Status communication for mobile access control systems

Upgrading ACS readers to convert access controller signals into digital messages for mobile devices addresses the lack of feedback in existing systems, enhancing user experience and security through real-time access status updates.

WO2026104197A1PCT designated stage Publication Date: 2026-05-21ASSA ABLOY AB
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
ASSA ABLOY AB
Filing Date
2025-10-30
Publication Date
2026-05-21

Smart Images

  • Figure EP2025081384_21052026_PF_FP_ABST
    Figure EP2025081384_21052026_PF_FP_ABST
Patent Text Reader

Abstract

A system includes a secure access reader and a secure access controller. The secure access reader receives access requests from a user access credential device and identifies visual or auditory access signals from the secure access controller, where the visual or auditory access signals indicate access status. The reader transmits data indicative of the access status to the user device. The reader may include modified firmware to convert signals into digital messages and may have sensors to identify signals such as LED or beeper responses. The reader can determine access status, send denied notifications, maintain communication sessions, and prompt the user for next steps.
Need to check novelty before this filing date? Find Prior Art

Description

STATUS COMMUNICATION FOR MOBILE ACCESS CONTROL SYSTEMSPRIORITY APPLICATION(S)

[0001] This application claims priority to Indian Provisional Patent Application No.202411087202, filed on November 12, 2024, the disclosure of which is incorporated by reference herein in its entirety.TECHNICAL FIELD

[0002] Embodiments described herein generally relate to an access control system, and particularly to improved communication for an access control system.BACKGROUND

[0003] Access control technologies cover a range of systems and methods to govern access, for example by people, to secure areas or secure assets. Physical access control includes identification of authorized users or devices (e.g., vehicles, drones, etc.) and actuation of a gate, door, or other mechanism used to secure an area or actuation of a control mechanism, e.g., a physical or electronic / software control mechanism, permitting access to a secure physical asset, such as a computing device (e.g., desktop computer, mobile device, wearable electronic device, copier / printer, and the like). Logical access control includes identification of authorized users or devices to provide access to logical assets, such as an application, a cloud-based service, a financial or personal account, or another logical asset.

[0004] Access control systems (ACS) may include physical access control systems (PACS) or logical access control systems (LACS). These ACS generally include a reader (e.g., an online or offline reader) that holds authorization data and can be capable of determining whether credentials (e.g., from credential or key devices such as radio frequency identification (RFID) chips in cards, fobs, magnetic stripe cards, or personal electronic devices such as mobile phones) are authorized for accessing the secure area or asset.Alternatively, PACS / LACS can include a host server as part of the access controller to which readers are operably connected (e.g., via a controller device) in a centrally managed configuration. In centrally managed configurations, readers can obtain credentials from credential or key devices and pass those credentials to the PACS / LACS host server. The host server can then determine whether the credentials authorize access to the secure area or secure asset and command the actuator or other control mechanism accordingly or can command the reader to operate the actuator or other control mechanism accordingly.Wireless PACS / LACS, e.g., those that use wireless communication between the reader and the credential or key device, such as for secure credential exchange, can use RFID or personal area network (PAN) technologies, such as the IEEE 802.15.1, Bluetooth, Bluetooth Low Energy (BLE), near field communications (NFC), ZigBee, GSM, CDMA, Wi-Fi, ultrawide band (UWB), etc.

[0005] A credential device, in general, may include any device that carries evidence of authority, status, rights, or entitlement to privileges for a holder of the credential device, including any portable device (such as a credential card, electronic key, mobile phone, etc.) having memory storing one or more user credentials or credential data. Non-limiting example credential devices include various credential devices offered by HID Global Corporation, based in Austin, Texas.

[0006] Access credentials devices may be based on diverse types of access technology. In some examples, physical access cards may use magnetic stripe credentials, radio frequency identification (RFID) credentials (e.g., low frequency (LF) 125 KHz credentials, high frequency (HF) 13.56 MHz credentials), or other wireless technologies. Physical access card adoption and use faces various problems, such as physical access cards becoming lost, and physical access cards being environmentally unfriendly to produce. To address problems facing lost or environmentally unfriendly physical access cards, additional technologies have been explored. These alternative access credential technologies may include biometric readers (e.g., fingerprint reader, facial recognition) or wireless radio devices such as mobile phones or wearable devices. Wireless radio devices may use one or more wireless radio technologies, such as Bluetooth (BT), Bluetooth Low Energy (BLE), WiFi, Ultra-wideband (UWB), and other wireless radio technologies.

[0007] Mobile device access solutions may include the use of a mobile device (e.g., smartphone, tablet, wearable) to gain access to secure physical or logical assets. These mobile device access solutions may use built-in security features of the mobile device.However, these mobile devices may not receive status information from the secure physical or logical asset, or provide that status information to the mobile device user. Thus, solutions are desirable that would enable improved information communication with the mobile device and the mobile device user.BRIEF SUMMARY

[0008] The following presents a simplified summary of one or more embodiments of the present disclosure to provide a basic understanding of such embodiments. This summaryis not an extensive overview of all contemplated embodiments, and is intended to neither identify key or critical elements of all embodiments, nor delineate the scope of any or all embodiments.

[0009] In some aspects, the techniques described herein relate to a method for communicating access status in a secure access control system, the method including: receiving an access request from a user access credential device at a secure access reader; transmitting the access request from the secure access reader to a secure access controller; identifying a visual access signal or auditory access signal from the secure access controller, the visual access signal or auditory access signal indicating an access status response from the secure access controller; and transmitting data indicative of the access status response from the secure access reader to the user access credential device.

[0010] In some aspects, the techniques described herein relate to a secure access control system, including: a secure access reader including a processor and memory including instructions, the instructions causing the secure access reader to: receive an access request from a user access credential device; transmit the access request to a secure access controller; identify a visual access signal or auditory access signal from the secure access controller, the visual access signal or auditory access signal indicating an access status response from the secure access controller; and transmit data indicative of the access status response to the user access credential device.

[0011] In some aspects, the techniques described herein relate to a non-transitory computer-readable medium storing instructions that, when executed by one or more processors of a secure access reader, cause the secure access reader to perform operations including: receiving an access request from a user access credential device; transmitting the access request to a secure access controller; identifying a visual access signal or auditory access signal from the secure access controller, the visual access signal or auditory access signal indicating an access status response from the secure access controller; and transmitting data indicative of the access status response to the user access credential device.

[0012] While multiple embodiments are disclosed, still other embodiments of the present disclosure will become apparent to those skilled in the art from the following detailed description, which shows and describes illustrative embodiments of the invention. As will be realized, the various embodiments of the present disclosure are capable of modifications in various obvious aspects, all without departing from the scope of the present disclosure.Accordingly, the drawings and detailed description are to be regarded as illustrative in nature and not restrictive.BRIEF DESCRIPTION OF THE DRAWINGS

[0013] In the drawings, which are not necessarily drawn to scale, like numerals may describe similar components in different views. Like numerals having different letter suffixes may represent different instances of similar components. Some embodiments are illustrated by way of example, and not limitation, in the figures of the accompanying drawings:

[0014] FIG. 1 illustrates an example access control system.

[0015] FIG. 2 illustrates an example sequence diagram for secure access.

[0016] FIG. 3 illustrates an example method for secure access.

[0017] FIG. 4 illustrates a block diagram schematic of various components of an example reader, such as the credential reader discussed herein.

[0018] FIG. 5 illustrates a block diagram schematic of various example hardware components of an example machine that can be used as one or more credential-based devices described herein.DETAILED DESCRIPTION

[0019] The systems and methods described herein provide technical solutions for technical problems facing access control systems (ACS). These solutions including providing improved communication between a mobile device and an ACS reader device. Current ACS operate by transmitting credential data from the mobile device to the credential reader, which in turn sends credential data to an access controller. The access controller provides an access control decision (e.g., access granted, access denied) from the access controller to the reader device, however the reader device may have limited ability to communicate that access control decision back to the mobile device. These technical solutions include providing access control decision status from the reader device to the mobile device. In an example, this may include updating the reader device firmware to convert audible or visual status and communicate with the mobile device. By enhancing the reader device (e.g., via reader device firmware upgrade), these solutions may significantly improve the accuracy, reliability, and responsiveness of ACS. These solutions may improve the reliability and user satisfaction for ACS by providing substantially real-time acknowledgments from the access controller, providing users with substantially immediate feedback on their access attempts, reducing access uncertainties, and improving overall access control experience. These solutions may also make ACS more robust, such as by providing improved error detection and faster troubleshooting.

