EP3062294B1 - Procédé et dispositifs permettant l'amélioration d'un système de commande d'accès existant - Google Patents
Procédé et dispositifs permettant l'amélioration d'un système de commande d'accès existant Download PDFInfo
- Publication number
- EP3062294B1 EP3062294B1 EP15156996.9A EP15156996A EP3062294B1 EP 3062294 B1 EP3062294 B1 EP 3062294B1 EP 15156996 A EP15156996 A EP 15156996A EP 3062294 B1 EP3062294 B1 EP 3062294B1
- Authority
- EP
- European Patent Office
- Prior art keywords
- access
- handheld device
- unit
- mobile handheld
- interception unit
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Active
Links
Images
Classifications
-
- G—PHYSICS
- G07—CHECKING-DEVICES
- G07C—TIME OR ATTENDANCE REGISTERS; REGISTERING OR INDICATING THE WORKING OF MACHINES; GENERATING RANDOM NUMBERS; VOTING OR LOTTERY APPARATUS; ARRANGEMENTS, SYSTEMS OR APPARATUS FOR CHECKING NOT PROVIDED FOR ELSEWHERE
- G07C9/00—Individual registration on entry or exit
- G07C9/20—Individual registration on entry or exit involving the use of a pass
- G07C9/27—Individual registration on entry or exit involving the use of a pass with central registration
Definitions
- the present invention relates to a method for upgrading an existing access control system for increasing access control security and functionality. Furthermore it relates to a correspondingly upgraded access control system.
- US2004/0041019 discloses a method of augmenting an existing token-based identification system, The concept is to splice into a data stream transmitted from a token reader to a control panel such that an acquired token factor from a user is intercepted by a biometric identification, or authentication, system that is wedged in series at a splice in the data stream.
- a biometric identification, or authentication, system that is wedged in series at a splice in the data stream.
- the biometric reader creates a biometric inquiry template that is transmitted to a biometric search engine, along with the acquired token factor, such as a PIN or barcode, to perform data match analysis against one or more enrollment templates associated with the acquired token factor.
- the search engine will either match an authorized user or reject an unidentifiable user. If there is a match, then the data stream is allowed to pass from the biometric reader to the control panel of the existing token-based identification system.
- the existing system does not otherwise need to be modified.
- the security of an Access Control System (ACS) can be greatly enhanced by this method of augmentation that, preferably, wedges an automatic fingerprint identification system (AFIS) into the data stream of an established ACS.
- AFIS automatic fingerprint identification system
- the present invention proposes such a method for upgrading an existing access control system, as well as an upgraded access control system.
- the present invention in a 1 st aspect thereof relates to a method for upgrading an existing access control system.
- an existing access control system comprises at least one access point (e.g. a door) which is controlled by a reader unit for reading authorization information from a portable token (a batch, a key or the like) and a corresponding unlocking device (typically a physical device physically locking and unlocking the door).
- a reader unit for reading authorization information from a portable token (a batch, a key or the like)
- a corresponding unlocking device typically a physical device physically locking and unlocking the door.
- the reader unit is in wired connection via at least one 1 st control line (a physical wired line, can be a single line, two or more wired lines) communicatively connected to an access controller, and said access controller is in wired connection via at least one 2nd control line (again a physical wired line, can be a single line, two or more wired lines) communicatively connected to said unlocking device, and said access controller controls the locking state of said unlocking device via said 2nd control line by verifying identification information transmitted via 1 st control line from said reader unit.
- 1 st control line a physical wired line, can be a single line, two or more wired lines
- 2nd control line again a physical wired line, can be a single line, two or more wired lines
- Such an access control system comprises one central access control unit and, depending on the access points, a corresponding number of reader units and unlocking units, but it is also possible that for each access point in individual reader unit, access unit and unlocking unit are pre-existing, in both cases the proposed upgrade is possible.
- the proposal is to upgrade as follows: the method comprises the steps of interposing into the at least one 1st control line an interception unit.
- Said interception unit is adapted to and allowing for receiving and, if needed after temporarily withholding said identification information received from said reader unit, and only transmitting it to the access control unit once said interception unit has verified permission to access independently via a 2nd communication with a holder of said token (i.e. a person carrying the token).
- the upgrade is realized in that a 2 nd identification retrieval mechanism is embedded into the pre-existing access control system.
- This identification information retrieval mechanism is brought in by an additional interception unit.
- This interception unit which can simply be inserted into the communication channel between the reader and the access controller, has the functionality of independently establishing a connection to either the same or another token of the holder desiring to access through the access point. The idea is to have as a 1 st token the badge of the holder, and the 2 nd token of the holder is the personal mobile handheld device.
- the interception unit is adapted for establishing a communication link to the personal mobile handheld device in order to retrieve information there from to allow for increased security access granting.
