Reader detection and background service activation method for mobile access

WO2026201732A1PCT designated stage Publication Date: 2026-10-01ASSA ABLOY AB
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2026/057650
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2025-03-25
Filing Date
2026-03-18
Publication Date
2026-10-01

Smart Images

  • Figure EP2026057650_01102026_PF_FP_ABST
    Figure EP2026057650_01102026_PF_FP_ABST
Patent Text Reader

Abstract

A method of operating a credential device for authentication to a physical access control system (PACS) is described. The method includes detecting, by the credential device, a reader device of the PACS using a magnetometer of the credential device; detecting, using an inertial measurement unit (IMU) of the credential device, intent of a user of the credential device to access a physical access portal of the PACS; and activating, in response to the detection of intent, a background service of the credential device for authentication of the credential device to the reader device.
Need to check novelty before this filing date? Find Prior Art

Description

ENHANCED READER DETECTION AND BACKGROUND SERVICE ACTIVATION METHOD FOR MOBILE ACCESSPRIORITY APPLICATION(S)

[0001] This application claims priority to Indian Provisional Patent Application No.202511028116, filed on March 25, 2025, the disclosure of which is incorporated by reference herein in its entirety.TECHNICAL FIELD

[0002] Embodiments illustrated and described herein generally relate to system architectures for physical access control systems.BACKGROUND

[0003] Seamless access control refers to when physical access is granted to an authorized user through a controlled portal without requiring intrusive actions of the user such as entering or swiping an access card at a card reader or entering a personal identification number (PIN) or password. A Physical Access Control System (PACS) is a type of system that can provide seamless access. A PACS authenticates and authorizes a person to pass through a physical access point such as a secured door. It is desirable for the devices that control the access to the physical portal to be able to correctly determine whether a credential device holder intends seamless access to the controlled physical access portal or if the credential device holder is merely passing by the controlled physical access portal.BRIEF DESCRIPTION OF THE DRAWINGS

[0004] FIG. 1 is an illustration of an example of a basic Physical Access Control System (PACS) structure.

[0005] FIG. 2 is a flow diagram of an example of a method of a credential device for authentication to a PACS.

[0006] FIG. 3 is an illustration of a user with a credential device moving toward a reader device.

[0007] FIG. 4 is an illustration of a user orienting a credential device to interact with a reader device.

[0008] FIG. 5 is a flow diagram of an example of two different approaches for physical access to a controlled physical access portal.

[0009] FIG. 6 is a block diagram schematic of portions of a device for supporting the device architectures described and illustrated herein.DETAILED DESCRIPTION

[0010] FIG. 1 is an illustration of an example of a basic PACS structure. The example PACS may be useful for an office application to control access through a door. The Access Credential is a data object, a piece of knowledge (e.g., PIN, password, etc.), or a facet of the person’s physical being (e.g., face, fingerprint, etc.) that provides proof of the person’s identity. The Credential Device 104 stores the Access Credential when the Access Credential is a data object. The Credential Device 104 may be a smart card, smartphone, or tablet computer. The Reader Device 102 retrieves and authenticates the Access Credential when a Credential Device 104 is used and sends the Access Credential to the Access Controller 106. The Access Controller 106 compares the Access Credential to an Access Control list and grants or denies access based on the comparison, such as by controlling an automatic lock on the door for example. The functionality of an Access Controller 106 may be included in the Reader Device 102. These Reader Devices can be referred to as offline readers or standalone readers. If the unlocking mechanism is included as well, a device is referred to as smart door lock which is more typically used in residential applications.

[0011] An alternative approach is “match on card” where the Credential Device 104 (whether a smartphone or smartcard) checks the user’s identity and stores a biometric, PIN, or password stored in a secure storage element of the Credential Device 104. The Credential Device 104 may also store an Access Control List in the secure storage element. The Credential Device 104 checks if the user has authorization to enter. If there is a match and the user is authorized, the Credential Device 104 sends an authorization signal to the Reader Device or the Access Controller to grant access. If there is not a match and the user is not authorized, the Credential Device 104 may do nothing, or may display a notice that the user is not authorized.

