EP3062294B1 - Procédé et dispositifs permettant l'amélioration d'un système de commande d'accès existant - Google Patents

Procédé et dispositifs permettant l'amélioration d'un système de commande d'accès existant Download PDF

Info

Publication number
EP3062294B1
EP3062294B1 EP15156996.9A EP15156996A EP3062294B1 EP 3062294 B1 EP3062294 B1 EP 3062294B1 EP 15156996 A EP15156996 A EP 15156996A EP 3062294 B1 EP3062294 B1 EP 3062294B1
Authority
EP
European Patent Office
Prior art keywords
access
handheld device
unit
mobile handheld
interception unit
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Active
Application number
EP15156996.9A
Other languages
German (de)
English (en)
Other versions
EP3062294A1 (fr
Inventor
Johannes Rietschel
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Qibixx AG
Original Assignee
Qibixx Ag
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Qibixx Ag filed Critical Qibixx Ag
Priority to EP15156996.9A priority Critical patent/EP3062294B1/fr
Publication of EP3062294A1 publication Critical patent/EP3062294A1/fr
Application granted granted Critical
Publication of EP3062294B1 publication Critical patent/EP3062294B1/fr
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Classifications

    • GPHYSICS
    • G07CHECKING-DEVICES
    • G07CTIME OR ATTENDANCE REGISTERS; REGISTERING OR INDICATING THE WORKING OF MACHINES; GENERATING RANDOM NUMBERS; VOTING OR LOTTERY APPARATUS; ARRANGEMENTS, SYSTEMS OR APPARATUS FOR CHECKING NOT PROVIDED FOR ELSEWHERE
    • G07C9/00Individual registration on entry or exit
    • G07C9/20Individual registration on entry or exit involving the use of a pass
    • G07C9/27Individual registration on entry or exit involving the use of a pass with central registration