[0020] This provides improvements over existing solutions that are limited to providing only communication success status (e.g., whether the mobile device was able to initiate communication with the reader device). This also provides improvements over existing solutions that use a unidirectional communication between the reader device and an access controller (e.g., data Wiegand protocol, where data only flows from the reader to the controller). The limitations of these existing solutions are particularly evident in scenarios where users receive an indication that communication has been established between a mobile device and a reader device, yet the user remains unaware of the actual access decision made by the access controller. As a result, users may be left without immediate knowledge of whether access has been granted or denied, which can lead to confusion and potential security vulnerabilities.

[0021] These solutions may include providing a modified reader device that generates and communicates status updates based on visual status (e.g., light emitting diode (LED)) or audible status (e.g., beeping response) that are communicated between the reader device and the controller device. For example, when a user attempts to access a secure area, the user device may indicate a successful communication between the user device and the reader device, however the reader device may generate a red light or audible beep to indicate that access has been denied. The technical solutions described herein may include an improved reader device that receives an access response visual or audible status from the access controller, converts the visual or audible status into a digital message format suitable for transmission to the user mobile device, and provides that response status back to the user mobile device using an existing or new communication session. These technical solutions may include modifying the firmware of the reader device to receive, interpret, and communicate the visual or audible status with the user mobile device. By using existing visual or audible status signals, these solutions provide an improved solution that does not require additional hardware, which enables maintaining the integrity of the existing security infrastructure.

[0022] These solutions provide improved performance for unidirectional access control request communications between the reader device and access controller. Some ACS use a unidirectional protocol (e.g., Weigand protocol) to convey an access request from the reader device to the access controller. These unidirectional ACS configurations may include a first set of wires dedicated to transferring the access control request from the reader device to the access controller, and may include a second set of wires dedicated to receiving access control decision responses (e.g., access granted, access denied) from the access controller atthe reader device. The received response may be interpreted by the reader device and displayed through audio or visual signals. For unidirectional ACS configurations, these solutions may include interpreting the received response at the reader device and sending an indication of the access control decision to the user mobile device. These solutions may include upgrading the reader device (e.g., firmware upgrade), enabling the reader device to capture access control decision responses and relay the response to the mobile device, providing users with real-time confirmation of access events.

[0023] These solutions also provide improved performance for bidirectional access control request communications between the reader device and access controller. For ACS that use the Open Supervised Device Protocol (OSDP) or other bidirectional communication, the access event information may be retrieved directly from the access controller and relayed to the user mobile device. These bidirectional ACS configurations may use a single communication (e.g., RS 485 protocol) to transfer the access control request from the reader device to the access controller and subsequently receive access control decision responses from the access controller at the reader device. For bidirectional ACS configurations, these solutions may include interpreting the received response at the reader device and sending an indication of the access control decision to the user mobile device. This may also include providing a separate indication of the access control decision at the reader device, such as an audio or visual signal. These solutions may include upgrading the reader device (e.g., firmware upgrade), to transmit access control decision responses directly to the mobile device. These solutions may close a loop in the communication process by enabling substantially real-time feedback, improving the user experience and ensuring that access events are accurately logged and processed.

[0024] These solutions may include providing a substantially real-time indication of access control success or failure status from the reader device to the mobile device. This provides improvements over systems in which the mobile device is only able to confirm that the initial communication with the reader device was successful. In various examples, the real-time indication may be used by the mobile device to provide information to the user or prompt the user for various security options. This may include suggesting the user attempt access again, displaying an indication of historical usage (e.g., whether and when the user previously accessed this secure location), displaying a button to initiate communication (e.g., phone call, messaging, technical support ticket) with security personnel, or other information or security options. This may provide improved security and user experience, both for theusers of the mobile device and for security personnel (e.g., ACS operators, on-site security offices).

[0025] FIG. 1 illustrates an example ACS 100, or portions thereof. While FIG. 1 primarily illustrates a PACS, it is recognized that the present disclosure similarly relates to LACS, and that while the secure asset in FIG. 1 is illustrated as a secure area surrounded by a wall and protected by a physical access point (e.g., a door) and the control mechanism is described as a locking mechanism, the secure asset could instead be a logical asset (e.g., an application, a cloud-based service, or a financial or personal account), the control mechanism could be an electronic / software control mechanism separate from or incorporated with the reader device, and the reader device need not be fixed and could include a device owned or operated by the user, such as a mobile device (e.g., smart phone, tablet, or the like).

[0026] ACS 100 can include a reader device 102 (e.g., reader device) associated with a secure area, access point, or other asset. In some cases, such as in the example illustrated in FIG. 1, secure asset is a secure area secured by an access point 105, such as a door, gate, turnstile or the like controlling or permitting authorized access to the secure area, but as explained above, secure asset may alternatively be a logical asset. Reader device 102 can include or be operably connected with a command control mechanism 106, such as but not limited to a locking mechanism in the case of PACS or an electronic / software control mechanism in the case of LACS, that controls whether access via access point 105 is permitted (e.g., can be opened or accessed) or may even control opening and / or closing of the access point. Reader device 102 can be an offline reader, e.g., a reader not connected to a control panel or host server, and in such cases may make its own access control determinations and directly operate or command control mechanism 106, accordingly.Reader device 102 can be a wireless reader device, in that the reader may communicate with credential or key devices via wireless technologies, such as RFID or PAN technologies, such as the IEEE 802.15.1, Bluetooth, Bluetooth Low Energy (BLE), near field communications (NFC), ZigBee, GSM, CDMA, Wi-Fi, UWB, etc. Reader device 102 may also include a PIN pad, touch screen, fingerprint reader, magnetic stripe reader, chip reader, or other nonwireless input means for receiving credential or other information, such as a PIN or other secret code, biometric information such as a fingerprint, or information from a magnetic stripe card or chip card, for example.

[0027] In some cases, reader device 102 can be connected by wire or wirelessly to a control panel 108. In such cases, reader device 102 may transmit credential information to control panel 108, and the control panel may make, or may share responsibilities with thereader in making, access control determinations. Based on the access control determinations, control panel 108 can instruct reader device 102 to operate or command control mechanism 106, accordingly. Alternately, control panel 108 can be connected directly or wirelessly to command control mechanism 106, and in such cases may directly operate or command the control mechanism, accordingly, bypassing reader device 102.

[0028] In some cases, reader device 102 and control panel 108, and even command control mechanism 106, can be connected to a network 110 (e.g., wired network, wireless network) and communicate with each other, as described above, via network 110. Example networks can include a local area network (LAN), a wide area network (WAN), a packet data network (e.g., the Internet), mobile telephone networks (e.g., cellular networks), Plain Old Telephone (POTS) networks, wireless data networks (e.g., networks based on the IEEE 802.11 family of standards known as Wi-Fi or the IEEE 802.16 family of standards known as WiMax), networks based on the IEEE 802.15.4 family of standards, and peer-to-peer (P2P) networks, among others. If ACS 100 is managed by a remote system, the ACS can include a host server 112 connected by wire or wirelessly to network 110 and that may communicate with reader device 102 and / or control panel 108. In such cases, reader device 102 can transmit credential information to host server 112 via network 110 or can transmit credential information to control panel 108, which can then transmit the credential information to the host server via the network. Host server 112 may make, or may share responsibilities with reader device 102 and / or control panel 108 in making, access control determinations. Based on the access control determinations, host server 112 can instruct reader device 102, directly or indirectly via control panel 108, to operate or command control mechanism 106, accordingly. Alternately, host server 112 can instruct control panel 108 to operate or command control mechanism 106, accordingly. In still another example, host server 112 can be connected via network 110 to command control mechanism 106 and directly operate or command the control mechanism, accordingly, bypassing reader device 102 and control panel 108.

