HK1248024B - Lock and methods for redundant access control - Google Patents
Lock and methods for redundant access control Download PDFInfo
- Publication number
- HK1248024B HK1248024B HK18107385.8A HK18107385A HK1248024B HK 1248024 B HK1248024 B HK 1248024B HK 18107385 A HK18107385 A HK 18107385A HK 1248024 B HK1248024 B HK 1248024B
- Authority
- HK
- Hong Kong
- Prior art keywords
- access
- user
- lock
- button
- administrator
- Prior art date
Links
Description
相关申请的交叉引用CROSS-REFERENCE TO RELATED APPLICATIONS
本申请要求于2016年5月5日提交的美国专利申请第15/147,759号的优先权,该美国专利申请要求于2015年7月6日提交的美国临时专利申请第62/189,193号的优先权,这两个专利申请全部内容通过引用并入本文。本申请涉及于2016年3月3日提交的美国专利申请第15/060,327号,其全部内容也通过引用并入本文。This application claims priority to U.S. Patent Application No. 15/147,759, filed May 5, 2016, which claims priority to U.S. Provisional Patent Application No. 62/189,193, filed July 6, 2015, both of which are incorporated herein by reference in their entireties. This application is related to U.S. Patent Application No. 15/060,327, filed March 3, 2016, which is also incorporated herein by reference in its entirety.
技术领域Technical Field
本发明涉及锁和移动设备,更具体地,涉及使用移动设备、接入控制冗余信道和可移除无线锁按钮控制对锁的接入的系统和方法。The present invention relates to locks and mobile devices, and more particularly, to systems and methods for controlling access to a lock using a mobile device, an access control redundant channel, and a removable wireless lock button.
背景技术Background Art
使用机械或机电钥匙和锁的进入控制系统持续遭受若干缺点。具体而言,机械锁和钥匙不能针对盗窃、丢失、非法进入或不期望的复制提供强大的防护。例如,如果钥匙丢失或被盗,锁通常会被替换。机械锁和钥匙也不提供关于钥匙如何或何时被使用的信息-或者如果有的话该信息也不是近实时的。这种类型的信息对于个人来说可能是非常需要的,并且对于某些企业来说可能是关键的。使用电子锁和钥匙系统提供接入信息的系统通常硬件连接到门框中。此外,硬件连接的解决方案完全依赖于直接或替代形式的电源和数据连接以高效地运行。硬件连接系统通常安装成本高,在温度范围变化很大的室外环境中表现不佳,并且与通用系统(诸如欧规锁芯(Europrofile cylinder))不兼容。此外,大多数传统的机械锁系统使用的钥匙仅可用于进入一个门,因此,需要通过多个锁的用户由于不得不携带一串用于其相应锁的不同钥匙而不方便。Access control systems using mechanical or electromechanical keys and locks continue to suffer from several drawbacks. Specifically, mechanical locks and keys do not provide robust protection against theft, loss, unauthorized entry, or unwanted duplication. For example, if a key is lost or stolen, the lock is typically replaced. Mechanical locks and keys also do not provide information about how or when the key was used—or, if available, this information is not available in near real-time. This type of information can be highly desirable for individuals and critical for certain businesses. Systems that provide access information using electronic locks and key systems are typically hardwired into the door frame. Furthermore, hardwired solutions rely entirely on direct or alternative power and data connections to operate efficiently. Hardwired systems are often expensive to install, perform poorly in outdoor environments with widely varying temperatures, and are incompatible with universal systems (such as Europrofile cylinders). Furthermore, most conventional mechanical lock systems use keys that can only be used to access a single door, making it inconvenient for users who need to access multiple locks to carry a set of different keys for their respective locks.
移动设备的无线通信能力(诸如例如NFC和蓝牙之类的)提供了改善使用机械或机电钥匙的接入控制系统的机遇。具体地说,移动设备的近场通信(NFC)、蓝牙或类似的无线能力可以通过使用移动设备作为电子密钥来适配作进入控制系统。此外,在一些移动设备上近实时地传送接入数据的能力提供了传递关于密钥如何以及何时被使用以及锁被打开的信息的机会。The wireless communication capabilities of mobile devices, such as NFC and Bluetooth, offer opportunities to improve access control systems that use mechanical or electromechanical keys. Specifically, near-field communication (NFC), Bluetooth, or similar wireless capabilities of mobile devices can be adapted for use as access control systems by using the mobile device as an electronic key. Furthermore, the ability to transmit access data in near real time on some mobile devices offers the opportunity to communicate information about how and when keys are used and locks are opened.
然而,将移动设备集成到接入控制系统中仍然存在若干缺点。与机械锁和钥匙系统一样,移动设备不能对于盗窃和非法进入提供强大的防护。此外,移动设备通常依赖于电池作为其电源,在用户打开锁之前电池经常会耗尽电量。此外,对于一些企业来说,在其所有资产中部署移动设备可能是昂贵和不切实际的。此外,无论移动设备是否耗尽电量,在范围之外,还是由于其它原因不可用,用户可能无法接入锁或锁中存储的信息。However, integrating mobile devices into access control systems still has several drawbacks. Like mechanical lock and key systems, mobile devices don't offer the same robust protection against theft and unauthorized entry. Furthermore, mobile devices typically rely on batteries for power, which often run out before the user can open the lock. Furthermore, for some businesses, deploying mobile devices across all of their assets can be expensive and impractical. Furthermore, whether a mobile device runs out of power, is out of range, or otherwise unavailable, the user may be unable to access the lock or the information stored within it.
另外,为了将移动设备集成到接入控制系统中,锁通常配备有NFC和无线通信设备。然而,这些设备需要连续可靠的电源。虽然电池电源适用于NFC或无线设备(如移动设备),但是它们可能会意外耗尽电量或遭受其他故障,使用户无法通过移动设备打开锁。Additionally, to integrate mobile devices into access control systems, locks are often equipped with NFC and wireless communication devices. However, these devices require a continuous and reliable power source. While battery power is suitable for NFC or wireless devices such as mobile devices, they can unexpectedly run out of power or suffer other malfunctions, preventing users from opening the lock with their mobile devices.
因此,需要一种作为机械锁的安全可靠的替代方案的接入控制系统,以及在近实时地提供使用信息的同时提供冗余接入信道,并在故障或放电的情况下提供冗余的电力供应的移动设备。接入控制系统应易于安装,减少使用的有线连接数量,并可在长时间段内独立地运行。接入控制系统的冗余信道应允许能或不能使用普通电话、智能手机、平板电脑和类似移动设备的用户接入锁。此外,接入控制系统应允许锁与网络以及连接到网络的用户和设备直接且实时地通信。Therefore, there is a need for an access control system that provides a secure and reliable alternative to mechanical locks, as well as a mobile device that provides near-real-time usage information while offering redundant access channels and redundant power supplies in the event of a failure or discharge. The access control system should be easy to install, reduce the number of wired connections used, and operate independently for extended periods of time. The access control system's redundant channels should allow users with or without access to regular phones, smartphones, tablets, and similar mobile devices to access the lock. Furthermore, the access control system should allow the lock to communicate directly and in real time with the network, as well as with users and devices connected to the network.
发明内容Summary of the Invention
在各种实施例中,本发明提供了用于控制和监视接入控制系统的系统、方法和装置。根据本发明的一些实施例,接入控制系统包括提供冗余接入控制的智能锁。智能锁包括存储介质、电源、硬件处理器、具有接合门栓的凸轮的锁芯以及接合凸轮以解锁门栓的按钮。In various embodiments, the present invention provides systems, methods, and apparatus for controlling and monitoring an access control system. According to some embodiments of the present invention, the access control system includes a smart lock that provides redundant access control. The smart lock includes a storage medium, a power supply, a hardware processor, a lock cylinder having a cam that engages a deadbolt, and a button that engages the cam to unlock the deadbolt.
按钮包括用于接收认证信息的多个冗余接入信道。冗余接入信道可以包括用于接收生物特征信息的生物特征扫描器、密码小键盘和/或用于从移动设备接收令牌并向移动设备发送应答的无线收发机。The button includes multiple redundant access channels for receiving authentication information. The redundant access channels may include a biometric scanner for receiving biometric information, a PIN pad, and/or a wireless transceiver for receiving a token from a mobile device and sending a reply to the mobile device.
智能锁被配置为基于由管理员确定的一组规则来验证从密码小键盘、生物特征扫描器和/或移动设备接收的认证信息,并且如果用户通过多个冗余接入信道中的第一信道被认证,则解锁门栓。如果用户无法通过第一信道打开智能锁,则启用智能锁以允许通过多个冗余接入信道中的第二信道接入。以这种方式,当用户不再能够使用第一信道接入智能锁时,用户可以使用第二信道打开锁。The smart lock is configured to verify authentication information received from a PIN keypad, biometric scanner, and/or mobile device based on a set of rules determined by an administrator and unlock the deadbolt if the user is authenticated through a first of multiple redundant access channels. If the user is unable to open the smart lock through the first channel, the smart lock is enabled to allow access through a second of the multiple redundant access channels. In this way, when the user can no longer access the smart lock using the first channel, the user can use the second channel to open the lock.
接入控制系统可以包括一个或多个智能锁。这些系统可以由请求接入智能锁的用户接入,并由限制对智能锁的接入的主人或管理员控制。在一些实施例中,用户可以接入,并且主人或管理员可以近实时地从其各自的移动设备控制对智能锁的接入。主人和管理员可以使用移动设备配置控制用户如何和何时打开智能锁的规则和接入权限。以这种方式,可以提供允许主人和管理员近实时地控制和监视用户的接入控制系统,而无需将硬件连接的互联网或数据连接安装到门或锁上。由于锁芯适于配合标准槽,因此门框和锁系统不需要修改或重装。Access control systems may include one or more smart locks. These systems can be accessed by users who request access to the smart locks and controlled by owners or administrators who restrict access to the smart locks. In some embodiments, users can access and the owner or administrator can control access to the smart locks from their respective mobile devices in near real time. Owners and administrators can use mobile devices to configure rules and access permissions that control how and when users open the smart locks. In this way, an access control system can be provided that allows owners and administrators to control and monitor users in near real time without having to install a hard-wired internet or data connection to the door or lock. Because the lock cylinder fits into a standard slot, the door frame and lock system do not need to be modified or reinstalled.
在本发明的一些方面,主人或管理员可以配置限制用户如何接入智能锁的规则和接入权限。接入权限指定用户可以接入哪些锁,并且可配置规则指定在打开智能锁之前必须满足的条件。因此,规则允许主人或管理员根据位置和时间来限制用户的接入。以这种方式,可以使主人或管理员精确地控制用户如何打开智能锁。In some aspects of the present invention, an owner or administrator can configure rules and access permissions that restrict how users access a smart lock. Access permissions specify which locks a user can access, and configurable rules specify conditions that must be met before a smart lock can be opened. Thus, rules allow an owner or administrator to restrict user access based on location and time of day. In this way, an owner or administrator can precisely control how a user can open a smart lock.
每次尝试打开智能锁时,主人和管理员可能要求用户请求密码或令牌。当用户提交请求时,主人或管理员可以近实时地接收请求,并确定是否授予用户接入权限。主人或管理员可能要求用户提供另外的认证信息,例如口令,以确保用户的身份。如果主人或管理员确定授予用户接入权限,则将令牌或密码近实时地发送给用户。在一些实施例中,可以基于触发事件发送请求。因此,主人或管理员可以根据具体情况控制用户的接入。Each time a user attempts to open a smart lock, the owner or administrator may require the user to request a password or token. When a user submits a request, the owner or administrator can receive it in near real time and determine whether to grant access to the user. The owner or administrator may require the user to provide additional authentication information, such as a password, to confirm the user's identity. If the owner or administrator determines to grant access, the token or password is sent to the user in near real time. In some embodiments, requests can be sent based on triggering events. This allows the owner or administrator to control user access based on the specific situation.
密码可以是固定的或动态的。动态密码可使主人或管理员能够授予用户对锁的一次性使用接入或限时接入。密码可以从移动设备无线地提供给锁,或者手动输入到小键盘上。因此,即使用户的移动设备不可用,用户也能够利用密码接入锁。Passwords can be fixed or dynamic. Dynamic passwords allow the owner or administrator to grant a user one-time or time-limited access to the lock. The password can be provided to the lock wirelessly from a mobile device or manually entered into a keypad. This allows the user to access the lock using the password even if their mobile device is unavailable.
在本发明的一些实施例中,智能锁的无线收发机被配置为直接且近实时地向移动设备以及网络设备、控制接入服务器或管理员设备进行通信。然后,锁可以从网络设备、控制接入服务器或管理员设备接收指示锁准许或拒绝对用户的接入的通信。In some embodiments of the present invention, the wireless transceiver of the smart lock is configured to communicate directly and in near real time to the mobile device and the network device, control access server, or administrator device. The lock can then receive communications from the network device, control access server, or administrator device indicating whether the lock grants or denies access to the user.
根据本发明的一些实施例,智能锁包括被配置为创建蜂窝宽带连接并且近实时地与管理员设备或中央接入服务器通信的无线调制解调器。当锁接收到令牌、生物特征扫描或密码时,它可以基于一组可配置规则来发送接入锁的请求。然后,锁可以近实时地从管理员设备或中央接入服务器接收准许或拒绝接入请求的指令。以这种方式,如果用户的移动设备不能与管理员设备或中央接入服务器通信,则该锁可以自己建立到管理员设备或中央接入服务器的连接。因此,锁可以在不依赖于用户的移动设备来中继通信的情况下与管理员设备或中央接入服务器进行通信。According to some embodiments of the present invention, a smart lock includes a wireless modem configured to establish a cellular broadband connection and communicate with an administrator device or central access server in near real time. When the lock receives a token, biometric scan, or password, it can send a request to access the lock based on a set of configurable rules. The lock can then receive instructions from the administrator device or central access server in near real time to grant or deny the access request. In this way, if the user's mobile device is unable to communicate with the administrator device or central access server, the lock can establish a connection to the administrator device or central access server on its own. Thus, the lock can communicate with the administrator device or central access server without relying on the user's mobile device to relay communications.
在本发明的其它实施例中,智能锁还可以被配置为与将通信中继到管理员设备或中央接入服务器的网络设备进行通信。网络设备可以是使用近场无线发射机或无线LAN来建立短距离无线连接的无线接收机、路由器、中继器或类似设备。因此,智能锁可以类似地创建连接以与管理员设备或中央接入服务器通信,而不依赖于用户的移动设备来中继通信。In other embodiments of the present invention, the smart lock can also be configured to communicate with a network device that relays communications to an administrator device or a central access server. The network device can be a wireless receiver, router, repeater, or similar device that uses a near-field wireless transmitter or wireless LAN to establish a short-range wireless connection. Thus, the smart lock can similarly establish a connection to communicate with the administrator device or central access server without relying on the user's mobile device to relay the communication.
智能锁可以包括惯性模块。该惯性模块被配置为确定指示门是否已经打开或关闭的门状态。锁可以类似地被配置为确定指示门栓的锁定或解锁位置的门栓状态。该锁可以近实时地将门状态和门栓状态传送到管理员设备或中央接入服务器。因此,管理员设备或中央接入服务器可以确定门是否已经被打开、关闭、锁定或解锁。A smart lock can include an inertia module. The inertia module is configured to determine a door status, indicating whether the door is open or closed. Similarly, the lock can be configured to determine a bolt status, indicating whether the bolt is locked or unlocked. The lock can transmit the door status and bolt status to an administrator device or a central access server in near real time. Thus, the administrator device or central access server can determine whether the door is open, closed, locked, or unlocked.
