BLE-based peer-to-peer wake-up system
A peer-to-peer communication system between mobile devices automatically re-establishes BLE services using Wi-Fi, addressing the challenge of terminated communication channels in access control systems, ensuring continuous and unobtrusive access.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- ASSA ABLOY AB
- Filing Date
- 2025-10-29
- Publication Date
- 2026-05-15
AI Technical Summary
Existing access control systems face challenges in managing seamless access through controlled portals when communication channels, such as Bluetooth Low Energy (BLE), are terminated due to low battery or other operating system issues, requiring user intervention to restart services.
A peer-to-peer communication mechanism between mobile devices is employed to automatically re-establish BLE services using a secondary communication channel, such as Wi-Fi, to maintain seamless access by sending a wake-up message to another mobile device to restart the BLE service without user intervention.
Ensures continuous and unobtrusive access control by automatically re-establishing communication channels, enhancing system reliability and user experience by maintaining seamless access even when primary communication channels fail.
Smart Images

Figure EP2025081226_15052026_PF_FP_ABST
Abstract
Description
BLE-BASED PEER-TO-PEER WAKE-UP SYSTEMPRIORITY APPLICATION^)
[0001] This application claims priority to Indian Provisional Patent Application No.202411086669, filed on November 11, 2024, the disclosure of which is incorporated by reference herein in its entirety.TECHNICAL FIELD
[0002] Embodiments illustrated and described herein generally relate to access control system architectures that grant access of authorized users to a controlled resource.BACKGROUND
[0003] Access control can include granting physical access to an authorized user through a controlled portal. A Physical Access Control System (PACS) authenticates and authorizes a person to pass through a physical access point, such as a secured door, to enter a controlled space. The access may be seamless where physical access is granted to an authorized user through a controlled portal without requiring intrusive actions of the user such as entering or swiping an access card at a card reader or entering a personal identification number (PIN) or password. Instead, a reader device may unobtrusively read information from the user’s credential device (e.g., a mobile phone) without user action. However, managing the interplay between credential devices and authentication devices can be challenging. The inventors have recognized a need for improvements in managing access-controlled spaces.BRIEF DESCRIPTION OF THE DRAWINGS
[0004] FIG. 1 is an illustration of an example of portions of an access control system structure.
[0005] FIG. 2 is a block diagram of an example of portions of a mobile communication device.
[0006] FIG. 3 is a flow diagram of an example of a method of operating a mobile communication device.
[0007] FIG. 4 is a flow diagram of another example of a method of operating a mobile communication device.
[0008] FIG. 5 is a block diagram of another example of portions of a mobile communication device.
[0009] FIG. 6 is an illustration of another example of portions of an access control system structure.DETAILED DESCRIPTION
[0010] FIG. 1 is an illustration of a basic PACS structure useful for an office application. The Access Credential includes credential information that may be a data object, a piece of knowledge (e.g., PIN, password, etc.), or a facet of the person’s physical being (e.g., face, fingerprint, etc.) that provides proof of the person’s identity. The Credential Device stores the credential information when the Access Credential is a data object. The Credential Device may be a mobile communication device, or mobile device 104 (e.g., a mobile phone, a computer tablet, personal digital assistants (PDAs), etc.
[0011] The Reader Device 102 receives the credential information of the Credential Device. The Reader Device 102 may include a wireless communication port to receive the credential information wirelessly from the Credential Device. The Reader Device 102 sends the credential information to an authentication device (e.g., an Access Controller 106). The authentication device may compare the credential information to an Access Control List and grant or deny access based on the comparison, such as by controlling an automatic lock on a door. In some examples, the authentication device is a server and the Reader Device 102 or an Access Controller 106 sends the credential information to the server (e.g., via local area network or LAN) for authentication. The server performs the authentication and returns an indication to the Access Controller 106 to grant or deny access. The functionality of the Access Controller 106 may be included in the Reader Device 102. These Reader Devices can be referred to as offline readers or standalone readers. If the unlocking mechanism is included as well, a device is referred to as smart door lock.
[0012] FIG. 2 is a block diagram of an example of portions of a mobile communication device or mobile device 104. The mobile device 104 includes a first communication channel 210 and a second communication channel 212. The first communication channel 210 includes a Physical Layer (PHY 214) and an antenna 216 to communicate with the Reader Device 102. The mobile device 104 communicates information to the Reader Device 102 using Bluetooth Low Energy (BLE) signaling or using other nearfield communication (NFC) signals. The second communication channel 212 includes another PHY 218 and another antenna 220 and may communicate information using Wi-Fi signaling.
