Automated access control device selection

A mobile access-based system addresses inefficiencies in traditional access control by using real-time data and intelligent decision-making to automate anti-passback mechanisms, enhancing security and user experience by preventing unauthorized re-entry and reducing administrative burdens.

WO2026093025A1PCT designated stage Publication Date: 2026-05-07ASSA ABLOY AB
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
ASSA ABLOY AB
Filing Date
2025-10-15
Publication Date
2026-05-07

AI Technical Summary

Technical Problem

Traditional access control systems face inefficiencies and resource wastage due to complex configurations and manual oversight in implementing anti-passback mechanisms, leading to unauthorized re-entry attempts and increased administrative burdens.

Method used

A mobile access-based system that leverages real-time data and intelligent decision-making to manage anti-passback functionality, using mobile devices to evaluate previous transactions and signal strengths, providing immediate feedback and automating reader connections.

Benefits of technology

The system optimizes resource allocation and strengthens security by preventing unauthorized re-entry, reducing confusion, and minimizing repeated access attempts through automated and real-time feedback.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2025079785_07052026_PF_FP_ABST
    Figure EP2025079785_07052026_PF_FP_ABST
Patent Text Reader

Abstract

A system for controlling access to a protected resource is described. The system accesses, by a mobile device, data describing configuration of a plurality of access control devices and detects a signal associated with a first access control device of the plurality of access control devices. The system determines one or more previous transactions that the mobile device performed with one or more of the plurality of access control devices and selectively establishes a communication session with the first access control device based on the data describing the configuration of the plurality of access control devices and the one or more previous transactions that the mobile device performed with one or more of the plurality of access control devices.
Need to check novelty before this filing date? Find Prior Art

Description

AUTOMATED ACCESS CONTROL DEVICE SELECTIONPRIORITY APPLICATION(S)

[0001] This application claims priority to Indian Provisional Patent Application No. 202411083270, filed on October 30, 2024, the disclosure of which is incorporated by reference herein in its entirety.BACKGROUND

[0002] Access control systems have become integral to securing physical spaces, ensuring that only authorized individuals can enter or exit specific areas. With the advent of mobile technology and Bluetooth Low Energy (BLE) communication, these systems have evolved to offer enhanced convenience and flexibility. Mobile access solutions allow users to utilize their smartphones as access credentials, facilitating seamless and secure interactions with access control devices. This integration of mobile technology into access control systems represents a significant advancement, providing users with a modern and efficient means of managing entry to secure locations. The use of BLE technology enables short-range wireless communication, ensuring secure and reliable connections between mobile devices and access control readers.BRIEF SUMMARY

[0003] In some aspects, the techniques described herein relate to a system including: one or more hardware processors; and at least one machine-storage medium for storing instructions that, when executed by the one or more hardware processors, cause the one or more hardware processors to perform operations including: accessing, by a mobile device, data describing configuration of a plurality of access control devices; detecting a signal associated with a first access control device of the plurality of access control devices; determining one or more previous transactions that the mobile device performed with one or more of the plurality of access control devices; and selectively establishing a communication session with the first access control device based on the data describing the configuration of the plurality of access control devices and the one or more previous transactions that the mobile device performed with one or more of the plurality of access control devices.

[0004] In some aspects, the techniques described herein relate to a system, wherein the operations include: receiving, by the first access control device from an administrator application, a first portion of the data defining the first access control device as an entrance reader; and receiving, by a first access control device of the plurality of access control devices from the administrator application, a second portion of the data defining the second access control device as an exit reader.

[0005] In some aspects, the techniques described herein relate to a system, wherein the operations include: storing the first portion of the data and the second portion of the data on a server.

[0006] In some aspects, the techniques described herein relate to a system, wherein the operations include: downloading, by the mobile device, the first portion of the data and the second portion of the data from the server.

[0007] In some aspects, the techniques described herein relate to a system, wherein the signal includes a Bluetooth Low Energy (BLE) signal transmitted by the first access control device.

[0008] In some aspects, the techniques described herein relate to a system, wherein the operations include: determining that the first access control device is an entrance reader based on the accessed data; determining whether a last transaction of the one or more previous transactions includes an entrance or an exit; and selectively establishing the communication session with the first access control device based on determining whether the last transaction of the one or more previous transactions includes the entrance or the exit.

[0009] In some aspects, the techniques described herein relate to a system, wherein the operations include: determining that the last transaction includes the entrance; and preventing the mobile device from establishing the communication session with the first access control device in response to determining that the last transaction includes the entrance and based on determining that the first access control device is the entrance reader.

[0010] In some aspects, the techniques described herein relate to a system, wherein the operations include: searching for a signal transmitted by a second access control device; detecting the signal transmitted by a second access control device; determining that the second access control device is an exit reader based on the accessed data; and establishing the communication session with the second access control device inresponse to determining that the last transaction includes the exit and based on determining that the second access control device is the exit reader.

[0011] In some aspects, the techniques described herein relate to a system, wherein the operations include: transmitting a credential to the second access control device from the mobile device to obtain access to a resource protected by the second access control device.

[0012] In some aspects, the techniques described herein relate to a system, wherein the operations include: determining that access to the resource has been granted by the second access control device; and updating the last transaction of the one or more previous transactions to specify that the last transaction includes the exit.

[0013] In some aspects, the techniques described herein relate to a system, wherein the last transaction is stored using the accessed data associated with the second access control device.

[0014] In some aspects, the techniques described herein relate to a system, wherein the operations include: determining that the first access control device is an exit reader based on the accessed data; determining whether a last transaction of the one or more previous transactions includes an entrance or an exit; and selectively establishing the communication session with the first access control device based on determining whether the last transaction of the one or more previous transactions includes the entrance or the exit.

[0015] In some aspects, the techniques described herein relate to a system, wherein the operations include: determining that the last transaction includes the exit; and preventing the mobile device from establishing the communication session with the first access control device in response to determining that the last transaction includes the exit and based on determining that the first access control device is the exit reader.

[0016] In some aspects, the techniques described herein relate to a system, wherein the operations include: detecting a plurality of signals associated with the plurality of access control devices, the plurality of signals including the signal associated with the first access control device; in response to detecting the plurality of signals, determining a last transaction performed by the mobile device of the one or more previous transactions; and selecting one of the plurality of access control devices with which to establish a communication session based on the data describing configuration of the plurality of access control devices and the last transaction.

[0017] In some aspects, the techniques described herein relate to a system, wherein the operations include: replacing the last transaction with a portion of the accessed data describing the selected one of the plurality of access control devices after determining that access has been granted to the mobile device by the selected one of the plurality of access control devices.

[0018] In some aspects, the techniques described herein relate to a system, wherein the operations include: determining that data describing the last transaction is different from the accessed data describing the one of the plurality of access control devices; and transmitting a credential to the selected one of the plurality of access control devices in response to determining that the data describing the last transaction is different from the accessed data describing the one of the plurality of access control devices.

[0019] In some aspects, the techniques described herein relate to a system, wherein the operations include: preventing establishing a communication session with an individual access control device of the plurality of access control devices in response to determining that data describing the last transaction matches the accessed data describing the individual access control device; and presenting a notification on the mobile device indicating an anti-passback violation including a message that identifies a correct access control device to use based on the last transaction.

[0020] In some aspects, the techniques described herein relate to a system, wherein the one or more previous transactions include a set of transactions performed within a threshold range of a current location of the mobile device, and wherein the mobile device presents identifiers of the plurality of access control devices based on the data for selection by a user to establish a communication session.

[0021] In some aspects, the techniques described herein relate to a method including: accessing, by a mobile device, data describing configuration of a plurality of access control devices; detecting a signal associated with a first access control device of the plurality of access control devices; determining one or more previous transactions that the mobile device performed with one or more of the plurality of access control devices; and selectively establishing a communication session with the first access control device based on the data describing the configuration of the plurality of access control devices and the one or more previous transactions that the mobile device performed with one or more of the plurality of access control devices.

[0022] In some aspects, the techniques described herein relate to a machine-storage medium for storing instructions that, when executed by one or more hardware processors, cause the one or more hardware processors to perform operations including: accessing, by a mobile device, data describing configuration of a plurality of access control devices; detecting a signal associated with a first access control device of the plurality of access control devices; determining one or more previous transactions that the mobile device performed with one or more of the plurality of access control devices; and selectively establishing a communication session with the first access control device based on the data describing the configuration of the plurality of access control devices and the one or more previous transactions that the mobile device performed with one or more of the plurality of access control devices.BRIEF DESCRIPTION OF THE SEVERAL VIEWS OF THE DRAWINGS

[0023] To easily identify the discussion of any particular element or act, the most significant digit or digits in a reference number refer to the figure number in which that element is first introduced.