根据本发明的一些实施例,智能锁的按钮可以是可移除的和可再充电的。该按钮可以包括与再充电站的再充电接口相匹配的再充电接口。当按钮的电源不足时,用户可以取出按钮,并用再充电站对按钮进行再充电。在本发明的另外的实施例中,该按钮可以包括允许用户从例如外部设备或再充电站为该按钮供电的I/O端口。I/O端口还允许用户获取存储在按钮上的接入信息。因此,当按钮在再充电站上进行再充电时,充电按钮可以通过I/O端口获取存储在按钮上的接入信息。在一些实施例中,再充电站耦合到使其能够将接入信息传送到管理员设备或中央接入服务器的网络连接。According to some embodiments of the present invention, the button of the smart lock may be removable and rechargeable. The button may include a recharging interface that matches the recharging interface of the recharging station. When the button is out of power, the user can remove the button and recharge the button using the recharging station. In another embodiment of the present invention, the button may include an I/O port that allows the user to power the button from, for example, an external device or a recharging station. The I/O port also allows the user to obtain access information stored on the button. Therefore, when the button is recharging on the recharging station, the charging button can obtain the access information stored on the button through the I/O port. In some embodiments, the recharging station is coupled to a network connection that enables it to transmit the access information to an administrator device or a central access server.
附图说明BRIEF DESCRIPTION OF THE DRAWINGS
参考以下详细描述和附图,可以更好地理解本发明的目的和特征。The objects and features of the present invention can be better understood with reference to the following detailed description and accompanying drawings.
图1A、1B、1C和1D示出了根据本发明的实施例的接入控制系统。1A , 1B, 1C and 1D illustrate an access control system according to an embodiment of the present invention.
图2A、2B、2C和2D示出了根据本发明实施例的用于接入控制系统的智能锁。2A , 2B, 2C, and 2D illustrate a smart lock for an access control system according to an embodiment of the present invention.
图3示出了根据本发明的实施例的具有可再充电电源的智能锁。FIG. 3 illustrates a smart lock with a rechargeable power supply according to an embodiment of the present invention.
图4示出了根据本发明的实施例的用于打开智能锁的过程。FIG4 illustrates a process for opening a smart lock according to an embodiment of the present invention.
图5示出了根据本发明的实施例的在接入控制系统中登记触发事件的过程。FIG5 shows a process of registering a trigger event in an access control system according to an embodiment of the present invention.
图6示出了根据本发明的实施例的接入控制系统中用于控制对智能锁的接入的过程。FIG6 shows a process for controlling access to a smart lock in an access control system according to an embodiment of the present invention.
图7A、7B、7C、7D和7E示出了根据本发明的实施例的接入控制系统中用于控制对智能锁的接入的接口。7A , 7B, 7C, 7D, and 7E illustrate interfaces for controlling access to a smart lock in an access control system according to an embodiment of the present invention.
图8A、8B、8C、8D、8E和8F示出了根据本发明的实施例的接入控制系统中用于控制智能锁的接口。8A , 8B, 8C, 8D, 8E, and 8F illustrate interfaces for controlling a smart lock in an access control system according to an embodiment of the present invention.
图9A、9B和9C示出了根据本发明的实施例的接入控制系统中用于接入智能锁的用户接口。9A , 9B and 9C illustrate a user interface for accessing a smart lock in an access control system according to an embodiment of the present invention.
具体实施方式DETAILED DESCRIPTION
本发明的实施例包括使得用户能够使用冗余接入信道打开锁并允许主人或管理员近实时地控制用户的接入的系统、方法和装置。Embodiments of the present invention include systems, methods, and apparatus that enable a user to open a lock using redundant access channels and allow an owner or administrator to control the user's access in near real time.
在图1A和1B中示出了在向用户提供冗余的接入信道的同时近实时地传送使用信息的示例性接入控制系统。该系统包括一个或多个智能锁104、中央接入服务器105,以及用于接入和控制智能锁的设备101,102和103。用户通过一个或多个接入信道打开智能锁104,如下面更详细描述的。主人和管理员控制用户如何从主人设备101或管理员设备102接入智能锁104。用户可以与主人、管理员通信,并且从用户设备103打开智能锁。用户还可以手动地打开智能锁,而没有对用户设备103的任何需要。中央接入服务器105近实时地中继和存储在用户与主人或管理员之间交换的信息。值得注意的是,“近实时”通信是可能表现为实时或基本上实时发生、但是由于网络基础设施而导致经历轻微的、不明显的或不显著的延迟的通信。当用户不能再通过其中一个接入信道打开智能锁,例如因为接入信道不可用或变得无法操作,用户可以通过其他可用的接入信道打开智能锁。因此,接入控制系统100使得用户能够使用冗余接入信道打开智能锁,并允许主人或管理员近实时地控制用户的接入。Figures 1A and 1B illustrate an exemplary access control system that transmits usage information in near real time while providing redundant access channels to users. The system includes one or more smart locks 104, a central access server 105, and devices 101, 102, and 103 for accessing and controlling the smart locks. Users unlock smart locks 104 via one or more access channels, as described in more detail below. Owners and administrators control how users access smart locks 104 from either owner device 101 or administrator device 102. Users can communicate with the owner or administrator and unlock the smart lock from user device 103. Users can also unlock the smart lock manually without requiring a user device 103. Central access server 105 relays and stores information exchanged between users and owners or administrators in near real time. It is important to note that "near real-time" communication is communication that may appear to occur in real time or substantially real time, but experiences slight, inconspicuous, or insignificant delays due to network infrastructure. If a user is no longer able to unlock the smart lock via one of the access channels, for example because the access channel is unavailable or inoperable, the user can unlock the smart lock via another available access channel. Thus, the access control system 100 enables a user to open a smart lock using redundant access channels and allows an owner or administrator to control access for a user in near real time.
主人设备101和管理员设备102为寻求获得对一个或多个智能锁104的接入的用户创建和分配规则和接入权限。接入权限识别每个用户被授权打开的智能锁104。规则添加在允许用户打开智能锁104之前必须满足的条件。例如,接入权限可以由主人设备101或管理员设备102配置为指定用户可以打开的一组智能锁104,而规则指定用户在什么日期和时间被允许打开特定的智能锁。The master device 101 and the administrator device 102 create and assign rules and access permissions for users seeking to gain access to one or more smart locks 104. Access permissions identify the smart locks 104 that each user is authorized to open. Rules define the conditions that must be met before a user is allowed to open a smart lock 104. For example, access permissions can be configured by the master device 101 or the administrator device 102 to specify a set of smart locks 104 that a user can open, while rules specify the dates and times when a user is allowed to open a specific smart lock.
如图1B所示,主人设备101和管理员设备102还被配置为指定用户可以使用哪些接入信道来提供认证信息以打开智能锁104。如下面更详细地解释的,接入信道可以例如为:将生物特征信息扫描到生物特征扫描器114中,在小键盘115上输入密码,或从移动设备116无线地发送令牌。智能锁可以将任何或所有接入信道的组合提供给用户。例如,用于常规或默认使用的第一接入信道可以是从用户的移动设备116无线地传送令牌,并且第二接入信道和第三接入信道可以分别是生物特征扫描器114和密码小键盘115,其在第一接入信道变得对用户不可用的情况下使用。As shown in FIG1B , the master device 101 and the administrator device 102 are also configured to specify which access channels the user can use to provide authentication information to open the smart lock 104. As explained in more detail below, the access channels can be, for example, scanning biometric information into a biometric scanner 114, entering a password on a keypad 115, or wirelessly sending a token from a mobile device 116. The smart lock can provide a combination of any or all access channels to the user. For example, a first access channel for regular or default use can be wirelessly transmitting a token from the user's mobile device 116, and a second access channel and a third access channel can be a biometric scanner 114 and a password keypad 115, respectively, which are used in the event that the first access channel becomes unavailable to the user.
主人设备101、管理员设备102或用户设备103可以是移动设备、软件服务或软件应用。移动设备可以是例如智能电话、平板电脑或手持设备。移动设备包括触摸屏显示器107、存储介质108和处理器109。在一些实施例中,移动设备包括用于接收和发送RFID、NFC或蓝牙信号,或者通过移动设备的蜂窝或互联网连接的无线收发机110。Master device 101, administrator device 102, or user device 103 can be a mobile device, software service, or software application. The mobile device can be, for example, a smartphone, tablet, or handheld device. The mobile device includes a touchscreen display 107, storage media 108, and a processor 109. In some embodiments, the mobile device includes a wireless transceiver 110 for receiving and transmitting RFID, NFC, or Bluetooth signals, or via the mobile device's cellular or internet connection.
中央接入服务器105可以是基于云的服务器,并且可以连接到远程服务器106。远程服务器106可以包括具有接收用户呼叫和接入请求的代理的呼叫中心。The central access server 105 may be a cloud-based server and may be connected to a remote server 106. The remote server 106 may include a call center with agents that receive user calls and access requests.
在本发明的一些实施例中,移动设备包括NFC元件111,其可以是配备有NFC发射机的SIM卡或SD卡。可将具有NFC功能的SD卡放置在移动设备的SD卡插槽中,为智能手机提供NFC通信能力。类似地,可将具有NFC功能的SIM卡放置在移动设备的SIM卡插槽中,为智能手机提供NFC通信能力。In some embodiments of the present invention, a mobile device includes an NFC element 111, which can be a SIM card or SD card equipped with an NFC transmitter. An NFC-enabled SD card can be placed in the SD card slot of the mobile device to provide NFC communication capabilities for the smartphone. Similarly, an NFC-enabled SIM card can be placed in the SIM card slot of the mobile device to provide NFC communication capabilities for the smartphone.
如图1A所示,接入控制系统中的个体可以具有不同的角色。例如,个体可能是主人、管理员或用户。主人可以添加、删除和配置管理员或用户的接入权限。管理员可以类似地添加、删除和配置用户的接入权限。用户是寻求进入由智能锁保护的场地的个人。可以为每个用户或管理员,或者在更普遍的级别为一组用户或管理员,配置个体的接入权限。类似地,可以向用户或管理员授予对特定的智能锁或一组智能锁的接入。As shown in Figure 1A, individuals in an access control system can have different roles. For example, an individual may be an owner, an administrator, or a user. An owner can add, delete, and configure access permissions for an administrator or user. An administrator can similarly add, delete, and configure access permissions for a user. A user is an individual seeking access to a location protected by a smart lock. Individual access permissions can be configured for each user or administrator, or more generally for a group of users or administrators. Similarly, a user or administrator can be granted access to a specific smart lock or group of smart locks.
例如,在商业环境下的接入控制系统中,主人设备101或管理员设备102可以由希望控制其员工如何和何时进入公司内的区域的主管或管理者来操作。业务经理可以指定一名主管作为管理员,该管理员可以进一步将一组员工指定为对特定一组智能锁有接入权的用户。作为另一示例,在住宅环境下,主人设备101或管理员设备102可以由家长操作以控制人员进入其房屋不同区域的接入权并监视人员进入其房屋不同区域的接入信息。指定自己作为主人的家长可以将他们的保姆指定为管理员并将他们的孩子指定为用户,并规定保姆和孩子可以进入房屋的哪些区域以及他们如何以及何时可以进入这些区域。如下面更详细描述的,主管或家长可以接收关于雇员、保姆或孩子如何以及何时尝试进入由智能锁104控制的场地的警报或报告。For example, in an access control system in a commercial environment, the master device 101 or the administrator device 102 can be operated by a supervisor or manager who wants to control how and when their employees enter areas within the company. The business manager can designate a supervisor as an administrator, who can further designate a group of employees as users with access rights to a specific set of smart locks. As another example, in a residential environment, the master device 101 or the administrator device 102 can be operated by a parent to control access rights of people to different areas of their house and monitor access information of people entering different areas of their house. Parents who designate themselves as masters can designate their babysitter as an administrator and their children as users, and specify which areas of the house the babysitter and children can access and how and when they can enter those areas. As described in more detail below, a supervisor or parent can receive alerts or reports about how and when an employee, babysitter, or child attempts to enter a venue controlled by a smart lock 104.
接入控制系统的主人或管理员使用一组规则112和接入权限113来配置用户如何打开智能锁。接入权限113识别接入控制系统中的每个个体或个体组,以及接入控制系统中的每个智能锁或智能锁组。接入权限113还将每个个体与智能锁相关联。规则集12指定了何种接入信道可以用于打开智能锁,以及(如果有)需要何种条件才能使个体打开智能锁。例如,指定自己作为主人的家长可以配置保姆的接入权限和规则,使得他们可以使用密码或生物特征扫描来打开智能锁。这些规则可以进一步被配置有条件,使得保姆只能在一周中的某些天或者家长批准每次接入请求之后才能打开智能锁。The owner or administrator of the access control system uses a set of rules 112 and access permissions 113 to configure how users open smart locks. Access permissions 113 identify each individual or group of individuals in the access control system, as well as each smart lock or group of smart locks in the access control system. Access permissions 113 also associates each individual with a smart lock. The rule set 12 specifies what access channels can be used to open the smart lock and what conditions, if any, are required for an individual to open the smart lock. For example, a parent who designates themselves as the owner can configure access permissions and rules for a babysitter so that they can use a password or biometric scan to open the smart lock. These rules can be further configured with conditions so that the babysitter can only open the smart lock on certain days of the week or after the parent approves each access request.
接入权限和规则可以存储在中央接入服务器、智能锁、用户、管理员或主人的移动设备中。如下面更详细说明的,主人或管理员可以从主人设备101、管理员设备102或中央接入服务器105创建、修改或删除接入权限和规则。当主人或管理员创建、修改或删除接入权限或规则时,接入权限或规则可以被传送到用户的移动设备或中央接入服务器。然后,用户的移动设备随后可以将接入权限或规则作为令牌的一部分发送到智能锁。当用户尝试打开智能锁时,可以从移动设备或智能锁检查接入权限和规则。例如,如果用户提供密码或生物特征扫描,则智能锁可以检查接入权限和规则以确定用户是否被授权在给定日期或时间打开智能锁。作为另一示例,在将令牌发送到智能锁之前,用户的移动设备可以检查接入权限和规则以确定用户是否被授权打开特定的智能锁。如果用户不具有授权,则移动设备将不发送令牌给智能锁。在本发明的一些实施例中,可以从主人设备101、管理员设备102或中央接入服务器105检查接入权限和规则。Access permissions and rules can be stored on a central access server, a smart lock, or on a user, administrator, or owner's mobile device. As described in more detail below, an owner or administrator can create, modify, or delete access permissions and rules from the owner device 101, administrator device 102, or central access server 105. When an owner or administrator creates, modifies, or deletes access permissions or rules, the access permissions or rules can be transmitted to the user's mobile device or the central access server. The user's mobile device can then send the access permissions or rules as part of a token to the smart lock. When a user attempts to open the smart lock, the access permissions and rules can be checked on the mobile device or the smart lock. For example, if the user provides a password or biometric scan, the smart lock can check the access permissions and rules to determine whether the user is authorized to open the smart lock at a given date or time. As another example, before sending a token to the smart lock, the user's mobile device can check the access permissions and rules to determine whether the user is authorized to open a specific smart lock. If the user does not have authorization, the mobile device will not send the token to the smart lock. In some embodiments of the present invention, the access permissions and rules can be checked on the owner device 101, administrator device 102, or central access server 105.