[0013] The mobile device 104 includes processing circuitry 222 (e.g., a microprocessor, Central Processing Unit (CPU), or plurality of microprocessors or CPUs that are configured to execute instructions sets stored in a memory of the mobile device 104). The mobile device 104 includes a resource application 224 (or App). The resource application 224 includes instructions executable by the processing circuitry 222 to perform the functions described. The resource application 224 may be run by the processing circuitry 222 in the background and does not require input from the user or send notifications to the user that it is running. According to some examples, the resource application 224 is a resource access application. Performing the instructions of the resource access application causes the mobile device to communicate information (e.g., authentication information) to the authentication system to gain access to a resource. The resource may be a secured area and authentication of the mobile device 104 allows the user to gain access to the secured area through a physical access portal. In variations, the resource can be a virtual resource (e.g., a financial account) and authentication of the mobile device 104 gives the user rights to access the virtual resource.
[0014] Returning to FIG. 1, the example shows the mobile device 104 sending authentication information wirelessly to the authentication system to gain access through the secured door. The mobile device 104 may use BLE scanning by the first communication channel 210 to detect the Reader Device 102 of the authentication system, which may advertise using BLE. When the mobile device 104 detects the Reader Device 102, the mobile device 104 may send information to the Reader Device 102 via the first communication channel 210 using BLE or the second communication channel using Wi-Fi. Challenges to implementing a system such as the example system of FIG. 1 arise when the operating system (OS) of the mobile device 104 terminates the service of the first communication channel 210. For example, the OS may terminate service when the battery of the mobile device 104 becomes low. This may end the seamless access by the mobile device 104. The user of the mobile device 104 may have to manually restart service of the first communication channel 210 to send information to the authentication system.
[0015] When service of the first channel communication is terminated, peer-to-peer communications between mobile devices is used to communicate with the Reader Device 102. FIG. 1 shows a second mobile device 130. The second mobile device 104 also includesthe first communication channel 210, second communication channel 212 and the resource application 224. When the first mobile device 104 identifies the second mobile device 130 and determines that the second mobile device 130 has the service of the first communication channel terminated, the resource application 224 of the first mobile device 104 sends a secure wake-up message to the resource application 224 of the second mobile device 130 using the second communication channel 212. The secure wake-up message prompts the second mobile device 130 to autonomously restart service of its first communication channel 210. This peer-to-peer interaction results in a swift and seamless re-establishment of service of the second mobile device 130 without using external factors or intrusion to the user. Peer-to-peer communication can also resolve a situation where the first mobile device 104 loses service.
[0016] FIG. 3 is a flow diagram of an example of a method 300 of operating a mobile communication device. At block 305, a resource access application is performed or executed on the mobile communication device (e.g., mobile device 104 in FIG. 1). The resource access application communicates information with an authentication system using a first communication channel of the mobile communication device. The information is authentication information to prove the user has rights to gain access to a controlled resource.
[0017] At block 310, the resource access application determines that service for the first communication channel is unavailable. For example, the mobile device 104 may approach the Reader Device 102 and door in FIG. 1 and the resource access application determines that the service is terminated at that time. The resource access application may receive an indication that the service is terminated from the OS of the mobile device 104.
[0018] At block 315, the resource access application may initiate a discovery mode to detect another mobile device (e.g., mobile device 130 in FIG. 1) in response to detecting the terminated service. Mobile device 104 may determine that the service of the discovered other mobile device 130 is unavailable.
[0019] At block 320, when the other mobile device 130 is detected, the resource access application of mobile device 104 sends a wake-up message to the mobile device 130 to cause the mobile device 130 to wake up service of its first communication channel. The wake-up message may be sent using a second communication channel of mobile device 104. Mobile device 130 may be inside the controlled space but with terminated service (e.g., terminated BLE service). Mobile device 104 may detect that the service of mobile device 130 is terminated before sending the wake-up message. The wake-up message may be sent using Bluetooth Generic Attribute (GATT) characteristics. Mobile device 103 decodes the wake-up message and takes actions to wake up its terminated channel service. The resource accessapplication executing on mobile device 104 may display a prompt to send the wake-up message, and the resource access application executing on mobile device 130 may display a prompt to the user for consent to activate or wake-up the terminated service in response to receiving the wake-up message.
[0020] At block 325, authentication information is communicated from mobile device 104 to mobile device 130 peer-to-peer after sending the wake-up message to mobile device 130. The peer-to-peer communication may be performed using the second communication channel of mobile device 104 because service of the first communication charnel is unavailable. At block 330, the authentication information is communicated from the other mobile device 130 to the authentication system using the awakened communication channel service of mobile device 130. The authentication system grants access to mobile device 104 according to the authentication information communicated peer-to-peer to mobile device 130.