[0029] The user 101 may use a credential device 114 (e.g., smartcard 114a, mobile device 114b) to access a secure area. In an example, the user 101 may approach reader device 102 associated with access point 105, and the credential device 114 may communicate the user’s credential or credential data to the reader, for example, via a suitable RFID or PAN technology. In general, a credential device 114 may include any device that carries evidence of authority, status, rights, and / or entitlement to privileges for a holder of the credential device. A credential device 114 can be a portable device having memory 116, storing one ormore user credentials or credential data, and a reader interface 118 (i.e., an antenna and Integrated Circuit (IC) chip), which permits the credential to exchange data with a reader device, such as reader device 102, via a credential interface of the reader device, such as antenna 406. One example of credential device 114 is an RFID smartcard (e.g., smartcard 114a) that has data stored thereon allowing a holder of the credential device to access a secure area or asset protected by reader device 102, such as a secure area. Other examples of credential devices 114 include, but are not limited to, proximity RFID-based cards, access control cards, credit cards, debit cards, passports, identification cards, key fobs, NFC-enabled devices, mobile phones (e.g., mobile device 114b), personal digital assistants (PDAs), tags, or any other device configurable to emulate a virtual credential. A credential device may also be understood to be a combination of two or more such example devices that are associated with one another and in combination serve to validate a user’s access request, e.g., a smartcard and mobile device that are both associated to an authorized user. In some example embodiments, such as but not limited to certain LACS embodiments, reader device 102 and credential device 114 may be the same device, wherein, for example, the user may be attempting to access a logical asset via the user’s own mobile device (e.g., mobile device 114b).

[0030] When reader device 102, control panel 108, and / or host server 112 determine that credential data provided by credential device 114 is valid and / or authorized, reader device 102, control panel 108, or host server 112 may send access control instruction data that instructs the control mechanism 106 to allow access to a secure asset by the user 101 having the credential device. Alternatively, when reader device 102, control panel 108, and / or host server 112 determine that credential data provided by credential device 114 is not valid or authorized, reader device 102, control panel 108, or host server 112 may send access control data that indicates access has been denied. The access control data that indicates access has been denied may include visual or auditory access signals, which may be interpreted by the reader device 102 and used to generate corresponding visual or auditory notifications. In another example, the access control data may contain additional information encoded within the allow / denial signal, which can be represented by patterns within the visual and / or auditory signals, such as the number or duration of indicators. For example, the access control data may comprise a pattern or sequence of visual and / or auditory signals, which may optionally be time-varying in the duration of each visual or auditory indicator. The combination of a visual and auditory signal may also be used to differentiate from other access control data using only one of those signals. Different tonalpitch and color may be used by systems whose visual and auditory outputs support such additional variations. It would be appreciated that the complexity and length of the signal patterns could be used to convey encoded information, for example using Morse code patterns or other mappings of patterns. These may be used to communicate additional messages represented by the patterns, such as last access date / time, one-time codes, etc. Alternatively, predefined patterns may be programmed into the system and stored to indicate various expected access control system states (e.g., denial due to incorrect credential, denial due to unauthorized date, etc.). In some embodiments, the frequency of pulses for the LED may be sufficiently high so that the changes in visual indicator are not perceptible to the human eye. In other embodiments, particularly where the reader’s transmission capabilities are more limited, the frequency of changes in the visual indicator may be slower to accommodate signal communication to the user via the visual spectrum. The reader device 102 may further convert these visual or auditory signals into a digital message format suitable for transmission to the credential device 114. In an example, the reader device 102 may maintain a communication session from the time it receives the access request until it transmits data indicative of the access status. In another example, the reader device 102 may receive the access request via a first communication session, receive data indicative of the access status, and initiate a second communication session to transmit data indicative of the access status to the credential device 114. In another alternative, the reader device may be configured to broadcast or relay the visual and / or auditory signals from the controller directly to the mobile device without conversion. In such a scenario, the reader may still need to make adjustments to the signal, e.g., scaling of amplitude or frequency of the access control data for output that conforms to the LED or buzzer equipment available on the reader.Additionally, the controller may transmit relay parameters, such as a scaling parameter to be applied, based upon the acceptable parameters of the mobile device that is associated with the credential. However, interpretation of the access control data itself may be left to the mobile device to decipher and convert into a digital message after receiving the relayed visual and / or auditory signals. The mobile device may then perform processing or take further action using the digital message and any additional included data.

[0031] The credential device 114 may provide additional information to the user 101. In an example, the credential device 114 may be configured to determine if a predetermined access response period has elapsed before receiving data indicating access status, and may prompt the user with an indication that no access control response has been received within the expected time. In another example, in response to receiving an indication that access wasdenied, the credential device 114 may provide additional information or prompt the user 101 to take additional steps. This may include the credential device 114 displaying a prompt suggesting the user attempt access again, displaying an indication of historical usage (e.g., whether and when the user previously accessed this secure location), displaying a button to initiate communication (e.g., phone call, messaging, technical support ticket) with security personnel, or displaying other information or security options.

[0032] FIG. 2 illustrates an example sequence diagram 200 for secure access. The sequence diagram 200 includes communication between a credential device 210, a credential reader 220, and an access controller 230. The credential device 210 may initiates an access request 215 to the credential reader 220. In an example, this includes opening a communication session between the credential device 210 and the credential reader 220 and transmitting access credentials. The credential reader 220 may be configured to receive this access request from the credential device 210.

[0033] Upon receiving the access request, the credential reader 220 transmits the credential information 225 to the access controller 230. The access controller 230 may be configured to receive the credential informaiton, process the credentials 235, and determine access status 245 based on the received credentials. This determination of access status 245 may include evaluating the credentials against predefined access criteria, such as determining whether a user is authorized to access a secure asset associated with the credential device 210.

[0034] Once the access decision is made, the access controller 230 communicates the decision 255 back to the credential reader 220. The decision may include an instruction to cause a control mechanism to unlock a door or take no action. The decision may also include visual or auditory signals instructing the credential reader 220 to generate visual or auditory feedback. The credential reader 220 may interpret these signals 265, such as determining that the credential reader 220 is to generate a corresponding visual or auditory response to the user in the form of a light or beeping sound. The credential reader 220 may also convert these signals 275, such as converting the signals into a digital message format suitable for transmission to the credential device 210. The credential reader 220 then forwards access status 285 to the credential device 210, such as by sending the digital message from the credential reader 220 to the credential device 210. In an example, converting signals 275 and forwarding access status 285 may be implemented using modified firmware loaded into the credential reader 220. If the credential device 210 is not capable of processing thetransmission, a second associated device may be used for processing the transmission, such as a mobile device associated with the credential user.

[0035] The signal conversion 275 and forwarding of access status 285 may be based on whether the credential reader 220 and the access controller 230 communicate using a unidirectional or bidirectional protocol. For ACS that use a unidirectional protocol (e.g., Weigand protocol), dedicated communication lines may be used for receiving access control decision responses (e.g., access granted, access denied) from the access controller 230 at the credential reader 220. The received response may be interpreted by the credential reader 220 and displayed through audio or visual signals. In these unidirectional ACS configurations, the signal conversion 275 converts the access control decision responses, and then the access status is forwarded 285 from the credential reader 220 to the credential device 210. This forwarding may include using an existing communication session or creating a new communication session between the credential reader 220 and the credential device 210.

[0036] For ACS that use a bidirectional protocol (e.g., OSDP), the bidirectional protocol may be used for both transmission of credential information 225 and the communication of the decision 255. In these bidirectional ACS configurations, the signal conversion 275 converts the access control decision responses, and then the access status is forwarded 285 from the credential reader 220 to the credential device 210. This forwarding may include using an existing communication session or creating a new communication session between the credential reader 220 and the credential device 210.

[0037] Various types of communication channels may be used for the communications shown in sequence diagram 200. In an example, the credential device 210 and the credential reader 220 may maintain a single communication session used for both initiating the access request 215 and for forwarding the access status 285. In another example, the credential device 210 may initiate a first communication session for initiating the access request 215, and the credential reader 220 may initiate a second communication session for forwarding the access status 285. The first and second communication sessions may be conducted using one or more communication technologies. For example, the first communication session may be conducted using RFID, and the second communication session may be conducted using Bluetooth. Similarly, the credential reader 220 may communicate with the access controller 230 using one or two communication sessions or communication technologies.

[0038] Following forwarding of the access status 285 to the credential device 210, the credential reader 220 may interpret the access status and display an indication of the accessstatus 295 on the credential device 210, such as to indicate that access has been denied. The credential device 210 may also display additional information about the access status, such as a reason for access denial, a prompt suggesting the user attempt access again, displaying an indication of historical usage, displaying a button to initiate communication with security personnel, or displaying other information or security options.