可以安装智能锁以保护场地内的特定区域或房间,从而使得主人或管理员能够精确地控制个体可以获得何处的进入权限。例如,在手机信号塔中,智能锁可以安装在设施的前门,储藏室的门和柜子的门上,这些地方中通常是盗窃目标的电池、铜缆、电子设备和其他资产得以保全。然后,公司经理(例如,主人)可以准许某些雇员(例如,用户)对设施的进入,同时将对储存室和柜门的进入限制为选定的少数员工。如上所述,公司经理可以进一步配置规则以规定员工如何接入智能锁,以及(如果有的话)何种条件使雇员获得接入权限。Smart locks can be installed to protect specific areas or rooms within a facility, allowing the owner or administrator to precisely control where individuals can gain access. For example, in a cell phone tower, smart locks can be installed on the facility's front door, storage room doors, and cabinet doors where batteries, copper cables, electronic equipment, and other assets that are often targets of theft are secured. A company manager (e.g., the owner) can then grant access to the facility to certain employees (e.g., users) while limiting access to storage rooms and cabinet doors to a select few employees. As described above, the company manager can further configure rules to dictate how employees access the smart locks and, if so, under what conditions an employee gains access.
作为另一示例,场地内的区域可以是例如地下室、后院、卧室、前大门、健身中心或车库。因此,在住宅环境中,家长可以使保姆进入地下室、后院或家长的卧室,但只能在保姆照顾婴儿的特定时间段期间。如下所述,家长可以进一步配置规则以授予保姆附条件的进入权限,其需要保姆在其每次寻求接入智能锁时请求许可。家长可以进一步配置接入权限和规则以授予孩子在加强的限制下进入家中不同的区域或房间的权限。例如,家长可以配置接入权限和规则来拒绝孩子进入房屋中例如地下室的房间,或限制在一天的特定时间段内进入诸如健身中心的区域。家长可以进一步配置规则以规定孩子可以使用哪些接入信道来进入该区域,例如使用孩子的指纹来进入后院。As another example, an area within a venue can be, for example, a basement, a backyard, a bedroom, a front door, a fitness center, or a garage. Thus, in a residential environment, a parent can allow a babysitter to enter the basement, backyard, or parent's bedroom, but only during a specific time period when the babysitter is caring for the baby. As described below, the parent can further configure rules to grant the babysitter conditional access rights, which requires the babysitter to request permission each time the babysitter seeks access to the smart lock. The parent can further configure access rights and rules to grant the child access to different areas or rooms in the home under enhanced restrictions. For example, the parent can configure access rights and rules to deny the child access to a room in the house, such as the basement, or restrict access to an area, such as a fitness center, to a specific time period of the day. The parent can further configure rules to specify which access channels the child can use to enter the area, such as using the child's fingerprint to enter the backyard.
根据本发明的一些实施例,用户通过从用户的移动设备到智能锁的无线通信116来打开一个或多个智能锁104。通过使用用户的移动设备的无线功能,智能锁104可以被链接到中央接入服务器105,而没有两者之间的直接连接。以这种方式,可以远程地控制对智能锁104的接入,而不需要在门框或锁上实现硬件连接系统。According to some embodiments of the present invention, a user opens one or more smart locks 104 by wirelessly communicating 116 from the user's mobile device to the smart lock. By using the wireless capabilities of the user's mobile device, the smart lock 104 can be linked to the central access server 105 without a direct connection between the two. In this way, access to the smart lock 104 can be remotely controlled without requiring a hardware connection system to be implemented on the door frame or lock.
如上所述,智能锁104可以通过将令牌从用户的移动设备无线地发送到智能锁104来打开。令牌包含包括字母、数字、符号或其任何组合的密码。密码可以是动态的或固定的,如下面更详细地讨论的。智能锁104基于由主人或管理员确定的接入权限和规则并且通过将接收到的密码与由智能锁104中存储的进程产生的密码进行比较来验证令牌。如果接收到的密码与进程产生的密码相匹配,则智能锁104将接受令牌。基于接入权限和规则以及该令牌是否与存储的进程产生的令牌相匹配,智能锁104向用户的移动设备103传送该令牌是否被验证。然后可以将该信息从用户移动设备103发送到中央接入服务器105,在中央接入服务器中该信息可以作为通知或警报被中继到主人设备101或管理员设备102。As described above, the smart lock 104 can be opened by wirelessly sending a token from the user's mobile device to the smart lock 104. The token contains a password that includes letters, numbers, symbols, or any combination thereof. The password can be dynamic or fixed, as discussed in more detail below. The smart lock 104 verifies the token based on access permissions and rules determined by the owner or administrator and by comparing the received password with a password generated by a process stored in the smart lock 104. If the received password matches the password generated by the process, the smart lock 104 will accept the token. Based on the access permissions and rules and whether the token matches the stored token generated by the process, the smart lock 104 transmits to the user's mobile device 103 whether the token is verified. This information can then be sent from the user's mobile device 103 to the central access server 105, where it can be relayed to the owner device 101 or administrator device 102 as a notification or alert.
主人设备101和管理员设备102被配置为规定用户是否可以使用用户的移动设备的无线能力接入智能锁104,以及用户具有哪些接入权限。例如,主人设备101和管理员设备102可以规定用户的对特定智能锁104或智能锁104组的接入权限是固定的或附条件的。The master device 101 and the administrator device 102 are configured to specify whether a user can use the wireless capabilities of the user's mobile device to access the smart lock 104, and what access permissions the user has. For example, the master device 101 and the administrator device 102 can specify whether the user's access permissions to a specific smart lock 104 or a group of smart locks 104 are fixed or conditional.
附条件的接入权限允许主人或管理员批准用户打开智能锁104的每次尝试。例如,当具有附条件的接入权限的用户尝试接入智能锁104或智能锁104组时,系统将警告主人设备101或管理员设备102用户103正在试图接入智能锁104,并且近实时地请求主人设备101或管理员设备102准许用户对智能锁104的接入。用户然后可以确定是否允许或拒绝用户接入。该确定可以基于附加条件或验证步骤。例如,主人或管理员可以请求用户提供证明用户身份或真实性的标识信息,诸如例如附加口令。作为另一示例,管理员的主人可以拒绝用户接入,因为用户不应接入该特定智能锁104,或者不应在该特定日期或时间接入。如果主人或管理员确定用户对智能锁104的接入应被准许,则主人设备101或管理员设备102然后可以向用户提供如下面更详细描述的令牌。如果主人或管理员确定用户对智能锁104的接入应被拒绝,则主人设备101或管理员设备102不向用户提供令牌,并且用户将无法打开智能锁104。以此方式,主人设备101或管理员设备102可以近实时地允许或拒绝对智能锁104的接入。在一些实施例中,当主人或管理员确定是否准许或拒绝用户接入时,主人设备101或管理员设备102向用户发送警报,通知用户他们的接入请求已被准许或拒绝。Conditional access rights allow an owner or administrator to approve each attempt by a user to open a smart lock 104. For example, when a user with conditional access rights attempts to access a smart lock 104 or a group of smart locks 104, the system will alert the owner device 101 or administrator device 102 that the user 103 is attempting to access the smart lock 104 and request the owner device 101 or administrator device 102 to grant the user access to the smart lock 104 in near real time. The user can then determine whether to allow or deny the user access. This determination can be based on additional conditions or verification steps. For example, the owner or administrator can request that the user provide identification information proving the user's identity or authenticity, such as an additional password. As another example, the owner of the administrator can deny the user access because the user should not access that particular smart lock 104 or should not access it on that particular date or time. If the owner or administrator determines that the user's access to the smart lock 104 should be granted, the owner device 101 or administrator device 102 can then provide the user with a token as described in more detail below. If the owner or administrator determines that the user's access to the smart lock 104 should be denied, the owner device 101 or administrator device 102 does not provide the token to the user, and the user will not be able to open the smart lock 104. In this way, the owner device 101 or administrator device 102 can allow or deny access to the smart lock 104 in near real time. In some embodiments, when the owner or administrator determines whether to grant or deny user access, the owner device 101 or administrator device 102 sends an alert to the user notifying the user that their access request has been granted or denied.
固定接入权限允许用户在没有首先接收到来自主人设备101或管理员设备102的批准的情况下获得对智能锁104的接入。例如,用户可以被授予以不受限制的方式打开特定智能锁104的固定接入权限。这样的固定接入可以通过固定密码提供,例如用户可以在智能锁104的小键盘上输入的固定密码。然后,用户可以使用固定密码打开智能锁104,而无需首先请求主人设备101或管理员设备102的批准。在一些实施例中,当具有固定接入权限的用户已经接入或尝试接入智能锁104时,用户的移动设备103仍然可以通知主人设备101或管理员设备102。例如,在用户在智能锁小键盘上输入固定密码之后,智能锁可以向用户的移动设备通信它接收到有效的固定密码并解锁智能锁。然后,用户的移动设备可以近实时地通知主人设备101、管理员设备102或中央接入服务器105用户接入并解锁智能锁104。Fixed access rights allow a user to gain access to a smart lock 104 without first receiving approval from the master device 101 or administrator device 102. For example, a user may be granted fixed access rights to open a specific smart lock 104 in an unrestricted manner. Such fixed access may be provided via a fixed password, such as one that the user can enter on the keypad of the smart lock 104. The user can then use the fixed password to open the smart lock 104 without first requesting approval from the master device 101 or administrator device 102. In some embodiments, the user's mobile device 103 may still notify the master device 101 or administrator device 102 when a user with fixed access rights has accessed or attempted to access the smart lock 104. For example, after the user enters the fixed password on the smart lock keypad, the smart lock may communicate to the user's mobile device that it has received a valid fixed password and unlock the smart lock. The user's mobile device may then notify the master device 101, administrator device 102, or central access server 105 in near real time that the user has accessed and unlocked the smart lock 104.
主人设备101和管理员设备102还可以用于允许用户使用在小键盘115上输入的密码或生物特征扫描114打开一个或多个智能锁104。这些接入信道使得用户能够获得对智能锁104的接入而不使用移动设备,因为如下面更详细描述的,密码或生物特征扫描可以由用户手动输入。以这种方式,用户可以在他们不拥有移动设备、或者他们的移动设备丢失、损坏或者由于其它原因无法将令牌无线发送到智能锁104的情况下获得对智能锁104的接入。因此,根据本发明的一些实施例,用于输入密码的小键盘或生物特征扫描用作向用户提供对智能锁104的接入的冗余接入信道。在本发明的其它实施例中,用于输入密码或生物特征扫描的小键盘可以用作主要或默认接入信道,而从用户的移动设备到智能锁104无线通信可以用作冗余接入信道。在本发明的另外的实施例中,可能要求用户使用替代接入信道的组合来认证自身。例如,可能要求用户在授予对锁的接入权之前提供动态密码和指纹的组合。The master device 101 and the administrator device 102 can also be used to allow a user to open one or more smart locks 104 using a password or biometric scan 114 entered on a keypad 115. These access channels enable users to gain access to a smart lock 104 without using a mobile device, as the password or biometric scan can be manually entered by the user, as described in more detail below. In this way, users can gain access to a smart lock 104 even if they do not have a mobile device, or if their mobile device is lost, damaged, or otherwise unable to wirelessly send a token to the smart lock 104. Therefore, according to some embodiments of the present invention, the keypad for entering a password or biometric scan serves as a redundant access channel to provide users with access to the smart lock 104. In other embodiments of the present invention, the keypad for entering a password or biometric scan can serve as the primary or default access channel, while wireless communication from the user's mobile device to the smart lock 104 can serve as a redundant access channel. In yet other embodiments of the present invention, users may be required to authenticate themselves using a combination of alternative access channels. For example, a user may be required to provide a combination of a dynamic password and a fingerprint before access to the lock is granted.
如上所述,令牌可以包括可以从用户的移动设备103无线地发送到智能锁104的密码。如下面更详细地描述的,密码也可以显示在用户设备上,使得用户可以手动将其输入到智能锁104的小键盘上。智能锁04通过将输入的密码与存储在智能锁404上的进程所产生的密码进行比较来验证固定密码。如果该进程产生匹配的密码,则智能锁104将授予用户接入权限。As described above, the token may include a password that can be wirelessly transmitted from the user's mobile device 103 to the smart lock 104. As described in more detail below, the password may also be displayed on the user's device so that the user can manually enter it into the keypad of the smart lock 104. The smart lock 104 verifies the fixed password by comparing the entered password with a password generated by a process stored on the smart lock 104. If the process generates a matching password, the smart lock 104 grants access to the user.
在本发明的一些实施例中,密码可以是由代码生成系统(CGS)生成的动态密码。动态密码是中央接入服务器根据请求而生成的唯一的、单次使用的、限时的或一次性密码。密码部分基于请求密码的时间。In some embodiments of the present invention, the password may be a dynamic password generated by a code generation system (CGS). A dynamic password is a unique, single-use, time-limited, or one-time password generated by a central access server upon request. The password is based in part on the time the password was requested.
根据本发明的一些实施例,提供给用户的密码的生成基于关于用户的移动设备的唯一信息和请求或正在生成密码的时间。对于移动设备,密码可以基于例如国际移动设备标识(“IMEI”)、移动设备的网络ID或两个ID的组合,以及从移动设备发送请求的时间。According to some embodiments of the present invention, the generation of the password provided to the user is based on unique information about the user's mobile device and the time when the password is requested or being generated. For mobile devices, the password can be based on, for example, the International Mobile Equipment Identity ("IMEI"), the network ID of the mobile device, or a combination of both IDs, and the time when the request was sent from the mobile device.
可替代地,密码可以是固定的。固定密码不会更改或过期,可以被使用不止一次,并且可以在没有来自主人或管理员的请求的情况下获得。希望阻止固定密码被泄漏的主人或管理员可以要求固定的密码与其他信息或生物特征扫描结合使用。Alternatively, the password can be fixed. A fixed password does not change or expire, can be used more than once, and can be obtained without a request from the owner or administrator. An owner or administrator who wishes to prevent the fixed password from being disclosed can require the fixed password to be used in conjunction with other information or a biometric scan.
用户可以通过联系主人或管理员来请求动态的或固定的密码。例如,用户的移动设备103可以包括移动应用,其允许用户通过移动设备的蜂窝数据、WiFi或NFC/蓝牙连接向主人设备101、管理员设备102或中央接入服务器105发送密码请求。作为另一示例,用户可以通过从用户的移动设备向主人、管理员或中央接入服务器代理发起语音呼叫或者发送文本消息来提交请求。以这种方式,即使当移动设备不能连接到互联网或者没有配备数据或互联网连接时,用户也可以发送请求。A user can request a dynamic or fixed password by contacting the owner or administrator. For example, the user's mobile device 103 may include a mobile application that allows the user to send a password request to the owner device 101, the administrator device 102, or the central access server 105 via the mobile device's cellular data, WiFi, or NFC/Bluetooth connection. As another example, the user can submit a request by initiating a voice call or sending a text message from the user's mobile device to the owner, administrator, or central access server agent. In this way, the user can send a request even when the mobile device cannot connect to the internet or is not equipped with a data or internet connection.
在本发明的一些实施例中,智能锁104可以通过提供用户的生物特征扫描来打开。如下面更详细地描述的,智能锁04包括存储介质201,其可以存储被授权接入锁的每个用户的生物特征数据。生物特征数据可以包括例如每个用户的指纹。当用户接收到生物特征扫描时,智能锁104将扫描与存储在智能锁104中的生物特征数据进行比较。如果扫描与所存储的生物特征数据匹配,则智能锁将准许用户接入。当生物特征扫描器用作冗余接入信道时,如果例如用户没有或丢失其移动设备并且不能获得令牌或密码,则用户可以提供生物特征扫描。In some embodiments of the present invention, the smart lock 104 can be opened by providing a biometric scan of the user. As described in more detail below, the smart lock 04 includes a storage medium 201 that can store biometric data for each user authorized to access the lock. The biometric data may include, for example, a fingerprint of each user. When the user receives a biometric scan, the smart lock 104 compares the scan with the biometric data stored in the smart lock 104. If the scan matches the stored biometric data, the smart lock grants access to the user. When the biometric scanner is used as a redundant access channel, the user can provide a biometric scan if, for example, the user does not have or has lost their mobile device and cannot obtain a token or password.