[0024] FIG. 1 is a diagrammatic representation of a networked environment in which the present disclosure may be deployed, in accordance with some examples.

[0025] FIG. 2 illustrates a diagram of an environment for accessing a secure resource, in accordance with some examples.

[0026] FIG. 3 illustrates a routine for accessing a secure resource, in accordance with some examples.

[0027] FIG. 4 is a block diagram illustrating a representative software architecture, which may be used in conjunction with various hardware architectures herein described, in accordance with some examples.

[0028] FIG. 5 is a diagrammatic representation of a machine in the form of a computer system within which a set of instructions may be executed for causing the machine to perform any one or more of the methodologies discussed herein, in accordance with some examples.DETAILED DESCRIPTION

[0029] Example methods and systems for an access control system are described. In the following description, for purposes of explanation, numerous specific details are setforth in order to provide a thorough understanding of the disclosed examples. It will be evident, however, to one of ordinary skill in the art that examples of the disclosure may be practiced without these specific details.

[0030] Anti-passback (APB) mechanisms are designed to prevent unauthorized re-entry into secured areas without first exiting, ensuring that access control systems maintain accurate records of user movements. However, implementing APB in traditional systems often presents significant challenges, leading to wasted resources and inefficiencies. These systems typically rely on complex configurations and additional infrastructure, such as dedicated controllers or headend applications, to enforce APB rules. This complexity increases installation and maintenance costs, as administrators must ensure that all components are correctly configured and synchronized.

[0031] The inefficiencies associated with APB mechanisms are further exacerbated by the lack of real-time feedback to users. Without immediate confirmation of access status, users may inadvertently attempt to re-enter an area, triggering APB violations. This can lead to repeated access attempts, causing unnecessary strain on the system and potentially activating security alarms. Facilities management teams are then required to address these issues, consuming valuable time and resources that could be better allocated elsewhere.

[0032] Moreover, the manual oversight required to manage APB violations adds to the administrative burden. Administrators must continuously monitor access logs and adjust configurations to prevent unauthorized access attempts, which can be both timeconsuming and prone to error. This reliance on manual processes not only increases the risk of security breaches but also detracts from the overall efficiency of the access control system, highlighting the need for more streamlined and automated solutions.

[0033] The disclosed system addresses these issues by integrating a mobile accessbased anti-passback mechanism that leverages real-time data and intelligent decisionmaking. By utilizing mobile devices to manage APB functionality, the system eliminates the need for complex infrastructure and manual oversight. The mobile application intelligently evaluates previous transactions and signal strengths to ensure accurate reader connections, preventing unauthorized re-entry attempts. This approach provides users with immediate feedback, reducing confusion and minimizing repeated access attempts. Additionally, the system's cloud-based configuration allows for seamless updates and synchronization, significantly reducing administrative burdens andenhancing overall efficiency. By automating APB enforcement and providing real-time feedback, the system optimizes resource allocation and strengthens security protocols.

[0034] Specifically, the disclosed techniques access, by a mobile device, data describing configuration of a plurality of access control devices and detect a signal associated with a first access control device of the plurality of access control devices. The disclosed techniques determine one or more previous transactions that the mobile device performed with one or more of the plurality of access control devices and selectively establish a communication session with the first access control device based on the data describing the configuration of the plurality of access control devices and the one or more previous transactions that the mobile device performed with one or more of the plurality of access control devices.

[0035] Components of the system include a mobile application that accesses real-time data describing the configuration of multiple access control devices. The application evaluates previous transactions and signal strengths to ensure accurate reader connections, thereby preventing unauthorized access attempts. This intelligent decisionmaking process provides users with immediate feedback, reducing confusion and minimizing repeated access attempts. Additionally, the system's cloud-based (e.g., server-based) configuration allows for seamless updates and synchronization, ensuring that all devices are consistently aligned with the latest security protocols.

[0036] The disclosed techniques can be deployed, for example, in an office building where employees use mobile devices to access multiple entry and exit points. The system intelligently manages anti-passback rules by evaluating previous transactions and signal strengths, ensuring that users connect to the correct reader. This prevents unauthorized re-entry and reduces confusion, enhancing both security and user experience. As employees approach an entry or exit point, their mobile devices detect signals from nearby access control readers. The system evaluates previous transactions to determine the user's last action, ensuring that the correct reader is selected for the current transaction. If the last transaction was an entry, the system prioritizes connecting to an exit reader, preventing unauthorized re-entry. This process is facilitated by real-time feedback provided to the user, reducing confusion and minimizing repeated access attempts.

[0037] In the healthcare facility scenario, the system enhances security by providing quick and accurate access to sensitive areas. As staff members approach a secure zone,their mobile devices access configuration data and detect signals from access control readers. The system evaluates previous transactions to ensure that the correct reader is engaged, preventing unauthorized access. Real-time feedback is provided to the user, confirming successful access or indicating an error. This automated approach reduces the need for manual oversight and allows healthcare professionals to focus on their critical tasks without interruption, ensuring a seamless and secure access control experience.

[0038] FIG. 1 is a block diagram showing an example access control system 100, according to various examples. The access control system 100 can include a client device 120 (e.g., mobile device) and PAC device 110. The client device 120 and the PAC device 110 are communicatively coupled over a network 130 (e.g., Internet, BLE, ultra- wideband (UWB) communication protocol, Near Field Communication (NFC), and / or telephony network). While the disclosed techniques are discussed in the context of PAC devices, similar techniques are applicable to any other type of access control device, such as a logical access control (LAC) device.

[0039] As used herein, the term “client device” may refer to any machine that interfaces to a communications network (such as network 130) to exchange credentials with an access control device, such as the PAC device 110, a server / controller associated with the access control device, another client device 120, or any other component to obtain access to a logical or physical asset or resource protected by the access control device. In some examples, the client device 120 can additionally or alternatively communicate directly with, for example, an access control device or another client device 120. The client device 120 can include or store one or more credentials which can be provided to the access control device 110 for obtaining access to a protected physical or logical asset or resource.

[0040] A client device 120 may be, but is not limited to, a mobile phone, desktop computer, laptop, portable digital assistant (PDA), smart phone, a wearable device (e.g., a smart watch), tablet, ultrabook, netbook, multi-processor system, microprocessor-based or programmable consumer electronics, physical card, or any other communication device that a user may use to access a network.

[0041] The access control device (e.g., the PAC device 110) can include an access reader device (also referred to as an access control reader) connected to a secure / protected resource (e.g., a door locking mechanism or backend server) that controls the secure / protected resource (e.g., door locking mechanism). The resourceassociated with the access control device can include a door lock, an ignition system for a vehicle, or any other device that grants or denies access to a physical component or that can be operated to grant or deny access to the physical component. For example, in the case of a door lock, the access control device can deny access, in which case the door lock remains locked and the door cannot be opened; or can grant access, in which case the door lock becomes unlocked to allow the door to be opened. As another example, in the case of an ignition system, the access control device can deny access, in which case the vehicle ignition system remains disabled and the vehicle cannot be started; or can grant access, in which case the vehicle ignition becomes enabled to allow the vehicle to be started.

[0042] Physical access control (PAC) covers a range of systems and methods to govern access, for example by people, to secure areas or secure assets. Physical access control includes identification of authorized users or devices (e.g., vehicles, drones, etc.) and actuation of a gate, door, or other facility used to secure an area, or actuation of a control mechanism, for example, a physical or electronic / software control mechanism, permitting access to a secure asset. The access control device may form part of a physical access control system (PACS), which can include a reader (e.g., an online or offline reader) that may hold authorization data (also referred to access control information) and can be capable of determining whether credentials (e.g., from credential or key devices such as radio frequency identification (RFID) chips in cards, fobs, or personal electronic devices such as mobile phones) are authorized for an actuator or control mechanism (e.g., door lock, door opener, software control mechanism, turning off an alarm, etc.), or a PACS can include a host server to which readers and actuators are connected (e.g., via a controller) in a centrally managed configuration.

[0043] In centrally managed configurations, readers can obtain credentials from credential or key devices (e.g., from one or more client devices 120) and pass those credentials to the PACS host server or headend system. The readers can send the credentials over a wired or wireless link, such as network 130. The host server then determines whether the credentials authorize access to the secure area or secure asset (or resource) and commands the actuator or other control mechanism of the PAC device 110 accordingly by sending an allow / deny message back to the reader over the wired or wireless link. While examples in physical access control are used herein, the disclosureapplies similarly to logical access control system (LACS) use cases (e.g., logical access to personal electronic devices, logical access to personal online or electronic accounts or documents, etc.).

