Time and attendance management solution
The integration of UWB and biometric authentication in access control systems addresses the challenge of monitoring user presence and location, providing real-time tracking and enhanced security and compliance in controlled environments.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- ASSA ABLOY AB
- Filing Date
- 2025-10-23
- Publication Date
- 2026-05-07
AI Technical Summary
Existing access control systems lack efficient methods for monitoring and verifying the presence and location of authorized users within controlled spaces, particularly in large areas with limited access points, and do not provide real-time tracking and authentication of user activities.
Implementing an access control system that integrates ultra-wide band (UWB) capable reader devices and biometric authentication, along with a server that tracks user presence, location, and occupancy information, and provides real-time updates through an API endpoint, enhancing security and compliance monitoring.
Enables precise tracking of user presence and location within controlled spaces, improves security by flagging unauthorized activities, and enhances compliance through real-time monitoring and verification, minimizing disruptions and ensuring efficient resource management.
Smart Images

Figure EP2025080702_07052026_PF_FP_ABST
Abstract
Description
TIME AND ATTENDANCE MANAGEMENT SOLUTIONPRIORITY APPLICATION(S)
[0001] This application claims priority to Indian Provisional Patent Application No. 202411084101, filed on November 4, 2024, the disclosure of which is incorporated by reference herein in its entirety.TECHNICAL FIELD
[0002] Embodiments illustrated and described herein generally relate to access control system architectures that grant access of authorized users to a controlled resource.BACKGROUND
[0003] Access control can include granting physical access to an authorized user through a controlled portal. A Physical Access Control System (PACS) authenticates and authorizes a person to pass through a physical access point, such as a secured door, to enter a controlled space. The architecture of a PACS may vary significantly based on the application (e.g., a hotel, a residence, an office, etc.), the technology (e.g., access interfaces technology, door type, etc.), and the manufacturer. The inventors have recognized a need for improvements in managing access-controlled spaces.BRIEF DESCRIPTION OF THE DRAWINGS
[0004] FIG. 1 is an illustration of an access control system structure.
[0005] FIG. 2 is a flow diagram of an example of operating an access control system.
[0006] FIG. 3 is an example of a mobile phone display showing occupancy information for an access control system.
[0007] FIG. 4 is an illustration of an example of a credential device and a reader device.
[0008] FIGS. 5 and 6 are illustrations of more examples of a credential device and a reader device.
[0009] FIG. 7 is a block diagram illustrating an example of using an ultrawide band capable reader device.
[0010] FIG. 8 is a flow diagram of an example of a method of operating a real time location system.
[0011] FIG. 9 is a block diagram schematic of portions of an example of a reader device.DETAILED DESCRIPTION
[0012] FIG. 1 is an illustration of a basic PACS structure useful for an office application. The Access Credential includes credential information that may be a data object, a piece of knowledge (e.g., PIN, password, etc.), or a facet of the person’s physical being (e.g., face, fingerprint, etc.) that provides proof of the person’s identity. The Credential Device 104 stores the credential information when the Access Credential is a data object. The Credential Device 104 may be a smartcard or mobile phone. Other examples of Credential Devices include, but are not limited to, proximity radio frequency identification based (RFID-based) cards, access control cards, credit cards, debit cards, passports, identification cards, key fobs, near field communication (NFC) enabled devices, mobile phones, personal digital assistants (PDAs), tags, or any other device configurable to emulate a virtual credential.
[0013] The Reader Device 102 receives the credential information of the Credential Device 104. The Reader Device 102 may include a card reader to receive the credential information from a Credential Device 104 that is a smartcard. The Reader Device 102 may include a wireless communication port to receive the credential information wirelessly from the Credential Device 104 (e.g., when the Credential Device 104 is a mobile phone). In some examples, the Reader Device 102 sends the credential information to a Server 106 (e.g., via a Local Area Network or LAN). The Server 106 includes processing circuitry 112 (e.g., one or more hardware processors executing instructions included in software or firmware to perform the functions described) and memory 114. The Server 106 may perform the access control process. The server processing circuitry 112 compares the credential information to an Access Control list stored in memory 114, and enables or denies access based on the comparison, such as by controlling an automatic lock 108 on a door for example.
[0014] FIG. 2 is a flow diagram of an example of a method 200 of operating an access control system (e.g., the PACS in FIG. 1). At block 205, the Reader Device 102 of the access control system receives credential information from a Credential Device 104. If the Credential Device 104 is a smartcard, the holder or user of the Credential Device 104 may swipe the smartcard through a card reader at the physical access portal (e.g., a door) or tap the smartcard at the card reader. In some examples, the Reader Device 102 reads the credential information from the Credential Device 104 without action by the holder. For instance, theCredential Device 104 may be a mobile phone and a client application or App of the mobile phone may be active and sends the credential information to the Reader Device 102 without action by the holder. In another example, the Credential Device 104 can be an RFID and the Reader Device 102 may read the credential information from the RFID without action by the holder. The credential information includes a credential holder identifier (ID) that identifies the holder or user of the Credential Device 104. The Reader Device 102 sends credential information that includes the credential holder ID to the Server 106.
[0015] At block 210, access to the controlled space is enabled or granted to the credential holder when the credential information is authenticated. If the credential information is not authenticated, the credential holder is not given access to the controlled space. The Server 106 stores occupancy information about the access to the controlled space for the credential holder ID.
[0016] At block 215, in response to the access being enabled according to the credential information, the Server 106 records the date and / or time of access for the credential holder ID. The Server 106 may also set a logic status for the credential holder ID to “inside” the controlled space. The Server 106 may also start a timer to monitor the amount of time the credential holder is in the controlled space.
[0017] At block 220, the Reader Device 102 determines that the Credential Device 104 exits the controlled space. The credential holder may swipe or tap a Credential Device 104 that is a smartcard as the holder exits the controlled space, or the Reader Device 102 may read the credential holder identifier of the Credential Device 104 without action by the holder. The Reader Device 102 sends an indication of the exit of the Credential Device 104 to the Server 106. At 225, the Server 106 records the time duration that the Credential Device 104 was in the controlled space and the sets the logic status for the credential holder ID to “outside” the controlled space. In some examples, the server processing circuitry 112 determines the difference between the entry time and exit time to determine the time duration the time duration that the Credential Device 104 was in the controlled space. In certain examples, the server processing circuitry 112 reads a timer to determine the amount of time the credential holder was in the controlled space.