图1C示出了根据本发明的一些实施例,智能锁104耦合到主人设备101、管理员设备102或中央接入服务器106,从而绕过移动设备。例如,智能锁104可以耦合到网络设备117,网络设备117将通信中继到主人设备101、管理员设备102或中央接入服务器106。网络设备117可以是例如无线接收机、路由器、中继器或类似设备。作为另一示例,智能锁104可以通过蜂窝宽带连接直接与主人设备101、管理员设备102或中央接入服务器106进行双向通信,如下面更详细描述的。Figure 1C illustrates how, in some embodiments according to the present invention, a smart lock 104 can be coupled to a master device 101, an administrator device 102, or a central access server 106, thereby bypassing a mobile device. For example, the smart lock 104 can be coupled to a network device 117, which relays communications to the master device 101, the administrator device 102, or the central access server 106. The network device 117 can be, for example, a wireless receiver, a router, a repeater, or the like. As another example, the smart lock 104 can communicate bidirectionally directly with the master device 101, the administrator device 102, or the central access server 106 via a cellular broadband connection, as described in more detail below.
在如图1C所示智能锁104与网络设备117通信的配置中,智能锁104可以使用近场无线发射机或无线LAN来建立短距离无线连接。可以使用例如蓝牙、NFC、ZigBee或类似的短距离无线网络技术来建立连接。例如,网络设备117可以是家中的无线中继器、扩展器或路由器,并且使用蓝牙来与智能锁通信。然后,网络设备117可以使用诸如因特网、以太网或类似连接的网络连接耦合到主人设备、管理员设备或中央接入服务器。然后,网络设备117可以近实时地中继从智能锁到主人设备,管理员设备或中央接入服务器的通信。因此,即使当用户的智能手机或移动设备被盗或不可操作时,智能锁也能够近实时地与主人设备、管理员设备或中央接入服务器进行通信。In the configuration in which the smart lock 104 communicates with the network device 117 as shown in FIG1C , the smart lock 104 can use a near-field wireless transmitter or a wireless LAN to establish a short-range wireless connection. The connection can be established using, for example, Bluetooth, NFC, ZigBee, or similar short-range wireless network technologies. For example, the network device 117 can be a wireless repeater, extender, or router in the home and use Bluetooth to communicate with the smart lock. The network device 117 can then be coupled to a master device, an administrator device, or a central access server using a network connection such as the Internet, Ethernet, or a similar connection. The network device 117 can then relay communications from the smart lock to the master device, the administrator device, or the central access server in near real time. Therefore, even when the user's smartphone or mobile device is stolen or inoperable, the smart lock can communicate with the master device, the administrator device, or the central access server in near real time.
在本发明的一些实施例中,智能锁可以包括直接与中央服务器或管理员通信的无线发射机,如图1D所示。例如,智能锁104可以包括蜂窝宽带或广域网连接,其使得按钮能够直接与主人设备101、管理员设备102或中央接入服务器106进行通信。锁可以包括用于建立蜂窝宽带连接并且以近实时的方式传送信息的无线调制解调器。例如,调制解调器可以是嵌入在锁中的芯片组上的Intel XMM 62553G调制解调器。在另外的实施例中,调制解调器可以是提供对蜂窝网络的接入的USB加密狗、数据卡或类似设备,并且可以通过I/O端口耦合到锁,如下面更详细描述的。蜂窝网络可以是例如GSM,GPRS,EDGE,UMTS,HSDPA,HSPA,HSPA+,CDMA,LTE或类似的蜂窝网络。In some embodiments of the present invention, a smart lock may include a wireless transmitter that communicates directly with a central server or administrator, as shown in FIG1D . For example, the smart lock 104 may include a cellular broadband or wide area network connection that enables the button to communicate directly with the master device 101 , the administrator device 102 , or the central access server 106 . The lock may include a wireless modem for establishing a cellular broadband connection and transmitting information in near real time. For example, the modem may be an Intel XMM 6255 3G modem on a chipset embedded in the lock. In another embodiment, the modem may be a USB dongle, data card, or similar device that provides access to a cellular network and may be coupled to the lock via an I/O port, as described in more detail below. The cellular network may be, for example, GSM, GPRS, EDGE, UMTS, HSDPA, HSPA, HSPA+, CDMA, LTE, or a similar cellular network.
令智能锁能够与主人设备、管理员设备或中央接入服务器通信提供了对用户接入智能锁的附加控制。例如,智能锁可以被配置为在每次用户尝试获得对智能锁的接入权时向主人设备或管理员设备发送获得批准的请求。因此,即使用户尝试使用密码或生物特征扫描来获取接入权限时,主人或管理员也可以批准每次接入请求。Enabling a smart lock to communicate with an owner device, an administrator device, or a central access server provides additional control over user access to the smart lock. For example, the smart lock can be configured to send an approval request to the owner device or administrator device each time a user attempts to gain access to the smart lock. Thus, even if a user attempts to gain access using a password or biometric scan, the owner or administrator can approve each access request.
作为另一示例,智能锁可以使用到主人设备、管理员设备或中央接入服务器的连接来核实用户是否被授权打开智能锁。具体来说,在接收到认证信息之后,智能锁可以与主人设备、管理员设备或中央接入服务器通信,主人设备、管理员设备或中央接入服务器检查一组可配置规则以核实用户是否被授权接入智能锁。As another example, a smart lock can use a connection to a master device, an administrator device, or a central access server to verify whether the user is authorized to open the smart lock. Specifically, after receiving authentication information, the smart lock can communicate with the master device, the administrator device, or the central access server, which checks a set of configurable rules to verify whether the user is authorized to access the smart lock.
在本发明的另一方面,主人设备、管理员设备或中央接入服务器可以将指令传送到智能锁以执行某些功能或过程。例如,如果中央接入服务器确定智能锁的门栓被解锁,则中央服务器可以指示智能锁锁定门栓。以这种方式,如果管理员或用户离开家,而不记得其是否锁门,则管理员或用户可以确认门是否未上锁,并且如果确实如此,则将其远程上锁。在其他实施例中,主人设备、管理员设备或中央接入服务器可以将指令传送到智能锁,以阻止从某些设备接收的通信或从某些用户接收的生物特征。例如,如果用户的移动设备已被报告为丢失或被盗,则主人设备、管理员设备或中央接入服务器可以指示智能锁阻止从该特定移动设备接收到的任何通信。类似地,主人设备、管理员设备或中央接入服务器可以向智能锁发送特定用户将不再被允许使用其生物特征扫描来解锁智能锁,并且报告从该用户接收的任何这样的生物特征扫描的指令。In another aspect of the present invention, a master device, an administrator device, or a central access server can transmit instructions to a smart lock to perform certain functions or processes. For example, if the central access server determines that the smart lock's deadbolt is unlocked, the central server can instruct the smart lock to lock the deadbolt. In this way, if an administrator or user leaves home and does not remember whether they locked the door, the administrator or user can confirm whether the door is unlocked and, if so, lock it remotely. In other embodiments, a master device, an administrator device, or a central access server can transmit instructions to a smart lock to block communications received from certain devices or biometrics received from certain users. For example, if a user's mobile device has been reported as lost or stolen, the master device, administrator device, or central access server can instruct the smart lock to block any communications received from that particular mobile device. Similarly, a master device, administrator device, or central access server can send an instruction to the smart lock that a particular user will no longer be allowed to use their biometric scan to unlock the smart lock, and report any such biometric scans received from that user.
根据本发明的一些实施例,按钮包括用于检测和测量门的移动和位置的惯性模块。惯性模块可以包括用于检测和测量移动和/或位置的传感器组合,例如基于MEMS的加速度计、陀螺仪和/或磁力计。基于MEMS的加速度计可以是1轴,2轴或3轴加速度计,并且测量可以包括例如门在这些轴上的速度和加速度。可以对由加速度计提供的测量值进行滤波和分析,以确定运动是否与门的打开或关闭相关。可以使用的其它传感器可以包括磁传感器,例如磁性开关,其响应于其磁场的变化而产生测量值。也可以使用电位计来产生对应于门框铰链的角移动和位置的信号。其他实施例可以包括在门打开或关闭时测量光或声波的反射的光学或超声波传感器。According to some embodiments of the present invention, the button includes an inertial module for detecting and measuring the movement and position of the door. The inertial module may include a combination of sensors for detecting and measuring movement and/or position, such as a MEMS-based accelerometer, a gyroscope, and/or a magnetometer. The MEMS-based accelerometer may be a 1-axis, 2-axis, or 3-axis accelerometer, and the measurements may include, for example, the velocity and acceleration of the door along these axes. The measurements provided by the accelerometer may be filtered and analyzed to determine whether the movement is related to the opening or closing of the door. Other sensors that may be used may include magnetic sensors, such as magnetic switches, which generate measurements in response to changes in their magnetic field. A potentiometer may also be used to generate a signal corresponding to the angular movement and position of the door frame hinge. Other embodiments may include optical or ultrasonic sensors that measure the reflection of light or sound waves when the door is opened or closed.
由惯性模块的传感器进行的测量用于跟踪位置和门移动的变化,使按钮能够确定门是打开还是关闭。在一些实施例中,按钮可以通过将传感器测量值与与门的打开和关闭相关联的已知加速度和/或移动特征进行比较来确定门是打开还是关闭。例如,关闭门的移动的特征在于其加速度的变化;如果加速度急剧增加(即用户推门),随后突然减小(即,门接触门框并且关闭),则按钮可以确定门被关闭。作为另一个示例,关门的移动可以以其速度表征;如果速度或加速度达到最大阈值,则可以确定门已经达到使得其最终将关闭的速率或速度。类似地,如果门的速度或加速度从未达到最小阈值,则可以确定门没有被足以关闭的力推动。该按钮可被配置为跟踪门在什么时间被打开或关闭。例如,按钮可以通过在智能锁的存储介质中保持日志来记录门在何时被打开或关闭。Measurements taken by the inertial module's sensors are used to track changes in position and door movement, enabling the button to determine whether the door is open or closed. In some embodiments, the button can determine whether the door is open or closed by comparing the sensor measurements with known acceleration and/or movement characteristics associated with the opening and closing of the door. For example, the movement of a closing door can be characterized by changes in its acceleration; if the acceleration increases sharply (i.e., the user pushes the door) and then suddenly decreases (i.e., the door contacts the doorframe and closes), the button can determine that the door is closed. As another example, the movement of a closing door can be characterized by its speed; if the speed or acceleration reaches a maximum threshold, it can be determined that the door has reached a rate or speed that will cause it to eventually close. Similarly, if the door's speed or acceleration never reaches a minimum threshold, it can be determined that the door was not pushed with sufficient force to close. The button can be configured to track when the door is opened or closed. For example, the button can record when the door is opened or closed by maintaining a log in the smart lock's storage medium.
在本发明的另外的方面,这些传感器可以用于检测锁具锁芯的门栓是否已经旋转,从而指示用户是否已经锁定或解锁了门。例如,加速度计可用于检测使门栓延伸到门榫内的按钮的旋转。该按钮还可以被配置为跟踪凸轮在什么时间被接合来锁定或解锁门栓。在本发明的一些实施例中,按钮可以包括门栓的锁定或解锁状态,以确认门是被打开还是被关闭。例如,如果按钮检测到门被关闭,则按钮可以通过确定门栓是否从解锁状态变为锁定状态(其指示门被关闭并被锁定)来确认门已经关闭。In another aspect of the present invention, these sensors can be used to detect whether the bolt of the lock cylinder has been rotated, thereby indicating whether the user has locked or unlocked the door. For example, an accelerometer can be used to detect the rotation of a button that extends the bolt into the door tenon. The button can also be configured to track when the cam is engaged to lock or unlock the bolt. In some embodiments of the present invention, the button can include the locked or unlocked state of the bolt to confirm whether the door is open or closed. For example, if the button detects that the door is closed, the button can confirm that the door is closed by determining whether the bolt changes from an unlocked state to a locked state (which indicates that the door is closed and locked).
在本发明的一些实施例中,该按钮可将门打开、关闭、锁定还是解锁传送到网络设备、管理员设备、主人设备或中央接入服务器。以这种方式,用户可以远程确定他们的门是打开还是关闭。In some embodiments of the present invention, the button can transmit whether the door is open, closed, locked or unlocked to a network device, an administrator device, a master device or a central access server. In this way, users can remotely determine whether their door is open or closed.
图2A和图2B示出了根据本发明的一些实施例的智能锁。智能锁包括存储介质201、电源202、硬件处理器203、锁芯204和按钮205。智能锁还可以包括无线收发机206、密码小键盘207和生物特征扫描器208。锁芯包括接合门栓(未示出)的凸轮209。用户向智能锁提供认证信息,认证信息由硬件处理器203和存储介质201验证。认证信息可以是例如用户扫描的指纹、输入到小键盘上的密码、或从用户设备无线发送的令牌。当智能锁验证认证信息时,按钮205接合凸轮205,该凸轮解锁门栓。存储介质201存储用于验证认证信息,保持接入事件和智能锁使用的日志以及标识智能锁的信息和数据。例如,存储介质可以存储被授权打开锁的用户的资料数据或标识智能锁的唯一标识号。Figures 2A and 2B illustrate a smart lock according to some embodiments of the present invention. The smart lock includes a storage medium 201, a power supply 202, a hardware processor 203, a lock cylinder 204, and a button 205. The smart lock may also include a wireless transceiver 206, a password keypad 207, and a biometric scanner 208. The lock cylinder includes a cam 209 that engages a deadbolt (not shown). The user provides authentication information to the smart lock, which is verified by the hardware processor 203 and the storage medium 201. The authentication information can be, for example, a fingerprint scanned by the user, a password entered into the keypad, or a token wirelessly sent from the user's device. When the smart lock verifies the authentication information, the button 205 engages the cam 205, which unlocks the deadbolt. The storage medium 201 stores information and data used to verify the authentication information, maintain a log of access events and smart lock usage, and identify the smart lock. For example, the storage medium may store profile data of users authorized to open the lock or a unique identification number that identifies the smart lock.
硬件处理器203被配置为基于由主人或管理员确定的接入权限和规则来验证从接入信道接收的认证信息。当用户通过接入信道认证时,硬件处理器可以解锁门栓。在本发明的一个方面,当第一冗余接入信道对用户不可用时,硬件处理器203被配置为允许通过第二冗余接入信道接入以解锁门栓。The hardware processor 203 is configured to verify the authentication information received from the access channel based on access permissions and rules determined by the owner or administrator. When the user is authenticated through the access channel, the hardware processor can unlock the deadbolt. In one aspect of the present invention, when the first redundant access channel is unavailable to the user, the hardware processor 203 is configured to allow access through the second redundant access channel to unlock the deadbolt.