[0012] For physical access applications, an electronic device needs to authenticate a person, which can require different methodologies than those used for electronic devices authenticating each other. Authentication methods for persons are typically split into three broad categories: “Something you know,” “Something you have,” or “Something you are.”For a PACS, “Proof of Presence” can be as important as the authentication information when granting access through a particular physical access portal at a given moment in time.

[0013] To conduct a seamless interaction at a controlled physical access portal, it is also important to be able to understand a person’s Intent. A person holding a valid credential with proper privileges to unlock a door may be walking by near the door but not intending to pass through. In such cases, the door should not unlock, which would have a variety of negative consequences. These negative consequences include creating a security vulnerability, wasting energy, and creating anomalous entries in security logs. For this reason, a well-functioning intent detection is important. The seamless access should also be prompt without an undue amount of user waiting time for a positive user experience.

[0014] The Credential Device 104 can be used for proof of presence and determination of intent to access the physical access portal. The Credential Device 104 may include an Inertial Measurement Unit (IMU 116). IMUs include motion sensors such as 3-axis accelerometers and 3-axis gyroscopes for example. Smartphones and other mobile devices (e.g., tablet computers, smart watches, and other wearable devices) include IMUs and can be used as Credential Devices. IMUs can be used for motion tracking and gesture recognition, screen orientation detection, navigation and location services, image stabilization for cameras, and step counting and fitness tracking. The Credential Device 104 may include a magnetometer in the IMU or the magnetometer may be separate from the IMU 116. The magnetometer can be used to determine direction. The Credential Device 104 also includes processing circuitry, such as one or more microprocessors for example. The processing circuitry executes instructions associated with a client resource access application (or App) to perform the functions described for the processing circuitry. The signals produced by the magnetometer and IMU of the Credential Device 104 when approaching a Reader Device 102 may be processed for a seamless estimation of presence of a person at a physical access portal and intent of a person to pass through the portal.

[0015] For instance, there may be time-changing magnet fluctuations associated with the Reader Device 102. The magnetometer of the Credential Device 104 may produce one or more signals based on the magnetic fluctuations. The processing circuitry of the Credential Device 104 processes the signals to detect the Reader Device 102. The motion sensors of the IMU 116 may produce one or more signals associated with movement of the user. The processing circuitry may detect intent of a user of the Credential Device 104 to interact with the Reader Device 102 (e.g., to gain access through the physical access portal) using the signals from the IMU 116.

[0016] FIG. 2 is a flow diagram of an example of a method 200 of operating a Credential Device 104 for authentication to a PACS. The method 200 provides seamless access to the space controlled by the PACS. In the example PACS of FIG. 1, the Reader Device 102 (or Reader & Access Controller Device) controls access to the physical access portal (e.g., a door) used to enter the controlled space. The Reader Device 102 can include processing circuitry 110 and a physical layer 108 for wireless communication with the Credential Device 104.

[0017] At block 205 of FIG. 2, the Credential Device 104 detects presence of the Reader Device 102 using the magnetometer of the Credential Device 104. The magnetic fluctuations of the Reader Device 102 may be unique from other devices encountered by the user and can be used as a magnetic signature or fingerprint. The uniqueness of the magnetic fluctuations of the Reader Device 102 may result in the magnetometer producing unique signals when the Credential Device 104 is in the proximity of the Reader Device 102. The processing circuitry of the Credential Device 104 detects presence of the Reader Device 102 by processing the signal or signals produced by the magnetometer.

[0018] At block 210, the Credential Device 104 determines that the user intends to interact with the Reader Device 102 to gain access to the physical access portal controlled by the PACS. The processing circuitry of the Credential Device 104 determines the intent of the user using signals produced by the IMU 116. FIG. 3 is an illustration of a user moving toward a Reader Device 102 holding a Credential Device 104. The IMU 116 may include an accelerometer and a gyroscope. The accelerometer and the gyroscope produce signals based on the movement of the user and the orientation of the Credential Device 104. Using the output of the accelerometer and gyroscope, the processing circuitry of the Credential Device 104 determines that the Credential Device 104 is moving toward the Reader Devicel02 and is in a predetermined orientation indicative of interaction with the Reader Device 102. The processing circuitry of the Credential Device 104 detects intent of the user to access the physical access portal based on the detected user movement and device orientation. In variations, the accelerometer may produce one or more signals when the user changes speed (e.g., changes to walking slower). The Credential Device 104 may detect intent of the user to access the physical access portal when the user slows down in the proximity of the Reader Device 102.