Definitions

  • the present invention relates to a method for upgrading an existing access control system for increasing access control security and functionality. Furthermore it relates to a correspondingly upgraded access control system.
  • US2004/0041019 discloses a method of augmenting an existing token-based identification system, The concept is to splice into a data stream transmitted from a token reader to a control panel such that an acquired token factor from a user is intercepted by a biometric identification, or authentication, system that is wedged in series at a splice in the data stream.
  • a biometric identification, or authentication, system that is wedged in series at a splice in the data stream.
  • the biometric reader creates a biometric inquiry template that is transmitted to a biometric search engine, along with the acquired token factor, such as a PIN or barcode, to perform data match analysis against one or more enrollment templates associated with the acquired token factor.
  • the search engine will either match an authorized user or reject an unidentifiable user. If there is a match, then the data stream is allowed to pass from the biometric reader to the control panel of the existing token-based identification system.
  • the existing system does not otherwise need to be modified.
  • the security of an Access Control System (ACS) can be greatly enhanced by this method of augmentation that, preferably, wedges an automatic fingerprint identification system (AFIS) into the data stream of an established ACS.
  • AFIS automatic fingerprint identification system
  • the present invention proposes such a method for upgrading an existing access control system, as well as an upgraded access control system.
  • the present invention in a 1 st aspect thereof relates to a method for upgrading an existing access control system.
  • an existing access control system comprises at least one access point (e.g. a door) which is controlled by a reader unit for reading authorization information from a portable token (a batch, a key or the like) and a corresponding unlocking device (typically a physical device physically locking and unlocking the door).
  • a reader unit for reading authorization information from a portable token (a batch, a key or the like)
  • a corresponding unlocking device typically a physical device physically locking and unlocking the door.
  • the reader unit is in wired connection via at least one 1 st control line (a physical wired line, can be a single line, two or more wired lines) communicatively connected to an access controller, and said access controller is in wired connection via at least one 2nd control line (again a physical wired line, can be a single line, two or more wired lines) communicatively connected to said unlocking device, and said access controller controls the locking state of said unlocking device via said 2nd control line by verifying identification information transmitted via 1 st control line from said reader unit.
  • 1 st control line a physical wired line, can be a single line, two or more wired lines
  • 2nd control line again a physical wired line, can be a single line, two or more wired lines
  • Such an access control system comprises one central access control unit and, depending on the access points, a corresponding number of reader units and unlocking units, but it is also possible that for each access point in individual reader unit, access unit and unlocking unit are pre-existing, in both cases the proposed upgrade is possible.
  • the proposal is to upgrade as follows: the method comprises the steps of interposing into the at least one 1st control line an interception unit.
  • Said interception unit is adapted to and allowing for receiving and, if needed after temporarily withholding said identification information received from said reader unit, and only transmitting it to the access control unit once said interception unit has verified permission to access independently via a 2nd communication with a holder of said token (i.e. a person carrying the token).
  • the upgrade is realized in that a 2 nd identification retrieval mechanism is embedded into the pre-existing access control system.
  • This identification information retrieval mechanism is brought in by an additional interception unit.
  • This interception unit which can simply be inserted into the communication channel between the reader and the access controller, has the functionality of independently establishing a connection to either the same or another token of the holder desiring to access through the access point. The idea is to have as a 1 st token the badge of the holder, and the 2 nd token of the holder is the personal mobile handheld device.
  • the interception unit is adapted for establishing a communication link to the personal mobile handheld device in order to retrieve information there from to allow for increased security access granting.
  • the interception device So basically the function of the interception device is to intercept the data transfer between the reader and the access controller until, after having established a connection between the interception device and the mobile handheld device and after having established further identification information by using the mobile handheld device, only forwarding the data transfer further to the access controller once identification has been verified.
  • a corresponding central authority e.g. cloud-based
  • Preferably all this data communication is encrypted, and it is possible to basically store the token information using the interception unit and the handheld device the 1 st time, on the mobile handheld device so as to avoid to have to use the token (key, badge) each time an access point needs to be released and passed.
  • the interception unit comprises at least one radiofrequency interface for establishing a wireless communication channel between said interception unit and a mobile handheld device of said holder, and said verification by the interception unit involves retrieving information about access permission of said holder via said mobile handheld device.
  • the radiofrequency interface is a wireless local area network (WLAN) interface, a Bluetooth interface, Bluetooth smart, including a low-energy Bluetooth or Bluetooth smart interface.
  • WLAN wireless local area network
  • Bluetooth Bluetooth smart
  • retrieving information about access permission of said holder via said mobile handheld device includes the steps of identifying said holder and/or said mobile handheld device by means of input given by said holder into said mobile handheld device, and/or by means of readout of an unambiguous identification information from said mobile handheld device.
  • identification information can for example be input into the mobile handheld device in a 1 st contact with the upgraded access control system, and can be the identification information associated with the personal token of the holder of the personal mobile handheld device, see further description below.
  • said input is at least one of: a pin code, a biometric information collected by said mobile device, such as fingerprint, picture, in particular face and/or skin picture, eyepicture, positional information, or a combination thereof.