在一些实施例中,智能锁包括用于从和向用户的移动设备收发RFID、NFC或蓝牙信号的无线收发机206。如上所述,用户可以将令牌无线地发送到智能锁104。当无线收发机206接收到令牌时,智能锁如上所述验证该令牌。无线收发机还可以将接入信息传送到用户的移动设备。接入信息提供有关接入事件的详情,例如哪些用户已接入了智能锁以及他们在何时接入。接入信息可以存储在智能锁的存储介质201中。接入信息被存储在智能锁中,直到移动设备接入锁,此时智能锁将把接入信息发送到用户的移动设备。然后移动设备将接入信息传送到中央接入服务器。当用户的移动设备被盗或无法接收无线通信时,智能锁将等待直至下一个有能力的移动设备试图接入智能锁。In some embodiments, the smart lock includes a wireless transceiver 206 for transmitting and receiving RFID, NFC, or Bluetooth signals from and to the user's mobile device. As described above, the user can send a token wirelessly to the smart lock 104. When the wireless transceiver 206 receives the token, the smart lock verifies the token as described above. The wireless transceiver can also transmit access information to the user's mobile device. The access information provides details about the access event, such as which users have accessed the smart lock and when they accessed. The access information can be stored in the storage medium 201 of the smart lock. The access information is stored in the smart lock until the mobile device accesses the lock, at which time the smart lock will send the access information to the user's mobile device. The mobile device then transmits the access information to the central access server. When the user's mobile device is stolen or cannot receive wireless communication, the smart lock will wait until the next capable mobile device attempts to access the smart lock.
智能锁锁芯204适合于装入标准规格槽。在本发明的一些实施例中,智能锁的锁芯204是欧规(或“Euro DIN”)设计。在其它实施例中,锁芯可以是椭圆形、圆形、斯堪的纳维亚(Scandinavian)、日本、联合(Union)或Schlage类型的轮廓。然而,欧规锁芯通常在门的内部包括用于接合或脱离门栓的可旋转旋钮,而智能锁具有自由旋转的按钮205。与通常旋转半圈或四分之一圈以接合或脱离门栓的旋钮不同,自由旋转的按钮205可围绕其轴旋转若干次。如下面更详细地解释的,旋转自由旋转的按钮205产生旋转能量,旋转能量可以用于为锁内的电源202通电和再充电几天。The smart lock cylinder 204 is adapted to fit into a standard specification slot. In some embodiments of the present invention, the lock cylinder 204 of the smart lock is a European standard (or "Euro DIN") design. In other embodiments, the lock cylinder can be an oval, round, Scandinavian, Japanese, Union, or Schlage type profile. However, European standard lock cylinders typically include a rotatable knob on the inside of the door for engaging or disengaging the deadbolt, while smart locks have a free-spinning button 205. Unlike a knob that typically rotates a half or a quarter turn to engage or disengage the deadbolt, the free-spinning button 205 can rotate several times about its axis. As explained in more detail below, rotating the free-spinning button 205 generates rotational energy, which can be used to power and recharge the power supply 202 within the lock for several days.
当用户的认证信息已被验证时,智能锁被启用以接合门栓。具体地,按钮205可以向内推动,激活与凸轮209接合的离合器。随着用户继续旋转按钮205,凸轮209将门栓从锁定位置移动到解锁位置。用户将无法打开智能锁,直到其被授权进入场地(例如,通过无线发送令牌,提供生物特征扫描或在小键盘上输入密码)。在用户被授权之前,按钮可自由旋转,不会与凸轮啮合。When the user's authentication information has been verified, the smart lock is enabled to engage the deadbolt. Specifically, the button 205 can be pushed inward, activating a clutch that engages the cam 209. As the user continues to rotate the button 205, the cam 209 moves the deadbolt from the locked position to the unlocked position. The user will not be able to open the smart lock until they are authorized to enter the venue (for example, by wirelessly sending a token, providing a biometric scan, or entering a password on the keypad). Before the user is authorized, the button can rotate freely and will not engage with the cam.
如图2A所示,按钮设置在锁芯的面向外侧的端部。在本发明的一个方面,智能锁使用单个按钮,这使得智能锁适应于不同尺寸或锁规格。例如,自由旋转的按钮205也可以适配于单入口锁、按钮入口锁、双入口锁和挂锁。例如,挂锁可以仅包括自由旋转的按钮而不需要内部旋钮。As shown in FIG2A , the button is disposed on the outward-facing end of the lock cylinder. In one aspect of the present invention, the smart lock utilizes a single button, which allows the smart lock to be adapted to different sizes or lock specifications. For example, the freely rotating button 205 can also be adapted to single-entry locks, push-button entry locks, dual-entry locks, and padlocks. For example, a padlock may include only a freely rotating button without requiring an internal knob.
图2B示出了根据本发明的一些实施例的锁芯的前视图。该按钮可以包括若干接入信道,例如密码小键盘207和生物特征扫描器208,其可以被盖210隐藏。在用户不能使用其移动设备无线发送令牌来解锁门的情况下(例如,用户的移动设备被盗或者设备的电池已经被耗尽),用户可以通过使用数字小键盘输入密码或者使用生物特征扫描器来获得接入权。2B shows a front view of a lock cylinder according to some embodiments of the present invention. The button may include several access channels, such as a PIN keypad 207 and a biometric scanner 208, which may be concealed by a cover 210. In the event that the user is unable to wirelessly send a token using their mobile device to unlock the door (e.g., the user's mobile device has been stolen or the device's battery has been depleted), the user may gain access by entering a PIN using the numeric keypad or using a biometric scanner.
如图2C所示,根据本发明的一些实施例,智能锁包括设置在锁芯204的面向内侧的相对端的旋钮或第二按钮211。外部按钮205可以具有比内部按钮211更长的半径和更大的厚度,如下文更详细地解释的,这可以减小旋转按钮所需的力或速度并对其内部电源充电。在智能锁包括内部按钮211的实施例中,内部按钮211可以接合或脱离门栓,而不需要向智能锁提供认证信息或从主人或管理员请求接入。因此,用户可以随时锁定或解锁门以离开场地的内部。As shown in FIG2C , according to some embodiments of the present invention, the smart lock includes a knob or second button 211 disposed at the opposite end of the lock cylinder 204 facing inward. The external button 205 can have a longer radius and a greater thickness than the internal button 211, which can reduce the force or speed required to rotate the button and charge its internal power supply, as explained in more detail below. In embodiments where the smart lock includes an internal button 211, the internal button 211 can engage or disengage the deadbolt without providing authentication information to the smart lock or requesting access from the owner or administrator. Thus, the user can lock or unlock the door at any time to leave the interior of the venue.
图2D示出了在本发明的一些实施例中,按钮可从锁芯拆卸。可拆卸按钮可以包括再充电接口213和输入/输出端口(“I/O端口”)214。电源202可以是可再充电电源,例如电容器组、可充电电池或类似设备。如下面更详细地描述的,按钮还可以包括能量收集元件216。通过从锁芯中移除按钮,用户可以将按钮带到再充电站215,在再充电站215处可以恢复其电荷。再充电站215可以耦合到电源插座,其中电荷可以通过再充电接口213传送到可再充电电源202。再充电接口213可以例如是从具有匹配接口的充电站215接收电流的电线、插头或一个或多个触针。当再充电接口通过匹配的线、插头或触针配置耦合到再充电站215时,再充电站215向按钮供电。可再充电电源202储存从再充电站215接收的电荷。Figure 2D shows that in some embodiments of the present invention, the button is detachable from the lock cylinder. The detachable button may include a recharging interface 213 and an input/output port ("I/O port") 214. The power source 202 may be a rechargeable power source, such as a capacitor bank, a rechargeable battery, or the like. As described in more detail below, the button may also include an energy harvesting element 216. By removing the button from the lock cylinder, the user can take it to a recharging station 215, where its charge can be restored. The recharging station 215 may be coupled to an electrical outlet, where the charge may be transferred to the rechargeable power source 202 via the recharging interface 213. The recharging interface 213 may be, for example, a wire, plug, or one or more contact pins that receive current from a charging station 215 having a matching interface. When the recharging interface is coupled to the recharging station 215 via a matching wire, plug, or contact configuration, the recharging station 215 supplies power to the button. The rechargeable power source 202 stores the charge received from the recharging station 215.
该按钮还可以通过I/O端口214来充电。I/O端口214可以是例如USB、火线(Firewire)、雷电接口(Thunderbolt)、e-SATA、以太网或用于传递电力和/或数据的类似端口。在本发明的一些实施例中,I/O端口214可以从诸如便携式电池充电器的、具有能够输送电荷的匹配接口的外部设备接收电力。例如,外部设备可以是具有USB连接的电池组。在本发明的另外的实施例中,I/O端口214可以从具有匹配端口接口的再充电站215接收电力。再充电站215可以通过I/O端口214将电力从电源插座传递到按钮的电源202。The button can also be charged via I/O port 214. I/O port 214 can be, for example, a USB, Firewire, Thunderbolt, e-SATA, Ethernet, or a similar port for transferring power and/or data. In some embodiments of the present invention, I/O port 214 can receive power from an external device, such as a portable battery charger, that has a matching interface capable of delivering charge. For example, the external device can be a battery pack with a USB connection. In another embodiment of the present invention, I/O port 214 can receive power from a recharging station 215 having a matching port interface. Recharging station 215 can transfer power from an electrical outlet to the button's power supply 202 via I/O port 214.
再充电站215可以耦合到主人设备101、管理员设备102或中央接入服务器106。例如,再充电站215可以包括用于建立因特网连接并与主人设备101、管理员设备102或中央接入服务器106通信的以太网端口或WiFi发射机。在连接到I/O端口214时,再充电站215可以获取存储在存储介质201中的数据。如上所述,这样的数据可以包括例如用于验证认证信息、保持诸如接入事件和智能锁使用的日志的接入信息以及标识智能锁的信息和数据。然后,再充电站215可以将从存储介质201获取的数据发送到主人设备101、管理员设备102或中央接入服务器106。因此,在按钮被再充电时,其可以将接入信息传送到其他设备或中央接入服务器。The recharging station 215 can be coupled to the master device 101, the administrator device 102, or the central access server 106. For example, the recharging station 215 can include an Ethernet port or a WiFi transmitter for establishing an Internet connection and communicating with the master device 101, the administrator device 102, or the central access server 106. When connected to the I/O port 214, the recharging station 215 can retrieve data stored in the storage medium 201. As described above, such data can include, for example, authentication information, access information for maintaining logs such as access events and smart lock usage, and information and data identifying the smart lock. The recharging station 215 can then transmit the data retrieved from the storage medium 201 to the master device 101, the administrator device 102, or the central access server 106. Thus, when the button is recharged, it can transmit access information to other devices or the central access server.
根据本发明的一些实施例,I/O端口可以用于将智能锁连接到无线调制解调器。例如,可以将用于提供对蜂窝网络的接入的USB加密狗、数据卡或类似设备插入到I/O端口中,使得智能锁可以通过蜂窝宽带连接与主人设备、管理员设备或中央接入服务器通信。According to some embodiments of the present invention, the I/O port can be used to connect the smart lock to a wireless modem. For example, a USB dongle, data card, or similar device for providing access to a cellular network can be inserted into the I/O port, allowing the smart lock to communicate with the owner device, administrator device, or central access server via the cellular broadband connection.
在本发明的一些实施例中,为了从锁芯释放按钮,需要有效凭证。例如,只有在接收到有效的密码或生物特征扫描时,才可以移除该按钮。这样,当按钮设置在门的外表面上时,该按钮可不被盗贼或不受欢迎的破坏者偷走或移除。在其他实施例中,按钮可以被配置为从锁芯中移除,而不需要提供凭证。例如,当按钮布置在门的内表面上时,面向家的内部,可以随时移除按钮。In some embodiments of the present invention, valid credentials are required to release the button from the lock cylinder. For example, the button can only be removed upon receiving a valid password or biometric scan. This way, when the button is located on the exterior surface of the door, it can be protected from being stolen or removed by thieves or unwanted vandals. In other embodiments, the button can be configured to be removed from the lock cylinder without requiring credentials. For example, when the button is located on the interior surface of the door, facing the interior of the home, the button can be removed at any time.
根据本发明的一些实施例,智能锁包括设置在门的内表面上的按钮和设置在门的外表面上的按钮。在这种构造中,设置在门的内表面上的按钮可以是可移除的和可再充电的,而设置在门的外表面上的按钮既不可拆卸也不可再充电。因此,外部按钮从朝向内部按钮的电源获取电力。以这种方式,可以提供具有抵抗外部篡改的外部按钮的节能双按钮智能锁。According to some embodiments of the present invention, a smart lock includes a button disposed on the inner surface of the door and a button disposed on the outer surface of the door. In this configuration, the button disposed on the inner surface of the door can be removable and rechargeable, while the button disposed on the outer surface of the door is neither removable nor rechargeable. Thus, the outer button draws power from a power source directed toward the inner button. In this way, an energy-efficient two-button smart lock with an outer button that resists external tampering can be provided.
如上所述,由移动设备传送的令牌可以包含密码,例如用于单次使用的动态密码。在本发明的一个方面,可以自动地从移动设备产生和传送密码,使得不需要来自用户的交互。具体来说,用户的移动设备可以确定或检测到它在智能锁附近。例如,使用移动设备的基于位置的功能,移动设备可以确定用户正在接近场地。在一些实施例中,可以通过分析过去的用户模式来帮助确定,并且推断出用户正在从工作回家并且正在其打开他们的家门的路上。移动设备可以替代地通过使用其NFC/蓝牙或无线能力进行该确定。在检测到锁时,移动设备可以识别锁和锁护卫的场地。然后,移动设备可以自动地将该信息传送到中央接入服务器,以确定用户是否被允许接入智能锁。如果用户满足接入锁的所有条件(例如,允许用户在特定时间和日期接入锁),则接入控制系统将生成动态密码。动态密码可以在主人设备、管理员设备或中央接入服务器处产生,然后被发送到移动设备,或者替代地,其由用户的移动设备上的移动应用产生。然后,移动设备可以将密码发送到智能锁,智能锁使用存储在锁中的进程来验证密码。一旦验证了密码,用户可以向内推动按钮,并使用离合器系统接合或脱离门栓。如果不允许用户打开锁,管理员将接收到未经授权的用户试图打开锁的通知。As described above, the token transmitted by the mobile device can contain a password, such as a single-use dynamic password. In one aspect of the present invention, the password can be automatically generated and transmitted from the mobile device, eliminating the need for user interaction. Specifically, the user's mobile device can determine or detect that it is in the vicinity of a smart lock. For example, using the mobile device's location-based functionality, the mobile device can determine that the user is approaching a venue. In some embodiments, this determination can be aided by analyzing past user patterns and inferring that the user is returning home from work and on their way to unlock their home. The mobile device can alternatively make this determination using its NFC/Bluetooth or wireless capabilities. Upon detecting the lock, the mobile device can identify the lock and the venue it guards. The mobile device can then automatically transmit this information to a central access server to determine whether the user is allowed access to the smart lock. If the user meets all the conditions for accessing the lock (e.g., allowing the user access to the lock at a specific time and date), the access control system will generate a dynamic password. The dynamic password can be generated on a master device, an administrator device, or a central access server and then sent to the mobile device, or alternatively, it can be generated by a mobile application on the user's mobile device. The mobile device can then send the password to the smart lock, which verifies the password using a process stored in the lock. Once the code is verified, the user can push the button inwards and use the clutch system to engage or disengage the deadbolt. If the user is not allowed to open the lock, the administrator will receive a notification that an unauthorized user has attempted to open the lock.
根据本发明的一些实施例,按钮包括基于操作模式改变颜色的光指示器212。例如,如果认证信息已经被接受,则灯光发绿光;如果验证信息被拒绝,则会发红光;在待机模式下,它会发蓝光。According to some embodiments of the present invention, the button includes a light indicator 212 that changes color based on the operating mode. For example, if the authentication information has been accepted, the light will glow green; if the authentication information is rejected, it will glow red; in standby mode, it will glow blue.
