Reader to reader telemetry using advertisement packets

Reader-to-reader communication via telemetry advertisement packets addresses the limitations of conventional access control systems by enabling efficient information sharing and coordinated operations, including security alerts and configuration updates.

WO2026098980A1PCT designated stage Publication Date: 2026-05-15ASSA ABLOY AB
View PDF 5 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
ASSA ABLOY AB
Filing Date
2025-10-23
Publication Date
2026-05-15

AI Technical Summary

Technical Problem

Conventional access control readers lack the capability to communicate with other readers, limiting their ability to efficiently share information and coordinate operations such as security breaches, sleep mode notifications, and configuration updates.

Method used

Implementing reader-to-reader communication through telemetry advertisement packets that are ignored by client devices but received by other readers within RF range, allowing for the transmission of notifications and establishment of data sessions.

Benefits of technology

Enables quick propagation of security alerts, synchronized power management, and automated configuration updates across a physical access control system, enhancing system resilience and efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2025080701_15052026_PF_FP_ABST
    Figure EP2025080701_15052026_PF_FP_ABST
Patent Text Reader

Abstract

Reader-to-reader communication in a physical access control can employ telemetry advertisement packets broadcasted by readers. The telemetry advertisement packets can be ignored by client devices, such as phones, badges, etc., but are directed to and can be received by other readers within communication range. Information, such as notifications for security breaches, sleep mode operations, etc., can be transmitted with the telemetry advertisement packets. Moreover, more substantial information can also be transmitted between readers with the establishment of a data sessions.
Need to check novelty before this filing date? Find Prior Art

Description

READER TO READER TELEMETRY USING ADVERTISEMENT PACKETSPRIORITY APPLICATIONS)

[0001] This application claims priority to Indian Provisional Patent Application No. 202411085864, filed on November 8, 2024, the disclosure of which is incorporated by reference herein in its entirety.TECHNICAL FIELD

[0002] The present disclosure generally relates to using physical access control systems, and in particular to reader-to-reader communication in the physical access control systems.BACKGROUND

[0003] Physical access control systems can control access to restricted areas and assets. Access control readers interact with user devices, such as phones, badges, etc., to make access decisions. The access control readers can communicate with the user devices using wireless communication protocols. However, conventional access control readers do not have the capability to communicate with other readers.SUMMARY

[0004] This disclosure describes a method comprising: transmitting, by a first reader of a physical access control system, a first advertisement packet, wherein the first advertisement packet is directed to one or more client devices within radio frequency (RF) range of the first reader; receiving, by the first reader, a first response by a client device to the first advertisement packet; receiving, by the first reader, a set of credentials from the client device to perform credential verification associated with the client device; and transmitting, by the first reader, a second advertisement packet, wherein the second advertisement packet is directed to one or more readers in the physical access control system within RF range of the first reader.

[0005] This disclosure also describes a reader device comprising at least one hardware processor; and at least one memory storing instructions that, when executed by the at least one hardware processor, cause the at least one hardware processor to perform operationscomprising: transmitting a first advertisement packet, wherein the first advertisement packet is directed to one or more client devices of a physical access control system within radio frequency (RF) range of the reader device; receiving a first response by a client device to the first advertisement packet; receiving a set of credentials from the client device to perform credential verification associated with the client device; and transmitting a second advertisement packet, wherein the second advertisement packet is directed to one or more readers in the physical access control system within RF range of the reader device

[0006] This disclosure further describes a machine-readable medium embodying instructions that, when executed by a machine, cause the machine to perform operations comprising: transmitting, by a first reader of a physical access control system, a first advertisement packet, wherein the first advertisement packet is directed to one or more client devices within radio frequency (RF) range of the first reader; receiving, by the first reader, a first response by a client device to the first advertisement packet; receiving, by the first reader, a set of credentials from the client device to perform credential verification associated with the client device; and transmitting, by the first reader, a second advertisement packet, wherein the second advertisement packet is directed to one or more readers in the physical access control system within RF range of the first reader.BRIEF DESCRIPTION OF THE DRAWINGS

[0007] Various ones of the appended drawings merely illustrate example embodiments of the present disclosure and should not be considered as limiting its scope.

[0008] FIG. 1 illustrates example portions of a physical access control system (PACS).

[0009] FIG. 2 is an example timing diagram for transmitting advertisement packets by a reader in a PACS.

[0010] FIG. 3 is a flow diagram of a method for transmitting security alarm notifications.

[0011] FIG. 4 is a flow diagram of a method for sleep mode notifications.

[0012] FIG. 5 is a flow diagram for a method for establishing a data pipeline between two readers.

[0013] FIG. 6 is a flow diagram for a method for updating configurations on a plurality of readers.

[0014] FIG. 7 is a flow diagram of a method for “buddy” communication between readers.

[0015] FIG. 8 illustrates a block diagram schematic of various example components of an example machine that can be used as, for example, a reader.DETAILED DESCRIPTION

[0016] Techniques for reader-to-reader communication in a physical access control system are described. The techniques employ telemetry advertisement packets broadcasted by readers. The telemetry advertisement packets can be ignored by client devices, such as phones, badges, etc., but are directed to and can be received by other readers within communication range. Information, such as notifications for security breaches, sleep mode operations, etc., can be transmitted with the telemetry advertisement packets. Moreover, more substantial information can also be transmitted between readers with the establishment of a data sessions.

[0017] FIG. 1 illustrates example portions of a physical access control system (PACS) 100. In this example, the PACS 100 may control access to different restricted areas in a building; however, PACS 100 may be used in different security applications. The PACS 100 includes a plurality of readers 102, 104, 106, 108. For example, readers 102, 104 may be located in a first room near an entrance of a building, controlling access in and out of the building. Reader 106 may be located in a second room behind the first room controlling access to the second room. Reader 108 may be located in a third room above the second room (e.g., second floor) controlling access to the third room.