[0018] The Reader Device 102 may include reader processing circuitry 116. In certain examples, the reader processing circuitry 116 performs the access control process. The reader processing circuitry 116 authenticates the credential information and controls access to the controlled space (such as by controlling the automatic lock 108 of the door in FIG. 1). TheReader Device 102 sends the credential holder ID to the Server 106 and the server processing circuitry 112 generates occupancy information for the credential holder ID.
[0019] As shown in FIG. 1, the server processing circuitry 112 is configured to implement an application programming interface (API) endpoint. In certain examples, the API endpoint 110 is a representational state transfer API endpoint (REST API endpoint). The API endpoint 110 returns one or more of date and / or time of access, date and / or time of exit, occupancy time duration, and the logic status for the credential holder ID when queried by a client application of another device. In other variations, the occupancy information for the credential holder ID may also include a series of one or more prior events, such as a log series of access times and / or dates. The log series may be configured to include a predefined number of most recent events or include up to a predefined number of recent events associated with the credential holder ID. As additional events occur, such as subsequent accesses by the credential holder, the log series may be updated to add the more recent events and discard the oldest events. The API endpoint 110 can be consumed by any platform (e.g., a mobile phone App or a worldwide web App).
[0020] Additionally, the disclosures herein may be used in support of verification and authentication processes to augment typical credential verification methods. For example, occupancy information for the credential holder ID may be pushed to or retrieved by a mobile device associated with the credential holder ID as part of the verification or authentication process. In some embodiments, after an event (e.g., entry or exit) associated with a credential holder ID, one or more elements of the occupancy information (such as date and / or time of access, date and / or time of exit, occupancy time duration, etc.) may be obtained by the mobile device associated with the credential holder ID. Additionally, the credential holder may be asked to approve or confirm the event. This request to approve / confirm may be treated as part of the authentication process, or it may be considered as part of a logging process to verify access history.
[0021] When used as part of the authentication process, the confirmation of the event may be required before granting access, and if verification is not provided within a predetermined set of time, access may be denied. Additionally, a notification may be transmitted to security if the verification is either denied or timed out. When used as part of a logging process, the prior event verification may be provided after the authentication process has concluded. If verification is denied by the credential holder indicating that the access event was not valid, a notification may similarly be transmitted to security or to a system administrator. In response to a verification denial, the event may also be removed from theoccupancy information stored on the mobile device. Additionally, a message may be transmitted to the server to indicate that the credential user denied verification, and the server in response may remove or segregate the event from the log of verified occupancy information as part of updating the stored records of events associated with the credential holder ID. In certain embodiments where a user’s exit from the facility is also tracked, the access control system may pair the entrance and exit from the facility in the stored records and, upon an exit event associated with the credential holder ID, the mobile device associated with the credential holder may display the occupancy information associated with the entry event for verification of the paired entry and exit records by the credential holder.
[0022] In other embodiments, when a later authentication request is made in association with the credential holder ID, the access control system may also request the previous occupancy information be transmitted from the mobile device of the credential holder. The access control system may then verify that the provided occupancy information from the mobile device is consistent with the occupancy information stored in the server. In the event that the occupancy information on the mobile device and the server do not match, the previous occupancy information from the server may be displayed on the mobile device for the credential holder to verify, which may optionally be treated as a required part of the authentication process.
[0023] Additionally, if the occupancy information previously received by the mobile device has not yet been verified by the credential holder, a prompt may be provided to require verification by the credential holder, which optionally may be required before authentication can be completed. Alternatively, the previous occupancy information may be displayed on the mobile device for the user to verify, which may optionally be treated as a required part of the authentication process. If verification of the previous occupancy information is denied, the mobile device may transfer its most recent verified occupancy information, which may be used instead to authenticate the user. The server receives the most recent verified occupancy information from the mobile device and confirms that this record aligns with a prior record of occupancy information stored in the server. In embodiments where the occupancy information history is a chain or series of records, the server may scan through the chain to confirm whether a match exists.
[0024] Where one or more records on the chain are chronologically more recent than the mobile device’s most recent verified occupancy information, the server may additionally flag those other records for user verification and may also notify security personnel and / or system administrators to indicate a possible security concern to investigate. These additionalunverified records may be indicative of an issue requiring corrective action by the system administrator, such as a system error, component failure, facility policy violations, or an issue with credential integrity. One benefit of the disclosures herein is to provide added transparency for monitoring and auditing and to provide information in real-time or at least in temporal association with the expected flow of access control operations to potentially identify such issues earlier. Additionally, in response to a verification denial of the previous occupancy information, the mobile device may transmit the denial message to the server, and the server may transmit a notification to security personnel and / or system administrators to indicate a potential security concern to investigate.
[0025] In other embodiments, additional logic rules may be established to further monitor the event history for any credential holder ID. For example, during a later authentication request associated with an entry event to a facility, the access control system may determine whether an appropriate exit event has been previously assigned to the prior entry event, indicating that an exit event exists for each entry event of the credential holder ID. If no exit event exists, the server may notify the mobile device associated with the credential holder ID to verify the occupancy information associated with the prior entry event and, if verified by the user, may optionally add an exit event entry or request input of an exit date / time to insert in connection with the prior entry event. Similarly, an exit event without a corresponding entry event may also trigger a notification to the user to request verification of the exit event and optionally, a placeholder entry event could be inserted or preferably a request for information on the entry date / time to associate with the exit could be sent to the user for insertion into the stored records.
