Second factor triggering for use of access control credentials

By combining wireless communication measurements with proximity detection techniques like optical sensors and RF field interference, the patent addresses inconsistent Bluetooth-based access control, ensuring reliable and efficient credential authentication.

WO2026087039A1PCT designated stage Publication Date: 2026-04-30ASSA ABLOY AB
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
ASSA ABLOY AB
Filing Date
2024-10-23
Publication Date
2026-04-30

Smart Images

  • Figure EP2024079912_30042026_PF_FP_ABST
    Figure EP2024079912_30042026_PF_FP_ABST
Patent Text Reader

Abstract

Various methods and implementations of a proximity-based credential authentication process, including a second factor to require a credential-presenting device within a defined distance of a credential reader, are described. An example method performed by an access control reader comprises: detecting a mobile computing device as located in wireless communication range of the access control reader, based on a characteristic of a wireless communication signal received from the mobile computing device; detecting the mobile computing device as located within the defined distance of the access control reader based on a proximity detection performed by the access control reader; and activating a physical access control system, in response to concurrently (i) detecting the mobile computing device as located within the defined distance of the access control reader and (ii) detecting the mobile computing device as located in the wireless communication range of the access control reader.
Need to check novelty before this filing date? Find Prior Art

Description

SECOND FACTOR TRIGGERING FORUSE OF ACCESS CONTROL CREDENTIALSTECHNICAL FIELD

[0001] Embodiments described herein generally relate to the use of network communications and access control systems, such as in connection with identifying and communicating credentials and other data such as for the physical access control of doors, door locks, or secure areas.BACKGROUND

[0002] A variety of technologies are used to present credentials for physical access control systems. Physical credential readers may be adapted to read credentials provided via a magnetic stripe, RFID circuitry (e.g., low-frequency RFID systems operating at approximately 125kHz, and high-frequency RFID systems operating at approximately 13.56MHz), or a wireless data transmission (e.g., via Bluetooth or Bluetooth Low Energy (BLE) wireless communications), to obtain credentials for an access control system. For example, a physical credential reader may be located on a wall next to a locked door, which only unlocks the door when a particular credential is presented by a card, a fob, a smartphone, etc.

[0003] The use of a smartphone to present credentials has become an increasingly popular way to interface with access control systems, especially via the use of Bluetooth and BLE credential technologies that wirelessly communicate a credential from the smartphone to a credential reader. However, the use of physical credential readers may encounter a variety of challenges with wireless communications, especially when multiple readers and access control devices are co-located in a small, confined area such as an office.BRIEF SUMMARY

[0004] The following presents a simplified summary of one or more embodiments of the present disclosure in order to provide a basic understanding of such embodiments. This summary is not an extensive overview of all contemplated embodiments, and is intended to neither identify key or critical elements of all embodiments, nor delineate the scope of any or all embodiments.

[0005] The present disclosure, in one or more embodiments, relates to a method for proximity -based credential authentication and access control performed by or at an access control reader (e.g. a credential reader of an access control system). This method includes: detecting a mobile computing device (e.g., smartphone) as located in wireless communication range of the access control reader, based on a characteristic of a wireless communication signal received from or exchanged with the mobile computing device; detecting the mobile computing device as located within a defined distance of the access control reader, based on a proximity detection technique performed by the access control reader; and using physical access control system data to activate a physical access control system, in response to concurrently (i) detecting the mobile computing device as located within the defined distance of the access control reader, and (ii) detecting the mobile computing device as located in the wireless communication range of the access control reader.

[0006] Various techniques can be used at an access control reader for proximity detection of a mobile computing device. This may include: determining that the mobile computing device is within the defined distance of the access control reader, based on the detection of an object with an optical sensor; determining that the mobile computing device is within the defined distance of the access control reader, based on an interruption in a radio frequency field of RFID data communications when polling for credentials; or performing a near-field communication (NFC) data communication between the access control reader and the mobile computing device, to identify that the mobile computing device is located within an NFC communication range and is within the defined distance of the access control reader.

[0007] The present disclosure, in one or more embodiments, additionally relates to a method for proximity -based access control performed by or at a mobile computing device (e.g. a smartphone). This method includes: transmitting at least one wireless communication signal to an access control reader, wherein in response to transmitting the at least one wireless communication signal, the access control reader detects the mobile computing device as located in wireless communication range of the access control reader, based on a characteristic of the at least one wireless communication signal; interacting with the access control reader, when located within a defined distance of the access control reader, wherein in response to interacting with the access control reader, the access control reader detects the mobile computing device as located within the defined distance of the access control reader based on a proximity detection technique performed by the access control reader; receiving a request from the access control reader for an access credential; and transmitting the access credential to the access control reader to authenticate the mobile computing device, with theaccess control reader being configured to activate a physical access control system after mutual authentication of the mobile computing device when the mobile computing device is concurrently (i) located in the wireless communication range of the access control reader and (ii) located within the defined distance of the access control reader.

[0008] The present disclosure, in one or more embodiments, additionally relates to a non-transitory computer readable medium comprising executable program code, that when executed by one or more processors of a computing device, causes the one or more processors to perform the methods for proximity-based access control, as performed by or at an access control device or a mobile computing device, based on the methods described herein.

[0009] The present disclosure, in one or more embodiments, additionally relates to an apparatus (e.g., a computing device, an embedded device, controller, electronic component or subsystem, etc.) comprising memory configured or adapted to store an access credential (such as one or more secure keys), wireless communication circuitry, and processing circuitry or logic and circuitry configured to or adapted to perform proximity -based access control, based on the methods described herein.

[0010] While multiple embodiments are disclosed, still other embodiments of the present disclosure will become apparent to those skilled in the art from the following detailed description, which shows and describes illustrative embodiments of the invention. As will be realized, the various embodiments of the present disclosure are capable of modifications in various obvious aspects, all without departing from the scope of the present disclosure.Accordingly, the drawings and detailed description are to be regarded as illustrative in nature and not restrictive.BRIEF DESCRIPTION OF THE DRAWINGS

[0011] In the drawings, which are not necessarily drawn to scale, like numerals may describe similar components in different views. Like numerals having different letter suffixes may represent different instances of similar components. Some embodiments are illustrated by way of example, and not limitation, in the figures of the accompanying drawings in which:

[0012] FIG. 1 illustrates a scenario of proximity detection of a mobile computing device to a credential reader, according to an example;

[0013] FIG. 2 illustrates components and communications used for proximity -based credential presentation and verification between a mobile computing device and a credential reader, according to an example;

[0014] FIG. 3 A illustrates a sequence of operations and communications performed for authenticating a credential provided by a Bluetooth / Bluetooth Low Energy wireless communication, based on user proximity detection, according to an example;

[0015] FIG. 3B illustrates a sequence of operations and communications performed for authenticating a credential provided by a Bluetooth / Bluetooth Low Energy wireless communication, based on buffered access control data and user proximity detection, according to an example;

[0016] FIG. 3C illustrates a sequence of operations and communications performed for authenticating a credential provided by a Bluetooth / Bluetooth Low Energy wireless communication, based on buffered access control data and user proximity detection triggered from NFC communications, according to an example;

[0017] FIG. 4 illustrates a flowchart of a method performed by an access control reader for location-based credential authentication and access control, according to an example;

[0018] FIG. 5 illustrates a flowchart of a method performed by a mobile computing device for location-based credential authentication and access control, according to an example;

[0019] FIG. 6 illustrates a block diagram schematic of various components of an example electronic device configured to perform authentication operations, according to an example; and

[0020] FIG. 7 illustrates a block diagram schematic of various components of an example computing machine configured to perform authentication or related computing operations, according to an example.DETAILED DESCRIPTION

[0021] The present disclosure generally relates to the use of second-factor triggering and proximity detection, in connection with wirelessly communicating access control credentials from a mobile computing device. Among other examples, the process described herein may be used for establishing a consistent experience for the presentation of a credential via a wireless transmission from the mobile computing device, including at a fixed distance (e.g. at 10cm) from the reader. This can be used to establish a reliable “tap” experience with the credential reader, which enables the presentation of a mobile computing device to operate similar to the presentation of a physical RFID credential card.

[0022] Some approaches are currently used by access control readers to detect the proximity of a nearby credential device and prevent an access control system from opening the wrong door or reading the incorrect credential. For example, some credential readers usevery low power to wirelessly communicate with only closely located devices, or use radio signal measurements (e.g., RSSI) to try to verify that a device is very closely located.However, measurements using RSSI of Bluetooth and BLE communications to estimate distance may result in large variations due to environmental surroundings that interfere with RSSI. For example, the existence of metallic objects in the proximity of the credential reader may induce signal irregularities and reflections, yielding unreliable RSSI (Received Signal Strength Indication) measurements. This causes significant variation in the credential presentation and authentication experience. Additionally, the intrinsic variability in Bluetooth antenna characteristics among mobile devices can lead to instances where credential authentication is triggered either significantly farther or closer than the intended range from the reader. Thus, reliance on RSSI techniques alone may introduce other problems such as inconsistency in transmissions or delays in operation.