[0018] The readers 102-108 connected to a locking mechanism (e.g., a door locking mechanism) that controls access the secur e / protected resource (e.g., area, asset). The locking mechanism can include a door lock, an ignition system for a vehicle, or any other device that grants or denies access to a physical component or that can be operated to grant or deny access to the physical component. For example, in the case of a door lock, the readers 102- 108 can deny access, in which case the door lock remains locked and the door cannot be opened; or can grant access, in which case the door lock becomes unlocked to allow the door to be opened. As another example, in the case of an ignition system, the access readers 102- 108 can deny access, in which case the vehicle ignition system remains disabled and the vehicle cannot be started; or can grant access, in which case the vehicle ignition becomes enabled to allow the vehicle to be started

[0019] Physical access control covers a range of systems and methods to govern access,for example by people, to secure areas or secure assets. Physical access control includes identification of authorized users or devices (e.g., vehicles, drones, etc.) and actuation of a gate, door, or other facility used to secure an area, or actuation of a control mechanism, e.g., a physical or electronic / software control mechanism, permitting access to a secure asset. In some examples, the readers 102-108 may hold authorization data (also referred to access control information) and can be capable of determining whether credentials (e.g., from credential or key devices such as radio frequency identification (RFID) chips in cards, fobs, or personal electronic devices such as mobile phones) are authorized for an actuator or control mechanism (e.g., door lock, door opener, software control mechanism, turning off an alarm, etc.).

[0020] The readers 102-108 are connected to a controller 110, which can manage the operations of the readers 102-108 in a centrally managed configuration. In some examples, the controller 110 can perform the access control decisions based on the authorization data. The controller 110 may be connected to the readers 102-108 with a wired connection. In some examples, each reader 102-108 may have a dedicated connection (e.g., Wiegand) to the controller 110. In some other examples, the readers 102-108 may have a shared line (e.g., OSDP) to the controller 110. In some examples, the readers 102-108 and the controller 110 may be connected using a wireless connection.

[0021] The readers 102-108 may engage with a client device 150 using electronic messages over the Internet, Bluetooth Low Energy (BLE), Ultra-Wide Band (UWB), WiFi Direct, Near-Field Communication (NFC), or any other pr / otocol). The client device 150 may refer to any machine that interfaces to a communications network (such as a wireless network) to exchange credentials with one or more of the readers 102-108, the controller 110, or any other component to obtain access to the asset or resource protected by the readers 102- 108. The client device 150 can include or store one or more credentials which can be provided to the readers 102-108 for obtaining access to a protected physical or logical asset or resource. A client device 150 may be, but is not limited to, a mobile phone, desktop computer, laptop, portable digital assistant (PDA), smart phone, a wearable device (e.g., a smart watch), tablet, ultrabook, netbook, laptop, multi-processor system, microprocessorbased or programmable consumer electronics, physical card, or any other communication device that a user may use to access a network.

[0022] The readers 102-108 may broadcast advertisement packets, such as BLE advertisement packets, in fixed intervals to notify client devices (e.g., client device 150) oftheir presence and capability. For example, the readers may transmit two advertisement packets, a lock profile advertisement packet and a beacon advertisement packet, periodically. The lock profile advertisements are connectable / scannable advertisement packets that enable connection establishment and credential exchange with the readers 102-108 and client device 150. The beacon advertisement packets (e.g., iBeacon) are non-connectable advertisement packets used by client device 150 to open (or wake up) a mobile access application on the client device 150. Other devices, such as other readers, within radio frequency (RF) range receive the advertisement packets from the broadcasting reader, but those other devices may be configured not to respond (i.e., ignore the advertisement packets).

[0023] Additionally, the readers 102-108 may broadcast telemetry advertisement packets intended for other readers within RF range to read and respond. In the example of FIG. 1, reader 104 and reader 106 are within RF range of reader 102. Reader 106 and reader 108 are within RF range of each other. However, reader 102 may not be within RF range of reader 108, and, likewise, reader 104 may not be within RF range of reader 108. Therefore, reader 102 or reader 104 cannot directly communicate with reader 108. But, as described in further detail below, reader 102 or reader 104 may send a message using the techniques described herein to reader 106, which in turn may transmit that message using another telemetry advertisement packet to reader 108.

[0024] The telemetry advertisement packets can enable wireless connection between readers within RF range. As described in further detail below, the reader-to-reader channel may be used to relay information, such as security alarms and sleep notifications. A telemetry advertisement packet may have a limited size. In some examples, a reader can transmit up to 31 bytes of data in a telemetry advertisement packet.

[0025] After receiving a telemetry advertisement packet from a transmitting reader, a receiving reader may transmit a scan request to the transmitting reader. The transmitting reader, in response, can transmit an additional scan response packet. The scan response packet may have a limited size. In some examples, a reader can transmit up to 31 bytes of data in a scan response packet. Additionally or alternatively, a secure data connection can be established between two readers to transmit more amount of data. As described in further detail below, time multiplexed connections can be used. In some examples, a reader (e.g., reader 102) can communicate with a client device 150 while also communicating with another reader (e.g., reader 106) using time multiplexed communications. In some examples, the reader can take on different roles in the communications. For example, reader 102 mayoperate as a peripheral device to a client device 150, which operates as a central device, for credential exchange and verification. The reader 102 may also act as a central device to another reader 106 for reader-to-reader communication, where reader 106 operates as a peripheral device.

[0026] FIG. 2 is an example timing diagram for transmitting advertisement packets by a reader in a PACS. At time tl, reader 102 transmits a lock advertisement packet. The lock advertisement packet is broadcasted and is intended to be received by client devices, such as client device 150, when the client devices are within RF range of reader 102. The lock advertisement packet may also be received by other readers, such as reader 106, within RF range of reader 102. However, other readers may ignore the lock advertisement packet because it is intended for client devices. As described herein, client device 150 may initiate a credential exchange session in response to receiving lock advertisement packet.

