Secure resource control using light emission
By using a mobile device's flashlight as a LiFi transmitter to modulate light based on a transaction identifier, the system addresses BLE's inefficiencies and security vulnerabilities, ensuring accurate and reliable access control.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- ASSA ABLOY AB
- Filing Date
- 2025-10-09
- Publication Date
- 2026-04-23
AI Technical Summary
Existing mobile credential systems relying on Bluetooth Low Energy (BLE) for proximity determination face inefficiencies and security vulnerabilities due to unreliable Received Signal Strength Indicator (RSSI) measurements, leading to inaccurate access control decisions and potential unauthorized access.
Integrate a mobile device's flashlight as a Light Fidelity (LiFi) transmitter to enhance proximity verification by modulating light based on a transaction identifier, combining it with BLE for accurate access control.
Ensures secure and reliable proximity verification, maintaining compatibility across devices and environments, reducing false positives and negatives, and enhancing user confidence in access control systems.
Smart Images

Figure EP2025079131_23042026_PF_FP_ABST
Abstract
Description
SECURE RESOURCE CONTROL USING LIGHT EMISSIONPRIORITY APPLICATION(S)
[0001] This application claims priority to Indian Provisional Patent Application No. 202411077714, filed on October 14, 2024, the disclosure of which is incorporated by reference herein in its entirety.BACKGROUND
[0002] Smartphones often exhibit limitations in accurately measuring signal strength. This inaccuracy can lead to delays or premature communication between devices and control systems, resulting in a suboptimal user experience. The reliance on signal strength for triggering transactions poses challenges, particularly in environments where external factors affect signal strength.BRIEF SUMMARY
[0003] In some aspects, the techniques described herein relate to a system including: one or more hardware processors; and at least one machine-storage medium for storing instructions that, when executed by the one or more hardware processors, cause the one or more hardware processors to perform operations including: detecting an access control device that is within a threshold proximity to a mobile device; establishing a communication session between the mobile device and the access control device; receiving, by the mobile device via the communication session, a transaction identifier from the access control device; and modulating light emitted by one or more light emitting sources of the mobile device based on the transaction identifier to obtain access to a resource protected by the access control device in response to a credential provided by the mobile device.
[0004] In some aspects, the techniques described herein relate to a system, wherein the one or more light emitting sources include a flashlight of the mobile device.
[0005] In some aspects, the techniques described herein relate to a system, wherein the communication session includes a Bluetooth Low Energy (BLE) communication session or any other suitable communication session, such as a long-range wireless communication protocol (e.g., WiFi) or short-range wireless communication protocol.
[0006] In some aspects, the techniques described herein relate to a system, wherein the one or more light emitting sources include a light fidelity (LiFi) device of the mobile device.
[0007] In some aspects, the techniques described herein relate to a system, wherein the operations include: scanning, by the mobile device, received signal strength indicator (RSSI) signals transmitted by one or more access control devices; and determining that an individual RSSI signal of the received RSSI signals corresponds to a specified threshold.
[0008] In some aspects, the techniques described herein relate to a system, wherein the operations include: determining that the access control device is within the threshold proximity to the mobile device in response to determining that the individual RSSI signal transmitted by the access control device corresponds to the specified threshold.
[0009] In some aspects, the techniques described herein relate to a system, wherein the operations include: establishing the communication session in response to determining that the access control device is within the threshold proximity to the mobile device.
[0010] In some aspects, the techniques described herein relate to a system, wherein the operations include: receiving, from the access control device, a request for a credential; and transmitting, from the mobile device to the access control device, the credential to obtain access to the resource protected by the access control device.
[0011] In some aspects, the techniques described herein relate to a system, wherein the operations include: authorizing the mobile device to access the resource based on the credential received from the mobile device; and enabling access to the resource protected by the access control device in response to determining that the mobile device satisfies a proximity criterion.
[0012] In some aspects, the techniques described herein relate to a system, wherein the operations include: determining that the mobile device satisfies the proximity criterion based on processing the light emitted by one or more light emitting sources of the mobile device.
[0013] In some aspects, the techniques described herein relate to a system, wherein the operations include: determining that a pattern of the light emitted by the mobile device corresponds to the transaction identifier; and in response to determining that the pattern of the light emitted by the mobile device corresponds to the transaction identifier, determining that the mobile device satisfies the proximity criterion.
[0014] In some aspects, the techniques described herein relate to a system, wherein the access control device captures the pattern of the light using one or more photodiodes or any other suitable visible light sensor, such as Silicon Photodiodes, Avalanche Photodiodes (APD), PIN Photodiodes, and so forth.
[0015] In some aspects, the techniques described herein relate to a system, wherein the operations include: causing the access control device to provide access to the resource protected by the access control device in response to determining that the pattern of the light emitted by the mobile device corresponds to the transaction identifier.
[0016] In some aspects, the techniques described herein relate to a system, wherein the operations include: determining that the mobile device satisfies a proximity criterion based on processing the light emitted by one or more light emitting sources of the mobile device.
[0017] In some aspects, the techniques described herein relate to a system, wherein the operations include: in response to determining that the mobile device satisfies the proximity criterion based on processing the light emitted by one or more light emitting sources of the mobile device, transmitting, from the access control device, a request for a credential to the mobile device; and transmitting, from the mobile device to the access control device, the credential to obtain access to the resource protected by the access control device.
[0018] In some aspects, the techniques described herein relate to a system, wherein the operations include: causing the access control device to provide access to the resource protected by the access control device in response to determining that the credential is authorized to access the resource.
[0019] In some aspects, the techniques described herein relate to a method including: detecting an access control device that is within a threshold proximity to a mobile device; establishing a communication session between the mobile device and the access control device; receiving, by the mobile device via the communication session, a transaction identifier from the access control device; and modulating light emitted by one or more light emitting sources of the mobile device based on the transaction identifier to obtain access to a resource protected by the access control device in response to a credential provided by the mobile device.
[0020] In some aspects, the techniques described herein relate to a method, wherein the one or more light emitting sources include a flashlight of the mobile device.
[0021] In some aspects, the techniques described herein relate to a method, wherein the one or more light emitting sources include a LiFi device of the mobile device.
[0022] In some aspects, the techniques described herein relate to a machine-storage medium for storing instructions that, when executed by one or more hardware processors, cause the one or more hardware processors to perform operations including: detecting an access control device that is within a threshold proximity to a mobile device; establishing a communication session between the mobile device and the access control device; receiving, by the mobile device via the communication session, a transaction identifier from the access control device; and modulating light emitted by one or more light emitting sources of the mobile device based on the transaction identifier to obtain access to a resource protected by the access control device in response to a credential provided by the mobile device.BRIEF DESCRIPTION OF THE SEVERAL VIEWS OF THE DRAWINGS
[0023] To easily identify the discussion of any particular element or act, the most significant digit or digits in a reference number refer to the figure number in which that element is first introduced.
[0024] FIG. 1 is a diagrammatic representation of a networked environment in which the present disclosure may be deployed, in accordance with some examples.
[0025] FIG. 2 illustrates a diagram of an environment for accessing a secure resource, in accordance with some examples.
[0026] FIG. 3 illustrates a diagram of a sequence of operations for accessing a secure resource, in accordance with some examples.