[0044] In general, the access control device can include one or more of a memory, a processor, one or more antennas, a communication module, a network interface device, a user interface, a display, and a power source or supply. The memory of the access control device can be used in connection with the execution of application programming or instructions by the processor of the access control device, and for the temporary or long-term storage of program instructions or instruction sets and / or credential or authorization data, such as credential data, credential authorization data, or access control data or instructions. For example, the memory can contain executable instructions that are used by the processor to run other components of access control device and / or to make access determinations based on credential or authorization data.

[0045] The memory of the access control device (e.g., PAC device 110 and / or client device 120) can include a transitory or non-transitory computer-readable medium. The computer-readable medium can be, for example, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device. More specific examples of suitable computer-readable medium include, but are not limited to, an electrical connection having one or more wires or a tangible storage medium such as a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), Dynamic RAM (DRAM), any solid-state storage device in general, a compact disc read-only memory (CD-ROM), or other optical or magnetic storage device. Computer-readable media includes, but is not to be confused with, computer-readable storage medium, which is intended to cover all physical, non- transitory, or similar examples of computer-readable media.

[0046] The processor of the access control device can correspond to one or more computer processing devices or resources. For instance, the processor can be provided as silicon, as a Field Programmable Gate Array (FPGA), an Application-Specific Integrated Circuit (ASIC), any other type of Integrated Circuit (IC) chip, a collection of IC chips, or the like. As a more specific example, the processor can be provided as a microprocessor, Central Processing Unit (CPU), or plurality of microprocessors or CPUs that areconfigured to execute instructions sets stored in an internal memory and / or memory of the access control device.

[0047] The antenna of the access control device can correspond to one or multiple antennas and can be configured to provide for wireless communications between access control device and a credential or key device (e.g., client device 120). The antenna can be arranged to operate using one or more wireless communication protocols and operating frequencies including, but not limited to, the IEEE 502.15.1, Bluetooth, BLE, NFC, ZigBee, Global System for Mobile communications (GSM), Code Division Multiple Access (CDMA), Wi-Fi, RF, UWB, and the like. By way of example, the antenna(s) can be RF antenna(s), and as such, may transmit / receive RF signals through free-space to be received / transferred by a credential or key device having an RF transceiver.

[0048] A communication module or communication component of the access control device can be configured to communicate according to any suitable communications protocol with one or more different systems or devices either remote or local to the access control device, such as one or more client devices 120 and / or servers / controllers. In some cases, the communication module of the access control device is configured to perform the disclosed authentication protocol securely.

[0049] In some cases, the communication module uses a same wired or wireless link between the access control device and the server / controller for all the communication modes. In some cases, the communication module uses one wired or wireless link between the access control device and the server / controller to communicate access control information and uses a different wired or wireless link to communicate or receive configuration information updates from the server / controller over the Internet Protocol (IP) communication mode.

[0050] The network interface device of the access control device (any functionality / configuration described in association with the access control device is similarly applicable to the PAC device 110 and vice versa) includes hardware to facilitate communications with other devices, such as a one or more client devices 120 and / or server / controller (e.g., a PACS server), over a communication network, such as network 130, utilizing any one of a number of transfer protocols (e.g., frame relay, IP, transmission control protocol (TCP), user datagram protocol (UDP), hypertext transfer protocol (HTTP), etc.). Example communication networks can include a local areanetwork (LAN), a wide area network (WAN), a packet data network (e.g., the Internet), mobile telephone networks (e.g., cellular networks), Plain Old Telephone (POTS) networks, wireless data networks (e.g., IEEE 502.11 family of standards known as WiFi, IEEE 502.16 family of standards known as WiMax), IEEE 502.15.4 family of standards, and peer-to-peer (P2P) networks, among others. In some examples, network interface device can include an Ethernet port or other physical jack, a Wi-Fi card, a Network Interface Card (NIC), a cellular interface (e.g., antenna, filters, and associated circuitry), or the like. In some examples, network interface device can include a plurality of antennas to wirelessly communicate using at least one of single-input multiple-output (SIMO), multiple-input multiple-output (MIMO), or multiple-input single-output (MISO) techniques.

[0051] A user interface of the access control device can include one or more input devices and / or display devices. Examples of suitable user input devices that can be included in the user interface include, without limitation, one or more buttons, a keyboard or keypad, a mouse, a touch-sensitive surface, a stylus, a camera, a microphone, and so forth. Examples of suitable user output devices that can be included in the user interface include, without limitation, one or more light emitting diodes (LEDs), an liquid crystal display (LCD) panel, a display screen, a touchscreen, one or more lights, a speaker, and so forth. It should be appreciated that the user interface can also include a combined user input and user output device, such as a touch-sensitive display or the like. Any reference to operations performed by the access control device apply to the PAC device 110, shown in FIG. 1.

[0052] The network 130 may include, or operate in conjunction with, an ad hoc network, an intranet, an extranet, a virtual private network (VPN), a LAN, a wireless network, a wireless LAN (WLAN), a WAN, a wireless WAN (WWAN), a metropolitan area network (MAN), BLE, UWB, the Internet, a portion of the Internet, a portion of the Public Switched Telephone Network (PSTN), a POTS network, a cellular telephone network, a wireless network, a Wi-Fi® network, another type of network, or a combination of two or more such networks. For example, a network or a portion of a network may include a wireless or cellular network and the coupling may be a CDMA connection, a GSM connection, or other type of cellular or wireless coupling. In this example, the coupling may implement any of a variety of types of data transfer technology, such as Single Carrier Radio Transmission Technology (IxRTT), Evolution-Data Optimized (EVDO) technology, General Packet Radio Service (GPRS) technology, Enhanced Data rates for GSM Evolution (EDGE) technology, third Generation Partnership Project (3 GPP) including 3G, fourth generation wireless (4G) networks, fifth generation wireless (5G) networks, Universal Mobile Telecommunications System (UMTS), High Speed Packet Access (HSPA), Worldwide Interoperability for Microwave Access (WiMAX), Long Term Evolution (LTE) standard, others defined by various standard setting organizations, other short range or long range protocols, or other data transfer technology.

[0053] In an example, as the client device 120 approaches the PAC device 110 (e.g., comes within range of a BLE communication protocol), the client device 120 transmits credentials of the client device 120 over the network 130. In one example, the client device 120 provides the credentials directly to the PAC device 110. In such cases, the PAC device 110 communicates the credentials with the server / controller. The server / controller (not shown) includes an authorization system (not shown). The server / controller, client device 120, and / or the PAC device 110 can further include elements described with respect to FIG. 4 and FIG. 5, such as a processor and memory, having instructions stored thereon, that when executed by the processor, causes the processor to control the functions of the server / controller, client device 120, and / or the PAC device 110. The server / controller can be implemented on a centralized set of servers of a cloud-based system.

[0054] The server / controller searches a list of credentials stored in the authorization system to determine whether the received credentials match credentials from the list of authorized credentials for accessing a secure asset or resource (e.g., door or secure area) protected by the PAC device 110. In response to determining that the received credentials are authorized to access the PAC device 110, the server / controller instructs the PAC device 110 to perform an operation granting access for the client device 120 (e.g., instructing the PAC device 110 to unlock a lock of a door).

[0055] In some examples, prior to granting access to the resource protected by the PAC device 110, the PAC device 110 and / or the server / controller, and / or the client device 120 can perform operations to verify that the client device 120 is within a specified distance of the client device 120. This can be performed before, substantially simultaneous with, and / or after verifying that the credentials received from the client device 120 are authorized to access the asset or resource.

[0056] Specifically, the client device 120 can scan BLE signals (or other suitable signals) transmitted by the PAC device 110 over the network 130. The client device 120 can determine whether the BLE signals of a particular PAC device 110 satisfy a proximity threshold or criterion. In response, the client device 120 establishes a communication session (via BLE and / or WiFi) with the PAC device 110. The PAC device 110 can, either before verifying proximity or after verifying proximity, request additional information from the client device 120. Specifically, the PAC device 110 can request a credential to be provided by the client device 120.

[0057] FIG. 2 illustrates a diagram 202 of an environment for accessing a secure resource, in accordance with some examples. The diagram 202 features a mobile user device 212, which interacts with both previous transaction data 208 and access control device configuration data 214. This setup ensures that the mobile user device 212 can intelligently manage access control by evaluating past transactions and current configurations.

[0058] The mobile user device 212 communicates with a first access control device 204 and a second access control device 206. The first access control device 204 and second access control device 206 can be configured as entrance and exit readers, respectively, as defined by the access control device configuration data 214. The system uses Bluetooth Low Energy (BLE) signals to detect the presence of these devices (e.g., the first access control device 204 and the second access control device 206), allowing the mobile user device 212 to selectively establish communication sessions based on previous transactions stored in the previous transaction data 208.

