Identity positioning using AOA / AOD technology

By integrating AoA and AoD capabilities into PAC readers, the system addresses inaccuracies in conventional access control systems, ensuring precise user positioning and security through directional awareness, reducing hardware redundancy and operational inefficiencies.

WO2026153967A1PCT designated stage Publication Date: 2026-07-23ASSA ABLOY AB
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
ASSA ABLOY AB
Filing Date
2026-01-14
Publication Date
2026-07-23

Smart Images

  • Figure EP2026050764_23072026_PF_FP_ABST
    Figure EP2026050764_23072026_PF_FP_ABST
Patent Text Reader

Abstract

A system for validating presence of a user is described. The system receives, by a server, an identifier associated with a physical access control (PAC) reader device and directional data indicating an angle between the PAC reader device and a mobile device associated with a user. The system processes the directional data by the server to determine whether the mobile device associated with the user is located within a defined region relative to the PAC reader device and validates, by the server, presence of the user within the defined region in response to processing the directional data.
Need to check novelty before this filing date? Find Prior Art

Description

IDENTITY POSITIONING USING AOA / AOD TECHNOLOGYPRIORITY APPLICATION(S)

[0001] This application claims priority to Indian Provisional Patent Application No.202511003723, filed on January 16, 2026, the disclosure of which is incorporated by reference herein in its entirety.BACKGROUND

[0002] Access control systems have become integral to securing physical spaces, ensuring that only authorized individuals can enter or exit specific areas. With the advent of mobile technology and Bluetooth Low Energy (BLE) communication, these systems have evolved to offer enhanced convenience and flexibility. Mobile access solutions allow users to utilize their smartphones as access credentials, facilitating seamless and secure interactions with access control devices. This integration of mobile technology into access control systems represents a significant advancement, providing users with a modern and efficient means of managing entry to secure locations. The use of BLE technology enables short-range wireless communication, ensuring secure and reliable connections between mobile devices and access control readers.BRIEF SUMMARY

[0003] In some aspects, the techniques described herein relate to a system including: one or more hardware processors; and at least one machine-storage medium for storing instructions that, when executed by the one or more hardware processors, cause the one or more hardware processors to perform operations including: receiving, by a server, an identifier associated with a physical access control (PAC) reader device and directional data indicating an angle between the PAC reader device and a mobile device associated with a user; processing the directional data by the server to determine whether the mobile device associated with the user is located within a defined region relative to the PAC reader device; and validating, by the server, presence of the user within the defined region in response to processing the directional data.

[0004] In some aspects, the techniques described herein relate to a system, wherein the directional data includes angle of arrival (AoA) data computed by the PAC reader device based on one or more signals received from the mobile device.

[0005] In some aspects, the techniques described herein relate to a system, wherein the directional data includes angle of departure (AoD) data transmitted by the PAC reader device and received by the mobile device.

[0006] In some aspects, the techniques described herein relate to a system, wherein the PAC reader device includes multiple antennas for computing the directional data.

[0007] In some aspects, the techniques described herein relate to a system, wherein processing the directional data includes determining whether the mobile device is located inside or outside of a building associated with the PAC reader device.

[0008] In some aspects, the techniques described herein relate to a system, wherein the operations further include: receiving timestamp information associated with the directional data; and using the timestamp information to validate the presence of the user.

[0009] In some aspects, the techniques described herein relate to a system, wherein validating presence includes: determining whether the user is authorized to access an area associated with the defined region; and granting or denying access based on the determination.

[0010] In some aspects, the techniques described herein relate to a system, wherein the operations further include: storing historical positioning information for the user based on previously received directional data.

[0011] In some aspects, the techniques described herein relate to a system, wherein the operations further include: receiving, from the PAC reader device by the mobile device, encoded angular data transmitted through multiple antennas of the PAC reader device, wherein the encoded angular data indicates a direction that one or more signals are being transmitted from the PAC reader device; processing, by the mobile device, the encoded angular data using a built-in antenna array to interpret the angular data and determine AoD information; and transmitting the determined AoD information to the server as part of the directional data for validating the presence of the user.

[0012] In some aspects, the techniques described herein relate to a system, wherein the PAC reader device computes the directional data by performing operations including: receiving, via multiple antennas of the PAC reader device, Bluetooth Low Energy (BLE) signals transmitted from the mobile device; measuring signal characteristics of the BLE signals received at each antenna of the multiple antennas to determine relative signaltiming and strength between the antennas; and calculating, based on the measured signal characteristics from the multiple antennas, an angle of arrival (AoA) value indicating the direction from which the BLE signals from the mobile device were received relative to the PAC reader device.

[0013] In some aspects, the techniques described herein relate to a system, the operations including: combining the calculated AoA value with a timestamp indicating when the BLE signals were received; and transmitting the calculated AoA value and timestamp to the server for use in determining whether the mobile device is located within the defined region.

[0014] In some aspects, the techniques described herein relate to a system, wherein the server receives the directional data from the mobile device.

[0015] In some aspects, the techniques described herein relate to a system, wherein the server receives the directional data from the PAC reader device.

[0016] In some aspects, the techniques described herein relate to a system, wherein the operations include: detecting, by the mobile device, the identifier of the PAC reader device in packets broadcast by the PAC reader device using BLE scanning; deriving the angle between the PAC reader device and the mobile device based on directional metadata included in the packets that are broadcast; and generating a package of data for transmission to the server by the mobile device, the package of data including the identifier of the PAC reader device, the derived angle including the directional data, and a timestamp.

[0017] In some aspects, the techniques described herein relate to a system, wherein validating the presence of the user includes providing location-based services to the mobile device associated with the defined region.

[0018] In some aspects, the techniques described herein relate to a method including: receiving, by a server, an identifier associated with a PAC reader device and directional data indicating an angle between the PAC reader device and a mobile device associated with a user; processing the directional data by the server to determine whether the mobile device associated with the user is located within a defined region relative to the PAC reader device; and validating, by the server, presence of the user within the defined region in response to processing the directional data.

[0019] In some aspects, the techniques described herein relate to a method, wherein the directional data includes AoA data computed by the PAC reader device based on one or more signals received from the mobile device.

[0020] In some aspects, the techniques described herein relate to a method, wherein the directional data includes AoD data transmitted by the PAC reader device and received by the mobile device.

[0021] In some aspects, the techniques described herein relate to a method, wherein the PAC reader device includes multiple antennas for computing the directional data.

[0022] In some aspects, the techniques described herein relate to a machine-storage medium for storing instructions that, when executed by one or more hardware processors, cause the one or more hardware processors to perform operations including: receiving, by a server, an identifier associated with a PAC reader device and directional data indicating an angle between the PAC reader device and a mobile device associated with a user; processing the directional data by the server to determine whether the mobile device associated with the user is located within a defined region relative to the PAC reader device; and validating, by the server, presence of the user within the defined region in response to processing the directional data.BRIEF DESCRIPTION OF THE SEVERAL VIEWS OF THE DRAWINGS

[0023] To easily identify the discussion of any particular element or act, the most significant digit or digits in a reference number refer to the figure number in which that element is first introduced.

[0024] FIG. 1 is a diagrammatic representation of a networked environment in which the present disclosure may be deployed, in accordance with some examples.

[0025] FIG. 2 illustrates an example of AoA and AoD approaches, in accordance with some examples.

[0026] FIG. 3 illustrates a routine for accessing a secure resource, in accordance with some examples.

[0027] FIG. 4 is a block diagram illustrating a representative software architecture, which may be used in conjunction with various hardware architectures herein described, in accordance with some examples.