[0019] In some examples, the Credential Device 104 determines the intent of the user to access the physical access portal using a detected change in orientation of the Credential Device 104. FIG. 4 is an illustration of a user orienting the Credential Device 104 to interactwith a Reader Device 102. The gyroscope of the IMU 116 may produce one or more signals when the user changes the orientation from looking at the Credential Device 104 to changing the orientation to interact with the Reader Device 102. The processing circuitry of the Credential Device 104 detects intent of the user to access the physical access portal based on one or both of the detected movement toward the Reader Device 102 and change in orientation.

[0020] The gyroscope of the IMU may produce signals related to angular motion of the user. Angular motion toward the access portal may indicate that the person intends to pass by the access portal without entering. Using the combination of change in distance and angular motion may provide better accuracy in the determinations of intent to enter the portal by the processing circuitry of the Credential Device 104.

[0021] The Credential Device 104 may also determine that the user intends to pass by the Reader Device 102 using the signals output from the IMU 116. For example, the Credential Device 104 may detect the Reader Device 102 but determines that the user intends to pass by the physical access portal if there is no detected movement toward the Reader Device 102 or if there is no turning of the Credential Device 104 toward the Reader Device. In another example, the Credential Device 104 may determine that user intends to pass by the physical access portal when detecting the Reader Device 102 but not detecting a change in speed of movement of the user. Additionally, angular motion away from the access portal may indicate that the person intends to pass by the access portal without entering.

[0022] Returning to FIG. 2 at block 215, the Credential Device 104 activates a background service in response to detecting the intent of the user to access the physical access portal. The background service is used by the Credential Device 104 to communicate information with the Reader Device 102, and the background service may be activated in anticipation of communication with the Reader Device 102. The communication between the Credential Device 104 and the Reader Device 102 may use, among other things, Near Field Communication (NFC) signaling or Bluetooth® Low Energy (BLE) signaling.

[0023] At block 220, the Credential Device 104 authenticates to the Reader Device 102 by communicating access credential information to the Reader Device 102 when the background service is activated. The access credential information may be stored in a secure memory storage element of the Credential Device 104. The secure memory storage element may be a hardware memory area separate from other memory of the Credential Device 104.

[0024] The access credential information is communicated according to an authentication protocol. The authentication may be initiated by the Credential Device 104 orthe Reader Device 102. For instance, the Credential Device 104 may send a request for authentication to the Reader Device 102 when the background service is activated in response to the detection of the Reader Device 102 by the Credential Device 104. Alternatively, the Reader Device 102 may send a request for authentication information to the Credential Device 104. The Reader Device 102 may detect the Credential Device 104 using NFC scanning or BLE scanning when the Credential Device 104 activates the background service.

[0025] The processing circuitry 110 of the Reader Device 102 establishes a communication channel 114 with the Credential Device 104 and the access credential information is sent using the communication channel 114. The communication channel 114 may be a secure communication channel. If the access credential information is valid and is authenticated by the Reader Device 102, the user is granted access and the physical access portal is opened by the Access Controller 106. If the access credential information is not authenticated, the physical access portal is not opened.