[0027] At time t2, reader 102 transmits a beacon advertisement packet. The beacon advertisement packet is broadcasted and is intended to be received by client devices, such as client device 150, when the client devices are within RF range of reader 102. The beacon advertisement packet may also be received by other readers, such as reader 106, within RF range of reader 102. However, other readers may ignore the beacon advertisement packet because it is intended for client devices. As described herein, client device 150 may open (or wake up) a mobile access application on the client device 150 in response to receiving beacon advertisement packet.

[0028] At time t3, reader 102 transmits a telemetry advertisement packet. The telemetry advertisement packet is broadcasted and is intended to be received by other readers, such as reader 106, within RF range of reader 102. Reader 102 may transmit information, such as a notification for security breach, sleep mode, etc., in the telemetry advertisement packet. The telemetry advertisement packet may also include identification information of reader 102. The telemetry advertisement packet may also be received by other devices, such as client devices, within RF range of reader 102. However, those other devices may ignore the telemetry advertisement packet because it is intended for other readers.

[0029] The advertisement packet transmission schedule may then repeat, transmitting the different advertisement packets in fixed intervals. For example, reader 102 may transmit a lock advertisement packet at time t4, a beacon advertisement packet at time t5, a telemetry advertisement packet at time t6, and so on. Moreover, other readers, such as reader 106, may be concurrently transmitting advertisement packets based on their respective advertisementpacket transmission schedules.

[0030] Telemetry advertisement packets may be used by readers in a PACS for a variety of applications, such as security and sleep mode notifications and firmware upgrade procedures.

[0031] FIG. 3 is a flow diagram of a method 300 for transmitting security alarm notifications. Below, method 300 is described with reference to the PACS 100 described above with reference to FIG. 1. At operation 302, reader 102 detects a security breach. For example, an intruder may be tampering with the reader 102. In some examples, the intruder may disconnect the reader 102 from the controller 110, and therefore reader 102 cannot communicate with the controller 110 to alert controller 110 of the security breach.

[0032] At operation 304, reader 102 generates a telemetry advertisement packet including a notification of the security breach at reader 102. The telemetry advertisement packet may include identification information of the reader 102. The notification may include indication that a security breach has occurred at reader 102. In some examples, this information may be equal to or less than 31 bytes.

[0033] At operation 306, reader 102 transmits the telemetry advertisement packet. The reader 102 may broadcast the telemetry advertisement packet so that readers within RF range of reader 102 can receive the telemetry advertisement packet.

[0034] At operation 308, reader 106, which is within RF range of reader 102, receives the telemetry advertisement packet. The reader 106 may extract the security breach notification in the telemetry advertisement packet. In some examples, reader 106 may trigger a security alarm, such as a siren with flashing lights, in response to receiving the telemetry advertisement packet with the security breach notification from reader 102.

[0035] At operation 310, reader 106 may a transmit a telemetry advertisement packet including information about the security breach at reader 102. The reader 106 may broadcast the telemetry advertisement packet so that readers within RF range of reader 106 can receive the telemetry advertisement packet. In some examples, the reader 106 may re-transmit the security breach notification received from reader 102 including identification of the initial security breach at reader 102.

[0036] At operation 312, reader 108, which is within RF range of reader 106 but not within RF range of reader 102, receives the telemetry advertisement packet from reader 106. The reader 108 may extract the security breach notification in the telemetry advertisement packet. In some examples, reader 108 may trigger a security alarm, such as a siren withflashing lights, in response to receiving the telemetry advertisement packet with the security breach notification from reader 102.

[0037] The method 300 may continue with the security breach notification being propagated to the respective readers in PACS 100. Hence, the use of telemetry advertisement packets can enable quick notification of security breaches in different parts of the PACs even if some components, such as the controller 110, are compromised. In this example, a security guard located in the third room can be quickly notified by the security alarm being triggered at reader 108 in response to receiving the telemetry advertisement packet from reader 106 including the notification of the security breach at reader 102 in a completely different room in a different part of the building.

[0038] FIG. 4 is a flow diagram of a method 400 for sleep mode notifications. Below, method 400 is described with reference to the PACS 100 described above with reference to FIG. 1. At operation 402, reader 102 determines that it can enter sleep mode to conserve power. For example, a client device may not have engaged with the reader 102 for a specified time.

[0039] At operation 404, reader 102 generates a telemetry advertisement packet including a notification that it is entering sleep mode. The telemetry advertisement packet may include identification information of the reader 102.

[0040] At operation 406, reader 102 may transmit the telemetry advertisement packet. The reader 102 may broadcast the telemetry advertisement packet so that readers within RF range of reader 102 can receive the telemetry advertisement packet. At operation 408, the reader 102 enters sleep mode.

[0041] At operation 410, reader 106, which is within RF range of reader 102, receives the telemetry advertisement packet. The reader 106 may extract the sleep mode notification in the telemetry advertisement packet. The reader 106 may determine that reader 106 can enter sleep mode, too, based receiving the notification that reader 102 has entered sleep mode.

[0042] At operation 412, reader 106 transmits a telemetry advertisement packet including information a sleep mode notification about reader 106. The reader 106 may broadcast the telemetry advertisement packet so that readers within RF range of reader 106 can receive the telemetry advertisement packet. In some examples, the telemetry advertisement packet transmitted by reader 106 may include information that reader 106 is entering sleep mode as well as reader 102. At operation 414, reader 106 enters sleep mode.

[0043] At operation 416, reader 108, which is within RF range of reader 106 but not within RF range of reader 102, receives the telemetry advertisement packet from reader 106. The reader 108 may extract the sleep mode notification in the telemetry advertisement packet.

[0044] The method 400 may continue with the sleep mode notification being propagated to the respective readers in PACS 100. Thus, telemetry advertisement messages may be used to conserve power by synchronizing sleep modes with different readers. Wake up notifications may communicated similarly. That is, reader 102 may wake up from sleep mode because a new client device begins engagement with reader 102. Reader 102 may then generate and transmit a telemetry advertisement packet notifying readers within RF range of its wake-up operation. The readers that receive the notification (e.g., reader 106) may wake up from sleep mode in response to receiving the notification and transmit their own wake up notifications to other readers and so on.

