Short range to long range booster

WO2026166619A1PCT designated stage Publication Date: 2026-08-13ASSA ABLOY AB
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-02-07
Publication Date
2026-08-13

Smart Images

  • Figure EP2025053256_13082026_PF_FP_ABST
    Figure EP2025053256_13082026_PF_FP_ABST
Patent Text Reader

Abstract

A system for communicating with a physical access control (PAC) reader device is described. The system receives, by a controller, via a first communication interface, credential data from a physical component when the physical component is within a communication range of the first communication interface. The system, in response to receiving the credential data, transmits, by the controller, via a second communication interface, the credential data to a physical access control (PAC) reader device. A communication range associated with the second communication interface being greater than a communication range associated with the first communication interface.
Need to check novelty before this filing date? Find Prior Art

Description

SHORT RANGE TO LONG RANGE BOOSTERBACKGROUND

[0001] Access control systems have become integral to securing physical spaces, ensuring that only authorized individuals can enter or exit specific areas. Physical access control (PAC) reader devices are wall-mounted readers that interface with controllers to manage secure access to facilities. These readers serve as the front-end hardware components that communicate with access control system controllers to authenticate and process credential information.BRIEF SUMMARY

[0002] In some aspects, the techniques described herein relate to a system including: one or more hardware processors; and at least one machine-storage medium for storing instructions that, when executed by the one or more hardware processors, cause the one or more hardware processors to perform operations including: receiving, by a controller, via a first communication interface, credential data from a physical component when the physical component is within a communication range of the first communication interface; and in response to receiving the credential data, transmitting, by the controller, via a second communication interface, the credential data to a physical access control (PAC) reader device, a communication range associated with the second communication interface being greater than a communication range associated with the first communication interface.

[0003] In some aspects, the techniques described herein relate to a system, wherein the first communication interface includes a near-field communication (NFC) interface and the second communication interface includes a Bluetooth Low Energy (BLE) interface.

[0004] In some aspects, the techniques described herein relate to a system, wherein the physical component includes an access control card.

[0005] In some aspects, the techniques described herein relate to a system, wherein the controller is implemented on a mobile device.

[0006] In some aspects, the techniques described herein relate to a system, wherein the mobile device includes a smartphone having the first communication interface and the second communication interface.

[0007] In some aspects, the techniques described herein relate to a system, wherein the operations further include launching a booster application on the smartphone in response to detecting the physical component within range of the first communication interface.

[0008] In some aspects, the techniques described herein relate to a system, wherein the operations further include presenting, via a user interface of the smartphone, a prompt, the prompt including an option that, when selected by a user, confirms transmission of the credential data to the PAC reader device.

[0009] In some aspects, the techniques described herein relate to a system, wherein the operations further include automatically transmitting the credential data to the PAC reader device over the second communication interface without user intervention when the physical component is detected within range of the first communication interface.

[0010] In some aspects, the techniques described herein relate to a system, wherein the operations further include establishing a communication channel with the PAC reader device via the second communication interface prior to transmitting the credential data; and receiving, by the controller, a request for credentials from the PAC reader device over the established communication channel, the credential data being transmitted to the PAC reader device in response to receiving the request.

[0011] In some aspects, the techniques described herein relate to a system, wherein the controller is implemented on a dedicated hardware booster device having the first communication interface and the second communication interface.

[0012] In some aspects, the techniques described herein relate to a system, wherein the system operates as a relay between the physical component and the PAC reader device without storing authentication credentials.

[0013] In some aspects, the techniques described herein relate to a system, wherein the PAC reader device includes a hybrid reader configured to process both near-field communications (NFC) and Bluetooth Low Energy (BLE) communications.

[0014] In some aspects, the techniques described herein relate to a system, wherein the credential data includes encrypted data packets.

[0015] In some aspects, the techniques described herein relate to a system, wherein the system includes an application executing on a mobile device, the application configured to operate in a background mode to detect the physical component.

[0016] In some aspects, the techniques described herein relate to a system, wherein the first communication interface is configured to operate within a range of approximately one inch from the physical component.

[0017] In some aspects, the techniques described herein relate to a system, wherein the second communication interface is configured to operate within a range of multiple meters from the PAC reader device.

[0018] In some aspects, the techniques described herein relate to a system, wherein the physical component lacks circuitry configured to communicate via the second communication interface.

[0019] In some aspects, the techniques described herein relate to a method including: receiving, by a controller, via a first communication interface, credential data from a physical component when the physical component is within a communication range of the first communication interface; and in response to receiving the credential data, transmitting, by the controller, via a second communication interface, the credential data to a physical access control (PAC) reader device, a communication range associated with the second communication interface being greater than a communication range associated with the first communication interface.

[0020] In some aspects, the techniques described herein relate to a machine-storage medium for storing instructions that, when executed by one or more hardware processors, cause the one or more hardware processors to perform operations including: receiving, by a controller, via a first communication interface, credential data from a physical component when the physical component is within a communication range of the first communication interface; and in response to receiving the credential data, transmitting, by the controller, via a second communication interface, the credential data to a physical access control (PAC) reader device, a communication range associated with the second communication interface being greater than a communication range associated with the first communication interface.

[0021] In some aspects, the techniques described herein relate to a machine-storage medium, wherein the first communication interface includes a near-field communication (NFC) interface, and the second communication interface includes a Bluetooth Low Energy (BLE) interface.BRIEF DESCRIPTION OF THE SEVERAL VIEWS OF THE DRAWINGSDETAILED DESCRIPTION

[0022] Example methods and systems for an access control system are described. In the following description, for purposes of explanation, numerous specific details are set forth in order to provide a thorough understanding of the disclosed examples. It will be evident, however, to one of ordinary skill in the art that examples of the disclosure may be practiced without these specific details.

[0023] Access control systems have become integral to securing physical spaces, such as parking lots, ensuring that only authorized individuals can enter or exit specific areas. PAC reader devices serve as wall-mounted readers that interface with controllers to manage secure access to facilities, where these readers function as the front-end hardware components that communicate with access control system controllers to authenticate and process credential information. One of the fundamental challenges in conventional access control systems relates to range limitations of the underlying radio frequency identification (RFID) technology. These systems primarily rely on RFID characteristics to couple readers and cards within a very limited range, making it particularly problematic for applications like parking access where longer range capabilities are needed. The intrinsic limitations of the technology create significant difficulties for businesses to provide suitable experiences, especially in scenarios requiring extended range functionality.

[0024] In parking environments (and other similar environments and applications), users are typically required to present their credentials within an extremely short range -approximately one inch from the reader. This often necessitates drivers to awkwardly stretch out of their vehicle windows or exit their vehicles entirely to reach the reader mounted on an entry pole. This conventional approach creates considerable friction in the user experience, as drivers may need to physically maneuver their vehicles and themselves to achieve the proper credential reading distance. The situation is particularly problematic because, while hybrid readers with both short-range and long-range capabilities are available, the fundamental limitation remains with the traditional plastic cards that lack the physical capability to communicate beyond the short-range field. This results in customers expressing frustration that despite modern technological advances, they are still forced to comply with these cumbersome short-range reading requirements.

[0025] The inefficiencies extend beyond mere inconvenience. Organizations may either accept these limitations and the associated reduction in throughput at parking entrances (and other similar access restricted areas) or invest in expensive alternative solutions. While virtual credentials stored on phones exist as an alternative, these solutions introduce their own complications, including resistance from organizations concerned about requiring employees to use personal devices for corporate access control. This creates additional overhead in managing separate credential systems and raises issues around device integrity, ownership, liability, and potential tracking concerns.Furthermore, the existing infrastructure of installed readers and issued credentials represents a significant investment that organizations are reluctant to abandon, creating a costly technological deadlock that impacts operational efficiency.

[0026] The security requirement policies in conventional systems usually mandate that vendors prevent producing market solutions that can be cloned or copied. Additionally, these security systems need to resist relay attacks, where attackers attempt to create a chain connecting a user far away from an access point to enable unauthorized access. These relay attacks utilize complex technology to bridge the distance gap, effectively bypassing the intentional range limitations built into the security system. This creates a significant technical challenge in developing solutions that can extend range capabilities while maintaining robust security measures.