[0059] A mobile admin device 210 plays an important role in configuring the access control devices, such as the first access control device 204 and the second access control device 206. The mobile admin device 210 uploads configuration data to the cloud (e.g., a set of servers accessible over an IP connection), ensuring that all user devices receive accurate and up-to-date information about the access control devices in a certain environment. This centralized management simplifies the setup and maintenance of the system, reducing administrative burdens.

[0060] The system's anti-passback functionality is highlighted by its ability to prevent unauthorized re-entry. If the mobile user device 212 detects that the last transaction was an entry, it prioritizes connecting to the second access control device 206, designated as the exit reader. This prevents the user from re-entering through the first access controldevice 204 without first exiting, thereby enforcing anti-passback rules. Similarly, if the mobile user device 212 detects that the last transaction was an exit, it prioritizes connecting to the first access control device 204, designated as the entrance reader. This prevents the user from re-exiting through the second access control device 206 without first entering, thereby enforcing anti-passback rules.

[0061] In some examples, the mobile admin device 210 can communicate with the first access control device 204. The mobile admin device 210 can store configuration information for the first access control device 204 that describes the configuration of the first access control device 204 as the entrance or entry reader. The first access control device 204 can broadcast this information to nearby devices, such as mobile user device 212 in order for the mobile user device 212 to determine which type of access control device is within a threshold proximity to the mobile user device 212. In some cases, the information can be stored on the access control device configuration data 214, such as in association with an IP address or other unique identifier that is broadcast by the first access control device 204. The mobile user device 212 can download the configuration information indicating that the first access control device 204 is designated as an entry reader by matching a unique identifier or IP address of the first access control device 204 with the information stored on the access control device configuration data 214.

[0062] Similarly, the mobile admin device 210 can communicate with the second access control device 206. The mobile admin device 210 can store configuration information for the second access control device 206 that describes the configuration of the second access control device 206 as the exit reader. The second access control device 206 can broadcast this information to nearby devices, such as mobile user device 212 in order for the mobile user device 212 to determine which type of access control device is within a threshold proximity to the mobile user device 212. In some cases, the information can be stored on the access control device configuration data 214, such as in association with an IP address or other unique identifier (or MAC address) that is broadcast by the second access control device 206. The mobile user device 212 can download the configuration information indicating that the second access control device 206 is designated as an exit reader by matching a unique identifier or IP address (or MAC address) of the second access control device 206 with the information stored on the access control device configuration data 214.

[0063] In some cases, the first access control device 204 and the second access control device 206 are each designated as entrance readers. The access control device configuration data 214 can receive input that identifies one of the many entrance readers as a favorite or preferred reader. In such cases, the mobile user device 212 can prioritize communicating with one of the first access control device 204 and the second access control device 206 that is designated as the favorite or preferred reader. This way, if the user has a specific path associated with a particular access control device which is in the presence of other access control devices that are within a threshold proximity to each other, the mobile user device 212 can select the preferred access control device for transmitting the credential to gain access. For example, multiple access control devices can be associated with different entrance lanes. The mobile user device 212 can detect multiple signals transmitted by each of the multiple access control devices. The mobile user device 212 can obtain the access control device configuration data 214 to identify different lanes associated with each of the multiple access control devices. The mobile user device 212 can also obtain previous transaction data 208 to determine that the preferred access control device is in a second lane of the multiple lanes. In response, the mobile user device 212 automatically establishes a communication session with the access control device associated with the second lane and prevents establishing a communication session with the other access control devices. The mobile user device 212 can then send a credential to the access control device associated with the second lane to gain access to the resource protected by the access control device associated with the second lane. In some cases, the previous transaction data 208 can automatically store the indication of which access control device is preferred in response to determining that the user successfully gained access to the resource protected by the access control device associated with the second lane on one or more prior occasions or a threshold number of occasions.

[0064] The mobile admin device 210 can store a set of anti-passback rules on the access control device configuration data 214. The mobile user device 212 can download these rules to make a determination as to which access control device to communicate with for exchanging credentials. For example, the anti-passback rules can indicate that the mobile user device 212 is allowed to communicate with the second access control device 206 only after exchanging credentials and gaining access to a protected resource associated with the first access control device 204. For example, the rules can specify that themobile user device 212 has to first enter or gain access through an entrance reader before communicating and gaining access through an exit reader. As another example, the mobile admin device 210 can specify a rule that communication with the first access control device 204 is disallowed if access was granted by the first access control device 204 within a threshold period of time. The rules specified by the mobile admin device 210 can be stored as part of the access control device configuration data 214 on a cloudbased server. The access control device configuration data 214 can include a first portion of data that designates the type of device (e.g., entry device, exit device, device in a particular lane, and so forth) of the first access control device 204 and can include a second portion of data that designates the type of device (e.g., entry device, exit device, device in a particular lane, and so forth) of the second access control device 206.

[0065] The mobile user device 212 can approach a barrier in which the first access control device 204 and the second access control device 206 are placed. The mobile user device 212 can detect signals transmitted by the first access control device 204 and the second access control device 206. The mobile user device 212 can access the previous transaction data 208 and the access control device configuration data 214, from local storage and / or from a centralized server, such as the cloud-based server. The mobile user device 212 can then determine, from the previous transaction data 208, the last transaction that the mobile user device 212 performed in a particular location. For example, the mobile user device 212 can search the previous transaction data 208 for a list of transactions performed within a threshold distance of a current location of the mobile user device 212. The mobile user device 212 can then search timestamps of the list of transactions and select the transaction having the most recent timestamp (the timestamp closest in time to the current time) as the last transaction. The mobile user device 212 can then determine what type of transaction was the last transaction.

[0066] For example, the mobile user device 212 can determine that the last transaction was an exit. In such cases, the mobile user device 212 searches the list of anti-passback rules stored in the access control device configuration data 214 to determine what type of access control device the mobile user device 212 is authorized to communicate with based on that last transaction. In some cases, the rules can specify that the mobile user device 212 is authorized to communicate with an entry access control device or entry reader when the last transaction is an exit. In such circumstances, the mobile user device 212 can determine based on the signals transmitted by the first access control device 204and the second access control device 206 which one of the two devices is the entry reader. The mobile user device 212 can determine that the first access control device 204 is designated as the entry reader using the access control device configuration data 214. In such cases, the mobile user device 212 establishes a communication session with the first access control device 204 instead of the second access control device 206 even though both devices are within a communication range and proximity to the mobile user device 212. The mobile user device 212 can the send a credential to the first access control device 204 to gain access to the resource protected by the first access control device 204.

[0067] As another example, the mobile user device 212 can determine that the last transaction was an entrance or entry. In such cases, the mobile user device 212 searches the list of anti-passback rules stored in the access control device configuration data 214 to determine what type of access control device the mobile user device 212 is authorized to communicate with based on that last transaction. In some cases, the rules can specify that the mobile user device 212 is authorized to communicate with an exit access control device or exit reader when the last transaction is an entry. In such circumstances, the mobile user device 212 can determine based on the signals transmitted by the first access control device 204 and the second access control device 206 which one of the two devices is the exit reader. The mobile user device 212 can determine that the second access control device 206 is designated as the exit reader using the access control device configuration data 214. In such cases, the mobile user device 212 establishes a communication session with the second access control device 206 instead of the first access control device 204 even though both devices are within a communication range and proximity to the mobile user device 212. The mobile user device 212 can then send a credential to the second access control device 206 to gain access to the resource protected by the second access control device 206.

[0068] In this way, an application on the mobile user device 212 can implement a logic to avoid connecting with the same reader multiple times without intervening access at a different reader. In some cases, these operations are performed if the mobile user device 212 receives input that enables the automated access control device selection mechanism. Once activated, if a mobile user device 212 connects with the first access control device 204, the application can prevent subsequent connections to first access control device 204 until the mobile user device 212 connects with another reader (e.g.,the second access control device 206). This logic can be managed using the MAC addresses of the readers or other unique identifiers, discussed above.

[0069] In some examples, the application can allow users to define a custom delay time between transactions. This delay acts as a buffer to prevent repeated connection attempts within a short period, reducing the likelihood of APB violations and BLE fluctuation issues. Users can set their preferred delay time, which can be enforced by the application on the mobile user device 212 before allowing another connection to the same access control device.