- the interception device So basically the function of the interception device is to intercept the data transfer between the reader and the access controller until, after having established a connection between the interception device and the mobile handheld device and after having established further identification information by using the mobile handheld device, only forwarding the data transfer further to the access controller once identification has been verified.
- a corresponding central authority e.g. cloud-based
- Preferably all this data communication is encrypted, and it is possible to basically store the token information using the interception unit and the handheld device the 1 st time, on the mobile handheld device so as to avoid to have to use the token (key, badge) each time an access point needs to be released and passed.
- the interception unit comprises at least one radiofrequency interface for establishing a wireless communication channel between said interception unit and a mobile handheld device of said holder, and said verification by the interception unit involves retrieving information about access permission of said holder via said mobile handheld device.
- the radiofrequency interface is a wireless local area network (WLAN) interface, a Bluetooth interface, Bluetooth smart, including a low-energy Bluetooth or Bluetooth smart interface.
- WLAN wireless local area network
- Bluetooth Bluetooth smart
- retrieving information about access permission of said holder via said mobile handheld device includes the steps of identifying said holder and/or said mobile handheld device by means of input given by said holder into said mobile handheld device, and/or by means of readout of an unambiguous identification information from said mobile handheld device.
- identification information can for example be input into the mobile handheld device in a 1 st contact with the upgraded access control system, and can be the identification information associated with the personal token of the holder of the personal mobile handheld device, see further description below.
- said input is at least one of: a pin code, a biometric information collected by said mobile device, such as fingerprint, picture, in particular face and/or skin picture, eyepicture, positional information, or a combination thereof.
- further increasing the security level of the upgrade retrieving information about access permission of said holder via said mobile handheld device includes the step of establishing an external wireless communication using a WLAN or telecommunication channel by said mobile handheld device to an overall control authority (i.e. the central data control unit, e.g. established cloud-based) which verifies access permission independently and transmits, provided access granted, a corresponding permission back to said mobile handheld device and directly and/or in directly via said radiofrequency interface to the interception unit.
- an overall control authority i.e. the central data control unit, e.g. established cloud-based
- the interception unit after having verified permission to access, transmits said identification information from said reader unit identical to the one as initially received from said reader unit. However it's also possible to transmit specifically modified data to the access controller.
- Verifying permission to access is possible either by the interception unit autonomously and/or by an overall control authority via communication therewith by means of the mobile handheld device and may involve authorizing at least one of: access time, access frequency, access number, access permission status of holder, trust status of holder, compliance of data about or from holder retrieved by said mobile handheld device with an internal database, or a combination thereof.
- the radio frequency interface automatically establishes a radiofrequency connection to said mobile handheld device once it is in sufficient proximity to the interception unit , and, if needed, once connection established, increases the power level from low level stand by to high-level.
- the interception unit can be provided with means for determining the distance between the interception unit and the mobile handheld device, and this distance can also be taken into account as a parameter for granting access.
- the interception unit comprises an independent CPU, RAM, ROM, volatile and/or non-volatile data storage elements, an encryption unit, standalone and/or grid based power supply. If need be also a real-time clock element, and optionally a secondary CPU, RAM/ROM, data storage element can be present.
- the interception unit can be put into the same housing as the reader, and the access controller, it's however also possible to put the interception unit only into a housing of the reader or into a separate housing.
- the data transmitted via said 1 st communication line is serial, Wiegand (3 wires, one common ground and D0 and D1) or clock and data.
- the 2 nd communication line is often just a power line.
- Last but not least the present disclosure relates to a particularly tailored interception unit for a method as outlined above or to be part of or used in an access control system as outlined above and preferably comprising at least one radiofrequency interface for establishing a wireless communication channel between said interception unit and a mobile handheld device of said holder, and wherein said verification by the interception unit involves retrieving information about access permission of said holder via said mobile handheld device, wherein preferably the radiofrequency interface is a wireless local area network (WLAN) interface, a Bluetooth interface, Bluetooth smart, preferably a low-energy Bluetooth interface.
- WLAN wireless local area network
- a pre-existing access control system typically involves, at each access point, a reader unit 1 and an unlocking device 3, the latter normally being an electric motor controlled to withdraw or bring forward a locking pin or the like.
- an unlocking device 3 normally being an electric motor controlled to withdraw or bring forward a locking pin or the like.
- Such a pre-existing access control system furthermore typically includes a management unit 7, e.g. a central computer or server, which is also linked to the access controller 2, and which can be used to manage and control the access permissions in the access controller 2.
- a management unit 7 e.g. a central computer or server, which is also linked to the access controller 2, and which can be used to manage and control the access permissions in the access controller 2.
- Access is controlled in this case by a personal token 6, which can be a batch, or a key, which would then be a combination of a mechanical and an electrical/electronic access device, which can be used for accessing a certain access point.
