Beacon and device location verification using broadcast location data

The system fortifies PACS against relay attacks by using beacon signal authentication with location verification and environmental signal fingerprinting, ensuring only authorized devices can access secure areas, thus enhancing security and integrity.

WO2026117229A1PCT designated stage Publication Date: 2026-06-04ASSA ABLOY AB

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
ASSA ABLOY AB
Filing Date
2024-11-26
Publication Date
2026-06-04

AI Technical Summary

Technical Problem

Conventional Physical Access Control Systems (PACS) are vulnerable to relay attacks where unauthorized third parties manipulate beacon signals to gain access to secure areas, compromising security and authenticity of user credentials.

Method used

The system employs beacon signal authentication using location verification and environmental signal fingerprinting to ensure the beacon signal is genuine, involving credential device and authentication server collaboration to confirm the device's proximity to the authorized access point, utilizing GPS, beacon identifiers, and environmental wireless signals for validation.

Benefits of technology

Enhances security by preventing unauthorized access through relay attacks, ensuring that only genuine beacon signals from authorized devices are recognized, thereby improving the integrity of access control processes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure US2024057481_04062026_PF_FP_ABST
    Figure US2024057481_04062026_PF_FP_ABST
Patent Text Reader

Abstract

A physical access control (PAC) system includes a reader device configured to receive credential information from a credential device; a beacon transmitting device configured to transmit a beacon signal detectable by the credential device; and an mauthentication server. The authentication server includes a first communication channel configured to communicate information with the credential device; a second communication channel configured to communicate information with the reader device; and server processing circuitry. The server processing circuitry is configured to receive beacon signal information from the credential device and send beacon signal authentication information to the credential device; receive credential information from the reader device when the beacon signal is authenticated; and initiate access to a physical access portal conditional on authentication of the credential information.
Need to check novelty before this filing date? Find Prior Art

Description

BEACON AND DEVICE LOCATION VERIFICATION USING BROADCAST LOCATION DATATECHNICAL FIELD

[0001] Embodiments illustrated and described herein generally relate to system architectures for physical access control systems.BACKGROUND

[0002] Seamless access control refers to when physical access is granted to an authorized user through a controlled portal without requiring intrusive actions of the user such as entering or swiping an access card at a card reader or entering a personal identification number (PIN) or password. A Physical Access Control System (PACS) is a type of system that can provide seamless access. A PACS authenticates and authorizes a person to pass through a physical access point such as a secured door. Improvements to PAC systems are described herein having innovative interplay between wireless technologies, smart phones, and access system infrastructure. These improvements enhance the security of the overall system and lead to a better user experience.BRIEF DESCRIPTION OF THE DRAWINGS

[0003] FIG. 1 is a block diagram of an example of a basic Physical Access Control System (PACS) structure.

[0004] FIG. 2 is a flow diagram of an example of a method of operating a PACS.

[0005] FIG. 3 is a block diagram of another example of a PACS structure.

[0006] FIG. 4 is a block diagram of still another example of a PACS structure.

[0007] FIG. 4 is a block diagram of a further example of a PACS structure.

[0008] FIG. 6 is a flow diagram of another example of a method of operating aPACS.

[0009] FIG. 7 is a block diagram schematic of portions of an example of an authentication device.DETAILED DESCRIPTION

[0010] FIG. 1 is a block diagram of an example of a basic PACS structure that authenticates access to a physical portal using a credential device. The credential device 102presents an access credential to a reader device 106 to gain access to through a secured physical access portal (e.g., secured door 108) to enter a secure area 110. The access credential may be a data object, a piece of knowledge (e.g., PIN, password, etc.), or a facet of the person’s physical being (e.g., face, fingerprint, etc.) that provides proof of the person’s identity.

[0011] The credential device 102 stores the credential information 104 when the access credential is a data object. The credential device 102 may be a smartphone, or tablet computer. Other examples of Credential Devices include, but are not limited to, key fobs, near field communication (NFC) enabled devices, personal digital assistants (PDAs), or any other device configurable to emulate a virtual credential. The reader device 106 can include an automatic locking / unlocking mechanism for the physical access portal, or the PACS can include a separate access controller that communicates with the reader device 106 to control the automatic locking / unlocking mechanism of an automatic lock that may be integral to or separate from the access controller.

[0012] The PACS includes a beacon transmitting device 112 positioned in the vicinity of the controlled access portal and reader device 106 or may be integral to the reader device 106. A beacon signal broadcast by the beacon transmitting device 112 advertises the presence of the reader device 106. When the credential device 102 detects a beacon signal from the beacon transmitting device 112, the credential device 102 sends the credential information 104 to the reader device 106 using a wireless communication protocol. For example, if the credential device 102 is a smartphone, the smartphone may be enabled in a read mode or scan mode to look for a beacon signal from the beacon transmitting device 112. The smartphone may support background BLE scanning when the smartphone is configured as a Bluetooth™ central device. A Resource Access Application or App 118 of the smartphone may be activated or wakened when the beacon signal is detected. BLE is only an example and other wireless protocols either long range or short range can be used. The term beacon signal is intended to include all wireless signals that can potentially serve the functions of the beacon signal described herein.

[0013] The PACS system includes an authentication server 114. The authentication server 114 includes processing circuitry. The processing circuitry can include one or more processors and memory, and software or firmware to execute on the processor to perform the functions described for the authentication server 114. The authentication server described herein may consist of several components (sub-systems) of more than one server, including hardware controllers and cloud services. The reader device 106 sends the credentialinformation 104 to the authentication server 114 for authentication of the credential device 102. The credential information 104 may be communicated to the authentication server 114 using a communication channel 116. In certain examples, the communication channel is a secure channel between the reader device 106 and the authentication server 114. In certain examples, the communication channel may include secure messaging via the cloud.

[0014] The authentication server 114 authenticates the credential information 104. The authentication server 114 may authenticate the credential device 102 by comparing the credential information 104 to an access control list. Authentication is successful or not successful based on the comparison to the list. If the authentication is successful, the authentication server 114 may transmit information to the reader device 106 or an access controller to allow access. If the authentication is not successful, the authentication server 114 may deny access.