[0045] The telemetry advertisement packets may be used to initiate more substantial data communication. FIG. 5 is a flow diagram for a method 500 for establishing a data pipeline between two readers. Below, method 500 is described with reference to the PACS 100 described above with reference to FIG. 1. At operation 502, reader 102 transmits a telemetry advertisement packet. The reader 102 may broadcast the telemetry advertisement packet to readers within RF range. The telemetry advertisement packet may include a notification for more substantial data communication, such as transmission of a firmware upgrade.

[0046] At operation 504, reader 106 may receive the telemetry advertisement packet from reader 102. Reader 106 may extract the notification for more substantial data communication.

[0047] At operation 506, reader 106 and reader 102 may establish a data session for reader-to-reader data communication. In some examples, reader 106 and reader 102 may use a dedicated channel for the data session. For example, reader 102 may transmit data, such as a firmware upgrade, to reader 106 in the data session. Here, reader 102 may operate as a central entity while reader 106 may operate as a peripheral entity in the data session.

[0048] Reader 102 may also simultaneously communicate with client devices. At operation 508, reader 102 transmits a lock and / or beacon advertisement packet. Reader 102 may broadcast the lock and / or beacon advertisement packet so that client devices within RF range can receive and respond.

[0049] At operation 510, client device 150 receives the lock and / or beaconadvertisement packet. At operation 512, the client device 150 and reader 102 may establish a data session for credential exchange and verification, as described above. Here, the reader 102 may operate as a peripheral entity while the client device may operate as a central entity in the data session.

[0050] The two data sessions may be conducted concurrently using time multiplexed communication. Reader 102 may operate as a central entity in the data session with the other reader 106, and reader 102 may operate as peripheral entity in the data session with the client device 150. At a baseband level, the packets directed to different devices may be sent in a time multiplexed manner. The multiplex communication can affect throughput of an individual channel as the baseband connection is shared between multiple devices.

[0051] In some examples, the data session for exchanging credentials with the client device 150 is prioritized. In this case, when the data session between reader 102 and client device 150 is established, the reader 102 pauses the data session with other reader 102. After the credentials are exchanged and the reader authorizes or denies access to the client device 150 and the data session between the reader 102 and client device 150 is terminated, reader 102 may resume the data session with reader 106.

[0052] Configuration updates can be installed using the reader-to-reader connections described herein. In conventional systems, a technician updates each reader manually. Typically, the technician connects to a reader through a physical connection or a short-range wireless communication connection. That is, a technician must manually go to each reader for the configuration update procedure. For example, a technician approaches a first reader, connects to the first reader, and updates the configurations on the first reader. The technician then approaches a second reader, connects to the second reader, and updates the configurations on the second reader and so on.

[0053] Additionally, some access control systems may be configured to require multiple factor authentication for user credentials. The disclosures herein may also be adapted to support improved implementation of such additional authentication. For example, in one such embodiment, access control readers may be configured to require an additional factor authentication as part of granting access. These additional factor authentications may include any number of approaches, such as biometric, pin code, one-time code, location verification, and / or verification through an additional communication medium other than a near-field communication such as Wi-Fi, Bluetooth, etc. Upon satisfaction of the additional factor authentication, the confirming reader may broadcast telemetry advertisement packetsindicating that additional factor authentication has been completed for the credential. This completion information may then propagate throughout the system according to the disclosures herein, informing the other readers within the access control system. The completion information may also include temporal data, such as a date / time stamp, to correspond to completion of the additional factor authentication. In response to receiving the completion information, a subsequent reader within the access control system receiving a subsequent access request from the same credential may then be configured to bypass additional factor authentication. This bypass may be configured to be for a duration of time after the initial completion of additional factor authentication, such as within a workday, or predefined set of hours.

[0054] Alternatively or in addition, the access control system may be configured to bypass additional factor authentication for subsequent access attempts until the user has been detected to exit the boundaries of the access control system. This may be useful in secured facilities with controlled entrance / egress points. The user’s entrance into the facility may require additional factor authentication, and once obtained, the system then bypasses subsequent requests until the user exits the facility. Upon exit, the access control reader at the point of exit may then broadcast a telemetry advertisement packet to propagate information indicating that the user has exited to the other readers in the access control system. In response, the readers may then reset their state to require additional factor authentication again. This may be useful in conjunction with a system providing a time period of bypass because the user’s exit from the facility may be prior to the endpoint of the predefined bypass period. The system may be configured to reset status rather than wait for the predefined bypass period to conclude.

[0055] Similarly, in other embodiments, the access control system may be configured to require multiple factor authentication, however, access may be provided to the user while the additional authentication process completes. This may be particularly useful in situations where the authentication process comprises securely transmitting a one-time code from the system to a computing device associated with the user and then receiving an affirmative response from the associated computing device within a predefined period of time. Due to communications delays or other factors, the additional authentication may not be instantaneously completed. However, access could be temporarily granted while the authentication process completes. Upon completion, telemetry advertisement packets could be used to propagate the completion information throughout the system. Similarly, if theadditional authentication is not completed in time or fails, telemetry advertisement packets could be used to propagate the failure information throughout the system, informing the other access control readers that the credential still requires additional factor authentication. A subsequent access request may be handled more strictly to re-request additional factor authentication as a requirement to gain further access. The failure message may also be propagated to security personnel in a similar manner for follow-up.

[0056] In other embodiments, the telemetry advertisement packets could be used to broadcast information about a temporary guest pass issued by an authorized client device within communication range of a reader in the access control system. The temporary guest pass information may include information identifying which select readers are intended to grant access for the guest pass, and the information would propagate throughout the access control system to update those select readers. Revocation or alteration of the temporary guest pass may also be conducted in a similar manner by propagating information to remove or change access for the guest pass from the same or different specifically identified readers.