[0023] The presently described operations include the use of one or more additional proximity detection and verification techniques to confirm the presentation of the user’s device. These operations can be tuned to a consistent, defined distance to provide a uniform and repeatable tap experience to present credentials from a mobile computing device. In one example, an optical sensor provided on a reader can be used to detect a variation change in light level, e.g., when the user presents their phone in front of the reader. In another example, a reader includes the capability to adjust its HF tuning based on the mounting surface material (metallic or non-metallic), and such readers can use the ability to measure the current through the high frequency (HF) RFID antenna system during an HF credential transaction while polling RF energy. This mechanism can be used to detect an RF field disturbance and the presence of a user’s device when the user’s device is presented in front of the credential reader. These or similar proximity detection and verification techniques can be used as a second factor to trigger a wireless credential exchange (e.g., via Bluetooth / BLE communications), in conjunction with other measurements related to the wireless credential exchanges such as characteristics of the wireless transmission (e.g., BLE RSSI measurements).

[0024] FIG. 1 illustrates an example system 100, depicting a scenario of proximity detection of a mobile computing device to a credential reader. System 100 can include additional computing devices or electronic devices operated by users, but for simplicity depicts a single mobile computing device 160 operated by a user 150.

[0025] The mobile computing device 160 is depicted as a smartphone but may be provided by any suitable computing machine, such as but not limited to a personal computer (PC), atablet, a personal digital assistant (PDA), or an Internet of Things (loT) device. Additional features of such computing machines are discussed with reference to an example machine 700 in FIG. 7. The mobile computing device 160 includes circuitry to provide wireless credential presentation via one or more types of radio frequency communications (e.g., via near-field communication (NFC), Bluetooth, BLE communications, etc.). Additional details of wireless communications are discussed with reference to FIG. 2, below.

[0026] The credential reader devices 141 and 142 are depicted as a keypad, with each including radio frequency (RF) technology to emitRF transmissions to communicate with nearby credential presentation devices including the mobile computing device 160. Other examples of credential reader devices may not include a keypad or user interaction feature. The credential reader devices 141 and 141 may be wired or wirelessly connected to a controller 110 and one or more locks, such as a first lock 131 corresponding to a first door, and a second lock 132 corresponding to a second door. For example, in response to the presentation of a credential from a credential presentation device (e.g., a card, a mobile computing device, etc.), received via one of the credential reader devices 141 and 142, the controller 110 may determine whether the provided credential is valid. If the credential is valid, the controller 110 sends a communication signal to the respective lock (lock 131 for credential reader device 141, lock 132 for credential reader device 142) to actuate an electromechanical control (e.g., to disengage a lock, to mechanically open a door, etc.).Additional features of a credential device or hardware are discussed with reference to an example machine 700 in FIG. 7.

[0027] The mobile computing device 160 may include at least one software application, library, service, or component that enables use as a credential device. A credential device may generally include any device that carries (and provides or obtains) evidence of authority, status, rights, and / or entitlement to privileges for a holder of the credential device, including based on the authentication and proximity detection procedures discussed herein. A credential device may be provided in any suitable form factor. Other types of credential devices (usable with the credential reader devices 141 and 142) include but are not limited to RFID smartcards or other proximity-based cards, access control cards, electronic keys, key fobs, suitable near field communications (NFC)-enabled devices, tags, personal electronic devices, such as mobile phones, tablet PCs, wearable electronic devices, or PDAs, or any device configurable to emulate a credential.

[0028] A connection 161 to a public network 120 such as the Internet may be provided to the mobile computing device 160. This connection 161 may be provided via wireless networkcommunications, such as but not limited to a local area network (LAN), a wide area network (WAN), a packet data network (e.g., the Internet), a mobile telephone or data networks (e.g., 3GPP 4G / 5G cellular networks), a wireless data network (e.g., the IEEE 802.11 family of standards known as Wi-Fi, the LoRaWAN® family of standards defined by the LoRa Alliance®), any network based on the IEEE 802.15.4 family of standards, and a peer-to-peer (P2P) network, or any suitable combination of wired and / or wireless networks.

[0029] A credential device may generally include memory, storing, for example, one or more user credentials or credential data and any program instructions, and a reader interface (e.g., an antenna and Integrated Circuit (IC) chip), which permits the credential device to process instructions and / or exchange data with another device. Similarly, the reader devices, such as the credential reader devices 141 and 142, can communicate with credential or key devices via wireless technologies, such as RFID or PAN technologies, such as the IEEE 802.15.1, Bluetooth, Bluetooth Low Energy (BLE), near field communications (NFC), ZigBee, GSM, CDMA, Wi-Fi (IEEE 802.11), UWB, etc. The credential reader devices 141 and 142 may be adapted or tuned to evaluate multiple factors for proximity -based access control based on proximity detection. This may include a first factor indicating a characteristic of a wireless communication signal received from or exchanged with the mobile computing device (e.g. RSSI), in addition to a second factor requiring indicating a proximity of the mobile computing device (e.g., determined by a proximity detection technique such as sensor detection, RFID field interference, NFC communications, etc.).

[0030] Each credential reader device, such as the credential reader devices 141 and 142, may include a PIN pad, touch screen, fingerprint reader, magnetic stripe reader, chip reader, or other non-wireless input means for receiving additional credentials or other information, such as a PIN or other secret code, biometric information such as a fingerprint, or information from a magnetic stripe card or chip card, for example. Thus, additional factors for authentication, in addition to a communicated credential wirelessly received from the mobile computing device, may be requested and received at the credential reader devices 141 and 142. Additional features of the electronic device (e.g., incorporated into the credential reader devices 141 and 142) are discussed with reference to an example machine 700 in FIG. 7.

[0031] Other access control or credential services are not depicted for simplicity in FIG. 1 but are depicted in FIG. 2 as access control service 205, and referenced elsewhere below. An access control service (or a similar credential service) may be operated as a cloud service on remote processing hardware. In some examples, the controller 110 may operate on a privatenetwork (e.g., private access control network 115 depicted in FIG. 2), and be kept separate from public network access or publicly accessible services.

[0032] FIG. 2 illustrates a variety of components 200 used for proximity -based credential presentation and verification between a mobile computing device and a credential reader. Here, the components include the mobile computing device 160 and a credential reader 140 (a reader similar to credential reader devices 141 and 142).

[0033] In this example, the mobile computing device 160 obtains a reader-specific unique access credential from an access control service 205 and then wirelessly communicates this unique access credential to the credential reader 140 when in wireless communications range. The mobile computing device 160 uses a local-area network or a wide-area network connection (e.g., via a Wi-Fi or 4G / 5G mobile data network) to access the access control service 205 via a public network 120 such as the Internet and provide a request for a credential. The access control service 205 may generate a credential (directly or indirectly based on access information), and return a reader-specific credential relevant to a reader located at or near the device’s position.

[0034] After receiving the unique access credential from the access control service 205, the mobile computing device 160 communicates the unique access credential to the credential reader 140 via a short-range network (e.g., Bluetooth, Bluetooth Low Energy, NFC, etc.). In some examples, the credential reader 140 may perform mutual authentication to verify this credential and derive a set of physical access control system (PACS) data. The PACS data is then communicated to a controller (e.g., controller 110, not shown in FIG. 2), accessible by private access control network 115. The controller or other components then may physically activate and operate some access control mechanism in response to verification of the PACS data, such as to actuate a lock (e.g., open a lock 131, not shown in FIG. 2).

[0035] The mobile computing device 160 may include various software and hardware functionality 210 to support these communications, and to enable multi -factor proximity detection with the credential reader 140. The various software and hardware functionality 210, in an example, includes access control software 220, secure credential management 230, and communication systems 240. The access control software 220 is used for selecting, obtaining, and controlling communication of an access credential. The secure credential management 230 is used for storing and maintaining the access credential at the mobile computing device 160. The communication systems 240 can include communication circuitry and related software / logic / hardware including: 4G / 5G mobile data communication subsystem 242; Wi-Fi communication subsystem 244; Bluetooth and / or Bluetooth Low Energy (BLE)communication subsystem 246; RFID communication subsystem 248. The RFID communication subsystem 248 in some examples may include separate NFC hardware or components (not shown).