[0028] FIG. 5 is a diagrammatic representation of a machine in the form of a computer system within which a set of instructions may be executed for causing the machine toperform any one or more of the methodologies discussed herein, in accordance with some examples.DETAILED DESCRIPTION

[0029] Example methods and systems for an access control system are described. In the following description, for purposes of explanation, numerous specific details are set forth in order to provide a thorough understanding of the disclosed examples. It will be evident, however, to one of ordinary skill in the art that examples of the disclosure may be practiced without these specific details.

[0030] Conventional identity positioning systems suffer from significant technical limitations that create inefficiencies and reliability issues in access control applications. Current solutions primarily rely on received signal strength indication (RS SI) values and user identifier (UUID) data from BLE beacons or readers to determine user presence, which creates accuracy problems in real-world deployments. A technical limitation is that RSSI-based detection creates circular regions around readers, making it impossible to determine if a user is inside or outside a building or defined region. When a person passes through a doorway, the RS SI values follow the same pattern regardless of direction - the signal strength reduces and then increases as they move through the circular detection zone. This fundamental limitation can be addressed by installing redundant hardware, specifically two readers for each entry / exit point, which creates unnecessary costs and installation complexity.

[0031] Additionally, this conventional approach is vulnerable to security risks since unauthorized users may attempt to spoof presence by capturing and replaying UUID values from beacons and / or readers. The technical constraints of conventional systems also create significant operational inefficiencies. For example, in scenarios involving legal disputes about employee presence and overtime claims, organizations struggle to definitively prove whether employees were inside or outside facilities at specific times. The lack of directional awareness in existing solutions requires companies to maintain separate systems and infrastructure, such as CCTV cameras, to validate presence claims. This results in wasted resources managing multiple overlapping systems while still failing to provide the precise positioning data needed for many business use cases. These technical limitations have broader implications for workforce management and security applications. The inability to accurately determine user position relative to access pointsmeans organizations may need to implement complex workarounds and additional validation steps.

[0032] The disclosed system addresses these issues by integrating AoA and / or AoD capabilities into PAC readers (PAC reader devices), enabling precise directional awareness that is complex or impracticable to perform using conventional RSSI-based solutions. For example, by utilizing multiple antennas in the PAC readers and leveraging BLE technology, the disclosed techniques can determine the angle between mobile user devices and PAC readers. This enables the disclosed techniques to perform a determination of whether a user is inside or outside a defined region. This enhanced positioning capability may eliminate the need for redundant reader installations while providing superior security through validation of physical presence rather than just proximity. The disclosed system can support two flexible implementation approaches. A mobile-based solution can be utilized where user mobile devices interpret directional data from PAC readers and provide such data to the server for processing. A readerbased approach can be utilized where the PAC readers compute positioning using signals from mobile devices. This technological advancement enables organizations to definitively validate user presence claims, streamline access control operations, and reduce infrastructure costs while providing more reliable positioning data for security and compliance purposes.

[0033] Specifically, the disclosed techniques can validate presence of a user. The disclosed techniques can receive, by a server, an identifier associated with a physical access control (PAC) reader device and directional data indicating an angle between the PAC reader device and a mobile device associated with a user. The disclosed techniques can process the directional data by the server to determine whether the mobile device associated with the user is located within a defined region relative to the PAC reader device and can validate, by the server, presence of the user within the defined region in response to processing the directional data.

[0034] FIG. 1 is a block diagram showing an example access control system 100, according to various examples. The access control system 100 can include a client device 120 (e.g., mobile device), server 122, and PAC device 110. The client device 120 and the PAC device 110 are communicatively coupled over a network 130 (e.g., Internet, BLE, ultra-wideband (UWB) communication protocol, Near Field Communication (NFC), and / or telephony network) with each other and with the server 122. While the disclosedtechniques are discussed in the context of PAC devices, similar techniques are applicable to any other type of access control device, such as a logical access control (LAC) device.

[0035] As used herein, the term “client device” may refer to any machine that interfaces to a communications network (such as network 130) to exchange credentials with an access control device, such as the PAC device 110, the server 122 associated with the access control device, another client device 120, or any other component to obtain access to a logical or physical asset or resource protected by the access control device. In some examples, the client device 120 can additionally or alternatively communicate directly with, for example, an access control device or another client device 120. The client device 120 can include or store one or more credentials which can be provided to the PAC device 110 for obtaining access to a protected physical or logical asset or resource.

[0036] A client device 120 may be, but is not limited to, a mobile phone, desktop computer, laptop, portable digital assistant (PDA), smart phone, wearable device (e.g., a smart watch), tablet, ultrabook, netbook, multi-processor system, microprocessor-based or programmable consumer electronics, physical card, or any other communication device that a user may use to access a network.

[0037] The access control device (e.g., the PAC device 110) can include an access reader device (also referred to as an access control reader) connected to a secure / protected resource (e.g., a door locking mechanism or backend server) that controls the secure / protected resource (e.g., door locking mechanism). The resource associated with the access control device can include a door lock, an ignition system for a vehicle, or any other device that grants or denies access to a physical component or that can be operated to grant or deny access to the physical component. For example, in the case of a door lock, the access control device can deny access, in which case the door lock remains locked and the door cannot be opened; or can grant access, in which case the door lock becomes unlocked to allow the door to be opened. As another example, in the case of an ignition system, the access control device can deny access, in which case the vehicle ignition system remains disabled and the vehicle cannot be started; or can grant access, in which case the vehicle ignition becomes enabled to allow the vehicle to be started.

[0038] PAC covers a range of systems and methods to govern access, for example by people, to secure areas or secure assets. PAC includes identification of authorized users or devices (e.g., vehicles, drones, etc.) and actuation of a gate, door, or other facilityused to secure an area, or actuation of a control mechanism, for example, a physical or electronic / software control mechanism, permitting access to a secure asset. The access control device may form part of a physical access control system (PACS), which can include a reader (e.g., an online or offline reader) that may hold authorization data (also referred to as access control information) and can be capable of determining whether credentials (e.g., from credential or key devices such as radio frequency identification (RFID) chips in cards, fobs, or personal electronic devices such as mobile phones) are authorized for an actuator or control mechanism (e.g., door lock, door opener, software control mechanism, turning off an alarm, etc.), or a PACS can include a host server 122 to which readers and actuators are connected (e.g., via a controller) in a centrally managed configuration.

[0039] In centrally managed configurations, readers can obtain credentials from credential or key devices (e.g., from one or more client devices 120) and pass those credentials to the PACS host server (e.g., server 122) or headend system. The readers can send the credentials over a wired or wireless link, such as network 130. The host server then determines whether the credentials authorize access to the secure area or secure asset (or resource) and commands the actuator or other control mechanism of the PAC device 110 accordingly by sending an allow / deny message back to the reader over the wired or wireless link. While examples in PAC are used herein, the disclosure applies similarly to local access control systems (LACs) use cases (e.g., logical access to personal electronic devices, logical access to personal online or electronic accounts or documents, etc.).

[0040] In general, the PAC device 110 can include one or more of a memory, a processor, one or more antennas, a communication module, a network interface device, a user interface, a display, and a power source or supply. The memory of the PAC device 110 can be used in connection with the execution of application programming or instructions by the processor of the PAC device 110, and for the temporary or long-term storage of program instructions or instruction sets and / or credential or authorization data, such as credential data, credential authorization data, or access control data or instructions. For example, the memory can contain executable instructions that are used by the processor to run other components of PAC device 110 and / or to make access determinations based on credential or authorization data, such as by communicating with authorization system 126 of the server 122.

