control reader based on the credential.
[0098] In Example 7, the subject matter of Example 6 optionally including, wherein the resource includes a physical resource, and wherein the individual access control reader includes a physical access control system (PACS) reader.
[0099] In Example 8, the subject matter of Example 6 optionally including, wherein the resource includes a logical resource, and wherein the individual access control reader includes a logical access control system (LACS) reader.
[0100] In Example 9, the subject matter of Example 6 optionally including receiving, by the user device, a plurality of signals from the plurality of access control readers, wherein the direction is determined based on the plurality of signals.
[0101] In Example 10, the subject matter of one or any combination of Examples 7-9 optionally including, wherein the plurality of signals include Bluetooth Low Energy (BLE) signals.
[0102] In Example 11, the subject matter of Example 10 optionally including determining a position in three-dimensional (3D) space based on at least one of BLE Direction Finding or BLE Channel Sounding processes.
[0103] In Example 12, the subject matter of one or any combination of Examples 1-11 optionally including, wherein the direction is determined based on analysis of an angular phase shift in the plurality of signals received in the plurality of frequencies by the user device from the plurality of the access control readers.
[0104] In Example 13, the subject matter of one or any combination of Examples 1-11 optionally including, wherein each of the plurality of access control readers includes a plurality of antennas, and wherein the individual access control reader simultaneously transmits a packet by the plurality of antennas of the individual access control reader, further including: determining an angle of departure of the user device relative to the individual access control reader based on respective times when the packet is received by the user device from the plurality of antennas of the individual access control reader.
[0105] In Example 14, the subject matter of one or any combination of Examples 12-13 optionally including transmitting, by the user device, a plurality of signals to theplurality of access control readers, wherein the direction is determined based on the plurality of signals.
[0106] In Example 15, the subject matter of Example 14 optionally including, wherein each of the plurality of access control readers includes a plurality of antennas, further including: determining an angle of arrival of the user device relative to the individual access control reader based on respective times when the packet is received by the plurality of antennas of the individual access control reader.
[0107] In Example 16, the subject matter of Example 14 optionally including, wherein each of the plurality of access control readers is located at a different height relative to the user device, the visual representations representing the different heights of the plurality of access control readers.
[0108] In Example 17, the subject matter of one or any combination of Examples 15-16 optionally including presenting, in the GUI, an image that depicts the plurality of access control readers, wherein the visual representations are overlaid on respective ones of the plurality of access control readers depicted in the image.
[0109] In Example 18, the subject matter of Example 17 optionally including receiving input that selects the individual access control reader; and transmitting a credential to the individual access control reader in response to receiving the input.
[0110] In Example 19, the subject matter of Example 18 optionally including restricting transmission of a credential to one of the plurality of access control readers based on the direction that the user device is pointing.
[0111] In Example 20, the subject matter of Example 19 optionally including preventing transmission of the credential to a particular access control reader of the plurality of access control readers in response to determining that the direction that the user device is pointing fails to intersect the location of the particular access control reader.
[0112] In Example 21, the subject matter of Example 20 optionally including preventing transmission of the credential to a particular access control reader of the plurality of access control readers in response to determining that the distance between the access control reader of the plurality of access control readers and the user device is greater than the distance between another access control reader of the plurality of access control readers, when both of them are located in the same direction that the user device is pointing.
[0113] In Example 22, the subject matter of one or any combination of Examples 20-22 optionally including animating the individual visual representation or visually distinguishing the individual visual representation from other visual representations in the plurality of visual representations to visually indicate the individual visual representation.
[0114] In Example 23, the subject matter of Example 1 optionally including one or more processors coupled to a memory including non-transitory computer instructions that, when executed by the one or more processors, cause the one or more processors to perform operations including: determining a direction that a user device is pointing relative to locations of each of a plurality of access control readers; identifying an individual access control reader of the plurality of access control readers that corresponds to the direction that the user device is pointing; presenting, on a graphical user interface (GUI) of the user device, visual representations of the locations of the plurality of access control readers; and in response to identifying the individual access control reader that corresponds to the direction that the user device is pointing and the distance from the user device, visually indicating an individual visual representation in the GUI corresponding to the individual access control reader.
[0115] Example 24, the subject matter of one or any combination of Examples 1-4, 6- 17, 22 optionally including automatically receiving, at an access controller coupled to the plurality of access control readers, a credential from the user device, the credential being associated with access to a resource protected by one of the plurality of access control readers identified by the direction and / or distance information of the client device received during a secure communication session.
[0116] In Example 25, the subject matter of Example 24, optionally including granting by the controller access to the resource protected by the identified one of the plurality of access control readers based on the received credential and direction and / or distance information.
[0117] In Example 26, the subject matter of Example 25 optionally including receiving updated direction and / or distance information during the same secure communication session.