[0026] In other embodiments, the facility may also include one or more interior layers of access gates within an exterior control layer, such as exterior entry / exit point(s) followed by one or more interior layers of entry / exit point(s) at various locations or floors, or to secure certain interior spaces. Just as an entry event and exit event may be paired for the exterior layer of a facility access control system, interior access events may also be grouped in association with the initial entry (first) and final exit (last) events within a cluster or package. Additional rules may be configured and implemented in association with exterior and interior events, such as requesting verification if an interior entry event occurs without a preceding entry event or after an exit event, or if the order of proceeding through doors violates a logical order in which the one or more interior layers must be traversed. Additionally, if the access control system encounters a logical rule violation such as one of the foregoing, the system may notify a system administrator or security personnel for additional investigation.The logical rule violation may indicate lax compliance with facility rules (e.g., no piggybacking or holding access gates open) resulting in occupancy information that does not conform with expected rules.
[0027] It would be appreciated that the foregoing may be implemented in conjunction with any credential technology, including legacy card technologies without high security encryption. While the underlying credential technology and credential information remains unchanged, the implementation in conjunction with the foregoing adds an extra layer of security to assist with authentication, monitoring and verification. Unverified or erroneous events may be flagged and pushed to the user as part of the normal operations of the access control system to more contemporaneously identify potential security issues. User and administrator awareness and visibility of the credential holder ID event history at the server is improved, which may increase communication, proactive involvement and security awareness by the credential holder with minimal disruption to the normal access control process. Additionally, for normal operations, a form of additional factor authentication may be seamlessly introduced without alteration of the credential technology or credential information through use of the occupancy information as a set of one or more user-verified access control events stored on the server to reference against. In order to minimize delays in the credential authentication process, the use of occupancy information may be configured to be a verification process to be generally completed at the credential holder’s convenience up until the time of the next authentication request by the same credential holder ID.
[0028] FIG. 3 is an example of a mobile phone display showing occupancy information for an access control system. The display 300 shows results of a request to the API endpoint 110 from a mobile phone App. The display 300 shows the Credential Holder Name corresponding to the credential holder ID, the current logic status of the credential holder “Swiped Out”, and the Occupancy Time of the credential holder in the controlled space. If the credential holder was still in the space, the display 300 may show the logic status as “Swiped In” and may show the current running occupancy time of the credential holder in the controlled space. A web display may look similar to the mobile phone display in FIG. 3.
[0029] The mobile phone App may be the mobile phone App of the credential holder or may be a mobile phone App or web App of an administrator. The API endpoint 110 may restrict or allow access to occupancy information based on the role of the requesting device. In some examples, the client App of the requesting device may provide role information to the API endpoint 110. If the API endpoint 110 receives role information indicating anadministrator role, the API endpoint 110 may provide occupancy information for a specified group of credential holder IDs to the requesting device.
[0030] The Server 106 may perform one or more actions based on the credential ID and the occupancy status for the credential ID. For instance, controlled space may include a workspace for occupants that includes electrical appliances such as lights and other equipment that can be electrically activated. The server processing circuitry 112 may activate electrical appliances associated with the credential holder ID inside the controlled space in response to the enabling the access for the identified credential holder. For instance, the lights, electrical appliances, and the Server 106 may be connected to an internet of things (loT), and the server processing circuitry 112 activates the lights and electrical appliances using the loT. The server processing circuitry 112 may deactivate the electrical appliances associated with the credential holder ID in response to the determining that the credential device exits the controlled space.
[0031] FIG. 4 is an illustration showing an example of a Credential Device 104 being presented to a Reader Device 102. When the credential information is authenticated and the credential holder is granted access, the server processing circuitry 112 turns on lights and other electrical appliances for the cabin space or cubicle space of the identified credential holder. FIG. 5 is an illustration showing another example of a Credential Device 104 being presented to a Reader Device 102. When the credential holder presents their credential information to the Reader Device 102 when exiting the controlled space, the server processing circuitry 112 turns off the lights and electrical appliances of the identified credential holder. The Server 106 may also activate and deactivate lights and appliances for common areas within the controlled space.
[0032] FIG. 6 is an illustration showing another example of a Credential Device 104 being presented to a Reader Device 102. The server processing circuitry 112 turns on appliances based on occupancy of the controlled space. FIG. 6 shows basic electric appliances for the controlled space being turned on when the first credential holder enters the controlled premises that was previously void of holders. Some examples of such basic appliances include lights, a printer, a television, climate control appliances such as an air conditioner, etc. Interior Reader Devices may also be turned on if the controlled space includes sub-spaces that require additional access control (e.g., using a controlled access interior door). The server processing circuitry 112 may also turn on the specific appliances associated with the credential holder ID of the first credential holder. As further credential holders enter the space, the server processing circuitry 112 may also turn on the specificappliances associated with those credential holder IDs. The server processing circuitry 112 tracks the number of people in the controlled space.
[0033] When the first credential holder exits the controlled space, the server processing circuitry 112 may turn off the specific appliances associated with the identified first credential holder but continues to keep the basic appliances turned on if there are still other credential holders in the controlled space and may keep the appliances associated with the other credential holders based on the credential holder IDs of the people remaining inside. When the last credential holder exits the controlled space, the server processing circuitry 112 turns off the basic appliances and may turn off any specific appliances associated with the identified last credential holder that were still on.
[0034] FIG. 7 is a block diagram illustrating a real time location system (RTLS). The system uses Impulse Radio Ultra-Wideband (IR-UWB, or simply UWB) to detect presence of objects including people. UWB is a radio communication methodology that uses a wide signal bandwidth. The wide bandwidth is typically defined as either a -10 decibel (dB) bandwidth greater than 20% of the center frequency of the signal, or a bandwidth greater than 500 megahertz (500MHz) in absolute terms. The large bandwidth of UWB systems provides a high level of resilience to frequency selective fading, which is an effect that can limit the performance of narrow-band technologies.
[0035] The RTLS includes an ultra-wide band (UWB) capable real time location device. The UWB Device 720 includes a UWB Physical Layer or UWB PHI 722 and processing circuitry 724 operatively coupled to the UWB PHI 722. One or more UWB antennas 726 are operatively coupled to the UWB PHI 722. The UWB Device 720 uses oneway transmitting of radio frequency (RF) signal pulses and detecting of reflected RF pulses using the UWB PHI 722. The reflected RF pulses are the transmitted RF pulses reflected off objects. The transmitting of pulses and the receiving of the reflected pulses can be used by the UWB Device 720 as radar to detect objects including people.