[0027] FIG. 4 illustrates a routine for accessing a secure resource, in accordance with some examples.
[0028] FIG. 5 is a block diagram illustrating a representative software architecture, which may be used in conjunction with various hardware architectures herein described, in accordance with some examples.
[0029] FIG. 6 is a diagrammatic representation of a machine in the form of a computer system within which a set of instructions may be executed for causing the machine to perform any one or more of the methodologies discussed herein, in accordance with some examples.DETAILED DESCRIPTION
[0030] Example methods and systems for an access control system are described. In the following description, for purposes of explanation, numerous specific details are set forth in order to provide a thorough understanding of the disclosed examples. It will be evident, however, to one of ordinary skill in the art that examples of the disclosure may be practiced without these specific details.
[0031] In mobile credential systems, devices commonly utilize technologies such as Near Field Communication (NFC) and Bluetooth Low Energy (BLE) to interact with access control readers. While BLE's widespread support across various devices and operating systems has made it a prevalent choice, its extended range — typically up to 100 meters — poses significant challenges in environments where precise proximity determination is crucial, such as physical access control systems. This extended range can lead to ambiguity in determining which user has authenticated with a reader, potentially compromising security by allowing unauthorized access from a distance.
[0032] Current solutions often rely on the Received Signal Strength Indicator (RS SI) to estimate proximity between devices. RS SI measures the power level of a received signal, with stronger signals theoretically indicating closer proximity. However, this approach is fraught with inefficiencies and potential waste of resources. RS SI can be notoriously unreliable due to a multitude of factors, including environmental conditions, physical obstacles, and device-specific characteristics such as power output and antenna design. Interference from other electronic devices, signal reflections, and multipath propagation can further distort RSSI readings, leading to inconsistent proximity verification and potentially inaccurate access control decisions.
[0033] The reliance on RSSI for proximity determination often results in a system that is overly sensitive to fluctuations in signal strength, which can occur due to factors unrelated to actual distance. This sensitivity can lead to false positives, where the system may grant access when devices are actually too far apart, or false negatives, denying access even when devices are within the intended range. These inaccuracies not only compromise security but also lead to user frustration and reduced confidence in the access control system.
[0034] In summary, existing systems that rely on BLE, particularly with BLE using RSSI for proximity determination, suffer from significant inefficiencies and potential security vulnerabilities. These shortcomings stem from the inherent limitations of RSSI-based distance estimation, the extended range of BLE, and the susceptibility of these technologies to environmental interference. As a result, these systems often struggle to provide the level of accuracy and reliability required for secure and efficient access control.
[0035] The disclosed system addresses these challenges by integrating a novel approach to proximity validation in mobile credential systems. The system leverages the mobile device's flashlight as a LiFi transmitter to enhance proximity verification during the credential handshake process. This method ensures compatibility across a wide range of devices and maintains secure and reliable proximity verification, even in the absence of NFC capabilities. By combining BLE with close-range LiFi, the system provides a robust solution for accurate access control. LiFi is a wireless communication technology that uses light to transmit data. It operates by modulating the intensity of light emitted by a light source, such as an LED or flashlight, to encode data. This data is then received by a photodetector or one or more photodiodes, which decode the light signals back into electronic data. LiFi offers high-speed data transmission and can be used as an alternative to radio frequency-based wireless communication technologies like Wi-Fi. It can be useful in environments where radio frequencies may cause interference or are not permitted.
[0036] Specifically, the disclosed techniques detect an access control device (e.g., a physical access control (PAC) device) that is within a threshold proximity to a mobile device. The disclosed techniques establish a communication session between the mobile device and the access control device and receive, by the mobile device via the communication session, a transaction identifier from the access control device. The disclosed techniques modulate light emitted by one or more light emitting sources of the mobile device based on the transaction identifier to obtain access to a resource protected by the access control device.
[0037] FIG. 1 is a block diagram showing an example access control system 100, according to various examples. The access control system 100 can include a client device 120 (e.g., mobile device) and PAC devices 110 that can be used to determine a location of one or more objects. The client device 120 and the PAC devices 110 are communicatively coupled over a network 130 (e.g., Internet, BLE, ultra-wideband (UWB) communication protocol, Near Field Communication (NFC), and / or telephony network). While the disclosed techniques are discussed in the context of PAC devices,similar techniques are applicable to any other type of access control device, such as a logical access control (LAC) device.
[0038] As used herein, the term “client device” may refer to any machine that interfaces to a communications network (such as network 130) to exchange credentials with an access control device, such as the PAC devices 110, a server / controller associated with the access control device, another client device 120, or any other component to obtain access to a logical or physical asset or resource protected by the access control device. In some examples, the client device 120 can additionally or alternatively communicate directly with, e.g., an access control device or another client device 120. The client device 120 can include or store one or more credentials which can be provided to the access control device 110 for obtaining access to a protected physical or logical asset or resource.
[0039] A client device 120 may be, but is not limited to, a mobile phone, desktop computer, laptop, portable digital assistant (PDA), smart phone, a wearable device (e.g., a smart watch), tablet, ultrabook, netbook, laptop, multi-processor system, microprocessor-based or programmable consumer electronics, physical card, or any other communication device that a user may use to access a network.
[0040] The access control device (e.g., the PAC devices 110) can include an access reader device (also referred to as an access control reader) connected to a secure / protected resource (e.g., a door locking mechanism or backend server) that controls the secure / protected resource (e.g., door locking mechanism). The resource associated with the access control device can include a door lock, an ignition system for a vehicle, or any other device that grants or denies access to a physical component or that can be operated to grant or deny access to the physical component. For example, in the case of a door lock, the access control device can deny access, in which case the door lock remains locked and the door cannot be opened; or can grant access, in which case the door lock becomes unlocked to allow the door to be opened. As another example, in the case of an ignition system, the access control device can deny access, in which case the vehicle ignition system remains disabled and the vehicle cannot be started; or can grant access, in which case the vehicle ignition becomes enabled to allow the vehicle to be started.
[0041] Physical access control (PAC) covers a range of systems and methods to govern access, for example by people, to secure areas or secure assets. Physical access controlincludes identification of authorized users or devices (e.g., vehicles, drones, etc.) and actuation of a gate, door, or other facility used to secure an area, or actuation of a control mechanism, e.g., a physical or electronic / software control mechanism, permitting access to a secure asset. The access control device may form part of a physical access control system (PACS), which can include a reader (e.g., an online or offline reader) that may hold authorization data (also referred to access control information) and can be capable of determining whether credentials (e.g., from credential or key devices such as radio frequency identification (RFID) chips in cards, fobs, or personal electronic devices such as mobile phones) are authorized for an actuator or control mechanism (e.g., door lock, door opener, software control mechanism, turning off an alarm, etc.), or a PACS can include a host server to which readers and actuators are connected (e.g., via a controller) in a centrally managed configuration.
[0042] In centrally managed configurations, readers can obtain credentials from credential or key devices (e.g., from one or more client devices 120) and pass those credentials to the PACS host server or headend system. The readers can send the credentials over a wired or wireless link, such as network 130. The host server then determines whether the credentials authorize access to the secure area or secure asset (or resource) and commands the actuator or other control mechanism of the PAC devices 110 accordingly by sending an allow / deny message back to the reader over the wired or wireless link. While examples in physical access control are used herein, the disclosure applies similarly to logical access control system (LACS) use cases (e.g., logical access to personal electronic devices, logical access to personal online or electronic accounts or documents, etc.).