[0015] The system operation described may use a passive beacon signal to broadcast the location of the physical portal. The PACS uses the beacon signal to facilitate determining whether an access control request is being made and utilize the access credential information to validate the credential device of the user. However, conventional methods of broadcasting a beacon signal may be compromised, manipulated, or inaccurate. For example, in a relay attack scenario, an unauthorized third party may attempt to gain access to a secured area by employing a variety of tactics to the trick the PACS into granting access. In one type of relay attack, a credential device may be tricked into presenting the authorized access credential information. For instance, the credential device 102 may be presented a manipulated or false beacon signal to cause the credential device 102 to enter authentication mode, allowing entry by the unauthorized third party to the secure area. In another attack, the credential information 104 of the credential device 102 may be captured by the unauthorized third party who then manipulates the authentication process to gain access to the secure area.

[0016] FIG. 2 is a flow diagram of an example of a method 200 of operating a PACS, such as the PACS example of FIG. 1, that mitigates third party attacks. The credential device 102 authenticates the beacon signal to confirm that the beacon signal is associated with an authorized device (e.g., reader device 106) with which the credential device 102 should interact to authenticate. At block 205, the credential device 102 detects a beacon signal. At block 210, the beacon signal is authenticated as a valid beacon signal. Different techniques can be used to authenticate the beacon signal.

[0017] In some examples, credential device location is used to authenticate the beacon signal. The beacon signal can include an identifier (e.g., a predetermined bit pattern orcode) of the beacon signal. Credential device location may be ascertained in real time and compared to a pre-defined location of the beacon transmitting device 112 or the physical access portal. The authentication of the beacon signal can involve confirming that the location of the credential device 102 corresponds to the known location of the beacon transmitting device 112 and reader device 106.

[0018] In some examples, the credential device 102 sends a request to the authentication server 114 for authentication of the beacon signal by the authentication server 114. The credential device 102 may determine its location using the Global Positioning System (GPS) or other geolocation technique. The request message to the authentication server 114 may include the beacon signal identifier received in the beacon signal and location information of the credential device 102. The authentication server 114 may receive the request via another communication channel 120 different from the communication channel used by the authentication server 114 to communicate with the reader device 106. The authentication server 114 authenticates the beacon signal. The authentication server 114 uses the beacon identifier to determine location information for the identified beacon signal. Beacon signal location information can be stored in a database in memory of the authentication server 114. The database can include a list of beacon signal identifiers for beacon signals transmitted by multiple beacon transmitting devices and location information of the beacon transmitting devices. The authentication server 114 authenticates the beacon signal using the identifier of the beacon signal, the stored location information for the identified beacon signal, and the location information of the credential device based on whether the credential device location matches the stored beacon transmitting device location.

[0019] At block 215, if the beacon signal is authenticated, the PACS proceeds further in the process of the authentication of the credential device 102. The credential device 102 has determined that the received beacon signal is associated with a device that it is authorized to interact with. The credential device 102 may transfer the credential information 104 to the reader device 106 using a secure communication session initiated by either the credential device 102 or the reader device 106 as part of the authentication process.

[0020] At block 220, if the beacon signal is not authenticated, the process of the authentication of the credential device 102 ends. The authentication server 114 may send a response message to the credential device that the beacon signal is not authenticated and the credential device 102 stops communication and does not communicate the credential information 104. In certain examples, the authentication server 114 stops communicationwith the credential device when the authentication of the beacon signal fails. The communication of the credential device 102 times out and the credential device 102 does not communicate the credential information 104.

[0021] At block 225, when the beacon signal is authenticated, the authentication server 114 continues with the authentication process. The credential device 102 sends the credential information 104 to the reader device 106, and the authentication server 114 receives the credential information 104 from the reader device 106. At block 230, if the credential device is authenticated, the authentication server may initiate access to the physical access portal by sending message to the reader device 106 that the credential device is authenticated. In certain examples, the authentication server sends an activation signal to an access controller at the physical access portal to unlock the portal.

[0022] In some examples, the credential device 102 authenticates the beacon signal at block 210 instead of or in addition to the authentication by the authentication server 114. The credential device 102 may include a memory that stores the predefined beacon transmitting device location. When the credential device 102 detects the beacon signal, an App 118 may decode the beacon identifier in the beacon signal. The App 118 sends the beacon identifier to the authentication server 114 via the communication channel 120. The authentication server 114 receives the beacon identifier and sends the associated beacon location information for the identified beacon signal to the credential device 102. The App 118 authenticates the beacon signal using the received beacon location information and the location of the credential device based on whether the credential device location matches the beacon transmitting device location. If the beacon signal is authenticated, the credential device 102 proceeds with the process of authentication at block 210 and sends credential information 104 to the reader device 106. If the beacon signal is not authenticated, the credential device ends the process of process of authentication of the credential device at block 220.

[0023] In some examples, the credential device 102 includes enough storage to beacon signal identifiers in association with corresponding location information for the beacon signals. This database of beacon signal identifiers and location information may be pre-provisioned in the credential device 102 and recurrently re-provisioned. The App 118 compares stored location information corresponding to the beacon signal identifier received in the signal to the location to the current location of the credential device 102. The App 118 authenticates the beacon signal when the current location of the credential device 102 is logically within the corresponding stored location information. If the beacon signal is authenticated by the credential device 102, the credential device 102 proceeds with theprocess of authentication at block 210 and sends credential information 104 to the reader device 106. If the beacon signal is not authenticated, the credential device ends the process of process of authentication of the credential device at block 220. This approach of provisioning the credential device 102 with the beacon signal authentication information may include cryptographic protection of information in the beacon signal, such as the identifier, as described herein. In certain examples, the credential device 102 stores beacon signal identifiers it receives and stores the identifiers in association with location information in a rolling buffer.

[0024] In some examples, the beacon transmitting device 112 broadcasts a beacon signal that includes location data indicating the predefined beacon location as part of the beacon identifier or as part of a beacon signature. The location data may be configurable by an administrator at the time of the installation of the reader device 106 and the beacon transmitting device 112. The location portion of the beacon identifier may be represented by a dictionary system associating a code or phrase with the particular global coordinates of the beacon signal location. The credential device 102 detects the beacon signal that is being broadcast and the App 118 authenticates the beacon signal when the location of the credential device 102 is logically within the expected vicinity of the beacon signal based upon the location portion.

[0025] Alternatively, the credential device 102 may send the authentication server 114 the location data of the detected beacon signal and the current geolocation information of the credential device 102. The authentication server 114 then determines (at block 215 of FIG. 2) whether to proceed further with the process of authenticating the credential device 102 based on whether the location data of the detected beacon signal corresponds to the credential device geolocation. The determination of correspondence may be configurable based on a threshold distance or proximity of the credential device to the location data.

