EP2691940B1 - Gestion de droits d'accès à des données de fonctionnement et/ou de commande de bâtiments ou complexes de bâtiments - Google Patents

Gestion de droits d'accès à des données de fonctionnement et/ou de commande de bâtiments ou complexes de bâtiments Download PDF

Info

Publication number
EP2691940B1
EP2691940B1 EP12709625.3A EP12709625A EP2691940B1 EP 2691940 B1 EP2691940 B1 EP 2691940B1 EP 12709625 A EP12709625 A EP 12709625A EP 2691940 B1 EP2691940 B1 EP 2691940B1
Authority
EP
European Patent Office
Prior art keywords
user
building
access rights
communication
service
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Active
Application number
EP12709625.3A
Other languages
German (de)
English (en)
Other versions
EP2691940A1 (fr
Inventor
Adrian Bünter
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Inventio AG
Original Assignee
Inventio AG
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Inventio AG filed Critical Inventio AG
Priority to PL12709625T priority Critical patent/PL2691940T3/pl
Priority to EP12709625.3A priority patent/EP2691940B1/fr
Publication of EP2691940A1 publication Critical patent/EP2691940A1/fr
Application granted granted Critical
Publication of EP2691940B1 publication Critical patent/EP2691940B1/fr
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Classifications

    • GPHYSICS
    • G07CHECKING-DEVICES
    • G07CTIME OR ATTENDANCE REGISTERS; REGISTERING OR INDICATING THE WORKING OF MACHINES; GENERATING RANDOM NUMBERS; VOTING OR LOTTERY APPARATUS; ARRANGEMENTS, SYSTEMS OR APPARATUS FOR CHECKING NOT PROVIDED FOR ELSEWHERE
    • G07C9/00Individual registration on entry or exit
    • G07C9/30Individual registration on entry or exit not involving the use of a pass
    • G07C9/38Individual registration on entry or exit not involving the use of a pass with central registration
    • GPHYSICS
    • G07CHECKING-DEVICES
    • G07CTIME OR ATTENDANCE REGISTERS; REGISTERING OR INDICATING THE WORKING OF MACHINES; GENERATING RANDOM NUMBERS; VOTING OR LOTTERY APPARATUS; ARRANGEMENTS, SYSTEMS OR APPARATUS FOR CHECKING NOT PROVIDED FOR ELSEWHERE
    • G07C9/00Individual registration on entry or exit
    • G07C9/20Individual registration on entry or exit involving the use of a pass
    • G07C9/27Individual registration on entry or exit involving the use of a pass with central registration