[0026] The techniques of using the Credential Device 104 IMU to detect presence and intent of the user to gain entry through the physical access portal provide a seamless access that is quick and accurate. FIG. 5 is a flow diagram of an example of two different techniques for physical access to a controlled physical access portal. Both techniques begin at block 502 with the user approaching the physical access portal (e.g., the door in FIG. 1). The technique on the left in the diagram uses a location service to detect presence of the user. At block 505, if the location service of the Credential Device 104 is enabled, it is determined at block 510 if a reader beacon signal broadcast by the Reader Device 102 is detected by the Credential Device 104. If the reader beacon is detected, at block 515 an App is awakened in the Credential Device 104. At block 520, waking up the App causes the Credential Device 104 to perform the scanning for the Reader Device 102. Returning to block 505, if the location service of the Credential Device 104 is not enabled, at block 525 the user manually opens the App on the credential device to awaken the App, and at 520 the scanning for the Reader Device 102 is performed. At block 530, the user enters if the Credential Device 104 is authenticated.

[0027] The technique on the right in the diagram is a portion of the example in FIG.2. At block 205, the Credential Device 104 detects presence and intent of the user using the IMU of the Credential Device 104 as discussed previously herein regarding FIG. 2. At block 215, the Credential Device 104 activates the background service. The scanning is performed at block 520, and at block 530, the user enters if the Credential Device 104 is authenticated.

[0028] Because the background service is activated sooner in anticipation of communication with the Reader Device 102, the IMU-based approach can be quicker than the location service-based approach. Additionally, the IMU-based approach can be more accurate than the location service-based approach. If the location service-based approach uses Bluetooth®, the Bluetooth® signaling may provide a greater range, but it can be challenging to precisely identify the correct reader device in environments with multiple Bluetooth®-enabled devices within range of the credential device. This can result in delayed interactions and unintended connections to the credential device. The IMU-based approach uses the multiple sensors available to detect proximity and user intent, ensuring the app wakes up without requiring location permissions. This results in higher precision in identifying the nearest reader device and reduces errors and delays in user authentication.

[0029] FIG. 6 is a block diagram schematic of various example components of a device 600 (e.g., a Credential Device) for supporting the device architectures described and illustrated herein. The device 600 of FIG. 6 could be, for example, a Credential Device that stores and sends credential information of authority, status, rights, and / or entitlement to privileges for the holder of the device. At a basic level, device 600 can include an interface (e.g., one or more antennas and Integrated Circuit (IC) chip(s)), which permits the device to exchange data with another device, such as a reader device. One example of credential device is a smartphone that has data stored thereon allowing a holder of the credential device to access a secure area or asset protected by a reader device.

[0030] With reference specifically to FIG. 6, additional examples of a device 600 for supporting the device architecture described and illustrated herein may generally include one or more of a memory 614, a processor 612, one or more antennas 626, a communication port or communication module 630, a network interface device 632, a user interface 634, and inertial measurement unit (IMU) 616, and a power source 636 or power supply.

[0031] Memory 614 can be used in connection with the execution of application programming or instructions by processing circuitry, and for the temporary or long-term storage of program instructions 638 of a resource access application. Memory 624 can be used to store access credential information 640, credential authorization data, or access control data or instructions, as well as any data, data structures, and / or computer-executable instructions needed or desired to support the above-described device architecture. For example, memory 614 can contain executable instructions 638 that are used by a processor 612 of the processing circuitry to run other components of device 600, to perform any of the functions or operations described herein, such as the method of FIG. 2 for example. Memory614 can comprise a computer readable medium that can be any medium that can contain, store, communicate, or transport data, program code, or instructions for use by or in connection with device 600. The computer readable medium can be, for example but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device. More specific examples of suitable computer readable medium include, but are not limited to, an electrical connection having one or more wires or a tangible storage medium such as a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), Dynamic RAM (DRAM), any solid-state storage device, in general, a compact disc read-only memory (CD-ROM), or other optical or magnetic storage device. Computer-readable media includes, but is not to be confused with, computer-readable storage medium, which is intended to cover all physical, non-transitory, or similar embodiments of computer-readable media.

[0032] Processor 612 can correspond to one or more computer processing devices or resources. For instance, processor 612 can be provided as silicon, as a Field Programmable Gate Array (FPGA), an Application-Specific Integrated Circuit (ASIC), any other type of Integrated Circuit (IC) chip, a collection of IC chips, or the like. As a more specific example, processor 612 can be provided as a microprocessor, Central Processing Unit (CPU), or plurality of microprocessors or CPUs that are configured to execute instructions sets stored in an internal memory of the processor 612 and / or memory 614.