[0026] When the beacon signal incorporates its expected geolocation in the beacon signal itself, the broadcasted location cannot be changed without altering the beacon signal itself, which would disrupt the authentication process for the associated physical portal. In some examples, the beacon signal is broadcast with an authentication signature to protect against tampering of the beacon signal. During installation, the beacon signal would be configured by the administrator based on and incorporating the installation location. The authentication server 114 may also compare the detected beacon signal with a stored list of all known beacon signals installed in the access control system, which provides an additional check to validate an authentication or access request. If the detected beacon signal locationdata does not match the beacon signal for a known installation (e.g., because the location portion of the signal has been altered), the authentication server 114 may refuse to open or complete the remainder of the process of authenticating the credential device 102.

[0027] FIG. 3 is a block diagram of another example of a basic PACS structure. In the example, the beacon transmitting device 112 broadcasts beacon credential information 122 in the beacon signal. The beacon transmitting device 112 is provisioned credential information 122 that is uniquely associated with the physical access portal. The beacon credential information may be encrypted and may cryptographically protected (e.g., using a digital signature) like the credential information 104 stored in the credential device 102. The App 118 of the credential device 102 may implement a beacon reader subsystem in the credential device 102. The beacon credential information 122 is also associated with one or more beacon reader subsystem identities in the authentication server 114, with each beacon reader subsystem identity being uniquely associated with a reader device 106. The beacon transmitting device 112 may transmit the beacon credential information using a credential messaging protocol adapted for beacon credential messaging. The beacon transmitting device 112 may be located within the secure area 110 and may broadcast the beacon signal from within the secure area 110.

[0028] The credential device 102 detects the beacon signal and the App 118 extracts the beacon credential information transmitted in the beacon signal. The credential device 102 sends the beacon credential information to the authentication server 114. The authentication server 114 then authenticates the received beacon credential information and may confirm that the relaying beacon reader subsystem identity of the credential device 102 corresponds with the transmitted beacon credential information. Alternatively, the App 118 may authenticate the received beacon credential information. If the beacon credential information is valid and corresponds with the beacon reader subsystem identity of the credential device 102, the authentication server 114 grants access to the physical access portal associated with the beacon credential information. The credential device 102 initiates a secure communication channel 124 with the reader device 106 to send the credential information 104 of the credential device 102 when the beacon credential information is authenticated.

[0029] In some examples, the beacon transmitting device 112 does not transmit the beacon credential information in the beacon signal. The credential device 102 obtains the beacon credential information at the location of the physical access portal. For instance, the credential device 102 may obtain the beacon credential information from a tag mounted at the at the location of the physical access portal. The tag may be a radio frequency identifier(RFID) tag and the credential device reads the beacon credential information using near field wireless communication. In another example, the tag at the location of the physical access portal may include a Quick Response (QR) code and the credential device 102 scans the beacon credential information of the tag. The credential device 102 sends the beacon credential information to the authentication server 114. When the beacon credential information is authenticated, the credential device 102 may initiate a secure communication session with the reader device 106 to send the credential information 104 of the credential device 102.

[0030] FIG. 4 is a block diagram of another example of a basic PACS structure that authenticates access to a physical portal using a credential device. Like the example of FIG. 1, in the example of FIG. 4, the credential device 102 presents an access credential to a reader device 106 to gain access to through a secured physical access portal (e.g., secured door 108) to enter a secure area 110. An authentication server 114 authenticates the credential information 104. The PACS includes a beacon transmitting device 112 positioned in the vicinity of the controlled access portal and reader device 106 or the beacon transmitting device 112 may be integral to the reader device 106. The beacon signal is authenticated to confirm that the beacon signal is associated with an authorized device (e.g., reader device 106) with which the credential device 102 should interact to authenticate. The block diagram also shows environmental signals 432 expected to be present in the environment of the physical access portal.

[0031] Operation of the PACS example of FIG. 4 to mitigate third party attacks can be described using the flow diagram of the example method 200 of FIG. 2. At block 205, the credential device 102 detects a beacon signal transmitted by the beacon transmitting device 112. The credential device 102 may be a smartphone and detects the beacon signal using the device detection feature. At block 210, the beacon signal is authenticated as a valid beacon signal to confirm that the beacon signal is associated with an authorized device (e.g., reader device 106) with which the credential device 102 should interact to authenticate. As in the previous examples of FIGS 1 and 3, the location of the credential device 102 is used to authenticate the beacon signal. The beacon signal can include a beacon signal and the identified beacon signal is authenticated if the location of the credential device matches or corresponds sufficiently to the known location of the physical access portal with the transmitting beacon device 112. Knowing that the credential device 102 is at the physical access portal ensures that the beacon signal is genuine and is not being sent as part of a relay attack.

[0032] That the credential device 102 is at the physical access portal location and the beacon is genuine may be confirmed in real time when the credential device 102 detects the environmental signals 432 expected to be broadcast in the environment of the physical access portal. When the environmental signals 432 are present, the beacon signal is authenticated and the credential device 102 reveals its credential information 104. For a relay attack to work with this approach, it would not be sufficient to fool the credential device 102 by reproducing the one beacon signal of the physical access portal, the attack would need to reproduce the wireless signal environment of the physical access portal.

[0033] According to some examples, the credential device 102 alone can authenticate the beacon signal at block 210 in FIG. 2. The credential device 102 may authenticate the beacon signal when detecting an expected wireless signal expected to be present with the beacon signal. For instance, the credential device 102 may detect a wireless signal that is different from the beacon signal and extract an identifier from the detected wireless signal. The identifier of the candidate detected signal may be a bit pattern or code included in the detected wireless signal. The credential device 102 may store an expected signal identifier (e.g., in a memory of the credential device 102). The credential device 102 may include an App 118 to extract and decode the identifier and compare the extracted identifier and the stored expected identifier. The credential device 102 may store multiple expected signal identifiers. Which expected signal identifier to use in the comparison is determined from the beacon signal identifier.