[0036] In some examples, the transmitted RF pulses may include a specific string or pattern of UWB pulses transmitted by the UWB PHI 722. The processing circuitry 724 of the UWB Device 720 may include a correlator to determine the channel impulse response (CIR) from the transmitted pattern of pulses. The correlator may determine the CIR by acting as a deconvolution operator on the known pulse pattern. In some examples, the specific pulse pattern transmitted has low autocorrelation properties. In some examples, preamble symbols included in the ranging packets may be the pulse pattern transmitted for the detection radar.
[0037] The signals transmitted by the UWB Device 720 cause signals to be reflected by objects and persons in the environment of the UWB Device 720. The environment may be a store that receives customers. By determining the CIR of the reflected signals, the UWB Device 720 may obtain information of the RF properties of its environment. By regularly estimating the CIR based on the reflected signals, the UWB Device 720 can identify changes in the surrounding RF properties, such as changes due to a moving person. Thus, the estimation of the CIR based on the reflected signals by the UWB Device 720 provides basic radar functionality. This can be used by the UWB Device 720 to detect location and movement of people in the store relative to products kept in aisles, cubicles, or kiosks. When one or more persons are detected, the processing circuitry 724 records foot traffic information in the area of the UWB Device 720. This foot traffic information can include locations of customers in the store, density of customers in locations in the store, locations of customers in the store at particular times, movement of customers between locations in the store, etc. Analytics can be run on the foot traffic information to deduce customer demand on certain goods and services for example.
[0038] FIG. 8 is a flow diagram of a method 800 of operating a UWB capable RTLS, such as the RTLS of FIG. 7. At block 805, a UWB RF signal is transmitted using an antenna of the RTLS (e.g., an antenna 726 of UWB Device 720). At block 810, a reflected RF signal is received by the RTLS. The received reflected RF signal corresponds to the transmitted RF signal reflecting off an object. The RTLS determines when the object is a person. For instance, processing circuitry of the RTLS (e.g., processing circuitry 724 in FIG. 2) may regularly measure the RF properties of the RF environment of the RTLS. The processing circuitry may identify changes in the surrounding RF properties that indicate moving objects or sudden appearance of objects implying movement. The detection of objects that move or are moving may correspond to people in the RTLS environment.
[0039] At block 815, the RTLS determines location information of persons relative to the antenna of the RTLS using the reflected RF signals, such as distance and direction from the antenna. The RTLS may determine movement information of persons relative to the antenna of the RTLS. At block 820, the RTLS identifies and records foot traffic patterns using the location and movement information. The location information can be correlated to product location and customer interest in a product may be deduced from the foot traffic information. The location information can be used to produce a heat map of locations in the RTLS environment, which may indicate which products are more popular and those that are less popular.
[0040] The RTLS may include multiple UWB Devices 720 positioned at different locations throughout a space of interest such as a store. A heat map of the space can be produced from the person location information obtained by the UWB Devices 720. The movement information can be used to produce digital trails of people within the space. The digital trails may be used to see if product promotions are working or to identify products with related popularity.
[0041] Returning to FIG. 7, in some examples the UWB Device 720 is a Reader Device. The RTLS environment may be within a controlled space accessed using a Credential Device. For instance, the RTLS environment may be a large undivided space within a factory, a store, or an exhibition hall, etc., and the credentialed persons are assigned to specific locations within the RTLS environment. If the space was only an access control system, access using the Credential Device would provide information that the credentialed persons are within RTLS environment, but not whether the credentialed persons are at their assigned locations.
[0042] With a UWB capable Reader Device (or Devices), the RTLS system receives credential information of a credentialed person and authenticates the credential information of the Credential Device to grant access. The UWB capable Reader Device transmits UWB RF signals and detects a location of the credentialed person using the reflected RF signal. The UWB capable Reader Device can track location information for the credentialed person that can be used to track if the employee is where they are supposed to be and for how long.
[0043] In some examples, the Credential Device is a mobile phone, and the credentialed person uses an App of the mobile phone to present access to the UWB capable Reader Device. The processing circuitry of the UWB capable Reader Device receives biometric information included in the credential information and authenticates the biometric information to authenticate the credentialed person.
[0044] For instance, in large open spaces such as an exhibition floor or factor floor, it may be difficult to determine whether employees are manning their specific assigned areas and machines. Additionally, it may also be difficult to track the movement of equipment or raw materials between different assembly points or stalls in the large open space. The large open space may have a limited number of controlled access points and merely gaining access to the space does not guarantee the employees are manning their specific assigned location within the space. The RTLS system with biometric authentication can be used to verify attendance of the employee at their assigned location within the large open space. RTLS withUWB or Bluetooth can verify location within less than ten centimeters (10cm). Biometric authentication services can verify the identity of the user at the specific location.
[0045] To use the RTLS with biometric authentication, the user moves to the location assigned to him or her in the exhibition floor or factory and opens an application on their smartphone. The application verifies the location of the user using UWB or BLE signaling. The application may prompt the user to mark their attendance at the location using biometric information (e.g., fingerprint). Alternatively, the application may prompt the user to enter a unique code (e.g., a PIN). The application then marks the identified user at the identified location. The RTLS application ensures employee availability at the assigned location in the large open space. The RTLS can also verify delivery of equipment or raw materials at the assigned location for the equipment or materials.
[0046] In some examples, both the Reader Device of the RTLS and the mobile phones of the credentialed persons are UWB capable. The UWB capable Reader Device performs ranging using Time-of-Flight (TOF) Two Way Ranging (TWR) with the mobile phone of the credentialed person. In TWR, radio packets are exchanged between the UWB capable Reader Device and the UWB capable mobile phone. The timing differences for the transmitting and receiving of the packets between the Reader Device and the mobile phone can be used to identify the credentialed person and calculate ranging information for the credentialed person, such as one or both of distance of the credentialed person from the UWB capable Reader Device and angle of the credentialed person relative to the UWB capable Reader Device.