[0043] In general, the access control device can include one or more of a memory, a processor, one or more antennas, a communication module, a network interface device, a user interface, a display, and a power source or supply. The memory of the access control device can be used in connection with the execution of application programming or instructions by the processor of the access control device, and for the temporary or long-term storage of program instructions or instruction sets and / or credential or authorization data, such as credential data, credential authorization data, or access control data or instructions. For example, the memory can contain executable instructions that are used by the processor to run other components of access control device and / or to make access determinations based on credential or authorization data.
[0044] The memory of the access control device (e.g., PAC devices 110 and / or client device 120) can include a transitory or non-transitory computer-readable medium. The computer-readable medium can be, for example, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device. More specific examples of suitable computer-readable medium include, but are not limited to, an electrical connection having one or more wires or a tangible storage medium such as a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), Dynamic RAM (DRAM), any solid-state storage device in general, a compact disc read-only memory (CD-ROM), or other optical or magnetic storage device. Computer-readable media includes, but is not to be confused with, computer-readable storage medium, which is intended to cover all physical, non- transitory, or similar examples of computer-readable media.
[0045] The processor of the access control device can correspond to one or more computer processing devices or resources. For instance, the processor can be provided as silicon, as a Field Programmable Gate Array (FPGA), an Application-Specific Integrated Circuit (ASIC), any other type of Integrated Circuit (IC) chip, a collection of IC chips, or the like. As a more specific example, the processor can be provided as a microprocessor, Central Processing Unit (CPU), or plurality of microprocessors or CPUs that are configured to execute instructions sets stored in an internal memory and / or memory of the access control device.
[0046] The antenna of the access control device can correspond to one or multiple antennas and can be configured to provide for wireless communications between access control device and a credential or key device (e.g., client device 120). The antenna can be arranged to operate using one or more wireless communication protocols and operating frequencies including, but not limited to, the IEEE 602.15.1, Bluetooth, BLE, NFC, ZigBee, Global System for Mobile communications (GSM), Code Division Multiple Access (CDMA), Wi-Fi, RF, UWB, and the like. By way of example, the antenna(s) can be RF antenna(s), and as such, may transmit / receive RF signals through free-space to be received / transferred by a credential or key device having an RF transceiver.
[0047] A communication module or communication component of the access control device can be configured to communicate according to any suitable communicationsprotocol with one or more different systems or devices either remote or local to the access control device, such as one or more client devices 120 and / or servers / controllers. In some cases, the communication module of the access control device is configured to perform the disclosed authentication protocol securely.
[0048] In some cases, the communication module uses a same wired or wireless link between the access control device and the server / controller for all the communication modes. In some cases, the communication module uses one wired or wireless link between the access control device and the server / controller to communicate access control information and uses a different wired or wireless link to communicate or receive configuration information updates from the server / controller over the Internet Protocol (IP) communication mode.
[0049] The network interface device of the access control device includes hardware to facilitate communications with other devices, such as a one or more client devices 120 and / or server / controller (e.g., a PACS server), over a communication network, such as network 130, utilizing any one of a number of transfer protocols (e.g., frame relay, IP, transmission control protocol (TCP), user datagram protocol (UDP), hypertext transfer protocol (HTTP), etc.). Example communication networks can include a local area network (LAN), a wide area network (WAN), a packet data network (e.g., the Internet), mobile telephone networks (e.g., cellular networks), Plain Old Telephone (POTS) networks, wireless data networks (e.g., IEEE 602.11 family of standards known as WiFi, IEEE 602.16 family of standards known as WiMax), IEEE 602.15.4 family of standards, and peer-to-peer (P2P) networks, among others. In some examples, network interface device can include an Ethernet port or other physical jack, a Wi-Fi card, a Network Interface Card (NIC), a cellular interface (e.g., antenna, filters, and associated circuitry), or the like. In some examples, network interface device can include a plurality of antennas to wirelessly communicate using at least one of single-input multiple-output (SIMO), multiple-input multiple-output (MIMO), or multiple-input single-output (MISO) techniques.
[0050] A user interface of the access control device can include one or more input devices and / or display devices. Examples of suitable user input devices that can be included in the user interface include, without limitation, one or more buttons, a keyboard or keypad, a mouse, a touch-sensitive surface, a stylus, a camera, a microphone, etc. Examples of suitable user output devices that can be included in theuser interface include, without limitation, one or more LEDs, an LCD panel, a display screen, a touchscreen, one or more lights, a speaker, and so forth. It should be appreciated that the user interface can also include a combined user input and user output device, such as a touch-sensitive display or the like. Any reference to operations performed by the access control device apply to the PAC devices 110, shown in FIG. 1.
[0051] The network 130 may include, or operate in conjunction with, an ad hoc network, an intranet, an extranet, a virtual private network (VPN), a LAN, a wireless network, a wireless LAN (WLAN), a WAN, a wireless WAN (WWAN), a metropolitan area network (MAN), BLE, UWB, the Internet, a portion of the Internet, a portion of the Public Switched Telephone Network (PSTN), a POTS network, a cellular telephone network, a wireless network, a Wi-Fi® network, another type of network, or a combination of two or more such networks. For example, a network or a portion of a network may include a wireless or cellular network and the coupling may be a CDMA connection, a GSM connection, or other type of cellular or wireless coupling. In this example, the coupling may implement any of a variety of types of data transfer technology, such as Single Carrier Radio Transmission Technology (IxRTT), Evolution- Data Optimized (EVDO) technology, General Packet Radio Service (GPRS) technology, Enhanced Data rates for GSM Evolution (EDGE) technology, third Generation Partnership Project (3 GPP) including 3G, fourth generation wireless (4G) networks, fifth generation wireless (5G) networks, Universal Mobile Telecommunications System (UMTS), High Speed Packet Access (HSPA), Worldwide Interoperability for Microwave Access (WiMAX), Long Term Evolution (LTE) standard, others defined by various standard setting organizations, other short range or long range protocols, or other data transfer technology.
[0052] In an example, as the client device 120 approaches the PAC devices 110 (e.g., comes within range of a BLE communication protocol), the client device 120 transmits credentials of the client device 120 over the network 130. In one example, the client device 120 provides the credentials directly to the PAC devices 110. In such cases, the PAC devices 110 communicate the credentials with the server / controller. The server / controller (not shown) includes an authorization system (not shown). The server / controller, client device 120, and / or the PAC devices 110 can further include elements described with respect to FIG. 5 and FIG. 6, such as a processor and memory, having instructions stored thereon, that when executed by the processor, causes theprocessor to control the functions of the server / controller, client device 120, and / or the PAC devices 110.
[0053] The server / controller searches a list of credentials stored in the authorization system to determine whether the received credentials match credentials from the list of authorized credentials for accessing a secure asset or resource (e.g., door or secure area) protected by the PAC devices 110. In response to determining that the received credentials are authorized to access the PAC devices 110, the server / controller instructs the PAC devices 110 to perform an operation granting access for the client device 120 (e.g., instructing the PAC devices 110 to unlock a lock of a door).