- the token 6 is approached to the reader unit 1 for access, and the reader unit typically communicates via radiofrequency with the token, which basically then acts as an RFID. Typically this communication is encrypted.
- the corresponding token information is subsequently transferred via a 1 st physical control line 4 from the reader unit 1 to the access controller 2.
- the token information is compared with corresponding authorization codes, or databases, and if there the required access permission can be established by this comparison, an unlocking signal is transmitted from the access controller 2 to the unlocking device 3 for unlocking the door of the access point.
- All that needs to be done for upgrading such an access control system is one basically inserts an interception unit 9 into the 1 st control line 4 between the reader and the access controller 2. So basically this 1 st line 4 is split into a 1 st part line 4' between the reader unit 1 and the interception unit 9, and a 2 nd part line 4" between the interception unit 9 and the access controller.
- the interception unit acts to intercept the data transfer and only forward the data received from the reader if corresponding access granting or identification is established in the interception unit 9.
- the interception unit 9 is provided with communication means to communicate with a portable handheld device 10 carried by the person also carrying the token 6 and desiring to pass the access point. Once the handheld device 10 is in sufficient proximity to the interception unit 9, a preferably encrypted data connection is established between the interception unit 9 and the mobile handheld device 10.
- An app installed on the mobile handheld device 10 after establishment of this data connection for example request the user to input a pin, to present the finger to a fingerprint sensor on the handheld device, to make a picture of the face or of the eye or the like, in the sense of biometric data, and only if this data is then verified to be correct, the interception unit 9 forwards the data, initially received from the reader unit via line 4', for which via line 4" to the access controller 2, which will then, without having to be modified at all basically, trigger the corresponding unlocking signal for the unlocking device 3.
- the information retrieved by the mobile handheld device is further verified by establishment of a mobile data connection of the mobile handheld device 10 to the Internet, where on the Internet then, by corresponding communication between the app on the handheld device and the corresponding Internet site, preferably using an encrypted protocol, the information is verified, and if positively verified the corresponding access granting approval is transmitted to the app on the handheld device, the handheld device will transmit the approval to the interception unit 9, and in turn the interception unit 9 will then basically release the signal to the access controller 2.
- the interception unit 9 which can be in a separate housing, which however can also be put into the housing of the reader for example, comprises a reader interface 14 for communicating with the reader by line 4' , and a controller interface 15 for communicating with the access controller 2 by line 4".
- the interception unit 9 comprises a radiofrequency interface for communication with the mobile handheld device 10. This is preferably a low-energy Bluetooth interface, so as to save energy and to avoid unnecessary radiofrequency emission.
- the main electronics of the interception unit shall be outlined as follows: there is provided a usual intelligent controller, often SoC or single chip, like, comprising CPU, ROM to hold program storage, RAM for temporary data storage (volatile) and stack, data storage nonvolatile, an encryption unit, typically in the hardware, supports accelerated Advanced Encryption Standard (AES) calculation, RTC - Realtime clock to maintain time in case of power outage (battery powered), RF interface 13 - here: Bluetooth low energy (BLE, bluetooth smart) protocol engine, radio, HF amplifiers etc.
- CC2540 TI specialized microcontroller which contains all above (no RTC, but a counter).
- eader interface 14 Connected to such a main controller is the eader interface 14, which behaves like the usual "controller side” interfaces a reader is connected to.
- eader interface 14 In case of "wiegand”, there are min. 2 inputs for "D0" and D1" data lines, typically a reader block or LED indication output, a buzzer control output (optional).
- Alternative versions can use different interfaces like Omron Magstripe (clock&Data) interface, serial RS-485 or other interfaces a controller-side interface 15, which behaves like the usual "wiegand” or other access reader.
- clock&Data Omron Magstripe
- serial RS-485 serial RS-485 or other interfaces
- controller-side interface 15 which behaves like the usual "wiegand” or other access reader.
- there are min. 2 outputs for D0 and D1 data lines typically reader block or LED indication INPUTS, buzzer control input.
- a key is that 14 and 15 are "inverse function" interfaces, so while a reader can be connected to 14, 15 actually SIMULATES a reader to the controller.
- Other components might include a higher level application CPU with more memory, encryption, decision making capabilities.
- Power supply circuitry will generally be needed also, as illustrated by reference numeral 12.
- a smart phone 10 which can communicate with the main electronics via Bluetooth or Bluetooth Smart or Wifi.
- a cloud based service can be used also to enhance functionality in the communication 19.
- the invention can be used as a standard BLE based ID reader.
- the device 9 can receive credentials from a smart phone and deliver these to the controller, effectively emulating a Wiegand Reader.
- the two main functions the invention can provide are:
- use of the invention can also provide online reporting and even decision making for currently offline, installed access control systems, which generally also results in higher security and monitorability.