[0070] In the context of FIG. 2, the workflow begins with the Admin Configuration phase. The mobile admin device 210 is used to log into the admin app, where the administrator configures the reader settings, such as naming the first access control device 204 as "Main Entrance" and the second access control device 206 as "Emergency Exit." These configurations are then uploaded to the cloud as the access control device configuration data 214, making them accessible to all associated mobile access applications for real-time updates.

[0071] During user onboarding, a new user downloads the mobile access application on their mobile user device 212. The application retrieves the access control device configuration data 214 from the cloud, which includes the configured reader names and statuses. This data is stored locally on the mobile user device 212 for quick access during user transactions. In the user operation phase, the user initiates a transaction, such as by tapping the mobile user device 212 on a reader. The mobile user device 212 scans for nearby readers and identifies the strongest signal, displaying the detected readers and their statuses for clarity on a graphical user interface of the mobile user device 212. The graphical user interface can specify the names retrieved from the access control device configuration data 214 for each reader that transmitted a signal received by the mobile user device 212. The signals can include the MAC address or unique identifier of each reader that is matched against the MAC address or unique identifier stored in the access control device configuration data 214 to determine the name of the reader assigned by the mobile admin device 210. The signal assessment step involves checking the previous transaction data 208 to determine the user's last transaction. If the last transaction was an entry, the mobile user device 212 prioritizes connecting to the entry reader.

[0072] Finally, in the connection decision phase, the mobile user device 212 connects to the appropriate reader based on the last transaction. If the last transaction was anentry, it connects to the entry reader; if it was an exit, it connects to the exit reader. If the app detects an attempt to use the exit reader after an entry transaction, it displays an anti- passback violation error, ensuring proper access control. The mobile access-based anti- passback system introduces a sophisticated approach to access control, enhancing both security and user experience. By intelligently managing reader connections and utilizing cloud data, the system effectively mitigates anti-passback violations while offering a user-friendly interface.

[0073] In the office building access scenario, employees use their mobile user device 212 to interact with multiple entry and exit points configured by the mobile admin device 210. When an employee attempts to exit but accidentally connects to the first access control device 204 due to a strong signal, the system checks the previous transaction data 208. It identifies the last action as an entry and prevents the exit transaction, notifying the user of the error, thus maintaining proper access control.

[0074] For event venue management, attendees use their mobile user devices 212 to access entry and exit points. If a patron tries to exit but connects to the entry reader, the system retrieves the last entry transaction from the previous transaction data 208. It ensures the connection to the second access control device 206, the appropriate exit reader, thereby avoiding a violation and ensuring smooth access control.

[0075] In the healthcare facility security example, staff members use mobile user devices 212 to enter secure areas. If a staff member attempts to exit while another reader has a stronger signal, the system confirms the last transaction was an entry into the secure area. It restricts the exit attempt by referencing the previous transaction data 208, maintaining the integrity of the access control system and ensuring secure operations within the facility.

[0076] In a corridor or hallway reader deployment scenario, FIG. 2 illustrates how the system manages access control in a long hallway setup with entry and exit readers at different access points. The mobile user device 212 interacts with both the first access control device 204 and the second access control device 206, which are configured by the mobile admin device 210. The access control device configuration data 214 ensures that the mobile device has up-to-date information on reader statuses.

[0077] Challenges arise when users are positioned near both readers, potentially triggering conflicting signals. The mobile user device 212 uses signal filtering and historical data from the previous transaction data 208 to address this. The mobile userdevice 212 filters out strong signals that do not match the user’s last transaction. For instance, if a user entered through one side of the hallway, the mobile user device 212 will connect to the exit reader upon attempting to leave, ignoring stronger signals from the entry reader.

[0078] In the gate barrier reader deployment scenario, FIG. 2 demonstrates how the system manages access control in parking lots or restricted areas where entry and exit readers are positioned close together. The mobile user device 212 interacts with the first access control device 204 and the second access control device 206, configured by the mobile admin device 210. The access control device configuration data 214 provides the necessary reader information to the mobile user device 212. Challenges occur when vehicles trigger strong signals from both readers due to their proximity. The mobile user device 212 uses transaction history from the previous transaction data 208 to determine the correct reader connection. If a vehicle previously entered the parking lot, the mobile user device 212 prioritizes connecting to the exit reader upon leaving, ensuring accurate access control.

[0079] In a company parking lot example, an employee enters the lot in the morning, and the mobile user device 212 tracks the vehicle’s entry. When the employee leaves at the end of the day, the mobile user device 212 ensures the connection to the exit reader, despite any nearby signals from the entry reader. This process maintains compliance with anti-passback rules and ensures efficient access management.

[0080] The mobile access-based anti-passback system, when deployed across different reader setups (e.g., turnstiles, glass doors, hallways, and gate barriers), ensures seamless, secure user experiences. By prioritizing reader connections based on the last user transaction instead of simply signal strength, the system eliminates the risk of anti- passback violations. Regardless of deployment model, this approach enhances both security and user convenience, making it ideal for various environments.

[0081] FIG. 3 illustrates a routine 300 (e.g., method or process) in accordance with some examples. The operations discussed in connection with FIG. 3 can be performed sequentially, in parallel, and in any suitable order. The operations discussed in FIG. 3 can be performed by the access control system 100.

[0082] In operation 302, the client device 120 accesses data describing configuration of a plurality of access control devices (e.g., PAC device 110), as discussed above.

[0083] In operation 304, the client device 120 detects a signal associated with a first access control device of the plurality of access control devices, as discussed above.

[0084] In operation 306, the client device 120 determines one or more previous transactions that the mobile device performed with one or more of the plurality of access control devices, as discussed above.

[0085] In operation 308, the client device 120 selectively establishes a communication session with the first access control device based on the data describing the configuration of the plurality of access control devices and the one or more previous transactions that the mobile device performed with one or more of the plurality of access control devices, as discussed above.

[0086] FIG. 4 is a block diagram illustrating an example of a software architecture 402 that may be installed on a machine, according to some examples. FIG. 4 is merely a nonlimiting example of a software architecture, and it will be appreciated that many other architectures may be implemented to facilitate the functionality described herein. The software architecture 402 may be executing on hardware such as a machine 500 of FIG.5 that includes, among other things, processors 510, memory 504, and input / output (I / O) components 542. A representative hardware layer 444 is illustrated and can represent, for example, the machine 500 of FIG. 5. The representative hardware layer 444 comprises one or more processing units 446 having associated executable instructions 448. The executable instructions 448 represent the executable instructions of the software architecture 402. The hardware layer 444 also includes memory 504, which also have the executable instructions 448. The hardware layer 444 may also comprise other hardware 452, which represents any other hardware of the hardware layer 444, such as the other hardware illustrated as part of the machine 500.

[0087] The instructions 448 may be transmitted or received over the network using a transmission medium via a network interface device (e.g., a network interface component included in the communication components 540) and utilizing any one of a number of well-known transfer protocols (e.g., hypertext transfer protocol (HTTP)). Similarly, the instructions 448 may be transmitted or received using a transmission medium via the coupling (e.g., a peer-to-peer coupling) to the devices. The terms “transmission medium” and “signal medium” mean the same thing and may be used interchangeably in this disclosure. The terms “transmission medium” and “signal medium” shall be taken to include any intangible medium that is capable of storing,encoding, or carrying the instructions 448 for execution by the machine 500, and include digital or analog communications signals or other intangible media to facilitate communication of such software. Hence, the terms “transmission medium” and “signal medium” shall be taken to include any form of modulated data signal, carrier wave, and so forth. The term “modulated data signal” means a signal that has one or more of its characteristics set or changed in such a manner as to encode information in the signal.

[0088] The terms “machine-readable medium,” “computer-readable medium,” and “device-readable medium” mean the same thing and may be used interchangeably in this disclosure. The terms are defined to include both machine-storage media and transmission media. Thus, the terms include both storage devices / media and carrier waves / modulated data signals.

[0089] As used herein, the terms “machine-storage medium,” “device-storage medium,” and “computer-storage medium” mean the same thing and may be used interchangeably in this disclosure. The terms refer to a single or multiple storage devices and / or media (e.g., a centralized or distributed database, and / or associated caches and servers) that store executable instructions and / or data. The terms shall accordingly be taken to include, but not be limited to, solid-state memories, and optical and magnetic media, including memory internal or external to processors. Specific examples of machinestorage media, computer-storage media, and / or device-storage media include nonvolatile memory, including by way of example semiconductor memory devices, e.g., erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), field-programmable gate arrays (FPGAs), and flash memory devices; magnetic disks such as internal hard disks and removable disks; magneto-optical disks; and CD-ROM and DVD-ROM disks. The terms “machinestorage medium,” “computer-storage medium,” and “device-storage medium” are non- transitory computer-readable media and specifically exclude carrier waves, modulated data signals, and other such media, at least some of which are covered under the term “signal medium.”