[0039] In another alternative embodiment, the credential device 210 comprises a near-field credential, such as an RFID smart card, and an associated mobile device capable of communicating with the access reader and the host server, such as a mobile phone or similar device. Upon confirming the near-field credential is authorized, the reader may receive access control data for the visual and / or auditory outputs to reflect authentication of the credential information. However, the access control system may hold granting physical or logical access approval at this stage. The reader then converts the access control data into a transmission for the mobile device (e.g., via Bluetooth) along with additional data for further authentication. The additional data may be packaged with the access control data in the form of one or more patterns or sequences of visual and / or auditory signals, as described above. The additional data may comprise a second authentication code, such as a one-time passcode. The additional data may also comprise reader information or other data intended to indicate the particular authentication session with the reader. In an example, the second authentication code may be generated by the reader and transmitted back to the access controller, e.g., at random at the time of the authentication. In another example, the second authentication code may be generated by the access controller and communicated to the reader as part of the access control data sent to the reader, such as through an encoded pattern of visual and / or auditory signals. The mobile device receives the additional data from the reader, and in response to receiving the additional data, the mobile device automatically opens an additional secure communication channel with the access controller to provide the mobile device’s identity and the received additional data. If the additional data from the mobile device matches the expected additional data that was transmitted by the reader, and if the mobile device’s identity indicates the correct association with the user of the credential being authenticated, then the access control system may grant physical or logical access. Alternatively, if the additional data from the mobile device does not match the expected data, or if another anomaly is detected such as a mismatch in the mobile device identity or a timeout with no response, etc., then the access control system may deny physical or logical access.

[0040] In other embodiments, the access control system proceeds first with granting physical or logical access approval at the stage after the user near-field credential device has been authenticated. The reader may still receive access control data for the visual and / or auditory outputs to reflect authentication of the credential information, along with additional data. The additional data can then be used to confirm the validity of the access request by the user of the credential through the user’s associated mobile device, for example by the reader transmitting the additional data to the mobile device and the controller, and then the mobile device transmitting the additional data to the controller for verification that the transmitted data matches what the controller separately received from the reader.

[0041] A second visual / auditory signal may subsequently be sent to the reader to indicate completion of the additional authentication process along with additional access control data signaling the result and / or status of the reader. Additional data may again be combined as part of the access control data through one or more patterns or sequences of visual and / or auditory signals sent from the access controller to the access reader. In the event that the additional authentication process fails, such as where the transmitted data from the associated mobile device does not match what is expected, the process times out with no response from the associated mobile device, or the responding device is not associated with the user credential, the access control system may separately notify an administrator or security personnel that the access request has not been fully validated. In instances where access was previously granted based on the credential authentication alone, this second message that additional authorization failed may be used to alert security or the system administrator in near-real-time that a potentially suspicious request may need additional follow-up.

[0042] In other alternative embodiments, after presentment of a credential that is authorized, the mobile device may instead receive the additional data along with an indicator to display a message to the user of the mobile device to request approval to further authenticate the credential presented to the reader. If the user approves, the mobile device then opens an additional secure communication channel with the access controller to provide at least the mobile device’s identity for determination if is associated with the user of the credential being authenticated. The received additional data may also be included to be transmitted to further validate the authentication request as well as the origin of the reader request for user approval.

[0043] In another alternative embodiment, the credential device 210 comprises a mobile device that either contains the credential information or is associated with a near-fieldcredential, such as an RFID smart card. Upon confirming the user near-field credential device is authorized, the reader may receive access control data for the visual and / or auditory outputs to reflect authentication of the credential information. The access control system may be configured to grant physical or logical access based upon credential authentication alone. Alternatively, the access control system may be configured to hold granting physical or logical access approval at this stage, subject to additional authorization. In either case, upon authentication of the credential by the controller, a message may be sent to the mobile device associated with the credential to request the user position the mobile device for receiving access control data from the reader. Upon indication that the user has positioned the mobile device, an additional secure communication channel is established with the controller, and the mobile device is placed in a data receive mode. For example, the data receive mode may be a mode that turns on a specified local-proximity communication mechanism (e.g., Bluetooth, IR, NFC, etc.) to ensure that the mobile device is ready. Alternatively, the data receive mode may be a mode that activates the mobile device’s camera and / or microphone to receive visual and / or auditory signals directly output by the reader.

[0044] Upon establishment of the additional secure communication channel, the controller then initiates sending access control data to the reader, which the reader may then transmit to the readied mobile device via the appropriate communication medium. In the case of a local-proximity communication mechanism, the transmitted data may be a digital message converted from the visual and / or auditory signals received by the reader from the controller. In the case where the data receive mode involves activating the camera and / or microphone of the mobile device, the reader relays the visual and / or auditory signals from the controller to the mobile device via the reader’s LED and / or buzzer outputs. The mobile device then receives the visual and / or auditory signals via the camera and / or microphone and converts them to the equivalent digital message for further processing and action.

[0045] In other embodiments, the timing and order of transmitted data may vary. In an example, the timing and order of transmitted data may be based on the operation of the access controller. For example, the access controller, upon validating that the user near-field credential device is authorized, may transmit the access control data along with additional data to the access reader via one or more patterns or sequences of visual and / or auditory signals. Concurrently, the access controller may open an additional secure communication channel with a mobile device associated with the validated credential, based upon the access control system’s user registration and records. The mobile device then listens for communication from the nearby access reader to receive any transmitted access control data.A limited time window may be set by the access control system administrator, and may be applied to this additional communication channel and listening session to limit the duration of the communication window. During the listening window of the mobile device, the access reader transmits the access control data and any additional data to the mobile device. As described herein, the transmission may occur via a local communication medium, such as Bluetooth, providing an implicit geographic proximity check between the mobile device and the access reader with which the user is interacting. Upon receiving the access control data and additional data from the access reader, the mobile device transmits the received data to the access controller using the additional secure communication channel. The access controller then proceeds with additional authentication of the user to determine whether to grant or deny physical or logical access based upon the data received over the additional secure communication channel, as described herein.

[0046] FIG. 3 illustrates an example method 300 for secure access. Method 300 begins by receiving 310 an access request from a user access credential device at a secure access reader. Method 300 includes transmitting 320 the access request from the secure access reader to a secure access controller. Method 300 includes identifying 330 a visual access signal or auditory access signal from the secure access controller. The visual access signal or auditory access signal may indicate an access status response from the secure access controller. Method 300 includes transmitting 340 data indicative of the access status response from the secure access reader to the user access credential device.

[0047] The secure access reader may include firmware modified to convert the visual access signal or auditory access signal into a digital message format suitable for transmission to the user access credential device. The secure access reader may include a visual input sensor or audible input sensor to identify the visual access signal or auditory access signal. The visual access signal or auditory access signal may include a light emitting diode (LED) response or a beeping response. A first communication protocol between the secure access reader and the secure access controller may include a unidirectional communication protocol. The unidirectional communication protocol may include Wiegand protocol. The user access credential device communicates with the secure access reader using at least one of NFC or Bluetooth BLE.

[0048] Method 300 may further include determining 350 the access status response may include an access denied status. Method 300 may further include sending 360 a status denied notification to a secure access administrator system, the status denied notification including a plurality of access attempt details. The secure access reader may be configured tomaintain a communication session between receiving the access request and transmitting data indicative of the access status response. A first type of communication channel may be used to receive the access request from the user access credential device at the secure access reader. The first type of communication channel may be used to transmit data indicative of the access status response from the secure access reader to the user access credential device.

[0049] Method 300 may further include determining 370 that a predetermined access response period has elapsed before receiving the access status response. Method 300 may further include transmitting 380 an error message to the user access credential device, the error message indicating the predetermined access response period has elapsed. The secure access reader may be configured to log access attempts and outcomes for security auditing purposes. The secure access reader may be configured to operate in multiple communication modes based on one or more available communication protocols.

[0050] FIG. 4 illustrates a block diagram 400 of various components of an example reader device 102, such as the credential reader discussed herein. In general, reader device 102 can include one or more of a memory 402, a processor 404, antenna 406, a communication module 408, a network interface device 410, a user interface 412, and a power source 414 (e.g., power supply). Reader device 102 may include a device affixed to a surface (e.g., wall, door), though reader device 102 may also be a free-standing device or a portable device (e.g., mobile electronic device).