[0027] The disclosed system addresses these technical challenges by implementing a short-range to long-range booster solution that enables secure credential transmission over extended distances. The disclosed system utilizes a controller, which may be implemented on a mobile device or dedicated hardware, to receive credential data from a physical component (like a physical access card) via a first communication interface operating at short range. In response to detecting that the physical component has come within range of the first communication interface (e.g., about one inch), the controller can receive the credential data. The controller can then automatically (or responsive to user input / confirmation) transmit the credential data via a second communication interface to a PAC reader device. The second interface can operate at a greater range of multiple meters than the first communication interface.

[0028] This approach is particularly effective for parking access scenarios, as it allows users to present their physical access cards to their mobile device (e.g., smartphone or booster device) while still remaining in their vehicle. The mobile device can then receivethe credential data from the physical access card (e.g., over NFC) and relay the credential data over BLE to the PAC reader device at the entrance. The disclosed system can operate as a neutral relay without storing any authentication credentials or corporate information, making it more palatable for organizations concerned about using personal devices for access control. Additionally, the solution leverages existing infrastructure and credentials while extending their functional range through the booster technology.

[0029] The disclosed system can be implemented through a smartphone application running in the background that detects nearby credentials, or through a dedicated hardware booster device. In either case, the solution maintains security by transmitting properly encrypted data packets within specific time windows, while the PAC reader device validates the relayed credentials using existing security protocols. This enables organizations to provide convenient long-range access capabilities without compromising their security requirements or requiring significant infrastructure changes.

[0030] FIG. 1 is a block diagram showing an example access control system 103, according to various examples. The access control system 103 can include a client device 104 (e.g., mobile device or dedicated booster device), a controller 106, server 107, and PAC device 101. The client device 104 (which can in some cases perform functionality of the controller 106) and the PAC device 101 are communicatively coupled over a network 102 (e.g., Internet, BLE, ultra-wideband (UWB) communication protocol, Near Field Communication (NFC), and / or telephony network) with each other and with the server 107. While the disclosed techniques are discussed in the context of PAC devices, similar techniques are applicable to any other type of access control device, such as a logical access control (LAC) device.

[0031] As used herein, the term “client device” may refer to any machine that interfaces to a communications network (such as network 102) to exchange credentials with an access control device, such as the PAC device 101, the server 107 associated with the access control device, another client device 104, or any other component to obtain access to a logical or physical asset or resource protected by the access control device. In some examples, the client device 104 can additionally or alternatively communicate directly with, for example, an access control device or another client device 104. The client device 104 can include or store one or more credentials which can be provided to the access control device 101 for obtaining access to a protected physical or logical asset or resource.

[0032] A client device 104 may be, but is not limited to, a mobile phone, desktop computer, laptop, portable digital assistant (PDA), smart phone, a wearable device (e.g., a smart watch), tablet, ultrabook, netbook, multi-processor system, microprocessor-based or programmable consumer electronics, physical card, or any other communication device that a user may use to access a network.

[0033] The access control device (e.g., the PAC device 101) can include an access reader device (also referred to as an access control reader) connected to a secure / protected resource (e.g., a door locking mechanism or backend server) that controls the secure / protected resource (e.g., door locking mechanism). The resource associated with the access control device can include a door lock, an ignition system for a vehicle, or any other device that grants or denies access to a physical component or that can be operated to grant or deny access to the physical component. For example, in the case of a door lock, the access control device can deny access, in which case the door lock remains locked, and the door cannot be opened; or the access control device can grant access, in which case the door lock becomes unlocked to allow the door to be opened. As another example, in the case of an ignition system, the access control device can deny access, in which case the vehicle ignition system remains disabled and the vehicle cannot be started; or the access control device can grant access, in which case the vehicle ignition becomes enabled to allow the vehicle to be started.

[0034] PAC covers a range of systems and methods to govern access, for example by people, to secure areas or secure assets. PAC includes identification of authorized users or devices (e.g., vehicles, drones, etc.) and actuation of a gate, door, or other facility used to secure an area, or actuation of a control mechanism, for example, a physical or electronic / software control mechanism, permitting access to a secure asset. The access control device may form part of a physical access control system (PACS), which can include a reader (e.g., an online or offline reader) that may hold authorization data (also referred to access control information) and can be capable of determining whether credentials (e.g., from credential or key devices such as radio frequency identification (RFID) chips in cards, fobs, or personal electronic devices such as mobile phones) are authorized for an actuator or control mechanism (e.g., door lock, door opener, software control mechanism, turning off an alarm, etc.), or a PACS can include a host server 107 to which readers and actuators are connected (e.g., via a controller) in a centrally managed configuration.

[0035] In centrally managed configurations, readers can obtain credentials from credential or key devices (e.g., from one or more client devices 104) and pass those credentials to the PACS host server (e.g., server 107) or headend system. The readers can send the credentials over a wired or wireless link, such as network 102. The host server then determines whether the credentials authorize access to the secure area or secure asset (or resource) and commands the actuator or other control mechanism of the PAC device 101 accordingly by sending an allow / deny message back to the reader over the wired or wireless link. While examples in physical access control are used herein, the disclosure applies similarly to LACS use cases (e.g., logical access to personal electronic devices, logical access to personal online or electronic accounts or documents, etc.).

[0036] In general, the PAC device 101 can include one or more of a memory, a processor, one or more antennas, a communication module, a network interface device, a user interface, a display, and a power source or supply. The memory of the PAC device 101 can be used in connection with the execution of application programming or instructions by the processor of the PAC device 101, and for the temporary or long-term storage of program instructions or instruction sets and / or credential or authorization data, such as credential data, credential authorization data, or access control data or instructions. For example, the memory can contain executable instructions that are used by the processor to run other components of PAC device 101 and / or to make access determinations based on credential or authorization data, such as by communicating with the authorization system 108 of the server 107.

[0037] The memory of the PAC device 101, server 107, and / or client device 104 can include a transitory or non-transitory computer-readable medium. The computer-readable medium can be, for example, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device. More specific examples of suitable computer-readable medium include, but are not limited to, an electrical connection having one or more wires or a tangible storage medium such as a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), Dynamic RAM (DRAM), any solid-state storage device in general, a compact disc read-only memory (CD-ROM), or other optical or magnetic storage device.Computer-readable media includes, but is not to be confused with, computer-readablestorage medium, which is intended to cover all physical, non-transitory, or similar examples of computer-readable media.

[0038] The processor of the PAC device 101 can correspond to one or more computer processing devices or resources. For instance, the processor can be provided as silicon, as a Field Programmable Gate Array (FPGA), an Application-Specific Integrated Circuit (ASIC), any other type of Integrated Circuit (IC) chip, a collection of IC chips, or the like. As a more specific example, the processor can be provided as a microprocessor, Central Processing Unit (CPU), or plurality of microprocessors or CPUs that are configured to execute instructions sets stored in an internal memory and / or memory of the access control device.

[0039] The antenna of the PAC device 101 can correspond to one or multiple antennas and can be configured to provide for wireless communications between PAC device 101 and a credential or key device (e.g., client device 104). The antenna can be arranged to operate using one or more wireless communication protocols and operating frequencies including, but not limited to, the IEEE 502.15.1, Bluetooth, BLE, NFC, ZigBee, Global System for Mobile communications (GSM), Code Division Multiple Access (CDMA), Wi-Fi, RF, UWB, and the like. By way of example, the antenna(s) can be RF antenna(s), and as such, may transmit / receive RF signals through free space to be received / transferred by a credential or key device having an RF transceiver.