[0090] In the example architecture of FIG. 4, the software architecture 402 may be conceptualized as a stack of layers, where each layer provides particular functionality. For example, the software architecture 402 may include layers such as an operating system 436, libraries 428, framework / middl eware 422, applications 416, and a presentation layer 414. Operationally, the applications 416 or other components within the layers may invokeAPI calls API calls 424 through the software stack and receive a response, returned values, and so forth (illustrated as messages 426) in response to the API calls 424. The layers illustrated are representative in nature, and not all software architectures have all layers. For example, some mobile or special-purpose operating systems may not provide a framework / middleware 422 layer, while others may provide such a layer. Other software architectures may include additional or different layers.

[0091] The operating system 436 may manage hardware resources and provide common services. The operating system 436 may include, for example, a kernel 438, services 440, and drivers 442. The kernel 438 may act as an abstraction layer between the hardware and the other software layers. For example, the kernel 438 may be responsible for memory management, processor management (e.g., scheduling), component management, networking, security settings, and so on. The services 440 may provide other common services for the other software layers. The drivers 442 may be responsible for controlling or interfacing with the underlying hardware. For instance, the drivers 442 may include display drivers, camera drivers, Bluetooth® drivers, flash memory drivers, serial communication drivers (e.g., Universal Serial Bus (USB) drivers), Wi-Fi® drivers, audio drivers, power management drivers, and so forth depending on the hardware configuration.

[0092] The libraries 428 may provide a common infrastructure that may be utilized by the applications 416 and / or other components and / or layers. The libraries 428 typically provide functionality that allows other software modules to perform tasks in an easier fashion than by interfacing directly with the underlying operating system 436 functionality (e.g., kernel 438, services 440, or drivers 442). The libraries 428 may include system libraries 430 (e.g., C standard library) that may provide functions such as memory allocation functions, string manipulation functions, mathematic functions, and the like. In addition, the libraries 428 may include API libraries 432 such as media libraries (e.g., libraries to support presentation and manipulation of various media formats such as MPEG4, H.264, MP3, AAC, AMR, JPG, and PNG), graphics libraries (e.g., an OpenGL framework that may be used to render 2D and 3D graphic content on a display), database libraries (e.g., SQLite that may provide various relational database functions), web libraries (e.g., WebKit that may provide web browsing functionality), and the like. The libraries 428 may also include a wide variety of other libraries 434 to provide many other APIs to the applications 416 and other software components / modules.

[0093] The frameworks / middleware 422 (also sometimes referred to as middleware) may provide a higher-level common infrastructure that may be utilized by the applications 416 or other software components / modules. For example, the frameworks / middleware 422 may provide various graphical user interface functions, high-level resource management, high-level location services, and so forth. The frameworks / middleware 422 may provide a broad spectrum of other APIs that may be utilized by the applications 416 and / or other software components / modules, some of which may be specific to a particular operating system or platform.

[0094] The applications 416 include built-in applications 418 and / or third-party applications 420. Examples of representative built-in applications 418 may include, but are not limited to, a home application, a contacts application, a browser application, a book reader application, a location application, a media application, a messaging application, or a game application.

[0095] The third-party applications 420 may include any of the built-in applications 418, as well as a broad assortment of other applications. In a specific example, the third-party applications 420 (e.g., an application developed using the Android™ or iOS™ software development kit (SDK) by an entity other than the vendor of the particular platform) may be mobile software running on a mobile operating system such as iOS™, Android™, or other mobile operating systems. In this example, the third-party applications 420 may invoke the API calls 424 provided by the mobile operating system such as the operating system 436 to facilitate functionality described herein.

[0096] The applications 416 may utilize built-in operating system functions (e.g., kernel 438, services 440, or drivers 442), libraries (e.g., system libraries 430, API libraries 432, and other libraries 434), or framework / middleware 422 to create user interfaces to interact with users of the system. Alternatively, or additionally, in some systems, interactions with a user may occur through a presentation layer, such as the presentation layer 414. In these systems, the application / module “logic” can be separated from the aspects of the application / module that interact with the user.

[0097] Some software architectures utilize virtual machines. In the example of FIG. 4, this is illustrated by a virtual machine 404. The virtual machine 404 creates a software environment where applications / modules can execute as if they were executing on a hardware machine (e.g., the machine 500 of FIG. 5). The virtual machine 404 is hosted by a host operating system (e.g., the operating system 436) and typically, although notalways, has a virtual machine monitor, which manages the operation of the virtual machine 404 as well as the interface with the host operating system (e.g., the operating system 436). A software architecture executes within the virtual machine 404, such as an operating system 412, libraries 410, frameworks 408, applications 416, or a presentation layer 406. These layers of software architecture executing within the virtual machine 404 can be the same as corresponding layers previously described or may be different.

[0098] FIG. 5 is a diagrammatic representation of the machine 500 within which instructions 508 (e.g., software, a program, an application, an applet, an app, or other executable code) for causing the machine 500 to perform any one or more of the methodologies discussed herein may be executed. For example, the instructions 508 may cause the machine 500 to execute any one or more of the methods described herein. The instructions 508 transform the general, non-programmed machine 500 into a particular machine 500 programmed to carry out the described and illustrated functions in the manner described. The machine 500 may operate as a standalone device or may be coupled (e.g., networked) to other machines. In a networked deployment, the machine 500 may operate in the capacity of a server machine or a client machine in a server-client network environment, or as a peer machine in a peer-to-peer (or distributed) network environment. The machine 500 may comprise, but not be limited to, a server computer, a client computer, a personal computer (PC), a tablet computer, a laptop computer, a netbook, a set-top box (STB), a PDA, an entertainment media system, a cellular telephone, a smart phone, a mobile device, a wearable device (e.g., a smart watch), a smart home device (e.g., a smart appliance), other smart devices, a web appliance, a network router, a network switch, a network bridge, or any machine capable of executing the instructions 508, sequentially or otherwise, that specify actions to be taken by the machine 500. Further, while only a single machine 500 is illustrated, the term “machine” shall also be taken to include a collection of machines that individually or jointly execute the instructions 508 to perform any one or more of the methodologies discussed herein.

[0099] The machine 500 may include processors 502, memory 504, and I / O components 542, which may be configured to communicate with each other via a bus 544. In an example, the processors 502 (e.g., a Central Processing Unit (CPU), a Reduced Instruction Set Computing (RISC) processor, a Complex Instruction Set Computing (CISC) processor, a Graphics Processing Unit (GPU), a Digital Signal Processor (DSP), an ASIC, a Radio-Frequency Integrated Circuit (RFIC), anotherprocessor, or any suitable combination thereof) may include, for example, a processor 506 and a processor 510 that execute the instructions 508. The term “processor” is intended to include multi-core processors that may comprise two or more independent processors (sometimes referred to as “cores”) that may execute instructions contemporaneously. Although FIG. 5 shows multiple processors 502, the machine 500 may include a single processor with a single core, a single processor with multiple cores (e.g., a multi-core processor), multiple processors with a single core, multiple processors with multiples cores, or any combination thereof.

[0100] The memory 504 includes a main memory 512, a static memory 514, and a storage unit 516, both accessible to the processors 502 via the bus 544. The main memory 504, the static memory 514, and storage unit 516 store the instructions 508 embodying any one or more of the methodologies or functions described herein. The instructions 508 may also reside, completely or partially, within the main memory 512, within the static memory 514, within machine-readable medium 518 within the storage unit 516, within at least one of the processors 502 (e.g., within the processor’s cache memory), or any suitable combination thereof, during execution thereof by the machine 500.

[0101] The I / O components 542 may include a wide variety of components to receive input, provide output, produce output, transmit information, exchange information, capture measurements, and so on. The specific I / O components 542 that are included in a particular machine will depend on the type of machine. For example, portable machines such as mobile phones may include a touch input device or other such input mechanisms, while a headless server machine will likely not include such a touch input device. It will be appreciated that the I / O components 542 may include many other components that are not shown in FIG. 5. In various examples, the I / O components 542 may include output components 528 and input components 530. The output components 528 may include visual components (e.g., a display such as a plasma display panel (PDP), a light emitting diode (LED) display, a liquid crystal display (LCD), a projector, or a cathode ray tube (CRT)), acoustic components (e.g., speakers), haptic components (e.g., a vibratory motor, resistance mechanisms), other signal generators, and so forth. The input components 530 may include alphanumeric input components (e.g., a keyboard, a touch screen configured to receive alphanumeric input, a photo-optical keyboard, or other alphanumeric input components), point-based input components (e.g., a mouse, atouchpad, a trackball, a joystick, a motion sensor, or another pointing instrument), tactile input components (e.g., a physical button, a touch screen that provides location and / or force of touches or touch gestures, or other tactile input components), audio input components (e.g., a microphone), and the like.