[0041] The memory of the PAC device 110, server 122, and / or client device 120 can include a transitory or non-transitory computer-readable medium. The computer-readable medium can be, for example, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device. More specific examples of suitable computer-readable medium include, but are not limited to, an electrical connection having one or more wires or a tangible storage medium such as a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), Dynamic RAM (DRAM), any solid-state storage device in general, a compact disc read-only memory (CD-ROM), or other optical or magnetic storage device.Computer-readable media includes, but is not to be confused with, computer-readable storage medium, which is intended to cover all physical, non-transitory, or similar examples of computer-readable media.

[0042] The processor of the PAC device 110 can correspond to one or more computer processing devices or resources. For instance, the processor can be provided as silicon, as a Field Programmable Gate Array (FPGA), an Application-Specific Integrated Circuit (ASIC), any other type of Integrated Circuit (IC) chip, a collection of IC chips, or the like. As a more specific example, the processor can be provided as a microprocessor, Central Processing Unit (CPU), or plurality of microprocessors or CPUs that are configured to execute instruction sets stored in an internal memory and / or memory of the access control device.

[0043] The antenna of the PAC device 110 can correspond to one or multiple antennas and can be configured to provide for wireless communications between PAC device 110 and a credential or key device (e.g., client device 120). The antenna can be arranged to operate using one or more wireless communication protocols and operating frequencies including, but not limited to, the IEEE 502.15.1, Bluetooth, BLE, NFC, ZigBee, Global System for Mobile communications (GSM), Code Division Multiple Access (CDMA), Wi-Fi, RF, UWB, and the like. By way of example, the antenna(s) can be RF antenna(s), and as such, may transmit / receive RF signals through free-space to be received / transferred by a credential or key device having an RF transceiver.

[0044] A communication module or communication component of the PAC device 110 can be configured to communicate according to any suitable communications protocol with one or more different systems or devices either remote or local to the PAC device110, such as one or more client devices 120 and / or servers / controllers, such as server 122. In some cases, the communication module uses a same wired or wireless link between the PAC device 110 and the server 122 for all the communication modes. In some cases, the communication module uses one wired or wireless link between the PAC device 110 and the server 122 to communicate access control information to the authorization system 126 and uses a different wired or wireless link to communicate or receive configuration information updates from the server 122 over the Internet Protocol (IP) communication mode.

[0045] The network interface device of the PAC device 110 includes hardware to facilitate communications with other devices, such as a one or more client devices 120 and / or server / controller (e.g., server 122), over a communication network, such as network 130, utilizing any one of a number of transfer protocols (e.g., frame relay, IP, transmission control protocol (TCP), user datagram protocol (UDP), hypertext transfer protocol (HTTP), etc.). Example communication networks can include a local area network (LAN), a wide area network (WAN), a packet data network (e.g., the Internet), mobile telephone networks (e.g., cellular networks), Plain Old Telephone (POTS) networks, wireless data networks (e.g., IEEE 502.11 family of standards known as WiFi, IEEE 502.16 family of standards known as WiMax), IEEE 502.15.4 family of standards, and peer-to-peer (P2P) networks, among others. In some examples, network interface device can include an Ethernet port or other physical jack, a Wi-Fi card, a Network Interface Card (NIC), a cellular interface (e.g., antenna, filters, and associated circuitry), or the like. In some examples, network interface device can include a plurality of antennas to wirelessly communicate using at least one of single-input multiple-output (SIMO), multiple-input multiple-output (MIMO), or multiple-input single-output (MISO) techniques.

[0046] A user interface of the PAC device 110 can include one or more input devices and / or display devices. Examples of suitable user input devices that can be included in the user interface include, without limitation, one or more buttons, a keyboard or keypad, a mouse, a touch-sensitive surface, a stylus, a camera, a microphone, and so forth.Examples of suitable user output devices that can be included in the user interface include, without limitation, one or more light emitting diodes (LEDs), a liquid crystal display (LCD) panel, a display screen, a touchscreen, one or more lights, a speaker, andso forth. It should be appreciated that the user interface can also include a combined user input and user output device, such as a touch-sensitive display or the like.

[0047] The network 130 may include, or operate in conjunction with, an ad hoc network, an intranet, an extranet, a virtual private network (VPN), a LAN, a wireless network, a wireless LAN (WLAN), a WAN, a wireless WAN (WWAN), a metropolitan area network (MAN), BLE, UWB, the Internet, a portion of the Internet, a portion of the Public Switched Telephone Network (PSTN), a POTS network, a cellular telephone network, a wireless network, a Wi-Fi® network, another type of network, or a combination of two or more such networks. For example, a network or a portion of a network may include a wireless or cellular network and the coupling may be a CDMA connection, a GSM connection, or other type of cellular or wireless coupling. In this example, the coupling may implement any of a variety of types of data transfer technology, such as Single Carrier Radio Transmission Technology (IxRTT), Evolution-Data Optimized (EVDO) technology, General Packet Radio Service (GPRS) technology, Enhanced Data rates for GSM Evolution (EDGE) technology, third Generation Partnership Project (3 GPP) including 3G, fourth generation wireless (4G) networks, fifth generation wireless (5G) networks, Universal Mobile Telecommunications System (UMTS), High Speed Packet Access (HSPA), Worldwide Interoperability for Microwave Access (WiMAX), Long Term Evolution (LTE) standard, others defined by various standard setting organizations, other short range or long range protocols, or other data transfer technology.

[0048] In an example, as the client device 120 approaches the PAC device 110 (e.g., comes within range of a BLE communication protocol), the client device 120 transmits credentials of the client device 120 over the network 130. In one example, the client device 120 provides the credentials directly to the PAC device 110. In such cases, the PAC device 110 communicates the credentials with the server 122. The server 122 includes an authorization system 126. The server 122, client device 120, and / or the PAC device 110 can further include elements described with respect to FIG. 4 and FIG. 5, such as a processor and memory, having instructions stored thereon, that when executed by the processor, causes the processor to control the functions of the server / controller, client device 120, and / or the PAC device 110. The server 122 can be implemented on a centralized set of servers of a cloud-based system.

[0049] The server 122 searches a list of credentials stored in the authorization system 126 to determine whether the received credentials match credentials from the list of authorized credentials for accessing a secure asset or resource (e.g., door or secure area) protected by the PAC device 110. In response to determining that the received credentials are authorized to access the PAC device 110, the server 122 (also referred to as the controller) instructs the PAC device 110 to perform an operation granting access for the client device 120 (e.g., instructing the PAC device 110 to unlock a lock of a door).

[0050] In some examples, prior to granting access to the resource protected by the PAC device 110, the PAC device 110 and / or the authorization system 126 of the server 122, and / or the client device 120 can perform operations to verify that the client device 120 is within a specified distance of the client device 120. This can be performed before, substantially simultaneous with, and / or after verifying that the credentials received from the client device 120 are authorized to access the asset or resource.

[0051] Specifically, the client device 120 can scan BLE signals (or other suitable signals) transmitted by the PAC device 110 over the network 130. The client device 120 can determine whether the BLE signals of a particular PAC device 110 satisfy a proximity threshold or criterion. In response, the client device 120 establishes a communication session (via BLE and / or WiFi) with the PAC device 110. The PAC device 110 can, either before verifying proximity or after verifying proximity, request additional information from the client device 120. Specifically, the PAC device 110 can request a credential to be provided by the client device 120.

[0052] FIG. 2 illustrates a diagram 200 of an example of AoA and AoD approaches, in accordance with some examples. Specifically, BLE direction finding is a technology that enhances the location services capabilities of standard BLE by enabling more precise positioning and direction detection. This technology primarily relies on two methods: AoA and AoD.