[0034] At block 215, if the extracted identifier does not match the stored expected signal identifier, the App 118 ends the process to authenticate the credential device 102. At block 220, if the extracted identifier matches the stored expected signal identifier, the beacon signal is authenticated the credential device 102 proceeds further with the process of authentication of the credential device 102 with the authentication server 114. For instance, the credential device 102 may send the credential information 104 to the reader device 106 for authentication by the authentication server 114 in response to authenticating the beacon signal. The reader device 106 sends the credential information 104 to the authentication server 114. At block 225, if the credential information 104 is authenticated, the authentication server 114 initiates access to the physical access portal, such as by sending a signal to the reader device 106 or access controller to grant access to the physical access portal. If the credential information 104 is not authenticated at block 225, the authentication server 114 ends the process of authenticating the credential device at block 215.

[0035] As explained previously herein the beacon signal is authenticated if an expected signal is present with the beacon signal. The expected signal is one of the environmental signals 432 expected to be present in the environment of the physical access portal corresponding to the beacon signal. An example of an expected signal is a Bluetooth™ signal or Bluetooth™ Low Energy (BLE) signal from office equipment such as an office printer. Such signals may include a medium access control (MAC) address that can be used as a signal identifier. Another example is a signal advertising a WiFi network near the physical access portal. Wireless signals that are repeatedly transmitted and include a wireless signature can also be used, with the wireless signature as the expected signal identifier. The expected signal identifier can be provisioned to the credential device 102 by an administrator.

[0036] In some examples, the wireless environmental signals 432 present at a physical access portal can be used as a wireless signal fingerprint of the physical access portal. Multiple expected signal identifiers can be provisioned to the credential device 102. The credential device 102 samples the wireless signals present in the environment. The credential device may include memory 434 to store multiple signal identifiers for multiple environmental signals. The App 118 compares identifiers of the detected signals to the expected signal identifiers. The App 118 may authenticate the beacon signal based on the number of expected wireless signals it detects. For instance, the App 118 may authenticate the beacon signal when the number of detected expected wireless signals exceeds a predetermined threshold number. The threshold number can be increased (e.g., by an administrator) for added security. Using different numbers of expected signals to verify can provide different levels of assurance that the beacon signal is valid. In some examples, the App 118 uses a weighting of expected wireless signals to authenticate the beacon signal. Some expected signals are weighted more than other, and the App 118 may authenticate the beacon signal when the determined weighting of detected expected wireless signals exceeds a predetermined threshold weighting.

[0037] According to some examples, the beacon signal is authenticated using combined actions of the credential device 102 and the authentication server 114. The credential device 102 detects the beacon signal at block 205 in FIG. 2 and extracts the beacon signal identifier from the beacon signal. The credential device 102 sends a request message that includes the beacon identifier to the authentication server 114 (e.g., using communication channel 120). The authentication server 114 returns an expected signal identifier to the credential device 102. The expected signal identifier identifies an expected wireless signal in the environment of the physical access portal associated with the identified beacon signal.The authentication server 114 selects the expected signal identifier using the beacon identifier. In some examples, the authentication server 114 selects the expected signal identifier using the beacon identifier and a timestamp of the message from the credential device to select the expected signal identifier. The wireless signals present at a physical access portal may change during the day. The authentication server 114 can use the timestamp to select an appropriate expected signal identifier. The timestamp can be used to verify that the identified beacon signal would be transmitted at the time of day indicated by the timestamp. For instance, the beacon transmitting device 112 may be powered down during nights and weekends.

[0038] The credential device 102 searches for the expected wireless signal. If the credential device 102 detects a wireless signal with the expected signal identifier, the beacon signal is authenticated and the credential device 102 proceeds further with the process of authentication of the credential device 102 with the authentication server 114 at block 220. If the credential device 102 does not detect a wireless signal with the expected signal identifier, the credential device 102 ends the process of authentication of the credential device 102 at block 215.

[0039] Storing the expected signal identifiers in the authentication server 114 eliminates the need to provision expected signal identifiers in the credential device 102. This centralizes the process for an administrator to configure security of multiple physical access sites. The authentication server 114 may require different levels of assurance of validation of the beacon signals. The authentication server 114 may send multiple expected signal identifiers to a credential device 102 according to an environmental signal profile based on the beacon signal identifier it receives from the credential device 102. The credential device 102 authenticates the beacon signal when it identifies the expected signal identifiers it received from the authentication server 114, or a threshold number of the expected signal identifiers designated by the authentication server 114.

[0040] In some examples, the authentication server 114 initiates sampling of wireless signals in the environment of the physical access portal in response to receiving the beacon identifier from the credential device 102. The sampling may be performed by the reader device 106 or another device at the location of the known location of the beacon signal. The authentication server 114 receives the sampled signals from the signal sampling device and determines one or more expected signal identifiers from the sampled signals. The authentication server 114 sends one or more of the expected signal identifiers to the credential device 102. The credential device 102 authenticates the beacon signal when itidentifies the expected signal identifiers it received from the authentication server 114, or a threshold number of the expected signal identifiers designated by the authentication server 114.

[0041] According to some examples, when the credential device 102 detects the beacon signal, the credential device 102 searches for other wireless signals. The credential device 102 sends the beacon signal identifier and one or more other signal identifiers of other detected wireless signals in an authentication request to the authentication server 114. The authentication server 114 determines if the one or more other signal identifiers correspond to wireless signals expected at the predefined location of the identified beacon signal. If a sufficient number of the other signal identifiers match wireless signals expected at the known location of the identified beacon signal, the authentication server 114 sends a response message to the credential device 102 authenticating the beacon signal. The credential device 102 proceeds further with the process of authentication of the credential device 102 with the authentication server 114. If there isn’t match of the other signal identifiers or insufficient number of matches, the authentication server 114 may send a response message to the credential device 102 indicating that the beacon signal is not authenticated. The credential device 102 then ends the process of authentication of the credential device 102 and does not expose the credential information 104. In certain examples, if there isn’t a match of the other signal identifiers or insufficient number of matches, the authentication server 114 ends the process of authentication of the credential device 102. The authentication server 114 may not respond to the credential device 102. The communication with the credential device 102 times out and the credential device 102 does not expose its credential information 104.