[0036] The credential reader 140 may include hardware or programmable logic to receive and verify the access credential via wireless communications. This may be provided by communication circuitry 145 including BLE communication circuitry 146 to perform BLE communications with the mobile computing device 160, and RFID communication circuitry 148 to communicate with physical credential devices (e.g., fobs, cards, etc.), including with NFC communication protocols. The credential reader 140 may also include hardware or programmable logic to also determine whether the mobile computing device 160 is in physical proximity, such as within some defined distance or range (e.g., approximately within 10 cm) of the credential reader 140. The hardware or programmable logic to determine proximity may include some combination of: a proximity sensor 143 used to optically detect the presence of an object such as the mobile computing device 160 or the user of the mobile computing device 160; and RF field detection logic 144 to determine whether disturbance or interference of an RF field (e.g., a RFID communication field) is being caused by the presence of an object such as the mobile computing device 160 or the user of the mobile computing device 160. Some of the logic and scenarios for using a credential and PACS data, based on whether a user is detected at a reader, is discussed with reference to FIGS. 3 A to 3C.

[0037] In an example, these communication systems 240 are used at different times throughout the process to obtain and provide the access credential (based on information and conditions related to proximity of the mobile computing device 160). For example, the BLE communication subsystem 246 may be used during a device discovery and at a medium range to discover the credential reader 140 and communicate the credentials to the credential reader 140 under the control of the access control software 220. The mobile computing device 160 receives the credential from the access control service 205 (via the mobile data communication subsystem 242 or the Wi-Fi communication subsystem 244), manages the credential via the secure credential management 230, and then communicates this credential to the credential reader 140 based on a credential exchange protocol with the access control software 220. The RFID communication subsystem 248 may be used to determine a short-range communication proximity, e.g., within NFC communication range (as discussed with reference to FIG. 3C, below).

[0038] As will be understood, the use of BLE communications may result in unintended behaviors when wirelessly communicating credentials from mobile devices to a fixed credential reader. One significant problem is that the relative distance at which the mobile device communicates with the reader is heavily dependent on the BLE settings in the reader and the BLE hardware configuration in the mobile device. As a result, there may be a large variation in the distance at which the mobile device starts wireless communication with the reader. This distance can, in some cases, be so long that BLE communications will trigger unwanted door openings just because someone is walking near a door reader. To address this issue, the following approaches can require a detection of a user’s proximity to an access control reader, as a second factor, before using the credential at the reader for some credential action (e.g., to open or unlock a door, etc.).

[0039] FIG. 3A illustrates a sequence 300A of operations and communications performed for authenticating a credential provided by a Bluetooth / BLE wireless communication, based on detection of a user’s proximity to an access control reader. Here, this sequence 300A demonstrates a proximity detection of the user (e.g., the user’s hand) or the mobile device (e.g., the user’s smartphone), in conjunction with wireless communication measurements (e.g., BLE RSSI measurements) that trigger a credential exchange with the mobile device and an access control operation.

[0040] At operation 302, the access control reader performs polling for RFID low-frequency credentials, and at operation 304, the access control reader performs polling for RFID high-frequency credentials. Concurrently or adjacently (e.g., immediately before, or immediately after in time) the access control reader discovers the Bluetooth / BLE access devices at operation 306, such as to discover a smartphone that communicates with Bluetooth / BLE and is capable of presenting an access credential.

[0041] Determination 310 is performed to detect the Bluetooth / BLE access device. If a Bluetooth / BLE device is not detected, then a polling delay (e.g., a configurable delay) is used, and operations 302-306 are repeated. If a Bluetooth / BLE device is detected, then determination 312 is performed to evaluate whether the mobile device provides wireless communications in close communication range of the access control reader, providing a first factor of determining proximity of the mobile device. This may include the evaluation of the wireless communications based on a Bluetooth / BLE RSSI threshold. Other characteristics of the wireless communication signal(s) received from (or exchanged with) the mobile device may be evaluated.

[0042] Determination 314 is performed to identify whether a user (or a device associated with the user) is detected at the reader, as a second factor of determining proximity of the mobile device. In a first example, this determination 314 may include use of an optical sensor to detect a variation change in light level, e.g., when the user presents their phone at a defined distance (e.g., 10cm or less) in front of the credential reader. Other types of motion or light sensors may be used. In a second example, this determination may include the detection of the presence of some object based on RF field disturbance when the user’s phone is presented in front of the credential reader. An access control reader can adjust its HF tuning based on the mounting surface material (metallic or non-metallic), and the access control reader can measure the current through the HF RFID antenna system during an HF credential transaction and while polling RF energy. The access control reader, when polling, can then determine if object(s) such as a user or the user’s mobile device are interrupting or interfering with the RF field. In a third example, user detection may be based on NFC communications. An example of the use of NFC communications for user proximity detection is discussed in more detail in FIG. 3C.

[0043] If the first factor and the second factor are both satisfied (e.g., based on determination 312, determination 314), then the access control reader and the mobile device can authenticate with a credential (operation 316), and PACS data can be provided to activate a physical access control system. In the example of FIG. 3A, only after the RSSI and user proximity conditions are met, will the credential be processed and PACS data sent to a control panel (e.g., controller 110). If either of the first factor or the second factor are not satisfied (e.g., based on failure of determination 312, determination 314), then the Bluetooth detection can be repeated with determination 310.

[0044] FIG. 3B illustrates a sequence 300B of operations and communications performed for authenticating a credential provided by a Bluetooth / Bluetooth Low Energy wireless communication, based on buffered access control data and user proximity detection. This sequence 300B includes use of some of the same operations referenced in FIG. 3A above (operations 302, 306, 308, and determinations 310, 312). However, the sequence 300B depicts how an access control reader could transact at further desired distances away from the reader based on a weaker RSSI measurement, and then securely store (buffer) the PACS data until a user proximity event is detected. This is shown with operation 318 (to authenticate the credential and securely buffer the PACS data) which precedes determination 314 (to detect that the user is within a defined range of the reader). The PACS data is released (at operation 320) to the control panel or controller only after verifying the second factor of detecting theuser’s proximity, within a defined range of the reader (e.g., based on optical sensor detection, interference with the RFID credential polling, etc.).

[0045] In addition to enforcing close physical proximity as a second authentication, the sequence of FIG. 3B can be used to improve speed of the overall process by securely precaching the credentials, PACS data, or other information used for access control operations. The credentials or PACS data can be discarded from memory if, for example, a timer expires and no user proximity event is detected.

[0046] FIG. 3C illustrates a sequence 300C of operations and communications performed for authenticating a credential provided by a Bluetooth / Bluetooth Low Energy wireless communication, based on buffered access control data and user proximity detection identified from NFC communications. This sequence 300C also includes use of some of the same operations referenced in FIGS. 3A and 3B above (operations 306, 308, 318, 320, and determinations 310, 312), but omits the use of RFID polling and RFID communications.

[0047] Specifically, sequence 300C introduces the ability to use NFC read and distance, which is very consistent and achieves the same results whether reading the presentation of physical credentials or mobile device credentials. Although some types of mobile computing devices do not enable the exchange of credentials via NFC, the use of NFC communications can be used as a trigger to verify a close proximity of the device, and then verify that BLE communications should occur with the reader (or, that credentials or PACS data buffered at the reader can be released for use).

[0048] In sequence 300C, after buffering the PACS data at operation 318, an NFC user detection 322 is based on attempting an NFC data communication at operation 324. If the device is in NFC communication range, based on determination 326, then the PACS data is released to the control panel at operation 320. If the device is not yet in NFC communication range, then NFC data communications are re-attempted at operation 324 (e.g., until successful or until a time-out, not shown).

[0049] In still other variations, a mobile computing device can perform pre-authenti cation and communication handshakes (e.g., with BLE communications) long before the user presents the device to the reader. Then, when a user comes within close NFC range (e.g., between 5-10 cm), the device will verify that the NFC field is detectable before instructing the reader to release the PACS data. This can also enable a reader to increase the power level (e.g., dbM value) at which the phone / reader can communicate — omitting the dependency of the BLE hardware — and only triggering the release and use of the PACS data after the NFC device is detected.

[0050] FIG. 4 illustrates a flowchart 400 of an example method for proximity -based credential authentication, performed by an access control reader (e.g., credential reader 140), which utilizes proximity as a second factor for triggering the use of access control system data. This method may be performed by many types of the devices or systems discussed herein, in connection with a credential-receiving device or system as discussed herein.

[0051] Operation 410 includes performing a discovery of at least one mobile device (e.g., smartphone such as mobile computing device 160), via a wireless communication protocol (e.g., via Bluetooth communications that perform a Bluetooth device discovery). For instance, when a Bluetooth device discovery is performed, the following operations for detecting the mobile device may occur in response to the discovery of at least one Bluetooth device including the mobile device.