[0051] Memory 402 can be used in connection with the execution of application programming or instructions by processor 404, and for the temporary or long-term storage of executable instructions (e.g., program instructions, instruction sets) or credential or authorization data 418, such as credential data, credential authorization data, or access control data or instructions. For example, memory 402 can contain executable instructions 416 that are used by the processor 404 to run other components of reader device 102 and make access determinations based on credential or authorization data 418. Memory 402 can comprise a computer readable medium that can be any medium that can contain, store, communicate, or transport data, program code, or instructions for use by or in connection with reader device 102. The computer readable medium can be, for example but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device. More specific examples of suitable computer readable medium include, but are not limited to, an electrical connection having one or more wires or a tangible storage medium such as a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or EEPROM),Dynamic RAM (DRAM), any solid-state storage device, in general, a compact disc read-only memory (CD-ROM), or other optical or magnetic storage device. Computer readable media includes but is not to be confused with, computer readable storage medium, which is intended to cover all physical, non-transitory, or similar embodiments of computer readable media.

[0052] Processor 404 can correspond to one or more computer processing devices or resources. For instance, processor 404 can be provided as silicon, as a Field Programmable Gate Array (FPGA), an Application-Specific Integrated Circuit (ASIC), any other type of Integrated Circuit (IC) chip, a collection of IC chips, or the like. As a more specific example, processor 404 can be provided as a microprocessor, Central Processing Unit (CPU), or plurality of microprocessors or CPUs that are configured to execute instructions sets stored in an internal memory 420 or memory 402.

[0053] Antenna 406 can correspond to one or multiple antennas and can be configured to provide for wireless communications between, for example, reader device 102 and a credential or key device. Antenna 406 can be arranged to operate using one or more wireless communication protocols and operating frequencies such as the IEEE 802.15.1, Bluetooth, Bluetooth Low Energy (BLE), near field communications (NFC), ZigBee, GSM, CDMA, Wi-Fi, RF, UWB, and the like. By way of example, antenna 406 can be RF antenna(s), and as such, may transmit / receive RF signals through free-space to be received / transferred by a credential or key device having an RF transceiver.

[0054] Communication module 408 can be configured to communicate according to any suitable communications protocol with one or more different systems or devices either remote or local to reader device 102, such as one or more command control mechanisms 106 or control panel 108.

[0055] Network interface device 410 includes hardware to facilitate communications with other devices, such as a control panel or host server over a communication network, using any one of a number of transfer protocols (e.g., frame relay, internet protocol (IP), transmission control protocol (TCP), user datagram protocol (UDP), hypertext transfer protocol (HTTP), etc.). Example communication networks can include a local area network (LAN), a wide area network (WAN), a packet data network (e.g., the Internet), mobile telephone networks (e.g., cellular networks), Plain Old Telephone (POTS) networks, wireless data networks (e.g., IEEE 802.11 family of standards known as Wi-Fi or IEEE 802.16 family of standards known as WiMax), networks based on the IEEE 802.15.4 family of standards, and peer-to-peer (P2P) networks, among others. In some examples, network interface device 410 can include an Ethernet port or other physical jack, a Wi-Fi card, a Network InterfaceCard (NIC), a cellular interface (e.g., antenna, filters, and associated circuitry), or the like. In some examples, network interface device 410 can include one or more antennas to wirelessly communicate using, for example, at least one of single-input multiple-output (SIMO), multiple-input multiple-output (MIMO), or multiple-input single-output (MISO) techniques.

[0056] User interface 412 can include one or more input devices or display devices. Examples of suitable user input devices that can be included in user interface 412 include, without limitation, one or more buttons, a keyboard, a mouse, a touch-sensitive surface, a stylus, a camera, a microphone, a PIN pad, touch screen, fingerprint reader, magnetic stripe reader, chip reader, etc. Examples of suitable user output devices that can be included in user interface 412 include, without limitation, one or more LEDs, an LCD panel, a display screen, a touchscreen, one or more lights, a speaker, etc. It should be appreciated that user interface 412 can also include a combined user input and user output device, such as a touch-sensitive display or the like.

[0057] Power source 414 can be any suitable internal power source, such as a battery, capacitive power source or similar type of charge-storage device, etc., or can include one or more power conversion circuits suitable to convert external power into suitable power (e.g., conversion of externally supplied AC power into DC power) for components of the reader device 102. Power source 414 can also include some implementation of surge protection circuitry to protect the components of reader device 102 from power surges.

[0058] Reader device 102 can also include one or more busses or interlinks 422 operable to transmit communications between the various hardware components of the reader. A system bus or interlink 422 can be any of several types of commercially available bus structures or bus architectures. A computing device or credential reader manager may reconfigure the reader device 102 by connecting a device to the reader device 102 via bus or interlink 422, such as by changing device parameters (e.g., configurable interpolling delays), by overwriting a device management policy, by updating software, by reflashing firmware, or other reconfigurations.

[0059] FIG. 5 illustrates a block diagram schematic of various example hardware components of an example machine 500 that can be used as, for example, one or more credential-based devices described herein. These credential-based devices may include one or more of a credential reader (e.g., reader device 102), a credential reader manager device that is connected to a credential reader (e.g., to reflash the credential reader), a computing device (e.g., a computer allowing a user to enter input to update a power management policy), or a credential device (e.g., BLE device). These devices may include one or more ofthe example components illustrated in FIG. 5, which may depend on the form factor of the device. Examples, as described herein, can generally include, or can operate by, logic or a number of components, modules, or mechanisms in machine 500. Modules may be hardware, software, or firmware communicatively coupled to one or more processors in order to carry out the operations described herein. Generally, circuitry (e.g., processing circuitry) of example machine 500 may include a collection of circuits implemented in tangible entities of the machine 500 that include hardware (e.g., simple circuits, gates, logic, etc.). Circuitry membership can be flexible over time. Circuitries include members that can, alone or in combination, perform specified operations when operating. In some examples, hardware of the circuitry can be immutably designed to carry out a specific operation (e.g., hardwired). In some examples, the hardware of the circuitry can include variably connected physical components (e.g., execution units, transistors, simple circuits, etc.) including a machine readable medium physically modified (e.g., magnetically, electrically, moveable placement of invariant massed particles, etc.) to encode instructions of the specific operation. In connecting the physical components, the underlying electrical properties of a hardware constituent are changed, for example, from an insulator to a conductor or vice versa. The instructions permit embedded hardware (e.g., the execution units or a loading mechanism) to create members of the circuitry in hardware via the variable connections to carry out portions of the specific operation when in operation. Accordingly, in some examples, the machine readable medium elements are part of the circuitry or are communicatively coupled to the other components of the circuitry when the device is operating. In some examples, any of the physical components can be used in more than one member of more than one circuitry. For example, under operation, execution units can be used in a first circuit of a first circuitry at one point in time and reused by a second circuit in the first circuitry, or by a third circuit in a second circuitry at a different time. Additional or more specific examples of components with respect to machine 500 follow.

[0060] In some embodiments, machine 500 can operate as a standalone device or can be connected (e.g., networked) to other machines. In a networked deployment, machine 500 can operate in the capacity of a server machine, a client machine, or both in server-client network environments. In some examples, machine 500 can act as a peer machine in a peer-to-peer (P2P) (or other distributed) network environment. Machine 500 can be or include a PC, a tablet PC, a set-top box (STB), a PDA, a mobile telephone, a web appliance, a network router, switch or bridge, an RFID smartcard or other proximity-based card, access control card, electronic key, key fob, or any machine capable of executing instructions (sequential orotherwise) that specify actions to be taken by that machine. Further, while only a single machine is illustrated, the term “machine” shall also be taken to include any collection of machines that individually or jointly execute a set (or multiple sets) of instructions to perform any one or more of the methodologies discussed herein, such as cloud computing, software as a service (SaaS), other computer cluster configurations.