[0033] Antenna 626 can correspond to one or multiple antennas and can be configured to provide for wireless communications between device 600 and another device. Antenna(s) 626 can be coupled to one or more physical (PHY) layers 622 to operate using one or more wireless communication protocols and operating frequencies including, but not limited to, the IEEE 802.15.1, Bluetooth, Bluetooth Low Energy (BLE), near field communications (NFC), ZigBee, GSM, CDMA, Wi-Fi, RF, UWB, and the like. In an example, antenna 626 may include one or more antennas coupled to one or more physical layers 622 to operate using UWB for in band activity / communi cation and Bluetooth (e.g., BLE) for out-of-band (OOB) activity / communication. However, any RFID or personal area network (PAN) technologies, such as the IEEE 502.15.1, near field communications (NFC), ZigBee, GSM, CDMA, Wi-Fi, etc., may alternatively or additionally be used for the OOB activity / communication described herein.

[0034] Device 600 may additionally include a communication module 630 and / or network interface device 632. Communication module 630 can be configured tocommunicate according to any suitable communications protocol with one or more different systems or devices either remote or local to device 600. Network interface device 632 includes hardware to facilitate communications with other devices over a communication network utilizing any one of a number of transfer protocols (e.g., frame relay, internet protocol (IP), transmission control protocol (TCP), user datagram protocol (UDP), hypertext transfer protocol (HTTP), etc.). Example communication networks can include a local area network (LAN), a wide area network (WAN), a packet data network (e.g., the Internet), mobile telephone networks (e.g., cellular networks), Plain Old Telephone (POTS) networks, wireless data networks (e.g., IEEE 802.11 family of standards known as Wi-Fi, IEEE 802.16 family of standards known as WiMax), IEEE 802.15.4 family of standards, and peer-to-peer (P2P) networks, among others. In some examples, network interface device 632 can include an Ethernet port or other physical jack, a Wi-Fi card, a Network Interface Card (NIC), a cellular interface (e.g., antenna, filters, and associated circuitry), or the like. In some examples, network interface device 632 can include a plurality of antennas to wirelessly communicate using at least one of single-input multiple-output (SIMO), multiple-input multiple-output (MIMO), or multiple-input single-output (MISO) techniques. In some example embodiments, one or more of the antenna 626, communication module 630, and / or network interface device 632 or subcomponents thereof, may be integrated as a single module or device, function or operate as if they were a single module or device, or may comprise of elements that are shared between them.

[0035] IMU 616 can include a magnetometer, an accelerometer, and a gyroscope. User interface 634 can include one or more input devices and / or display devices. Examples of suitable user input devices that can be included in user interface 634 include, without limitation, one or more buttons, a touch-sensitive surface, a camera, a microphone, a speaker, etc. Power source 636 can be any suitable internal power source, such as a battery, capacitive power source or similar type of charge-storage device, etc., and / or can include one or more power conversion circuits suitable to convert external power into suitable power (e.g., conversion of externally supplied AC power into DC power) for components of the device 600. Device 600 can also include one or more interlinks or buses 644 operable to transmit communications between the various hardware components of the device. A system bus 644 can be any of several types of commercially available bus structures or bus architectures.ADDITIONAL DISCLOSURE AND EXAMPLES

[0036] A first Example (Example 1) includes subject matter (such as a method of operating a credential device for authentication to a physical access control system (PACS) comprising detecting, by the credential device, a reader device of the PACS using a magnetometer of the credential device, detecting, using an inertial measurement unit (IMU) of the credential device, intent of a user of the credential device to access a physical access portal of the PACS, and activating, in response to the detection of intent, a background service of the credential device for authentication of the credential device to the reader device.

[0037] In Example 2, the subject matter of Example 1 optionally includes detecting intent of the user to access the PACS using one or more signals output from an accelerometer of the IMU and a gyroscope of the IMU.