[0052] Operation 420 includes detecting a mobile device, based on at least one characteristic of at least one wireless communication signal received from (or exchanged with) the mobile device. In an example, this at least one characteristic includes a received signal strength indicator (RSSI) of a Bluetooth wireless communication, which is used as a first factor to estimate that the mobile device is in communication range of the access control reader and is roughly in proximity of the access control reader.

[0053] Operation 430 includes performing a credential exchange, via wireless communication protocol, and deriving (or determining) physical access control system (PACS) data. This operation for performing the credential exchange (and respective transmission / reception operations) may occur in response to detecting the mobile device in the wireless communication range of the access control reader.

[0054] Operation 440 optionally includes buffering the PACS data at the access control reader, until the mobile device is detected as located within a defined distance of the access control reader. The buffering of the PACS data occurs before detecting that the mobile device has entered / is located within the defined distance of the access control reader. Thus, the buffered PACS data will be used to subsequently authenticate the mobile device once the device is detected as entering / being located within a defined distance (e.g., close proximity) of the access control reader.

[0055] Operation 450 includes detecting the mobile device as being located within a defined distance (e.g., close proximity) of the access control reader, using some type of a proximity detection second factor for verifying the close proximity of the mobile device. Various techniques may be used to detect this condition, and / or estimate the distance between the access control reader and the mobile device. The detection of the mobile device as beingwithin the defined distance may be required to occur within a predefined time period after detecting the mobile device as within the wireless communication range of the access control reader.

[0056] Operation 460 includes using PACS data (e.g., the buffered PACS data from operation 440) to activate a physical access control system, in response to concurrently detecting two conditions: (i) detecting that the mobile device is located within the defined distance and (ii) detecting the mobile computing device as located in the wireless communication range of the access control reader. In some examples, the defined distance may correspond to an area (zone, sphere, etc.) located within approximately 10 centimeters of the access control reader. The access control device may be tuned or adjusted for other distances. Additional operations that use the PACS data at a controller (e.g., to grant access, actuate some physical component, etc.) are not depicted for simplicity.

[0057] In an example, object detection is used to detect the proximity of the mobile device. An optical sensor (at or integrated with the access control device) can be used to track an area within the defined distance of the access control reader. Then, the mobile device can be determined to be located within the defined distance of the access control reader, based on detection of an object (e.g., the mobile device, the user of the mobile device, some object associated with the mobile device or the user).

[0058] In another example, an RFID RF field is monitored to detect the proximity of the mobile device. This can include polling for credentials with radio frequency identification (RFID) data communications (e.g., polling with a low-frequency RFID data communication operating between 125kHz and 134 kHz; or polling with a high-frequency RFID data communication operating at 13.56MHz; etc.). Then, the mobile device can be determined to be located within the defined distance of the access control reader, based on an interruption in a radio frequency field of the RFID data communications when polling for the credentials. The access control reader can be calibrated to identify the interruption in the radio frequency field that generally corresponds to an area within the defined distance of the access control reader. For example, the detection of the interruption in the radio frequency field may be based on interruption in the radio frequency field is detected based on an observed difference in a resonant frequency voltage peak, or based on an observed difference in power consumption.

[0059] In another example, a near-field communication (NFC) data exchange is used to detect the proximity of the mobile device. An NFC data communication is performed between the access control reader and the mobile device, to identify that the mobile device islocated within an NFC communication range. Then, the buffered access credential can be released for use to subsequently authenticate the mobile device, in response to identifying that the mobile device is located within the NFC communication range.

[0060] FIG. 5 illustrates a flowchart 500 of an example method, performed by a mobile device (e.g., mobile computing device 160 such as a smartphone), based on an authentication procedure that utilizes proximity detection as a second factor for triggering the use of access control credentials. This method may correspond to a counterpart of operations in flowchart 400, as performed by a mobile device, but may also include additional or variations of such operations.

[0061] Operation 510 includes transmitting at least one wireless communication signal to an access control reader. This may correspond to operation 420, discussed above, to provide a wireless communication signal that can be used for evaluating a signal characteristic (e.g., RSSI).

[0062] Operation 520 includes interacting with the access control reader, when located within a defined distance of the access control reader. This may correspond to operations of RFID polling, NFC communication, or other interactions occurring at a short distance from the reader.

[0063] Operation 530 includes receiving a request from the access control reader for an access credential. Operation 540 includes transmitting the access credential to the access control reader to authenticate the mobile computing device. This may correspond to operation 430, discussed above, to provide credentials and determine PACS data.

[0064] Additional operations and variations may occur based on reader buffering of PACS data (e.g., corresponding to operation 440), and providing other information to assist in the detection of the mobile device as located within the defined distance of the access control reader.

[0065] For example, in an alternative embodiment, an access control system may utilize multiple communications protocols to validate an access request by a credential holder, such as via Bluetooth and NFC / RFID communication protocols. The disclosures herein may be adapted to support a multiple factor authentication process with these multiple communications protocols. For example, in some variations, the mobile device may utilize wireless communications to pre-validate an associated credential with the access control system prior to the credential being presented at a reader within the access control system. While the system may still be configured to require close proximity or presentment of the credential at a reader as part of the authentication process, the use of the mobile device’sother wireless communications protocols can provide early additional factor verification of the credential prior to presentment or close proximity. Such an implementation could advantageously provide the benefits of multiple factor authentication without requiring user interaction or introducing additional post-presentment procedures to slow down the authentication process. If the credential is presented without a pre-validation, then the access control system may proceed with standard additional factor authentication processes, depending on system configuration.

[0066] Similarly, in other variations, the mobile device holding a credential may also be associated with a supplemental RFID or NFC device, such as a physical credential card. The supplemental device may or may not contain the identical credential information presented by the mobile device, but may instead contain other credential information associated with the information stored on the mobile device. In some examples, the supplemental device may be presented to the reader in place of or in addition to the presence of the mobile device. As part of a multiple factor authentication process, the mobile device may use wireless communications with the access control system to pre-validate the credential information associated with at least the supplemental device, and presentment of the supplemental device at a reader within the access control system may then complete the authentication process. Such an implementation could again advantageously provide the benefits of multiple factor authentication without requiring user interaction or introducing additional post-presentment procedures to slow down the authentication process.

[0067] FIG. 6 illustrates a block diagram schematic of various components of an example electronic device 600, such as implemented by an electronic device of controller 110, the credential reader 140, or a related access or credential device. In general, electronic device 600 can include one or more of a memory 602, a processor 604, one or more antennas 606, communication circuitry 608, a network interface device 610, optionally a user interface 612, and a power source 614 or like power supply. The electronic device 600 may take a variety of form factors such as a mounted device, a free-standing device, or a portable device (such as but not limited to a mobile computing device such as a tablet, but which may be mounted in a fixed location).

[0068] Memory 602 can be used in connection with the execution of application programming or instructions by processor 604, and for the temporary or long-term storage of program executable instructions 616 or instruction sets and / or credential data 618, including the authentication keysets, identifiers, or other access control data or instructions related to authentication and verification operations. For example, memory 602 can contain executableinstructions 616 that are used by the processor 604 to run functions or perform determinations based on credential data 618. Memory 602 can comprise a machine readable medium that can be any medium that can contain, store, communicate, or transport data, program code, or instructions for use by or in connection with the device 600. The computer readable medium can be, for example but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device. More specific examples of suitable computer readable medium include, but are not limited to, an electrical connection having one or more wires or a tangible storage medium such as a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or EEPROM), Dynamic RAM (DRAM), any solid-state storage device, in general, a compact disc read-only memory (CD-ROM), or other optical or magnetic storage device. Computer readable media includes, but is not to be confused with, computer readable storage medium, which is intended to cover all physical, non-transitory, or similar embodiments of computer readable media.

[0069] Processor 604 can correspond to one or more computer processing devices or resources. For instance, processor 604 can be provided as silicon, as a Field Programmable Gate Array (FPGA), an Application-Specific Integrated Circuit (ASIC), any other type of Integrated Circuit (IC) chip, a collection of IC chips, or the like. As a more specific example, processor 604 can be provided as a microprocessor, Central Processing Unit (CPU), or plurality of microprocessors or CPUs that are configured to execute instruction sets 620 stored in an internal memory and / or memory 602.

[0070] Antenna 606 can correspond to one or multiple antennas and can be configured to provide for wireless communications between, for example, device 600 and a credential or key device. Antenna(s) 606 can be arranged to operate using one or more wireless communication protocols and operating frequencies including, but not limited to, the IEEE 802.15.1, Bluetooth, Bluetooth Low Energy (BLE), near field communications (NFC), ZigBee, GSM, CDMA, Wi-Fi, RF, UWB, and the like. By way of example, antenna(s) 606 can be RF antenna(s), and as such, may transmit / receive RF signals through free-space to be received / transferred by a credential or key device having an RF transceiver.