- One key idea of the invention is that it can "intercept" the credentials coming from a reader 1, and only forwarding these to the controller 2 after certain additional security checks, logging or validation of personal security credentials (pin, password, fingerprint, face contour etc) have been conducted.
- Possibilities include time or other criteria based additional checks (for example, if an employee comes in the morning, he also needs to do a face recognition check on his mobile, but later he does not need to do this).
- intercepted credentials can be stored into the memory of the RF connected mobile phone, so that the user has no access, the data is safely encrypted, and can be released at the next reader (door).
- an employee arriving in the morning to the premises of a military or industrial location will "badge" to open the door, with all other security steps involved.
- the credentials of his card can be captured into the memory of the mobile phone, and for any further access within the premises, no ID card or batch is needed any more ("hands free” operations) because the ID of the employee has now entered the memory of the smart phone, potentially has been online validated, and can be transmitted through the inventions port 15 to door controllers 9 as if the employee would use his hands and his ID/batch manually (which he still may do).
- one aspect of the invention can be that by use of location data, the ID information can be erased from the mobile phone once it leaves the perimeter of the location (geo fencing), so a lost phone outside of the area can not be used for entry.
- the mobile phone 10 connects to a server to get the ID credentials (userid/password can be used to secure that data, and the phone can then get a local copy of the ID data), and instead of presenting a badge, carrying the mobile phone will be enough to be identified.
- the BLE standard preferably used in the present device includes the possibility to transmit at different RF levels, and also include the actual transmit energy level in announcements.
- standard mobile phone, bluetooth BLE stack implementations, API and libraries support "ranging” by reading the RSSI level from the RF receivers, and calculating, based on that information PLUS the transmitted RSSI level, the approximate distance.
- this functionality can be used to make sure the above mentioned “copy ID into local memory” function can only be used if the mobile is within very close proximity of the device 9, however, later, for the "hands free” solution (sending back the ID for entry), a larger distance is allowed.
- the system can even be used as a modern "immobilizer” or locking system for trucks, machines etc.
- a "driver” can safely go to a coffee break, because without his mobile phone, the truck will not start.
- the mobile phone When he returns to his car, the mobile phone will "see” the truck, and go online to request an authorization key that the user may operate the truck, which then, upon approval, is encrypted with the car's security credentials and sent via the invention into the truck to unlock it.
- the main use of the disclosed interception unit is the upgrade of current access control installations using readers, to increase security or usability, by adding the mobile phone component with its readers and interfaces, and the possibility to go online for recording and decision making at a central location.
- the invention enables legacy access control systems to be part of the "internet of things" without the central controllers to be touched.
- 1 reader unit 11 wireless communication 2 access controller between interception unit and 3 unlocking device mobile handheld device 4 1st control line between 12 power supply unit reader unit and access 13 radiofrequency interface, controller Bluetooth low energy 5 2nd control line between 14 reader interface access controller and 15 controller interface unlocking device 16 housing 6 token (batch, key) 17 central control unit 7 management unit 18 wireless communication 8 communication between between interception unit and access controller and mobile handheld device management unit 19 wireless communication 9 interception unit between mobile handheld 10 mobile handheld device device and overall control
Landscapes
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Lock And Its Accessories (AREA)
Claims (10)
- Procédé de mise à niveau d'un système de contrôle d'accès existant, ledit système de contrôle d'accès existant comprenant au moins un point d'accès qui est commandé par une unité de lecture (1) pour lire des informations d'autorisation à partir d'un jeton portable (6) et un dispositif de déverrouillage correspondant (3), dans lequel l'unité de lecture (1) est en connexion câblée via au moins une 1ère ligne de commande (4) connectée de manière communicative à un contrôleur d'accès (2), dans lequel ledit contrôleur d'accès (2) est en connexion câblée via au moins une 2ème ligne de commande (5) connectée de manière communicative audit dispositif de déverrouillage (3), et dans lequel ledit contrôleur d'accès (2) commande l'état de verrouillage dudit dispositif de déverrouillage (3) via ladite 2ème ligne de commande (5) en vérifiant les informations d'identification transmises via la 1ère ligne de commande (4) depuis ladite unité de lecture (1),