如上所述,智能锁由电源202供电。在本发明的一些实施例中,按钮包括冗余电源,如图3所示。冗余电源可用于在其中一个电源故障的情形下对存储介质、无线收发机和灯光指示器通电。冗余电源可以是例如位于按钮内的一组电容器或电池301。当电池或电容器处于低电荷时,按钮可以将该信息传送到下一个接入锁的移动设备。然后,移动设备可以将该信息传送给主人或管理员。可替代地,可以使用颜色指示器来传送低电荷或电池电量。As mentioned above, the smart lock is powered by power supply 202. In some embodiments of the present invention, the button includes a redundant power supply, as shown in Figure 3. The redundant power supply can be used to power the storage medium, wireless transceiver, and light indicator in the event of a power failure. The redundant power supply can be, for example, a set of capacitors or batteries 301 located within the button. When the batteries or capacitors are at a low charge, the button can transmit this information to the next mobile device that accesses the lock. The mobile device can then transmit this information to the owner or administrator. Alternatively, a color indicator can be used to communicate low charge or battery level.
在其他实施例中,按钮具有通过按钮的旋转运动而被充电的一组电容器301。通过旋转运动储存的能量足以支撑数天,并且如果另一个电源(例如,电池)故障,则提供方便、可靠和冗余的电源。按钮可绕其中心轴自由旋转,产生高水平的动能。而一些旋钮限制为四分之一圈或半圈,按钮可以旋转一整圈。类似于手表上的表冠的上发条,按钮的旋转运动被收集并由按钮内的元件转换成电能,并且储存以供将来使用。按钮旋转越大的转数,锁中储存的电荷就越高。在一个示例性实施例中,按钮的旋转运动驱动一系列齿轮和弹簧302,其传递通过转动按钮产生的旋转能量。由于锁内的弹簧和齿轮302可以小于按钮,所以按钮可以以较低的速度和扭矩旋转。因此,通过针对锁中的齿轮和弹簧按比例地调整按钮的尺寸,可以减小为锁充能的力量。In other embodiments, the button features a set of capacitors 301 that are charged by its rotational motion. The energy stored by this rotational motion is sufficient to last for several days and provides a convenient, reliable, and redundant power source should another power source (e.g., a battery) fail. The button can rotate freely about its central axis, generating a high level of kinetic energy. While some knobs are limited to a quarter or half turn, the button can rotate a full turn. Similar to the winding crown of a watch, the button's rotational motion is collected and converted into electrical energy by components within the button, which is then stored for future use. The greater the number of revolutions the button rotates, the higher the charge stored in the lock. In one exemplary embodiment, the button's rotational motion drives a series of gears and springs 302, which transfer the rotational energy generated by turning the button. Because the springs and gears 302 within the lock can be smaller than the button, the button can rotate at a lower speed and torque. Therefore, by proportionally adjusting the size of the button to the gears and springs within the lock, the force required to charge the lock can be reduced.
在其他实施例中,按钮的旋转运动被施加到压电元件303。当用户旋转按钮时,按钮的旋转运动被施加到产生压电的压电元件,压电然后被转移并作为电荷储存在电容器组或电池中。压电可由按钮旋转引起的应变、张力或扭转而产生。应变、张力或扭转被施加到压电元件,并产生可以储存在电容器组中的电荷。在其他实施例中,可以通过将旋转运动转换成振动能量来产生压电。具体来说,按钮内部的齿轮或弹簧可与随着按钮的每次转动而振动的压电片接触。In other embodiments, the button's rotational motion is applied to the piezoelectric element 303. When the user rotates the button, the rotational motion is applied to the piezoelectric element, generating piezoelectricity, which is then transferred and stored as charge in a capacitor bank or battery. Piezoelectricity can be generated by the strain, tension, or torsion caused by the button's rotation. The strain, tension, or torsion applied to the piezoelectric element generates a charge that can be stored in the capacitor bank. In other embodiments, piezoelectricity can be generated by converting rotational motion into vibration energy. Specifically, a gear or spring inside the button can contact a piezoelectric plate that vibrates with each rotation of the button.
在其它实施例中,旋转运动可另外转换成静电能或电磁能。例如,按钮的旋转可以用作使发电机304中的电枢旋转的机械能。在另外的实施例中,按钮的旋转运动可以储存在弹簧或类似的机械装置中。In other embodiments, the rotational motion can be converted into electrostatic energy or electromagnetic energy. For example, the rotation of the button can be used as mechanical energy to rotate the armature in the generator 304. In other embodiments, the rotational motion of the button can be stored in a spring or similar mechanical device.
在本发明的一些方面,可以通过收集按钮的旋转运动或通过再充电接口来对按钮进行再充电。以这种方式,如果能量收集部件停止正常工作,再充电接口仍然可用于对按钮再充电,反之亦然。因此,再充电接口和能量收集部件可以以互补的方式操作,以确保按钮能够被再充电。In some aspects of the present invention, the button can be recharged either by harvesting its rotational motion or through the recharging interface. In this way, if the energy harvesting component ceases to function properly, the recharging interface can still be used to recharge the button, and vice versa. Thus, the recharging interface and the energy harvesting component can operate in a complementary manner to ensure that the button can be recharged.
尽管图2A-D和图3描绘了按钮内部的多个部件,但是在本发明的其它实施例中,这些部件可以放置在按钮的外部。例如,无线收发机、存储器,硬件处理器和电容器/电池组可以设置在锁芯外部,按钮位于锁壳内。这些组件可以通过锁芯与按钮耦合。在其他实施例中,这些部件可以在锁芯内或门接线盒内。Although Figures 2A-D and 3 depict various components within the button, in other embodiments of the present invention, these components may be located externally. For example, the wireless transceiver, memory, hardware processor, and capacitor/battery pack may be located externally to the lock cylinder, with the button located within the lock housing. These components may be coupled to the button via the lock cylinder. In other embodiments, these components may be located within the lock cylinder or within the door junction box.
图4示出了根据本发明的实施例的使用具有接入信道的锁的过程。在步骤401中,用户选择第一接入信道。如果信道如步骤402所示可用,则用户可以提供认证信息404。例如,如果接入信道将令牌无线地发送到智能锁,则如果例如用户的移动设备丢失、被盗或电量耗尽则可以确定接入信道不可用。如果第一接入信道不可用,则选择第二冗余接入信道403。例如,第二冗余接入信道可以是输入到智能锁的小键盘上的密码或生物特征扫描。Figure 4 illustrates the process of using a lock with access channels, according to an embodiment of the present invention. In step 401, a user selects a first access channel. If the channel is available, as shown in step 402, the user can provide authentication information 404. For example, if the access channel wirelessly transmits a token to the smart lock, it may be determined that the access channel is unavailable if, for example, the user's mobile device is lost, stolen, or has a dead battery. If the first access channel is unavailable, a second, redundant access channel is selected 403. For example, the second, redundant access channel can be a password entered into the smart lock's keypad or a biometric scan.
如步骤405所示,智能锁验证认证信息。如上所述,如果认证信息包括令牌或密码,则将令牌或密码与存储在智能锁上的进程所产生的令牌或密码进行比较。如果认证信息是生物特征扫描,则将扫描的数据与存储在智能锁中的生物特征数据进行比较。以这种方式,本发明提供冗余的接入信道,其确保即使当用户的移动设备丢失或不可操作时,用户也可以接入锁。As shown in step 405, the smart lock verifies the authentication information. As described above, if the authentication information includes a token or password, the token or password is compared with a token or password generated by a process stored on the smart lock. If the authentication information is a biometric scan, the scanned data is compared with the biometric data stored in the smart lock. In this way, the present invention provides a redundant access channel, which ensures that the user can access the lock even if the user's mobile device is lost or inoperable.
如果认证信息被验证,则检查接入权限以确定用户是否被授权接入智能锁,如步骤406所示。例如,确定主人或管理员是否允许用户在给定的日期或时间接入智能锁。如果用户被授权打开锁,则用户被准许接入,并且该按钮可以接合凸轮以打开智能锁407。如果认证信息无效,或者主人或管理员决定拒绝用户接入锁,该按钮将不接合凸轮并打开智能锁408。如上所述,可以在用户设备、中央接入服务器、主人设备或管理员设备处检查规则和接入权限。If the authentication information is verified, the access permissions are checked to determine whether the user is authorized to access the smart lock, as shown in step 406. For example, it is determined whether the owner or administrator allows the user to access the smart lock at a given date or time. If the user is authorized to open the lock, the user is granted access, and the button can engage the cam to open the smart lock 407. If the authentication information is invalid, or the owner or administrator decides to deny the user access to the lock, the button will not engage the cam and open the smart lock 408. As described above, the rules and access permissions can be checked at the user device, the central access server, the owner device, or the administrator device.
图5示出了根据本发明的实施例的用于控制具有接入信道的锁的过程。在步骤501中,登记触发事件。触发事件可用于自动启动打开智能锁的过程。触发事件可以是例如当用户的移动设备进入智能锁的预定距离(例如,10英尺)内。然后,触发事件可以例如使得移动设备自动地将令牌发送到按钮。Figure 5 illustrates a process for controlling a lock with an access channel according to an embodiment of the present invention. In step 501, a trigger event is registered. The trigger event can be used to automatically initiate the process of opening a smart lock. The trigger event can be, for example, when a user's mobile device comes within a predetermined distance (e.g., 10 feet) of the smart lock. The trigger event can then, for example, cause the mobile device to automatically send a token to a button.
可以基于移动设备的其他能力来登记触发事件。例如,如果移动设备具有手势识别传感器和软件,则可以基于用户何时以特定方式摇动其移动设备来登记触发事件。可替代地,当用户选择按钮或者在移动设备上的移动应用上输入代码时,移动设备可以登记触发事件。Trigger events can be registered based on other capabilities of the mobile device. For example, if the mobile device has gesture recognition sensors and software, a trigger event can be registered based on when the user shakes their mobile device in a specific manner. Alternatively, the mobile device can register a trigger event when the user selects a button or enters a code on a mobile application on the mobile device.
在移动设备登记触发事件之后,移动设备识别其正在打开的智能锁,如步骤502所示。然后确定规则是否被配置为准许用户附条件的接入权限或固定接入权限,如步骤503所示。如果用户具有附条件的接入权限,则移动设备将向主人或管理员提交请求,如步骤504所示。否则,在步骤505中评估规则和接入权限以确定用户是否被授权打开锁。After the mobile device registers the triggering event, the mobile device identifies the smart lock it is opening, as shown in step 502. It then determines whether the rules are configured to grant the user conditional access or fixed access, as shown in step 503. If the user has conditional access, the mobile device submits a request to the owner or administrator, as shown in step 504. Otherwise, the rules and access permissions are evaluated in step 505 to determine whether the user is authorized to open the lock.
如上所述,移动设备可以以多种方式向管理员提交请求。例如,移动设备可以使用其数据连接、通过发送文本消息或者通过向具有呼叫中心的中央接入服务器呼叫来向主人设备、管理员设备或中央服务器提交请求。在本发明的一些实施例中,主人、管理员或中央接入服务器可能要求用户在发出令牌之前提供附加凭证。例如,用户的移动设备提交的请求可以包括用户的位置、口令或其他类似的标识凭证,例如他们的电话号码或电子邮件地址。作为另一示例,附加凭证可以包括证实用户位于智能锁位置的用户的移动设备的GPS坐标。在其他实施例中,还可能要求用户拍摄智能锁的照片,并向其提供证明用户位于智能锁的位置的请求。凭证成功验证后,会将令牌发送给用户的移动设备。As described above, a mobile device can submit a request to an administrator in a variety of ways. For example, a mobile device can submit a request to a master device, an administrator device, or a central server using its data connection, by sending a text message, or by calling a central access server with a call center. In some embodiments of the present invention, the master, administrator, or central access server may require the user to provide additional credentials before issuing a token. For example, the request submitted by the user's mobile device may include the user's location, a password, or other similar identification credentials, such as their phone number or email address. As another example, the additional credentials may include the GPS coordinates of the user's mobile device that confirms that the user is at the location of the smart lock. In other embodiments, the user may also be required to take a photo of the smart lock and provide it with a request proving that the user is at the location of the smart lock. After the credentials are successfully verified, a token is sent to the user's mobile device.
如果主人或管理员批准用户的请求,或者用户具有足以打开锁的接入权限,则用户可以接收令牌,如步骤506所示。如果主人或管理员拒绝了用户的请求,或者用户未经授权打开锁,则用户将不会收到令牌,如步骤507所示。If the owner or administrator approves the user's request, or the user has access rights sufficient to open the lock, the user may receive a token, as shown in step 506. If the owner or administrator denies the user's request, or the user is not authorized to open the lock, the user will not receive a token, as shown in step 507.
然后,用户可以向智能锁提供认证信息,如步骤508所示。如果用户将通过在小键盘上输入密码来打开锁,则用户可以例如接收作为文本消息或显示在移动应用上的密码,用户可以在智能锁小键盘上输入该密码。如果用户的移动设备无线地将令牌发送到智能锁,则移动设备一旦接收到令牌就可以自动发送令牌。The user can then provide authentication information to the smart lock, as shown in step 508. If the user will open the lock by entering a password on a keypad, the user can receive the password, for example, as a text message or displayed on a mobile app, which the user can enter on the smart lock keypad. If the user's mobile device wirelessly sends the token to the smart lock, the mobile device can automatically send the token once it receives it.
在本发明的一个方面,在认证信息可以提供给智能锁之前,可以需要附加的安全层。例如,在移动设备认证信息无线地发送到按钮之前,可以提示用户在移动设备中输入口令。在其他实施例中,规则可以被配置为要求用户在接收令牌之前在移动设备上扫描其指纹。如上所述,移动设备还可以自动发送认证信息,而无需用户的进一步交互。例如,移动设备可以在启动移动应用时发送认证信息。In one aspect of the present invention, an additional layer of security may be required before authentication information can be provided to the smart lock. For example, the user may be prompted to enter a password on their mobile device before the mobile device authentication information is wirelessly transmitted to the button. In other embodiments, rules may be configured to require the user to scan their fingerprint on the mobile device before receiving the token. As described above, the mobile device may also automatically send authentication information without further user interaction. For example, the mobile device may send authentication information upon launching a mobile app.
在一些实施例中,按钮可以是可以从单个接口控制并且基于在接入控制系统中发生的事件而自动化的设备互连集线器的一部分。例如,设备互连网络可以包括通过WiFi或蓝牙无线通信的家用恒温器、照明系统、音响系统和接入控制系统。家用恒温器、照明系统、音响系统和接入控制系统可以使用相同的应用编程接口(“API”)彼此通信或与中央服务器进行通信。使用API,家用恒温器、照明系统、音响系统和接入控制系统可以基于某些规则或事件来自动化。例如,在用户利用他的移动设备解锁他的家门之后,接入控制系统可以将用户偏好传送给恒温器以在一定温度下打开空调器,打开客厅中的某些照明设备,并开始通过扬声器系统播放特定的用户定义的音乐。In some embodiments, the button can be part of a device interconnection hub that can be controlled from a single interface and automated based on events that occur in the access control system. For example, a device interconnection network can include a home thermostat, lighting system, sound system, and access control system that communicate wirelessly via WiFi or Bluetooth. The home thermostat, lighting system, sound system, and access control system can use the same application programming interface ("API") to communicate with each other or with a central server. Using the API, the home thermostat, lighting system, sound system, and access control system can be automated based on certain rules or events. For example, after a user unlocks his door using his mobile device, the access control system can transmit user preferences to the thermostat to turn on the air conditioner at a certain temperature, turn on certain lighting devices in the living room, and start playing specific user-defined music through the speaker system.