[0053] In AoA approach 210, the device whose location (e.g., the user device 212, such as client device 120) is being determined transmits a signal 240 containing a specific sequence known as a Constant Tone Extension (CTE). The receiving device (e.g., the reader 230, such as PAC device 110), equipped with multiple antennas 232 and 234, captures this signal 240. By measuring or analyzing the angular phase shift or phase difference of the incoming signal 240 across these antennas 232 and 234, the reader 230can determine the angle from which the signal is arriving. This angle information can then be used to triangulate the position of the transmitting device relative to the reader 230. This position can then be shared with the server 122 for confirming presence of a user within a certain location.

[0054] In the AoD approach 220, the roles are reversed. The reader 230 with multiple antennas transmits the signal simultaneously using different antennas (e.g., the same packet is sent by each antenna using a respective signal 250 and 252). The receiving device (e.g., the user device 212), which can have a single antenna, receives these signals 250 and 252. The transmitting device sends the signals 250 and 252 in such a way that it varies systematically across its antennas, embedding directional information in the signals themselves or in a single signal. The user device 212 uses this information to determine the angle at which the signals 250 and 252 were sent, aiding in the localization process. This can then be used to determine the direction towards which the user device 212 is pointing.

[0055] In some examples, the disclosed system implements enhanced identity positioning through integration of AoA and AoD capabilities with PAC device 110. The system utilizes BLE direction finding technology to enable precise positioning and direction detection beyond traditional proximity-based approaches. In the AoA implementation, the client device 120 transmits signal 240 that is received by multiple antennas 232 and 234 integrated into the reader 230. The reader 230 measures and analyzes the angular phase shifts and timing differences between signal 240 received at each antenna 232 and 234 to compute the precise angle from which the client device 120's signals are arriving. This directional data is combined with timestamps and transmitted to server 122 for presence validation in one or more packets.

[0056] In some examples, when client device 120 initiates communication, it transmits signal 240 containing a specialized CTE sequence that enables precise directional measurements. The reader 230's multiple antennas 232 and 234 capture this signal and perform detailed phase shift analysis to determine the exact angle of arrival with high precision. The reader 230 processes this information to create a comprehensive data package containing the reader's unique identifier, computed angle measurements derived from the signal analysis, signal strength indicators, precise timestamp of signal receipt, and / or additional directional metadata. This rich data package is then securely transmitted to server 122 for sophisticated multi-step validation processing.

[0057] Upon receiving the package, the server 122 performs a series of validation steps to ensure accurate positioning. This includes confirming timestamp validity, analyzing the computed angles to determine exact position relative to defined zones, combining directional data with signal strength measurements for enhanced accuracy, and validating user authorization for the detected location. The server 122 can employ multiple processing approaches including real-time validation against authorized zones, historical pattern analysis for movement anomaly detection, multi-factor validation combining directional data with access credentials, temporal analysis of movement sequences, and zone-based processing for varying security requirements.

[0058] This validated positioning data enables a range of sophisticated location-based services. For employee management, the system provides precise time and attendance tracking with directional awareness to definitively resolve presence disputes and overtime claims. In access control applications, it enables automated zone-based permissions that dynamically grant or deny access based on validated user presence and movement direction. For retail environments, the system delivers detailed customer analytics including movement patterns and dwell times to optimize store layouts and staffing. The solution also supports security compliance through comprehensive audit trails with directional validation for investigations and regulatory requirements.Additionally, organizations can leverage the precise positioning data for workspace optimization by analyzing detailed facility utilization patterns.

[0059] The system's ability to process positioning data through multiple validation approaches ensures robust and reliable presence detection. By combining real-time position validation, historical pattern analysis, multi-factor authentication, temporal movement tracking, and zone-based security processing, the solution delivers unprecedented accuracy in user positioning and presence validation.

[0060] For the AoD approach, the reader 230's multiple antennas 232 and 234 transmit encoded directional information through systematically varied signals 250 and 252. The user device 212 receives these signals 250 and 252 and uses its built-in antenna array to interpret the embedded angular data, determining its position relative to reader 230. This computed directional information is then sent to server 122 along with the reader's identifier and timestamps. Namely, the client device 120 (e.g., user device 212) can generate a comprehensive data package containing the reader's unique identifier and / or identifier of the client device 120, computed angle measurements derived from the signalanalysis, signal strength indicators, precise timestamp of signal receipt, and / or additional directional metadata. This rich data package is then securely transmitted to server 122 by the client device 120 for sophisticated multi-step validation processing. The server 122 then performs similar operations as previously discussed to provide location-based services and verify presence of the user within a defined zone.

[0061] The system supports flexible deployment options where either the user device 212 or reader 230 can perform the directional computations. In the mobile-based implementation, the client device 120 scans for reader broadcasts containing UUID and directional metadata, processes this data to determine relative positioning, and transmits the results to server 122. The reader-based approach leverages multiple antennas 232 and 234 to calculate positioning from received mobile device signals. In some cases, in the reader-based approach and / or the mobile-based implementation, the determination of the directional information can be performed in response to an unlock event, such as tap, twist-and-go, and / or app-widget interactions). For example, the PAC device 110 can detect an unlock event performed by a particular user device 212. In response, the PAC device 110 interprets angle of arrival information from data received by the PAC device 110 from the user device 212 and transmits that information to the server 122 for processing.

[0062] The server 122 receives the positioning data packages containing reader identifiers, computed angles, and timestamps. The server 122 processes this information to definitively determine whether client device 120 is located within defined regions relative to PAC device 110, enabling precise validation of user presence that is impossible with traditional RSSI-based detection.

[0063] For enhanced security, the system validates not just proximity but actual physical presence through the directional awareness capabilities of reader 230 and its multiple antennas 232 and 234. This prevents spoofing attempts that could occur with UUID capture and replay in conventional systems. The solution enables streamlined access control by eliminating the need for redundant reader installations at entry / exit points. A single reader 230 with AoA / AoD capabilities can definitively determine direction of movement and presence within defined zones.

[0064] Historical positioning data can be maintained by server 122 to support audit trails and presence verification. This is particularly valuable for resolving disputes about facility access and employee presence, providing definitive directional evidence ratherthan just proximity detection. The system supports integration with existing access control infrastructure while adding the enhanced positioning capabilities of reader 230 and its multiple antennas 232 and 234. Organizations can leverage their current reader deployments by upgrading to AoA / AoD-capable hardware without requiring complete infrastructure replacement.

[0065] Real-time presence validation enables automated access decisions based on precise positioning. The system can determine whether users of client device 120 are authorized for specific zones and grant or deny access accordingly. The solution addresses limitations of traditional RSSI-based systems, which create circular detection regions that cannot distinguish direction. By measuring actual angles between user device 212 and reader 230 using signals 240, 250, and 252, the system provides true directional awareness.

[0066] Implementation flexibility allows organizations to choose mobile-based or reader-based approaches based on their requirements. The system supports locationbased services by providing precise positioning information that applications can leverage. This enables contextual features and automations based on validated presence of client device 120 within defined regions.

[0067] The server 122 maintains timestamps with all positioning data from client device 120 and / or the PAC device 110 to enable temporal analysis and validation. This timing information helps confirm legitimate presence and movement patterns. Backend processing at server 122 combines reader identifiers, directional data from signals 240, 250, and 252, and timestamps to make definitive presence determinations. The server 122 maintains the access control logic while leveraging the enhanced positioning capabilities.