[0021] Additionally, further verifications or authentications may be implemented between the authentication system and the mobile devices, as well as between the mobile devices themselves. Preferably, this further verification or authentication of the peer-to-peer communication chain occurs prior to the sharing of any sensitive user-specific authentication information to ensure that the communication chain is secure and that the requests to be processed are valid.
[0022] FIG. 6 shows an example of the first mobile device 104 communicating indirectly with an authentication server 650 of an authentication system using a first communication channel 652 between the first mobile device 104 and the second mobile device 130, and the second communication channel 654 between the second mobile device 130 and the reader device 102. In certain examples, the second communication channel may utilize a more direct communication channel 656 between the second mobile device 130 and the authentication server 650, such as via WiFi 658 or cellular if supported by the authentication system. The second mobile device 130 may need to demonstrate it is a trusted device to one or both of the authentication system or the first mobile device 104 as part of the peer-to-peer communication process. Additionally, the authenticity of the first mobile device 104 may need to be verified by the authentication system while still communicating indirectly through the second mobile device 130.
[0023] In some embodiments, the mobile devices may be verified by the authentication system through use of shared key pairs. For example, the shared key pair for the second mobile device may be used for mutual authentication with the authentication system after the second mobile device’s first communication channel has been awakened. Inother examples, the authentication system may separately authenticate the second mobile device 130 at a different or earlier time (for example a prior transaction) that remains within a pre-configured window of time (e.g., within an hour or day, etc.) relative to the peer-to-peer communication attempt or other associated action, such as an attempt by the second mobile device 130 to verify authentication of the authentication system to communicate with via the first communication channel 652.
[0024] In other examples, the second mobile device 130 may be designated as a trusted device by the authentication system. For example, the second mobile device ID may be registered in the authentication system as a trusted device on a whitelist, e.g. a device belonging to an administrator or to security personnel. In other examples, the user of the second mobile device 130 may perform a login or verification action with the authentication server 650 to place the second mobile device 130 on a whitelist (either temporarily or until removed). Additionally, administrator-defined rules may be applied to determine whether the second mobile device 130 is considered a trusted device, such as setting a rule based upon whether the second mobile device 130 has presented a valid authentication credential within a pre-configured window of time. The authentication system may also maintain a blacklist that the second mobile device 130 is checked against to determine if it is not a valid trusted device, which would prevent it from being used in valid peer-to-peer communications. In other examples, the administrator-defined rules for a facility may include verifying that the second mobile device 130 has been granted access and has not yet exited the secure premises.
[0025] The foregoing trusted device (or blacklisted device) information may also be transmitted periodically to other user mobile devices such as the first mobile device 104, for use as part of authenticating between the first and second mobile devices. In other examples, the first mobile device 104 may authenticate the second mobile device using a shared key 660 associated with the first mobile device 104 prior to transmitting any sensitive authentication information for peer-to-peer communication via the second mobile device 130. In other examples, the authentication system may, after authenticating with the second mobile device, communicate a shared key 660 over the second communication channel 654 to use for verification between the first and second mobile devices.
[0026] In some embodiments, the authentication system may also verify that the first mobile device 104 is legitimate by utilizing a pair of keys for authentication stored on both the authentication system and the first mobile device. In some examples, the authentication system may generate a temporary code (e.g., a random code, cycling code, or code based on a transient metric such as date / time / counter) which the authentication system then encryptswith the first key in the key pair. The encrypted code is then transmitted to the first mobile device 104 via the second mobile device 130, and the first mobile device 104 decrypts the code using the first key and re-encrypts the code using the second key in the key pair. The first mobile device 104 then transmits the re-encrypted code to the authentication system via the second mobile device 130, and the authentication system decrypts the re-encrypted code using the second key to verify that the received code matches what was transmitted and thus validating the first mobile device 104.