[0102] In further examples, the I / O components 542 may include biometric components 532, motion components 534, environmental components 536, or position components 538, among a wide array of other components. For example, the biometric components 532 include components to detect expressions (e.g., hand expressions, facial expressions, vocal expressions, body gestures, or eye tracking), measure biosignals (e.g., blood pressure, heart rate, body temperature, perspiration, or brain waves), identify a person (e.g., voice identification, retinal identification, facial identification, fingerprint identification, or electroencephalogram-based identification), and the like. The motion components 534 include acceleration sensor components (e.g., accelerometer), gravitation sensor components, rotation sensor components (e.g., gyroscope), and so forth. The environmental components 536 include, for example, illumination sensor components (e.g., photometer), temperature sensor components (e.g., one or more thermometers that detect ambient temperature), humidity sensor components, pressure sensor components (e.g., barometer), acoustic sensor components (e.g., one or more microphones that detect background noise), proximity sensor components (e.g., infrared sensors that detect nearby objects), gas sensors (e.g., gas detection sensors to detection concentrations of hazardous gases for safety or to measure pollutants in the atmosphere), or other components that may provide indications, measurements, or signals corresponding to a surrounding physical environment. The position components 538 include location sensor components (e.g., a GPS receiver component), altitude sensor components (e.g., altimeters or barometers that detect air pressure from which altitude may be derived), orientation sensor components (e.g., magnetometers), and the like.

[0103] Communication may be implemented using a wide variety of technologies. The I / O components 542 further include communication components 540 operable to couple the machine 500 to a network 520 or devices 522 via a coupling 524 and a coupling 526, respectively. For example, the communication components 540 may include a network interface component or another suitable device to interface with the network 520. In further examples, the communication components 540 may include wiredcommunication components, wireless communication components, cellular communication components, Near Field Communication (NFC) components, Bluetooth® components (e.g., Bluetooth® Low Energy), Wi-Fi® components, and other communication components to provide communication via other modalities. The devices 522 may be another machine or any of a wide variety of peripheral devices (e.g., a peripheral device coupled via a USB).

[0104] Moreover, the communication components 540 may detect identifiers or include components operable to detect identifiers. For example, the communication components 540 may include Radio Frequency Identification (RFID) tag reader components, NFC smart tag detection components, optical reader components (e.g., an optical sensor to detect one-dimensional bar codes such as Universal Product Code (UPC) bar code, multi-dimensional bar codes such as Quick Response (QR) code, Aztec code, Data Matrix, Dataglyph, MaxiCode, PDF417, Ultra Code, UCC RSS-2D bar code, and other optical codes), or acoustic detection components (e.g., microphones to identify tagged audio signals). In addition, a variety of information may be derived via the communication components 540, such as location via Internet Protocol (IP) geolocation, location via Wi-Fi® signal triangulation, location via detecting an NFC beacon signal that may indicate a particular location, and so forth.

[0105] The various memories (e.g., memory 504, main memory 512, static memory 514, and / or memory of the processors 502) and / or storage unit 516 may store one or more sets of instructions and data structures (e.g., software) embodying or used by any one or more of the methodologies or functions described herein. These instructions (e.g., the instructions 508), when executed by processors 502, cause various operations to implement the disclosed examples.

[0106] The instructions 508 may be transmitted or received over the network 520, using a transmission medium, via a network interface device (e.g., a network interface component included in the communication components 540) and using any one of a number of well-known transfer protocols (e.g., hypertext transfer protocol (HTTP)). Similarly, the instructions 508 may be transmitted or received using a transmission medium via the coupling 526 (e.g., a peer-to-peer coupling) to the devices 522.

[0107] Although examples have been described, it will be evident that various modifications and changes may be made to these examples without departing from the broader scope of the present disclosure. Accordingly, the specification and drawings areto be regarded in an illustrative rather than a restrictive sense. The accompanying drawings that form a part hereof, show by way of illustration, and not of limitation, specific examples in which the subject matter may be practiced. The examples illustrated are described in sufficient detail to enable those skilled in the art to practice the teachings disclosed herein. Other examples may be utilized and derived therefrom, such that structural and logical substitutions and changes may be made without departing from the scope of this disclosure. This Detailed Description, therefore, is not to be taken in a limiting sense, and the scope of various examples is defined only by the appended claims, along with the full range of equivalents to which such claims are entitled.

[0108] Such examples of the inventive subject matter may be referred to herein, individually and / or collectively, by the term "invention" merely for convenience and without intending to voluntarily limit the scope of this application to any single invention or inventive concept if more than one is in fact disclosed. Thus, although specific examples have been illustrated and described herein, it should be appreciated that any arrangement calculated to achieve the same purpose may be substituted for the specific examples shown. This disclosure is intended to cover any and all adaptations or variations of various examples. Combinations of the above examples, and other examples not specifically described herein, will be apparent to those of skill in the art upon reviewing the above description.

[0109] The Abstract of the Disclosure is provided to allow the reader to quickly ascertain the nature of the technical disclosure. It is submitted with the understanding that it will not be used to interpret or limit the scope or meaning of the claims. In addition, in the foregoing Detailed Description, it can be seen that various features are grouped together in a single example for the purpose of streamlining the disclosure. This method of disclosure is not to be interpreted as reflecting an intention that the claimed examples require more features than are expressly recited in each claim. Rather, as the following claims reflect, inventive subject matter lies in less than all features of a single disclosed example. Thus the following claims are hereby incorporated into the Detailed Description, with each claim standing on its own as a separate example.

[0110] In view of the disclosure above, various examples are set forth below. It should be noted that one or more features of an example, taken in isolation or combination, should be considered within the disclosure of this application.

[0111] Example 1. A system comprising: one or more hardware processors; and at least one machine-storage medium for storing instructions that, when executed by the one or more hardware processors, cause the one or more hardware processors to perform operations comprising: accessing, by a mobile device, data describing configuration of a plurality of access control devices; detecting a signal associated with a first access control device of the plurality of access control devices; determining one or more previous transactions that the mobile device performed with one or more of the plurality of access control devices; and selectively establishing a communication session with the first access control device based on the data describing the configuration of the plurality of access control devices and the one or more previous transactions that the mobile device performed with one or more of the plurality of access control devices.

[0112] Example 2. The system of Example 1, wherein the operations comprise: receiving, by the first access control device from an administrator application, a first portion of the data defining the first access control device as an entrance reader; and receiving, by a first access control device of the plurality of access control devices from the administrator application, a second portion of the data defining the second access control device as an exit reader.

[0113] Example 3. The system of Example 2, wherein the operations comprise: storing the first portion of the data and the second portion of the data on a server.

[0114] Example 4. The system of Example 3, wherein the operations comprise: downloading, by the mobile device, the first portion of the data and the second portion of the data from the server.

[0115] Example 5. The system of any one of Examples 1-4, wherein the signal comprises a Bluetooth Low Energy (BLE) signal transmitted by the first access control device.

[0116] Example 6. The system of any one of Examples 1-5, wherein the operations comprise: determining that the first access control device is an entrance reader based on the accessed data; determining whether a last transaction of the one or more previous transactions comprises an entrance or an exit; and selectively establishing the communication session with the first access control device based on determining whether the last transaction of the one or more previous transactions comprises the entrance or the exit.

[0117] Example 7. The system of Example 6, wherein the operations comprise: determining that the last transaction comprises the entrance; and preventing the mobile device from establishing the communication session with the first access control device in response to determining that the last transaction comprises the entrance and based on determining that the first access control device is the entrance reader.

[0118] Example 8. The system of Example 7, wherein the operations comprise: searching for a signal transmitted by a second access control device; detecting the signal transmitted by a second access control device; determining that the second access control device is an exit reader based on the accessed data; and establishing the communication session with the second access control device in response to determining that the last transaction comprises the exit and based on determining that the second access control device is the exit reader.

[0119] Example 9. The system of Example 8, wherein the operations comprise: transmitting a credential to the second access control device from the mobile device to obtain access to a resource protected by the second access control device.

[0120] Example 10. The system of Example 9, wherein the operations comprise: determining that access to the resource has been granted by the second access control device; and updating the last transaction of the one or more previous transactions to specify that the last transaction comprises the exit.

[0121] Example 11. The system of Example 10, wherein the last transaction is stored using the accessed data associated with the second access control device.