[0042] FIG. 5 is a block diagram of another example of a basic PACS structure that authenticates access to a physical portal using a credential device. Like the example of FIGS. 1, 3, and 4, in the example of FIG. 5, the credential device 102 presents an access credential to a reader device 106 to gain access to through a secured physical access portal (e.g., secured door 108) to enter a secure area 110. An authentication server 114 authenticates the credential information 104. The PACS includes a beacon transmitting device 112 positioned in the vicinity of the controlled access portal and reader device 106 or the beacon transmitting device 112 may be integral to the reader device 106. The beacon signal is authenticated to confirm that the beacon signal is associated with an authorized device (e.g., reader device 106) with which the credential device 102 should interact to authenticate. In the example of FIG. 5, the PACS includes device-readable beacon authentication information 536 located at the location of the physical access portal to authenticate beacon signal.

[0043] FIG. 6 is a flow diagram of an example of a method 600 of operating a PACS, such as the PACS example of FIG. 1, that mitigates third party attacks. At block 605, the credential device 102 detects a beacon signal. At block 610, the credential device 102 reads beacon authentication information for the beacon signal. The device-readable beacon authentication information 536 may be read by the credential device 102 in different ways. For instance, the credential device 102 may scan an electronic display located near the reader device 106 or physical access portal to read the authentication information. The electronic display may present a QR code or bar code scannable by the credential device 102. The scannable authentication information may be recurrently updated on the display by an administrator or updated by the authentication server 114 according to a schedule. The authentication server may send the QR code or bar code in response to a request from the credential device 102 sent by the credential device 102 when the credential device detects the beacon signal. In another example, the credential device 102 may read the beacon authentication information from a Near Field Communication (NFC) tag located near the reader device 106 or physical access portal.

[0044] At block 615, the beacon signal is authenticated as a valid beacon signal. Different techniques can be used to authenticate the beacon signal. In some examples, the beacon signal is authenticated by the credential device 102. The device-readable beacon authentication information 536 can include location information for the beacon transmitting device 112. The App 118 of the credential device 102 may determine the geolocation of the credential device (e.g., such as by the Global Positioning System (GPS)). The credential device 102 may authenticate that the beacon signal is a genuine or valid beacon signal when the beacon location information sufficiently corresponds to the geolocation of the credential device. The determination of correspondence may be configurable based on a threshold distance or proximity of the credential device 102 to the location information for the beacon signal.

[0045] In a further example, the credential device 102 authenticates the beacon signal by comparing the beacon authentication information 536 read by the credential device 102 to known information of the beacon signal. The credential device 102 may store authentication information for the beacon signal (e.g., in a secure component of the credential device 102). The credential device 102 authenticates the beacon signal when the beacon authentication information 536 read by the credential device matches the expected authentication information stored by the credential device 102.

[0046] In some examples, the credential device 102 authenticates the beacon signal using information from the authentication server 114. For instance, the beacon signal may include a beacon signal identifier (e.g., a predetermined sequence of bits broadcast in the beacon signal). The credential device 102 extracts the beacon signal identifier and sends the identifier to the authentication server 114 (e.g., using communication channel 120). The authentication server 114 may push the device-readable beacon authentication information 536 to the physical access portal to be read by the credential device 102 in response to receiving the information from the credential device 102. For instance, the authentication server 114 may change a QR code displayed at the physical access portal and the credential device 102 scans the QR code. Provisioning the beacon authentication information at the authentication server 114 centralizes the management of the beacon authorization and eliminates the need to provision beacon authentication information to the credential devices.

[0047] The pushed device-readable beacon authentication information 536 may include location information used by the credential device 102 to authenticate the beacon signal. In another example, the pushed device-readable beacon authentication information 536 includes a code generated by the authentication server 114. The credential device 102 compares the received code to an expected code from the authentication server 114. The credential device 102 authenticates the beacon signal if the code matches a code expected by the credential device 102.

[0048] When the beacon signal is authenticated by the credential device 102, at block 620, the credential device 102 proceeds with the process of authenticating the credential device 102 to the authenticated server 114 when the beacon signal is authenticated. At block 625, the credential device 102 ends the process of authenticating the credential device 102 to the authenticated server 114 when the beacon signal is not authenticated.

[0049] In another example, the authentication server 114 authenticates the beacon signal. For instance, the credential device 102 may send the beacon signal identifier and the device-readable beacon authentication information 536 read at the physical access portal to the authentication server 114 using a secure communication channel 120. The authentication server 114 authenticates the beacon signal using the information received from the credential device 102. When the beacon signal is authenticated by the authentication server 114, at block 620, the authentication server 114 proceeds with the process of authenticating the credential device 102. The authentication server 114 may send a response message to the credential device 102 that the beacon signal is authenticated. If the beacon signal is not authenticated by the authentication server 114, at block 625, the authentication server 114ends the process of authenticating the credential device 102. The authentication server 114 may end the process of authenticating the credential device 102 by a response message that indicates that the beacon signal is not authenticated. In certain examples, the authentication server 114 ends the process of authenticating the credential device 102 by not responding to the credential device 102 and terminating the communication with the credential device 102 when the beacon signal is not authenticated.

[0050] When the beacon signal is authenticated by either the credential device 102 or the authentication server 114, at block 630, the credential device 102 sends its credential information 104 to the reader device 106. At block 635, the authentication server 114 initiates access to the physical access portal conditional on authentication of the credential device 102. In certain examples, the authentication server 114 sends an activation signal to an access controller at the physical access portal to unlock the portal. If the credential device 102 is not authenticated, at block 630, the authentication server 114 ends the process of authentication of the credential device 102.

[0051] The techniques described herein ensure that the beacon signal received by a credential device 102 is genuine in order to confirm that a valid request for the credential information 104 has been made. Authentication of the transmitted beacon can be performed by one or both of the authentication server 114 and the credential device 102. In the event of a discrepancy in the authentication of the beacon, one or both of the credential device 102 and the authorization server 114 may end the credentialing process and notifications may be provided to the user and the administrator. Additional actions may be taken to block unauthorized activity.

[0052] FIG. 7 is a block diagram schematic of various example components of an authentication device for supporting the device architectures described and illustrated herein. The device 700 of FIG. 7 could be, for example, an authentication device (e.g., the authentication server 114 in FIG. 1) that analyzes evidence of authority, status, rights, and / or entitlement to privileges for a holder of a credential device (e.g., the credential device 102 of FIG. 1). At a basic level, a credential device can be a portable device having memory, storing one or more user credentials or credential data, and an interface (e.g., one or more antennas and Integrated Circuit (IC) chip(s)), which permit the credential device to exchange data with another device, such as an authentication device. One example of credential device is a smartphone that has data stored in memory allowing a holder of the credential device to access a secure area or asset protected by a reader device. Another example of a credential device is RFID smartcard that has the data stored thereon.