[0054] In some examples, prior to granting access to the resource protected by the PAC devices 110, the PAC devices 110 and / or the server / controller, and / or the client device 120 can perform operations to verify that the client device 120 is within a specified distance of the client device 120. This can be performed before, substantially simultaneous with, and / or after verifying that the credentials received from the client device 120 are authorized to access the asset or resource.
[0055] Specifically, the client device 120 can scan BLE signals (or other suitable signals) transmitted by the PAC devices 110 over the network 130. The client device 120 can determine whether the BLE signals of a particular PAC device 110 satisfy a proximity threshold or criterion. In response, the client device 120 establishes a communication session (via BLE and / or WiFi) with the PAC device 110. The PAC devices 110 can, either before verifying proximity or after verifying proximity, request additional information from the client device 120. Specifically, the PAC device 110 can request a credential to be provided by the client device 120.
[0056] The client device 120 can provide a credential to the PAC devices 110 over the network 130. The PAC devices 110 verify whether the credential is authorized to access a resource protected by the PAC devices 110. In such cases, the PAC devices 110 grant access to the resource after confirming that the client device 120 is within a threshold proximity to the PAC devices 110. In some examples, the PAC devices 110 transmit a nonce, random value, or other transaction identifier to the client device 120 via the network 130. The client device 120 can then module light transmitted or emitted by one or more light emitting sources of the client device 120 (e.g., LiFi sources) using the nonce, random value, or other transaction identifier received from the PAC devices 110. The PAC devices 110 receive and decode the modulated light and determine whether thedecoded data matches or corresponds to the nonce, random value, or other transaction identifier. If so, the PAC devices 110 determine that the PAC devices 110 and the client device 120 are within a threshold proximity and satisfy a proximity criterion. In this case, the PAC devices 110 grant access to the resource protected by the PAC devices 110.
[0057] FIG. 2 illustrates a diagram 202 of an environment for accessing a secure resource, in accordance with some examples. For example, as shown in the diagram 202, a mobile device 208 (e.g., the client device 120) can scan for signals transmitted by an access control device 210 over BLE communication 212. In response to determining that the RSSI value of the signals received from the access control device 210 (e.g., the PAC device 110) satisfies a criterion (e.g., is above a threshold value), the mobile device 208 establishes a secure link or communication session with the access control device 210 over the BLE communication 212.
[0058] The access control device 210 transmits a transaction identifier to the mobile device 208 over the BLE communication 212. In some cases, the access control device 210 also requests a credential and / or other information from the mobile device 208 over the secure link. The mobile device 208 provides the requested information over the BLE communication 212 (e.g., provides the credential). The mobile device 208, simultaneously with providing the credential or after providing the credential to the access control device 210, encodes the transaction identifier and modulates light emitted by LiFi emitter 206 to represent the transaction identifier. The mobile device 208 can repeat the modulation of the light emitted by the LiFi emitter 206 a certain number of times, continuously for a period of time, and / or until a user input is received requesting termination of the modulation of the light emitted by the LiFi emitter 206. The user input can include a user interaction to initiate modulation of light using one or more gestures, such as twisting, tapping, and so forth.
[0059] The access control device 210 can receive the light emitted by the LiFi emitter 206 using a LiFi receiver 204 (e.g., one or more photodiodes). The access control device 210 can perform proximity verification 214 using the modulated light. For example, the LiFi receiver 204 can decode the data encoded by the pattern of light emitted by the LiFi emitter 206. The access control device 210 can determine whether the decoded data matches the transaction identifier. If so, the access control device 210 can then determine whether the credential and / or other information received from the mobile device 208 isauthorized to access the resource protected by the access control device 210. In such cases, the access control device 210 provides access to the protected resource, such as by unlocking a door lock. In some cases, the access control device 210 requests the credential from the mobile device 208 prior to performing the proximity verification 214 (e.g., prior to transmitting the transaction identifier and detecting the light modulated by the mobile device 208). In some cases, the access control device 210 requests the credential from the mobile device 208 after performing the proximity verification 214 (e.g., after transmitting the transaction identifier and detecting the light modulated by the mobile device 208).
[0060] FIG. 3 illustrates a diagram 302 of a sequence of operations for accessing a secure resource, in accordance with some examples. For example, a mobile device 306 can scan for BLE signals transmitted by access control device 304. In response to determining that an RSSI of the BLE signals transgresses a threshold value, the mobile device 306 performs a sequence of operations 308. Specifically, the mobile device 306 initiates a communication session with the access control device 304. After initiating and establishing the communication session with the access control device 304, the access control device 304 and the mobile device 306 perform proximity verification operations 310. These proximity verification operations 310 include the exchange of credentials (e.g., before or after verifying proximity using the LiFi device or protocol of the mobile device 306).
[0061] For example, the access control device 304 can transmit the transaction identifier to the mobile device 306. The access control device 304 can also request information (e.g., a credential) from the mobile device 306. The mobile device 306 provides the credential and after determining that the credential is authorized to access the resource protected by the access control device 304, the access control device 304 can capture or search for light emitted by the mobile device 306. If the credential is determined to not be authorized, the access control device 304 prevents performing operations for searching for and capturing the light emitted by the mobile device 306.
[0062] The mobile device 306 can receive an indication from the access control device 304 that the credential has been authorized and an instruction to begin modulating light according to the previously received transaction identifier. The mobile device 306 can activate a LiFi device of the mobile device 306 (e.g., a flashlight) and modulate light emitted by the LiFi device according to and representing the transaction identifierpreviously received from the access control device 304 over the BLE communication session. The access control device 304 captures the light emitted by the mobile device 306 and decodes the light into a set of data. The access control device 304 determines whether the set of data corresponds to the transaction identifier. In response to determining that the decoded data corresponds to the transaction identifier, the access control device 304 enables access to the protected resource and terminates the communication session. In response to determining that the decoded data fails to correspond to the transaction identifier, the access control device 304 prevents access to the protected resource and terminates the communication session.
[0063] The access control device 304 can continue capturing and verifying whether the light emitted by the mobile device 306 represents data corresponding to the transaction identifier for a threshold period of time (e.g., 30 seconds) after instructing the mobile device 306 to provide the transaction identifier using the LiFi device. If the access control device 304 fails to detect light matching the transaction identifier within the threshold period of time, the access control device 304 terminates the connection and the mobile device 306 may need to repeat the sequence of operations 308 to regain or retry gaining access to the protected resource.
[0064] In some examples, the determination of whether the access control device 304 and the mobile device 306 are within a threshold proximity of each other using the LiFi device can be performed by the mobile device 306 instead of, or in addition to, the access control device 304. In such cases, the mobile device 306 can receive the request for the credential from the access control device 304 after establishing the BLE communication session. Prior to sending the credential to the access control device 304, the mobile device 306 can transmit a transaction identifier to the access control device 304 via the BLE communication session. The access control device 304 can then modulate light using a LiFi device of the access control device 304 based on the transaction identifier received from the mobile device 306. The mobile device 306 can use a LiFi detector or receiver to decode the light modulated by the access control device 304. The mobile device 306 can determine whether the data encoded by the modulated light matches the transaction identifier sent by the mobile device 306. In response to determining that the data encoded by the modulated light of the access control device 304 matches the transaction identifier sent by the mobile device 306, the mobile device 306 then sends the credential to the access control device 304 over the BLEcommunication session. The access control device 304 can then verify whether the credential is authorized to access the resource protected by the access control device 304 and enables the mobile device 306 to access the protected resource (e.g., by unlocking a door) in response to determining that the credential is authorized to access the resource.