[0071] Communication circuitry 608 can be configured to communicate according to any suitable communications protocol with one or more different systems or devices either remote or local to the device 600. This may include communications with other control mechanisms or control systems, or other functional entities arranged in a system.

[0072] Network interface device 610 includes hardware to facilitate communications with other devices, such as with a cloud service, over a communication network, such as network 105 or network 115, utilizing any one of a number of transfer protocols (e.g., frame relay, internet protocol (IP), transmission control protocol (TCP), user datagram protocol (UDP), hypertext transfer protocol (HTTP), etc.). Example communication networks can include a local area network (LAN), a wide area network (WAN), a packet data network (e.g., the Internet), mobile telephone or data networks (e.g., 3GPP 4G / 5G cellular networks), Plain Old Telephone (POTS) networks, wireless data networks (e.g., the IEEE 802.11 family of standards known as Wi-Fi, the LoRaWAN® family of standards defined by the LoRa Alliance®, or low-earth-orbit satellite communication networks), networks based on the IEEE 802.15.4 family of standards, and peer-to-peer (P2P) networks, among others. In some examples, network interface device 610 can include an Ethernet port or other physical jack, a Wi-Fi card, a Network Interface Card (NIC), a cellular interface (e.g., antenna, filters, and associated circuitry), or the like. In some examples, network interface device 610 can include one or more antennas to wirelessly communicate using, for example, at least one of singleinput multiple-output (SIMO), multiple-input multiple-output (MIMO), or multiple-input single-output (MISO) techniques.

[0073] User interface 612 can include one or more input devices and / or display devices. Examples of suitable user input devices that can be included in user interface 612 include, without limitation, one or more buttons, a keyboard, a mouse, a touch-sensitive surface, a stylus, a camera, a microphone, a PIN pad, touch screen, fingerprint reader, magnetic stripe reader, chip reader, etc. Examples of suitable user output devices that can be included in user interface 612 include, without limitation, one or more LEDs, an LCD panel, a display screen, a touchscreen, one or more lights, a speaker, etc. It should be appreciated that user interface 612 can also include a combined user input and user output device, such as a touch-sensitive display or the like.

[0074] Power source 614 can be any suitable internal power source, such as a battery, capacitive power source or similar type of charge-storage device, etc., and / or can include one or more power conversion circuits suitable to convert external power into suitable power (e.g., conversion of externally-supplied AC power into DC power) for components of the device 600. Power source 614 can also include some implementation of surge protection circuitry to protect the components of device 600 from power surges.

[0075] Device 600 can also include one or more interlinks, interconnects, or buses 622 operable to transmit communications between the various hardware components of thereader. A system bus 622 can be any of several types of commercially available bus structures or bus architectures.

[0076] As suggested above, the device 600 may be embodied by a credential device or a reader device, or related equipment such as a control panel or other specialized electronic device for security or credential operations. Thus, the device 600 may include various programmed functionality for making access control determinations, including with the use of authentication operations and location identification operations as discussed herein. Based on the access control determinations, the device 600 or an associated a control panel can instruct a reader or another device to operate or command a control mechanism, or may directly operate or command a control mechanism.

[0077] More generally, and as indicated above, a credential reader device may include some, any, or all of the various components described above with respect to the block diagram schematic of FIG. 6. Additional reader, control panel, and / or host server components may be used to determine that the user’s credential or credential data provided by credential device is valid and / or authorized (e.g., based on authentication), followed by the reader, control panel, or host server to operate a control mechanism to allow access to a secure asset by the user having the credential device. Further, although not illustrated in FIGS. 6 or 7, a variety of secure storage, memory, and compute elements or configurations may be used to ensure the security and integrity of any credential or identifiers, used with the presently disclosed techniques.

[0078] FIG. 7 illustrates a block diagram schematic of various example components of an example computing machine 700 that can be used as, for example, mobile computing device 160, one or more hardware devices of access control service 205, controller 110, other cloud computing system(s) or servers, and the like. Examples, as described herein, can generally include, or can operate by, logic or a number of components, modules, or mechanisms in machine 700. Such components may be hardware, software, or firmware communicatively coupled to one or more processors in order to carry out the operations described herein. Generally, circuitry (e.g., processing circuitry) of example machine 700 may include a collection of circuits implemented in tangible entities of the machine 700 that include hardware (e.g., simple circuits, gates, logic, etc.). Circuitry membership can be flexible over time. Circuitries include members that can, alone or in combination, perform specified operations when operating. In some examples, hardware of the circuitry can be immutably designed to carry out a specific operation (e.g., hardwired). In some examples, the hardware of the circuitry can include variably connected physical components (e.g., execution units,transistors, simple circuits, etc.) including a machine readable medium physically modified (e.g., magnetically, electrically, moveable placement of invariant massed particles, etc.) to encode instructions of the specific operation. In connecting the physical components, the underlying electrical properties of a hardware constituent are changed, for example, from an insulator to a conductor or vice versa. The instructions permit embedded hardware (e.g., the execution units or a loading mechanism) to create members of the circuitry in hardware via the variable connections to carry out portions of the specific operation when in operation. Accordingly, in some examples, the machine readable medium elements are part of the circuitry or are communicatively coupled to the other components of the circuitry when the device is operating. In some examples, any of the physical components can be used in more than one member of more than one circuitry. For example, under operation, execution units can be used in a first circuit of a first circuitry at one point in time and reused by a second circuit in the first circuitry, or by a third circuit in a second circuitry at a different time.Additional and / or more specific examples of components with respect to machine 700 follow.

[0079] In some embodiments, machine 700 can operate as a standalone device or can be connected (e.g., networked) to other machines. In a networked deployment, machine 700 can operate in the capacity of a server machine, a client machine, or both in server-client network environments. In some examples, machine 700 can act as a peer machine in a peer-to-peer (P2P) (or other distributed) network environment. Machine 700 can be or include a PC, a tablet, a compute node, a mobile telephone, a web appliance, a network router, switch or bridge, an RFID smartcard or other proximity -based card, access control card, electronic key, key fob, or any machine capable of executing instructions (sequential or otherwise) that specify actions to be taken by that machine. Further, while only a single machine is illustrated, the term “machine” shall also be taken to include any collection of machines that individually or jointly execute a set (or multiple sets) of instructions to perform any one or more of the methodologies discussed herein, such as cloud computing, software as a service (SaaS), other computer cluster configurations.

[0080] Machine (e.g., computer system) 700 can include a hardware processor 702 (e.g., a central processing unit (CPU), a graphics processing unit (GPU), a hardware processor core, or any combination thereof) and a main memory 704, a static memory (e.g., memory or storage for firmware, microcode, a basic-input-output (BIOS), unified extensible firmware interface (UEFI), etc.) 706, and / or mass storage 708 (e.g., hard drives, tape drives, flash storage, or other block devices) some or all of which can communicate with each other via an interlink (e.g., bus) 734. Machine 700 can further include a display device 710, an inputdevice 712, and / or a user interface (UI) navigation device 714. Examples of suitable display devices include, without limitation, one or more LEDs, an LCD panel, a display screen, a touchscreen, one or more lights, etc. Example input devices and UI navigation devices include, without limitation, one or more buttons, a keyboard, a touch-sensitive surface, a stylus, a camera, a microphone, etc. In some examples, one or more of the display device 710, input device 712, and / or UI navigation device 714 can be a combined unit, such as a touch screen display. Machine 700 can additionally include a signal generation device 718 (e.g., a speaker), a network interface device 720, one or more antennas 730, a power source 732, and one or more sensors 716, such as a global positioning system (GPS) sensor, compass, accelerometer, or other sensor. Machine 700 can include an output controller 728, such as a serial (e.g., universal serial bus (USB)), parallel, or other wired or wireless (e.g., infrared (IR), NFC, etc.) connection to communicate with or control one or more peripheral devices (e.g., a printer, card reader, etc.).

[0081] Processor 702 can correspond to one or more computer processing devices or resources. For instance, processor 702 can be provided as silicon, as a Field Programmable Gate Array (FPGA), an Application-Specific Integrated Circuit (ASIC), any other type of Integrated Circuit (IC) chip, a collection of IC chips, or the like. As a more specific example, processor 702 can be provided as a microprocessor, Central Processing Unit (CPU), or plurality of microprocessors or CPUs that are configured to execute instruction sets 722 stored in an internal memory and / or memory 704, 706 and mass storage 708.