[0040] A communication module or communication component of the PAC device 101 can be configured to communicate according to any suitable short-range and / or long-range communications protocol or interface with one or more different systems or devices either remote or local to the PAC device 101, such as one or more client devices 104 and / or servers / controllers, such as server 107 and / or a physical component 110 (e.g., a physical access card). In some cases, the communication module uses a same wired or wireless link between the PAC device 101 and the server 107 for all the communication modes. In some cases, the communication module uses one wired or wireless link between the PAC device 101 and the server 107 to communicate access control information to the authorization system 108 and uses a different wired or wireless link to communicate or receive configuration information updates from the server 107 over the Internet Protocol (IP) communication mode.

[0041] The network interface device of the PAC device 101 includes hardware to facilitate communications with other devices, such as a one or more client devices 104and / or server / controller (e.g., server 107, controller 106, and / or production server 105), over a communication network, such as network 102, utilizing any one of a number of transfer protocols (e.g., frame relay, IP, transmission control protocol (TCP), user datagram protocol (UDP), hypertext transfer protocol (HTTP), etc.). Example communication networks can include a local area network (LAN), a wide area network (WAN), a packet data network (e.g., the Internet), mobile telephone networks (e.g., cellular networks), Plain Old Telephone (POTS) networks, wireless data networks (e.g., IEEE 502.11 family of standards known as Wi-Fi, IEEE 502.16 family of standards known as WiMax), IEEE 502.15.4 family of standards, and peer-to-peer (P2P) networks, among others. In some examples, network interface device can include an Ethernet port or other physical jack, a Wi-Fi card, a Network Interface Card (NIC), a cellular interface (e.g., antenna, filters, and associated circuitry), or the like. In some examples, network interface device can include a plurality of antennas to wirelessly communicate using at least one of single-input multiple-output (SIMO), multiple-input multiple-output (MIMO), or multiple-input single-output (MISO) techniques.

[0042] A user interface of the PAC device 101 can include one or more input devices and / or display devices. Examples of suitable user input devices that can be included in the user interface include, without limitation, one or more buttons, a keyboard or keypad, a mouse, a touch-sensitive surface, a stylus, a camera, a microphone, and so forth.Examples of suitable user output devices that can be included in the user interface include, without limitation, one or more light emitting diodes (LEDs), a liquid crystal display (LCD) panel, a display screen, a touchscreen, one or more lights, a speaker, and so forth. It should be appreciated that the user interface can also include a combined user input and user output device, such as a touch-sensitive display or the like.

[0043] The network 102 may include, or operate in conjunction with, an ad hoc network, an intranet, an extranet, a virtual private network (VPN), a LAN, a wireless network, a wireless LAN (WLAN), a WAN, a wireless WAN (WWAN), short-range and / or long-range communication network, a metropolitan area network (MAN), BLE, UWB, the Internet, a portion of the Internet, a portion of the Public Switched Telephone Network (PSTN), a POTS network, a cellular telephone network, a wireless network, a Wi-Fi® network, another type of network, or a combination of two or more such networks. For example, a network or a portion of a network may include a wireless or cellular network and the coupling may be a CDMA connection, a GSM connection, orother type of cellular or wireless coupling. In this example, the coupling may implement any of a variety of types of data transfer technology, such as Single Carrier Radio Transmission Technology (IxRTT), Evolution-Data Optimized (EVDO) technology, General Packet Radio Service (GPRS) technology, Enhanced Data rates for GSM Evolution (EDGE) technology, third Generation Partnership Project (3 GPP) including 3G, fourth generation wireless (4G) networks, fifth generation wireless (5G) networks, Universal Mobile Telecommunications System (UMTS), High Speed Packet Access (HSPA), Worldwide Interoperability for Microwave Access (WiMAX), Long Term Evolution (LTE) standard, others defined by various standard setting organizations, other short range or long range protocols, or other data transfer technology.

[0044] In an example, as the client device 104 approaches the PAC device 101 (e.g., comes within range of a BLE communication protocol), the client device 104 transmits credentials of the client device 104 over the network 102. In some cases, these credentials can be received by the client device 104 from the physical component 110 via NFC. In one example, the client device 104 provides the credentials directly to the PAC device 101. In such cases, the PAC device 101 communicates the credentials with the server 107. The server 107 includes an authorization system 108. The server 107, client device 104, and / or the PAC device 101 can further include elements described with respect to FIG. 4 and FIG. 5, such as a processor and memory, having instructions stored thereon, that when executed by the processor, causes the processor to control the functions of the server / controller, client device 104, and / or the PAC device 101. The server 107 can be implemented on a centralized set of servers of a cloud-based system.

[0045] The server 107 searches a list of credentials stored in the authorization system 108 to determine whether the received credentials match credentials from the list of authorized credentials for accessing a secure asset or resource (e.g., door or secure area) protected by the PAC device 101. In response to determining that the received credentials are authorized to access the PAC device 101, the server 107 (also referred to as the controller) instructs the PAC device 101 to perform an operation granting access for the client device 104 (e.g., instructing the PAC device 101 to unlock a lock of a door).

[0046] In some examples, the client device 104 can receive credential data from the physical component 110 via a first communication interface 114 when the physical component 110 comes within a communication range of the first communicationinterface 114 of the client device 104. The first communication interface can operate using NFC at 13.56 MHz with a range of approximately one inch. The controller 106, which may be implemented on the client device 104, manages this initial credential data reception. The controller 106 can detect presence of the physical component 110 and, in response, the controller 106 obtains the credential data from the physical component 110.

[0047] In some cases, the client device 104 can implement an application executing on a mobile device that operates in background mode to continuously monitor for and detect when the physical component 110 comes within range of the first communication interface 114. When detection occurs, a booster application automatically launches on the mobile device in response to detecting the physical component within range. In some cases, the client device 104 can present a user interface prompt on the mobile device when the physical component 110 is detected, including an option that requires user confirmation before transmitting the credential data. This approach allows users to actively control when credential data is collected and transmitted. In some cases, the client device 104 can be configured to automatically detect the physical component 110 and transmit credential data without user intervention when the physical component 110 comes within range of the first communication interface 114. In this implementation, the controller 106 establishes a communication channel with the PAC reader device 212 beforehand and receives a request for credentials, enabling immediate transmission once the physical component 110 is detected.

[0048] In response to receiving the credential data from the physical component 110, the controller 106 transmits the credential data via a second communication interface 112 to the PAC device 101. The second communication interface can operate using BLE over 2.4 / 5 GHz frequencies, providing a communication range of multiple meters, which can be greater than the range of the first communication interface 114. This enables users to authenticate from a more convenient distance, particularly in parking access scenarios.

[0049] The client device 104 can be implemented either as a mobile device, such as a smartphone running a specialized application, or as a dedicated hardware booster device having both communication interfaces (e.g., the first communication interface 114 and the second communication interface 112). The client device 104 operates as a relay between the physical component 110 and the PAC device 101 without storingauthentication credentials, maintaining security while extending the functional range of traditional access credentials.

[0050] The PAC device 101 can include a hybrid reader configured to process both NFC and BLE communications. Namely, the PAC device 101 is configured to communicate via both the first communication interface 114 and the second communication interface 112 or can be configured to exclusively communicate or operate according to the second communication interface 112. When receiving credential data via the second communication interface 112, the PAC device 101 communicates with the authorization system 108 on server 107 to authenticate and process the credential information. The system maintains security by transmitting properly encrypted data packets within specific time windows.

[0051] The controller 106 can establish a communication channel with the PAC device 101 via the second communication interface prior to transmitting credential data. The controller 106 can receive requests for credentials from the PAC device 101 over this established channel. This ensures proper authentication and secure transmission of credential data throughout the extended range communication process.

[0052] FIG. 2 illustrates a diagram 204 of a system for boosting credential data transmission between a physical component 110 (e.g., a physical access card 210) and a PAC reader device 212, in accordance with some examples.

[0053] The system shown in FIG. 2 includes three primary components, such as a physical component 110 (physical access card 210), a booster component (which can be implemented as either as dedicated booster device 206 or a mobile device 208), and a PAC reader device 212.