Definitions

  • the invention relates to a system for managing access rights to operating and / or control data of buildings or building complexes. Furthermore, the invention relates to a method for operating such a system.
  • the access rights are usually assigned and managed for the individual systems or components. As a rule, this is an access of an authorized awarded and managed. As a rule, an access by an authorized user takes place via the interfaces provided by the building operator to the respective systems or installations.
  • the US 2002 099945 A1 discloses a system for door access controls and key management.
  • a door lock / control component is assigned to each shaft door. Such components are interconnected for communication via a communication network.
  • a key management system is for storing an identification code which is provided as a key for a single user.
  • the door lock / control member serves to read the user's key and check if that key has access to a landing door and operates that door in response to this access authorization. In this case, however, a user is only granted access rights to various doors of a building complex on the basis of an identity
  • the invention is based on the object of enabling a central service for enabling data access to one or more buildings.
  • a system for managing access rights to operating and / or control data of buildings or building complexes comprising: a first server for a building authorization service with at least one authorization database for storing user-specific access rights for specific buildings or building complexes, a second communication release service server having an authentication database for storing users registered in the system, the authentication database comprising a list of all users having user specific access rights, the list containing, for each user having access rights, the buildings or building complexes for which the User has access rights, wherein the communication release service for releasing a communication of a user with those for him in the list behind ten buildings or building complexes is provided and wherein the building authorization service to release the specific access rights for the user on operating and / or control data of the building or building complex is provided based on the stored in the authorization database access rights.
  • the object is further achieved by a method for operating a system for managing access rights to operating and / or control data of buildings or building complexes, in which a running on a first server communication release service communication of a user logged in with an identity with the for him in a list of stored buildings or building complexes, if its identity matches an identity stored in the list, and a building automation service running on a second server after the release of the communication by the communication release service grants the user specific access rights to the building's operation and / or control data or Building complex based on stored in an authentication database
  • the invention is based on the recognition that it is advantageous to provide access rights to building-specific data via a system in which the authentication of a user who wishes to have access to the data is separate from the specific access rights stored for the corresponding user.
  • the authentication of a registered user can be done in a simple manner via an application, for example via a web application provided by a service provider.
  • the service that regulates the authentication of the user does not require any special information as to which specific data or data sources the user has access to. Likewise, no information is needed about the specific role that the user fills in the system.
  • the authentication service merely has to determine whether the user has been registered at all and authorized for access, ie communication with a specific building or building complex. The operator of the system does not need to have any trustworthy data.
  • the trusted data can be managed directly in the building management.
  • the users registered in the system with their identity and also their role, i. which function they are allowed to perform and what they are allowed to do with the data released for communication. Likewise, it is stored, which extent of access rights they have.
  • the specific data maintenance can thus be carried out independently by the building management on site.
  • a user logon of the system can be made centrally via the authorization service for the respective buildings registered in the system.
  • the access of users to various buildings or building complexes that are managed in the system can be made possible in a simple manner.
  • the user thus has the ability to access different buildings from different owners and retrieve operational data there, as well as to perform operations such as data updating, through a single identity with which he is deposited in the system.
  • the system is advantageous because, for example, a service technician receives access to diagnostic data of different buildings or building complexes via a single logon in the system. This allows a service technician, for example, before his visit to a single site Application query the condition of certain system components in the different buildings and already take the necessary measures in advance, or order needed spare parts.
  • the system provides easy and consistent access to the building-specific data and easy management of the necessary access rights to multiple buildings or building complexes.
  • An advantageous embodiment of the invention consists in that the communication release service runs on a central server and is provided for the release of the communication of registered users for several buildings or building complexes, each building or each building complex has its own, decentralized server for the building authorization service and between the central server and the remote server, a communication connection is provided. If a user of the system logs on with his identity to the communication release service on the central server, then it merely has to be checked whether access rights to one or more buildings or building complexes exist at all. If this is the case, a message is sent from the central server to the remote server that has the user's specific access rights.
  • the communication can also be released for several buildings or building complexes.
  • the decentralized server it is then merely determined which specific access rights exist for the logged on user and released for communication, and then this data is then released for communication.
  • a further advantageous embodiment is that the communication release service has at least one data interface for receiving identities, the user stored in an authorization database of a building authorization service with user-specific access rights.
  • the users are stored with their user-specific access rights on the decentralized server or the authorization database of the decentralized server. In doing so, users are provided with their identity, their role and the amount of data they are allowed to access.