[0082] Any of memory 704, 706 and mass storage 708 can be used in connection with the execution of application programming or instructions by processor 702 for performing any of the functionality or methods described herein, and for the temporary or long-term storage of program instructions 724 or instruction sets and / or other data for performing any of the functionality or methods described herein, including in connection with the authentication operations as described herein. Any of memory 704, 706 and mass storage 708 can comprise a computer readable medium that can be any medium that can contain, store, communicate, or transport data, program code, or instructions 724 for use by or in connection with machine 700. The computer readable medium can be, for example but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device. More specific examples of suitable computer readable medium include, but are not limited to, an electrical connection having one or more wires or a tangible storage medium such as a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or EEPROM),Dynamic RAM (DRAM), a solid-state storage device, in general, a compact disc read-only memory (CD-ROM), or other optical or magnetic storage device. As noted above, computer readable media includes, but is not to be confused with, computer readable storage medium, which is intended to cover all physical, non-transitory, or similar embodiments of computer readable media.

[0083] Network interface device 720 includes hardware to facilitate communications with other devices over a communication network, such as network 112, utilizing any one of a number of transfer protocols (e.g., frame relay, internet protocol (IP), transmission control protocol (TCP), user datagram protocol (UDP), hypertext transfer protocol (HTTP), etc.). Example communication networks can include a local area network (LAN), a wide area network (WAN), a packet data network (e.g., the Internet), mobile telephone or data networks (e.g., 3GPP 4G / 5G cellular networks), Plain Old Telephone (POTS) networks, wireless data networks (e.g., the IEEE 802.11 family of standards known as Wi-Fi, the LoRaWAN® family of standards defined by the LoRa Alliance®, or low-earth-orbit satellite communication networks), networks based on the IEEE 802.15.4 family of standards, and peer-to-peer (P2P) networks, among others. In some examples, network interface device 720 can include an Ethernet port or other physical jack, a Wi-Fi card, a Network Interface Card (NIC), a cellular interface (e.g., antenna, filters, and associated circuitry), or the like. In some examples, network interface device 720 can include one or more antennas to wirelessly communicate using, for example, at least one of single-input multiple-output (SIMO), multiple-input multiple-output (MIMO), or multiple-input single-output (MISO) techniques.

[0084] Antenna 730 can correspond to one or multiple antennas and can be configured to provide for wireless communications between machine 700 and another device. Antenna(s) 730 can be arranged to operate using one or more wireless communication protocols and operating frequencies including, but not limited to, the IEEE 802.15.1, Bluetooth, Bluetooth Low Energy (BLE), near field communications (NFC), ZigBee, GSM, CDMA, Wi-Fi, RF, UWB, and the like. By way of example, antenna(s) 730 can be RF antenna(s), and as such, may transmit / receive RF signals through free-space to be received / transferred by another device having an RF transceiver.

[0085] Power source 732 can be any suitable internal power source, such as a battery, capacitive power source or similar type of charge-storage device, etc., and / or can include one or more power conversion circuits suitable to convert external power into suitable power (e.g., conversion of externally-supplied AC power into DC power) for components of themachine 700. Power source 732 can also include some implementation of surge protection circuitry to protect the components of machine 700 from power surges.

[0086] As indicated above, machine 700 can include one or more interlinks or buses 734 operable to transmit communications between the various hardware components of the machine. A system bus 734 can be any of several types of commercially available bus structures or bus architectures.

[0087] Additional examples of the present subject matter include the following list of examples. Other variations to the following examples will also be apparent based on the techniques discussed herein.

[0088] Example l is a method for proximity-based access control, performed by an access control reader, the method comprising: detecting a mobile computing device as located in wireless communication range of the access control reader, based on a characteristic of a wireless communication signal received from the mobile computing device; detecting the mobile computing device as located within a defined distance of the access control reader, based on a proximity detection performed by the access control reader; and using physical access control system data to activate a physical access control system, in response to concurrently (i) detecting the mobile computing device as located within the defined distance of the access control reader, and (ii) detecting the mobile computing device as located in the wireless communication range of the access control reader.

[0089] In Example 2, the subject matter of Example 1 optionally includes subject matter where detecting the mobile computing device comprises: using an optical sensor to track an area within the defined distance of the access control reader; and determining that the mobile computing device is within the defined distance of the access control reader, based on detection of an object with the optical sensor.

[0090] In Example 3, the subject matter of Example 2 optionally includes subject matter where the object is the mobile computing device or a user of the mobile computing device.

[0091] In Example 4, the subject matter of any one or more of Examples 1-3 optionally include subject matter where detecting the mobile computing device comprises: polling for credentials with radio frequency identification (RFID) data communications; and determining that the mobile computing device is within the defined distance of the access control reader, based on an interruption in a radio frequency field of the RFID data communications when polling for the credentials.

[0092] In Example 5, the subject matter of Example 4 optionally includes subject matter where wherein the polling for credentials includes at least one of: polling with a low-frequency RFID data communication operating between 125kHz and 134 kHz; or polling with a high-frequency RFID data communication operating at 13.56MHz.

[0093] In Example 6, the subject matter of any one or more of Examples 4-5 optionally include subject matter where the access control reader is calibrated to identify the interruption in the radio frequency field that corresponds to an area within the defined distance of the access control reader.

[0094] In Example 7, the subject matter of Example 6 optionally includes subject matter where the interruption in the radio frequency field is detected based on a difference in a resonant frequency voltage peak, or based on a difference in power consumption.

[0095] In Example 8, the subject matter of any one or more of Examples 1-7 optionally include performing a credential exchange with the mobile computing device, in response to detecting the mobile computing device in the wireless communication range of the access control reader; determining the physical access control system data, based on mutual authentication between the mobile computing device and the access control reader performed using the credential exchange; and buffering the physical access control system data at the access control reader, wherein the buffered physical access control system data is used to subsequently activate the physical access control system.

[0096] In Example 9, the subject matter of Example 8 optionally includes subject matter where detecting the mobile computing device as located within the defined distance of the access control reader comprises: performing a near-field communication (NFC) data communication between the access control reader and the mobile computing device, to identify that the mobile computing device is located within an NFC communication range; wherein the buffered physical access control system data is released for use to subsequently activate the physical access control system, in response to identifying that the mobile computing device is located within the NFC communication range.

[0097] In Example 10, the subject matter of any one or more of Examples 8-9 optionally include performing a discovery of Bluetooth devices to identify the mobile computing device; wherein detecting the mobile computing device as located in the wireless communication range of the access control reader, occurs in response of the discovery of Bluetooth devices including the mobile computing device; and wherein the buffering of the physical access control system data occurs before detecting the mobile computing device within the defined distance of the access control reader.

[0098] In Example 11, the subject matter of any one or more of Examples 1-10 optionally include subject matter where the characteristic of the wireless communication signal receivedfrom the mobile computing device, used for detecting the mobile computing device as located in the wireless communication range, includes a received signal strength indicator (RS SI) of a Bluetooth wireless communication.

[0099] In Example 12, the subject matter of any one or more of Examples 1-11 optionally include subject matter where detecting the mobile computing device as located within the defined distance of the access control reader occurs within a predefined time period after detecting the mobile computing device as located in the wireless communication range of the access control reader.

[0100] In Example 13, the subject matter of any one or more of Examples 1-12 optionally include subject matter where the defined distance of the access control reader corresponds to an area located within approximately 10 centimeters of the access control reader.

[0101] Example 14 is a non-transitory computer-readable medium comprising executable program code, that when executed by circuitry of a device, causes the circuitry to perform any of the methods of Examples 1 to 13.

[0102] Example 15 is an apparatus, comprising: memory configured to store an access credential provided from a mobile computing device; and circuitry configured to perform any of the methods of Examples 1 to 13 to perform proximity -based access control based on the access credential provided from the mobile computing device.

[0103] Example 16 is a method for proximity -based access control, performed by a mobile computing device, the method comprising: transmitting at least one wireless communication signal to an access control reader, wherein in response to transmitting the at least one wireless communication signal, the access control reader detects the mobile computing device as located in wireless communication range of the access control reader based on a characteristic of the at least one wireless communication signal; interacting with the access control reader, when located within a defined distance of the access control reader, wherein in response to interacting with the access control reader, the access control reader detects the mobile computing device as located within the defined distance of the access control reader based on a proximity detection performed by the access control reader; receiving a request from the access control reader for an access credential; and transmitting the access credential to the access control reader to authenticate the mobile computing device, wherein the access control reader is configured to activate a physical access control system after mutual authentication of the mobile computing device when the mobile computing device is concurrently (i) located in the wireless communication range of the access control reader and (ii) located within the defined distance of the access control reader.

[0104] In Example 17, the subject matter of any one or more of Examples 15-16 optionally include subject matter where the access control reader detects the mobile computing device as located within the defined distance of the access control reader based on use of an optical sensor to track an area within the defined distance of the access control reader, and based on detection of an object with the optical sensor.