[0068] The server 122 supports both entry and exit tracking through its directional awareness. A single reader 230 can determine whether user device 212 is entering or leaving a zone based on the computed angles from signals 240, 250, and 252.Specifically, the server 122 leverages sophisticated directional awareness capabilities to enable single-reader entry / exit tracking through comprehensive technical operations and validation processes. When user device 212 approaches reader 230, the system initiates a multi-step positioning process where the reader's multiple antennas 232 and 234 receive signal 240 and analyze the phase shifts to compute precise angular positioning. This advanced analysis allows the system to definitively determine whether the user isapproaching from outside (indicating an entry event) or inside (indicating an exit event) the controlled zone.

[0069] The server 122 continuously monitors and analyzes the data as user device 212 moves through the detection zone. For entry scenarios, reader 230 first detects signal 240 from an exterior approach angle, then performs continuous angle measurements as the user moves through the entry zone, ultimately confirming successful entry when the computed angles indicate interior positioning. Each event is precisely timestamped for validation purposes and sent to the server 122 for processing. Similarly, for exit tracking, reader 230 performs reversed angular analysis, beginning with detection of signal 240 originating from interior angles and tracking movement until exterior angles confirm a completed exit.

[0070] This sophisticated directional awareness enables various business applications, particularly in scenarios that need definitive proof of presence and movement. For example, banking institutions can now conclusively validate employee entry and exit times to resolve overtime disputes, while retail operations can leverage the technology for detailed customer flow analysis. The system also enhances security by preventing tailgating through access points, provides accurate time and attendance validation with direction-aware logging, and supports emergency response through precise occupancy tracking.

[0071] The server 122 processes this comprehensive directional data to maintain detailed audit trails that go beyond simple proximity detection, showing validated direction of movement through controlled zones. This enhanced capability eliminates the traditional requirement for duplicate reader installations while providing superior security through true directional awareness. Additionally, the system may leverage events or directional data from the historical positioning data for purposes of additional verification during an authentication process. For example, during an authentication request, the system may request the user provide detail associated with a recent entry from the historical positioning data, such as last date or time of arrival / departure from a defined zone, or last point of entry / exit or date / time thereof. Alternatively, a user’s mobile device may also keep its own historical record of directional data, or a recent portion thereof, to mirror the historical positioning data stored in the server. During an authentication request between the system and a mobile device, the system may retrieve an entry from the historical positioning data to use as a challenge for the mobile devicepurporting to belong to the user, and the user’s mobile device may provide the corresponding entry from its records to verify authenticity. This process may be performed automatically by the system and mobile device since user input would not be needed.

[0072] FIG. 3 illustrates a routine 300 (e.g., method or process) in accordance with some examples. The operations discussed in connection with FIG. 3 can be performed sequentially, in parallel, and in any suitable order. The operations discussed in FIG. 3 can be performed by the access control system 100.

[0073] In operation 302, the server 122 receives an identifier associated with a PAC reader device (e.g., PAC device 110) and directional data indicating an angle between the PAC reader device and a mobile device (e.g., client device 120) associated with a user, as discussed above.

[0074] In operation 304, the server 122 processes the directional data by the server to determine whether the mobile device associated with the user is located within a defined region relative to the PAC reader device, as discussed above.

[0075] In operation 306, the server 122 validates presence of the user within the defined region in response to processing the directional data, as discussed above.

[0076] FIG. 4 is a block diagram illustrating an example of a software architecture 402 that may be installed on a machine, according to some examples. FIG. 4 is merely a nonlimiting example of a software architecture, and it will be appreciated that many other architectures may be implemented to facilitate the functionality described herein. The software architecture 402 may be executing on hardware such as a machine 500 of FIG.5 that includes, among other things, processors 510, memory 504, and input / output (I / O) components 542. A representative hardware layer 444 is illustrated and can represent, for example, the machine 500 of FIG. 5. The representative hardware layer 444 comprises one or more processing units 446 having associated executable instructions 448. The executable instructions 448 represent the executable instructions of the software architecture 402. The hardware layer 444 also includes memory 504, which also have the executable instructions 448. The hardware layer 444 may also comprise other hardware 452, which represents any other hardware of the hardware layer 444, such as the other hardware illustrated as part of the machine 500.

[0077] The instructions 448 may be transmitted or received over the network using a transmission medium via a network interface device (e.g., a network interfacecomponent included in the communication components 540) and utilizing any one of a number of well-known transfer protocols (e.g., hypertext transfer protocol (HTTP)). Similarly, the instructions 448 may be transmitted or received using a transmission medium via the coupling (e.g., a peer-to-peer coupling) to the devices. The terms “transmission medium” and “signal medium” mean the same thing and may be used interchangeably in this disclosure. The terms “transmission medium” and “signal medium” shall be taken to include any intangible medium that is capable of storing, encoding, or carrying the instructions 448 for execution by the machine 500, and include digital or analog communications signals or other intangible media to facilitate communication of such software. Hence, the terms “transmission medium” and “signal medium” shall be taken to include any form of modulated data signal, carrier wave, and so forth. The term “modulated data signal” means a signal that has one or more of its characteristics set or changed in such a manner as to encode information in the signal.

[0078] The terms “machine-readable medium,” “computer-readable medium,” and “device-readable medium” mean the same thing and may be used interchangeably in this disclosure. The terms are defined to include both machine-storage media and transmission media. Thus, the terms include both storage devices / media and carrier waves / modulated data signals.

[0079] As used herein, the terms “machine-storage medium,” “device-storage medium,” and “computer-storage medium” mean the same thing and may be used interchangeably in this disclosure. The terms refer to a single or multiple storage devices and / or media (e.g., a centralized or distributed database, and / or associated caches and servers) that store executable instructions and / or data. The terms shall accordingly be taken to include, but not be limited to, solid-state memories, and optical and magnetic media, including memory internal or external to processors. Specific examples of machinestorage media, computer-storage media, and / or device- storage media include nonvolatile memory, including by way of example semiconductor memory devices, e.g., erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), field-programmable gate arrays (FPGAs), and flash memory devices; magnetic disks such as internal hard disks and removable disks; magneto-optical disks; and CD-ROM and DVD-ROM disks. The terms “machinestorage medium,” “computer-storage medium,” and “device- storage medium” are non-transitory computer-readable media and specifically exclude carrier waves, modulateddata signals, and other such media, at least some of which are covered under the term “signal medium.”

[0080] In the example architecture of FIG. 4, the software architecture 402 may be conceptualized as a stack of layers, where each layer provides particular functionality. For example, the software architecture 402 may include layers such as an operating system 436, libraries 428, framework / middl eware 422, applications 416, and a presentation layer 414. Operationally, the applications 416 or other components within the layers may invoke API calls API calls 424 through the software stack and receive a response, returned values, and so forth (illustrated as messages 426) in response to the API calls 424. The layers illustrated are representative in nature, and not all software architectures have all layers. For example, some mobile or special -purpose operating systems may not provide a framework / middleware 422 layer, while others may provide such a layer. Other software architectures may include additional or different layers.

[0081] The operating system 436 may manage hardware resources and provide common services. The operating system 436 may include, for example, a kernel 438, services 440, and drivers 442. The kernel 438 may act as an abstraction layer between the hardware and the other software layers. For example, the kernel 438 may be responsible for memory management, processor management (e.g., scheduling), component management, networking, security settings, and so on. The services 440 may provide other common services for the other software layers. The drivers 442 may be responsible for controlling or interfacing with the underlying hardware. For instance, the drivers 442 may include display drivers, camera drivers, Bluetooth® drivers, flash memory drivers, serial communication drivers (e.g., Universal Serial Bus (USB) drivers), Wi-Fi® drivers, audio drivers, power management drivers, and so forth depending on the hardware configuration.