[0054] The physical access card 210 can operate and be configured to transmit credential data stored on the physical access card 210 using high-frequency communications at 13.56 MHz, which is characteristic of NFC-based credentials. This physical access card 210 represents the existing infrastructure that organizations have already invested in and continue to use.

[0055] The booster component can include a controller 106. This booster component serves as the bridge between the short-range (e.g., NFC) and long-range communication protocols (e.g., BLE or Internet). The system operates as follows: initially, the booster component wakes up in response to detecting the physical access card 210 within the NFC range of the booster component. In response, the booster component obtains thecredential data from the physical access card 210. Then, the booster component (automatically or in response to user input) transmits the credential data to the PAC reader device 212 over a BLE communication session that is established with the PAC reader device 212.

[0056] In some examples, the booster component is initially woken up in response to detecting the PAC reader device 212 within range the BLE communication interface. In response, the booster component can negotiate transmission and credential collection parameters, including ephemeral keys with the PAC reader device 212. This establishes a secure connection between the booster component and the PAC reader device 212. The PAC reader device 212, via this secure connection, may request that the booster component transmit credential data. In response, the booster component activates the NFC interface and detects presence of the physical access card 210 within range of the NFC interface.

[0057] The booster component collects identification information or credential data within the short-range field using NFC / RF technology. This occurs when the physical component 110 comes within approximately one inch of the booster's first communication interface (e.g., the NFC interface). The booster component then transmits the identification information or credential data to the PAC reader device 212 over the pre-established BLE connection or long-range communication interface. This enables communication at distances of multiple meters between the booster component and the reader device.

[0058] In some cases, a threshold time period can be set between when the booster component establishes the connection with the PAC reader device 212 and when the booster component transmits the credential data to the PAC reader device 212. Namely, the system can implement time-based security controls. When establishing the communication channel with the PAC reader device 212, the controller 106 receives a request for credentials over the established channel. The PAC reader device 212 can be designed to only process properly formed encrypted data packets that are received within specific time windows, silently discarding any communications received outside these windows.

[0059] For denial of service protection and noise control, the PAC reader device 212 can be configured to automatically discard any communication attempts that submit malformed packets. Once the communication channel is established between the boostercomponent and PAC reader device 212, the booster component may have a very limited time window to submit properly formed packets with the correct encryption wrapping. This time-based validation helps the PAC reader device 212 distinguish genuine conversations from general noise that may need to be discarded. This time window approach is particularly important in environments with high device density, such as buildings or stadiums where thousands of phone holders may be present. The time threshold prevents the PAC reader device 212 from attempting to process every packet hitting its BLE interface, which could otherwise overwhelm the reader's memory and cause crashes.

[0060] The system maintains security by transmitting the encrypted credential data packets only within these specific designated time windows, while the PAC reader device 212 validates the relayed credentials using existing security protocols. When the booster component detects the physical component within range of the first communication interface, the booster component may need to collect and transmit the credential data within the specific designated time windows to maintain security. For the initial detection, the system can operate in background mode through a mobile application that continuously monitors for nearby credentials. Once the physical access card 210 is detected, the booster component may need to quickly establish the communication channel with the PAC reader device 212 and receive a request for credentials over that channel.

[0061] The booster component may then have a very limited time window to complete two steps, such as collecting the credential data from the physical access card 210 via the short-range NFC interface and transmitting properly formed encrypted packets containing the credential data with the correct encryption wrapping via BLE to the PAC reader device 212. The booster component may perform these operations without permanently storing the credential data. If the credential collection and transmission process extends beyond the designated time window, the PAC reader device 212 can be designed to automatically discard the communication attempt as potentially malicious or as noise. This time-based validation helps prevent relay attacks while ensuring legitimate credentials are processed efficiently. The system maintains security by enforcing these strict time windows between credential detection and transmission, particularly in high-density environments where multiple devices may be attempting to communicate with the reader. The PAC reader device 212 validates the relayed credentials only when theyare received within the proper time constraints and contain the correct encryption protocols.

[0062] The booster component implements both NFC and BLE interfaces, allowing it to communicate with legacy credentials at short range while extending their functionality through long-range BLE transmission. The PAC reader device 212 represents a hybrid PAC reader that can process both NFC and BLE communications. This dual-protocol capability allows the PAC reader device 212 to maintain compatibility with existing credentials while supporting the extended range functionality.

[0063] The system maintains security throughout the transmission process by operating as a relay without storing authentication credentials. This ensures that sensitive information is not retained within the booster component. When implemented as a mobile device application, the booster component can operate in background mode to continuously monitor for nearby credentials, launching a user interface automatically when a physical access card 210 comes within range of NFC.

[0064] The BLE communication channel between the booster component and PAC reader device 212 can be established prior to credential transmission, with the PAC reader device 212 sending requests for credentials over this established channel. The booster component can negotiate transmission parameters with the PAC reader device 212, ensuring proper encryption and security protocols are maintained throughout the extended range communication. In some cases, the BLE can be established after the booster component detects presence of the physical access card 210 within the NFC range of the booster component. In such cases, the booster component collects the credential data from the physical access card 210 (e.g., in encrypted form) and then establishes the BLE connection with the PAC reader device 212 to transmit the credential data over the BLE connection.

[0065] Optionally, the booster component may also detect the presence of one or more PAC reader devices within the vicinity of the mobile device. The booster component may then present a user interface displaying the one or more PAC reader devices detected. The user may then select which of the PAC readers to communicate with. Additionally, the booster component may display additional information (e.g., manufacturer, type, location, proximity, relative signal strength, etc.) or identifiers (e.g., friendly names, MAC addresses, etc.) associated with the one or more detected PAC reader devices to further assist the user in determining which PAC reader device tocommunicate with. The booster component may optionally be previously configured to pair with one or more specific PAC readers or store prior configuration information associated with one or more specific PAC readers. Configuration between the mobile device and a PAC reader device may include BLE authorization and / or authentication procedures, or may also include establishing a list of or connection with trusted / approved devices. In such a situation, the booster component may determine whether one of the one or more detected PAC reader devices matches a previously configured PAC reader device. If a match exists, the booster component may display an additional indicator to the user that the device is a previously configured device, or may indicate that other devices are not previously configured devices. Alternatively, if a match exists, the booster component may be configured to pre-select the previously configured PAC reader device and prompt the user for confirmation or to present their credential as described above. If more than one previously configured PAC reader device is within range, the displayed list of detected PAC reader devices may be filtered first to display those previously configured devices or may select from those whichever one of the PAC reader devices has the closest proximity or strongest signal strength. In some examples, the user may also configure one or more PAC reader devices to be preferred devices that are automatically selected whenever they are within range. The user may decline a selected PAC reader device and return to a listing of the devices within range instead to select a different PAC reader device.

[0066] In some examples, when the physical access card 210 comes within range of the mobile device's first communication interface 114, the mobile device (e.g., smartphone) can implement a user-controlled authentication flow through the user interface (display) of the mobile device. Specifically, the booster application launches the user interface on the mobile device in response to detecting the physical access card 210 within range of the first communication interface 114. Once launched, the application presents a prompt via the user interface of the mobile device. This prompt includes specific options that the user may select to confirm and authorize the transmission of the credential data to the PAC reader device 212. This user confirmation step provides an additional layer of control and security by ensuring credentials are only transmitted when explicitly authorized by the user.

[0067] After the user selects the confirmation option through the interface, the mobile device establishes a communication channel with the PAC reader device 212 via thesecond communication interface 112. The system then transmits the credential data over BLE to the PAC reader device 212, maintaining security through properly encrypted data packets within the designated time window. This approach gives users direct control over when their credentials are transmitted while still preserving the convenience of long-range access. The user interface confirmation process is particularly valuable in parking scenarios where multiple readers may be present, as it allows users to explicitly select which entrance they are attempting to access rather than automatically transmitting credentials to any nearby reader. This controlled transmission helps prevent unintended access attempts while still enabling convenient authentication from within the vehicle.