[0027] In other embodiments, the authentication system may verify the first mobile device 104 using a shared key 660 associated with the first mobile device 104. For example, the first mobile device 104 may generate a temporary code containing at least an identifier unique to the first mobile device 104 along with a current date / time stamp. The temporary code is encrypted by the first mobile device 104 with the shared key and the encrypted code is then transmitted to the authentication system via the second mobile device 130 for decryption and validation that the identifier and date / time information matches with the current authentication request. In other examples, the authentication system may generate a temporary code as described above and transmit the code unencrypted to the first mobile device 104 via the second mobile device 130. The first mobile device 104 then encrypts the received code with the shared key and returns the encrypted message back to the authentication server 650 for decryption and verification using the shared key. Alternatively, the authentication server may encrypt the temporary code prior to transmission, whereby the first mobile device 104 would proceed to decrypt the message and transmit back for verification the unencrypted code via the second mobile device 130. Optionally, the first mobile device 104 may instead first apply a secure hash to the unencrypted code and transmit the hash result rather than the unencrypted code back to the authentication system via the second mobile device. The authentication system similarly performs the same secure hash on the originally generated code and compares it with the received hash result from the first mobile device as part of verification. Preferably, in order to further protect the messaging process, the foregoing may occur only after the second mobile device 130 has been authenticated as a trusted device by both the authentication system and the first mobile device 104. Thereafter, communications between the second mobile device 130 and either of the authentication system and the first mobile device 104 may also be over their own secure communication sessions, established after the authentication between them has completed.
[0028] Additionally, it would be appreciated that public-private key pairs may be adapted for use in conjunction with the foregoing disclosures for asymmetric encryptionand / or signing of messages. For example, with an asymmetric encryption, the public key is used for encryption and a corresponding secure private key is used to decrypt the message. In other examples, with signing messages, a secure private key is used to sign the message, and a corresponding public key is used to verify the validity of the signed message.
[0029] Returning to FIG. 2, in some examples the resource application 224 is a resource locating application. Performing the instructions of the resource locating application causes the mobile device 104 to transmit a scanning RF signal using the first communication channel 210 to locate resources. For instance, the mobile device 104 may transmit a scanning BLE signal to read RFID labels that identify resources such as assets (e.g., equipment) or to inventory items (e.g., inventory in a warehouse). In another example, the mobile device 104 may transmit a scanning BLE signal to locate mobile devices of other users to track or monitor location of the users. Termination of service of the scanning may interrupt the resource tracking of mobile devices.
[0030] FIG. 4 is a flow diagram of another example of a method 400 of operating a mobile communication device. At block 405, a resource locating application is performed or executed on the mobile communication device (e.g., mobile device 104 in FIG. 1). The resource locating application causes the mobile communication device to transmit a scanning RF signal using a first communication channel of the mobile communication device to locate resources.
[0031] At block 410, the resource locating application determines that service is unavailable for the first communication channel. At block 415, the resource locating application detects another mobile communication device (e.g., mobile device 130 in FIG. 1). The resource locating application of the first mobile device 104 may initiate a discovery mode to discover the other mobile device 130 in response to the determining that the service for its first communication channel is terminated. The resource locating application may display a notification on the mobile device 104 to the user that scanning using the first communication channel is terminated or otherwise unavailable and may display a prompt on the mobile device 104 to initiate the discovery mode.
[0032] At block 420, the resource locating application initiates sending a wake-up message to the other mobile device 130. The wake-up message may be sent using the second communication channel. The wake-up message causes the other mobile device 130 to wakeup its service for its first communication channel. The other mobile device 130 may be executing the resource locating application. The resource locating application of other mobile device 130 may wake-up signaling for the first communication channel in response todecoding the received wake-up message and begin transmiting an RF scanning signal using its awakened first communication channel to locate resources. The awakening and signaling may be automatic and seamless. In some examples, the resource locating application of the other mobile device 130 may display a prompt to the user to consent to activating service of the first communication channel in response to receiving the wake-up message. Resource locating information may be communicated peer-to-peer between resource locating applications of the mobile devices. This enables continuous tracking of assets and users using first communication channel signaling (e.g., BLE signaling) even though the signaling by one of the mobile devices was terminated.
[0033] FIG. 5 is a block diagram schematic of various example components of a mobile communication device for supporting the system architectures described and illustrated herein. The device 500 of FIG. 5 could be, for example, a mobile phone, a laptop or tablet computer that communicates with a reader device that authenticates credential information of authority, status, rights, and / or entitlement to privileges for the holder of the mobile communication device. At a basic level, a mobile communication device can include an interface (e.g., one or more antennas and Integrated Circuit (IC) chip(s)), which permits the device to exchange data with another device, such as a reader device.
[0034] With reference specifically to FIG. 5, additional examples of a mobile communication device 500 for supporting the system architecture described and illustrated herein may generally include one or more of a memory 514, processing circuitry such as a processor 512, one or more antennas 526, a communication port or communication module 530, a network interface device 532, a user interface 534, and a power source 536.