[0057] FIG. 6 is a flow diagram for a method 600 for updating configurations on a plurality of readers. Below, method 600 is described with reference to the PACS 100 described above with reference to FIG. 1. At operation 602, a master reader is selected. For example, a technician can select reader 108 as the master reader because of its convenient location. At operation 604, the technician can update the configurations on selected master reader (reader 108). For example, the technical can use a configuration card to perform the configuration update. In some examples, the technician can use a smart phone application for the configuration update. After the configuration update is completed on reader 108, reader- to-reader communication techniques described herein can be used to automatically update the configurations of the other readers.

[0058] At operation 606, reader 108 transmits the configuration update to reader 106 using the techniques described herein (e.g., broadcasting telemetry advertisement packets to establish data session). At operation 608, reader 106 may install the configurations update received from reader 108.

[0059] At operation 610, reader 106 transmits the configuration update to reader 102 and 104 using the techniques described herein because both reader 102 and 104 are within RF range of reader 106. At operations 612 and 614, reader 102 and reader 104 install the configurations update received from reader 106, respectively. Method 600 may continue with configuration update being propagated to the respective readers in PACS 100.Therefore, readers may be configured and updated with minimal technician effort. A technician may start the update process on one reader, and the readers can then automatically relay the update to other readers. Moreover, this automatic configuration relay technique can be compatible to legacy readers with older protocol connections (e.g., Wiegand) with the controller.

[0060] In some examples, a PACS may be configured to use the non-reception of scheduled telemetry advertisement packets to indicate a fault in a reader. For example, a set of readers in a PACS may be designated as “buddy” readers. In “buddy” mode, a reader transmits telemetry advertisement packets to its “buddy” reader at scheduled intervals. Therefore, the non-reception of a telemetry advertisement packet at a scheduled time can indicate a fault at the transmitting reader (e.g., security breach, malfunction, etc.)

[0061] FIG. 7 is a flow diagram of a method 700 for “buddy” communication between readers. Below, method 700 is described with reference to the PACS 100 described above with reference to FIG. 1. At operation 702, reader 102 generates a telemetry advertisement packet. The telemetry advertisement packet may include identification information of the reader 102.

[0062] At operation 704, reader 102 transmits the telemetry advertisement packet. The reader 102 may broadcast the telemetry advertisement packet so that readers within RF range of reader 102 can receive the telemetry advertisement packet.

[0063] At operation 706, reader 104, which is within RF range of reader 102, receives the telemetry advertisement packet. The reader 104 may extract the information in the telemetry advertisement packet.

[0064] At operation 708, reader 104 evaluates the received telemetry advertisement packet to determine whether reader 102 should be selected as a “buddy” reader. For example, reader 104 may evaluate information, such as signal power level, consistency of packets, packet advertisement interval of telemetry packets from reader 102. For example, if the signal from the selected reader (e.g., reader 102) is inconsistent in terms of signal strength, advertisement interval or overall consistency, then a reader (e.g., reader 104) can refuse to enter in to a “buddy” mode of operation with the selected reader.

[0065] However, if the selected criteria are met, at operation 710, reader 104 enters into “buddy” mode of operation with reader 102. Reader 102 and reader 104 may then transmit scheduled telemetry advertisement packets to each other in “buddy” mode of operation. The periodic advertisement packets (telemetry packet) originating from a specific reader can havea secure irrefutable identification attached to it so that non availability of advertisement packet can be rightly attributed to non-availability of a specific reader in the system.

[0066] At operation 712, reader 104 detects non-availability of reader 102 based on “buddy’ mode operation. For example, reader 104 may not receive an advertisement packet from reader 102 at a scheduled time.

[0067] At operation 714, reader 104 determines a fault at reader 102 based on the detected non-availability of reader 102. In some examples, reader 104 may trigger a security alarm, such as a siren with flashing lights, in response to not receiving the telemetry advertisement packet in “buddy” mode of operation from reader 102.

[0068] FIG. 8 illustrates a block diagram schematic of various example components of an example machine 800 that can be used as, for example, readers 102-108. Examples, as described herein, can include, or can operate by, logic or a number of components, modules, or mechanisms in machine 800. Modules may be hardware, software, or firmware communicatively coupled to one or more processors in order to carry out the operations described herein. Generally, circuitry (e.g., processing circuitry) is a collection of circuits implemented in tangible entities of machine 800 that include hardware (e.g., simple circuits, gates, logic, etc.). Circuitry membership can be flexible over time. Circuitries include members that can, alone or in combination, perform specified operations when operating. In some examples, hardware of the circuitry can be immutably designed to carry out a specific operation (e.g., hardwired). In some examples, the hardware of the circuitry can include variably connected physical components (e.g., execution units, transistors, simple circuits, etc.) including a machine readable medium physically modified (e.g., magnetically, electrically, moveable placement of invariant massed particles, etc.) to encode instructions of the specific operation. In connecting the physical components, the underlying electrical properties of a hardware constituent are changed, for example, from an insulator to a conductor or vice versa. The instructions permit embedded hardware (e.g., the execution units or a loading mechanism) to create members of the circuitry in hardware via the variable connections to carry out portions of the specific operation when in operation. Accordingly, in some examples, the machine readable medium elements are part of the circuitry or are communicatively coupled to the other components of the circuitry when the device is operating. In some examples, any of the physical components can be used in more than one member of more than one circuitry. For example, under operation, execution units can be used in a first circuit of a first circuitry at one point in time and reused by a second circuit inthe first circuitry, or by a third circuit in a second circuitry at a different time. Additional and / or more specific examples of components with respect to machine 800 follow.