[0068] In some examples, when the mobile device comes within range of the PAC reader device 212, the booster application running in background mode detects the presence of the PAC reader device 212. The application then presents a user interface prompt requesting the user to present their physical access card 210 to the NFC interface of the mobile device to initiate the authentication process. After, before, or during displaying this prompt, the system establishes a communication channel with the PAC reader device 212 via the BLE interface. The PAC reader device 212 sends a request for credentials over this established channel, preparing for the upcoming credential transmission. During this time, the application waits for the user to present their physical access card 210 to the NFC interface of the mobile device, which can be within approximately one inch range.

[0069] Optionally, the mobile device may also detect the presence of one or more PAC reader devices within the vicinity of the mobile device. The application may then present a user interface displaying the one or more PAC reader devices detected. The user may then select which of the PAC readers to communicate with. Additionally, the application may display additional information (e.g., manufacturer, type, location, proximity, relative signal strength, etc.) or identifiers (e.g., friendly names, pseudonyms, MAC addresses, etc.) associated with the one or more detected PAC reader devices to further assist the user in determining which PAC reader device to communicate with. The mobile device may optionally be previously configured to pair with one or more specific PAC readers or store prior configuration information associated with one or more specific PAC readers. Configuration between the mobile device and a PAC reader device may include BLE authorization and / or authentication procedures, or mayalso include establishing a list of or connection with trusted / approved devices. In such a situation, the application may determine whether one of the one or more detected PAC reader devices matches a previously configured PAC reader device. If a match exists, the application may display an additional indicator to the user that the device is previously configured. Alternatively, if a match exists, the application may be configured to pre-select the previously configured PAC reader device and prompt the user for confirmation or to present their credential as described above. If more than one previously configured PAC reader device is within range, the displayed list of detected PAC reader devices may be filtered first to display those previously configured devices or may select from those whichever one of the PAC reader devices has the closest proximity or strongest signal strength. In some examples, the user may also configure one or more PAC reader devices to be preferred devices that are automatically selected whenever they are within range. The user also may decline a selected PAC reader device and return to a listing of the devices within range instead to select a different PAC reader device.

[0070] Once the user presents their physical access card 210 to the NFC interface of the mobile device, the controller 106 receives the credential data through the first communication interface 114. The application can then present another user interface prompt, displaying an option that, when selected by the user, confirms and authorizes the transmission of the credential data to the waiting PAC reader device 212. After receiving user confirmation through the interface, the controller 106 transmits the credential data via the BLE interface to the PAC reader device 212. This transmission can occur within a specific time window and includes properly encrypted data packets. The PAC reader device 212 then validates the relayed credentials using existing security protocols to complete the authentication process.

[0071] The system maintains security throughout this process by operating as a neutral relay and may never store the authentication credentials or corporate information on the booster component. Instead, the booster component simply facilitates the secure transmission of encrypted credential data between the physical component (e.g., physical access card 210) and the PAC reader device 212, in some cases within designated time constraints.

[0072] FIG. 3 illustrates a routine 300 (e.g., method or process) in accordance with some examples. The operations discussed in connection with FIG. 3 can be performedsequentially, in parallel, and in any suitable order. The operations discussed in FIG. 3 can be performed by the access control system 103.

[0073] In operation 302, a controller 106 receives, via a first communication interface 114, credential data from a physical component when the physical component is within a communication range of the first communication interface, as discussed above.

[0074] In operation 304, the controller 106, in response to receiving the credential data, transmits, via a second communication interface 112, the credential data to a physical access control (PAC) reader device, the PAC reader device, a communication range associated with the second communication interface being greater than a communication range associated with the first communication interface, as discussed above.

[0075] FIG. 4 is a block diagram illustrating an example of a software architecture 402 that may be installed on a machine, according to some examples. FIG. 4 is merely a nonlimiting example of a software architecture, and it will be appreciated that many other architectures may be implemented to facilitate the functionality described herein. The software architecture 402 may be executing on hardware such as a machine 500 of FIG.5 that includes, among other things, processors 510, memory 504, and input / output (I / O) components 542. A representative hardware layer 444 is illustrated and can represent, for example, the machine 500 of FIG. 5. The representative hardware layer 444 comprises one or more processing units 446 having associated executable instructions 448. The executable instructions 448 represent the executable instructions of the software architecture 402. The hardware layer 444 also includes memory 504, which also have the executable instructions 448. The hardware layer 444 may also comprise other hardware 452, which represents any other hardware of the hardware layer 444, such as the other hardware illustrated as part of the machine 500.

[0076] The instructions 448 may be transmitted or received over the network using a transmission medium via a network interface device (e.g., a network interface component included in the communication components 540) and utilizing any one of a number of well-known transfer protocols (e.g., hypertext transfer protocol (HTTP)). Similarly, the instructions 448 may be transmitted or received using a transmission medium via the coupling (e.g., a peer-to-peer coupling) to the devices. The terms “transmission medium” and “signal medium” mean the same thing and may be used interchangeably in this disclosure. The terms “transmission medium” and “signal medium” shall be taken to include any intangible medium that is capable of storing,encoding, or carrying the instructions 448 for execution by the machine 500, and include digital or analog communications signals or other intangible media to facilitate communication of such software. Hence, the terms “transmission medium” and “signal medium” shall be taken to include any form of modulated data signal, carrier wave, and so forth. The term “modulated data signal” means a signal that has one or more of its characteristics set or changed in such a manner as to encode information in the signal.

[0077] The terms “machine-readable medium,” “computer-readable medium,” and “device-readable medium” mean the same thing and may be used interchangeably in this disclosure. The terms are defined to include both machine-storage media and transmission media. Thus, the terms include both storage devices / media and carrier waves / modulated data signals.

[0078] As used herein, the terms “machine-storage medium,” “device-storage medium,” and “computer-storage medium” mean the same thing and may be used interchangeably in this disclosure. The terms refer to a single or multiple storage devices and / or media (e.g., a centralized or distributed database, and / or associated caches and servers) that store executable instructions and / or data. The terms shall accordingly be taken to include, but not be limited to, solid-state memories, and optical and magnetic media, including memory internal or external to processors. Specific examples of machinestorage media, computer-storage media, and / or device-storage media include nonvolatile memory, including by way of example semiconductor memory devices, e.g., erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), field-programmable gate arrays (FPGAs), and flash memory devices; magnetic disks such as internal hard disks and removable disks; magneto-optical disks; and CD-ROM and DVD-ROM disks. The terms “machinestorage medium,” “computer-storage medium,” and “device-storage medium” are non-transitory computer-readable media and specifically exclude carrier waves, modulated data signals, and other such media, at least some of which are covered under the term “signal medium.”

[0079] In the example architecture of FIG. 4, the software architecture 402 may be conceptualized as a stack of layers, where each layer provides particular functionality. For example, the software architecture 402 may include layers such as an operating system 436, libraries 428, framework / middl eware 422, applications 416, and a presentation layer 414. Operationally, the applications 416 or other components within the layers may invokeAPI calls API calls 424 through the software stack and receive a response, returned values, and so forth (illustrated as messages 426) in response to the API calls 424. The layers illustrated are representative in nature, and not all software architectures have all layers. For example, some mobile or special-purpose operating systems may not provide a framework / middleware 422 layer, while others may provide such a layer. Other software architectures may include additional or different layers.

[0080] The operating system 436 may manage hardware resources and provide common services. The operating system 436 may include, for example, a kernel 438, services 440, and drivers 442. The kernel 438 may act as an abstraction layer between the hardware and the other software layers. For example, the kernel 438 may be responsible for memory management, processor management (e.g., scheduling), component management, networking, security settings, and so on. The services 440 may provide other common services for the other software layers. The drivers 442 may be responsible for controlling or interfacing with the underlying hardware. For instance, the drivers 442 may include display drivers, camera drivers, Bluetooth® drivers, flash memory drivers, serial communication drivers (e.g., Universal Serial Bus (USB) drivers), Wi-Fi® drivers, audio drivers, power management drivers, and so forth depending on the hardware configuration.