在本发明的一些实施例中,设备互连集线器根据为用户、管理员或主人定制的设置而进行操作。当人员登记触发事件时,它们被识别,并且设备互连集线器根据对该人员定制的设置进行操作。例如,家长可以配置互连设备集线器的设置,使得当家长解锁前门时,卧室和厨房中的灯被打开,来自特定播放列表的音乐在客厅音响系统上播放,并打开空调/暖气使房屋温度达到70°。孩子可以配置不同的设置,其打开房屋的不同的灯,播放不同的播放列表,并将房间的温度加热/冷却到不同的温度。因此,如果家长解锁家的前门,从而登记触发事件,则设备互连集线器可以根据家长定义的定制设置来操作,并且打开卧室和厨房中的灯,从在客厅音响系统中的特定播放列表播放音乐,并打开空调/暖气以使房屋温度达到70°。In some embodiments of the present invention, the device interconnect hub operates according to settings customized for a user, administrator, or owner. When a person registers a trigger event, they are identified and the device interconnect hub operates according to the settings customized for that person. For example, a parent can configure the settings of the interconnect device hub so that when the parent unlocks the front door, the lights in the bedroom and kitchen turn on, music from a specific playlist plays on the living room audio system, and the air conditioning/heating turns on to bring the house temperature to 70°. A child can configure different settings that turn on different lights in the house, play different playlists, and heat/cool the room to different temperatures. Thus, if a parent unlocks the front door of the home, thereby registering a trigger event, the device interconnect hub can operate according to the customized settings defined by the parent and turn on the lights in the bedroom and kitchen, play music from a specific playlist on the living room audio system, and turn on the air conditioning/heating to bring the house temperature to 70°.
在一些实施例中,如上所述的门的移动或位置可以登记引起设备互连集线器执行某些任务或任务序列的触发事件。例如,当确定门被打开时,可以登记触发事件以与恒温器通信以在一定温度下打开空调器,打开客厅中的某些照明设备,并开始通过扬声器系统播放特定用户定义的音乐。In some embodiments, the movement or position of a door as described above can register a trigger event that causes the device interconnect hub to perform certain tasks or sequences of tasks. For example, when it is determined that a door is opened, a trigger event can be registered to communicate with the thermostat to turn on the air conditioner at a certain temperature, turn on certain lighting fixtures in the living room, and start playing specific user-defined music through the speaker system.
图6示出了使主人或管理员能够控制接入控制系统的过程。在步骤601中,向主人或管理员显示一组可配置的规则和接入权限。在步骤602中,主人或管理员配置接入权限以确定用户可以接入哪些智能锁。在步骤603中,主人或管理员配置指定用户可以使用哪些接入信道来打开智能锁,以及在打开智能锁之前必须满足何种(如果有的话)条件的规则。Figure 6 illustrates the process of enabling an owner or administrator to control an access control system. In step 601, the owner or administrator is presented with a set of configurable rules and access permissions. In step 602, the owner or administrator configures access permissions to determine which smart locks a user can access. In step 603, the owner or administrator configures rules that specify which access channels a user can use to open a smart lock, and what conditions, if any, must be met before the smart lock can be opened.
当具有附条件的接入权限的用户如上所述提交打开智能锁的请求时,主人或管理员接收接入请求,如步骤604所示。例如,可以以文本消息、电话呼叫或作为显示在主人或管理员的移动应用上的通知的形式接收请求。该请求可以直接从用户接收,或者可以从接收到来自用户的请求的中央接入服务器接收。When a user with conditional access rights submits a request to open the smart lock as described above, the owner or administrator receives the access request, as shown in step 604. For example, the request may be received in the form of a text message, a phone call, or as a notification displayed on the owner's or administrator's mobile app. The request may be received directly from the user or from a central access server that receives the request from the user.
在步骤605中,用户请求被验证。可以通过例如要求用户提供诸如口令的附加凭证来验证用户。作为另一示例,主人或管理员可以获得用户的移动设备的ID以确定移动设备是否已被报告为丢失或被盗。如果被盗,则可以将规则配置为自动拒绝接入请求,并将尝试使用通知主人、管理员或用户。In step 605, the user request is authenticated. The user can be authenticated by, for example, requiring the user to provide additional credentials such as a password. As another example, the owner or administrator can obtain the ID of the user's mobile device to determine whether the mobile device has been reported lost or stolen. If it has been reported stolen, a rule can be configured to automatically deny the access request and notify the owner, administrator, or user of the attempt to access the device.
如果主人或管理员验证用户,则主人或管理员可以进行到步骤606,其中主人或管理员确定是否准许用户接入。在此步骤中,可以检查规则和接入权限以确定用户是否被授权打开特定的锁,并且在打开锁之前是否必须满足任何条件。例如,可以确定用户没有被授权打开特定智能锁,或者没有被授权在特定的一天打开智能锁。如果用户被授权,主人或管理员可能仍然决定拒绝用户接入。例如,即使用户被授权,主人或管理员也可能更愿意使用自己的判断来批准请求。如果主人或管理员确定批准请求,则生成令牌或密码并将其提供给用户。令牌或密码可以如上所述发送给用户。例如,令牌或密码可以以文本消息、电话呼叫或作为在用户的移动应用上显示的通知的形式发送。然后可以在步骤608将令牌或密码提供给用户。If the owner or administrator authenticates the user, the owner or administrator may proceed to step 606, where the owner or administrator determines whether to grant access to the user. In this step, rules and access permissions may be checked to determine whether the user is authorized to open a specific lock and whether any conditions must be met before the lock can be opened. For example, it may be determined that the user is not authorized to open a specific smart lock, or is not authorized to open a smart lock on a specific day. If the user is authorized, the owner or administrator may still decide to deny the user access. For example, even if the user is authorized, the owner or administrator may prefer to use their own judgment to approve the request. If the owner or administrator decides to approve the request, a token or password is generated and provided to the user. The token or password may be sent to the user as described above. For example, the token or password may be sent in the form of a text message, a phone call, or as a notification displayed on the user's mobile app. The token or password may then be provided to the user in step 608.
根据本发明的一些实施例,可以在主人设备、管理员设备或用户设备上安装移动应用,用于控制使用接入控制系统。主人或管理员的移动应用可以提供以下接口:查看接入信息;创建接入权限;查看接入日志;管理用户权限;打开锁;以及创建成功进入以及拒绝进入的报告,包括为什么进入被拒绝的详情(例如,用户在允许其接入锁的时间表或日期之外接入锁,或者起初就不允许用户打开锁)。以这种方式,接入控制系统提供了机械锁和钥匙系统的安全和可靠性优势,同时还提供了移动设备和电子锁系统的报告和实时增值服务。类似地,用户的移动应用可以提供以下接口:接收接入警报;请求接入权限;查看接入日志;以及打开锁。According to some embodiments of the present invention, a mobile application can be installed on a master device, an administrator device, or a user device to control the use of the access control system. The master or administrator's mobile application can provide the following interfaces: viewing access information; creating access permissions; viewing access logs; managing user permissions; opening locks; and creating reports of successful and denied access, including details of why access was denied (for example, the user accessed the lock outside of the schedule or date on which access was allowed, or the user was not allowed to open the lock in the first place). In this way, the access control system provides the security and reliability advantages of mechanical locks and key systems while also providing reporting and real-time value-added services for mobile devices and electronic lock systems. Similarly, the user's mobile application can provide the following interfaces: receiving access alerts; requesting access permissions; viewing access logs; and opening locks.
在本发明的一个方面,移动应用提供如图7A所示的“通知者”特征,其向主人、管理员和用户通知有关接入事件和接入权限的信息。对于主人和管理员,移动应用将接收有关接入事件的信息,例如用户何时接入锁。如图7A所示,该特征向主人或管理员提供了约翰逊史密斯希望打开大门,靠近大门,或正试图打开大门的警报。该警报近实时地将接入事件或接入权限的变化通知主人或管理员。由于可以将事件快速传送给主人或管理员,因此移动应用可以另外近实时地向主人或管理员提供拒绝用户接入受保护场地的选项。类似地,当用户尝试用无效认证信息(例如,不正确的密码)打开锁时,移动应用也可以接收警报。In one aspect of the present invention, the mobile application provides a "notifier" feature, as shown in Figure 7A, which notifies the owner, administrator, and user about access events and access permissions. For the owner and administrator, the mobile application will receive information about access events, such as when a user accesses the lock. As shown in Figure 7A, this feature provides the owner or administrator with an alert that Johnson Smith wants to open the gate, is approaching the gate, or is attempting to open the gate. The alert notifies the owner or administrator of access events or changes in access permissions in near real time. Because events can be transmitted to the owner or administrator quickly, the mobile application can also provide the owner or administrator with the option of denying the user access to the protected venue in near real time. Similarly, the mobile application can also receive an alert when a user attempts to open the lock with invalid authentication information (e.g., an incorrect password).
使用移动设备的无线或基于位置的能力,移动应用可以确定用户停留在受保护场地的时间长度。移动应用还可以从按钮接收关于其何时被锁定和解锁的信息,以确定用户何时获得接入并随后离开受保护场地。如下面更详细的解释,锁上的按钮也将其锁定/解锁状态发送给用户的移动设备。然后,用户的移动设备可以向中央接入服务器发送锁定/解锁状态,然后中央接入服务器可以向主人或管理员发送关于锁状态的通知。以这种方式,在用户随后离开受保护场地之后,主人或管理员可能会被告警该场地仍然被解锁,并且可以联系用户通知其忘记锁定场地。Using the mobile device's wireless or location-based capabilities, the mobile application can determine the length of time a user has been at a protected venue. The mobile application can also receive information from the button about when it was locked and unlocked to determine when a user gained access and subsequently left the protected venue. As explained in more detail below, the button on the lock also sends its locked/unlocked status to the user's mobile device. The user's mobile device can then send the locked/unlocked status to a central access server, which can then send a notification about the lock status to the owner or administrator. In this way, after the user subsequently leaves the protected venue, the owner or administrator can be alerted that the venue is still unlocked and can contact the user to notify them that they forgot to lock the venue.
在本发明的一个方面,移动应用可以向主人或管理员显示已经锁定或解锁受保护地点的哪些区域,如图7B所示。当用户使用其移动设备解锁或锁定场地时,移动设备将信息传送到中央接入服务器。然后,中央接入服务器向主人或管理员提供锁定/解锁状态。当用户使用替代的接入信道来锁定或解锁场地时,该信息被存储在智能锁上,并且在下一次使用移动设备来打开智能锁时被传送到中央接入服务器。In one aspect of the present invention, the mobile application can display to the owner or administrator which areas of a protected location have been locked or unlocked, as shown in Figure 7B. When a user unlocks or locks a location using their mobile device, the mobile device transmits this information to a central access server. The central access server then provides the owner or administrator with the lock/unlock status. When the user uses an alternative access channel to lock or unlock the location, this information is stored on the smart lock and transmitted to the central access server the next time the mobile device is used to open the smart lock.
移动应用还被编程为提供用于显示和配置这些场地如何被解锁的用户接口。例如,如图7C所示,移动应用可以显示场地是否可以自动或手动打开。The mobile application is also programmed to provide a user interface for displaying and configuring how these venues are unlocked. For example, as shown in FIG7C , the mobile application can display whether the venue can be opened automatically or manually.
移动应用的另一个接口提供哪些用户可以接入锁的显示。如图7D所示,接口显示每个用户的图片及其个人信息,如姓名和联系信息。可以选择或删除列表中的每个用户。选择用户会导致移动应用显示另一个显示有关用户的附加详细信息的接口。Another interface in the mobile app displays which users can access the lock. As shown in Figure 7D, the interface displays a picture of each user and their personal information, such as name and contact information. Each user in the list can be selected or removed. Selecting a user causes the mobile app to display another interface showing additional detailed information about the user.
在本发明的一个方面,通知者将显示关于对用户的接入权限所做的改变的警报和消息。如图7E所示,通知者可以告知用户其在特定时间(例如从星期一到星期五,从下午5点到下午8点)对特定场地(例如,大门A)具有接入权限。类似地,通知者可以通知用户其接收到对特定区域的新的接入权限,或者这些接入权限已被限制或被撤销。In one aspect of the present invention, the notifier displays alerts and messages regarding changes to a user's access rights. As shown in FIG7E , the notifier can inform the user that they have access rights to a specific location (e.g., Gate A) during specific times (e.g., from 5 p.m. to 8 p.m., Monday through Friday). Similarly, the notifier can inform the user that they have received new access rights to a specific area, or that these access rights have been restricted or revoked.
虽然图7A-7E示出了使用移动应用接口的通知者的警报和消息传递功能,但是关于接入权限的警报和消息也可以通过SMS文本、电子邮件或通过电话传送给用户。因此,例如,当用户接入权限改变时,用户可以接收通知用户其接入权限已被改变的SMS文本。While Figures 7A-7E illustrate the alert and messaging functionality of the notifier using a mobile application interface, alerts and messages regarding access permissions may also be delivered to the user via SMS text, email, or over the phone. Thus, for example, when a user's access permissions change, the user may receive an SMS text notifying the user that their access permissions have changed.
在本发明的一个方面,移动应用提供了一个“授权”功能,其使得主人和管理员能够创建和改变用户的接入权限,并允许用户请求接入权限。每个用户的接入权限存储在主人设备、管理员设备或中央接入服务器中,其中可以对每个用户接入锁的尝试进行验证。In one aspect of the present invention, the mobile application provides an "authorization" function that enables owners and administrators to create and change user access permissions and allow users to request access permissions. Each user's access permissions are stored on the owner's device, administrator's device, or a central access server, where each user's attempt to access the lock can be authenticated.
如图8A所示,移动应用可以为主人或管理员提供用于创建用户接入权限和规则的接口。例如,该接口允许主人或管理员指定用户的联系信息(例如,姓名,电话号码,职业,年龄),用户将具有接入权限的特定个人锁,用户可以使用的接入信道(例如,密码,生物特征扫描,将令牌无线发送到智能锁,或其任何组合),以及对用户接入的条件(例如,对一天中的时间的限制)。移动应用的授权功能可供主人和管理员使用。在管理员使用的授权特征的一些实施例中,在提供接入信息之后,管理员将该信息作为请求提交给主人。然后将信息传送给最终批准或拒绝为新用户创建接入权限的主人。接入权限的创建可能近实时地发生;当主人批准用户的请求或管理员的请求时,用户可以立即开始使用他们的移动设备、密码或生物特征扫描来接入指定的智能锁。As shown in Figure 8A, the mobile application can provide an interface for the owner or administrator to create user access permissions and rules. For example, the interface allows the owner or administrator to specify the user's contact information (e.g., name, phone number, occupation, age), the specific personal locks to which the user will have access rights, the access channels the user can use (e.g., password, biometric scan, wireless transmission of a token to the smart lock, or any combination thereof), and the conditions for user access (e.g., time of day restrictions). The authorization function of the mobile application is available to both the owner and the administrator. In some embodiments of the authorization feature used by the administrator, after providing access information, the administrator submits the information as a request to the owner. The information is then transmitted to the owner, who ultimately approves or denies the creation of access rights for the new user. The creation of access rights can occur in near real time; when the owner approves the user's request or the administrator's request, the user can immediately begin accessing the designated smart lock using their mobile device, password, or biometric scan.
在本发明的一个方面,主人或管理员可以指定场地内的特定的锁、区域或门,如图8B所示。如图8B所示,主人或管理员可以选择诸如前大门、健身房、娱乐室或办公室之类的锁定区域来授权对用户的接入。移动应用可以使得该配置远程且近实时地发生;不需要主人或管理员在现场进行密钥拷贝或更新任何记录而导致延迟。In one aspect of the present invention, an owner or administrator can designate specific locks, areas, or doors within a facility, as shown in FIG8B . As shown in FIG8B , an owner or administrator can select locked areas such as the front gate, gym, recreation room, or office to grant access to users. A mobile application allows this configuration to occur remotely and in near real time; there is no need for the owner or administrator to be on-site to copy keys or update any records, which can cause delays.