  • the identity of the user can now be received via the data interface of the communication release service from the communication release service and stored in the list in which the identities of the users with access rights are stored. In this way it is ensured that the user identity stored in the communication release service is identical to the user identity stored in the authorization database of the corresponding building or building complex for the user.
  • the data interface can in this case be designed such that a message sent by the decentralized server can be received directly with the identity of the user and the recognition of the building, for example via the Internet. It is also conceivable that the data interface is designed so that, for example, a communication with a mobile phone, wherein the mobile phone transmits its identity and this identity is deposited at the same time as the identity of the user in the system on both the authorization database and the authentication database.
  • the communication release service may have multiple interfaces that allow the reception of sent identities from different communication media. Overall, all identities received via such interfaces are stored in the list.
  • a further advantageous embodiment consists in that the communication release service has a user interface for registration by a user by means of an identity. The user must thereby use only the one identity that has been assigned to him by the building authorization service or that corresponds to the identity of his mobile telephone.
  • the application advantageously takes place centrally via an application which is provided by the communication release service. So the user always has the same "look and feel" and easy interaction with the system is possible.
  • a further advantageous embodiment is that the user interface is provided for providing a user environment adapted to the user-specific access rights.
  • the remote server or building authorization service sends information indicating which of the user-specific environments available in the system is most suitable for operating the system. For example, depending on the role of a user, either provided a surface on which only data can be read by the user.
  • the interface may be static, so that the user has no opportunity to gain more knowledge than those provided by the building management.
  • the user interface may also be dynamic and allow for user interaction so that it can navigate in different hierarchies of the operational data structure.
  • the user interface can be designed so that the user is allowed to manipulate or manipulate the data.
  • the user can change thresholds via the system, but it is also conceivable that the user can load software updates. It is advantageous here that the user-specific user environment is provided only when the communication is also enabled for the user and the system knows which user interface is the user interface suitable for its access rights.
  • the various user interfaces themselves are provided exclusively by the communication release service and are also stored there only.
  • the building authorization service only needs to report which user interface is appropriate for the role or scope that the user is claiming.
  • the communication release service thus does not need to have the confidential data of the individual users for the provision of the user-specific user interface. Again, all that suffices is the identity and the subsequent transmission of the preferred user interface by the building authorization service. As a result, a simple handling of the user interface by the operator of the service is possible.
  • the user interfaces can be designed centrally and also changed.
  • a further advantageous embodiment consists in that the user interface when registering by a user is already provided for providing a selection of user-specific roles.
  • the user can thereby immediately restrict which of the various applications for the communication with the building-specific data is useful or necessary for him. He can already select on the user interface if he is merely a visitor, if he needs access to control data, if he wants to change something in an elevator configuration, if he only wants to know about the performance of the system by means of a scorecard containing the metrics be registered, want to be informed. He can alternatively indicate whether he would like to carry out a remote maintenance. In all of these specific applications, the user will only be provided with data corresponding to his selected current role.
  • the system 1 for managing access rights to operating and / or control data of buildings or building complexes 5 consists of a first server 2 on which a building authorization service runs.
  • the server 2 has one or more authorization databases 20.
  • User-specific access rights for specific buildings or building complexes 5 are stored in the authorization database (s) 20.
  • an identity for a user 10 of the system 1 are stored.
  • the identity of the user 10 is further defined as to what role the user 10 has. For example, the role may be limited and the user only has rights to read data generated or present in various components of the building or building complex 5. However, the role may also be that the user may manipulate data of the building complex 5.
  • an entry can be added in the authorization database 20 to the identity of the user in which the spatial extent of his access rights is defined.
  • a user can only have access rights to certain buildings of a building complex or, within a building complex, only access rights to certain system components, for example exclusively elevators or exclusively building automation or exclusively to the heating system.
  • the system 1 also has a second server 3 on which a communication release service is running.
  • the second server 3 has an authentication database 30 on. In this database, all users registered in system 1 are stored in a list 4 with their identity 4.1. Each identity of a user is further included in the list 4, to which buildings or building complexes 5 the user may access by means of communication via the communication link 23.
  • the second server 3 can in this case be operated centrally by a service provider, while the first servers 2 are arranged decentrally in the system 1.
  • the first servers 2 can be located here at any locations selected by a customer of the system. However, the first servers 2 can also be accommodated directly in the buildings or building complexes.
  • a user 10 can access the operation or control data of the buildings or building complexes via the user interface 7, which is located on the second server 3 and provided by the communication release service. For this purpose, the user 10 logs on the user interface 7 with his identity, which he has in the system. The communication release service checks whether the identity matches an identity stored in the list 4. If this is the case, it is determined from column 4.2 of list 4 for which buildings or building complexes 5 the user has access rights. Subsequently, the user is enabled to communicate with the building or building complex or several buildings or building complexes stored in column 4.2. Via the communication connection 23, the user can now access the data of the building or building complex. On site, however, only the access rights are granted to him, which are stored on the first server 2 in the authorization database.