[0065] In some examples, the access control device 304 transmits a first transaction identifier to the mobile device 306. The mobile device 306 can then modulate light representing the first transaction identifier. The access control device 304 can detect the modulated light emitted by the LiFi device of the mobile device 306. The access control device 304 can determine whether the light modulated by the LiFi device of the mobile device 306 corresponds to the first transaction identifier. If so, the access control device 304 can instruct the mobile device 306 to transmit a second transaction identifier. The mobile device 306 can then send the second transaction identifier to the access control device 304. The access control device 304 can then modulate light representing the second transaction identifier. The mobile device 306 can detect the modulated light emitted by the LiFi device of the access control device 304. The mobile device 306 can determine whether the light modulated by the LiFi device of the access control device 304 corresponds to the second transaction identifier. If so, the mobile device 306 can exchange the credential with the access control device 304 to gain access to the resource protected by the access control device 304.
[0066] FIG. 4 illustrates a routine 400 (e.g., method or process) in accordance with some examples. The operations discussed in connection with FIG. 4 can be performed sequentially, in parallel, and in any suitable order. The operations discussed in FIG. 4 can be performed by the access control system 100.
[0067] In operation 402, the client device 120 detects an access control device that is within a threshold proximity to the client device 120, as discussed above.
[0068] In operation 404, the client device 120 establishes a communication session between the mobile device and the access control device, as discussed above.
[0069] In operation 406, the client device 120 receives, by the mobile device via the communication session, a transaction identifier from the access control device, as discussed above.
[0070] In operation 408, the client device 120 modulates light emitted by one or more light emitting sources of the mobile device based on the transaction identifier to obtain access to a resource protected by the access control device, as discussed above.
[0071] FIG. 5 is a block diagram illustrating an example of a software architecture 502 that may be installed on a machine, according to some examples. FIG. 5 is merely a nonlimiting example of a software architecture, and it will be appreciated that many other architectures may be implemented to facilitate the functionality described herein. The software architecture 502 may be executing on hardware such as a machine 600 of FIG. 6 that includes, among other things, processors 610, memory 604, and input / output (I / O) components 642. A representative hardware layer 544 is illustrated and can represent, for example, the machine 600 of FIG. 6. The representative hardware layer 544 comprises one or more processing units 546 having associated executable instructions 548. The executable instructions 548 represent the executable instructions of the software architecture 502. The hardware layer 544 also includes memory 604, which also have the executable instructions 548. The hardware layer 544 may also comprise other hardware 552, which represents any other hardware of the hardware layer 544, such as the other hardware illustrated as part of the machine 600.
[0072] The instructions 548 may be transmitted or received over the network using a transmission medium via a network interface device (e.g., a network interface component included in the communication components 640) and utilizing any one of a number of well-known transfer protocols (e.g., hypertext transfer protocol (HTTP)). Similarly, the instructions 548 may be transmitted or received using a transmission medium via the coupling (e.g., a peer-to-peer coupling) to the devices. The terms “transmission medium” and “signal medium” mean the same thing and may be used interchangeably in this disclosure. The terms “transmission medium” and “signal medium” shall be taken to include any intangible medium that is capable of storing, encoding, or carrying the instructions 548 for execution by the machine 600, and include digital or analog communications signals or other intangible media to facilitate communication of such software. Hence, the terms “transmission medium” and “signal medium” shall be taken to include any form of modulated data signal, carrier wave, and so forth. The term “modulated data signal” means a signal that has one or more of its characteristics set or changed in such a manner as to encode information in the signal.
[0073] The terms “machine-readable medium,” “computer-readable medium,” and “device-readable medium” mean the same thing and may be used interchangeably in this disclosure. The terms are defined to include both machine-storage media andtransmission media. Thus, the terms include both storage devices / media and carrier waves / modulated data signals.
[0074] As used herein, the terms “machine-storage medium,” “device-storage medium,” and “computer-storage medium” mean the same thing and may be used interchangeably in this disclosure. The terms refer to a single or multiple storage devices and / or media (e.g., a centralized or distributed database, and / or associated caches and servers) that store executable instructions and / or data. The terms shall accordingly be taken to include, but not be limited to, solid-state memories, and optical and magnetic media, including memory internal or external to processors. Specific examples of machinestorage media, computer-storage media, and / or device-storage media include nonvolatile memory, including by way of example semiconductor memory devices, e.g., erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), field-programmable gate arrays (FPGAs), and flash memory devices; magnetic disks such as internal hard disks and removable disks; magneto-optical disks; and CD-ROM and DVD-ROM disks. The terms “machinestorage medium,” “computer-storage medium,” and “device-storage medium” are non- transitory computer-readable media and specifically exclude carrier waves, modulated data signals, and other such media, at least some of which are covered under the term “signal medium.”
[0075] In the example architecture of FIG. 5, the software architecture 502 may be conceptualized as a stack of layers, where each layer provides particular functionality. For example, the software architecture 502 may include layers such as an operating system 536, libraries 528, framework / middleware 522, applications 516, and a presentation layer 514. Operationally, the applications 516 or other components within the layers may invoke API calls API calls 524 through the software stack and receive a response, returned values, and so forth (illustrated as messages 526) in response to the API calls 524. The layers illustrated are representative in nature, and not all software architectures have all layers. For example, some mobile or special-purpose operating systems may not provide a framework / middleware 522 layer, while others may provide such a layer. Other software architectures may include additional or different layers.
[0076] The operating system 536 may manage hardware resources and provide common services. The operating system 536 may include, for example, a kernel 538, services 540, and drivers 542. The kernel 538 may act as an abstraction layer between the hardware andthe other software layers. For example, the kernel 538 may be responsible for memory management, processor management (e.g., scheduling), component management, networking, security settings, and so on. The services 540 may provide other common services for the other software layers. The drivers 542 may be responsible for controlling or interfacing with the underlying hardware. For instance, the drivers 542 may include display drivers, camera drivers, Bluetooth® drivers, flash memory drivers, serial communication drivers (e.g., Universal Serial Bus (USB) drivers), Wi-Fi® drivers, audio drivers, power management drivers, and so forth depending on the hardware configuration.
[0077] The libraries 528 may provide a common infrastructure that may be utilized by the applications 516 and / or other components and / or layers. The libraries 528 typically provide functionality that allows other software modules to perform tasks in an easier fashion than by interfacing directly with the underlying operating system 536 functionality (e.g., kernel 538, services 540, or drivers 542). The libraries 528 may include system libraries 530 (e.g., C standard library) that may provide functions such as memory allocation functions, string manipulation functions, mathematic functions, and the like. In addition, the libraries 528 may include API libraries 532 such as media libraries (e.g., libraries to support presentation and manipulation of various media formats such as MPEG4, H.264, MP3, AAC, AMR, JPG, and PNG), graphics libraries (e.g., an OpenGL framework that may be used to render 2D and 3D graphic content on a display), database libraries (e.g., SQLite that may provide various relational database functions), web libraries (e.g., WebKit that may provide web browsing functionality), and the like. The libraries 528 may also include a wide variety of other libraries 534 to provide many other APIs to the applications 516 and other software components / modules.