dans lequel la méthode de mise à niveau comprend les étapes suivantesen interposant dans au moins une 1ère ligne de contrôle (4) une unité d'interception (9),ladite unité d'interception (9) adaptée et permettant de recevoir et, si nécessaire après avoir temporairement retenu lesdites informations d'identification de ladite unité de lecture (1), de ne les transmettre à l'unité de contrôle d'accès (2) qu'une fois que ladite unité d'interception (9) a vérifié l'autorisation d'accès de manière indépendante via une 2ème communication avec un détenteur dudit jeton (6),dans lequel, pour ce faire, l'unité d'interception (9) comprend au moins une interface radiofréquence (13) avec laquelle elle établit un canal de communication sans fil (18) entre ladite unité d'interception (9) et un dispositif portatif mobile (10) dudit titulaire,dans laquelle ladite vérification par l'unité d'interception (9) implique la récupération d'informations sur l'autorisation d'accès dudit titulaire via ledit appareil portable (10),dans laquelle l'interface radiofréquence (13) est une interface de réseau local sans fil (WLAN), une interface Bluetooth, Bluetooth smart, y compris une interface Bluetooth à faible consommation d'énergie,et dans lequel la récupération d'informations concernant l'autorisation d'accès dudit titulaire via ledit dispositif portable mobile (10) comprend l'étape consistant à établir une communication sans fil externe (19) utilisant un WLAN ou un canal de télécommunication par ledit dispositif portable mobile (10) vers une autorité de contrôle globale qui vérifie l'autorisation d'accès de manière indépendante et transmet, si l'accès est accordé, une autorisation correspondante en retour audit dispositif portable mobile (10) et directement et/ou en direct via ladite interface radiofréquence (13) vers l'unité d'interception. - Procédé selon la revendication 1, dans lequel la récupération d'informations concernant l'autorisation d'accès dudit titulaire par l'intermédiaire dudit dispositif portable mobile (10) comprend les étapes consistant à identifier ledit titulaire et/ou ledit dispositif portable mobile (10) au moyen d'une entrée donnée par ledit titulaire dans ledit dispositif portable mobile (10), et/ou au moyen de la lecture d'un numéro d'identification non ambigu dudit dispositif portable mobile (10), dans lequel ladite entrée est de préférence au moins l'une de : un code pin, une information biométrique recueillie par ledit dispositif mobile, telle qu'une empreinte digitale, une image, en particulier une image de visage, une information de position, ou une combinaison de celles-ci.
- Procédé selon l'une des revendications précédentes, dans lequel l'unité d'interception (9), après avoir vérifié l'autorisation d'accès, transmet ladite information d'identification à partir de ladite unité de lecture (1) identique à celle initialement reçue de ladite unité de lecture (1) ou d'une manière modifiée.
- Procédé selon l'une des revendications précédentes, dans lequel la vérification de l'autorisation d'accès par l'unité d'interception (9) de manière autonome et/ou par une autorité de contrôle globale via une communication avec celle-ci au moyen du dispositif portable mobile (10) implique l'autorisation et/ou la détermination d'au moins un des éléments suivants : temps d'accès, fréquence d'accès, numéro d'accès, statut de l'autorisation d'accès du détenteur, statut de confiance du détenteur, conformité des données concernant le détenteur ou provenant du détenteur extraites par ledit dispositif portable mobile (10) avec une base de données interne, localisation du dispositif portable mobile déterminée par GPS (géo-clôture) ou une combinaison de ces éléments.
- Procédé selon l'une des revendications précédentes, dans lequel l'interface radiofréquence (13) établit automatiquement une connexion radiofréquence avec ledit dispositif portable mobile (10) une fois qu'il est à proximité suffisante de l'unité d'interception (9) et, si nécessaire, une fois la connexion établie, augmente le niveau de puissance de la veille de bas niveau à haut niveau.
- Procédé selon l'une des revendications précédentes, dans lequel l'unité d'interception (9) est munie de moyens pour déterminer la distance entre l'unité d'interception (9) et le dispositif portable mobile (10), et dans lequel cette distance est prise en compte comme paramètre pour l'octroi de l'accès.
- Procédé selon l'une des revendications précédentes, dans lequel l'unité d'interception (9) comprend une unité centrale indépendante, une mémoire vive (RAM), une mémoire morte (ROM), des éléments de stockage de données volatils et/ou non volatils, une unité de cryptage, une alimentation électrique autonome et/ou basée sur le réseau, si nécessaire un élément d'horloge en temps réel, et éventuellement une unité centrale secondaire, une mémoire vive (RAM), un élément de stockage de données.
- Procédé selon l'une des revendications précédentes, dans lequel la transmission par ladite première ligne de communication (4) est série, Wiegand ou horloge et données, et/ou dans lequel la communication par ladite première ligne de commande (4), et/ou par ladite deuxième ligne de commande (5), et/ou entre (18) l'unité d'interception (9) et le dispositif portable mobile (10) et/ou entre (19) le dispositif portable mobile (10) et la commande globale est cryptée.
- Procédé selon l'une des revendications précédentes, dans lequel, une fois autorisé par au moins l'un des éléments suivants : jeton (9), appareil mobile de poche (10), vérification indépendante par le contrôle global ou une combinaison de ceux-ci, l'accès peut être accordé sans avoir besoin du jeton (9) et uniquement par ledit appareil mobile de poche (10).