  • further increasing the security level of the upgrade retrieving information about access permission of said holder via said mobile handheld device includes the step of establishing an external wireless communication using a WLAN or telecommunication channel by said mobile handheld device to an overall control authority (i.e. the central data control unit, e.g. established cloud-based) which verifies access permission independently and transmits, provided access granted, a corresponding permission back to said mobile handheld device and directly and/or in directly via said radiofrequency interface to the interception unit.
  • an overall control authority i.e. the central data control unit, e.g. established cloud-based
  • the interception unit after having verified permission to access, transmits said identification information from said reader unit identical to the one as initially received from said reader unit. However it's also possible to transmit specifically modified data to the access controller.
  • Verifying permission to access is possible either by the interception unit autonomously and/or by an overall control authority via communication therewith by means of the mobile handheld device and may involve authorizing at least one of: access time, access frequency, access number, access permission status of holder, trust status of holder, compliance of data about or from holder retrieved by said mobile handheld device with an internal database, or a combination thereof.
  • the radio frequency interface automatically establishes a radiofrequency connection to said mobile handheld device once it is in sufficient proximity to the interception unit , and, if needed, once connection established, increases the power level from low level stand by to high-level.
  • the interception unit can be provided with means for determining the distance between the interception unit and the mobile handheld device, and this distance can also be taken into account as a parameter for granting access.
  • the interception unit comprises an independent CPU, RAM, ROM, volatile and/or non-volatile data storage elements, an encryption unit, standalone and/or grid based power supply. If need be also a real-time clock element, and optionally a secondary CPU, RAM/ROM, data storage element can be present.
  • the interception unit can be put into the same housing as the reader, and the access controller, it's however also possible to put the interception unit only into a housing of the reader or into a separate housing.
  • the data transmitted via said 1 st communication line is serial, Wiegand (3 wires, one common ground and D0 and D1) or clock and data.
  • the 2 nd communication line is often just a power line.
  • Last but not least the present disclosure relates to a particularly tailored interception unit for a method as outlined above or to be part of or used in an access control system as outlined above and preferably comprising at least one radiofrequency interface for establishing a wireless communication channel between said interception unit and a mobile handheld device of said holder, and wherein said verification by the interception unit involves retrieving information about access permission of said holder via said mobile handheld device, wherein preferably the radiofrequency interface is a wireless local area network (WLAN) interface, a Bluetooth interface, Bluetooth smart, preferably a low-energy Bluetooth interface.
  • WLAN wireless local area network
  • a pre-existing access control system typically involves, at each access point, a reader unit 1 and an unlocking device 3, the latter normally being an electric motor controlled to withdraw or bring forward a locking pin or the like.
  • an unlocking device 3 normally being an electric motor controlled to withdraw or bring forward a locking pin or the like.
  • Such a pre-existing access control system furthermore typically includes a management unit 7, e.g. a central computer or server, which is also linked to the access controller 2, and which can be used to manage and control the access permissions in the access controller 2.
  • a management unit 7 e.g. a central computer or server, which is also linked to the access controller 2, and which can be used to manage and control the access permissions in the access controller 2.
  • Access is controlled in this case by a personal token 6, which can be a batch, or a key, which would then be a combination of a mechanical and an electrical/electronic access device, which can be used for accessing a certain access point.
  • the token 6 is approached to the reader unit 1 for access, and the reader unit typically communicates via radiofrequency with the token, which basically then acts as an RFID. Typically this communication is encrypted.
  • the corresponding token information is subsequently transferred via a 1 st physical control line 4 from the reader unit 1 to the access controller 2.
  • the token information is compared with corresponding authorization codes, or databases, and if there the required access permission can be established by this comparison, an unlocking signal is transmitted from the access controller 2 to the unlocking device 3 for unlocking the door of the access point.
  • All that needs to be done for upgrading such an access control system is one basically inserts an interception unit 9 into the 1 st control line 4 between the reader and the access controller 2. So basically this 1 st line 4 is split into a 1 st part line 4' between the reader unit 1 and the interception unit 9, and a 2 nd part line 4" between the interception unit 9 and the access controller.
  • the interception unit acts to intercept the data transfer and only forward the data received from the reader if corresponding access granting or identification is established in the interception unit 9.
  • the interception unit 9 is provided with communication means to communicate with a portable handheld device 10 carried by the person also carrying the token 6 and desiring to pass the access point. Once the handheld device 10 is in sufficient proximity to the interception unit 9, a preferably encrypted data connection is established between the interception unit 9 and the mobile handheld device 10.
  • An app installed on the mobile handheld device 10 after establishment of this data connection for example request the user to input a pin, to present the finger to a fingerprint sensor on the handheld device, to make a picture of the face or of the eye or the like, in the sense of biometric data, and only if this data is then verified to be correct, the interception unit 9 forwards the data, initially received from the reader unit via line 4', for which via line 4" to the access controller 2, which will then, without having to be modified at all basically, trigger the corresponding unlocking signal for the unlocking device 3.
  • the information retrieved by the mobile handheld device is further verified by establishment of a mobile data connection of the mobile handheld device 10 to the Internet, where on the Internet then, by corresponding communication between the app on the handheld device and the corresponding Internet site, preferably using an encrypted protocol, the information is verified, and if positively verified the corresponding access granting approval is transmitted to the app on the handheld device, the handheld device will transmit the approval to the interception unit 9, and in turn the interception unit 9 will then basically release the signal to the access controller 2.