[0078] The frameworks / middleware 522 (also sometimes referred to as middleware) may provide a higher-level common infrastructure that may be utilized by the applications 516 or other software components / modules. For example, the frameworks / middleware 522 may provide various graphical user interface functions, high-level resource management, high-level location services, and so forth. The frameworks / middleware 522 may provide a broad spectrum of other APIs that may be utilized by the applications 516 and / or other software components / modules, some of which may be specific to a particular operating system or platform.
[0079] The applications 516 include built-in applications 518 and / or third-party applications 520. Examples of representative built-in applications 518 may include, butare not limited to, a home application, a contacts application, a browser application, a book reader application, a location application, a media application, a messaging application, or a game application.
[0080] The third-party applications 520 may include any of the built-in applications 518, as well as a broad assortment of other applications. In a specific example, the third-party applications 520 (e.g., an application developed using the Android™ or iOS™ software development kit (SDK) by an entity other than the vendor of the particular platform) may be mobile software running on a mobile operating system such as iOS™, Android™, or other mobile operating systems. In this example, the third-party applications 520 may invoke the API calls 524 provided by the mobile operating system such as the operating system 536 to facilitate functionality described herein.
[0081] The applications 516 may utilize built-in operating system functions (e.g., kernel 538, services 540, or drivers 542), libraries (e.g., system libraries 530, API libraries 532, and other libraries 534), or framework / middleware 522 to create user interfaces to interact with users of the system. Alternatively, or additionally, in some systems, interactions with a user may occur through a presentation layer, such as the presentation layer 514. In these systems, the application / module “logic” can be separated from the aspects of the application / module that interact with the user.
[0082] Some software architectures utilize virtual machines. In the example of FIG. 5, this is illustrated by a virtual machine 504. The virtual machine 504 creates a software environment where applications / modules can execute as if they were executing on a hardware machine (e.g., the machine 600 of FIG. 6). The virtual machine 504 is hosted by a host operating system (e.g., the operating system 536) and typically, although not always, has a virtual machine monitor, which manages the operation of the virtual machine 504 as well as the interface with the host operating system (e.g., the operating system 536). A software architecture executes within the virtual machine 504, such as an operating system 512, libraries 510, frameworks 508, applications 516, or a presentation layer 506. These layers of software architecture executing within the virtual machine 504 can be the same as corresponding layers previously described or may be different.
[0083] FIG. 6 is a diagrammatic representation of the machine 600 within which instructions 608 (e.g., software, a program, an application, an applet, an app, or other executable code) for causing the machine 600 to perform any one or more of the methodologies discussed herein may be executed. For example, the instructions 608 maycause the machine 600 to execute any one or more of the methods described herein. The instructions 608 transform the general, non-programmed machine 600 into a particular machine 600 programmed to carry out the described and illustrated functions in the manner described. The machine 600 may operate as a standalone device or may be coupled (e.g., networked) to other machines. In a networked deployment, the machine 600 may operate in the capacity of a server machine or a client machine in a server-client network environment, or as a peer machine in a peer-to-peer (or distributed) network environment. The machine 600 may comprise, but not be limited to, a server computer, a client computer, a personal computer (PC), a tablet computer, a laptop computer, a netbook, a set-top box (STB), a PDA, an entertainment media system, a cellular telephone, a smart phone, a mobile device, a wearable device (e.g., a smart watch), a smart home device (e.g., a smart appliance), other smart devices, a web appliance, a network router, a network switch, a network bridge, or any machine capable of executing the instructions 608, sequentially or otherwise, that specify actions to be taken by the machine 600. Further, while only a single machine 600 is illustrated, the term “machine” shall also be taken to include a collection of machines that individually or jointly execute the instructions 608 to perform any one or more of the methodologies discussed herein.
[0084] The machine 600 may include processors 602, memory 604, and I / O components 642, which may be configured to communicate with each other via a bus 644. In an example, the processors 602 (e.g., a Central Processing Unit (CPU), a Reduced Instruction Set Computing (RISC) processor, a Complex Instruction Set Computing (CISC) processor, a Graphics Processing Unit (GPU), a Digital Signal Processor (DSP), an ASIC, a Radio-Frequency Integrated Circuit (RFIC), another processor, or any suitable combination thereof) may include, for example, a processor 606 and a processor 610 that execute the instructions 608. The term “processor” is intended to include multi-core processors that may comprise two or more independent processors (sometimes referred to as “cores”) that may execute instructions contemporaneously. Although FIG. 6 shows multiple processors 602, the machine 600 may include a single processor with a single core, a single processor with multiple cores (e.g., a multi-core processor), multiple processors with a single core, multiple processors with multiples cores, or any combination thereof.
[0085] The memory 604 includes a main memory 612, a static memory 614, and a storage unit 616, both accessible to the processors 602 via the bus 644. The mainmemory 604, the static memory 614, and storage unit 616 store the instructions 608 embodying any one or more of the methodologies or functions described herein. The instructions 608 may also reside, completely or partially, within the main memory 612, within the static memory 614, within machine-readable medium 618 within the storage unit 616, within at least one of the processors 602 (e.g., within the processor’s cache memory), or any suitable combination thereof, during execution thereof by the machine 600.
[0086] The I / O components 642 may include a wide variety of components to receive input, provide output, produce output, transmit information, exchange information, capture measurements, and so on. The specific I / O components 642 that are included in a particular machine will depend on the type of machine. For example, portable machines such as mobile phones may include a touch input device or other such input mechanisms, while a headless server machine will likely not include such a touch input device. It will be appreciated that the I / O components 642 may include many other components that are not shown in FIG. 6. In various examples, the I / O components 642 may include output components 628 and input components 630. The output components 628 may include visual components (e.g., a display such as a plasma display panel (PDP), a light emitting diode (LED) display, a liquid crystal display (LCD), a projector, or a cathode ray tube (CRT)), acoustic components (e.g., speakers), haptic components (e.g., a vibratory motor, resistance mechanisms), other signal generators, and so forth. The input components 630 may include alphanumeric input components (e.g., a keyboard, a touch screen configured to receive alphanumeric input, a photo-optical keyboard, or other alphanumeric input components), point-based input components (e.g., a mouse, a touchpad, a trackball, a joystick, a motion sensor, or another pointing instrument), tactile input components (e.g., a physical button, a touch screen that provides location and / or force of touches or touch gestures, or other tactile input components), audio input components (e.g., a microphone), and the like.
[0087] In further examples, the I / O components 642 may include biometric components 632, motion components 634, environmental components 636, or position components 638, among a wide array of other components. For example, the biometric components 632 include components to detect expressions (e.g., hand expressions, facial expressions, vocal expressions, body gestures, or eye tracking), measure biosignals (e.g., blood pressure, heart rate, body temperature, perspiration, or brain waves), identify a person(e.g., voice identification, retinal identification, facial identification, fingerprint identification, or electroencephalogram-based identification), and the like. The motion components 634 include acceleration sensor components (e.g., accelerometer), gravitation sensor components, rotation sensor components (e.g., gyroscope), and so forth. The environmental components 636 include, for example, illumination sensor components (e.g., photometer), temperature sensor components (e.g., one or more thermometers that detect ambient temperature), humidity sensor components, pressure sensor components (e.g., barometer), acoustic sensor components (e.g., one or more microphones that detect background noise), proximity sensor components (e.g., infrared sensors that detect nearby objects), gas sensors (e.g., gas detection sensors to detection concentrations of hazardous gases for safety or to measure pollutants in the atmosphere), or other components that may provide indications, measurements, or signals corresponding to a surrounding physical environment. The position components 638 include location sensor components (e.g., a GPS receiver component), altitude sensor components (e.g., altimeters or barometers that detect air pressure from which altitude may be derived), orientation sensor components (e.g., magnetometers), and the like.