状态可以对应于从上述传感器接收到的对应于门被打开或关闭以及门栓被锁定或解锁的信息。The status may correspond to information received from the aforementioned sensors corresponding to whether the door is opened or closed and the deadbolt is locked or unlocked.
如上所述,授权特征允许主人或管理员添加对用户接入的限制。如图8C所示,主人或管理员可以允许用户具有永久无期限的接入,或者可以限制用户的接入是临时的,或者可以限制接入在一整天,一整周,一整月或一整年中的选定间隔期间内。As described above, the authorization feature allows the owner or administrator to add restrictions on user access. As shown in Figure 8C, the owner or administrator can allow the user to have permanent, unlimited access, or can limit the user's access to be temporary, or can limit access to selected intervals within a full day, a full week, a full month, or a full year.
授权特征还可以允许主人或管理员根据具体情况提供一次性接入。如上所述,用户可以通过向主人或管理员发送请求来接收一次性接入。该请求可以通过移动应用的用户授权接口、SMS文本、电子邮件或通过电话呼叫。该请求可以针对特定的锁或锁组,以及针对特定的接入类型。主人或管理员可以近实时地确定准许或拒绝该请求。如果主人或管理员批准请求,则用户可以打开锁。使用记录和报告功能,主人或管理员可以确定用户何时完成使用锁,并禁用或去除用户的接入权限。可替代地,如果主人或管理员决定准许用户接入,则主人或管理员可以向用户提供只能使用一次的动态密码,并且在使用之后到期。The authorization feature can also allow the owner or administrator to provide one-time access on a case-by-case basis. As described above, a user can receive one-time access by sending a request to the owner or administrator. This request can be made through the user authorization interface of the mobile app, an SMS text, an email, or through a phone call. The request can be for a specific lock or group of locks, as well as for a specific access type. The owner or administrator can determine in near real time whether to grant or deny the request. If the owner or administrator approves the request, the user can open the lock. Using the logging and reporting functions, the owner or administrator can determine when a user has finished using the lock and disable or remove the user's access rights. Alternatively, if the owner or administrator decides to grant the user access, the owner or administrator can provide the user with a dynamic password that can only be used once and expires after use.
如图8D所示,接入类型接口允许主人或管理员配置规则以指定什么接入信道可用于用户打开智能锁。例如,主人或管理员可以指定用户是否可以通过将令牌无线地发送到智能锁、在小键盘上输入密码、使用生物特征扫描或其任何组合来打开智能锁。主人或管理员还可以添加限制用户何时可以接入智能锁的条件,例如添加时间或日期限制。例如,主人或管理员可以指定用户可以在星期一至星期五使用智能手机或移动设备接入锁,但周末必须另外提供生物特征扫描或密码。As shown in Figure 8D, the access type interface allows the owner or administrator to configure rules to specify what access channels can be used by users to open the smart lock. For example, the owner or administrator can specify whether a user can open the smart lock by wirelessly sending a token to the smart lock, entering a password on the keypad, using a biometric scan, or any combination thereof. The owner or administrator can also add conditions that limit when users can access the smart lock, such as adding time or date restrictions. For example, the owner or administrator can specify that users can access the lock using a smartphone or mobile device Monday through Friday, but must provide a biometric scan or password on weekends.
在本发明的一个实施例中,主人或管理员可以使用其各自的移动设备将用户的生物特征扫描添加到智能锁。例如,用户可以在智能手机上扫描其指纹,并通过SMS文本或移动应用将其发送给主人或管理员。然后,主人或管理员可以将指纹添加到中央接入服务器,或者在下一次其移动设备与智能锁通信时添加到智能锁中。以这种方式,可以将新用户的生物特征扫描远程添加到智能锁中,而无需用户先前位于智能锁处。In one embodiment of the present invention, an owner or administrator can add a user's biometric scan to a smart lock using their respective mobile device. For example, a user can scan their fingerprint on a smartphone and send it to the owner or administrator via SMS text or mobile app. The owner or administrator can then add the fingerprint to a central access server or to the smart lock the next time their mobile device communicates with the smart lock. In this way, a new user's biometric scan can be added to the smart lock remotely without the user having to be physically present at the smart lock.
用户可以使用其移动设备上的移动应用发送对于接入权限的请求。登记后,用户可以加载场地列表及其相应的锁,并从智能锁的相应主人或管理员请求接入。用户可以搜索主人或管理员,并直接从他们请求接入权限。作为使用移动应用的替代方案,用户可以通过SMS文本、电子邮件或通过电话请求接入。Users can request access using the mobile app on their mobile device. After registration, users can load a list of venues and their corresponding locks and request access from the corresponding owner or administrator of the smart lock. Users can search for the owner or administrator and request access directly from them. As an alternative to using the mobile app, users can request access via SMS text, email, or phone call.
主人或管理员可以在任何时候通过授权接口修改每个用户的接入权限,如图8E所示。在本发明的一个方面,可以修改接入权限,而不通知或告知用户。以这种方式,主人或管理员可以远程地更改或删除与移动设备相关联的接入权限,而不需要与用户的任何接入或交互。因此,如果移动设备被盗或丢失,则主人或管理员可以禁用该特定的移动设备,防止其被未经授权的人员使用或以不期望的方式使用。在移动设备可能被禁用之前,主人或管理员可能会被提示以其他凭据来验证其身份。如果被禁用的手机之后被用于接入智能锁(例如,由盗贼或不期望的人员),则智能锁将拒绝它,并且主人或管理员将被通知未经授权的接入尝试。如下面的示例性说明所示,授权接口允许主人或管理员取消授权用户,禁用用户或将其从锁中完全移除。对用户接入权限的这些更改可以近实时地实现。The owner or administrator can modify the access permissions of each user at any time through the authorization interface, as shown in Figure 8E. In one aspect of the present invention, access permissions can be modified without notifying or informing the user. In this way, the owner or administrator can remotely change or delete the access permissions associated with a mobile device without requiring any access or interaction with the user. Therefore, if a mobile device is stolen or lost, the owner or administrator can disable that specific mobile device to prevent it from being used by unauthorized persons or in an unintended manner. Before the mobile device can be disabled, the owner or administrator may be prompted to verify their identity with additional credentials. If the disabled phone is later used to access the smart lock (for example, by a thief or an unintended person), the smart lock will deny it, and the owner or administrator will be notified of the unauthorized access attempt. As shown in the exemplary illustration below, the authorization interface allows the owner or administrator to deauthorize a user, disable the user, or remove them from the lock entirely. These changes to user access permissions can be implemented in near real time.
在本发明的一个方面,移动应用提供“报告”特征,其使得主人和管理员能够查看每个用户或每个锁的接入事件的记录和日志。诸如用户何时以及如何寻求或获得对智能锁的接入的各种接入事件的记录可以如上所述存储在按钮的存储介质中或存储在用户的移动设备的移动应用中。例如,当用户使用其移动设备寻求或获得对智能锁的接入时,该接入事件的记录可以被存储在移动设备或按钮中。类似地,如果用户经由冗余接入信道(例如,密码或生物特征扫描)来接入智能锁,则接入事件可以存储在按钮中,并且在另一个移动设备与智能锁接触的稍后阶段将无线地传送到中央接入服务器。In one aspect of the invention, the mobile application provides a "reporting" feature that enables owners and administrators to view records and logs of access events for each user or each lock. Records of various access events, such as when and how a user sought or obtained access to a smart lock, can be stored in the button's storage medium or in the mobile application of the user's mobile device as described above. For example, when a user seeks or obtains access to a smart lock using their mobile device, a record of that access event can be stored in the mobile device or in the button. Similarly, if a user accesses the smart lock via a redundant access channel (e.g., a password or biometric scan), the access event can be stored in the button and wirelessly transmitted to the central access server at a later stage when another mobile device comes into contact with the smart lock.
接入事件还可以包括由上述传感器接收的指示门是否已被打开或关闭或者门栓是否已被锁定或解锁的信息。Access events may also include information received by the aforementioned sensors indicating whether a door has been opened or closed or whether a deadbolt has been locked or unlocked.
每个用户或每个智能锁的接入事件的日志可以被周期性地汇编并传送或近实时地传送给主人或管理员。例如,如图8F所示,可以将用户当天的接入事件的日志汇编并报告给主人或管理员。日志显示特定用户的每个接入事件的详情,例如接入了什么智能锁,如何接入该智能锁,以及用户接入它的精确时间,以及用户在场地花费了多长时间。日志可以进一步包括智能锁的成功和不成功打开的记录,允许用户打开智能锁的时间段,以及用户何时请求接入智能锁。可以对于每个智能锁汇编类似的日志,报告谁接入智能锁,如何接入智能锁以及何时接入智能锁。主人和管理员可以配置其比较喜欢收到日志报告的频率。报告可以传送到中央接入服务器,或直接传送给主人或管理员。A log of access events for each user or each smart lock can be compiled and transmitted periodically or in near real time to the owner or administrator. For example, as shown in Figure 8F, a log of a user's access events for the day can be compiled and reported to the owner or administrator. The log shows the details of each access event for a specific user, such as what smart lock was accessed, how the smart lock was accessed, and the exact time the user accessed it, as well as how long the user spent at the venue. The log can further include a record of successful and unsuccessful openings of the smart lock, the time period during which the user was allowed to open the smart lock, and when the user requested access to the smart lock. A similar log can be compiled for each smart lock, reporting who accessed the smart lock, how the smart lock was accessed, and when the smart lock was accessed. Owners and administrators can configure the frequency with which they prefer to receive log reports. The report can be transmitted to a central access server or directly to the owner or administrator.
在本发明的其他实施例中,日志可以直接从智能锁直接传送到管理员或中央服务器,绕过移动设备。如上所述,智能锁可以使用其无线连接或通过网络设备将该信息直接传送到中央服务器或管理员。In other embodiments of the present invention, the log can be transmitted directly from the smart lock to an administrator or central server, bypassing the mobile device. As described above, the smart lock can use its wireless connection or through a network device to transmit this information directly to the central server or administrator.
在本发明的一个方面,可以处理日志和报告以发现关于接入使用和用户的模式。具体来说,可以挖掘日志和报告以检测与用户接入不同智能锁的方式和时间有关的模式。使用这些识别的接入行为模式,接入控制系统然后可以预测接入事件以增强系统安全性或接入控制。例如,如果日志和报告指示用户每个工作日在下午5:00从前大门进入家中,则接入控制系统可以使互连设备中的进程或任务自动化,例如与照明系统通信以激活在前庭院的灯光,恒温器启动空调器。In one aspect of the present invention, logs and reports can be processed to discover patterns regarding access usage and users. Specifically, logs and reports can be mined to detect patterns related to how and when users access different smart locks. Using these identified access behavior patterns, the access control system can then predict access events to enhance system security or access control. For example, if logs and reports indicate that a user enters the home through the front door at 5:00 PM every weekday, the access control system can automate processes or tasks in connected devices, such as communicating with the lighting system to activate the lights in the front yard and the thermostat to start the air conditioner.
图9A-9C示出了用于登录移动应用,请求令牌或密码以及接收令牌或密码的用户接口。如上所述,可能要求用户在被允许请求令牌或密码之前提供诸如口令的如图9A所示的凭证。如图9B所示,接口允许用户查看他们可以接入的智能锁,以及如果他们没有智能锁接入权限,或者仅具有附条件的接入权限,他们可以向主人或管理员提交请求。如图9B所示,用户可以通过几种方式提交请求,例如通过向主人或管理员的移动设备上的移动应用发送警报,或通过向他们发送文本或打电话。如图9C所示,如果用户已被验证并被主人或管理员批准接入,则用户将接收令牌或密码。如果用户收到密码,则可以显示他们的密码供用户输入到小键盘。如果用户接收到令牌,则令牌可以被无线地发送到智能锁。Figures 9A-9C show a user interface for logging into a mobile app, requesting a token or password, and receiving a token or password. As described above, a user may be required to provide credentials such as a password as shown in Figure 9A before being allowed to request a token or password. As shown in Figure 9B, the interface allows users to view the smart locks they can access, and if they do not have access to a smart lock, or only have conditional access, they can submit a request to the owner or administrator. As shown in Figure 9B, users can submit requests in several ways, such as by sending an alert to the mobile app on the owner or administrator's mobile device, or by sending them a text or calling them. As shown in Figure 9C, if the user has been authenticated and access is approved by the owner or administrator, the user will receive a token or password. If the user receives a password, their password can be displayed for the user to enter into a keypad. If the user receives a token, the token can be sent wirelessly to the smart lock.
在本发明的另外的方面,用日志发现的用户模式可以用于优化智能锁的某些组件。例如,日志可以用于确定用户何时通常离开家以及到达家。利用该信息,智能锁可以确定智能锁最不可能使用的某些时间段,并且因此可能改变其功能或其操作模式中的一些。例如,智能锁可以确定在工作日的营业时间内通常没有人进入家或离开家。在此期间,智能锁可能进入“睡眠”模式,其中智能锁会停用某些特征以降低其功耗。In another aspect of the present invention, user patterns discovered using logs can be used to optimize certain components of the smart lock. For example, the logs can be used to determine when a user typically leaves and arrives at home. Using this information, the smart lock can determine certain times when the smart lock is least likely to be used and, accordingly, may modify its functionality or some of its operating modes. For example, the smart lock may determine that no one typically enters or leaves the home during business hours on weekdays. During this time, the smart lock may enter a "sleep" mode, in which it deactivates certain features to reduce its power consumption.
在不脱离本发明及其权利要求的精神和范围的情况下,本领域普通技术人员可以想到本文所描述的内容的变型、修改和其他实现方式。Variations, modifications, and other implementations of what is described herein will occur to those of ordinary skill in the art without departing from the spirit and scope of the invention and the claims thereto.
Claims (17)
Applications Claiming Priority (5)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| US201562189193P | 2015-07-06 | 2015-07-06 | |
| US62/189,193 | 2015-07-06 | ||
| US15/147,759 | 2016-05-05 | ||
| US15/147,759 US9852562B2 (en) | 2015-07-06 | 2016-05-05 | Systems and methods for redundant access control systems based on mobile devices and removable wireless buttons |
| PCT/IB2016/000968 WO2017006172A1 (en) | 2015-07-06 | 2016-07-06 | Lock and methods for redundant access control |
Publications (2)
| Publication Number | Publication Date |
|---|---|
| HK1248024A1 HK1248024A1 (en) | 2018-10-05 |
| HK1248024B true HK1248024B (en) | 2021-03-19 |
Family
ID=
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| CN107889536B (en) | Lock and method for redundant access control | |
| US10726653B2 (en) | Systems and methods for redundant access control systems based on mobile devices | |
| US11321978B2 (en) | Systems and methods for secure lock systems with redundant access control | |
| US9672674B2 (en) | Systems and methods for secure lock systems with redundant access control | |
| US11436879B2 (en) | Wireless access control system and methods for intelligent door lock system | |
| KR102713609B1 (en) | Entrance management system and method thereof | |
| HK1248385A1 (en) | Lock for providing redundant channels of access | |
| US9691198B2 (en) | Wireless access control system and methods for intelligent door lock system | |
| KR102726058B1 (en) | Entrance management system and method thereof | |
| HK1248024B (en) | Lock and methods for redundant access control | |
| HK40019552B (en) | Lock for providing redundant channels of access | |
| HK40019552A (en) | Lock for providing redundant channels of access |