[0118] In Example 27, the subject matter of Example 26 optionally including granting access to a second resource protected by a second access control reader based upon the updated direction and / or distance information received.
[0119] In Example 28, the subject matter of Example 26 optionally including revoking the prior grant of access.
[0120] Example 29 includes subject matter such as an access control system, or can optionally be combined with one or any combination of Examples 1-28 and the hardware and software configurations disclosed with respect to Figures 3-6 to include such subject matter, including: one or more processors coupled to a memory comprising non- transitory computer instructions that, when executed by the one or more processors, cause the one or more processors to perform operations comprising: identifying a direction that a user device is pointing relative to locations of each of a plurality of access control readers and a distance between the user device and each of the plurality of access control readers; identifying an individual access control reader of the plurality of access control readers that corresponds to the direction and distance that the user device is pointing; presenting, on a graphical user interface (GUI) of the user device, visual representations of the locations of the plurality of access control readers; and in response to identifying the individual access control reader that corresponds to the direction and distance that the user device is pointing, visually indicating an individual visual representation in the GUI corresponding to the individual access control reader.
[0121] Example 30, includes subject matter such as non-transitory computer-readable instructions in an access control system, or can optionally be combined with one or any combination of Examples 1-29 and the hardware and software configurations disclosed with respect to Figures 3-6 to include such subject matter, including instructions that, when executed by one or more processors, configure the one or more processors to perform operations including: identifying a direction that a user device is pointing relative to locations of each of a plurality of access control readers and a distance between the user device and each of the plurality of access control readers; identifying an individual access control reader of the plurality of access control readers that corresponds to the direction and distance that the user device is pointing; presenting, on a graphical user interface (GUI) of the user device, visual representations of the locations of the plurality of access control readers; and in response to identifying the individual access control reader that corresponds to the direction and distance that the user device is pointing, visually indicating an individual visual representation in the GUI corresponding to the individual access control reader.
[0122] The above non-limiting Examples can be combined in any permutation. In this document, the terms “a” or “an” are used, as is common in patent documents, to include one or more than one, independent of any other instances or usages of “at least one” or “one or more.” In this document, the term “or” is used to refer to a nonexclusive or, such that “A or B ” includes “A but not B,” “B but not A,” and “A and B,” unless otherwise indicated. In this document, the terms “including” and “in which” are used as the plain- English equivalents of the respective terms “comprising” and “wherein.” Also, in the following claims, the terms “including” and “comprising” are open-ended, that is, a system, device, article, composition, formulation, or process that includes elements in addition to those listed after such a term in a claim are still deemed to fall within the scope of that claim. Moreover, in the following claims, the terms “first,” “second,” and “third,” etc. are used merely as labels, and are not intended to impose numerical requirements on their objects.
[0123] The above description is intended to be illustrative, and not restrictive. For example, the above-described examples (or one or more aspects thereof) may be used in combination with each other. Other embodiments can be used, such as by one of ordinary skill in the art upon reviewing the above description. The Abstract is provided to allow the reader to quickly ascertain the nature of the technical disclosure. It is submitted with the understanding that it will not be used to interpret or limit the scope or meaning of the claims. In the above Detailed Description, various features may be grouped together to streamline the disclosure. This should not be interpreted as intending that an unclaimed disclosed feature is essential to any claim. Rather, the subject matter may lie in less than all features of a particular disclosed embodiment. Thus, the following claims are hereby incorporated into the Detailed Description, with each claim standing on its own as a separate embodiment, and it is contemplated that such embodiments can be combined with each other in various combinations or permutations. The scope should be determined with reference to the appended claims, along with the full scope of equivalents to which such claims are entitled.
[0124] Changes and modifications may be made to the disclosed examples without departing from the scope of the present disclosure. These and other changes or modifications are intended to be included within the scope of the present disclosure, as expressed in the following claims.
[0125] The Abstract of the Disclosure is provided to allow the reader to quickly ascertain the nature of the technical disclosure. It is submitted with the understanding that it will not be used to interpret or limit the scope or meaning of the claims. In addition, in the foregoing Detailed Description, it can be seen that various features are grouped together in a single example for the purpose of streamlining the disclosure. This method of disclosure is not to be interpreted as reflecting an intention that the claimed examples require more features than are expressly recited in each claim. Rather, as the following claims reflect, inventive subject matter may lie in less than all features of a single disclosed example. Thus, the following claims are hereby incorporated into the Detailed Description, with each claim standing on its own as a separate example.
Claims
WHAT IS CLAIMED IS:
1. A method comprising: identifying a direction that a user device is pointing relative to locations of each of a plurality of access control readers and a distance between the user device and each of the plurality of access control readers; identifying an individual access control reader of the plurality of access control readers that corresponds to the direction and distance that the user device is pointing; presenting, on a graphical user interface (GUI) of the user device, visual representations of the locations of the plurality of access control readers; and in response to identifying the individual access control reader that corresponds to the direction and distance that the user device is pointing, visually indicating an individual visual representation in the GUI corresponding to the individual access control reader.
