IP Library › Granted Patent US 12,682,711
Granted Patent B2
US 12,682,711 · App. 18/587,933 · Granted Jul 14, 2026

Intelligent access control system

Inventors: Jeremy R. Fox (Georgetown, TX); Suman Patra (Kolkata, IN); Logan Bailey (Atlanta, GA); Zachary A. Silverstein (Georgetown, TX)
Assignee: International Business Machines Corporation
G07C9/28G07C9/21G07C9/215
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,682,711
App. No.
18/587,933
Filed
Feb 26, 2024
Granted
Jul 14, 2026
Kind
B2
Art Unit
2685
USPC
340/5.61
Abstract

A method, by an intelligent access control system, of implementing access control to a controlled area having a plurality access areas divided by at least one access point includes the following operations. A security token is generated. The security token is transmitted to a client module executing on a client device associated with a first user, and the client module is caused to pair with an access control device associated with the first user. The client module is caused to transfer the security token to the access control device. A physical location of the client device within the controlled area is monitored. A determination is made, by an access control system and based upon the physical location, that the first user is to be revalidated. The client module causes, based upon the determining, the client device to generate an alert.

Claims (51)

1 . A computer-implemented method, by an intelligent access control system, of implementing access control to a controlled area having a plurality of access areas divided by at least one access point, the computer-implemented method comprising:

generating a security token;

transmitting the security token to a client module executing on a first client device associated with a first user;

causing the client module to pair with an access control device associated with the first user;

causing the client module to transfer the security token to the access control device;

monitoring a physical location of the first client device within the controlled area; and

determining, based on the physical location of the first client device, that the first user is to be validated, wherein the client module causes, based on the determining that the first user is to be validated, the first client device to generate an alert.

2 . The computer-implemented method of claim 1 , wherein

the security token is regenerated and transmitted to the client module based on the access control device being used at one of the at least one access point.

3 . The computer-implemented method of claim 1 , wherein the transmitting of the security token includes transmitting a policy associated with the controlled area to the client module.

4 . The computer-implemented method of claim 1 , wherein:

the determining that the first user is to be validated is based on a second user with a second client device being at least a certain distance away from the first client device,

the first user is a controlling user, and

the second user is a controlled user.

5 . The computer-implemented method of claim 1 , wherein the determining that the first user is to be validated is based on a time in which the first user is within one of the plurality of access areas.

6 . The computer-implemented method of claim 1 , wherein a policy is based on one of the plurality of access areas corresponding to the physical location of the first user.

7 . The computer-implemented method of claim 1 , further comprising receiving, from the client module, a request to opt into using the intelligent access control system.

8 . An intelligent access control system configured to implement access control to controlled area having a plurality of access areas divided by at least one access point, intelligent access control system comprising:

a hardware processor configured to perform operations comprising:

generating a security token;

transmitting the security token to a client module executing on a first client device associated with a first user;

causing the client module to pair with an access control device associated with the first user;

causing the client module to transfer the security token to the access control device;

monitoring a physical location of the first client device within the controlled area; and

determining, based on the physical location of the first client device, that the first user is to be validated, wherein the client module causes, based on the determining that the first user is to be validated, the first client device to generate an alert.

9 . The intelligent access control system of claim 8 , wherein the security token is regenerated and transmitted to the client module based on the access control device being used at one of the at least one access point.

10 . The intelligent access control system of claim 8 , wherein the transmitting of the security token includes transmitting a policy associated with the controlled area to the client module.

11 . The intelligent access control system of claim 8 , wherein the determining that the first user is to be validated is based on:

a second user with a second client device being at least a certain distance away from the first client device;

the first user is a controlling user; and

the second user is a controlled user.

12 . The intelligent access control system of claim 8 , wherein the determining that the first user is to be validated is based on a time in which the first user is within one of the plurality of access areas.

13 . The intelligent access control system of claim 8 , wherein a policy is based on one of the plurality of access areas corresponding to the physical location of the first user.

14 . The intelligent access control system of claim 8 , wherein the operations further comprise receiving, from the client module, a request to opt into using the intelligent access control system.