  • the interception unit 9 which can be in a separate housing, which however can also be put into the housing of the reader for example, comprises a reader interface 14 for communicating with the reader by line 4' , and a controller interface 15 for communicating with the access controller 2 by line 4".
  • the interception unit 9 comprises a radiofrequency interface for communication with the mobile handheld device 10. This is preferably a low-energy Bluetooth interface, so as to save energy and to avoid unnecessary radiofrequency emission.
  • the main electronics of the interception unit shall be outlined as follows: there is provided a usual intelligent controller, often SoC or single chip, like, comprising CPU, ROM to hold program storage, RAM for temporary data storage (volatile) and stack, data storage nonvolatile, an encryption unit, typically in the hardware, supports accelerated Advanced Encryption Standard (AES) calculation, RTC - Realtime clock to maintain time in case of power outage (battery powered), RF interface 13 - here: Bluetooth low energy (BLE, bluetooth smart) protocol engine, radio, HF amplifiers etc.
  • CC2540 TI specialized microcontroller which contains all above (no RTC, but a counter).
  • eader interface 14 Connected to such a main controller is the eader interface 14, which behaves like the usual "controller side” interfaces a reader is connected to.
  • eader interface 14 In case of "wiegand”, there are min. 2 inputs for "D0" and D1" data lines, typically a reader block or LED indication output, a buzzer control output (optional).
  • Alternative versions can use different interfaces like Omron Magstripe (clock&Data) interface, serial RS-485 or other interfaces a controller-side interface 15, which behaves like the usual "wiegand” or other access reader.
  • clock&Data Omron Magstripe
  • serial RS-485 serial RS-485 or other interfaces
  • controller-side interface 15 which behaves like the usual "wiegand” or other access reader.
  • there are min. 2 outputs for D0 and D1 data lines typically reader block or LED indication INPUTS, buzzer control input.
  • a key is that 14 and 15 are "inverse function" interfaces, so while a reader can be connected to 14, 15 actually SIMULATES a reader to the controller.
  • Other components might include a higher level application CPU with more memory, encryption, decision making capabilities.
  • Power supply circuitry will generally be needed also, as illustrated by reference numeral 12.
  • a smart phone 10 which can communicate with the main electronics via Bluetooth or Bluetooth Smart or Wifi.
  • a cloud based service can be used also to enhance functionality in the communication 19.
  • the invention can be used as a standard BLE based ID reader.
  • the device 9 can receive credentials from a smart phone and deliver these to the controller, effectively emulating a Wiegand Reader.
  • the two main functions the invention can provide are:
  • use of the invention can also provide online reporting and even decision making for currently offline, installed access control systems, which generally also results in higher security and monitorability.
  • One key idea of the invention is that it can "intercept" the credentials coming from a reader 1, and only forwarding these to the controller 2 after certain additional security checks, logging or validation of personal security credentials (pin, password, fingerprint, face contour etc) have been conducted.
  • Possibilities include time or other criteria based additional checks (for example, if an employee comes in the morning, he also needs to do a face recognition check on his mobile, but later he does not need to do this).
  • intercepted credentials can be stored into the memory of the RF connected mobile phone, so that the user has no access, the data is safely encrypted, and can be released at the next reader (door).
  • an employee arriving in the morning to the premises of a military or industrial location will "badge" to open the door, with all other security steps involved.
  • the credentials of his card can be captured into the memory of the mobile phone, and for any further access within the premises, no ID card or batch is needed any more ("hands free” operations) because the ID of the employee has now entered the memory of the smart phone, potentially has been online validated, and can be transmitted through the inventions port 15 to door controllers 9 as if the employee would use his hands and his ID/batch manually (which he still may do).
  • one aspect of the invention can be that by use of location data, the ID information can be erased from the mobile phone once it leaves the perimeter of the location (geo fencing), so a lost phone outside of the area can not be used for entry.
  • the mobile phone 10 connects to a server to get the ID credentials (userid/password can be used to secure that data, and the phone can then get a local copy of the ID data), and instead of presenting a badge, carrying the mobile phone will be enough to be identified.
  • the BLE standard preferably used in the present device includes the possibility to transmit at different RF levels, and also include the actual transmit energy level in announcements.
  • standard mobile phone, bluetooth BLE stack implementations, API and libraries support "ranging” by reading the RSSI level from the RF receivers, and calculating, based on that information PLUS the transmitted RSSI level, the approximate distance.
  • this functionality can be used to make sure the above mentioned “copy ID into local memory” function can only be used if the mobile is within very close proximity of the device 9, however, later, for the "hands free” solution (sending back the ID for entry), a larger distance is allowed.
  • the system can even be used as a modern "immobilizer” or locking system for trucks, machines etc.
  • a "driver” can safely go to a coffee break, because without his mobile phone, the truck will not start.
  • the mobile phone When he returns to his car, the mobile phone will "see” the truck, and go online to request an authorization key that the user may operate the truck, which then, upon approval, is encrypted with the car's security credentials and sent via the invention into the truck to unlock it.
  • the main use of the disclosed interception unit is the upgrade of current access control installations using readers, to increase security or usability, by adding the mobile phone component with its readers and interfaces, and the possibility to go online for recording and decision making at a central location.
  • the invention enables legacy access control systems to be part of the "internet of things" without the central controllers to be touched.
  • 1 reader unit 11 wireless communication 2 access controller between interception unit and 3 unlocking device mobile handheld device 4 1st control line between 12 power supply unit reader unit and access 13 radiofrequency interface, controller Bluetooth low energy 5 2nd control line between 14 reader interface access controller and 15 controller interface unlocking device 16 housing 6 token (batch, key) 17 central control unit 7 management unit 18 wireless communication 8 communication between between interception unit and access controller and mobile handheld device management unit 19 wireless communication 9 interception unit between mobile handheld 10 mobile handheld device device and overall control