[0081] The libraries 428 may provide a common infrastructure that may be utilized by the applications 416 and / or other components and / or layers. The libraries 428 typically provide functionality that allows other software modules to perform tasks in an easier fashion than by interfacing directly with the underlying operating system 436 functionality (e.g., kernel 438, services 440, or drivers 442). The libraries 428 may include system libraries 430 (e.g., C standard library) that may provide functions such as memory allocation functions, string manipulation functions, mathematic functions, and the like. In addition, the libraries 428 may include API libraries 432 such as media libraries (e.g., libraries to support presentation and manipulation of various media formats such as MPEG4, H.264, MP3, AAC, AMR, JPG, and PNG), graphics libraries (e.g., an OpenGL framework that may be used to render 2D and 3D graphic content on a display), database libraries (e.g., SQLite that may provide various relational database functions), web libraries (e.g., WebKit that may provide web browsing functionality), and the like. The libraries 428 may also include a wide variety of other libraries 434 to provide many other APIs to the applications 416 and other software components / modules.

[0082] The frameworks / middleware 422 (also sometimes referred to as middleware) may provide a higher-level common infrastructure that may be utilized by the applications 416 or other software components / modules. For example, the frameworks / middleware 422 may provide various graphical user interface functions, high-level resource management, high-level location services, and so forth. The frameworks / middleware 422 may provide a broad spectrum of other APIs that may be utilized by the applications 416 and / or other software components / modules, some of which may be specific to a particular operating system or platform.

[0083] The applications 416 include built-in applications 418 and / or third-party applications 420. Examples of representative built-in applications 418 may include, but are not limited to, a home application, a contacts application, a browser application, a book reader application, a location application, a media application, a messaging application, or a game application.

[0084] The third-party applications 420 may include any of the built-in applications 418, as well as a broad assortment of other applications. In a specific example, the third-party applications 420 (e.g., an application developed using the Android™ or iOS™ software development kit (SDK) by an entity other than the vendor of the particular platform) may be mobile software running on a mobile operating system such as iOS™, Android™, or other mobile operating systems. In this example, the third-party applications 420 may invoke the API calls 424 provided by the mobile operating system such as the operating system 436 to facilitate functionality described herein.

[0085] The applications 416 may utilize built-in operating system functions (e.g., kernel 438, services 440, or drivers 442), libraries (e.g., system libraries 430, API libraries 432, and other libraries 434), or framework / middleware 422 to create user interfaces to interact with users of the system. Alternatively, or additionally, in some systems, interactions with a user may occur through a presentation layer, such as the presentation layer 414. In these systems, the application / module “logic” can be separated from the aspects of the application / module that interact with the user.

[0086] Some software architectures utilize virtual machines. In the example of FIG. 4, this is illustrated by a virtual machine 404. The virtual machine 404 creates a software environment where applications / modules can execute as if they were executing on a hardware machine (e.g., the machine 500 of FIG. 5). The virtual machine 404 is hosted by a host operating system (e.g., the operating system 436) and typically, although notalways, has a virtual machine monitor, which manages the operation of the virtual machine 404 as well as the interface with the host operating system (e.g., the operating system 436). A software architecture executes within the virtual machine 404, such as an operating system 412, libraries 410, frameworks 408, applications 416, or a presentation layer 406. These layers of software architecture executing within the virtual machine 404 can be the same as corresponding layers previously described or may be different.

[0087] FIG. 5 is a diagrammatic representation of the machine 500 within which instructions 508 (e.g., software, a program, an application, an applet, an app, or other executable code) for causing the machine 500 to perform any one or more of the methodologies discussed herein may be executed. For example, the instructions 508 may cause the machine 500 to execute any one or more of the methods described herein. The instructions 508 transform the general, non-programmed machine 500 into a particular machine 500 programmed to carry out the described and illustrated functions in the manner described. The machine 500 may operate as a standalone device or may be coupled (e.g., networked) to other machines. In a networked deployment, the machine 500 may operate in the capacity of a server machine or a client machine in a server-client network environment, or as a peer machine in a peer-to-peer (or distributed) network environment. The machine 500 may comprise, but not be limited to, a server computer, a client computer, a personal computer (PC), a tablet computer, a laptop computer, a netbook, a set-top box (STB), a PDA, an entertainment media system, a cellular telephone, a smart phone, a mobile device, a wearable device (e.g., a smart watch), a smart home device (e.g., a smart appliance), other smart devices, a web appliance, a network router, a network switch, a network bridge, or any machine capable of executing the instructions 508, sequentially or otherwise, that specify actions to be taken by the machine 500. Further, while only a single machine 500 is illustrated, the term “machine” shall also be taken to include a collection of machines that individually or jointly execute the instructions 508 to perform any one or more of the methodologies discussed herein.

[0088] The machine 500 may include processors 502, memory 504, and I / O components 542, which may be configured to communicate with each other via a bus 544. In an example, the processors 502 (e.g., a Central Processing Unit (CPU), a Reduced Instruction Set Computing (RISC) processor, a Complex Instruction Set Computing (CISC) processor, a Graphics Processing Unit (GPU), a Digital Signal Processor (DSP), an ASIC, a Radio-Frequency Integrated Circuit (RFIC), anotherprocessor, or any suitable combination thereof) may include, for example, a processor 506 and a processor 510 that execute the instructions 508. The term “processor” is intended to include multi-core processors that may comprise two or more independent processors (sometimes referred to as “cores”) that may execute instructions contemporaneously. Although FIG. 5 shows multiple processors 502, the machine 500 may include a single processor with a single core, a single processor with multiple cores (e.g., a multi-core processor), multiple processors with a single core, multiple processors with multiples cores, or any combination thereof.

[0089] The memory 504 includes a main memory 512, a static memory 514, and a storage unit 516, both accessible to the processors 502 via the bus 544. The main memory 504, the static memory 514, and storage unit 516 store the instructions 508 embodying any one or more of the methodologies or functions described herein. The instructions 508 may also reside, completely or partially, within the main memory 512, within the static memory 514, within machine-readable medium 518 within the storage unit 516, within at least one of the processors 502 (e.g., within the processor’s cache memory), or any suitable combination thereof, during execution thereof by the machine 500.

[0090] The I / O components 542 may include a wide variety of components to receive input, provide output, produce output, transmit information, exchange information, capture measurements, and so on. The specific I / O components 542 that are included in a particular machine will depend on the type of machine. For example, portable machines such as mobile phones may include a touch input device or other such input mechanisms, while a headless server machine will likely not include such a touch input device. It will be appreciated that the I / O components 542 may include many other components that are not shown in FIG. 5. In various examples, the I / O components 542 may include output components 528 and input components 530. The output components 528 may include visual components (e.g., a display such as a plasma display panel (PDP), a light emitting diode (LED) display, a liquid crystal display (LCD), a projector, or a cathode ray tube (CRT)), acoustic components (e.g., speakers), haptic components (e.g., a vibratory motor, resistance mechanisms), other signal generators, and so forth. Theinput components 530 may include alphanumeric input components (e.g., a keyboard, a touch screen configured to receive alphanumeric input, a photo-optical keyboard, or other alphanumeric input components), point-based input components (e.g., a mouse, atouchpad, a trackball, a joystick, a motion sensor, or another pointing instrument), tactile input components (e.g., a physical button, a touch screen that provides location and / or force of touches or touch gestures, or other tactile input components), audio input components (e.g., a microphone), and the like.