[0035] Memory 514 can be used in connection with the execution of application programming or instructions by processing circuitry, and for the temporary or long-term storage of program instructions or program instruction sets 538, as well as any data, data structures, and / or computer-executable instructions needed or desired to support the abovedescribed device architecture. For example, memory 514 can contain executable instructions that are used by a processor 512 of the processing circuitry to run other components of device 500, to detect termination of services and send a wakeup-signal, and / or to perform any of the functions or operations described herein, such as the example methods of FIG. 3 or FIG. 4 for example. Memory 514 can comprise a computer readable medium that can be any medium that can contain, store, communicate, or transport data, program code, or instructions for use by or in connection with device 500. The computer readable medium can be, for example but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductorsystem, apparatus, or device. More specific examples of suitable computer readable medium include, but are not limited to, an electrical connection having one or more wires or a tangible storage medium such as a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), Dynamic RAM (DRAM), any solid-state storage device, in general, a compact disc read-only memory (CD-ROM), or other optical or magnetic storage device. Computer-readable media includes, but is not to be confused with, computer-readable storage medium, which is intended to cover all physical, non-transitory, or similar embodiments of computer-readable media.
[0036] Processor 512 can correspond to one or more computer processing devices or resources. For instance, processor 512 can be provided as silicon, as a Field Programmable Gate Array (FPGA), an Application-Specific Integrated Circuit (ASIC), any other type of Integrated Circuit (IC) chip, a collection of IC chips, or the like. As a more specific example, processor 512 can be provided as a microprocessor, Central Processing Unit (CPU), or plurality of microprocessors or CPUs that are configured to execute instructions sets 542 stored in an internal processor memory and / or memory 514.
[0037] Antenna 526 can correspond to one or multiple antennas and can be configured to provide for wireless communications between device 500 and another device. Antenna(s) 526 can be coupled to one or more physical (PHY) layers 522 to operate using one or more wireless communication protocols and operating frequencies including, but not limited to, the IEEE 802.15.1, Bluetooth, Bluetooth Low Energy (BLE), near field communications (NFC), ZigBee, GSM, CDMA, Wi-Fi, RF, UWB, and the like. In an example, antenna 526 may include one or more antennas coupled to one or more physical layers 522 to operate using BLE for activity, communication, ranging, or radar.
[0038] Device 500 may additionally include a communication module 530 and / or network interface device 532. Communication module 530 can be configured to communicate according to any suitable communications protocol with one or more different systems or devices either remote or local to device 500. Network interface device 532 includes hardware to facilitate communications with other devices over a communication network utilizing any one of a number of transfer protocols (e.g., frame relay, internet protocol (IP), transmission control protocol (TCP), user datagram protocol (UDP), hypertext transfer protocol (HTTP), etc.). Example communication networks can include a local area network (LAN), a wide area network (WAN), a packet data network (e.g., the Internet), mobile telephone networks (e.g., cellular networks), Plain Old Telephone (POTS) networks,wireless data networks (e.g., IEEE 802.11 family of standards known as Wi-Fi, IEEE 802.16 family of standards known as WiMax), IEEE 802.15.4 family of standards, and peer-to-peer (P2P) networks, among others. In some examples, network interface device 532 can include an Ethernet port or other physical jack, a Wi-Fi card, a Network Interface Card (NIC), a cellular interface (e.g., antenna, filters, and associated circuitry), or the like. In some examples, network interface device 532 can include a plurality of antennas to wirelessly communicate using at least one of single-input multiple-output (SIMO), multiple-input multiple-output (MIMO), or multiple-input single-output (MISO) techniques. In some example embodiments, one or more of the antenna 526, communication module 530, and / or network interface device 532 or subcomponents thereof, may be integrated as a single module or device, function or operate as if they were a single module or device, or may comprise of elements that are shared between them.
[0039] User interface 534 can include one or more input devices and / or display devices. Examples of suitable user input devices that can be included in user interface 534 include, without limitation, one or more buttons, a keyboard, a mouse, a touch-sensitive surface, a stylus, a camera, a microphone, etc. Examples of suitable user output devices that can be included in user interface 534 include, without limitation, one or more LEDs, an LCD panel, a display screen, a touchscreen, one or more lights, a speaker, etc. It should be appreciated that user interface 534 can also include a combined user input and user output device, such as a touch-sensitive display or the like.
[0040] Power source 536 can be any suitable internal power source, such as a battery, capacitive power source or similar type of charge-storage device, etc., and / or can include one or more power conversion circuits suitable to convert external power into suitable power (e.g., conversion of externally supplied AC power into DC power) for components of the device 500. Device 500 can also include one or more interlinks or buses 544 operable to transmit communications between the various hardware components of the device. A system bus 544 can be any of several types of commercially available bus structures or bus architectures.