[0088] Communication may be implemented using a wide variety of technologies. The I / O components 642 further include communication components 640 operable to couple the machine 600 to a network 620 or devices 622 via a coupling 624 and a coupling 626, respectively. For example, the communication components 640 may include a network interface component or another suitable device to interface with the network 620. In further examples, the communication components 640 may include wired communication components, wireless communication components, cellular communication components, Near Field Communication (NFC) components, Bluetooth® components (e.g., Bluetooth® Low Energy), Wi-Fi® components, and other communication components to provide communication via other modalities. The devices 622 may be another machine or any of a wide variety of peripheral devices (e.g., a peripheral device coupled via a USB).
[0089] Moreover, the communication components 640 may detect identifiers or include components operable to detect identifiers. For example, the communication components 640 may include Radio Frequency Identification (RFID) tag reader components, NFC smart tag detection components, optical reader components (e.g., an optical sensor todetect one-dimensional bar codes such as Universal Product Code (UPC) bar code, multi-dimensional bar codes such as Quick Response (QR) code, Aztec code, Data Matrix, Dataglyph, MaxiCode, PDF417, Ultra Code, UCC RSS-2D bar code, and other optical codes), or acoustic detection components (e.g., microphones to identify tagged audio signals). In addition, a variety of information may be derived via the communication components 640, such as location via Internet Protocol (IP) geolocation, location via Wi-Fi® signal triangulation, location via detecting an NFC beacon signal that may indicate a particular location, and so forth.
[0090] The various memories (e.g., memory 604, main memory 612, static memory 614, and / or memory of the processors 602) and / or storage unit 616 may store one or more sets of instructions and data structures (e.g., software) embodying or used by any one or more of the methodologies or functions described herein. These instructions (e.g., the instructions 608), when executed by processors 602, cause various operations to implement the disclosed examples.
[0091] The instructions 608 may be transmitted or received over the network 620, using a transmission medium, via a network interface device (e.g., a network interface component included in the communication components 640) and using any one of a number of well-known transfer protocols (e.g., hypertext transfer protocol (HTTP)). Similarly, the instructions 608 may be transmitted or received using a transmission medium via the coupling 626 (e.g., a peer-to-peer coupling) to the devices 622.
[0092] In some cases, the I / O components 642 of a particular device include both the LiFi receiver 204 and the LiFi emitter 206. In some cases, the I / O components 642 of a particular device includes only the LiFi receiver 204. In some cases, the I / O components 642 of a particular device includes on the LiFi emitter 206.
[0093] Although examples have been described, it will be evident that various modifications and changes may be made to these examples without departing from the broader scope of the present disclosure. Accordingly, the specification and drawings are to be regarded in an illustrative rather than a restrictive sense. The accompanying drawings that form a part hereof, show by way of illustration, and not of limitation, specific examples in which the subject matter may be practiced. The examples illustrated are described in sufficient detail to enable those skilled in the art to practice the teachings disclosed herein. Other examples may be utilized and derived therefrom, such that structural and logical substitutions and changes may be made without departing fromthe scope of this disclosure. This Detailed Description, therefore, is not to be taken in a limiting sense, and the scope of various examples is defined only by the appended claims, along with the full range of equivalents to which such claims are entitled.
[0094] Such examples of the inventive subject matter may be referred to herein, individually and / or collectively, by the term "invention" merely for convenience and without intending to voluntarily limit the scope of this application to any single invention or inventive concept if more than one is in fact disclosed. Thus, although specific examples have been illustrated and described herein, it should be appreciated that any arrangement calculated to achieve the same purpose may be substituted for the specific examples shown. This disclosure is intended to cover any and all adaptations or variations of various examples. Combinations of the above examples, and other examples not specifically described herein, will be apparent to those of skill in the art upon reviewing the above description.
[0095] The Abstract of the Disclosure is provided to allow the reader to quickly ascertain the nature of the technical disclosure. It is submitted with the understanding that it will not be used to interpret or limit the scope or meaning of the claims. In addition, in the foregoing Detailed Description, it can be seen that various features are grouped together in a single example for the purpose of streamlining the disclosure. This method of disclosure is not to be interpreted as reflecting an intention that the claimed examples require more features than are expressly recited in each claim. Rather, as the following claims reflect, inventive subject matter lies in less than all features of a single disclosed example. Thus the following claims are hereby incorporated into the Detailed Description, with each claim standing on its own as a separate example.
[0096] In view of the disclosure above, various examples are set forth below. It should be noted that one or more features of an example, taken in isolation or combination, should be considered within the disclosure of this application.
[0097] Example 1. A system comprising: one or more hardware processors; and at least one machine-storage medium for storing instructions that, when executed by the one or more hardware processors, cause the one or more hardware processors to perform operations comprising: detecting an access control device that is within a threshold proximity to a mobile device; establishing a communication session between the mobile device and the access control device; receiving, by the mobile device via the communication session, a transaction identifier from the access control device; andmodulating light emitted by one or more light emitting sources of the mobile device based on the transaction identifier to obtain access to a resource protected by the access control device.
[0098] Example 2. The system of any of Examples 1, wherein the one or more light emitting sources comprise a flashlight of the mobile device.
[0099] Example 3. The system of any of Examples 1-2, wherein the communication session comprises a Bluetooth Low Energy (BLE) communication session.
[0100] Example 4. The system of any of Examples 1-3, wherein the one or more light emitting sources comprise a light fidelity (LiFi) device of the mobile device.
[0101] Example 5. The system of any of Examples 1-4, wherein the operations comprise: scanning, by the mobile device, received signal strength indicator (RSSI) signals transmitted by one or more access control devices; and determining that an individual RSSI signal of the received RSSI signals corresponds to a specified threshold.
[0102] Example 6. The system of any of Examples 1-5, wherein the operations comprise: determining that the access control device is within the threshold proximity to the mobile device in response to determining that the individual RSSI signal transmitted by the access control device corresponds to the specified threshold.
[0103] Example 7. The system of any of Examples 1-6, wherein the operations comprise: establishing the communication session in response to determining that the access control device is within the threshold proximity to the mobile device.
[0104] Example 8. The system of any of Examples 1-7, wherein the operations comprise: receiving, from the access control device, a request for a credential; and transmitting, from the mobile device to the access control device, the credential to obtain access to the resource protected by the access control device.
[0105] Example 9. The system of any of Examples 1-8, wherein the operations comprise: authorizing the mobile device to access the resource based on the credential received from the mobile device; and enabling access to the resource protected by the access control device in response to determining that the mobile device satisfies a proximity criterion. In some cases, the access control device sends a nonce / transaction identifier to the mobile device which can be then used to modulate the light by the mobile device.