[0038] In Example 3, the subject matter of one or both of Example 1 and 2 optionally includes detecting a change in orientation of the credential device by the user indicating intent to access the physical access portal.

[0039] In Example 4, the subject matter of one or any combination of Examples 1-3 optionally includes the IMU indicating that the credential device is moving toward the reader device and is in a predetermined orientation indicative of interaction with the reader device.

[0040] In Example 5, the subject matter of one or any combination of Examples 1-4 optionally includes communicating access credential information by the credential device to the reader device when the background service is activated in response to detecting the intent of the user to access the physical access portal.

[0041] In Example 6, the subject matter of one or any combination of Examples 1-5 optionally includes activating, in response to the detection of intent, wireless communication of the credential device that uses one of Bluetooth Low Energy (BLE) and Near Field Communication (NFC).

[0042] In Example 7, the subject matter of Example 6 optionally includes communicating wirelessly with the reader device according to an authentication protocol in response to the detection of intent by the credential device.

[0043] Example 8 includes subject matter (such as a credential device) or can optionally be combined with one or any combination of Examples 1-7 to include such subject matter, comprising a magnetometer, an IMU, a wireless communication interface, and processing circuitry. The processing circuitry is configured to detect a reader device of a PACS using a signal produced by the magnetometer, detect intent of a user of the credentialdevice to interact with the reader device, wherein the intent is detected using one or more signals produced by the IMU, and activate a background communication service for communication with the reader device in response to the detected intent to interact with the reader device.

[0044] In Example 9, the subject matter of Example 8 optionally includes an IMU including an accelerometer and a gyroscope, and processing circuitry configured to detect intent of the user interact with the reader device using one or more signals produced by the accelerometer and gyroscope.

[0045] In Example 10, the subject matter of Example 9 optionally includes processing circuitry configured to detect movement of the credential device toward the reader device using one or more signals produced by the accelerometer, detect a change in orientation of the credential device using one or more signals produced by the gyroscope, and activate the background communication service in response to the detected movement of the credential and change in orientation of the credential device.

[0046] In Example 11, the subject matter of one or both of Examples 9 and 10 optionally includes processing circuitry configured to detect movement of the credential device toward the reader device using one or more signals produced by the accelerometer, detect that the credential device is in a predetermined orientation to the reader device using one or more signals produced by the gyroscope, and activate the background communication service in response to the detected movement of the credential and change in orientation of the credential device.

[0047] In Example 12, the subject matter of one or any combination of Examples 8- 11 optionally includes a secure memory storage element to store access credential information and processing circuitry configured to communicate the access credential information to the reader device when the background service is activated in response to the detected intent to interact with the reader device.

[0048] In Example 13, the subject matter of one or any combination of Examples 8- 12 optionally includes processing circuitry configured to activate one of one of Bluetooth Low Energy (BLE) scanning and Near Field Communication (NFC) scanning for communication with the reader device when the intent to interact with the reader device is detected.

[0049] In Example 14, the subject matter of one or any combination of Examples 8- 13 optionally includes processing circuitry configured to communicate with the reader deviceusing the background service according to an authentication protocol when the intent to interact with the reader device is detected.

[0050] Example 15 includes subject matter (or can optionally be combined with one or any combination of Examples 1-14 to include such subject matter) such as a computer readable storage medium storing a resource access application. The resource application includes instructions performable by processing circuitry of a credential device to cause the credential device to detect a reader device of a PACS using a signal produced by a magnetometer of the credential device; detect intent of a user of the credential device to interact with the reader device, wherein the intent is detected using one or more signals produced by IMU of the credential device; and activate a background service of the credential device for communication with the reader device when the intent of the user to interact with the reader device is detected.

[0051] In Example 16, the subject matter of Example 15 optionally includes a resource access application including instructions to cause the credential device to detect the intent of the user to interact with the reader device using one or more signals output from an accelerometer of the IMU and a gyroscope of the IMU.

[0052] In Example 17, the subject matter of one or both of Examples 15 and 16 optionally includes a resource access application including instructions to cause the credential device to detect a change in orientation of the credential device by the user indicating an intent of the user to access a physical access portal of the PACS.