[0061] Machine 500 may include a computer system that includes a hardware processor 502 (e.g., a central processing unit (CPU), a graphics processing unit (GPU), a hardware processor core, or any combination thereof) and a main memory 504, a static memory (e.g., memory or storage for firmware, microcode, a basic-input-output (BIOS), unified extensible firmware interface (UEFI), etc.) 506, or mass storage 508 (e.g., hard drives, tape drives, flash storage, or other block devices) some or all of which can communicate with each other via an interlink 534 (e.g., one or more system buses, one or more interlinks). Machine 500 can further include a display device 510, an input device 512, or a user interface (UI) navigation device 514. Examples of suitable display devices include, without limitation, one or more LEDs, an LCD panel, a display screen, a touchscreen, one or more lights, etc. Example input devices and UI navigation devices include, without limitation, one or more buttons, a keyboard, a touch-sensitive surface, a stylus, a camera, a microphone, etc. In some examples, one or more of the display device 510, input device 512, or UI navigation device 514 can be a combined unit, such as a touch screen display. Machine 500 can additionally include a signal generation device 518 (e.g., a speaker), a network interface device 520, one or more antennas 530, a power source 532, and one or more sensors 516, such as a global positioning system (GPS) sensor, compass, accelerometer, or another sensor. Machine 500 can include an output controller 528, such as a serial (e.g., universal serial bus (USB)), parallel, or other wired or wireless (e.g., infrared (IR), NFC, etc.) connection to communicate with or control one or more peripheral devices (e.g., a printer, card reader, etc.).

[0062] Processor 502 can correspond to one or more computer processing devices or resources. For instance, processor 502 can be provided as silicon, as a Field Programmable Gate Array (FPGA), an Application-Specific Integrated Circuit (ASIC), any other type of Integrated Circuit (IC) chip, a collection of IC chips, or the like. As a more specific example, processor 502 can be provided as a microprocessor, Central Processing Unit (CPU), or plurality of microprocessors or CPUs that are configured to execute instructions sets stored in an internal memory 522 or memory 504, 506, 508.

[0063] Any of memory 504, 506, and 508 can be used in connection with the execution of application programming or instructions by processor 502 for performing any of the functionality or methods described herein, and for the temporary or long-term storage of program instructions or instructions 524 (e.g., instruction sets) or other data for performing any of the functionality or methods described herein, such as for in-field encoding of access credentials as described herein. Any of memory 504, 506, 508 can comprise a computer readable medium that can be any medium that can contain, store, communicate, or transport data, program code, or instructions 524 for use by or in connection with machine 500. The computer readable medium can be, for example but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device. More specific examples of suitable computer readable medium include, but are not limited to, an electrical connection having one or more wires or a tangible storage medium such as a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or EEPROM), Dynamic RAM (DRAM), a solid-state storage device, in general, a compact disc read-only memory (CD-ROM), or other optical or magnetic storage device. As noted above, computer readable media includes but is not to be confused with, computer readable storage medium, which is intended to cover all physical, non-transitory, or similar embodiments of computer readable media.

[0064] Network interface device 520 includes hardware to facilitate communications with other devices over a communication network, such as network 110, using any one of a number of transfer protocols (e.g., frame relay, internet protocol (IP), transmission control protocol (TCP), user datagram protocol (UDP), hypertext transfer protocol (HTTP), etc.). Example communication networks can include a local area network (LAN), a wide area network (WAN), a packet data network (e.g., the Internet), mobile telephone networks (e.g., cellular networks), Plain Old Telephone (POTS) networks, wireless data networks (e.g., IEEE 802.11 family of standards known as Wi-Fi or IEEE 802.16 family of standards known as WiMax), networks based on the IEEE 802.15.4 family of standards, and peer-to-peer (P2P) networks, among others. In some examples, network interface device 520 can include an Ethernet port or other physical jack, a Wi-Fi card, a Network Interface Card (NIC), a cellular interface (e.g., antenna, filters, and associated circuitry), or the like. In some examples, network interface device 520 can include one or more antennas to wirelessly communicate using, for example, at least one of single-input multiple-output (SIMO), multiple-input multiple-output (MIMO), or multiple-input single-output (MISO) techniques.

[0065] Antenna 530 can correspond to one or multiple antennas and can be configured to provide for wireless communications between machine 500 and another device. Antenna(s) 530 can be arranged to operate using one or more wireless communication protocols and operating frequencies including the IEEE 802.15.1, Bluetooth, Bluetooth Low Energy (BLE), near field communications (NFC), ZigBee, GSM, CDMA, Wi-Fi, RF, UWB, and the like. By way of example, antenna(s) 530 can be RF antenna(s), and as such, may transmit / receive RF signals through free-space to be received / transferred by another device having an RF transceiver.

[0066] Power source 532 can be any suitable internal power source, such as a battery, capacitive power source or similar type of charge-storage device, etc., or can include one or more power conversion circuits suitable to convert external power into suitable power (e.g., conversion of externally supplied AC power into DC power) for components of the machine 500. Power source 532 can also include some implementation of surge protection circuitry to protect the components of machine 500 from power surges. As indicated above, machine 500 can include an interlink 534 operable to transmit communications between the various hardware components of the machine. The interlink 534 can be any of several types of commercially available bus structures or bus architectures.

[0067] With reference back to FIGs. 1-3, a user may approach a credential reader device 102, and a credential device may communicate the user’s credential or credential data to the credential reader device 102, for example, via a suitable RFID or PAN technology. In some examples, a user credential device may include be a portable device having memory, storing one or more user credentials or credential data, and a reader interface (i.e., an antenna and Integrated Circuit (IC) chip), which permits the credential to exchange data with a reader device, such as credential reader device 102, via a credential interface of the reader device, such as antenna 406. More generally, and as indicated above, the credential device may include some, any, or all of the various components described above with respect to the block diagram schematic of FIG. 5. In some example embodiments, reader device 102 and credential device may be the same device, wherein, for example, the user may be attempting to access a logical asset via the user’s own mobile device. If credential reader device 102 or other device determines that the user’s credential or credential data provided by credential device is valid or authorized, credential reader device 102 may operate a control mechanism to allow access to a secure physical asset by the user having the credential device.Additional Examples

[0068] Example 1 is a method for communicating access status in a secure access control system, the method comprising: receiving an access request from a user access credential device at a secure access reader; transmitting the access request from the secure access reader to a secure access controller; receiving a visual access signal or auditory access signal from the secure access controller, the visual access signal or auditory access signal indicating an access status response from the secure access controller; and transmitting data indicative of the access status response from the secure access reader to the user access credential device.

[0069] In Example 2, the subject matter of Example 1 includes wherein the secure access reader includes firmware modified to convert the visual access signal or auditory access signal into a digital message format suitable for transmission to the user access credential device.

[0070] In Example 3, the subject matter of Examples 1-2 includes wherein the secure access reader includes a visual input sensor or audible input sensor to identify the visual access signal or auditory access signal.

[0071] In Example 4, the subject matter of Example 1-3 includes wherein the visual access signal or auditory access signal include one or more of light emitting diode (LED) or beeper responses in a sequence, pattern, or combination thereof.

[0072] In Example 5, the subject matter of Examples 1-4 includes wherein a first communication protocol between the secure access reader and the secure access controller includes a bidirectional communication protocol.

[0073] In Example 6, the subject matter of Example 5 includes wherein the bidirectional communication protocol includes an Open Supervised Device Protocol (OSDP).

[0074] In Example 7, the subject matter of Examples 1-6 includes wherein the user access credential device communicates with the secure access reader using at least one of Near Field Communication (NFC) or Bluetooth Low Energy (BLE).

[0075] In Example 8, the subject matter of Examples 1-7 includes determining the access status response includes an access denied status; and sending a status denied notification to a secure access administrator system, the status denied notification including a plurality of access attempt details.

[0076] In Example 9, the subject matter of Examples 1-8 includes wherein the secure access reader is configured to maintain a communication session between receiving the access request and transmitting data indicative of the access status response.

[0077] In Example 10, the subject matter of Examples 1-9 includes wherein: a first type of communication channel is used to receive the access request from the user access credential device at the secure access reader; and the first type of communication channel is used to transmit data indicative of the access status response from the secure access reader to the user access credential device.

[0078] In Example 11, the subject matter of Examples 1-10 includes determining that a predetermined access response period has elapsed before receiving the access status response; and transmitting an error message to the user access credential device, the error message indicating the predetermined access response period has elapsed.

[0079] In Example 12, the subject matter of Examples 1-11 includes wherein the secure access reader is configured to log access attempts and outcomes for security auditing purposes.

[0080] In Example 13, the subject matter of Examples 1-12 includes wherein the secure access reader is configured to operate in multiple communication modes based on one or more available communication protocols.