[0091] In further examples, the I / O components 542 may include biometric components 532, motion components 534, environmental components 536, or position components 538, among a wide array of other components. For example, the biometric components 532 include components to detect expressions (e.g., hand expressions, facial expressions, vocal expressions, body gestures, or eye tracking), measure biosignals (e.g., blood pressure, heart rate, body temperature, perspiration, or brain waves), identify a person (e.g., voice identification, retinal identification, facial identification, fingerprint identification, or electroencephalogram-based identification), and the like. The motion components 534 include acceleration sensor components (e.g., accelerometer), gravitation sensor components, rotation sensor components (e.g., gyroscope), and so forth. The environmental components 536 include, for example, illumination sensor components (e.g., photometer), temperature sensor components (e.g., one or more thermometers that detect ambient temperature), humidity sensor components, pressure sensor components (e.g., barometer), acoustic sensor components (e.g., one or more microphones that detect background noise), proximity sensor components (e.g., infrared sensors that detect nearby objects), gas sensors (e.g., gas detection sensors to detection concentrations of hazardous gases for safety or to measure pollutants in the atmosphere), or other components that may provide indications, measurements, or signals corresponding to a surrounding physical environment. The position components538 include location sensor components (e.g., a GPS receiver component), altitude sensor components (e.g., altimeters or barometers that detect air pressure from which altitude may be derived), orientation sensor components (e.g., magnetometers), and the like.

[0092] Communication may be implemented using a wide variety of technologies. The I / O components 542 further include communication components 540 operable to couple the machine 500 to a network 520 or devices 522 via a coupling 524 and a coupling 526, respectively. For example, the communication components 540 may include a network interface component or another suitable device to interface with the network 520. In further examples, the communication components 540 may include wiredcommunication components, wireless communication components, cellular communication components, Near Field Communication (NFC) components, Bluetooth® components (e.g., Bluetooth® Low Energy), Wi-Fi® components, and other communication components to provide communication via other modalities. The devices 522 may be another machine or any of a wide variety of peripheral devices (e.g., a peripheral device coupled via a USB).

[0093] Moreover, the communication components 540 may detect identifiers or include components operable to detect identifiers. For example, the communication components 540 may include Radio Frequency Identification (RFID) tag reader components, NFC smart tag detection components, optical reader components (e.g., an optical sensor to detect one-dimensional bar codes such as Universal Product Code (UPC) bar code, multi-dimensional bar codes such as Quick Response (QR) code, Aztec code, Data Matrix, Dataglyph, MaxiCode, PDF417, Ultra Code, UCC RSS-2D bar code, and other optical codes), or acoustic detection components (e.g., microphones to identify tagged audio signals). In addition, a variety of information may be derived via the communication components 540, such as location via Internet Protocol (IP) geolocation, location via Wi-Fi® signal triangulation, location via detecting an NFC beacon signal that may indicate a particular location, and so forth.

[0094] The various memories (e.g., memory 504, main memory 512, static memory 514, and / or memory of the processors 502) and / or storage unit 516 may store one or more sets of instructions and data structures (e.g., software) embodying or used by any one or more of the methodologies or functions described herein. These instructions (e.g., the instructions 508), when executed by processors 502, cause various operations to implement the disclosed examples.

[0095] The instructions 508 may be transmitted or received over the network 520, using a transmission medium, via a network interface device (e.g., a network interface component included in the communication components 540) and using any one of a number of well-known transfer protocols (e.g., hypertext transfer protocol (HTTP)). Similarly, the instructions 508 may be transmitted or received using a transmission medium via the coupling 526 (e.g., a peer-to-peer coupling) to the devices 522.

[0096] Although examples have been described, it will be evident that various modifications and changes may be made to these examples without departing from the broader scope of the present disclosure. Accordingly, the specification and drawings areto be regarded in an illustrative rather than a restrictive sense. The accompanying drawings that form a part hereof, show by way of illustration, and not of limitation, specific examples in which the subject matter may be practiced. The examples illustrated are described in sufficient detail to enable those skilled in the art to practice the teachings disclosed herein. Other examples may be utilized and derived therefrom, such that structural and logical substitutions and changes may be made without departing from the scope of this disclosure. This Detailed Description, therefore, is not to be taken in a limiting sense, and the scope of various examples is defined only by the appended claims, along with the full range of equivalents to which such claims are entitled.

[0097] Such examples of the inventive subject matter may be referred to herein, individually and / or collectively, by the term "invention" merely for convenience and without intending to voluntarily limit the scope of this application to any single invention or inventive concept if more than one is in fact disclosed. Thus, although specific examples have been illustrated and described herein, it should be appreciated that any arrangement calculated to achieve the same purpose may be substituted for the specific examples shown. This disclosure is intended to cover any and all adaptations or variations of various examples. Combinations of the above examples, and other examples not specifically described herein, will be apparent to those of skill in the art upon reviewing the above description.

[0098] The Abstract of the Disclosure is provided to allow the reader to quickly ascertain the nature of the technical disclosure. It is submitted with the understanding that it will not be used to interpret or limit the scope or meaning of the claims. In addition, in the foregoing Detailed Description, it can be seen that various features are grouped together in a single example for the purpose of streamlining the disclosure. This method of disclosure is not to be interpreted as reflecting an intention that the claimed examples require more features than are expressly recited in each claim. Rather, as the following claims reflect, inventive subject matter lies in less than all features of a single disclosed example. Thus, the following claims are hereby incorporated into the Detailed Description, with each claim standing on its own as a separate example.

[0099] In view of the disclosure above, various examples are set forth below. It should be noted that one or more features of an example, taken in isolation or combination, should be considered within the disclosure of this application.

[0100] Example 1. A system comprising: one or more hardware processors; and at least one machine-storage medium for storing instructions that, when executed by the one or more hardware processors, cause the one or more hardware processors to perform operations comprising: receiving, by a controller, via a first communication interface, credential data from a physical component when the physical component is within a communication range of the first communication interface; and in response to receiving user confirmation to retransmit the credential data, transmitting, by the controller, via a second communication interface, the credential data to a physical access control (PAC) reader device, a communication range associated with the second communication interface being greater than a communication range associated with the first communication interface.

[0101] Example 2. The system of Example 1, wherein the first communication interface comprises a near-field communication (NFC) interface and the second communication interface comprises a Bluetooth Low Energy (BLE) interface.

[0102] Example 3. The system of any one of Examples 1-2, wherein the physical component comprises an access control card.

[0103] Example 4. The system of any one of Examples 1-3, wherein the controller is implemented on a mobile device.

[0104] Example 5. The system of Example 4, wherein the mobile device comprises a smartphone having the first communication interface and the second communication interface.

[0105] Example 6. The system of Example 5, wherein the operations further comprise: launching a booster application on the smartphone in response to detecting the physical component within range of the first communication interface.

[0106] Example 7. The system of Example 6, wherein the operations further comprise: presenting, via a user interface of the smartphone, a prompt, the prompt comprising an option that, when selected by a user, confirms transmission of the credential data to the PAC reader device.

[0107] Example 8. The system of any one of Examples 1-7, wherein the operations further comprise: automatically transmitting the credential data to the PAC reader device over the second communication interface without user intervention when the physical component is detected within range of the first communication interface.

[0108] Example 9. The system of any one of Examples 1-8, wherein the operations further comprise: establishing a communication channel with the PAC reader device via the second communication interface prior to transmitting the credential data; and receiving, by the controller, a request for credentials from the PAC reader device over the established communication channel, the credential data being transmitted to the PAC reader device in response to receiving the request.

[0109] Example 10. The system of any one of Examples 1-9, wherein the controller is implemented on a dedicated hardware booster device having the first communication interface and the second communication interface.

[0110] Example 11. The system of any one of Examples 1-10, wherein the system operates as a relay between the physical component and the PAC reader device without storing authentication credentials.

[0111] Example 12. The system of any one of Examples 1-11, wherein the PAC reader device comprises a hybrid reader configured to process both near-field communications (NFC) and Bluetooth Low Energy (BLE) communications.

[0112] Example 13. The system of any one of Examples 1-12, wherein the credential data comprises encrypted data packets.

[0113] Example 14. The system of any one of Examples 1-13, wherein the system comprises an application executing on a mobile device, the application configured to operate in a background mode to detect the physical component.

[0114] Example 15. The system of any one of Examples 1-14, wherein the first communication interface is configured to operate within a range of approximately one inch from the physical component.

[0115] Example 16. The system of Example 15, wherein the second communication interface is configured to operate within a range of multiple meters from the PAC reader device.