[0069] In some embodiments, machine 800 can operate as a standalone device or can be connected (e.g., networked) to other machines. In a networked deployment, machine 800 can operate in the capacity of a server machine, a client machine, or both in server-client network environments. In some examples, machine 800 can act as a peer machine in a peer- to-peer (P2P) (or other distributed) network environment. Machine 800 can be or include a personal computer (PC), a tablet PC, a set-top box (STB), a personal digital assistant (PDA), a mobile telephone, a web appliance, a network router, switch or bridge, or any machine capable of executing instructions (sequential or otherwise) that specify actions to be taken by that machine. Further, while only a single machine is illustrated, the term “machine” shall also be taken to include any collection of machines that individually or jointly execute a set (or multiple sets) of instructions to perform any one or more of the methodologies discussed herein, such as cloud computing, software as a service (SaaS), other computer cluster configurations.

[0070] Machine (e.g., computer system) 800 can include a hardware processor 802 (e.g., a central processing unit (CPU), a graphics processing unit (GPU), a hardware processor core, or any combination thereof) and a main memory 804, a static memory (e.g., memory or storage for firmware, microcode, a basic-input-output (BIOS), unified extensible firmware interface (UEFI), etc.) 806, and / or mass storage 808 (e.g., hard drives, tape drives, flash storage, or other block devices) some or all of which can communicate with each other via an interlink (e.g., bus) 830. Machine 800 can further include a display device 810 and an input device 812 and / or a user interface (UI) navigation device 814. Example input devices and UI navigation devices include, without limitation, one or more buttons, a keyboard, a touch-sensitive surface, a stylus, a camera, a microphone, etc.). In some examples, one or more of the display device 810, input device 812, and UI navigation device 814 can be a combined unit, such as a touch screen display. Machine 800 can additionally include a signal generation device 818 (e.g., a speaker), a network interface device 820, and one or more sensors 816, such as a global positioning system (GPS) sensor, compass, accelerometer, or other sensor. Machine 800 can include an output controller 828, such as a serial (e.g., universal serial bus (USB), parallel, or other wired or wireless (e.g., infrared (IR), NFC, etc.) connection to communicate or control one or more peripheral devices (e.g., a printer, card reader, etc.).

[0071] Processor 802 can correspond to one or more computer processing devices or resources. For instance, processor 802 can be provided as silicon, as a Field Programmable Gate Array (FPGA), an Application-Specific Integrated Circuit (ASIC), any other type of Integrated Circuit (IC) chip, a collection of IC chips, or the like. As a more specific example, processor 802 can be provided as a microprocessor, Central Processing Unit (CPU), or plurality of microprocessors or CPUs that are configured to execute instructions sets stored in an internal memory 822 and / or memory 804, 806, 808.

[0072] Any of memory 804, 806, and 808 can be used in connection with the execution of application programming or instructions by processor 802 for performing any of the functionality or methods described herein, and for the temporary or long-term storage of program instructions or instruction sets 824 and / or other data for performing any of the functionality or methods described herein. Any of memory 804, 806, 808 can comprise a computer readable medium that can be any medium that can contain, store, communicate, or transport data, program code, or instructions 824 for use by or in connection with machine 800. The computer readable medium can be, for example but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device. More specific examples of suitable computer readable medium include, but are not limited to, an electrical connection having one or more wires or a tangible storage medium such as a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or EEPROM), Dynamic RAM (DRAM), a solid-state storage device, in general, a compact disc read-only memory (CD-ROM), or other optical or magnetic storage device. As noted above, computer- readable media includes, but is not to be confused with, computer-readable storage medium, which is intended to cover all physical, non-transitory, or similar embodiments of computer- readable media.

[0073] Network interface device 820 includes hardware to facilitate communications with other devices over a communication network, such as the one or more networks described above, utilizing any one of a number of transfer protocols (e.g., frame relay, internet protocol (IP), transmission control protocol (TCP), user datagram protocol (UDP), hypertext transfer protocol (HTTP), etc.). Example communication networks can include a local area network (LAN), a wide area network (WAN), a packet data network (e.g., the Internet), mobile telephone networks (e.g., cellular networks), Plain Old Telephone (POTS) networks, wireless data networks (e.g., networks based on the IEEE 802.11 family ofstandards known as Wi-Fi or the IEEE 802.16 family of standards known as WiMax), networks based on the IEEE 802.15.4 family of standards, and peer-to-peer (P2P) networks, among others. In some examples, network interface device 820 can include an Ethernet port or other physical jack, a Wi-Fi card, a Network Interface Card (NIC), a cellular interface (e.g., antenna, filters, and associated circuitry), or the like. In some examples, network interface device 820 can include one or more antennas to wirelessly communicate using at least one of single-input multiple-output (SIMO), multiple-input multiple-output (MIMO), or multiple-input single-output (MISO) techniques.Additional Examples

[0074] Example 1 includes subject matter relating to a method comprising: transmitting, by a first reader of a physical access control system, a first advertisement packet, wherein the first advertisement packet is directed to one or more client devices within radio frequency (RF) range of the first reader; receiving, by the first reader, a first response by a client device to the first advertisement packet; receiving, by the first reader, a set of credentials from the client device to perform credential verification associated with the client device; and transmitting, by the first reader, a second advertisement packet, wherein the second advertisement packet is directed to one or more readers in the physical access control system within RF range of the first read.

[0075] In Example 2, the subject matter of Example 1, wherein the first advertisement packet and the second advertisement packet are broadcasted using a Bluetooth low energy (BLE) protocol.

[0076] In Example 3, the subject matter any of Examples 1 to 2, wherein the second advertisement packet comprises information regarding a security breach at the first reader. Optionally, one or more readers receiving the second advertisement packet may in response perform one or more actions of triggering a security alarm, such as a siren or flashing light, rebroadcasting the security breach notification, or notifying an administrator or security personnel.

[0077] In Example 4, the subject matter of any of Examples 1 to 3, wherein the second advertisement packet comprises information regarding sleep mode or wake-up operation at the first reader. Optionally, this sleep or wake-up notification may be re-broadcast to other readers within RF range.

[0078] In Example 5, the subject matter of any of Examples 1 to 4, further comprising: receiving, by the first reader, a scan request message from a second reader in response to thesecond advertisement packet; and transmitting, by the first reader, a scan response packet to the second reader in response to the scan request message.