[0105] In Example 18, the subject matter of Example 17 optionally includes subject matter where the object is the mobile computing device or a user of the mobile computing device.

[0106] In Example 19, the subject matter of any one or more of Examples 16-18 optionally include subject matter where the access control reader detects the mobile computing device based on: receiving a request at the mobile computing device for credentials, via polling with radio frequency identification (RFID) data communications; and wherein the access control reader determines that the mobile computing device is within the defined distance of the access control reader, based on an interruption in a radio frequency field of the RFID data communications during the polling.

[0107] In Example 20, the subject matter of Example 19 optionally includes subject matter where the polling includes at least one of: polling with a low-frequency RFID data communication operating between 125kHz and 134 kHz; or polling with a high-frequency RFID data communication operating at 13.56MHz.

[0108] In Example 21, the subject matter of any one or more of Examples 19-20 optionally include subject matter where the access control reader is calibrated to identify the interruption in the radio frequency field that corresponds to an area within the defined distance of the access control reader.

[0109] In Example 22, the subject matter of any one or more of Examples 20-21 optionally include subject matter where the interruption in the radio frequency field is detected based on a difference in a resonant frequency voltage peak, or based on a difference in power consumption.

[0110] In Example 23, the subject matter of any one or more of Examples 16-22 optionally include subject matter where the request from the access control reader is provided in response to detection, by the access control reader, that the mobile computing device is in the wireless communication range; and wherein the access control reader buffers physical access control system data and uses the physical access control system data to subsequently activate the physical access control system.[OHl] In Example 24, the subject matter of Example 23 optionally includes subject matter where detection of the mobile computing device as located within the defined distance of theaccess control reader comprises: performing a near-field communication (NFC) data communication between the mobile computing device and the access control reader, to enable the access control reader to identify that the mobile computing device is located within an NFC communication range; wherein the buffered physical access control system data is released for use to subsequently activate the physical access control system, in response to the access control reader identifying that the mobile computing device is located within the NFC communication range.

[0112] In Example 25, the subject matter of any one or more of Examples 23-24 optionally include responding to a discovery of Bluetooth devices, provided from the access control reader, to enable the access control reader to identify the mobile computing device; wherein detection of the mobile computing device as located in the wireless communication range of the access control reader occurs in response of the discovery of Bluetooth devices including the mobile computing device; and wherein buffering of the physical access control system data occurs at the access control reader before detection of the mobile computing device as located within the defined distance of the access control reader.

[0113] In Example 26, the subject matter of any one or more of Examples 16-25 optionally include subject matter where the characteristic of the at least one wireless communication signal, used for detection of the mobile computing device as located in the wireless communication range, includes a received signal strength indicator (RS SI) of a Bluetooth wireless communication.

[0114] In Example 27, the subject matter of any one or more of Examples 16-26 optionally include subject matter where detection of the mobile computing device as located within the defined distance of occurs within a predefined time period after detection of the mobile computing device as located in the wireless communication range.

[0115] In Example 28, the subject matter of any one or more of Examples 16-27 optionally include subject matter where the defined distance of the access control reader corresponds to an area located within approximately 10 centimeters of the access control reader.

[0116] Example 29 is a non-transitory computer readable medium comprising executable program code, that when executed by one or more processors of a computing device, causes the one or more processors to perform any of the methods of Examples 16 to 28.

[0117] Example 30 is an apparatus, comprising: memory configured to store an access credential; wireless communication circuitry to communicate with an access control reader; and circuitry configured to perform any of the methods of Examples 16 to 28 to performproximity-based access control, based on providing the access credential to the access control reader.

[0118] Example 31 is a method for proximity -based access control, the method comprising: receiving from a mobile computing device at least one wireless communication signal through a first communication protocol, wherein in response to receiving the at least one wireless communication signal, the access control system determines the mobile computing device is located in a pre-defined range of an access control reader based on a characteristic of the at least one wireless communication signal and pre-validates a credential associated with the mobile computing device; receiving credential information associated with the mobile computing device at the access control reader within a defined distance through a second communication protocol, wherein in response to receiving the credential information, the access control reader determines a pre-defined distance requirement has been satisfied based on a proximity detection performed by the access control reader; wherein the access control reader is configured to activate a physical access control system after mutual authentication of the credential information when (i) presentment has been made within a pre-defined distance of the access control reader and (ii) the credential information has been validated because the system determines the mobile computing device associated with the credential information is located within the defined distance of the access control reader.

[0119] In Example 32, the subject matter of Example 31 optionally includes subject matter where the credential information is associated with the mobile computing device and presented to the access control reader by a supplemental NFC or RFID device.

[0120] In Example 33, the subject matter of Example 32 optionally includes subject matter where wherein the supplemental device is a physical credential card.

[0121] In Example 34, the subject matter of Example 32 optionally includes subject matter where the supplemental device is another mobile computing device, such as a smart watch.

[0122] In Example 35, the subject matter of any one or more of Examples 31-34 optionally includes subject matter where the credential information presented at the reader is associated with but not the same as the credential information stored on the mobile computing device.

[0123] In Example 36, the subject matter of any one or more of Examples 31-35 optionally include subject matter where if the credential information presented at the reader has not been pre-validated by the access control system, additional factor authentication procedures are initiated to validate the presented credential information.

[0124] In Example 37, the subject matter of any one or more of Examples 31-36 optionally include subject matter where the first communication protocol comprises a Bluetooth communication.

[0125] In Example 38, the subject matter of any one or more of Examples 31-37 optionally include subject matter where the first communication protocol comprises a Wi-Fi communication.

[0126] In Example 39, the subject matter of any one or more of Examples 31-38 optionally include subject matter where the second communication protocol comprises an NFC communication.

[0127] In Example 40, the subject matter of any one or more of Examples 31-39 optionally include subject matter where the second communication protocol comprises an RFID communication.

[0128] In Example 41, the subject matter of any one or more of Examples 31-40 optionally include subject matter where the characteristic of the at least one wireless communication signal, used for detection of the mobile computing device as located in the wireless communication range, includes a received signal strength indicator (RS SI) of a Bluetooth wireless communication.

[0129] In Example 42, the subject matter of any one or more of Examples 31-41 optionally include subject matter where detection of the mobile computing device as located within the defined distance of occurs within a predefined time period after detection of the mobile computing device as located in the wireless communication range.

[0130] In Example 43, the subject matter of any one or more of Examples 31-42 optionally include subject matter where the pre-defined distance of the access control reader corresponds to an area located within approximately 10 centimeters of the access control reader.

[0131] Example 44 is a non-transitory computer readable medium comprising executable program code, that when executed by one or more processors of a computing device, causes the one or more processors to perform any of the methods of Examples 31 to 43.

[0132] Example 45 is an apparatus, comprising: memory configured to store an access credential; wireless communication circuitry to communicate with an access control reader; and circuitry configured to perform any of the methods of Examples 31 to 43 to perform proximity-based access control, based on providing the access credential to the access control reader.

[0133] The above detailed description includes references to the accompanying drawings, which form a part of the detailed description. The drawings show, by way of illustration, specific embodiments that can be practiced. These embodiments may also be referred to herein as “examples.” Such embodiments or examples can include elements in addition to those shown or described. However, the present inventors also contemplate examples in which only those elements shown or described are provided. Moreover, the present inventors also contemplate examples using any combination or permutation of those elements shown or described (or one or more aspects thereof), either with respect to a particular example (or one or more aspects thereof), or with respect to other examples (or one or more aspects thereof) shown or described herein. That is, the above-described embodiments or examples or one or more aspects, features, or elements thereof can be used in combination with each other.

[0134] As will be appreciated by one of skill in the art, the various embodiments of the present disclosure may be embodied as a method (including, for example, a computer-implemented process, a business process, and / or any other process), apparatus (including, for example, a system, machine, device, computer program product, and / or the like), or a combination of the foregoing. Accordingly, embodiments of the present disclosure or portions thereof may take the form of an entirely hardware embodiment, an entirely software embodiment (including firmware, middleware, microcode, hardware description languages, etc.), or an embodiment combining software and hardware aspects. Furthermore, embodiments of the present disclosure may take the form of a computer program product on a computer-readable medium or computer-readable storage medium, having computerexecutable program code embodied in the medium, that define processes or methods described herein. A processor or processors may perform the necessary tasks defined by the computer-executable program code. In the context of this disclosure, a computer readable medium may be any medium that can contain, store, communicate, or transport the program for use by or in connection with the systems disclosed herein. As indicated above, the computer readable medium may be, for example but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device. More specific examples of suitable computer readable medium include, but are not limited to, an electrical connection having one or more wires or a tangible storage medium such as a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), a compact disc read-only memory (CD-ROM), or other optical, magnetic, or solid state storage device. As noted above, computer-readable media includes, but is not to be confusedwith, computer-readable storage medium, which is intended to cover all physical, non-transitory, or similar embodiments of computer-readable media.