[0082] The libraries 428 may provide a common infrastructure that may be utilized by the applications 416 and / or other components and / or layers. The libraries 428 typically provide functionality that allows other software modules to perform tasks in an easier fashion than by interfacing directly with the underlying operating system 436 functionality (e.g., kernel 438, services 440, or drivers 442). The libraries 428 may include system libraries 430 (e.g., C standard library) that may provide functions such as memory allocation functions, string manipulation functions, mathematic functions, and the like. In addition, the libraries 428 may include API libraries 432 such as media libraries (e.g., libraries to support presentation and manipulation of various media formats such asMPEG4, H.264, MP3, AAC, AMR, JPG, and PNG), graphics libraries (e.g., an OpenGL framework that may be used to render 2D and 3D graphic content on a display), database libraries (e.g., SQLite that may provide various relational database functions), web libraries (e.g., WebKit that may provide web browsing functionality), and the like. The libraries 428 may also include a wide variety of other libraries 434 to provide many other APIs to the applications 416 and other software components / modules.

[0083] The frameworks / middleware 422 (also sometimes referred to as middleware) may provide a higher-level common infrastructure that may be utilized by the applications 416 or other software components / modules. For example, the frameworks / middleware 422 may provide various graphical user interface functions, high-level resource management, high-level location services, and so forth. The frameworks / middleware 422 may provide a broad spectrum of other APIs that may be utilized by the applications 416 and / or other software components / modules, some of which may be specific to a particular operating system or platform.

[0084] The applications 416 include built-in applications 418 and / or third-party applications 420. Examples of representative built-in applications 418 may include, but are not limited to, a home application, a contacts application, a browser application, a book reader application, a location application, a media application, a messaging application, or a game application.

[0085] The third-party applications 420 may include any of the built-in applications 418, as well as a broad assortment of other applications. In a specific example, the third-party applications 420 (e.g., an application developed using the Android™ or iOS™ software development kit (SDK) by an entity other than the vendor of the particular platform) may be mobile software running on a mobile operating system such as iOS™, Android™, or other mobile operating systems. In this example, the third-party applications 420 may invoke the API calls 424 provided by the mobile operating system such as the operating system 436 to facilitate functionality described herein.

[0086] The applications 416 may utilize built-in operating system functions (e.g., kernel 438, services 440, or drivers 442), libraries (e.g., system libraries 430, API libraries 432, and other libraries 434), or framework / middleware 422 to create user interfaces to interact with users of the system. Alternatively, or additionally, in some systems, interactions with a user may occur through a presentation layer, such as the presentation layer 414. In thesesystems, the application / module “logic” can be separated from the aspects of the application / module that interact with the user.

[0087] Some software architectures utilize virtual machines. In the example of FIG. 4, this is illustrated by a virtual machine 404. The virtual machine 404 creates a software environment where applications / modules can execute as if they were executing on a hardware machine (e.g., the machine 500 of FIG. 5). The virtual machine 404 is hosted by a host operating system (e.g., the operating system 436) and typically, although not always, has a virtual machine monitor, which manages the operation of the virtual machine 404 as well as the interface with the host operating system (e.g., the operating system 436). A software architecture executes within the virtual machine 404, such as an operating system 412, libraries 410, frameworks 408, applications 416, or a presentation layer 406. These layers of software architecture executing within the virtual machine 404 can be the same as corresponding layers previously described or may be different.

[0088] FIG. 5 is a diagrammatic representation of the machine 500 within which instructions 508 (e.g., software, a program, an application, an applet, an app, or other executable code) for causing the machine 500 to perform any one or more of the methodologies discussed herein may be executed. For example, the instructions 508 may cause the machine 500 to execute any one or more of the methods described herein. The instructions 508 transform the general, non-programmed machine 500 into a particular machine 500 programmed to carry out the described and illustrated functions in the manner described. The machine 500 may operate as a standalone device or may be coupled (e.g., networked) to other machines. In a networked deployment, the machine 500 may operate in the capacity of a server machine or a client machine in a server-client network environment, or as a peer machine in a peer-to-peer (or distributed) network environment. The machine 500 may comprise, but not be limited to, a server computer, a client computer, a personal computer (PC), a tablet computer, a laptop computer, a netbook, a set-top box (STB), a PDA, an entertainment media system, a cellular telephone, a smart phone, a mobile device, a wearable device (e.g., a smart watch), a smart home device (e.g., a smart appliance), other smart devices, a web appliance, a network router, a network switch, a network bridge, or any machine capable of executing the instructions 508, sequentially or otherwise, that specify actions to be taken by the machine 500. Further, while only a single machine 500 is illustrated, the term “machine”shall also be taken to include a collection of machines that individually or jointly execute the instructions 508 to perform any one or more of the methodologies discussed herein.

[0089] The machine 500 may include processors 502, memory 504, and I / O components 542, which may be configured to communicate with each other via a bus 544. In an example, the processors 502 (e.g., a Central Processing Unit (CPU), a Reduced Instruction Set Computing (RISC) processor, a Complex Instruction Set Computing (CISC) processor, a Graphics Processing Unit (GPU), a Digital Signal Processor (DSP), an ASIC, a Radio-Frequency Integrated Circuit (RFIC), another processor, or any suitable combination thereof) may include, for example, a processor 506 and a processor 510 that execute the instructions 508. The term “processor” is intended to include multi-core processors that may comprise two or more independent processors (sometimes referred to as “cores”) that may execute instructions contemporaneously. Although FIG. 5 shows multiple processors 502, the machine 500 may include a single processor with a single core, a single processor with multiple cores (e.g., a multi-core processor), multiple processors with a single core, multiple processors with multiples cores, or any combination thereof.

[0090] The memory 504 includes a main memory 512, a static memory 514, and a storage unit 516, both accessible to the processors 502 via the bus 544. The main memory 504, the static memory 514, and storage unit 516 store the instructions 508 embodying any one or more of the methodologies or functions described herein. The instructions 508 may also reside, completely or partially, within the main memory 512, within the static memory 514, within machine-readable medium 518 within the storage unit 516, within at least one of the processors 502 (e.g., within the processor’s cache memory), or any suitable combination thereof, during execution thereof by the machine 500.

[0091] The I / O components 542 may include a wide variety of components to receive input, provide output, produce output, transmit information, exchange information, capture measurements, and so on. The specific I / O components 542 that are included in a particular machine will depend on the type of machine. For example, portable machines such as mobile phones may include a touch input device or other such input mechanisms, while a headless server machine will likely not include such a touch input device. It will be appreciated that the I / O components 542 may include many other components that are not shown in FIG. 5. In various examples, the I / O components 542 may include outputcomponents 528 and input components 530. The output components 528 may include visual components (e.g., a display such as a plasma display panel (PDP), a light emitting diode (LED) display, a liquid crystal display (LCD), a projector, or a cathode ray tube (CRT)), acoustic components (e.g., speakers), haptic components (e.g., a vibratory motor, resistance mechanisms), other signal generators, and so forth. Theinput components 530 may include alphanumeric input components (e.g., a keyboard, a touch screen configured to receive alphanumeric input, a photo-optical keyboard, or other alphanumeric input components), point-based input components (e.g., a mouse, a touchpad, a trackball, a joystick, a motion sensor, or another pointing instrument), tactile input components (e.g., a physical button, a touch screen that provides location and / or force of touches or touch gestures, or other tactile input components), audio input components (e.g., a microphone), and the like.