15 . A computer program product, comprising:

a computer readable storage medium having stored therein program code for implementing access control to a controlled area having a plurality of access areas divided by at least one access point,

the program code, which when executed by an intelligent access control system, causes the intelligent access control system to perform operations comprising:

generating a security token;

transmitting the security token to a client module executing on a first client device associated with a first user;

causing the client module to pair with an access control device associated with the first user;

causing the client module to transfer the security token to the access control device;

monitoring a physical location of the first client device within the controlled area; and

determining, based on the physical location of the first client device, that the first user is to be validated, wherein the client module causes, based on the determining that the first user is to be validated, the first client device to generate an alert.

16 . The computer program product of claim 15 , wherein the security token is regenerated and transmitted to the client module based on the access control device being used at one of the at least one access point.

17 . The computer program product of claim 15 , wherein the transmitting of the security token includes transmitting a policy associated with the controlled area to the client module.

18 . The computer program product of claim 15 , wherein the determining that the first user is to be validated is based on:

a second user with a second client device being at least a certain distance away from the first client device;

the first user is a controlling user; and

the second user is a controlled user.

19 . The computer program product of claim 15 , wherein the determining that the first user is to be validated is based on a time in which the first user is within one of the plurality of access areas.

20 . The computer program product of claim 15 , wherein a policy is based upon one of the plurality of access areas corresponding to the physical location of the first user.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 27, 2024
From: FOX, JEREMY R.; PATRA, SUMAN; BAILEY, LOGAN; SILVERSTEIN, ZACHARY A.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 066574/0717 →
Continuity (1)
Related Publication 20250273029A1 · Aug 28, 2025
References Cited (25)
US 9058702B2 · Chao · 2015 [cited by examiner]
US 9129450B2 · Robertson · 2015 [cited by examiner]
US 9444805B1 · Saylor · 2016 [cited by examiner]
US 9697656B2 · Trani · 2017 [cited by examiner]
US 10089807B2 · Plüss · 2018 [cited by examiner]
US 10186098B2 · Lingan · 2019 [cited by examiner]
US 10297094B2 · Day et al. · 2019 [cited by applicant]
US 10769924B2 · H. Kazerouni · 2020 [cited by examiner]
US 11049346B2 · Friedli · 2021 [cited by examiner]
US 11373473B2 · Biehlmann · 2022 [cited by applicant]
US 11606667B2 · Wang · 2023 [cited by applicant]
US 11640462B2 · Shrestha et al. · 2023 [cited by applicant]
US 11887416B2 · Hoyer · 2024 [cited by examiner]
US 11961344B2 · Kincaid · 2024 [cited by examiner]
US 11995929B2 · Verma · 2024 [cited by examiner]
US 12315319B2 · Shenoi · 2025 [cited by examiner]
US 20140375421A1 · Morrison · 2014 [cited by examiner]
US 20180011458A1 · Aggarwal et al. · 2018 [cited by applicant]
Crawford, J. et al., “Multi-Factor Authentication in Physical Security Environments Using Wireless Identity and Location Tracking,” Cisco Systems, Inc. © 2018, IP.com Prior Art Database, Technical Disclosure No. IPCOM00… [cited by applicant]
“Intelligent Co-Working Spaces Enabled by Smart Building Management, Augmented Reality & IoT,” IP.com Prior Art Database, Technical Disclosure No. IPCOM000268377D, Jan. 26, 2022, 5 pg. [cited by applicant]
“Utilization of Non-Fungible Tokens Persisting on a Permissioned Blockchain in an Edge System to Allow Time-Sensitive Electronic Access Control of a Premises,” IP.com Prior Art Database, Technical Disclosure No. IPCOM00… [cited by applicant]
Jansen, W., “Authenticating Mobile Device Users Through Image Selection,” The National Institute of Standards and Technology, WIT Transactions on Information and Communication Technologies, Apr. 7, 2004, vol. 30, 10 pg. [cited by applicant]
“NAC Deployment Guide, Network Admission Control Framework, Deployment Guide,” Cisco Systems, Inc. © 1992-2006, Guide C07-332601-00, Feb. 2006, 58 pg. [cited by applicant]
“Sonicwall Secure Mobile Access 9.0 User Guide,” SonicWall Inc. © 2018, 162 pg. [cited by applicant]
Mell, P. et al., The NIST Definition of Cloud Computing, National Institute of Standards and Technology, U.S. Dept. of Commerce, Special Publication 800-145, Sep. 2011, 7 pg. [cited by applicant]