[0079] In Example 6, the subject matter of any of Examples 1 to 5, further comprising: establishing a data session between the first reader and a second reader based on the second advertisement packet; and transmitting, by the first reader, a configuration update to the second reader using the data session.

[0080] In Example 7, the subject matter of any of Examples 1 to 6, wherein the second advertisement packet includes telemetry information about the first reader.

[0081] In Example 8, the subject matter of any of Examples 1 to 7, wherein the physical access control system is configured to request an additional factor authentication for the credential user or user device, including one or more of biometric, PIN code, location verification, or messaging over additional secure communication channels other than near- field communication such as Wi-Fi, Bluetooth, etc.

[0082] In Example 9, the subject matter of Example 8, wherein the second advertisement packet includes information indicating the first reader has completed additional factor authentication for the credential user or user device.

[0083] In Example 10, the subject matter of Example 8, wherein the second advertisement packet includes information indicating the first reader has not been able to complete additional factor authentication for the credential user or user device.

[0084] In Example 11, the subject matter of Example 8, wherein the second advertisement packet includes information indicating the credential user or user device failed to complete additional factor authentication with the first reader.

[0085] In Example 12, the subject matter of any of Examples 1 to 11, wherein the second advertisement packet includes information uniquely associated with the credential user or user device.

[0086] In Example 13, the subject matter of any of Examples 1 to 12, wherein the second advertisement packet includes temporal information associated with the authentication request.

[0087] In Example 14, the subject matter of any of Examples 1 to 13, wherein the second advertisement packet includes information generated randomly.

[0088] In Example 15, the subject matter of any of Examples 9, 12-14, wherein the one or more readers in the physical access control system within RF range of the first read are configured to bypass additional authentication requests in response to receiving the secondadvertisement packet.

[0089] In Example 16, the subject matter of any of Examples 10, 12-14, wherein the one or more readers in the physical access control system within RF range of the first read are configured to re-request additional authentication in response to receiving the second advertisement packet.

[0090] In Example 17, the subject matter of any of Examples 11-14, wherein the one or more readers in the physical access control system within RF range of the first read are configured to refuse access to the credential user or user device in response to receiving the second advertisement packet, and optionally to re-request additional authentication as a condition to granting access if additional authentication is successful.

[0091] In Example 18, the subject matter of any of Examples 15-17, wherein the one or more readers in the physical access control system within RF range of the first read are configured to bypass additional authentication requests for a predefined period of time after receiving the second advertisement packet containing information indicating additional factor authentication was successfully completed.

[0092] In Example 19, the subject matter of any of Examples 8-18, wherein the physical access control system further includes one or more exit readers configured to register the credential user or user device has exited a controlled space, wherein the controlled space optionally contains one or more other readers of the physical access control system.

[0093] In Example 20, the subject matter of Examples 19, wherein one of the exit readers transmits an exit advertisement packet, wherein the exit advertisement packet is directed to one or more readers in the physical access control system within RF range of the transmitting exit reader.

[0094] In Example 21, the subject matter of any of Examples 19-20, wherein the one or more readers in the physical access control system cease bypassing the additional authentication request process for the credential user or user device in response to receiving the exit advertisement packet associated with the credential user or user device.

[0095] In Example 22, the subject matter of any of Examples 1-21, wherein the second advertising packet includes information associated with authorizing access for a temporary guest pass granted by the credential user or user device.

[0096] In Example 23, the subject matter of any of Examples 1-21, wherein the second advertising packet further includes information indicating which of the one or more readers inthe physical access control system are permitted to accept the temporary guest pass, thereby defining a limited, specific access authorization for the temporary guest pass.

[0097] In Example 24, the subject matter of any of Examples 22-23, wherein the second advertising packet includes information associated with revoking or altering the authorized access for the temporary guest pass granted by the credential user or user device, which may be initiated on demand by the credential user or user device or may be based on predetermined rules such as the conclusion of a predefined period of time, an attempt to access a denied space over a predefined threshold number of times, an exit advertisement packet associated with one or more of the temporary guest pass, the credential user, or the user device.

[0098] In Example 25, the subject matter of any of Examples 1-24, wherein multiplexed communication is used to transmit two or more data sessions concurrently.

[0099] Example 26. A reader device comprising at least one hardware processor; and at least one memory storing instructions that, when executed by the at least one hardware processor, cause the at least one hardware processor to perform operations implementing any one of example methods 1 to 25.

[0100] Example 27. A machine-readable medium embodying instructions that, when executed by a machine, cause the machine to perform operations implementing any one of example methods 1 to 25.Additional Notes

[0101] The above detailed description includes references to the accompanying drawings, which form a part of the detailed description. The drawings show, by way of illustration, specific embodiments that can be practiced. These embodiments may also be referred to herein as “examples.” Such embodiments or examples can include elements in addition to those shown or described. However, the present inventors also contemplate examples in which only those elements shown or described are provided. Moreover, the present inventors also contemplate examples using any combination or permutation of those elements shown or described (or one or more aspects thereof), either with respect to a particular example (or one or more aspects thereof), or with respect to other examples (or one or more aspects thereof) shown or described herein. That is, the above-described embodiments or examples or one or more aspects, features, or elements thereof can be used in combination with each other.

[0102] As will be appreciated by one of skill in the art, the various embodiments of thepresent disclosure may be embodied as a method (including, for example, a computer- implemented process, a business process, and / or any other process), apparatus (including, for example, a system, machine, device, computer program product, and / or the like), or a combination of the foregoing. Accordingly, embodiments of the present disclosure or portions thereof may take the form of an entirely hardware embodiment, an entirely software embodiment (including firmware, middleware, microcode, hardware description languages, etc.), or an embodiment combining software and hardware aspects. Furthermore, embodiments of the present disclosure may take the form of a computer program product on a computer-readable medium or computer-readable storage medium, having computerexecutable program code embodied in the medium, that define processes or methods described herein. A processor or processors may perform the necessary tasks defined by the computer-executable program code. In the context of this disclosure, a computer readable medium may be any medium that can contain, store, communicate, or transport the program for use by or in connection with the systems disclosed herein. As indicated above, the computer readable medium may be, for example but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device. More specific examples of suitable computer readable medium include, but are not limited to, an electrical connection having one or more wires or a tangible storage medium such as a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or EEPROM), a compact disc read-only memory (CD-ROM), or other optical, magnetic, or solid state storage device. As noted above, computer-readable media includes, but is not to be confused with, computer-readable storage medium, which is intended to cover all physical, non-transitory, or similar embodiments of computer-readable media.