[0047] FIG. 9 is a block diagram schematic of various example components of a Reader Device for supporting the device architectures described and illustrated herein. The device 900 of FIG. 9 could be, for example, a reader device that authenticates credential information of authority, status, rights, and / or entitlement to privileges for the holder of a credential device. At a basic level, a reader device can include an interface (e.g., one or more antennas and Integrated Circuit (IC) chip(s)), which permits the device to exchange data with another device, such as a credential device or a reader device. One example of credential device is an RFID smartcard that has data stored thereon allowing a holder of the credential device to access a secure area or asset protected by the reader device.
[0048] With reference specifically to FIG. 9, additional examples of a reader device 900 for supporting the device architecture described and illustrated herein may generally include one or more of a memory 914, processing circuitry such as a processor 912, one ormore antennas 926, a communication port or communication module 930, a network interface device 932, a user interface 934, and a power source 936 or power supply.
[0049] Memory 914 can be used in connection with the execution of application programming or instructions by processing circuitry, and for the temporary or long-term storage of program instructions or instruction sets 938 and / or credential information 940, such as credential data, credential authorization data, or access control data or instructions, as well as any data, data structures, and / or computer-executable instructions needed or desired to support the above-described device architecture. For example, memory 914 can contain executable instructions 938 that are used by a processor 912 of the processing circuitry to run other components of device 900, to make access determinations based on credential or authorization data 940, and / or to perform any of the functions or operations described herein, such as the example methods of FIG. 2 or FIG. 8 for example. Memory 914 can comprise a computer readable medium that can be any medium that can contain, store, communicate, or transport data, program code, or instructions for use by or in connection with device 900. The computer readable medium can be, for example but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device. More specific examples of suitable computer readable medium include, but are not limited to, an electrical connection having one or more wires or a tangible storage medium such as a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), Dynamic RAM (DRAM), any solid-state storage device, in general, a compact disc read-only memory (CD-ROM), or other optical or magnetic storage device. Computer-readable media includes, but is not to be confused with, computer-readable storage medium, which is intended to cover all physical, non-transitory, or similar embodiments of computer-readable media.
[0050] Processor 912 can correspond to one or more computer processing devices or resources. For instance, processor 912 can be provided as silicon, as a Field Programmable Gate Array (FPGA), an Application-Specific Integrated Circuit (ASIC), any other type of Integrated Circuit (IC) chip, a collection of IC chips, or the like. As a more specific example, processor 912 can be provided as a microprocessor, Central Processing Unit (CPU), or plurality of microprocessors or CPUs that are configured to execute instructions sets 942 stored in an internal processor memory and / or memory 914.
[0051] Antenna 926 can correspond to one or multiple antennas and can be configured to provide for wireless communications between device 900 and another device.Antenna(s) 926 can be coupled to one or more physical (PHY) layers 922 to operate using one or more wireless communication protocols and operating frequencies including, but not limited to, the IEEE 802.15.1, Bluetooth, Bluetooth Low Energy (BLE), near field communications (NFC), ZigBee, GSM, CDMA, Wi-Fi, RF, UWB, and the like. In an example, antenna 926 may include one or more antennas coupled to one or more physical layers 922 to operate using UWB for activity, communication, ranging, or radar.
[0052] Device 900 may additionally include a communication module 930 and / or network interface device 932. Communication module 930 can be configured to communicate according to any suitable communications protocol with one or more different systems or devices either remote or local to device 900. Network interface device 932 includes hardware to facilitate communications with other devices over a communication network utilizing any one of a number of transfer protocols (e.g., frame relay, internet protocol (IP), transmission control protocol (TCP), user datagram protocol (UDP), hypertext transfer protocol (HTTP), etc.). Example communication networks can include a local area network (LAN), a wide area network (WAN), a packet data network (e.g., the Internet), mobile telephone networks (e.g., cellular networks), Plain Old Telephone (POTS) networks, wireless data networks (e.g., IEEE 802.11 family of standards known as Wi-Fi, IEEE 802.16 family of standards known as WiMax), IEEE 802.15.4 family of standards, and peer-to-peer (P2P) networks, among others. In some examples, network interface device 932 can include an Ethernet port or other physical jack, a Wi-Fi card, a Network Interface Card (NIC), a cellular interface (e.g., antenna, filters, and associated circuitry), or the like. In some examples, network interface device 932 can include a plurality of antennas to wirelessly communicate using at least one of single-input multiple-output (SIMO), multiple-input multiple-output (MIMO), or multiple-input single-output (MISO) techniques. In some example embodiments, one or more of the antenna 926, communication module 930, and / or network interface device 932 or subcomponents thereof, may be integrated as a single module or device, function or operate as if they were a single module or device, or may comprise of elements that are shared between them.
[0053] User interface 934 can include one or more input devices and / or display devices. Examples of suitable user input devices that can be included in user interface 934 include, without limitation, one or more buttons, a keyboard, a mouse, a touch-sensitive surface, a stylus, a camera, a microphone, etc. Examples of suitable user output devices that can be included in user interface 934 include, without limitation, one or more LEDs, an LCD panel, a display screen, a touchscreen, one or more lights, a speaker, etc. It should beappreciated that user interface 934 can also include a combined user input and user output device, such as a touch-sensitive display or the like.
[0054] Power source 936 can be any suitable internal power source, such as a battery, capacitive power source or similar type of charge-storage device, etc., and / or can include one or more power conversion circuits suitable to convert external power into suitable power (e.g., conversion of externally supplied AC power into DC power) for components of the device 900. Device 900 can also include one or more interlinks or buses 944 operable to transmit communications between the various hardware components of the device. A system bus 944 can be any of several types of commercially available bus structures or bus architectures.ADDITIONAL DISCLOSURE AND EXAMPLES
[0055] Example 1 includes subject matter (such as a physical access control system) comprising a reader device and a server. The reader device is configured to receive credential information that includes a credential holder ID. The server includes a memory to store the credential information and server processing circuitry. The server processing circuitry is configured to receive the credential information from the reader device, enable access to a controlled space according to the credential information, record a date and / or time of access or exit for the credential holder ID and set a logic status for the credential holder ID to inside the space in response to the enabling the access, receive information from the reader device indicating the credential device exits the controlled space, and record a time duration that the credential device was in the controlled space and the setting the logic status for the credential holder ID to outside the space.