- Système de contrôle d'accès comprenant au moins un point d'accès qui est contrôlé par une unité de lecture (1) configurée pour lire des informations d'autorisation à partir d'un jeton portable (6) et un dispositif de déverrouillage correspondant (3), dans lequel l'unité de lecture (1) est en connexion câblée via au moins une première ligne de contrôle (4) connectée de manière communicative à un contrôleur d'accès (2), dans lequel ledit contrôleur d'accès est en connexion câblée via au moins une deuxième ligne de contrôle (5) connectée de manière communicative audit dispositif de déverrouillage (3), et dans lequel ledit contrôleur d'accès (2) contrôle l'état de verrouillage dudit dispositif de déverrouillage (3) via ladite 2ème ligne de contrôle (5) en vérifiant les informations d'identification transmises via la 1ère ligne de contrôle (4) depuis ladite unité de lecture (1), le système de contrôle d'accès étant mis à niveau en utilisant une méthode selon l'une des revendications précédentes, comprenant en outre une unité d'interception, un dispositif portable mobile et une autorité de contrôle globale, dans lequel l'unité d'interception est interposée dans la au moins une première ligne de contrôle et ladite unité d'interception (9) est adaptée à et permet de recevoir et, si nécessaire après avoir temporairement retenu lesdites informations d'identification de ladite unité de lecture (1), ne la transmettant à l'unité de contrôle d'accès (2) qu'une fois que ladite unité d'interception (9) a vérifié l'autorisation d'accès de manière indépendante via une 2ème communication avec un détenteur dudit jeton (6), dans lequel pour ce faire l'unité d'interception (9) comprend au moins une interface radiofréquence (13) avec laquelle elle établit un canal de communication sans fil (18) entre ladite unité d'interception (9) et un dispositif portable mobile (10) dudit détenteur, dans lequel ladite vérification par l'unité d'interception (9) implique la récupération d'informations sur l'autorisation d'accès dudit titulaire via ledit dispositif portable (10), dans lequel l'interface radiofréquence (13) est une interface de réseau local sans fil (WLAN), une interface Bluetooth ou une interface intelligente Bluetooth, comprenant une interface Bluetooth à faible consommation d'énergie, et dans lequel, afin de récupérer des informations concernant l'autorisation d'accès dudit dispositif portable mobile (10), celui-ci est configuré pour établir une communication sans fil externe (19) utilisant un réseau local sans fil (WLAN) ou une télécommunication avec l'autorité de contrôle globale qui est configurée pour vérifier l'autorisation d'accès de manière indépendante et est configurée pour transmettre, si l'accès est accordé, une autorisation correspondante audit dispositif portable mobile (10) et directement et/ou en direct via ladite interface radiofréquence (13) à l'unité d'interception.
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| EP15156996.9A EP3062294B1 (fr) | 2015-02-27 | 2015-02-27 | Procédé et dispositifs permettant l'amélioration d'un système de commande d'accès existant |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| EP15156996.9A EP3062294B1 (fr) | 2015-02-27 | 2015-02-27 | Procédé et dispositifs permettant l'amélioration d'un système de commande d'accès existant |
Publications (2)
| Publication Number | Publication Date |
|---|---|
| EP3062294A1 EP3062294A1 (fr) | 2016-08-31 |
| EP3062294B1 true EP3062294B1 (fr) | 2021-04-14 |
Family
ID=52648826
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP15156996.9A Active EP3062294B1 (fr) | 2015-02-27 | 2015-02-27 | Procédé et dispositifs permettant l'amélioration d'un système de commande d'accès existant |
Country Status (1)
| Country | Link |
|---|---|
| EP (1) | EP3062294B1 (fr) |
Families Citing this family (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US9666000B1 (en) | 2014-01-04 | 2017-05-30 | Latchable, Inc. | Methods and systems for access control and awareness management |
| WO2017079438A1 (fr) * | 2015-11-04 | 2017-05-11 | Latchable, Inc. | Systèmes et procédés de contrôle d'accès dans un espace physique |
| KR102745825B1 (ko) | 2017-05-17 | 2024-12-20 | 래치 시스템즈, 인크. | 모니터링 및 컨시어지 서비스를 위한 확장가능 시스템들 및 방법들 |
| DE102018122758A1 (de) | 2018-09-17 | 2020-03-19 | ASTRA Gesellschaft für Asset Management mbH & Co. KG | Identifizierungsadapter und Identifizierungseinrichtung |
| GB2634559A (en) * | 2023-10-13 | 2025-04-16 | Paxton Access Ltd | Access control system |
Citations (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| EP2365477A1 (fr) * | 2007-03-14 | 2011-09-14 | Dexrad (Proprietary) Limited | Appareil d'identification personelle pour des transactions securisées |
Family Cites Families (7)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US5679945A (en) * | 1995-03-31 | 1997-10-21 | Cybermark, L.L.C. | Intelligent card reader having emulation features |
| US7079007B2 (en) * | 2002-04-19 | 2006-07-18 | Cross Match Technologies, Inc. | Systems and methods utilizing biometric data |
| US6944768B2 (en) * | 2002-04-19 | 2005-09-13 | Cross Match Technologies, Inc. | System and methods for access control utilizing two factors to control access |
| US6715674B2 (en) * | 2002-08-27 | 2004-04-06 | Ultra-Scan Corporation | Biometric factor augmentation method for identification systems |