Landscapes

  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Lock And Its Accessories (AREA)

Claims (10)

  1. Procédé de mise à niveau d'un système de contrôle d'accès existant, ledit système de contrôle d'accès existant comprenant au moins un point d'accès qui est commandé par une unité de lecture (1) pour lire des informations d'autorisation à partir d'un jeton portable (6) et un dispositif de déverrouillage correspondant (3), dans lequel l'unité de lecture (1) est en connexion câblée via au moins une 1ère ligne de commande (4) connectée de manière communicative à un contrôleur d'accès (2), dans lequel ledit contrôleur d'accès (2) est en connexion câblée via au moins une 2ème ligne de commande (5) connectée de manière communicative audit dispositif de déverrouillage (3), et dans lequel ledit contrôleur d'accès (2) commande l'état de verrouillage dudit dispositif de déverrouillage (3) via ladite 2ème ligne de commande (5) en vérifiant les informations d'identification transmises via la 1ère ligne de commande (4) depuis ladite unité de lecture (1),
    dans lequel la méthode de mise à niveau comprend les étapes suivantes
    en interposant dans au moins une 1ère ligne de contrôle (4) une unité d'interception (9),
    ladite unité d'interception (9) adaptée et permettant de recevoir et, si nécessaire après avoir temporairement retenu lesdites informations d'identification de ladite unité de lecture (1), de ne les transmettre à l'unité de contrôle d'accès (2) qu'une fois que ladite unité d'interception (9) a vérifié l'autorisation d'accès de manière indépendante via une 2ème communication avec un détenteur dudit jeton (6),
    dans lequel, pour ce faire, l'unité d'interception (9) comprend au moins une interface radiofréquence (13) avec laquelle elle établit un canal de communication sans fil (18) entre ladite unité d'interception (9) et un dispositif portatif mobile (10) dudit titulaire,
    dans laquelle ladite vérification par l'unité d'interception (9) implique la récupération d'informations sur l'autorisation d'accès dudit titulaire via ledit appareil portable (10),
    dans laquelle l'interface radiofréquence (13) est une interface de réseau local sans fil (WLAN), une interface Bluetooth, Bluetooth smart, y compris une interface Bluetooth à faible consommation d'énergie,
    et dans lequel la récupération d'informations concernant l'autorisation d'accès dudit titulaire via ledit dispositif portable mobile (10) comprend l'étape consistant à établir une communication sans fil externe (19) utilisant un WLAN ou un canal de télécommunication par ledit dispositif portable mobile (10) vers une autorité de contrôle globale qui vérifie l'autorisation d'accès de manière indépendante et transmet, si l'accès est accordé, une autorisation correspondante en retour audit dispositif portable mobile (10) et directement et/ou en direct via ladite interface radiofréquence (13) vers l'unité d'interception.
  2. Procédé selon la revendication 1, dans lequel la récupération d'informations concernant l'autorisation d'accès dudit titulaire par l'intermédiaire dudit dispositif portable mobile (10) comprend les étapes consistant à identifier ledit titulaire et/ou ledit dispositif portable mobile (10) au moyen d'une entrée donnée par ledit titulaire dans ledit dispositif portable mobile (10), et/ou au moyen de la lecture d'un numéro d'identification non ambigu dudit dispositif portable mobile (10), dans lequel ladite entrée est de préférence au moins l'une de : un code pin, une information biométrique recueillie par ledit dispositif mobile, telle qu'une empreinte digitale, une image, en particulier une image de visage, une information de position, ou une combinaison de celles-ci.
  3. Procédé selon l'une des revendications précédentes, dans lequel l'unité d'interception (9), après avoir vérifié l'autorisation d'accès, transmet ladite information d'identification à partir de ladite unité de lecture (1) identique à celle initialement reçue de ladite unité de lecture (1) ou d'une manière modifiée.
  4. Procédé selon l'une des revendications précédentes, dans lequel la vérification de l'autorisation d'accès par l'unité d'interception (9) de manière autonome et/ou par une autorité de contrôle globale via une communication avec celle-ci au moyen du dispositif portable mobile (10) implique l'autorisation et/ou la détermination d'au moins un des éléments suivants : temps d'accès, fréquence d'accès, numéro d'accès, statut de l'autorisation d'accès du détenteur, statut de confiance du détenteur, conformité des données concernant le détenteur ou provenant du détenteur extraites par ledit dispositif portable mobile (10) avec une base de données interne, localisation du dispositif portable mobile déterminée par GPS (géo-clôture) ou une combinaison de ces éléments.