[0122] Example 12. The system of any one of Examples 7-11, wherein the operations comprise: determining that the first access control device is an exit reader based on the accessed data; determining whether a last transaction of the one or more previous transactions comprises an entrance or an exit; and selectively establishing the communication session with the first access control device based on determining whether the last transaction of the one or more previous transactions comprises the entrance or the exit.

[0123] Example 13. The system of Example 12, wherein the operations comprise: determining that the last transaction comprises the exit; and preventing the mobile device from establishing the communication session with the first access control device in response to determining that the last transaction comprises the exit and based on determining that the first access control device is the exit reader.

[0124] Example 14. The system of any one of Examples 1-13, wherein the operations comprise: detecting a plurality of signals associated with the plurality of access control devices, the plurality of signals comprising the signal associated with the first access control device; in response to detecting the plurality of signals, determining a last transaction performed by the mobile device of the one or more previous transactions; and selecting one of the plurality of access control devices with which to establish a communication session based on the data describing configuration of the plurality of access control devices and the last transaction.

[0125] Example 15. The system of Example 14, wherein the operations comprise: replacing the last transaction with a portion of the accessed data describing the selected one of the plurality of access control devices after determining that access has been granted to the mobile device by the selected one of the plurality of access control devices.

[0126] Example 16. The system of any one of Examples 14-15, wherein the operations comprise: determining that data describing the last transaction is different from the accessed data describing the one of the plurality of access control devices; and transmitting a credential to the selected one of the plurality of access control devices in response to determining that the data describing the last transaction is different from the accessed data describing the one of the plurality of access control devices.

[0127] Example 17. The system of any one of Examples 14-16, wherein the operations comprise: preventing establishing a communication session with an individual access control device of the plurality of access control devices in response to determining that data describing the last transaction matches the accessed data describing the individual access control device; and presenting a notification on the mobile device indicating an anti-passback violation comprising a message that identifies a correct access control device to use based on the last transaction.

[0128] Example 18. The system of any one of Examples 1-17, wherein the one or more previous transactions comprise a set of transactions performed within a threshold range of a current location of the mobile device, and wherein the mobile device presents identifiers of the plurality of access control devices based on the data for selection by a user to establish a communication session.

[0129] Example 19. A method comprising: accessing, by a mobile device, data describing configuration of a plurality of access control devices; detecting a signalassociated with a first access control device of the plurality of access control devices; determining one or more previous transactions that the mobile device performed with one or more of the plurality of access control devices; and selectively establishing a communication session with the first access control device based on the data describing the configuration of the plurality of access control devices and the one or more previous transactions that the mobile device performed with one or more of the plurality of access control devices.

[0130] Example 20. A machine-storage medium for storing instructions that, when executed by one or more hardware processors, cause the one or more hardware processors to perform operations comprising: accessing, by a mobile device, data describing configuration of a plurality of access control devices; detecting a signal associated with a first access control device of the plurality of access control devices; determining one or more previous transactions that the mobile device performed with one or more of the plurality of access control devices; and selectively establishing a communication session with the first access control device based on the data describing the configuration of the plurality of access control devices and the one or more previous transactions that the mobile device performed with one or more of the plurality of access control devices.

Claims

CLAIMSWhat is claimed is:

1. A system comprising: one or more hardware processors; and at least one machine-storage medium for storing instructions that, when executed by the one or more hardware processors, cause the one or more hardware processors to perform operations comprising: accessing, by a mobile device, data describing configuration of a plurality of access control devices; detecting a signal associated with a first access control device of the plurality of access control devices; determining one or more previous transactions that the mobile device performed with one or more of the plurality of access control devices; and selectively establishing a communication session with the first access control device based on the data describing the configuration of the plurality of access control devices and the one or more previous transactions that the mobile device performed with one or more of the plurality of access control devices.

2. The system of claim 1, wherein the operations comprise: receiving, by the first access control device from an administrator application, a first portion of the data defining the first access control device as an entrance reader; and receiving, by the first access control device of the plurality of access control devices from the administrator application, a second portion of the data defining the second access control device as an exit reader.

3. The system of claim 2, wherein the operations comprise: storing the first portion of the data and the second portion of the data on a server.

4. The system of claim 3, wherein the operations comprise: downloading, by the mobile device, the first portion of the data and the second portion of the data from the server.

5. The system of claim 1, wherein the signal comprises a Bluetooth Low Energy (BLE) signal transmitted by the first access control device.

6. The system of claim 1, wherein the operations comprise: determining that the first access control device is an entrance reader based on the accessed data; determining whether a last transaction of the one or more previous transactions comprises an entrance or an exit; and selectively establishing the communication session with the first access control device based on determining whether the last transaction of the one or more previous transactions comprises the entrance or the exit.

7. The system of claim 6, wherein the operations comprise: determining that the last transaction comprises the entrance; and preventing the mobile device from establishing the communication session with the first access control device in response to determining that the last transaction comprises the entrance and based on determining that the first access control device is the entrance reader.

8. The system of claim 7, wherein the operations comprise: searching for a signal transmitted by a second access control device; detecting the signal transmitted by a second access control device; determining that the second access control device is an exit reader based on the accessed data; and establishing the communication session with the second access control device in response to determining that the last transaction comprises the exit and based on determining that the second access control device is the exit reader.

9. The system of claim 8, wherein the operations comprise: transmitting a credential to the second access control device from the mobile device to obtain access to a resource protected by the second access control device.

10. The system of claim 9, wherein the operations comprise: determining that access to the resource has been granted by the second access control device; and updating the last transaction of the one or more previous transactions to specify that the last transaction comprises the exit.

11. The system of claim 10, wherein the last transaction is stored using the accessed data associated with the second access control device.

12. The system of claim 7, wherein the operations comprise: determining that the first access control device is an exit reader based on the accessed data; determining whether a last transaction of the one or more previous transactions comprises an entrance or an exit; and selectively establishing the communication session with the first access control device based on determining whether the last transaction of the one or more previous transactions comprises the entrance or the exit.

13. The system of claim 12, wherein the operations comprise: determining that the last transaction comprises the exit; and preventing the mobile device from establishing the communication session with the first access control device in response to determining that the last transaction comprises the exit and based on determining that the first access control device is the exit reader.

14. The system of claim 1, wherein the operations comprise: detecting a plurality of signals associated with the plurality of access control devices, the plurality of signals comprising the signal associated with the first access control device; in response to detecting the plurality of signals, determining a last transaction performed by the mobile device of the one or more previous transactions; and selecting one of the plurality of access control devices with which to establish a communication session based on the data describing configuration of the plurality of access control devices and the last transaction.

15. The system of claim 14, wherein the operations comprise: replacing the last transaction with a portion of the accessed data describing the selected one of the plurality of access control devices after determining that access has been granted to the mobile device by the selected one of the plurality of access control devices.

16. The system of claim 14, wherein the operations comprise:determining that data describing the last transaction is different from the accessed data describing the one of the plurality of access control devices; and transmitting a credential to the selected one of the plurality of access control devices in response to determining that the data describing the last transaction is different from the accessed data describing the one of the plurality of access control devices.

17. The system of claim 14, wherein the operations comprise: preventing establishing a communication session with an individual access control device of the plurality of access control devices in response to determining that data describing the last transaction matches the accessed data describing the individual access control device; and presenting a notification on the mobile device indicating an anti-passback violation comprising a message that identifies a correct access control device to use based on the last transaction.

18. The system of claim 1, wherein the one or more previous transactions comprise a set of transactions performed within a threshold range of a current location of the mobile device, and wherein the mobile device presents identifiers of the plurality of access control devices based on the data for selection by a user to establish a communication session.

19. A method comprising: accessing, by a mobile device, data describing configuration of a plurality of access control devices; detecting a signal associated with a first access control device of the plurality of access control devices; determining one or more previous transactions that the mobile device performed with one or more of the plurality of access control devices; and selectively establishing a communication session with the first access control device based on the data describing the configuration of the plurality of access control devices and the one or more previous transactions that the mobile device performed with one or more of the plurality of access control devices.

20. A machine-storage medium for storing instructions that, when executed by one or more hardware processors, cause the one or more hardware processors to perform operations comprising: accessing, by a mobile device, data describing configuration of a plurality of access control devices; detecting a signal associated with a first access control device of the plurality of access control devices; determining one or more previous transactions that the mobile device performed with one or more of the plurality of access control devices; and selectively establishing a communication session with the first access control device based on the data describing the configuration of the plurality of access control devices and the one or more previous transactions that the mobile device performed with one or more of the plurality of access control devices.

Citation Information

Patent Citations

  • Apparatus and method for access control

    EP2584538A1

  • Access control system using mobile device

    US20220270424A1

  • Wireless access credential system

    WO2020061567A1