2. The method of claim 1, further comprising: automatically transmitting a credential from the user device to the individual access control reader in response to identifying the individual access control reader that corresponds to the direction and distance that the user device is pointing, the credential being associated with access to a resource protected by the individual access control reader.
3. The method of claim 2, further comprising: enabling access to the resource protected by the individual access control reader based on the credential.
4. The method of claim 3, wherein the resource comprises a physical resource, and wherein the individual access control reader comprises a physical access control system (PACS) reader.
5. The method of claim 3, wherein the resource comprises a logical resource, and wherein the individual access control reader comprises a logical access control system (LACS) reader.
6. The method of claim 1, further comprising: receiving, by the user device, a plurality of signals from the plurality of access control readers, wherein the direction and the distance is identified based on the plurality of signals.
7. The method of claim 6, wherein the plurality of signals comprises Bluetooth Low Energy (BLE) signals.
8. The method of claim 7, further comprising: determining a position in three-dimensional (3D) space based on at least one of BLE Direction Finding and BLE Channel Sounding processes.
9. The method of claim 6, wherein the direction is identified based on analysis of an angular phase shift in the plurality of signals received by the user device.
10. The method of claim 6, wherein each of the plurality of access control readers comprises a plurality of antennas, and wherein the individual access control reader simultaneously transmits a packet by the plurality of antennas of the individual access control reader, further comprising: determining an angle of departure of the user device relative to the individual access control reader based on respective times when the packet is received by the user device from the plurality of antennas of the individual access control reader.
11. The method of claim 1 , further comprising: transmitting, by the user device, a plurality of signals to the plurality of access control readers, wherein the direction is identified based on the plurality of signals.
12. The method of claim 11 , wherein each of the plurality of access control readers comprises a plurality of antennas, further comprising: determining an angle of arrival of the user device relative to the individual access control reader based on respective times when a packet is received by the plurality of antennas of the individual access control reader.
13. The method of claim 1, wherein each of the plurality of access control readers is located at a different height relative to the user device, the visual representations representing the different heights of the plurality of access control readers.
14. The method of claim 1, further comprising:presenting, in the GUI, an image that depicts the plurality of access control readers, wherein the visual representations are overlaid on respective ones of the plurality of access control readers depicted in the image.
15. The method of claim 1, further comprising: receiving input that selects the individual access control reader; and transmitting a credential to the individual access control reader in response to receiving the input.
16. The method of claim 1, further comprising: restricting transmission of a credential to one of the plurality of access control readers based on the direction that the user device is pointing.
17. The method of claim 16, further comprising: preventing transmission of the credential to a particular access control reader of the plurality of access control readers in response to determining that the direction that user device is pointing fails to intersect, at least within a provided tolerance, the location of the particular access control reader.
18. The method of claim 1, further comprising: animating the individual visual representation or visually distinguishing the individual visual representation from other visual representations in the plurality of visual representations to visually indicate the individual visual representation.
19. A system comprising: one or more processors coupled to a memory comprising non-transitory computer instructions that, when executed by the one or more processors, cause the one or more processors to perform operations comprising: identifying a direction that a user device is pointing relative to locations of each of a plurality of access control readers and a distance between the user device and each of the plurality of access control readers; identifying an individual access control reader of the plurality of access control readers that corresponds to the direction and distance that the user device is pointing;presenting, on a graphical user interface (GUI) of the user device, visual representations of the locations of the plurality of access control readers; and in response to identifying the individual access control reader that corresponds to the direction and distance that the user device is pointing, visually indicating an individual visual representation in the GUI corresponding to the individual access control reader.
20. A non-transitory computer-readable medium comprising non-transitory computer- readable instructions that, when executed by one or more processors, configure the one or more processors to perform operations comprising: identifying a direction that a user device is pointing relative to locations of each of a plurality of access control readers and a distance between the user device and each of the plurality of access control readers; identifying an individual access control reader of the plurality of access control readers that corresponds to the direction and distance that the user device is pointing; presenting, on a graphical user interface (GUI) of the user device, visual representations of the locations of the plurality of access control readers; and in response to identifying the individual access control reader that corresponds to the direction and distance that the user device is pointing, visually indicating an individual visual representation in the GUI corresponding to the individual access control reader.
Citation Information
Patent Citations
Data processing apparatus and associated user interfaces and methods
US20120068813A1
Systems and methods for locating tags
US20200042754A1
Capturing personal user intent when interacting with multiple access controls
US20200351661A1
Trajectory prediction with data normalization
WO2022128627A1
IN202411058401A