[0041] The systems and methods described herein provide a proactive mechanism to reestablish services (e.g., BLE services) for controlled access and resource locating when the services are terminated. The techniques described use peer-to-peer communication to automatically address terminated service without relying on action by the user.ADDITIONAL DISCLOSURE AND EXAMPLES
[0042] Example 1 includes subject matter such as a mobile communication device, comprising a first communication channel, processing circuitry operatively coupled to the first communication channel and the second communication channel, and a resource access application. The resource application includes instructions performable by the processing circuitry to cause the mobile communication device to communicate information with a reader device using the first communication channel, detect another mobile communication device, determine that service is unavailable for a first communication channel of the other mobile communication device, and send a service wake-up message to the other mobile communication device via the second communication channel.
[0043] In Example 2, the subject matter of Example 1 optionally includes the resource access application of the mobile communication device further including instructions to cause the mobile communication device to determine that service is unavailable for the first communication channel of the mobile communication device, and communicate authentication information to a resource access application of the other mobile communication device peer-to-peer via the second communication channel after sending the service wake-up message to the other mobile communication device.
[0044] In Example 3, the subject matter of Example 2 optionally includes the resource access application of the mobile communication device further including instructions to cause the mobile communication device to detect that an operating system of the mobile communication device terminated the service for the first communication channel, and initiate sending the service wake-up message in response to the detecting.
[0045] In Example 4, the subject matter of one or any combination of Examples 1-3 optionally includes the first communication channel being a Bluetooth communication channel, and the second communication channel being a Wi-Fi communication channel.
[0046] In Example 5, the subject matter of one or any combination of Examples 1-4 optionally includes the first communication channel being a near field communication channel, and the second communication channel being a secured communication channel.
[0047] In Example 6, the subject matter of one or any combination of Examples 1-5 optionally includes the resource access application of the mobile communication device further including instructions to cause the mobile communication device to run as a background application to send authentication information to the reader device.
[0048] In Example 7, the subject matter of one or any combination of Examples 1-6 optionally includes the resource access application of the mobile communication devicefurther including instructions to cause the mobile communication device to send authentication information to the reader device to gain access through a physical access portal.
[0049] In Example 8, the subject matter of one or any combination of Examples 1-7 optionally includes the resource access application of the mobile communication device further including instructions to cause the mobile communication device to transmit a scanning RF signal using the first communication channel to locate resources.
[0050] Example 9 includes subject matter (such as a method of operating a mobile communication device) or can optionally be combined with one or any combination of Examples 1-8 to include such subject matter, comprising executing a resource access application using the mobile communication device, wherein the resource access application is configured to communicate information with an authentication system using a first communication channel of the mobile communication device; detecting another mobile communication device and determining, by the resource access application, that service is unavailable for the first communication channel of the other mobile communication device; and sending a wake-up message to the other mobile communication device via a second communication channel to cause the other mobile communication device to wake-up its service for the first communication channel.
[0051] In Example 10, the subject matter of Example 9 optionally includes communicating, by the other mobile communication device, authentication information to a reader device of the authentication system using an awakened first communication channel service of the other mobile communication device.
[0052] In Example 11, the subject matter of one or both of Examples 9 and 10 optionally includes determining, by the resource access application on the mobile communication device, that service is unavailable for the first communication channel of the mobile communication device; communicating authentication information to the other mobile communication device peer-to-peer via the second communication channel after sending the wake-up message to the other mobile communication device; and communicating the authentication information to the authentication system using an awakened first communication channel service of the other mobile communication device.
[0053] In Example 12, the subject matter of Example 11 optionally includes the resource access application determining that an operating system of the mobile communication device terminated the service for the first communication channel.
[0054] In Example 13, the subject matter of one or both of Example 11 and 12 optionally includes the resource access application determining that Bluetooth communication is unavailable, and sending the wake-up message to the other mobile communication device using a Wi-Fi channel.
[0055] In Example 14, the subject matter of one or any combination of Examples 9- 13 optionally includes sending the wake-up message to the other mobile communication device via a secured communication channel to cause the other mobile communication device to wake-up its service for a near field communication channel.
[0056] In Example 15, the subject matter of one or any combination of Examples 9- 14 optionally includes the resource access application sending authentication information to a reader device of the authentication system using the first communication channel of the mobile communication device to gain access through a physical access portal.
[0057] In Example 16, the subject matter of one or any combination of Examples 9- 15 optionally includes displaying a prompt on a display of the mobile communication device to send the wake-up message displaying a prompt on a display of the other mobile communication device to activate service of the first communication channel in response to receiving the wake-up message.