[0092] In further examples, the I / O components 542 may include biometric components 532, motion components 534, environmental components 536, or position components 538, among a wide array of other components. For example, the biometric components 532 include components to detect expressions (e.g., hand expressions, facial expressions, vocal expressions, body gestures, or eye tracking), measure biosignals (e.g., blood pressure, heart rate, body temperature, perspiration, or brain waves), identify a person (e.g., voice identification, retinal identification, facial identification, fingerprint identification, or electroencephalogram-based identification), and the like. The motion components 534 include acceleration sensor components (e.g., accelerometer), gravitation sensor components, rotation sensor components (e.g., gyroscope), and so forth. The environmental components 536 include, for example, illumination sensor components (e.g., photometer), temperature sensor components (e.g., one or more thermometers that detect ambient temperature), humidity sensor components, pressure sensor components (e.g., barometer), acoustic sensor components (e.g., one or more microphones that detect background noise), proximity sensor components (e.g., infrared sensors that detect nearby objects), gas sensors (e.g., gas detection sensors to detection concentrations of hazardous gases for safety or to measure pollutants in the atmosphere), or other components that may provide indications, measurements, or signals corresponding to a surrounding physical environment. The position components538 include location sensor components (e.g., a GPS receiver component), altitude sensor components (e.g., altimeters or barometers that detect air pressure from whichaltitude may be derived), orientation sensor components (e.g., magnetometers), and the like.

[0093] Communication may be implemented using a wide variety of technologies. The I / O components 542 further include communication components 540 operable to couple the machine 500 to a network 520 or devices 522 via a coupling 524 and a coupling 526, respectively. For example, the communication components 540 may include a network interface component or another suitable device to interface with the network 520. In further examples, the communication components 540 may include wired communication components, wireless communication components, cellular communication components, Near Field Communication (NFC) components, Bluetooth® components (e.g., Bluetooth® Low Energy), Wi-Fi® components, and other communication components to provide communication via other modalities. The devices 522 may be another machine or any of a wide variety of peripheral devices (e.g., a peripheral device coupled via a USB).

[0094] Moreover, the communication components 540 may detect identifiers or include components operable to detect identifiers. For example, the communication components 540 may include Radio Frequency Identification (RFID) tag reader components, NFC smart tag detection components, optical reader components (e.g., an optical sensor to detect one-dimensional bar codes such as Universal Product Code (UPC) bar code, multi-dimensional bar codes such as Quick Response (QR) code, Aztec code, Data Matrix, Dataglyph, MaxiCode, PDF417, Ultra Code, UCC RSS-2D bar code, and other optical codes), or acoustic detection components (e.g., microphones to identify tagged audio signals). In addition, a variety of information may be derived via the communication components 540, such as location via Internet Protocol (IP) geolocation, location via Wi-Fi® signal triangulation, location via detecting an NFC beacon signal that may indicate a particular location, and so forth.

[0095] The various memories (e.g., memory 504, main memory 512, static memory 514, and / or memory of the processors 502) and / or storage unit 516 may store one or more sets of instructions and data structures (e.g., software) embodying or used by any one or more of the methodologies or functions described herein. These instructions (e.g., the instructions 508), when executed by processors 502, cause various operations to implement the disclosed examples.

[0096] The instructions 508 may be transmitted or received over the network 520, using a transmission medium, via a network interface device (e.g., a network interface component included in the communication components 540) and using any one of a number of well-known transfer protocols (e.g., hypertext transfer protocol (HTTP)). Similarly, the instructions 508 may be transmitted or received using a transmission medium via the coupling 526 (e.g., a peer-to-peer coupling) to the devices 522.

[0097] Although examples have been described, it will be evident that various modifications and changes may be made to these examples without departing from the broader scope of the present disclosure. Accordingly, the specification and drawings are to be regarded in an illustrative rather than a restrictive sense. The accompanying drawings that form a part hereof, show by way of illustration, and not of limitation, specific examples in which the subject matter may be practiced. The examples illustrated are described in sufficient detail to enable those skilled in the art to practice the teachings disclosed herein. Other examples may be utilized and derived therefrom, such that structural and logical substitutions and changes may be made without departing from the scope of this disclosure. This Detailed Description, therefore, is not to be taken in a limiting sense, and the scope of various examples is defined only by the appended claims, along with the full range of equivalents to which such claims are entitled.

[0098] Such examples of the inventive subject matter may be referred to herein, individually and / or collectively, by the term "invention" merely for convenience and without intending to voluntarily limit the scope of this application to any single invention or inventive concept if more than one is in fact disclosed. Thus, although specific examples have been illustrated and described herein, it should be appreciated that any arrangement calculated to achieve the same purpose may be substituted for the specific examples shown. This disclosure is intended to cover any and all adaptations or variations of various examples. Combinations of the above examples, and other examples not specifically described herein, will be apparent to those of skill in the art upon reviewing the above description.

[0099] The Abstract of the Disclosure is provided to allow the reader to quickly ascertain the nature of the technical disclosure. It is submitted with the understanding that it will not be used to interpret or limit the scope or meaning of the claims. In addition, in the foregoing Detailed Description, it can be seen that various features are grouped together in a single example for the purpose of streamlining the disclosure. Thismethod of disclosure is not to be interpreted as reflecting an intention that the claimed examples require more features than are expressly recited in each claim. Rather, as the following claims reflect, inventive subject matter lies in less than all features of a single disclosed example. Thus the following claims are hereby incorporated into the Detailed Description, with each claim standing on its own as a separate example.

[0100] In view of the disclosure above, various examples are set forth below. It should be noted that one or more features of an example, taken in isolation or combination, should be considered within the disclosure of this application.

[0101] Example 1. A system comprising: one or more hardware processors; and at least one machine-storage medium for storing instructions that, when executed by the one or more hardware processors, cause the one or more hardware processors to perform operations comprising: receiving, by a server, an identifier associated with a physical access control (PAC) reader device and directional data indicating an angle between the PAC reader device and a mobile device associated with a user; processing the directional data by the server to determine whether the mobile device associated with the user is located within a defined region relative to the PAC reader device; and validating, by the server, presence of the user within the defined region in response to processing the directional data.

[0102] Example 2. The system of Example 1, wherein the directional data comprises angle of arrival (AoA) data computed by the PAC reader device based on one or more signals received from the mobile device.

[0103] Example 3. The system of any one of Examples 1-2, wherein the directional data comprises angle of departure (AoD) data transmitted by the PAC reader device and received by the mobile device.

[0104] Example 4. The system of any one of Examples 1-3, wherein the PAC reader device includes multiple antennas for computing the directional data.

[0105] Example 5. The system of any one of Examples 1-4, wherein processing the directional data comprises determining whether the mobile device is located inside or outside of a building associated with the PAC reader device.

[0106] Example 6. The system of any one of Examples 1-5, wherein the operations further comprise: receiving timestamp information associated with the directional data; and using the timestamp information to validate the presence of the user.

[0107] Example 7. The system of any one of Examples 1-6, wherein validating presence comprises: determining whether the user is authorized to access an area associated with the defined region; and granting or denying access based on the determination.

[0108] Example 8. The system of any one of Examples 1-7, wherein the operations further comprise: storing historical positioning information for the user based on previously received directional data. Furthermore, one or more entries from the historical positioning information for the user may be retrieved to be used as part of authenticating a user or the user’s mobile device, such as for comparison against user input to a challenge or to compare the stored historical record with the corresponding information in the user’s authentic mobile device.

[0109] Example 9. The system of any one of Examples 1-8, wherein the operations further comprise: receiving, from the PAC reader device by the mobile device, encoded angular data transmitted through multiple antennas of the PAC reader device, wherein the encoded angular data indicates a direction that one or more signals are being transmitted from the PAC reader device; processing, by the mobile device, the encoded angular data using a built-in antenna array to interpret the angular data and determine AoD information; and transmitting the determined AoD information to the server as part of the directional data for validating the presence of the user.