[0053] With reference specifically to FIG. 7, examples of an authorization or authentication device 700 for supporting the device architecture described and illustrated herein may generally include one or more of a memory 702, a processor 704, one or more antennas 706, a communication module 708, a network interface device 710, a user interface 712, and a power source 714 or power supply.

[0054] Memory 702 can be used in connection with the execution of application programming or instructions by processor 704, and for the temporary or long-term storage of program instructions or executable instructions 716, authorization data 718, such as credential data, credential authorization data, or access control data or instructions, as well as any data, data structures, and / or computer-executable instructions needed or desired to support the above-described device architecture. For example, memory 702 can contain executable instructions 716 that are used by the processor 704 to run other components of device 700, to make access determinations based on credential or authorization data 718, and / or to perform any of the functions or operations described herein, such as the method examples of FIG. 2 and FIG. 6 for example. Memory 702 can comprise a computer readable medium that can be any medium that can contain, store, communicate, or transport data, program code, or instructions for use by or in connection with device 700. The computer readable medium can be, for example but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device. More specific examples of suitable computer readable medium include, but are not limited to, an electrical connection having one or more wires or a tangible storage medium such as a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), Dynamic RAM (DRAM), any solid-state storage device, in general, a compact disc read-only memory (CD-ROM), or other optical or magnetic storage device. Computer readable media includes, but is not to be confused with, computer readable storage medium, which is intended to cover all physical, non-transitory, or similar embodiments of computer readable media.

[0055] Processor 704 can correspond to one or more computer processing devices or resources. For instance, processor 704 can be provided as silicon, as a Field Programmable Gate Array (FPGA), an Application-Specific Integrated Circuit (ASIC), any other type of Integrated Circuit (IC) chip, a collection of IC chips, or the like. As a more specific example, processor 704 can be provided as a microprocessor, Central Processing Unit (CPU), or plurality of microprocessors or CPUs that are configured to execute instructions sets stored in an internal memory 720 and / or memory 702. Secure component 724 may provide securestorage or secure calculation, such as for producing keying material for authentication of a signature or storing credential information.

[0056] Antenna 706 can correspond to one or multiple antennas and can be configured to provide for wireless communications between device 700 and another device. Antenna(s) 706 can be arranged to operate using one or more wireless communication protocols and operating frequencies including, but not limited to, the IEEE 802.15.1, Bluetooth, Bluetooth Low Energy (BLE), near field communications (NFC), ZigBee, GSM, CDMA, Wi-Fi, RF, UWB, and the like. In an example, antenna 706 may include one or more antennas arranged to operate using UWB for in band activity / communication and Bluetooth (e.g., BLE) for out-of-band (OOB) activity / communication. However, any RFID or personal area network (PAN) technologies, such as the IEEE 802. 15.1, near field communications (NFC), ZigBee, GSM, CDMA, Wi-Fi, etc., may alternatively or additionally be used for the OOB activity / communication described herein.

[0057] Device 700 may additionally include a communication module 708 and / or network interface device 710. Communication module 708 can be configured to communicate according to any suitable communications protocol with one or more different systems or devices either remote or local to device 700. Network interface device 710 includes hardware to facilitate communications with other devices over a communication network utilizing any one of a number of transfer protocols (e.g., frame relay, internet protocol (IP), transmission control protocol (TCP), user datagram protocol (UDP), hypertext transfer protocol (HTTP), etc.). Example communication networks can include a local area network (LAN), a wide area network (WAN), a packet data network (e.g., the Internet), mobile telephone networks (e.g., cellular networks), Plain Old Telephone (POTS) networks, wireless data networks (e.g., IEEE 802. 11 family of standards known as Wi-Fi, or IEEE 802.16 family of standards known as WiMax), IEEE 802.15.4 family of standards, and peer- to-peer (P2P) networks, among others. In some examples, network interface device 810 can include an Ethernet port or other physical jack, a Wi-Fi card, a Network Interface Card (NIC), a cellular interface (e.g., antenna, filters, and associated circuitry), or the like. In some examples, network interface device 710 can include a plurality of antennas to wirelessly communicate using at least one of single-input multiple-output (SIMO), multiple-input multiple-output (MIMO), or multiple-input single-output (MISO) techniques. In some example embodiments, one or more of the antenna 706, communication module 708, and / or network interface device 710 or subcomponents thereof, may be integrated as a single moduleor device, function or operate as if they were a single module or device, or may comprise of elements that are shared between them.

[0058] User interface 712 can include one or more input devices and / or display devices. Examples of suitable user input devices that can be included in user interface 712 include, without limitation, one or more buttons, a keyboard, a mouse, a touch-sensitive surface, a stylus, a camera, a microphone, etc. Examples of suitable user output devices that can be included in user interface 712 include, without limitation, one or more LEDs, an LCD panel, a display screen, a touchscreen, one or more lights, a speaker, etc. It should be appreciated that user interface 712 can also include a combined user input and user output device, such as a touch-sensitive display or the like.

[0059] Power source 714 can be any suitable internal power source, such as a battery, capacitive power source or similar type of charge-storage device, etc., and / or can include one or more power conversion circuits suitable to convert external power into suitable power (e.g., conversion of externally supplied AC power into DC power) for components of the device 700. Device 700 can also include one or more interlinks or buses 722 operable to transmit communications between the various hardware components of the device. A system bus 722 can be any of several types of commercially available bus structures or bus architectures.ADDITIONAL DISCLOSURE AND EXAMPLES

[0060] Example 1 includes subject matter (such as a physical access control system (PACS)) comprising a reader device configured to receive credential information from a credential device, a beacon transmitting device configured to transmit a beacon signal detectable by the credential device, and an authentication server. The authentication server includes a first communication channel configured to communicate information with the credential device, a second communication channel configured to communicate information with the reader device, and server processing circuitry. The server processing circuitry is configured to receive beacon signal information from the credential device and send beacon signal authentication information to the credential device, receive credential information from the reader device when the beacon signal is authenticated, and initiate access to a physical access portal conditional on authentication of the credential information.