[0081] Example 14 is a system for secure access control, the system comprising: a secure access reader including a processor and memory including instructions, the instructions causing the secure access reader to: receive an access request from a user access credential device; transmit the access request to a secure access controller; identify a visual access signal or auditory access signal from the secure access controller, the visual access signal or auditory access signal indicating an access status response from the secure access controller; and transmit data indicative of the access status response to the user access credential device.

[0082] In Example 15, the subject matter of Example 14 includes wherein the secure access reader includes firmware modified to convert the visual access signal or auditory access signal into a digital message format suitable for transmission to the user access credential device.

[0083] In Example 16, the subject matter of Examples 14-15 includes wherein the secure access reader includes a visual input sensor or audible input sensor to identify the visual access signal or auditory access signal.

[0084] In Example 17, the subject matter of Example 16 includes wherein the visual access signal or auditory access signal include one or more of light emitting diode (LED) or beeper responses in a sequence, pattern or combination thereof.

[0085] In Example 18, the subject matter of Examples 14-17 includes wherein a first communication protocol between the secure access reader and the secure access controller includes a bidirectional communication protocol.

[0086] In Example 19, the subject matter of Example 18 includes wherein the bidirectional communication protocol includes an Open Supervised Device Protocol (OSDP).

[0087] In Example 20, the subject matter of Examples 14-19 includes wherein the user access credential device is configured to communicate with the secure access reader using at least one of Near Field Communication (NFC) or Bluetooth Low Energy (BLE).

[0088] In Example 21, the subject matter of Examples 14-20 includes the instructions further causing the secure access reader to: determine the access status response includes an access denied status; and send a status denied notification to a secure access administrator system, the status denied notification including a plurality of access attempt details.

[0089] In Example 22, the subject matter of Examples 14-21 includes wherein the secure access reader is configured to maintain a communication session between receiving the access request and transmitting data indicative of the access status response.

[0090] In Example 23, the subject matter of Examples 14-22 includes wherein: a first type of communication channel is used to receive the access request from the user access credential device at the secure access reader; and the first type of communication channel is used to transmit data indicative of the access status response from the secure access reader to the user access credential device.

[0091] In Example 24, the subject matter of Examples 14-23 includes the instructions further causing the secure access reader to: determine that a predetermined access response period has elapsed before receiving the access status response; and transmit an error message to the user access credential device, the error message indicating the predetermined access response period has elapsed.

[0092] In Example 25, the subject matter of Examples 14-24 includes wherein the secure access reader is configured to log access attempts and outcomes for security auditing purposes.

[0093] In Example 26, the subject matter of Examples 14-25 includes wherein the secure access reader is configured to operate in multiple communication modes based on one or more available communication protocols.

[0094] Example 27 is a non-transitory computer-readable medium storing instructions that, when executed by one or more processors of a secure access reader, cause the secure access reader to perform operations comprising: receiving an access request from a useraccess credential device; transmitting the access request to a secure access controller; identifying a visual access signal or auditory access signal from the secure access controller, the visual access signal or auditory access signal indicating an access status response from the secure access controller; and transmitting data indicative of the access status response to the user access credential device.

[0095] In Example 28, the subject matter of Example 27 includes wherein the instructions further cause the secure access reader to convert the visual access signal or auditory access signal into a digital message format suitable for transmission to the user access credential device.

[0096] In Example 29, the subject matter of Examples 27-28 includes wherein identifying the visual access signal or auditory access signal is performed using a visual input sensor or audible input sensor of the secure access reader.

[0097] In Example 30, the subject matter of Example 29 includes wherein the visual access signal or auditory access signal include light emitting diode (LED) or beeper responses.

[0098] In Example 31, the subject matter of Examples 27-30 includes wherein a first communication protocol between the secure access reader and the secure access controller includes a bidirectional communication protocol.

[0099] In Example 32, the subject matter of Example 31 includes wherein the bidirectional communication protocol includes an Open Supervised Device Protocol (OSDP).

[0100] In Example 33, the subject matter of Examples 27-32 includes wherein the user access credential device communicates with the secure access reader using at least one of Near Field Communication (NFC) or Bluetooth Low Energy (BLE).

[0101] In Example 34, the subject matter of Examples 27-33 includes wherein the operations further comprise: determining the access status response includes an access denied status; and sending a status denied notification to a secure access administrator system, the status denied notification including a plurality of access attempt details.

[0102] In Example 35, the subject matter of Examples 27-34 includes wherein the operations further comprise maintaining a communication session between receiving the access request and transmitting data indicative of the access status response.

[0103] In Example 36, the subject matter of Examples 27-35 includes wherein: a first type of communication channel is used to receive the access request from the user access credential device; and the first type of communication channel is used to transmit data indicative of the access status response to the user access credential device.

[0104] In Example 37, the subject matter of Examples 27-36 includes wherein the operations further comprise: determining that a predetermined access response period has elapsed before receiving the access status response; and transmitting an error message to the user access credential device, the error message indicating the predetermined access response period has elapsed.

[0105] In Example 38, the subject matter of Examples 27-37 includes wherein the operations further comprise logging access attempts and outcomes for security auditing purposes.

[0106] In Example 39, the subject matter of Examples 27-38 includes wherein the operations further comprise operating in multiple communication modes based on one or more available communication protocols.

[0107] Example 40 is a method for communicating access status as part of validating an authentication request in a secure access control system, the method comprising: receiving an access request from a user near-field credential device at a secure access reader; transmitting the access request from the secure access reader to a secure access controller; receiving a visual access signal or auditory access signal from the secure access controller, the visual access signal or auditory access signal indicating at least an access status response from the secure access controller; transmitting data indicative of the access status response from the secure access reader to a mobile device.

[0108] In Example 41, the subject matter of Example 40 includes transmitting additional data from the secure access reader for further authentication to the mobile device; and transmitting from the secure access reader the additional data to the secure access controller, wherein the additional data is generated by the secure access reader.

[0109] In Example 42, the subject matter of Example 40 includes transmitting additional data from the secure access reader for further authentication to the mobile device, wherein the additional data is generated by the secure access controller and transmitted to the secure access reader as part of the access status response.

[0110] In Example 43, the subject matter of Example 42 includes transmitting additional data for further authentication to the mobile device, wherein the additional data: is received as part of the access status response, includes a pattern of visual and / or auditory signals, and is converted into the additional data by the secure access reader.

[0111] In Example 44, the subject matter of Examples 40-43 includes wherein the additional data comprises a randomly generated code.

[0112] In Example 45, the subject matter of Examples 40-43 includes wherein the additional data comprises data representing a credential authentication session.

[0113] In Example 46, the subject matter of Examples 40-43 includes wherein the additional data comprises data identifying the secure access reader.

[0114] In Example 47, the subject matter of Examples 40-46 includes granting physical or logical access based on the secure access controller determining at least one of: identifying information of the mobile device is associated with the near-field credential device or the additional data transmitted by the secure access reader to the secure access controller matches the additional data received from the mobile device.

[0115] In Example 48, the subject matter of Example 40 includes granting physical or logical access based on the secure access controller determining a user has indicated approval of a further authentication request through the mobile device and the mobile device is associated with the near-field credential device.

[0116] In Example 49, the subject matter of Example 40 includes wherein the data indicative of the access status response transmitted to the mobile device comprises additional data comprising one or more visual and / or auditory signals received by the reader from the controller.

[0117] In Example 50, the subject matter of Example 40 and 49 includes wherein the transmitting of the additional data from the reader to the mobile device is in response to the reader receiving the access status response data including the additional data from the controller.

[0118] In Example 51, the subject matter of Example 50, includes wherein the reader adjusts one or more of a frequency or an amplitude of one or more visual and / or auditory signals of the additional data.

[0119] In Example 52, the subject matter of Example 51, includes wherein the adjustment of the one or more of the frequency or amplitude is based on hardware characteristics known about the controller and / or the reader.

[0120] In Example 53, the subject matter of Example 50-52, includes wherein the reader receiving the additional data from the controller is in response to the controller receiving a signal from the mobile device indicating the mobile device is ready to receive data from the reader.

[0121] In Example 54, the subject matter of Example 51-53, includes wherein the controller receiving a ready signal from the mobile device is in response to the controller establishing an additional secure communication channel with the mobile device after orconcurrent with authenticating the user near-field credential device that is associated with the mobile device.

[0122] In Example 55, the subject matter of Examples 49-54, includes wherein the mobile device interprets the additional data received from the reader by converting the visual and / or auditory signals into a digital signal representing the additional data.