[0135] In the foregoing description various embodiments of the present disclosure have been presented for the purpose of illustration and description. They are not intended to be exhaustive or to limit the invention to the precise form disclosed. Obvious modifications or variations are possible in light of the above teachings. The various embodiments were chosen and described to provide the best illustration of the principals of the disclosure and their practical application, and to enable one of ordinary skill in the art to utilize the various embodiments with various modifications as are suited to the particular use contemplated. All such modifications and variations are within the scope of the present disclosure as determined by the appended claims when interpreted in accordance with the breadth they are fairly, legally, and equitably entitled.

Claims

CLAIMSWhat is claimed is:

1. A method for proximity -based access control, performed by an access control reader, the method comprising:detecting a mobile computing device as located in wireless communication range of the access control reader, based on a characteristic of a wireless communication signal received from the mobile computing device;detecting the mobile computing device as located within a defined distance of the access control reader, based on a proximity detection performed by the access control reader; andusing physical access control system data to activate a physical access control system, in response to concurrently (i) detecting the mobile computing device as located within the defined distance of the access control reader, and (ii) detecting the mobile computing device as located in the wireless communication range of the access control reader.

2. The method of claim 1, wherein detecting the mobile computing device comprises: using an optical sensor to track an area within the defined distance of the access control reader; anddetermining that the mobile computing device is within the defined distance of the access control reader, based on detection of an object with the optical sensor.

3. The method of claim 2, wherein the object is the mobile computing device or a user of the mobile computing device.

4. The method of claim 1, wherein detecting the mobile computing device comprises: polling for credentials with radio frequency identification (RFID) data communications; anddetermining that the mobile computing device is within the defined distance of the access control reader, based on an interruption in a radio frequency field of the RFID data communications when polling for the credentials.

5. The method of claim 4, wherein the polling for credentials includes at least one of: polling with a low-frequency RFID data communication operating between 125kHz and 134 kHz; orpolling with a high-frequency RFID data communication operating at 13.56MHz.

6. The method of claim 4, wherein the access control reader is calibrated to identify the interruption in the radio frequency field that corresponds to an area within the defined distance of the access control reader.

7. The method of claim 6, wherein the interruption in the radio frequency field is detected based on a difference in a resonant frequency voltage peak, or based on a difference in power consumption.

8. The method of claim 1, further comprising:performing a credential exchange with the mobile computing device, in response to detecting the mobile computing device in the wireless communication range of the access control reader;determining the physical access control system data, based on mutual authentication between the mobile computing device and the access control reader performed using the credential exchange; andbuffering the physical access control system data at the access control reader, wherein the buffered physical access control system data is used to subsequently activate the physical access control system.

9. The method of claim 8, wherein detecting the mobile computing device as located within the defined distance of the access control reader comprises:performing a near-field communication (NFC) data communication between the access control reader and the mobile computing device, to identify that the mobile computing device is located within an NFC communication range;wherein the buffered physical access control system data is released for use to subsequently activate the physical access control system, in response to identifying that the mobile computing device is located within the NFC communication range.

10. The method of claim 8, further comprising:performing a discovery of Bluetooth devices to identify the mobile computing device; wherein detecting the mobile computing device as located in the wireless communication range of the access control reader, occurs in response of the discovery of Bluetooth devices including the mobile computing device; andwherein the buffering of the physical access control system data occurs before detecting the mobile computing device within the defined distance of the access control reader.

11. The method of claim 1, wherein the characteristic of the wireless communication signal received from the mobile computing device, used for detecting the mobile computing device as located in the wireless communication range, includes a received signal strength indicator (RS SI) of a Bluetooth wireless communication.

12. The method of claim 1, wherein detecting the mobile computing device as located within the defined distance of the access control reader occurs within a predefined time period after detecting the mobile computing device as located in the wireless communication range of the access control reader.

13. The method of claim 1, wherein the defined distance of the access control reader corresponds to an area located within approximately 10 centimeters of the access control reader.

14. A non-transitory computer-readable medium comprising executable program code, that when executed by circuitry of a device, causes the circuitry to perform any of the methods of claims 1 to 13.

15. An apparatus, comprising:memory configured to store an access credential provided from a mobile computing device; andcircuitry configured to perform any of the methods of claims 1 to 13 to perform proximity-based access control based on the access credential provided from the mobile computing device.

16. A method for proximity -based access control, performed by a mobile computing device, the method comprising:transmitting at least one wireless communication signal to an access control reader, wherein in response to transmitting the at least one wireless communication signal, the access control reader detects the mobile computing device as located in wireless communication range of the access control reader based on a characteristic of the at least one wireless communication signal;interacting with the access control reader, when located within a defined distance of the access control reader, wherein in response to interacting with the access control reader, the access control reader detects the mobile computing device as located within the defined distance of the access control reader based on a proximity detection performed by the access control reader;receiving a request from the access control reader for an access credential; and transmitting the access credential to the access control reader to authenticate the mobile computing device, wherein the access control reader is configured to activate a physical access control system after mutual authentication of the mobile computing device when the mobile computing device is concurrently (i) located in the wireless communication range of the access control reader and (ii) located within the defined distance of the access control reader.

17. The method of claim 15, wherein the access control reader detects the mobile computing device as located within the defined distance of the access control reader based on use of an optical sensor to track an area within the defined distance of the access control reader, and based on detection of an object with the optical sensor.

18. The method of claim 17, wherein the object is the mobile computing device or a user of the mobile computing device.

19. The method of claim 16, wherein the access control reader detects the mobile computing device based on:receiving a request at the mobile computing device for credentials, via polling with radio frequency identification (RFID) data communications; andwherein the access control reader determines that the mobile computing device is within the defined distance of the access control reader, based on an interruption in a radio frequency field of the RFID data communications during the polling.

20. The method of claim 19, wherein the polling includes at least one ofpolling with a low-frequency RFID data communication operating between 125kHz and 134 kHz; orpolling with a high-frequency RFID data communication operating at 13.56MHz.

21. The method of claim 19, wherein the access control reader is calibrated to identify the interruption in the radio frequency field that corresponds to an area within the defined distance of the access control reader.

22. The method of claim 20, wherein the interruption in the radio frequency field is detected based on a difference in a resonant frequency voltage peak, or based on a difference in power consumption.

23. The method of claim 16, wherein the request from the access control reader is provided in response to detection, by the access control reader, that the mobile computing device is in the wireless communication range; andwherein the access control reader buffers physical access control system data and uses the physical access control system data to subsequently activate the physical access control system.

24. The method of claim 23, wherein detection of the mobile computing device as located within the defined distance of the access control reader comprises:performing a near-field communication (NFC) data communication between the mobile computing device and the access control reader, to enable the access control reader to identify that the mobile computing device is located within an NFC communication range;wherein the buffered physical access control system data is released for use to subsequently activate the physical access control system, in response to the access control reader identifying that the mobile computing device is located within the NFC communication range.

25. The method of claim 23, further comprising:responding to a discovery of Bluetooth devices, provided from the access control reader, to enable the access control reader to identify the mobile computing device;wherein detection of the mobile computing device as located in the wireless communication range of the access control reader occurs in response of the discovery of Bluetooth devices including the mobile computing device; andwherein buffering of the physical access control system data occurs at the access control reader before detection of the mobile computing device as located within the defined distance of the access control reader.

26. The method of claim 16, wherein the characteristic of the at least one wireless communication signal, used for detection of the mobile computing device as located in the wireless communication range, includes a received signal strength indicator (RS SI) of a Bluetooth wireless communication.

27. The method of claim 16, wherein detection of the mobile computing device as located within the defined distance of occurs within a predefined time period after detection of the mobile computing device as located in the wireless communication range.

28. The method of claim 16, wherein the defined distance of the access control reader corresponds to an area located within approximately 10 centimeters of the access control reader.

29. A non-transitory computer readable medium comprising executable program code, that when executed by one or more processors of a computing device, causes the one or more processors to perform any of the methods of claims 16 to 28.

30. An apparatus, comprising:memory configured to store an access credential;wireless communication circuitry to communicate with an access control reader; and circuitry configured to perform any of the methods of claims 16 to 28 to perform proximity-based access control, based on providing the access credential to the access control reader.

Citation Information

Patent Citations

  • Physical access control systems with localization-based intent detection

    US20200314651A1

  • Systems, methods, and devices for access control

    US20240161558A1

  • Hands-free access control

    US9483887B1