[0061] In Example 2, the subject matter of Example 1 optionally includes server processing circuitry configured to receive, from the credential device, an identifier of abeacon signal detected by the credential device and location information of the credential device, determine beacon location information using the identifier of the beacon signal, authenticate the beacon signal using the identifier of the beacon signal, the location information for the identified beacon signal, and the location information of the credential device, and proceed with a process of authentication of the credential device when the beacon signal is authenticated.

[0062] In Example 3, the subject matter of Example 2 optionally includes multiple reader devices, multiple beacon transmitting devices, an authentication server that includes a memory to store a list of beacon signal identifiers for beacon signals transmitted by the multiple beacon transmitting devices, and server processing circuitry configured to authenticate the beacon signal using a comparison of the received identifier of the beacon signal to the list of identifiers of beacon signal identifiers.

[0063] In Example 4, the subject matter of one or any combination of Examples 1-3 optionally includes server processing circuitry configured to receive an identifier of a beacon signal from the credential device, and send beacon location information for the identified beacon signal to the credential device.

[0064] In Example 5, the subject matter of one or any combination of Examples 1-4 optionally includes server processing circuitry configured to receive, from the credential device, beacon credential information of a beacon signal detected by the credential device; authenticate the beacon signal using beacon credential information; and proceed with a process of authentication of the credential device when the beacon signal is authenticated.

[0065] Example 6 includes subject matter (such as a method of operating a PACS) or can optionally be combined with one or any combination of Examples 1-5 to include such subject matter, comprising detecting, by a credential device of the PACS, a beacon signal associated with a physical access portal of the PACS; authenticating the beacon signal; proceeding with a process of authentication of the credential device when the beacon signal is authenticated, and ending the process of authentication of the credential device when the beacon signal is not authenticated; and initiating access to a physical access portal conditional on authentication of the credential device.

[0066] In Example 7, the subject matter of Example 6 optionally includes sending, by the credential device, a request to an authentication server of the PACS for authentication of the beacon signal, wherein the request includes an identifier of the beacon signal and location information of the credential device in the request; and authenticating, by the authenticationserver, the beacon signal using the identifier of the beacon signal, the location information for the identified beacon signal, and the location information of the credential device.

[0067] In Example 8, the subject matter of Example 7 optionally includes the authentication server proceeding with the process of authentication of the credential device when the authentication server authenticates the beacon signal and the authentication server ending the process of authentication of the credential device when the beacon signal is not authenticated.

[0068] In Example 9, the subject matter of one or any combination of Examples 6-8 optionally includes sending, by the credential device, an identifier of the beacon signal to an authentication server of the PACS; sending, by the authentication server, beacon location information for the identified beacon signal to the credential device; and authenticating, by the credential device, the beacon signal using the beacon location information and location of the credential device.

[0069] In Example 10, the subject matter of Example 9 optionally includes the credential device sending credential information to a reader device of the PACS system when the beacon signal is authenticated and the credential device ending the process of process of authentication of the credential device when the beacon signal is not authenticated.

[0070] In Example 11, the subject matter of one or any combination of Examples 6-10 optionally includes receiving, by the credential device, beacon location information included in the beacon signal; and authenticating, by the credential device, the beacon signal using the beacon location information and location of the credential device.

[0071] In Example 12, the subject matter of one or any combination of Examples 6-11 optionally includes receiving, by the credential device, beacon credential information; sending the beacon credential information to an authentication server of the PACS; and the authentication server authenticating the beacon signal using the beacon credential information.

[0072] In Example 13, the subject matter of Example 12, optionally includes the credential device receiving the beacon credential information in the beacon signal.

[0073] In Example 14, the subject matter of Example 12 optionally includes the credential device scanning the beacon credential information at the physical access portal.

[0074] Example 15 includes subject matter (or can optionally be combined with one or any combination of Examples 1-14 to include such subject matter, such as a computer readable storage medium storing a resource access application, the resource access application including instructions performable by processing circuitry of a credential deviceto cause the credential device to: decode beacon signal information included in a beacon signal detected by the credential device; send the beacon signal information to an authentication server; receive authentication information for the beacon signal from the authentication server; and send credential information to a reader device for access to an access controlled resource when the beacon signal is authenticated.

[0075] In Example 16, the subject matter of Example 15 optionally includes the computer readable storage medium storing instructions to cause the credential device to send an identifier of the beacon signal and location information of the credential device to the authentication server; receive an indication of authentication of the beacon signal from the authentication server; and send the credential information to the reader device in response to receiving the indication of authentication of the beacon signal.

[0076] In Example 17, the subject matter of one or both of Examples 15 and 16 optionally includes the computer readable storage medium storing instructions to cause the credential device to determine location information for the credential device; send an identifier of the beacon signal to the authentication server; receive beacon location information for the identified beacon signal from the authentication server; and send the credential information to the reader device when the beacon location information corresponds to the location information for the credential device.

[0077] In Example 18, the subject matter of one or any combination of Examples 15-17 optionally includes the computer readable storage medium storing instructions to cause the credential device to determine beacon credential information for the beacon signal; send the beacon credential information to the authentication server; receive an indication of authentication of the beacon signal from the authentication server; and send the credential information to the reader device in response to receiving the indication of authentication of the beacon signal.

[0078] In Example 19, the subject matter of one or any combination of Examples 15-18 optionally includes the computer readable storage medium storing instructions to cause the credential device to decode the beacon credential information included in the beacon signal.

[0079] In Example 20, the subject matter of one or any combination of Examples 15-19 optionally includes the computer readable storage medium storing instructions to cause the credential device to perform a scan to obtain the beacon credential information.

[0080] The above non-limiting Examples can be combined in any permutation. In this document, the terms “a” or “an” are used, as is common in patent documents, to include one or more than one, independent of any other instances or usages of “at least one” or “oneor more.” In this document, the term “or” is used to refer to a nonexclusive or, such that “A or B” includes “A but not B,” “B but not A,” and “A and B,” unless otherwise indicated. In this document, the terms “including” and “in which” are used as the plain-English equivalents of the respective terms “comprising” and “wherein.” Also, in the following claims, the terms “including” and “comprising” are open-ended, that is, a system, device, article, composition, formulation, or process that includes elements in addition to those listed after such a term in a claim are still deemed to fall within the scope of that claim. Moreover, in the following claims, the terms “first,” “second,” and “third,” etc. are used merely as labels, and are not intended to impose numerical requirements on their objects.