| DE20309254U1 (de) * | 2003-06-16 | 2003-11-06 | SCM Microsystems GmbH, 85737 Ismaning | Zugangssystem |
| WO2012151290A1 (fr) * | 2011-05-02 | 2012-11-08 | Apigy Inc. | Systèmes et procédés de commande d'un mécanisme de verrouillage à l'aide d'un dispositif électronique portable |
| US9111401B2 (en) * | 2012-11-29 | 2015-08-18 | Hid Global Gmbh | Interactive reader commander |
-
2015
- 2015-02-27 EP EP15156996.9A patent/EP3062294B1/fr active Active
Patent Citations (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| EP2365477A1 (fr) * | 2007-03-14 | 2011-09-14 | Dexrad (Proprietary) Limited | Appareil d'identification personelle pour des transactions securisées |
Also Published As
| Publication number | Publication date |
|---|---|
| EP3062294A1 (fr) | 2016-08-31 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US10755507B2 (en) | Systems and methods for multifactor physical authentication | |
| CN114898482B (zh) | 针对利用虚拟卡数据的进入控制系统的远程编程 | |
| US11164413B2 (en) | Access control system with secure pass-through | |
| US10171444B1 (en) | Securitization of temporal digital communications via authentication and validation for wireless user and access devices | |
| CN104966336B (zh) | 智能锁及智能锁的授权管理方法和装置 | |
| US9659422B2 (en) | Using temporary access codes | |
| US20180262891A1 (en) | Electronic access control systems and methods using near-field communications, mobile devices and cloud computing | |
| EP2657917B1 (fr) | Système et procédé d'enregistrement de clé électronique | |
| KR102085975B1 (ko) | 도어락 정보 관리 시스템 및 그 구동방법 | |
| KR102427635B1 (ko) | 동적 키 액세스 제어 시스템들, 방법들 및 장치 | |
| US11477649B2 (en) | Access control system with trusted third party | |
| US20120169461A1 (en) | Electronic physical access control with remote authentication | |
| CN108510626B (zh) | 一种动态密码门禁管理方法及其管理系统 | |
| JP2004528655A (ja) | 周波数方式 | |
| EP3062294B1 (fr) | Procédé et dispositifs permettant l'amélioration d'un système de commande d'accès existant | |
| CN107005798A (zh) | 在与多个进入控制交互时捕获用户意图 | |
| CN106652109A (zh) | 智能锁控制方法、装置及锁管理服务器 | |
| KR101637516B1 (ko) | 출입 제어 방법 및 장치 | |
| KR20150056711A (ko) | 출입자 생체정보를 가지는 스마트 출입카드를 이용한 출입 관리 시스템 및 방법 | |
| CN112041525A (zh) | 密钥信息生成系统及密钥信息生成方法 | |
| US20200026829A1 (en) | Biometric access control identification card | |
| US12083992B2 (en) | Methods for shared vehicle access | |
| CN113763603B (zh) | 信息处理装置、方法、计算机可读存储介质及便携终端 | |
| CN114365126B (zh) | 生物体认证系统和生物体认证装置 | |
| US10645070B2 (en) | Securitization of temporal digital communications via authentication and validation for wireless user and access devices |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR |
|
| AX | Request for extension of the european patent |
Extension state: BA ME |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: REQUEST FOR EXAMINATION WAS MADE |
|
| 17P | Request for examination filed |
Effective date: 20170214 |
|
| RBV | Designated contracting states (corrected) |
Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: EXAMINATION IS IN PROGRESS |
|
| 17Q | First examination report despatched |
Effective date: 20180202 |
|
| REG | Reference to a national code |
Ref country code: DE Ref legal event code: R079 Ref document number: 602015068011 Country of ref document: DE Free format text: PREVIOUS MAIN CLASS: G07C0009000000 Ipc: G07C0009270000 |
|
| GRAP | Despatch of communication of intention to grant a patent |
Free format text: ORIGINAL CODE: EPIDOSNIGR1 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: GRANT OF PATENT IS INTENDED |
|
| RIC1 | Information provided on ipc code assigned before grant |
Ipc: G07C 9/27 20200101AFI20201028BHEP |
|
| INTG | Intention to grant announced |
Effective date: 20201116 |
|
| GRAS | Grant fee paid |
Free format text: ORIGINAL CODE: EPIDOSNIGR3 |
|
| GRAA | (expected) grant |
Free format text: ORIGINAL CODE: 0009210 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE PATENT HAS BEEN GRANTED |
|
| AK | Designated contracting states |
Kind code of ref document: B1 Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR |
|
| RAP3 | Party data changed (applicant data changed or rights of an application transferred) |
Owner name: QIBIXX AG |
|
| REG | Reference to a national code |
Ref country code: GB Ref legal event code: FG4D |
|
| REG | Reference to a national code |
Ref country code: CH Ref legal event code: EP |
|
| REG | Reference to a national code |
Ref country code: DE Ref legal event code: R096 Ref document number: 602015068011 Country of ref document: DE |
|
| REG | Reference to a national code |
Ref country code: IE Ref legal event code: FG4D |
|
| REG | Reference to a national code |
Ref country code: AT Ref legal event code: REF Ref document number: 1383119 Country of ref document: AT Kind code of ref document: T Effective date: 20210515 |
|
| REG | Reference to a national code |
Ref country code: LT Ref legal event code: MG9D |
|
| REG | Reference to a national code |
Ref country code: AT Ref legal event code: MK05 Ref document number: 1383119 Country of ref document: AT Kind code of ref document: T Effective date: 20210414 |
|
| REG | Reference to a national code |
Ref country code: NL Ref legal event code: MP Effective date: 20210414 |
|
| PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: HR Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20210414 Ref country code: BG Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20210714 Ref country code: AT Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20210414 Ref country code: FI Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20210414 Ref country code: NL Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20210414 Ref country code: LT Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20210414 |
|
| PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: ES Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20210414 Ref country code: PT Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20210816 Ref country code: NO Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20210714 Ref country code: PL Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20210414 Ref country code: RS Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20210414 Ref country code: SE Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20210414 Ref country code: LV Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20210414 Ref country code: IS Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20210814 Ref country code: GR Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20210715 |
|
| REG | Reference to a national code |
Ref country code: DE Ref legal event code: R097 Ref document number: 602015068011 Country of ref document: DE |
|
| PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: RO Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20210414 Ref country code: EE Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20210414 Ref country code: CZ Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20210414 Ref country code: DK Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20210414 Ref country code: SM Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20210414 Ref country code: SK Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20210414 |
|
| PLBE | No opposition filed within time limit |
Free format text: ORIGINAL CODE: 0009261 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: NO OPPOSITION FILED WITHIN TIME LIMIT |
|
| 26N | No opposition filed |
Effective date: 20220117 |
|
| PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: IS Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20210814 Ref country code: AL Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20210414 |
|
| PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: IT Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20210414 |
|
| PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: MC Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20210414 |
|
| REG | Reference to a national code |
Ref country code: BE Ref legal event code: MM Effective date: 20220228 |
|
| PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: LU Free format text: LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES Effective date: 20220227 |
|
| PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: IE Free format text: LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES Effective date: 20220227 |
|
| PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: BE Free format text: LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES Effective date: 20220228 |
|
| P01 | Opt-out of the competence of the unified patent court (upc) registered |
Effective date: 20230505 |
|
| PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: HU Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT; INVALID AB INITIO Effective date: 20150227 |
|
| PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: MK Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20210414 Ref country code: CY Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20210414 |
|
| PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: TR Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20210414 |
|
| PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: MT Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20210414 |
|
| REG | Reference to a national code |
Ref country code: DE Ref legal event code: R081 Ref document number: 602015068011 Country of ref document: DE Owner name: BARIX AG, CH Free format text: FORMER OWNER: QIBIXX AG, BUCHS, CH |
|
| REG | Reference to a national code |
Ref country code: GB Ref legal event code: 732E Free format text: REGISTERED BETWEEN 20250703 AND 20250709 |
|
| REG | Reference to a national code |
Ref country code: DE Ref legal event code: R082 Ref document number: 602015068011 Country of ref document: DE Representative=s name: TERGAU & WALKENHORST INTELLECTUAL PROPERTY GMB, DE |
|
| REG | Reference to a national code |
Ref country code: CH Ref legal event code: U11 Free format text: ST27 STATUS EVENT CODE: U-0-0-U10-U11 (AS PROVIDED BY THE NATIONAL OFFICE) Effective date: 20260301 |
|
| PGFP | Annual fee paid to national office [announced via postgrant information from national office to epo] |
Ref country code: GB Payment date: 20260219 Year of fee payment: 12 |
|
| PGFP | Annual fee paid to national office [announced via postgrant information from national office to epo] |
Ref country code: DE Payment date: 20260218 Year of fee payment: 12 |
|
| PGFP | Annual fee paid to national office [announced via postgrant information from national office to epo] |
Ref country code: FR Payment date: 20260218 Year of fee payment: 12 |
|
| PGFP | Annual fee paid to national office [announced via postgrant information from national office to epo] |
Ref country code: CH Payment date: 20260301 Year of fee payment: 12 |