[0106] Example 10. The system of any of Examples 1-9, wherein the operations comprise: determining that the mobile device satisfies the proximity criterion based on processing the light emitted by one or more light emitting sources of the mobile device.
[0107] Example 11. The system of any of Examples 1-10, wherein the operations comprise: determining that a pattern of the light emitted by the mobile device corresponds to the transaction identifier; and in response to determining that the pattern of the light emitted by the mobile device corresponds to the transaction identifier, determining that the mobile device satisfies the proximity criterion.
[0108] Example 12. The system of any of Examples 1-11, wherein the access control device captures the pattern of the light using one or more photodiodes.
[0109] Example 13. The system of any of Examples 1-12, wherein the operations comprise: causing the access control device to provide access to the resource protected by the access control device in response to determining that the pattern of the light emitted by the mobile device corresponds to the transaction identifier.
[0110] Example 14. The system of any of Examples 1-13, wherein the operations comprise: determining that the mobile device satisfies a proximity criterion based on processing the light emitted by one or more light emitting sources of the mobile device. In some cases, the access control device sends a nonce / transaction identifier to the mobile device which can be then used to modulate the light by the mobile device.
[0111] Example 15. The system of any of Examples 1-14, wherein the operations comprise: in response to determining that the mobile device satisfies the proximity criterion based on processing the light emitted by one or more light emitting sources of the mobile device, transmitting, from the access control device, a request for a credential to the mobile device; and transmitting, from the mobile device to the access control device, the credential to obtain access to the resource protected by the access control device.
[0112] Example 16. The system of any of Examples 1-15, wherein the operations comprise: causing the access control device to provide access to the resource protected by the access control device in response to determining that the credential is authorized to access the resource.
[0113] Example 17. A method comprising: detecting an access control device that is within a threshold proximity to a mobile device; establishing a communication session between the mobile device and the access control device; receiving, by the mobile devicevia the communication session, a transaction identifier from the access control device; and modulating light emitted by one or more light emitting sources of the mobile device based on the transaction identifier to obtain access to a resource protected by the access control device.
[0114] Example 18. The method of any of Examples 17, wherein the one or more light emitting sources comprise a flashlight of the mobile device.
[0115] Example 19. The method of any of Examples 17-18, wherein the one or more light emitting sources comprise a light fidelity (LiFi) device of the mobile device.
[0116] Example 20. A machine-storage medium for storing instructions that, when executed by one or more hardware processors, cause the one or more hardware processors to perform operations comprising: detecting an access control device that is within a threshold proximity to a mobile device; establishing a communication session between the mobile device and the access control device; receiving, by the mobile device via the communication session, a transaction identifier from the access control device; and modulating light emitted by one or more light emitting sources of the mobile device based on the transaction identifier to obtain access to a resource protected by the access control device.
Claims
CLAIMSWhat is claimed is:
1. A system comprising: one or more hardware processors; and at least one machine-storage medium for storing instructions that, when executed by the one or more hardware processors, cause the one or more hardware processors to perform operations comprising: detecting an access control device that is within a threshold proximity to a mobile device; establishing a communication session between the mobile device and the access control device; receiving, by the mobile device via the communication session, a transaction identifier from the access control device; and modulating light emitted by one or more light emitting sources of the mobile device based on the transaction identifier to obtain access to a resource protected by the access control device.
2. The system of claim 1, wherein the one or more light emitting sources comprise a flashlight of the mobile device.
3. The system of claim 1, wherein the communication session comprises a Bluetooth Low Energy (BLE) communication session.
4. The system of claim 1, wherein the one or more light emitting sources comprise a light fidelity (LiFi) device of the mobile device.
5. The system of claim 1, wherein the operations comprise: scanning, by the mobile device, received signal strength indicator (RSSI) signals transmitted by one or more access control devices; and determining that an individual RSSI signal of the received RSSI signals corresponds to a specified threshold.
6. The system of claim 5, wherein the operations comprise:determining that the access control device is within the threshold proximity to the mobile device in response to determining that the individual RS SI signal transmitted by the access control device corresponds to the specified threshold.
7. The system of claim 6, wherein the operations comprise: establishing the communication session in response to determining that the access control device is within the threshold proximity to the mobile device.
8. The system of claim 7, wherein the operations comprise: receiving, from the access control device, a request for a credential; and transmitting, from the mobile device to the access control device, the credential to obtain access to the resource protected by the access control device, the access control device sending a nonce / transaction identifier to the mobile device.
9. The system of claim 8, wherein the operations comprise: authorizing the mobile device to access the resource based on the credential received from the mobile device; and enabling access to the resource protected by the access control device in response to determining that the mobile device satisfies a proximity criterion.
10. The system of claim 9, wherein the operations comprise: determining that the mobile device satisfies the proximity criterion based on processing the light emitted by one or more light emitting sources of the mobile device.
11. The system of claim 10, wherein the operations comprise: determining that a pattern of the light emitted by the mobile device corresponds to the transaction identifier; and in response to determining that the pattern of the light emitted by the mobile device corresponds to the transaction identifier, determining that the mobile device satisfies the proximity criterion.
12. The system of claim 11, wherein the access control device captures the pattern of the light using one or more photodiodes.
13. The system of claim 11, wherein the operations comprise:causing the access control device to provide access to the resource protected by the access control device in response to determining that the pattern of the light emitted by the mobile device corresponds to the transaction identifier.
14. The system of claim 7, wherein the operations comprise: determining that the mobile device satisfies a proximity criterion based on processing the light emitted by one or more light emitting sources of the mobile device, the access control device sending a nonce / transaction identifier to the mobile device.
15. The system of claim 14, wherein the operations comprise: in response to determining that the mobile device satisfies the proximity criterion based on processing the light emitted by one or more light emitting sources of the mobile device, transmitting, from the access control device, a request for a credential to the mobile device; and transmitting, from the mobile device to the access control device, the credential to obtain access to the resource protected by the access control device.
16. The system of claim 15, wherein the operations comprise: causing the access control device to provide access to the resource protected by the access control device in response to determining that the credential is authorized to access the resource.
17. A method comprising: detecting an access control device that is within a threshold proximity to a mobile device; establishing a communication session between the mobile device and the access control device; receiving, by the mobile device via the communication session, a transaction identifier from the access control device; and modulating light emitted by one or more light emitting sources of the mobile device based on the transaction identifier to obtain access to a resource protected by the access control device.
18. The method of claim 17, wherein the one or more light emitting sources comprise a flashlight of the mobile device.
19. The method of claim 17, wherein the one or more light emitting sources comprise a light fidelity (LiFi) device of the mobile device.
20. A machine-storage medium for storing instructions that, when executed by one or more hardware processors, cause the one or more hardware processors to perform operations comprising: detecting an access control device that is within a threshold proximity to a mobile device; establishing a communication session between the mobile device and the access control device; receiving, by the mobile device via the communication session, a transaction identifier from the access control device; and modulating light emitted by one or more light emitting sources of the mobile device based on the transaction identifier to obtain access to a resource protected by the access control device.
Citation Information
Patent Citations
Dynamic password closed circuit access control system based on visible light communication
CN108520574A
An electronic device, an access control device, and related methods
EP3882872A1
Access control management system and method of access controller use
EP4092637A1
Rolling Code Based Proximity Verification for Entry Access
US20190172287A1
IN202411077714A