[0123] In Example 56, the subject matter of Example 54-54 includes wherein the mobile device transmits a ready signal after or concurrent with establishing a communication channel with the reader over a local-proximity communication channel.

[0124] In Example 57, the subject matter of Example 54-55, includes wherein the mobile device transmits a ready signal after or concurrent with being placed in front of the reader and enabling one or more of a camera and a microphone on the mobile device.

[0125] In Example 58, the subject matter of Example 57, includes wherein at least one of local-proximity communications, camera, or microphone is enabled in response to a command issued by the user of the mobile device after receiving a request from the controller to place the mobile device in a ready mode.

[0126] In Example 59, the subject matter of Example 40-58 includes wherein the secure access controller opens an additional secure channel with a mobile device whose identity has previously been associated with the credential presented for authentication, and the mobile device transmits additional data received from the secure access reader to the secure access controller through the additional secure channel.

[0127] In Example 60, the subject matter of Example 41-59, includes wherein the access control system signals one or more of an administrator or security personnel in response to a failure of an additional authentication due to one or more conditions, including a mismatch of additional data transmitted from the mobile device to the controller compared to the additional data transmitted from the controller to the reader, a mismatch of an identification of the mobile device compared to the mobile device identification associated with the user near-field credential device, a negative indication from the user in response to the request to validate the access request, or a timeout of the additional authentication process.

[0128] Example 61 is at least one machine-readable medium including instructions that, when executed by processing circuitry, cause the processing circuitry to perform operations to implement any of Examples 1-60.

[0129] Example 62 is an apparatus comprising means to implement any of Examples 1-60.

[0130] Example 63 is a system to implement any of Examples 1-60.

[0131] Example 64 is a method to implement any of Examples 1-60.Additional Notes

[0132] The above detailed description includes references to the accompanying drawings, which form a part of the detailed description. The drawings show, by way of illustration, specific embodiments that can be practiced. These embodiments may also be referred to herein as “examples.” Such embodiments or examples can include elements in addition to those shown or described. However, the present inventors also contemplate examples in which only those elements shown or described are provided. Moreover, the present inventors also contemplate examples using any combination or permutation of those elements shown or described (or one or more aspects thereof), either with respect to a particular example (or one or more aspects thereof), or with respect to other examples (or one or more aspects thereof) shown or described herein. That is, the above-described embodiments or examples or one or more aspects, features, or elements thereof can be used in combination with each other.

[0133] As will be appreciated by one of skill in the art, the various embodiments of the present disclosure may be embodied as a method (including, for example, a computer-implemented process, a business process, or any other process), apparatus (including, for example, a system, machine, device, computer program product, or the like), or a combination of the foregoing. Accordingly, embodiments of the present disclosure or portions thereof may take the form of an entirely hardware embodiment, an entirely software embodiment (including firmware, middleware, microcode, hardware description languages, etc.), or an embodiment combining software and hardware aspects. Furthermore, embodiments of the present disclosure may take the form of a computer program product on a computer-readable medium or computer-readable storage medium, having computerexecutable program code embodied in the medium, that define processes or methods described herein. A processor or processors may perform the necessary tasks defined by the computer-executable program code. In the context of this disclosure, a computer readable medium may be any medium that can contain, store, communicate, or transport the program for use by or in connection with the systems disclosed herein. As indicated above, the computer readable medium may be, for example but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device. More specific examples of suitable computer readable medium include, but are not limited to, anelectrical connection having one or more wires or a tangible storage medium such as a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), a compact disc read-only memory (CD-ROM), or other optical, magnetic, or solid state storage device. As noted above, computer-readable media includes but is not to be confused with, computer-readable storage medium, which is intended to cover all physical, non-transitory, or similar embodiments of computer-readable media.

[0134] In the foregoing description various embodiments of the present disclosure have been presented for the purpose of illustration and description. They are not intended to be exhaustive or to limit the invention to the precise form disclosed. Obvious modifications or variations are possible in light of the above teachings. The various embodiments were chosen and described to provide the best illustration of the principals of the disclosure and their practical application, and to enable one of ordinary skill in the art to use the various embodiments with various modifications as are suited to the particular use contemplated. All such modifications and variations are within the scope of the present disclosure as determined by the appended claims when interpreted in accordance with the breadth they are fairly, legally, and equitably entitled.

Claims

CLAIMSWhat is claimed is:

1. A method for communicating access status in a secure access control system, the method comprising:receiving an access request from a user access credential device at a secure access reader;transmitting the access request from the secure access reader to a secure access controller;receiving a visual access signal or auditory access signal from the secure access controller, the visual access signal or auditory access signal indicating an access status response from the secure access controller; andtransmitting data indicative of the access status response from the secure access reader to the user access credential device.

2. The method of claim 1, wherein the secure access reader includes firmware modified to convert the visual access signal or auditory access signal into a digital message format suitable for transmission to the user access credential device.

3. The method of claim 1, wherein the secure access reader includes a visual input sensor or audible input sensor to identify the visual access signal or auditory access signal.

4. The method of claim 1, wherein a first communication protocol between the secure access reader and the secure access controller includes a unidirectional communication protocol.

5. The method of claim 1, wherein the user access credential device communicates with the secure access reader using at least one of Near Field Communication (NFC) or Bluetooth Low Energy (BLE).

6. The method of claim 1, further including:determining the access status response includes an access denied status; and sending a status denied notification to a secure access administrator system, the status denied notification including a plurality of access attempt details.

7. The method of claim 1, wherein the secure access reader is configured to maintain a communication session between receiving the access request and transmitting data indicative of the access status response.

8. The method of claim 1, wherein:a first type of communication channel is used to receive the access request from the user access credential device at the secure access reader; andthe first type of communication channel is used to transmit data indicative of the access status response from the secure access reader to the user access credential device.

9. The method of claim 1, further including:determining that a predetermined access response period has elapsed before receiving the access status response; andtransmitting an error message to the user access credential device, the error message indicating the predetermined access response period has elapsed.

10. A system for secure access control, the system comprising:a secure access reader including a processor and memory including instructions, the instructions causing the secure access reader to:receive an access request from a user access credential device;transmit the access request to a secure access controller;identify a visual access signal or auditory access signal from the secure access controller, the visual access signal or auditory access signal indicating an access status response from the secure access controller; andtransmit data indicative of the access status response to the user access credential device.

11. The system of claim 10, wherein the secure access reader includes firmware modified to convert the visual access signal or auditory access signal into a digital message format suitable for transmission to the user access credential device.

12. The system of claim 10, wherein the secure access reader includes a visual input sensor or audible input sensor to identify the visual access signal or auditory access signal.3413. The system of claim 10, wherein a first communication protocol between the secure access reader and the secure access controller includes a unidirectional communication protocol.

14. The system of claim 10, wherein the user access credential device is configured to communicate with the secure access reader using at least one of Near Field Communication (NFC) or Bluetooth Low Energy (BLE).

15. The system of claim 10, the instructions further causing the secure access reader to:determine the access status response includes an access denied status; and send a status denied notification to a secure access administrator system, the status denied notification including a plurality of access attempt details.

16. The system of claim 10, wherein:a first type of communication channel is used to receive the access request from the user access credential device at the secure access reader; andthe first type of communication channel is used to transmit data indicative of the access status response from the secure access reader to the user access credential device.

17. The system of claim 10, the instructions further causing the secure access reader to:determine that a predetermined access response period has elapsed before receiving the access status response; andtransmit an error message to the user access credential device, the error message indicating the predetermined access response period has elapsed.

18. A non-transitory computer-readable medium storing instructions that, when executed by one or more processors of a secure access reader, cause the secure access reader to perform operations comprising:receiving an access request from a user access credential device;transmitting the access request to a secure access controller;identifying a visual access signal or auditory access signal from the secure access controller, the visual access signal or auditory access signal indicating an access status response from the secure access controller; andtransmitting data indicative of the access status response to the user access credential device.

19. The non-transitory computer-readable medium of claim 18, wherein the instructions further cause the secure access reader to convert the visual access signal or auditory access signal into a digital message format suitable for transmission to the user access credential device.

20. The non-transitory computer-readable medium of claim 18, wherein identifying the visual access signal or auditory access signal is performed using a visual input sensor or audible input sensor of the secure access reader.