[0053] In Example 18, the subject matter of one or any combination of Examples 15- 17 optionally includes a resource access application including instructions to cause the credential device to detect movement of the credential device toward the reader device, detect a predetermined orientation of the credential device to the reader device, and detect the intent of the user to interact with the reader device based on the movement of the credential device and orientation of the credential device.

[0054] In Example 19, the subject matter of one or any combination of Examples 15- 18 optionally includes a resource access application including instructions to cause the credential device to communicate access credential information by the credential device to the reader device when the background service is activated in response to detecting the intent of the user to interact with the reader device.

[0055] In Example 20, the subject matter of one or any combination of Examples 15- 19 optionally includes a resource access application including instructions to cause the credential device to activate one of one of Bluetooth Low Energy (BLE) scanning and NearField Communication (NFC) scanning for communication with the reader device when the intent to of the user interact with the reader device is detected.

[0056] These non-limiting Examples can be combined in any permutation or combination. The above detailed description includes references to the accompanying drawings, which form a part of the detailed description. The drawings show, by way of illustration, specific embodiments in which the invention can be practiced. These embodiments are also referred to herein as “examples.” All publications, patents, and patent documents referred to in this document are incorporated by reference herein in their entirety, as though individually incorporated by reference. In the event of inconsistent usages between this document and those documents so incorporated by reference, the usage in the incorporated reference(s) should be considered supplementary to that of this document; for irreconcilable inconsistencies, the usage in this document controls.

[0057] In this document, the terms “a” or “an” are used, as is common in patent documents, to include one or more than one, independent of any other instances or usages of “at least one” or “one or more.” In this document, the term “or” is used to refer to a nonexclusive or, such that “A or B” includes “A but not B,” “B but not A,” and “A and B,” unless otherwise indicated. In this document, the terms “including” and “in which” are used as the plain-English equivalents of the respective terms “comprising” and “wherein.” Also, in the following claims, the terms “including” and “comprising” are open-ended, that is, a system, device, article, composition, formulation, or process that includes elements in addition to those listed after such a term in a claim are still deemed to fall within the scope of that claim. Moreover, in the following claims, the terms “first,” “second,” and “third,” etc. are used merely as labels, and are not intended to impose numerical requirements on their objects.

[0058] The above description is intended to be illustrative, and not restrictive. For example, the above-described examples (or one or more aspects thereof) may be used in combination with each other. Other embodiments can be used, such as by one of ordinary skill in the art upon reviewing the above description. The Abstract is provided to allow the reader to quickly ascertain the nature of the technical disclosure. It is submitted with the understanding that it will not be used to interpret or limit the scope or meaning of the claims. In the above Detailed Description, various features may be grouped together to streamline the disclosure. This should not be interpreted as intending that an unclaimed disclosed feature is essential to any claim. Rather, the subject matter may lie in less than all features of a particular disclosed embodiment. Thus, the following claims are hereby incorporated into theDetailed Description, with each claim standing on its own as a separate embodiment, and it is contemplated that such embodiments can be combined with each other in various combinations or permutations. The scope should be determined with reference to the appended claims, along with the full scope of equivalents to which such claims are entitled.

Claims

WHAT IS CLAIMED IS:

1. A method of operating a credential device for authentication to a physical access control system (PACS), the method comprising:detecting, by the credential device, a reader device of the PACS using a magnetometer of the credential device;detecting, using an inertial measurement unit (IMU) of the credential device, intent of a user of the credential device to access a physical access portal of the PACS; and activating, in response to the detection of intent, a background service of the credential device for authentication of the credential device to the reader device.

2. The method of claim 1, wherein the detecting intent of the user includes detecting intent of the user to access the PACS using one or more signals output from an accelerometer of the IMU and a gyroscope of the IMU.

3. The method of claim 1, wherein the detecting intent of the user includes detecting a change in orientation of the credential device by the user indicating intent to access the physical access portal.

4. The method of claim 1, wherein the detecting intent of the user includes the IMU indicating that the credential device is moving toward the reader device and is in a predetermined orientation indicative of interaction with the reader device.