  5. Procédé selon l'une des revendications précédentes, dans lequel l'interface radiofréquence (13) établit automatiquement une connexion radiofréquence avec ledit dispositif portable mobile (10) une fois qu'il est à proximité suffisante de l'unité d'interception (9) et, si nécessaire, une fois la connexion établie, augmente le niveau de puissance de la veille de bas niveau à haut niveau.
  6. Procédé selon l'une des revendications précédentes, dans lequel l'unité d'interception (9) est munie de moyens pour déterminer la distance entre l'unité d'interception (9) et le dispositif portable mobile (10), et dans lequel cette distance est prise en compte comme paramètre pour l'octroi de l'accès.
  7. Procédé selon l'une des revendications précédentes, dans lequel l'unité d'interception (9) comprend une unité centrale indépendante, une mémoire vive (RAM), une mémoire morte (ROM), des éléments de stockage de données volatils et/ou non volatils, une unité de cryptage, une alimentation électrique autonome et/ou basée sur le réseau, si nécessaire un élément d'horloge en temps réel, et éventuellement une unité centrale secondaire, une mémoire vive (RAM), un élément de stockage de données.
  8. Procédé selon l'une des revendications précédentes, dans lequel la transmission par ladite première ligne de communication (4) est série, Wiegand ou horloge et données, et/ou dans lequel la communication par ladite première ligne de commande (4), et/ou par ladite deuxième ligne de commande (5), et/ou entre (18) l'unité d'interception (9) et le dispositif portable mobile (10) et/ou entre (19) le dispositif portable mobile (10) et la commande globale est cryptée.
  9. Procédé selon l'une des revendications précédentes, dans lequel, une fois autorisé par au moins l'un des éléments suivants : jeton (9), appareil mobile de poche (10), vérification indépendante par le contrôle global ou une combinaison de ceux-ci, l'accès peut être accordé sans avoir besoin du jeton (9) et uniquement par ledit appareil mobile de poche (10).
  10. Système de contrôle d'accès comprenant au moins un point d'accès qui est contrôlé par une unité de lecture (1) configurée pour lire des informations d'autorisation à partir d'un jeton portable (6) et un dispositif de déverrouillage correspondant (3), dans lequel l'unité de lecture (1) est en connexion câblée via au moins une première ligne de contrôle (4) connectée de manière communicative à un contrôleur d'accès (2), dans lequel ledit contrôleur d'accès est en connexion câblée via au moins une deuxième ligne de contrôle (5) connectée de manière communicative audit dispositif de déverrouillage (3), et dans lequel ledit contrôleur d'accès (2) contrôle l'état de verrouillage dudit dispositif de déverrouillage (3) via ladite 2ème ligne de contrôle (5) en vérifiant les informations d'identification transmises via la 1ère ligne de contrôle (4) depuis ladite unité de lecture (1), le système de contrôle d'accès étant mis à niveau en utilisant une méthode selon l'une des revendications précédentes, comprenant en outre une unité d'interception, un dispositif portable mobile et une autorité de contrôle globale, dans lequel l'unité d'interception est interposée dans la au moins une première ligne de contrôle et ladite unité d'interception (9) est adaptée à et permet de recevoir et, si nécessaire après avoir temporairement retenu lesdites informations d'identification de ladite unité de lecture (1), ne la transmettant à l'unité de contrôle d'accès (2) qu'une fois que ladite unité d'interception (9) a vérifié l'autorisation d'accès de manière indépendante via une 2ème communication avec un détenteur dudit jeton (6), dans lequel pour ce faire l'unité d'interception (9) comprend au moins une interface radiofréquence (13) avec laquelle elle établit un canal de communication sans fil (18) entre ladite unité d'interception (9) et un dispositif portable mobile (10) dudit détenteur, dans lequel ladite vérification par l'unité d'interception (9) implique la récupération d'informations sur l'autorisation d'accès dudit titulaire via ledit dispositif portable (10), dans lequel l'interface radiofréquence (13) est une interface de réseau local sans fil (WLAN), une interface Bluetooth ou une interface intelligente Bluetooth, comprenant une interface Bluetooth à faible consommation d'énergie, et dans lequel, afin de récupérer des informations concernant l'autorisation d'accès dudit dispositif portable mobile (10), celui-ci est configuré pour établir une communication sans fil externe (19) utilisant un réseau local sans fil (WLAN) ou une télécommunication avec l'autorité de contrôle globale qui est configurée pour vérifier l'autorisation d'accès de manière indépendante et est configurée pour transmettre, si l'accès est accordé, une autorisation correspondante audit dispositif portable mobile (10) et directement et/ou en direct via ladite interface radiofréquence (13) à l'unité d'interception.
EP15156996.9A 2015-02-27 2015-02-27 Procédé et dispositifs permettant l'amélioration d'un système de commande d'accès existant Active EP3062294B1 (fr)