[0056] In Example 2, the subject matter of Example 1 optionally includes server processing circuitry configured to implement an application programming interface (API) endpoint, and provide one or more of the date and / or time of access or exit, the time duration, and the logic status for the credential holder ID to a client application of another device via the API endpoint.
[0057] In Example 3, the subject matter of Example 2 optionally includes server processing circuitry configured to receive role information of the other device using the API endpoint, and provide one or more of the date and / or time of access or exit, the time duration, and the logic status for a specified group of credential holder IDs to the other device via the API endpoint according to the role of the other device.
[0058] In Example 4, the subject matter of any one of Examples 1-3 optionally includes server processing circuitry configured to activate electrical appliances associated with the credential holder ID inside the controlled space in response to the enabling the access, and deactivate the electrical appliances associated with the credential holder ID in response to the information that the credential device exits the controlled space.
[0059] In Example 5, the subject matter of any one of Examples 1-4 optionally includes server processing circuitry configured to track a number of credential device users in the controlled space, activate one or more electrical appliances in the controlled space in response to the enabling the access when the controlled space was void of credential device users before the access, and deactivate the one or more electrical appliances in the controlled space in response to determining that the credential device of an only user in the controlled space exits the controlled space.
[0060] In Example 6, the subject matter of any one of Examples 1-5 optionally includes a reader device including an ultra-wide band (UWB) physical layer and reader device processing circuitry operatively coupled to the UWB physical layer. The reader device processing circuitry is configured to use one-way signaling to transmit a UWB signal in the controlled space using the UWB physical layer, receive a reflected signal using the UWB physical layer that corresponds to the transmitted UWB signal reflecting off an object, and identify a user of the credential device and determine location information of the user using the reflected signal.
[0061] Example 7 includes subject matter (such as a method of operating an access control system) or can optionally be combined with one or any combination of Examples 1-6 to include such subject matter, comprising receiving, by a reader device of the access control system, credential information from a credential device, wherein the credential information includes a credential holder ID; enabling access to a controlled space according to the credential information; recording a date and / or time of access or exit for the credential holder ID and setting a logic status for the credential holder ID to inside the space in response to the enabling the access; determining that the credential device exits the controlled space; and recording a time duration that the credential device was in the controlled space and the setting the logic status for the credential holder ID to outside the space.
[0062] In Example 8, the subject matter of Example 7 optionally includes providing one or more of the date and / or time of access or exit, the time duration, and the logic status for the credential holder ID to a client application of another device using an application programming interface (API) endpoint of the access control system.
[0063] In Example 9, the subject matter of one or both of Examples 7 and 8 optionally includes determining a role of another device using an application programming interface (API) endpoint of the access control system, and providing one or more of the date and / or time of access or exit, the time duration, and the logic status for a specified group of credential holder IDs to the other device using the API endpoint according to the role of the other device.
[0064] In Example 10, the subject matter of one or any combination of Examples 7-9 optionally includes receiving a credential holder ID for a person from a credential device.
[0065] In Example 11, the subject matter of one or any combination of Examples 7-10 optionally includes receiving a credential holder ID for an asset from a credential device.
[0066] In Example 12, the subject matter of one or any combination of Examples 7-11 optionally includes turning on electrical appliances associated with the credential holder ID inside the controlled space in response to the enabling the access, and turning off the electrical appliances associated with the credential holder ID in response to the determining that the credential device exits the controlled space.
[0067] In Example 13, the subject matter of one or any combination of Examples 7-12 optionally includes tracking a number of credential device users in the controlled space, turning on one or more electrical appliances in the controlled space in response to the enabling the access when the controlled space was void of credential device users before the access, and turning off the one or more electrical appliances in the controlled space in response to determining that the credential device of an only user in the controlled space exits the controlled space.
[0068] Example 14 includes subject matter (such as an ultra- wide band (UWB) capable real time location device) or can optionally be combined with one or any combination of Examples 1-13 to include such subject matter, comprising an ultra-wide band (UWB) physical layer and processing circuitry operatively coupled to the UWB physical layer. The processing circuitry is configured to use one-way signaling to transmit a UWB signal using the UWB physical layer, receive a reflected signal using the UWB physical layer that corresponds to the transmitted UWB signal reflecting off an object, detect one or more persons using the received reflected signal, record location information of the one or more persons, and identify and record foot traffic patterns using the location information.
[0069] In Example 15, the subject matter of Example 14 optionally includes processing circuitry configured to determine movement information of the detected one ormore persons relative to the device using the received reflected signal and identify the foot traffic patterns using the movement information.
[0070] In Example 16 the subject matter of one or both of Examples 14 and 15 optionally includes processing circuitry configured to receive credential information of a credentialed person, authenticate the credential information, detect the credentialed person using the reflected signal, and track location information for the credentialed person.
[0071] In Example 17, the subject matter of Example 16 optionally includes processing circuitry configured to receive biometric information included in the credential information and authenticate the biometric information.
[0072] Example 18 includes subject matter (such as a method of operating UWB capable real time location system (RTLS)) or can optionally be combined with one or any combination of Examples 1-17 to include such subject matter, comprising transmitting a UWB radio frequency (RF) signal using an antenna of the UWB capable RTLS, receiving a reflected RF signal corresponding to the transmitted RF signal reflecting off an object, determining location information of persons relative to the antenna of the UWB capable RTLS using the reflected RF signal, and identifying and recording foot traffic patterns using the location information.
[0073] In Example 19, the subject matter of Example 18 optionally includes determining movement information of persons relative to the antenna of the UWB capable RTLS using the reflected RF signal and identifying the foot traffic patterns using the movement information.
[0074] In Example 20, the subject matter of one or both of Examples 18 and 19 optionally includes determining when the reflected RF signal reflects off a person and determining distance of the person from the antenna and direction of the person from the antenna.