[0110] Example 10. The system of any one of Examples 1-9, wherein the PAC reader device computes the directional data by performing operations comprising: receiving, via multiple antennas of the PAC reader device, Bluetooth Low Energy (BLE) signals transmitted from the mobile device; measuring signal characteristics of the BLE signals received at each antenna of the multiple antennas to determine relative signal timing and strength between the antennas; and calculating, based on the measured signal characteristics from the multiple antennas, an AoA value indicating the direction from which the BLE signals from the mobile device were received relative to the PAC reader device.

[0111] Example 11. The system of Example 10, the operations comprising: combining the calculated AoA value with a timestamp indicating when the BLE signals were received; and transmitting the calculated AoA value and timestamp to the server for use in determining whether the mobile device is located within the defined region.

[0112] Example 12. The system of any one of Examples 1-11, wherein the server receives the directional data from the mobile device.

[0113] Example 13. The system of any one of Examples 1-12, wherein the server receives the directional data from the PAC reader device.

[0114] Example 14. The system of any one of Examples 1-13, wherein the operations comprise: detecting, by the mobile device, the identifier of the PAC reader device in packets broadcast by the PAC reader device using BLE scanning; deriving the angle between the PAC reader device and the mobile device based on directional metadata included in the packets that are broadcast; and generating a package of data for transmission to the server by the mobile device, the package of data comprising the identifier of the PAC reader device, the derived angle comprising the directional data, and a timestamp.

[0115] Example 15. The system of any one of Examples 1-14, wherein validating the presence of the user comprises providing location-based services to the mobile device associated with the defined region.

[0116] Example 16. A method comprising: receiving, by a server, an identifier associated with a physical access control (PAC) reader device and directional data indicating an angle between the PAC reader device and a mobile device associated with a user; processing the directional data by the server to determine whether the mobile device associated with the user is located within a defined region relative to the PAC reader device; and validating, by the server, presence of the user within the defined region in response to processing the directional data.

[0117] Example 17. The method of Example 16, wherein the directional data comprises angle of arrival (AoA) data computed by the PAC reader device based on one or more signals received from the mobile device.

[0118] Example 18. The method of any one of Examples 16-17, wherein the directional data comprises angle of departure (AoD) data transmitted by the PAC reader device and received by the mobile device.

[0119] Example 19. The method of any one of Examples 16-18, wherein the PAC reader device includes multiple antennas for computing the directional data.

[0120] Example 20. A machine-storage medium for storing instructions that, when executed by one or more hardware processors, cause the one or more hardwareprocessors to perform operations comprising: receiving, by a server, an identifier associated with a physical access control (PAC) reader device and directional data indicating an angle between the PAC reader device and a mobile device associated with a user; processing the directional data by the server to determine whether the mobile device associated with the user is located within a defined region relative to the PAC reader device; and validating, by the server, presence of the user within the defined region in response to processing the directional data.

Claims

CLAIMSWhat is claimed is:

1. A system comprising:one or more hardware processors; andat least one machine-storage medium for storing instructions that, when executed by the one or more hardware processors, cause the one or more hardware processors to perform operations comprising:receiving, by a server, an identifier associated with a physical access control (PAC) reader device and directional data indicating an angle between the PAC reader device and a mobile device associated with a user;processing the directional data by the server to determine whether the mobile device associated with the user is located within a defined region relative to the PAC reader device; andvalidating, by the server, presence of the user within the defined region in response to processing the directional data.

2. The system of claim 1, wherein the directional data comprises angle of arrival (AoA) data computed by the PAC reader device based on one or more signals received from the mobile device.

3. The system of claim 1, wherein the directional data comprises angle of departure (AoD) data transmitted by the PAC reader device and received by the mobile device.

4. The system of claim 1, wherein the PAC reader device includes multiple antennas for computing the directional data.

5. The system of claim 1, wherein processing the directional data comprises determining whether the mobile device is located inside or outside of a building associated with the PAC reader device.

6. The system of claim 1, wherein the operations further comprise:receiving timestamp information associated with the directional data; and using the timestamp information to validate the presence of the user.

7. The system of claim 1, wherein validating presence comprises:determining whether the user is authorized to access an area associated with the defined region; andgranting or denying access based on the determination.

8. The system of claim 1, wherein the operations further comprise:storing historical positioning information for the user based on previously received directional data.

9. The system of claim 1, wherein the operations further comprise:receiving, from the PAC reader device by the mobile device, encoded angular data transmitted through multiple antennas of the PAC reader device, wherein the encoded angular data indicates a direction that one or more signals are being transmitted from the PAC reader device;processing, by the mobile device, the encoded angular data using a built-in antenna array to interpret the angular data and determine angle of departure (AoD) information; andtransmitting the determined AoD information to the server as part of the directional data for validating the presence of the user.

10. The system of claim 1, wherein the PAC reader device computes the directional data by performing operations comprising:receiving, via multiple antennas of the PAC reader device, Bluetooth Low Energy (BLE) signals transmitted from the mobile device;measuring signal characteristics of the BLE signals received at each antenna of the multiple antennas to determine relative signal timing and strength between the antennas; andcalculating, based on the measured signal characteristics from the multiple antennas, an angle of arrival (AoA) value indicating the direction from which the BLE signals from the mobile device were received relative to the PAC reader device.

11. The system of claim 10, the operations comprising:combining the calculated AoA value with a timestamp indicating when the BLE signals were received; andtransmitting the calculated AoA value and timestamp to the server for use in determining whether the mobile device is located within the defined region.

12. The system of claim 1, wherein the server receives the directional data from the mobile device.

13. The system of claim 1, wherein the server receives the directional data from the PAC reader device.

14. The system of claim 1, wherein the operations comprise:detecting, by the mobile device, the identifier of the PAC reader device in packets broadcast by the PAC reader device using Bluetooth Low Energy (BLE) scanning;deriving the angle between the PAC reader device and the mobile device based on directional metadata included in the packets that are broadcast; andgenerating a package of data for transmission to the server by the mobile device, the package of data comprising the identifier of the PAC reader device, the derived angle comprising the directional data, and a timestamp.

15. The system of claim 1, wherein validating the presence of the user comprises providing location-based services to the mobile device associated with the defined region.

16. A method comprising:receiving, by a server, an identifier associated with a physical access control (PAC) reader device and directional data indicating an angle between the PAC reader device and a mobile device associated with a user;processing the directional data by the server to determine whether the mobile device associated with the user is located within a defined region relative to the PAC reader device; andvalidating, by the server, presence of the user within the defined region in response to processing the directional data.

17. The method of claim 16, wherein the directional data comprises angle of arrival (AoA) data computed by the PAC reader device based on one or more signals received from the mobile device.

18. The method of claim 16, wherein the directional data comprises angle of departure (AoD) data transmitted by the PAC reader device and received by the mobile device.

19. The method of claim 16, wherein the PAC reader device includes multiple antennas for computing the directional data.

20. A machine-storage medium for storing instructions that, when executed by one or more hardware processors, cause the one or more hardware processors to perform operations comprising:receiving, by a server, an identifier associated with a physical access control (PAC) reader device and directional data indicating an angle between the PAC reader device and a mobile device associated with a user;processing the directional data by the server to determine whether the mobile device associated with the user is located within a defined region relative to the PAC reader device; andvalidating, by the server, presence of the user within the defined region in response to processing the directional data.