[0058] In Example 17, the subject matter of one or any combination of Examples 9- 16 optionally includes determining, by the resource access application, that service for the first communication channel of the mobile communication device is terminated; and initiating a discovery mode to discover the other mobile communication device in response to the determining that the service for the first communication channel is terminated.
[0059] Example 18 includes subject matter (such as a mobile communication device) or can optionally be combined with one or any combination of Examples 1-17 to include such subject matter, comprising a first communication channel, a second communication channel, processing circuitry operatively coupled to the first communication channel and the second communication channel, and a resource locating application. The resource locating application including instructions performable by the processing circuitry to cause the mobile communication device to transmit a scanning RF signal using the first communication channel to locate resources, determine when service is unavailable for the first communication channel, detect another mobile communication device in response to the service being unavailable and send a service wake-up message to the other mobile communication device via the second communication channel.
[0060] In Example 19, the subject matter of Example 18 is optionally configured to determine that the service for the first communication channel of the mobile communication device is terminated, and initiate a discovery mode to discover the other mobile communication device in response to the determining that the service for the first communication channel is terminated.
[0061] In Example 20, the subject matter of Example 19 is optionally configured to display a notification that scanning using the first communication channel is terminated, and display a prompt on the mobile communication device to send the wake-up message.
[0062] In Example 21, the subject matter of one or any combination of Examples 1- 20 optionally includes an authentication process between the authentication system and at least one of the first and second mobile devices to verify by the authentication system that one or both of the first and second mobile devices is authentic.
[0063] In Example 22, the subject matter of one or any combination of Examples 1- 21 optionally includes an authentication process between the authentication system and at least one of the first and second mobile devices to verify by one or both of the mobile devices that the authentication system is authentic.
[0064] In Example 23, the subject matter of one or any combination of Examples 1- 22 optionally includes an authentication process between the first and second mobile devices to verify by one of the mobile devices that the other mobile device is authentic.
[0065] In Example 24, the subject matter of one or any combination of Examples 21-23 optionally includes the use of encryption for any of the communications between the authentication system and a mobile device or between mobile devices, such as symmetric through one or more shared keys or asymmetric encryption through a public-private key pair.
[0066] In Example 25, the subject matter of one or any combination of Examples 21- 24 optionally includes the use of message signing for any of the communications between the authentication system and a mobile device or between mobile devices, through the use of one or more public-private key pairs.
[0067] In Example 26, the subject matter of one or any combination of Examples 21- 25 optionally includes the use of a secure hash function for any of the communications between the authentication system and a mobile device or between mobile devices.
[0068] In Example 27, the subject matter of one or any combination of Examples 21- 26 optionally includes generating a temporary code for use as part of an authentication communication between the authentication system and a mobile device or between mobile devices.
[0069] In Example 28, the subject matter of Example 27, where the temporary code optionally includes one or more identifiers associated with the authentication system and / or one of the mobile devices in the peer-to-peer communication chain.
[0070] In Example 29, the subject matter of one or any combination of Examples 26- 28, where the temporary code optionally includes date / time information corresponding to the authentication request.
[0071] In Example 30, the subject matter of one or any combination of Examples 26- 29, where the temporary code optionally includes a randomly generated value.
[0072] These Examples can be combined in any permutation or combination. The above detailed description includes references to the accompanying drawings, which form a part of the detailed description. The drawings show, by way of illustration, specific embodiments in which the invention can be practiced. The above description is intended to be illustrative, and not restrictive. For example, the above-described examples (or one or more aspects thereof) may be used in combination with each other. Other embodiments can be used, such as by one of ordinary skill in the art upon reviewing the above description. The Abstract is provided to allow the reader to quickly ascertain the nature of the technical disclosure. It is submitted with the understanding that it will not be used to interpret or limit the scope or meaning of the claims. In the above Detailed Description, various features may be grouped together to streamline the disclosure. This should not be interpreted as intending that an unclaimed disclosed feature is essential to any claim. Rather, the subject matter may lie in less than all features of a particular disclosed embodiment. Thus, the following claims are hereby incorporated into the Detailed Description, with each claim standing on its own as a separate embodiment, and it is contemplated that such embodiments can be combined with each other in various combinations or permutations. The scope should be determined with reference to the appended claims, along with the full scope of equivalents to which such claims are entitled.