[0075] In Example 21, the subject matter of one or any combination of Examples 18- 20 optionally includes receiving, using a reader device of the RTLS, credential information of a credentialed person; authenticating the credential information using the RTLS; and tracking location information of the credentialed person using the reflected RF signal.
[0076] In Example 22, the subject matter of Example 21 optionally includes receiving biometric information of the credentialed person using the reader device and authenticating the biometric information using the RTLS.
[0077] In Example 23, the subject matter of one or more combinations of Examples1-22 further includes obtaining in a mobile device associated with the credential holder ID afirst occupancy information associated with a first authentication request, the first occupancy information being transmitted from the server to the mobile device.
[0078] In Example 24, the subject matter of Example 23 further includes, at a second authentication request, requesting the mobile device associated with the credential holder ID to transmit the first occupancy information to the server, confirming by the server that the received first occupancy information matches the occupancy information records stored in the server, for example in a database entry, file, or records chain associated with the credential holder ID.
[0079] In Example 25, the subject matter of Example 24 further includes determining by the server that the first occupancy information has been verified by the credential holder, and in response to determining that the first occupancy information has not yet been verified, requesting the mobile device display the first occupancy information to the credential holder for verification.
[0080] In Example 26, the subject matter of Example 25 further includes, in response to the credential holder indicating a denial of verification, transmitting the denial of verification from the mobile device to the server and optionally transmitting to the server a most recently verified occupancy information for confirmation of a match with the records of occupancy information stored on the server.
[0081] In Example 27, the subject matter of Example 26 further includes, in response to receiving the denial of verification at the server, transmitting a notification of the denial to one or more of system administrators or security personnel to indicate the credential holder denied validity of an access control event associated with the credential holder ID.
[0082] In Example 28, the subject matter of one or more combinations of Examples 26-27, further includes, in response to receiving at the server the most recently verified occupancy information from the mobile device, identifying one or more access control events in the occupancy information stored on the server that are subsequent to the most recently verified occupancy information and also unverified, transmitting notification of the additional unverified access control events to one or more of system administrators or security personnel to indicate the unverified validity of additional events associated with the credential holder ID.
[0083] In Example 29, the subject matter of one or more combinations of Examples 26-27, further includes, in response to receiving at the server the most recently verified occupancy information from the mobile device, identifying one or more access control events in the occupancy information stored on the server that are subsequent to the most recentlyverified occupancy information and also unverified, transmitting the one or more subsequent unverified occupancy information to the credential holder for verification, updating the stored occupancy information on the server in response to any verifications received if any, and in response to receiving at the server from the mobile device a message indicating denial of verification for any of the subsequent unverified occupancy information, transmitting notification of the additional denied verification access control events to one or more of system administrators or security personnel.
[0084] In Example 30, the subject matter of Example 24 further includes determining by the mobile device prior to transmission of the first occupancy information that the first occupancy information has been verified by the credential holder, and in response to determining that the first occupancy information has not yet been verified, displaying the first occupancy information to the credential holder for verification.
[0085] In Example 31, the subject matter of Example 30, further includes, in response to receiving a denial of verification from the credential holder, transmitting a notification of the denial to one or more of system administrators or security personnel to indicate the credential holder denied validity of an access control event associated with the credential holder ID, and retrieving for transmission to the server a most recently verified occupancy information for confirmation of a match with the records of occupancy information stored on the server.
[0086] In Example 32, the subject matter of one or more combinations of Examples 24-31, further includes opening a secure communication channel between the mobile device and the server for transmitting notifications and occupancy information.
[0087] In Example 33, the subject matter of one or more combinations of Examples 24-32, further includes, in response to receiving a request for access for a credential holder ID, granting access only upon satisfaction of preconfigured conditions including (i) previous occupancy information received from the mobile device associated with the credential holder ID has been verified by the credential holder, and (ii) previous occupancy information received from the mobile device matches at least one record of previous occupancy information stored on the server in association with the credential holder ID.
[0088] In Example 34, the subject matter of one or more combinations of Examples 1-33, further includes grouping one or more associated events for a credential holder ID, such as pairing entry and exit events and grouping interior access events following an initial entry and prior to a final exit.
[0089] In Example 35, the subject matter of Example 34, further includes identifying if the event records within the occupancy information for a credential holder ID conform with one or more logical rules, and in response to determining that the one or more logical rules have been violated, sending a notification and requesting verification of the event records in the occupancy information.
[0090] In Example 36, the subject matter of Example 35, wherein the notification and request for verification are sent to a system administrator.
[0091] In Example 37, the subject matter of Example 35, wherein the notification and request for verification are sent to the mobile device associated with the credential holder ID.
[0092] In Example 38, the subject matter of Examples 36-37, wherein in response to a verification of the event records in violation of one or more logical rules, requesting from the credential holder input to provide date / time information for any missing event records.
[0093] In Example 39, the subject matter of Examples 36-37, wherein in response to a verification of the event records in violation of one or more logical rules, creating a corresponding placeholder event record for any missing event records in the occupancy information associated with the credential holder ID.
[0094] These Examples can be combined in any permutation or combination. The above detailed description includes references to the accompanying drawings, which form a part of the detailed description. The drawings show, by way of illustration, specific embodiments in which the invention can be practiced. The above description is intended to be illustrative, and not restrictive. For example, the above-described examples (or one or more aspects thereof) may be used in combination with each other. Other embodiments can be used, such as by one of ordinary skill in the art upon reviewing the above description. The Abstract is provided to allow the reader to quickly ascertain the nature of the technical disclosure. It is submitted with the understanding that it will not be used to interpret or limit the scope or meaning of the claims. In the above Detailed Description, various features may be grouped together to streamline the disclosure. This should not be interpreted as intending that an unclaimed disclosed feature is essential to any claim. Rather, the subject matter may lie in less than all features of a particular disclosed embodiment. Thus, the following claims are hereby incorporated into the Detailed Description, with each claim standing on its own as a separate embodiment, and it is contemplated that such embodiments can be combined with each other in various combinations or permutations. The scope should be determined with reference to the appended claims, along with the full scope of equivalents to which such claims are entitled.