Priority Applications (1)

Application Number Priority Date Filing Date Title
EP15156996.9A EP3062294B1 (fr) 2015-02-27 2015-02-27 Procédé et dispositifs permettant l'amélioration d'un système de commande d'accès existant

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
EP15156996.9A EP3062294B1 (fr) 2015-02-27 2015-02-27 Procédé et dispositifs permettant l'amélioration d'un système de commande d'accès existant

Publications (2)

Publication Number Publication Date
EP3062294A1 EP3062294A1 (fr) 2016-08-31
EP3062294B1 true EP3062294B1 (fr) 2021-04-14

Family

ID=52648826

Family Applications (1)

Application Number Title Priority Date Filing Date
EP15156996.9A Active EP3062294B1 (fr) 2015-02-27 2015-02-27 Procédé et dispositifs permettant l'amélioration d'un système de commande d'accès existant

Country Status (1)

Country Link
EP (1) EP3062294B1 (fr)

Families Citing this family (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US9666000B1 (en) 2014-01-04 2017-05-30 Latchable, Inc. Methods and systems for access control and awareness management
WO2017079438A1 (fr) * 2015-11-04 2017-05-11 Latchable, Inc. Systèmes et procédés de contrôle d'accès dans un espace physique
KR102745825B1 (ko) 2017-05-17 2024-12-20 래치 시스템즈, 인크. 모니터링 및 컨시어지 서비스를 위한 확장가능 시스템들 및 방법들
DE102018122758A1 (de) 2018-09-17 2020-03-19 ASTRA Gesellschaft für Asset Management mbH & Co. KG Identifizierungsadapter und Identifizierungseinrichtung
GB2634559A (en) * 2023-10-13 2025-04-16 Paxton Access Ltd Access control system

Citations (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP2365477A1 (fr) * 2007-03-14 2011-09-14 Dexrad (Proprietary) Limited Appareil d'identification personelle pour des transactions securisées

Family Cites Families (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US5679945A (en) * 1995-03-31 1997-10-21 Cybermark, L.L.C. Intelligent card reader having emulation features
US7079007B2 (en) * 2002-04-19 2006-07-18 Cross Match Technologies, Inc. Systems and methods utilizing biometric data
US6944768B2 (en) * 2002-04-19 2005-09-13 Cross Match Technologies, Inc. System and methods for access control utilizing two factors to control access
US6715674B2 (en) * 2002-08-27 2004-04-06 Ultra-Scan Corporation Biometric factor augmentation method for identification systems
DE20309254U1 (de) * 2003-06-16 2003-11-06 SCM Microsystems GmbH, 85737 Ismaning Zugangssystem
WO2012151290A1 (fr) * 2011-05-02 2012-11-08 Apigy Inc. Systèmes et procédés de commande d'un mécanisme de verrouillage à l'aide d'un dispositif électronique portable
US9111401B2 (en) * 2012-11-29 2015-08-18 Hid Global Gmbh Interactive reader commander

Patent Citations (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP2365477A1 (fr) * 2007-03-14 2011-09-14 Dexrad (Proprietary) Limited Appareil d'identification personelle pour des transactions securisées

Also Published As

Publication number Publication date
EP3062294A1 (fr) 2016-08-31

Similar Documents

Publication Publication Date Title
US10755507B2 (en) Systems and methods for multifactor physical authentication
CN114898482B (zh) 针对利用虚拟卡数据的进入控制系统的远程编程
US11164413B2 (en) Access control system with secure pass-through
US10171444B1 (en) Securitization of temporal digital communications via authentication and validation for wireless user and access devices
CN104966336B (zh) 智能锁及智能锁的授权管理方法和装置
US9659422B2 (en) Using temporary access codes
US20180262891A1 (en) Electronic access control systems and methods using near-field communications, mobile devices and cloud computing
EP2657917B1 (fr) Système et procédé d'enregistrement de clé électronique
KR102085975B1 (ko) 도어락 정보 관리 시스템 및 그 구동방법
KR102427635B1 (ko) 동적 키 액세스 제어 시스템들, 방법들 및 장치
US11477649B2 (en) Access control system with trusted third party
US20120169461A1 (en) Electronic physical access control with remote authentication
CN108510626B (zh) 一种动态密码门禁管理方法及其管理系统
JP2004528655A (ja) 周波数方式
EP3062294B1 (fr) Procédé et dispositifs permettant l'amélioration d'un système de commande d'accès existant
CN107005798A (zh) 在与多个进入控制交互时捕获用户意图
CN106652109A (zh) 智能锁控制方法、装置及锁管理服务器
KR101637516B1 (ko) 출입 제어 방법 및 장치
KR20150056711A (ko) 출입자 생체정보를 가지는 스마트 출입카드를 이용한 출입 관리 시스템 및 방법
CN112041525A (zh) 密钥信息生成系统及密钥信息生成方法
US20200026829A1 (en) Biometric access control identification card
US12083992B2 (en) Methods for shared vehicle access
CN113763603B (zh) 信息处理装置、方法、计算机可读存储介质及便携终端
CN114365126B (zh) 生物体认证系统和生物体认证装置
US10645070B2 (en) Securitization of temporal digital communications via authentication and validation for wireless user and access devices

Legal Events

Date Code Title Description
PUAI Public reference made under article 153(3) epc to a published international application that has entered the european phase

Free format text: ORIGINAL CODE: 0009012

AK Designated contracting states

Kind code of ref document: A1

Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR

AX Request for extension of the european patent

Extension state: BA ME

STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: REQUEST FOR EXAMINATION WAS MADE

17P Request for examination filed

Effective date: 20170214

RBV Designated contracting states (corrected)

Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR

STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: EXAMINATION IS IN PROGRESS

17Q First examination report despatched

Effective date: 20180202

REG Reference to a national code

Ref country code: DE

Ref legal event code: R079

Ref document number: 602015068011

Country of ref document: DE

Free format text: PREVIOUS MAIN CLASS: G07C0009000000

Ipc: G07C0009270000

GRAP Despatch of communication of intention to grant a patent

Free format text: ORIGINAL CODE: EPIDOSNIGR1

STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: GRANT OF PATENT IS INTENDED