Claims
WHAT IS CLAIMED IS:
1. A mobile communication device, the device comprising:a first communication channel;a second communication channel;processing circuitry operatively coupled to the first communication channel and the second communication channel; anda resource access application including instructions performable by the processing circuitry to cause the mobile communication device to:communicate information with a reader device using the first communication channel; detect another mobile communication device;determine that service is unavailable for a first communication channel of the other mobile communication device; andsend a service wake-up message to the other mobile communication device via the second communication channel.
2. The device of claim 1, wherein the resource access application of the mobile communication device further includes instructions to cause the mobile communication device to:determine that service is unavailable for the first communication channel of the mobile communication device; andcommunicate authentication information to a resource access application of the other mobile communication device peer-to-peer via the second communication channel after sending the service wake-up message to the other mobile communication device.
3. The device of claim 2, wherein the resource access application further includes instructions to:detect that an operating system of the mobile communication device terminated the service for the first communication channel; andinitiate sending the service wake-up message in response to the detecting.
4. The device of claim 1, wherein the first communication channel is a Bluetooth communication channel, and the second communication channel is a Wi-Fi communication channel.
5. The device of claim 1, wherein the first communication channel is a near field communication channel, and the second communication channel is a secured communication channel.
6. The device of claim 1, wherein the resource access application further includes instructions to cause the mobile communication device to run as a background application to send authentication information to the reader device.
7. The device of claim 1, wherein the resource access application further includes instructions to cause the mobile communication device to send authentication information to the reader device to gain access through a physical access portal.
8. The device of claim 1, wherein the resource access application further includes instructions to cause the mobile communication device to transmit a scanning RF signal using the first communication channel to locate resources.
9. A method of operating a mobile communication device, the method comprising: executing a resource access application using the mobile communication device, wherein the resource access application is configured to communicate information with an authentication system using a first communication channel of the mobile communication device;detecting another mobile communication device and determining, by the resource access application, that service is unavailable for the first communication channel of the other mobile communication device; andsending a wake-up message to the other mobile communication device via a second communication channel to cause the other mobile communication device to wake-up its service for the first communication channel.
10. The method of claim 9, including:communicating, by the other mobile communication device, authentication information to a reader device of the authentication system using an awakened first communication channel service of the other mobile communication device.
11. The method of claim 9, including:determining, by the resource access application on the mobile communication device, that service is unavailable for the first communication channel of the mobile communication device;communicating authentication information to the other mobile communication device peer-to-peer via the second communication channel after sending the wake-up message to the other mobile communication device; andcommunicating the authentication information to the authentication system using an awakened first communication channel service of the other mobile communication device.
12. The method of claim 11, wherein the determining that service is unavailable for the first communication channel includes the resource access application determining that an operating system of the mobile communication device terminated the service for the first communication channel.
13. The method of claim 11,wherein the determining that service is unavailable for the first communication channel includes the resource access application determining that Bluetooth communication is unavailable; andwherein the sending a wake-up message to the other mobile communication device via a second communication channel includes sending the wake-up message to the other mobile communication device using a Wi-Fi channel.
14. The method of claim 9, wherein the sending the wake-up message includes sending the wake-up message to the other mobile communication device via a secured communication channel to cause the other mobile communication device to wake-up its service for a near field communication channel.
15. The method of claim 9, including:the resource access application sending authentication information to a reader device of the authentication system using the first communication channel of the mobile communication device to gain access through a physical access portal.
16. The method of claim 9, including:displaying a prompt on the mobile communication device to send the wake-up message; anddisplaying a prompt on the other mobile communication device to activate service of the first communication channel in response to receiving the wake-up message.
17. The method of claim 9, including:determining, by the resource access application, that service for the first communication channel of the mobile communication device is terminated; and initiating a discovery mode to discover the other mobile communication device in response to the determining that the service for the first communication channel is terminated.
18. A mobile communication device, the device comprising:a first communication channel;a second communication channel;processing circuitry operatively coupled to the first communication channel and the second communication channel; anda resource locating application including instructions performable by the processing circuitry to cause the mobile communication device to:transmit a scanning RF signal using the first communication channel to locate resources;determine when service is unavailable for the first communication channel; detect another mobile communication device in response to the service being unavailable; andsend a service wake-up message to the other mobile communication device via the second communication channel.
19. The device of claim 18, wherein the resource locating application further includes instructions to:determine that the service for the first communication channel of the mobile communication device is terminated; andinitiate a discovery mode to discover the other mobile communication device in response to the determining that the service for the first communication channel is terminated.
20. The device of claim 19, wherein the resource locating application further includes instructions to:display a notification that scanning using the first communication channel is terminated; anddisplay a prompt on the mobile communication device to send the wake-up message.