[0116] Example 17. The system of any one of Examples 1-16, wherein the physical component lacks circuitry configured to communicate via the second communication interface.

[0117] Example 18. The system of any one of Examples 1-17, wherein the operations further comprise: detecting one or more PAC reader devices within the communication range and displaying the one or more detected PAC reader devices to the user.

[0118] Example 19. The system of Example 18, wherein the operations further comprise: displaying additional information associated with each of the one or more detected PAC reader devices, wherein such additional information includes one or more of: a device identifier, MAC address, hardware version / type, manufacturer name, friendly name, device location, location data, relative proximity, relative signal strength.

[0119] Example 20. The system of Example 19, wherein the operations further comprise: determining whether any of the one or more detected PAC reader devices matches a previously configured PAC reader device with the system.

[0120] Example 21. The system of Example 20, wherein the operations further comprise: displaying indicators to indicate whether the one or more detected PAC reader devices has been previously configured with the system.

[0121] Example 22. The system of any one of Examples 18-21, wherein the operations further comprise: requesting the user select one of the one or more detected PAC reader devices to retransmit the credential data with.

[0122] Example 23. The system of any one of Examples 18-21, wherein the operations further comprise: preselecting one of the one or more detected PAC reader devices and requesting the user confirm the preselected one of the one or more detected PAC reader devices to retransmit the credential data with.

[0123] Example 24. A method comprising: receiving, by a controller, via a first communication interface, credential data from a physical component when the physical component is within a communication range of the first communication interface; and in response to receiving user confirmation to retransmit the credential data, transmitting, by the controller, via a second communication interface, the credential data to a physical access control (PAC) reader device, a communication range associated with the second communication interface being greater than a communication range associated with the first communication interface.

[0124] Example 25. The method of Example 24, further comprising: launching a booster application on the smartphone in response to detecting the physical component within range of the first communication interface 114

[0125] Example 26. The method of Example 25, further comprising: presenting, via a user interface of the smartphone, a prompt, the prompt comprising an option that, when selected by a user, confirms transmission of the credential data to the PAC reader device.

[0126] Example 27. The method of any of Examples 24-26, further comprising: automatically transmitting the credential data to the PAC reader device over the second communication interface without user intervention when the physical component is detected within range of the first communication interface.

[0127] Example 28. The method of any of Examples 24-27, further comprising: establishing a communication channel with the PAC reader device via the second communication interface prior to transmitting the credential data; and receiving, by the controller, a request for credentials from the PAC reader device over the established communication channel, the credential data being transmitted to the PAC reader device in response to receiving the request.

[0128] Example 29. The method of any of Examples 24-28, further comprising: detecting one or more PAC reader devices within the communication range and displaying the one or more detected PAC reader devices to the user.

[0129] Example 30. The method of Example 29, further comprising: displaying additional information associated with each of the one or more detected PAC reader devices, wherein such additional information includes one or more of: a device identifier, MAC address, hardware version / type, manufacturer name, friendly name, device location, location data, relative proximity, relative signal strength.

[0130] Example 31. The method of Example 30, further comprising: determining whether any of the one or more detected PAC reader devices matches a previously configured PAC reader device with the system.

[0131] Example 32. The method of Example 31, further comprising: displaying indicators to indicate whether the one or more detected PAC reader devices has been previously configured with the system.

[0132] Example 33. The method any of Examples 29-32, further comprise: requesting the user select one of the one or more detected PAC reader devices to retransmit the credential data with.

[0133] Example 34. The method of any one of Examples 29-32, further comprising: preselecting one of the one or more detected PAC reader devices and requesting the user confirm the preselected one of the one or more detected PAC reader devices to retransmit the credential data with.

[0134] Example 35. A machine-storage medium for storing instructions that, when executed by one or more hardware processors, cause the one or more hardware processors to perform operations comprising: receiving, by a controller, via a first communication interface, credential data from a physical component when the physical component is within a communication range of the first communication interface; and in response to receiving the credential data, transmitting, by the controller, via a second communication interface, the credential data to a physical access control (PAC) reader device, a communication range associated with the second communication interface being greater than a communication range associated with the first communication interface.

[0135] Example 36. The machine-storage medium of Example 35, wherein the first communication interface comprises a near-field communication (NFC) interface and the second communication interface comprises a Bluetooth Low Energy (BLE) interface.

Claims

What is claimed is:

1. A system comprising:one or more hardware processors; andat least one machine-storage medium for storing instructions that, when executed by the one or more hardware processors, cause the one or more hardware processors to perform operations comprising:receiving, by a controller, via a first communication interface, credential data from a physical component when the physical component is within a communication range of the first communication interface; andin response to receiving user confirmation to retransmit the credential data, transmitting, by the controller, via a second communication interface, the credential data to a physical access control (PAC) reader device, a communication range associated with the second communication interface being greater than a communication range associated with the first communication interface.

2. The system of claim 1, wherein the first communication interface comprises a near-field communication (NFC) interface and the second communication interface comprises a Bluetooth Low Energy (BLE) interface.

3. The system of claim 1, wherein the physical component comprises an access control card.

4. The system of claim 1, wherein the controller is implemented on a mobile device.

5. The system of claim 4, wherein the mobile device comprises a smartphone having the first communication interface and the second communication interface.

6. The system of claim 5, wherein the operations further comprise:launching a booster application on the smartphone in response to detecting the physical component within range of the first communication interface.

7. The system of claim 6, wherein the operations further comprise:presenting, via a user interface of the smartphone, a prompt, the prompt comprising an option that, when selected by a user, confirms transmission of the credential data to the PAC reader device.

8. The system of claim 6, wherein the operations further comprise:automatically transmitting the credential data to the PAC reader device over the second communication interface without user intervention when the physical component is detected within range of the first communication interface.

9. The system of claim 6, wherein the operations further comprise:establishing a communication channel with the PAC reader device via the second communication interface prior to transmitting the credential data; andreceiving, by the controller, a request for credentials from the PAC reader device over the established communication channel, the credential data being transmitted to the PAC reader device in response to receiving the request.

10. The system of claim 1, wherein the controller is implemented on a dedicated hardware booster device having the first communication interface and the second communication interface.

11. The system of claim 1, wherein the system operates as a relay between the physical component and the PAC reader device without storing authentication credentials.

12. The system of claim 1, wherein the PAC reader device comprises a hybrid reader configured to process both near-field communications (NFC) and Bluetooth Low Energy (BLE) communications.

13. The system of claim 1, wherein the credential data comprises encrypted data packets.

14. The system of claim 1, wherein the system comprises an application executing on a mobile device, the application configured to operate in a background mode to detect the physical component.

15. The system of claim 1, wherein the first communication interface is configured to operate within a range of approximately one inch from the physical component.

16. The system of claim 15, wherein the second communication interface is configured to operate within a range of multiple meters from the PAC reader device.

17. The system of claim 1, wherein the physical component lacks circuitry configured to communicate via the second communication interface.

18. A method comprising:receiving, by a controller, via a first communication interface, credential data from a physical component when the physical component is within a communication range of the first communication interface; andin response to receiving user confirmation to retransmit the credential data, transmitting, by the controller, via a second communication interface, the credential data to a physical access control (PAC) reader device, a communication range associated with the second communication interface being greater than a communication range associated with the first communication interface.

19. A machine-storage medium for storing instructions that, when executed by one or more hardware processors, cause the one or more hardware processors to perform operations comprising:receiving, by a controller, via a first communication interface, credential data from a physical component when the physical component is within a communication range of the first communication interface; andin response to receiving user confirmation to retransmit the credential data, transmitting, by the controller, via a second communication interface, the credential data to a physical access control (PAC) reader device, a communication range associated with the second communication interface being greater than a communication range associated with the first communication interface.

20. The machine-storage medium of claim 19, wherein the first communication interface comprises a near-field communication (NFC) interface and the second communication interface comprises a Bluetooth Low Energy (BLE) interface.