[0081] The above description is intended to be illustrative, and not restrictive. For example, the above-described examples (or one or more aspects thereof) may be used in combination with each other. Other embodiments can be used, such as by one of ordinary skill in the art upon reviewing the above description. The Abstract is provided to allow the reader to quickly ascertain the nature of the technical disclosure. It is submitted with the understanding that it will not be used to interpret or limit the scope or meaning of the claims. In the above Detailed Description, various features may be grouped together to streamline the disclosure. This should not be interpreted as intending that an unclaimed disclosed feature is essential to any claim. Rather, the subject matter may lie in less than all features of a particular disclosed embodiment. Thus, the following claims are hereby incorporated into the Detailed Description, with each claim standing on its own as a separate embodiment, and it is contemplated that such embodiments can be combined with each other in various combinations or permutations. The scope should be determined with reference to the appended claims, along with the full scope of equivalents to which such claims are entitled.

Claims

WHAT IS CLAIMED IS:

1. A physical access control system (PACS), the system comprising: a reader device configured to receive credential information from a credential device; a beacon transmitting device configured to transmit a beacon signal detectable by the credential device; and an authentication server including: a first communication channel configured to communicate information with the credential device; a second communication channel configured to communicate information with the reader device; and server processing circuitry configured to: receive beacon signal information from the credential device and send beacon signal authentication information to the credential device; receive credential information from the reader device when the beacon signal is authenticated; and initiate access to a physical access portal conditional on authentication of the credential information.

2. The system of claim 1, wherein the server processing circuitry is configured to: receive, from the credential device, an identifier of a beacon signal detected by the credential device and location information of the credential device; determine beacon location information using the identifier of the beacon signal; authenticate the beacon signal using the identifier of the beacon signal, the location information for the identified beacon signal, and the location information of the credential device; and proceed with a process of authentication of the credential device when the beacon signal is authenticated.

3. The system of claim 2, including: multiple reader devices; multiple beacon transmitting devices; wherein the authentication server includes:a memory to store a list of beacon signal identifiers for beacon signals transmitted by the multiple beacon transmitting devices; and wherein the server processing circuitry is configured to authenticate the beacon signal using a comparison of the received identifier of the beacon signal to the list of identifiers of beacon signal identifiers.

4. The system of claim 1, wherein the server processing circuitry is configured to: receive an identifier of a beacon signal from the credential device; and send beacon location information for the identified beacon signal to the credential device.

5. The system of claim 1, wherein the server processing circuitry is configured to: receive, from the credential device, beacon credential information of a beacon signal detected by the credential device; authenticate the beacon signal using beacon credential information; and proceed with a process of authentication of the credential device when the beacon signal is authenticated.

6. A method of operating a physical access control system (PACS), the method comprising: detecting, by a credential device of the PACS, a beacon signal associated with a physical access portal of the PACS; authenticating the beacon signal; proceeding with a process of authentication of the credential device when the beacon signal is authenticated, and ending the process of authentication of the credential device when the beacon signal is not authenticated; and initiating access to a physical access portal conditional on authentication of the credential device.

7. The method of claim 6, wherein the authenticating the beacon signal includes: sending, by the credential device, a request to an authentication server of the PACS for authentication of the beacon signal, wherein the request includes an identifier of the beacon signal and location information of the credential device in the request; andauthenticating, by the authentication server, the beacon signal using the identifier of the beacon signal, the location information for the identified beacon signal, and the location information of the credential device.

8. The method of claim 7, wherein the proceeding with the process of authentication of the credential device includes the authentication server proceeding with the process of authentication of the credential device when the authentication server authenticates the beacon signal and the authentication server ending the process of authentication of the credential device when the beacon signal is not authenticated.

9. The method of claim 6, wherein the authenticating the beacon signal includes: sending, by the credential device, an identifier of the beacon signal to an authentication server of the PACS; sending, by the authentication server, beacon location information for the identified beacon signal to the credential device; and authenticating, by the credential device, the beacon signal using the beacon location information and location of the credential device.

10. The method of claim 9, wherein the proceeding with the process of authentication of the credential device includes the credential device sending credential information to a reader device of the PACS system when the beacon signal is authenticated and the credential device ending the process of process of authentication of the credential device when the beacon signal is not authenticated.

11. The method of claim 6, wherein the authenticating the beacon signal includes: receiving, by the credential device, beacon location information included in the beacon signal; and authenticating, by the credential device, the beacon signal using the beacon location information and location of the credential device.

12. The method of claim 6, wherein the authenticating the beacon signal includes:receiving, by the credential device, beacon credential information; sending the beacon credential information to an authentication server of the PACS; and the authentication server authenticating the beacon signal using the beacon credential information.

13. The method of claim 12, wherein the receiving the beacon credential information includes the credential device receiving the beacon credential information in the beacon signal.

14. The method of claim 12, wherein the receiving the beacon credential information includes the credential device scanning the beacon credential information at the physical access portal.

15. A computer readable storage medium storing a resource access application, the resource access application including instructions performable by processing circuitry of a credential device to cause the credential device to: decode beacon signal information included in a beacon signal detected by the credential device; send the beacon signal information to an authentication server; receive authentication information for the beacon signal from the authentication server; and send credential information to a reader device for access to an access controlled resource when the beacon signal is authenticated.

16. The computer readable storage medium of claim 15, wherein the resource access application includes instructions to cause the credential device to: send an identifier of the beacon signal and location information of the credential device to the authentication server; receive an indication of authentication of the beacon signal from the authentication server; and send the credential information to the reader device in response to receiving the indication of authentication of the beacon signal.

17. The computer readable storage medium of claim 15, wherein the resource access application includes instructions to cause the credential device to: determine location information for the credential device; send an identifier of the beacon signal to the authentication server; receive beacon location information for the identified beacon signal from the authentication server; and send the credential information to the reader device when the beacon location information corresponds to the location information for the credential device.

18. The computer readable storage medium of claim 15, wherein the resource access application includes instructions that cause the credential device to: determine beacon credential information for the beacon signal; send the beacon credential information to the authentication server; receive an indication of authentication of the beacon signal from the authentication server; and send the credential information to the reader device in response to receiving the indication of authentication of the beacon signal.

19. The computer readable storage medium of claim 15, wherein the resource access application includes instructions that cause the credential device to decode the beacon credential information included in the beacon signal.

20. The computer readable storage medium of claim 15, wherein the resource access application includes instructions that cause the credential device to perform a scan to obtain the beacon credential information.