5. The method of claim 1, including communicating access credential information by the credential device to the reader device when the background service is activated in response to detecting the intent of the user to access the physical access portal.

6. The method of any one of claims 1-5, wherein the activating the background service includes activating, in response to the detection of intent, wireless communication of the credential device that uses one of Bluetooth Low Energy (BLE) and Near Field Communication (NFC).

7. The method of claim 6, including communicating wirelessly with the reader device according to an authentication protocol in response to the detection of intent by the credential device.

8. A credential device, comprising:a magnetometer;an inertial measurement unit (IMU);a wireless communication interface; andprocessing circuitry configured to:detect a reader device of a Physical Access Control System (PACS) using a signal produced by the magnetometer;detect intent of a user of the credential device to interact with the reader device, wherein the intent is detected using one or more signals produced by the IMU; and activate a background communication service for communication with the reader device in response to the detected intent to interact with the reader device.

9. The credential device of claim 8, wherein the IMU includes an accelerometer and a gyroscope, and the processing circuitry is configured to detect intent of the user interact with the reader device using one or more signals produced by the accelerometer and gyroscope.

10. The credential device of claim 9, wherein the processing circuitry is configured to: detect movement of the credential device toward the reader device using one or more signals produced by the accelerometer;detect a change in orientation of the credential device using one or more signals produced by the gyroscope; andactivate the background communication service in response to the detected movement of the credential and change in orientation of the credential device.

11. The credential device of claim 9, wherein the processing circuitry is configured to: detect movement of the credential device toward the reader device using one or more signals produced by the accelerometer;detect that the credential device is in a predetermined orientation to the reader device using one or more signals produced by the gyroscope; andactivate the background communication service in response to the detected movement of the credential and detected orientation of the credential device.

12. The credential device of claim 8, including:a secure memory storage element to store access credential information; and wherein the processing circuitry is configured to communicate the access credential information to the reader device when the background service is activated in response to the detected intent to interact with the reader device.

13. The credential device of claim 8, wherein the processing circuitry is configured to activate one of one of Bluetooth Low Energy (BLE) scanning and Near Field Communication (NFC) scanning for communication with the reader device when the intent to interact with the reader device is detected.

14. The credential device of any one of claims 8-13, wherein the processing circuitry is configured to communicate with the reader device using the background service according to an authentication protocol when the intent to interact with the reader device is detected.

15. A computer readable storage medium storing a resource access application, the resource access application including instructions performable by processing circuitry of a credential device to cause the credential device to:detect a reader device of a Physical Access Control System (PACS) using a signal produced by a magnetometer of the credential device;detect intent of a user of the credential device to interact with the reader device, wherein the intent is detected using one or more signals produced by an inertial measurement unit (IMU) of the credential device; andactivate a background service of the credential device for communication with the reader device when the intent of the user to interact with the reader device is detected.

16. The computer readable storage medium of claim 15, wherein the resource access application includes instructions to cause the credential device to detect the intent of the user to interact with the reader device using one or more signals output from an accelerometer of the IMU and a gyroscope of the IMU.

17. The computer readable storage medium of claim 15, wherein the resource access application includes instructions to cause the credential device to detect a change in orientation of the credential device by the user indicating an intent of the user to access a physical access portal of the PACS.

18. The computer readable storage medium of claim 15, wherein the resource access application includes instructions to cause the credential device to detect movement of the credential device toward the reader device, detect a predetermined orientation of the credential device to the reader device, and detect the intent of the user to interact with the reader device based on the detected movement of the credential device and detected orientation of the credential device.

19. The computer readable storage medium of claim 15, wherein the resource access application includes instructions to cause the credential device to communicate access credential information by the credential device to the reader device when the background service is activated in response to detecting the intent of the user to interact with the reader device.

20. The computer readable storage medium of any one of claims 15-19, wherein the resource access application includes instructions to cause the credential device to activate one of one of Bluetooth Low Energy (BLE) scanning and Near Field Communication (NFC) scanning for communication with the reader device when the intent to of the user interact with the reader device is detected.