Claims
WHAT IS CLAIMED IS:
1. A physical access control system (PACS), the system comprising: a reader device configured to receive credential information that includes a credential holder identifier (ID); and a server including: a memory to store the credential information; and server processing circuitry configured to: receive the credential information from the reader device; enable access to a controlled space according to the credential information; record a time of access for the credential holder ID and set a logic status for the credential holder ID to inside the space in response to the enabling the access; receive information from the reader device indicating the credential device exits the controlled space; and record a time duration that the credential device was in the controlled space and the setting the logic status for the credential holder ID to outside the space.
2. The system of claim 1, wherein the server processing circuitry is configured to: implement an application programming interface (API) endpoint; and provide one or more of the date of access, time of access, date of exit, time of exit, the time duration, and the logic status for the credential holder ID to a client application of another device via the API endpoint.
3. The system of claim 2, wherein the server processing circuitry is configured to: receive role information of the other device using the API endpoint; and provide one or more of the date of access, time of access, date of exit, time of exit, the time duration, and the logic status for a specified group of credential holder IDs to the other device via the API endpoint according to the role of the other device.
4. The system of claim 1, wherein the server processing circuitry is configured to: activate electrical appliances associated with the credential holder ID inside the controlled space in response to the enabling the access; and deactivate the electrical appliances associated with the credential holder ID in response to the information that the credential device exits the controlled space.
225. The system of claim 1, wherein the server processing circuitry is configured to: track a number of credential device users in the controlled space; activate one or more electrical appliances in the controlled space in response to the enabling the access when the controlled space was void of credential device users before the access; and deactivate the one or more electrical appliances in the controlled space in response to determining that the credential device of an only user in the controlled space exits the controlled space.
6. The system of claim 1, wherein the reader device includes: an ultra-wide band (UWB) physical layer; and reader device processing circuitry operatively coupled to the UWB physical layer and configured to: use one-way signaling to transmit a UWB signal in the controlled space using the UWB physical layer; receive a reflected signal using the UWB physical layer that corresponds to the transmitted UWB signal reflecting off an object; and identify a user of the credential device and determine location information of the user using the reflected signal.
7. A method of operating an access control system, the method comprising: receiving, by a reader device of the access control system, credential information from a credential device, wherein the credential information includes a credential holder identifier (ID); enabling access to a controlled space according to the credential information; recording a time of access for the credential holder ID and setting a logic status for the credential holder ID to inside the space in response to the enabling the access; determining that the credential device exits the controlled space; and recording a time duration that the credential device was in the controlled space and the setting the logic status for the credential holder ID to outside the space.
8. The method of claim 7, including providing one or more of the date of access, time of access, date of exit, time of exit, the time duration, and the logic status for the credentialholder ID to a client application of another device using an application programming interface (API) endpoint of the access control system.
9. The method of claim 7, including: determining a role of another device using an application programming interface (API) endpoint of the access control system; and providing one or more of the date of access, time of access, date of exit, time of exit, the time duration, and the logic status for a specified group of credential holder IDs to the other device using the API endpoint according to the role of the other device.
10. The method of claim 7, wherein the receiving the credential information from a credential device includes receiving a credential holder ID for a person.
11. The method of claim 7, wherein the receiving the credential information from a credential device includes receiving a credential holder ID for an asset.
12. The method of claim 7, including: turning on electrical appliances associated with the credential holder ID inside the controlled space in response to the enabling the access; and turning off the electrical appliances associated with the credential holder ID in response to the determining that the credential device exits the controlled space.
13. The method of claim 7, including: tracking a number of credential device users in the controlled space; turning on one or more electrical appliances in the controlled space in response to the enabling the access when the controlled space was void of credential device users before the access; and turning off the one or more electrical appliances in the controlled space in response to determining that the credential device of an only user in the controlled space exits the controlled space.
14. An ultra-wide band (UWB) capable real time location device, the device comprising: an ultra-wide band (UWB) physical layer; and processing circuitry operatively coupled to the UWB physical layer and configured to:use one-way signaling to transmit a UWB signal using the UWB physical layer; receive a reflected signal using the UWB physical layer that corresponds to the transmitted UWB signal reflecting off an object; detect one or more persons using the received reflected signal; record location information of the one or more persons; and identify and record foot traffic patterns using the location information.
15. The device of claim 14, wherein the processing circuitry is configured to: determine movement information of the detected one or more persons relative to the device using the received reflected signal; and identify the foot traffic patterns using the movement information.
16. The device of claim 14, wherein the processing circuitry is configured to: receive credential information of a credentialed person; authenticate the credential information; detect the credentialed person using the reflected signal; and track location information for the credentialed person.
17. The device of claim 16, wherein the processing circuitry is configured to: receive biometric information included in the credential information; and authenticate the biometric information.
18. A method of operating an ultra-wide band (UWB) capable real time location system (RTLS), the method comprising: transmitting a UWB radio frequency (RF) signal using an antenna of the UWB capable RTLS; receiving a reflected RF signal corresponding to the transmitted RF signal reflecting off an object; determining location information of persons relative to the antenna of the UWB capable RTLS using the reflected RF signal; and identifying and recording foot traffic patterns using the location information.
19. The method of claim 18, including:determining movement information of persons relative to the antenna of the UWB capable RTLS using the reflected RF signal; and wherein the identifying foot traffic patterns includes identifying the foot traffic patterns using the movement information.
20. The method of claim 18, wherein the determining the location information includes: determining when the reflected RF signal reflects off a person; and determining distance of the person from the antenna and direction of the person from the antenna.
21. The method of claim 18, including: receiving, using a reader device of the RTLS, credential information of a credentialed person; authenticating the credential information using the RTLS; and tracking location information of the credentialed person using the reflected RF signal.
22. The method of claim 21, wherein the receiving the credential information includes receiving biometric information of the credentialed person using the reader device; and wherein the authenticating the credential information includes authenticating the biometric information using the RTLS.
Citation Information
Patent Citations
Tracking and Access System
US20170148239A1
Tracking Conditions Concerning an Area to Automatically Generate Artificial Intelligence Based Responsive Actions
US20210271210A1
Method and apparatus for controlling a passage barrier
US20230215230A1