RIC1 Information provided on ipc code assigned before grant

Ipc: G07C 9/27 20200101AFI20201028BHEP

INTG Intention to grant announced

Effective date: 20201116

GRAS Grant fee paid

Free format text: ORIGINAL CODE: EPIDOSNIGR3

GRAA (expected) grant

Free format text: ORIGINAL CODE: 0009210

STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: THE PATENT HAS BEEN GRANTED

AK Designated contracting states

Kind code of ref document: B1

Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR

RAP3 Party data changed (applicant data changed or rights of an application transferred)

Owner name: QIBIXX AG

REG Reference to a national code

Ref country code: GB

Ref legal event code: FG4D

REG Reference to a national code

Ref country code: CH

Ref legal event code: EP

REG Reference to a national code

Ref country code: DE

Ref legal event code: R096

Ref document number: 602015068011

Country of ref document: DE

REG Reference to a national code

Ref country code: IE

Ref legal event code: FG4D

REG Reference to a national code

Ref country code: AT

Ref legal event code: REF

Ref document number: 1383119

Country of ref document: AT

Kind code of ref document: T

Effective date: 20210515

REG Reference to a national code

Ref country code: LT

Ref legal event code: MG9D

REG Reference to a national code

Ref country code: AT

Ref legal event code: MK05

Ref document number: 1383119

Country of ref document: AT

Kind code of ref document: T

Effective date: 20210414

REG Reference to a national code

Ref country code: NL

Ref legal event code: MP

Effective date: 20210414

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: HR

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20210414

Ref country code: BG

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20210714

Ref country code: AT

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20210414

Ref country code: FI

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20210414

Ref country code: NL

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20210414

Ref country code: LT

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20210414

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: ES

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20210414

Ref country code: PT

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20210816

Ref country code: NO

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20210714

Ref country code: PL

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20210414

Ref country code: RS

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20210414

Ref country code: SE

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20210414

Ref country code: LV

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20210414

Ref country code: IS

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20210814

Ref country code: GR

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20210715

REG Reference to a national code

Ref country code: DE

Ref legal event code: R097

Ref document number: 602015068011

Country of ref document: DE

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: RO

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20210414

Ref country code: EE

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20210414

Ref country code: CZ

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20210414

Ref country code: DK

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20210414

Ref country code: SM

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20210414

Ref country code: SK

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20210414

PLBE No opposition filed within time limit

Free format text: ORIGINAL CODE: 0009261

STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: NO OPPOSITION FILED WITHIN TIME LIMIT

26N No opposition filed

Effective date: 20220117

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: IS

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20210814

Ref country code: AL

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20210414

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: IT

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20210414

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: MC

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20210414

REG Reference to a national code

Ref country code: BE

Ref legal event code: MM

Effective date: 20220228

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: LU

Free format text: LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES

Effective date: 20220227

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: IE

Free format text: LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES

Effective date: 20220227

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: BE

Free format text: LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES

Effective date: 20220228

P01 Opt-out of the competence of the unified patent court (upc) registered

Effective date: 20230505

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: HU

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT; INVALID AB INITIO

Effective date: 20150227

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: MK

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20210414

Ref country code: CY

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20210414

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: TR

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20210414

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: MT

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20210414

REG Reference to a national code

Ref country code: DE

Ref legal event code: R081

Ref document number: 602015068011

Country of ref document: DE

Owner name: BARIX AG, CH

Free format text: FORMER OWNER: QIBIXX AG, BUCHS, CH

REG Reference to a national code

Ref country code: GB

Ref legal event code: 732E

Free format text: REGISTERED BETWEEN 20250703 AND 20250709

REG Reference to a national code

Ref country code: DE

Ref legal event code: R082

Ref document number: 602015068011

Country of ref document: DE

Representative=s name: TERGAU & WALKENHORST INTELLECTUAL PROPERTY GMB, DE

REG Reference to a national code

Ref country code: CH

Ref legal event code: U11

Free format text: ST27 STATUS EVENT CODE: U-0-0-U10-U11 (AS PROVIDED BY THE NATIONAL OFFICE)

Effective date: 20260301

PGFP Annual fee paid to national office [announced via postgrant information from national office to epo]

Ref country code: GB

Payment date: 20260219

Year of fee payment: 12

PGFP Annual fee paid to national office [announced via postgrant information from national office to epo]

Ref country code: DE

Payment date: 20260218

Year of fee payment: 12

PGFP Annual fee paid to national office [announced via postgrant information from national office to epo]

Ref country code: FR

Payment date: 20260218

Year of fee payment: 12

PGFP Annual fee paid to national office [announced via postgrant information from national office to epo]

Ref country code: CH

Payment date: 20260301

Year of fee payment: 12