[0103] As used herein, the terms “substantially” or “generally” refer to the complete or nearly complete extent or degree of an action, characteristic, property, state, structure, item, or result. For example, an object that is “substantially” or “generally” enclosed would mean that the object is either completely enclosed or nearly completely enclosed. The exact allowable degree of deviation from absolute completeness may in some cases depend on the specific context. However, generally speaking, the nearness of completion will be so as to have generally the same overall result as if absolute and total completion were obtained. The use of “substantially” or “generally” is equally applicable when used in a negative connotation to refer to the complete or near complete lack of an action, characteristic,property, state, structure, item, or result. For example, an element, combination, embodiment, or composition that is “substantially free of’ or “generally free of’ an element may still actually contain such element as long as there is generally no significant effect thereof.

[0104] In the foregoing description various embodiments of the present disclosure have been presented for the purpose of illustration and description. They are not intended to be exhaustive or to limit the invention to the precise form disclosed. Obvious modifications or variations are possible in light of the above teachings. The various embodiments were chosen and described to provide the best illustration of the principals of the disclosure and their practical application, and to enable one of ordinary skill in the art to utilize the various embodiments with various modifications as are suited to the particular use contemplated. All such modifications and variations are within the scope of the present disclosure as determined by the appended claims when interpreted in accordance with the breadth they are fairly, legally, and equitably entitled.

Claims

CLAIMS:

1. A method comprising: transmitting, by a first reader of a physical access control system, a first advertisement packet, wherein the first advertisement packet is directed to one or more client devices within radio frequency (RF) range of the first reader; receiving, by the first reader, a first response by a client device to the first advertisement packet; receiving, by the first reader, a set of credentials from the client device to perform credential verification associated with the client device; and transmitting, by the first reader, a second advertisement packet, wherein the second advertisement packet is directed to one or more readers in the physical access control system within RF range of the first reader.

2. The method of claim 1, wherein the first advertisement packet and the second advertisement packet are broadcasted using a Bluetooth low energy (BLE) protocol.

3. The method of claim 1, wherein the second advertisement packet comprises information regarding a security breach at the first reader.

4. The method of claim 1, wherein the second advertisement packet comprises information regarding sleep mode operation at the first reader.

5. The method of claim 1, further comprising: receiving, by the first reader, a scan request message from a second reader in response to the second advertisement packet; and transmitting, by the first reader, a scan response packet to the second reader in response to the scan request message.

6. The method of claim 1, further comprising: establishing a data session between the first reader and a second reader based on the second advertisement packet; andtransmitting, by the first reader, a configuration update to the second reader using the data session.

7. The method of claim 1, wherein the second advertisement packet includes telemetry information about the first reader.

8. A reader device comprising: at least one hardware processor; and at least one memory storing instructions that, when executed by the at least one hardware processor, cause the at least one hardware processor to perform operations comprising: transmitting a first advertisement packet, wherein the first advertisement packet is directed to one or more client devices of a physical access control system within radio frequency (RF) range of the reader device; receiving a first response by a client device to the first advertisement packet; receiving a set of credentials from the client device to perform credential verification associated with the client device; and transmitting a second advertisement packet, wherein the second advertisement packet is directed to one or more readers in the physical access control system within RF range of the reader device.

9. The reader device of claim 8, wherein the first advertisement packet and the second advertisement packet are broadcasted using a Bluetooth low energy (BLE) protocol.

10. The reader device of claim 8, wherein the second advertisement packet comprises information regarding a security breach at the reader device.

11. The reader device of claim 8, wherein the second advertisement packet comprises information regarding sleep mode operation at the reader device.

12. The reader device of claim 8, the operations further comprising: receiving a scan request message from a second reader in response to the second advertisement packet; andtransmitting a scan response packet to the second reader in response to the scan request message.

13. The reader device of claim 8, the operations further comprising: establishing a data session between the reader device and a second reader based on the second advertisement packet; and transmitting a configuration update to the second reader using the data session.

14. The reader device of claim 8, wherein the second advertisement packet includes telemetry information about the reader device.

15. A machine-readable medium embodying instructions that, when executed by a machine, cause the machine to perform operations comprising: transmitting, by a first reader of a physical access control system, a first advertisement packet, wherein the first advertisement packet is directed to one or more client devices within radio frequency (RF) range of the first reader; receiving, by the first reader, a first response by a client device to the first advertisement packet; receiving, by the first reader, a set of credentials from the client device to perform credential verification associated with the client device; and transmitting, by the first reader, a second advertisement packet, wherein the second advertisement packet is directed to one or more readers in the physical access control system within RF range of the first reader.

16. The machine-readable medium of claim 15, wherein the first advertisement packet and the second advertisement packet are broadcasted using a Bluetooth low energy (BLE) protocol.

17. The machine-readable medium of claim 15, wherein the second advertisement packet comprises information regarding a security breach at the first reader.

18. The machine-readable medium of claim 15, wherein the second advertisement packet comprises information regarding sleep mode operation at the first reader.

19. The machine-readable medium of claim 15, further comprising: receiving, by the first reader, a scan request message from a second reader in response to the second advertisement packet; and transmitting, by the first reader, a scan response packet to the second reader in response to the scan request message.

20. The machine-readable medium of claim 15, further comprising: establishing a data session between the first reader and a second reader based on the second advertisement packet; and transmitting, by the first reader, a configuration update to the second reader using the data session.