  • the basic communication possibility is thus made possible for the user 10 by the authentication service with the aid of the information stored in the authentication database.
  • the user 10 is then granted the special data access by means of the building authorization service on the basis of the information stored in the authorization database 20. Separation of authentication and authorization is achieved in this way.
  • the authentication service allows access to different buildings or building complexes without this authentication service having confidential data.
  • the user-specific roles and access rights are only stored on the first server 2 in the building authorization service.
  • the registration of a new user for access to a building or building complex 5 can be done in different ways.
  • the user 10 may log in to the authentication service via the user interface 7. However, it must be authorized by the building management of the building to which it wishes to have access rights in order for the authentication service to enable it for communication over the communication link 23.
  • the building management system assigns the user an identity that corresponds to the one with which he logged on to the authentication service. This identity is assigned a role and scope by the facility management.
  • the data is stored on the first server 2 in the authorization database 20. If the user 10 is detected by the building management and stored in the database 20, then a message is sent to the authentication service by the building authorization service.
  • the authentication service then enters the identity of the user in the list 4 on the authentication database 30.
  • the authentication service enters the building ID of the building or building complex 5 from which the message was sent.
  • the user 10 is now in the system 1 with his identity and the buildings to which he can get access stored.
  • any standard communication can be used.
  • communication via the Internet is possible, but it is also conceivable that the communication takes place via a telecommunication line or a leased line.
  • the communication can be wired or via radio.
  • the registration of a user 10 can also take place via a device which has an identity and is capable of communication, ie, of sending and receiving data.
  • a device which has an identity and is capable of communication, ie, of sending and receiving data.
  • This may be, for example, a mobile phone, an i-phone or i-pad.
  • a registration is made on the first server 2 by the user 10 with the aid of the communication device 8.
  • the communication device in this case sends its identity to the first server 2 via a communication connection 8.1. This is done together with a request from the user as to whether he is granted access rights.
  • the identity of the user in this case, the identity of his Communication device deposited and assigned to this identity role and its scope.
  • the deposit takes place in the authorization database 20.
  • the building authorization service then transmits the communication device 8 via the communication connection 8.1 an encrypted message in which the identity is stored.
  • the identity is noted in the encrypted message, from which building this message comes, ie it is the building code deposited, which allows access to the respective building or the building complex 5 together with the identity of the authentication service.
  • the communication device 8 now transmits the encrypted message to a data interface 6 of the authentication service running on the second server 3. Here, another communication connection is used.
  • the authentication service sends the communication device 8 after receiving the encrypted message confirmation that the message has arrived.
  • the encrypted information is decrypted by the authentication service and stored in the identity of the user 10 stored in it together with the identifier of the building for which he has registered in the list 4 on the authentication database.
  • the encrypted message may be, for example, a two-dimensional barcode that can be received by the mobile device and also sent.
  • Other ways of message encryption are also conceivable. If the user 10 is now stored in the authentication service on the authentication database, he can make an application in the system 1 via the user interface 7 by means of the mobile device, whose identity is now in the system, and if the identity of the mobile stored in the list 4 matches Device with the identity at login, the user via the communication link 23, the communication with the building or building complex 5 allows.
  • the user interface 7 can be configured in many ways.
  • the user interface may have various applications through which the user can select a user-specific role when logging into system 1, and a user-specific interface is then made available to him which is optimally adapted to his needs.
  • a user-specific interface is then made available to him which is optimally adapted to his needs.
  • someone who does not need to manipulate data, but only needs to read data will be provided with a surface that has no input capabilities. If somebody has to manipulate data, for example to change thresholds, it becomes user interfaces provided through which he can make a corresponding data entry.
  • the changed data is then transmitted via the communication link 23 to the building, or complex of buildings, where, depending on the user's access rights, the data change is made in the various components installed in the building.
  • the authorization service can provide the user with a very specific operator control and monitoring interface.
  • the user is also given all the usual possibilities of visualization or access.
  • a user can connect to the authentication service or the interface of the authentication service via the Internet, via VPN, via Facebook, via Twitter, or via a normal telecommunications connection and via the interface which is then displayed in his respective environment with the Building or complex of buildings.

Landscapes

  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Management, Administration, Business Operations System, And Electronic Commerce (AREA)
  • Telephonic Communication Services (AREA)

Claims (11)

  1. Système (1) pour gérer des droits d'accès d'utilisateurs à des données de fonctionnement et/ou de commande de bâtiments ou de complexes de bâtiments (5), le système (1) comportant :
    • un premier serveur (2) pour un service d'autorisation de bâtiment avec au moins une banque de données d'autorisation (20) pour mettre en mémoire des droits d'accès, propres aux utilisateurs, à des bâtiments ou complexes de bâtiments (5) définis,
    • un deuxième serveur (3) pour un service de validation de communication avec une banque de données d'authentification (30) pour mettre en mémoire les utilisateurs enregistrés dans le système (1),
    ∘ la banque de données d'authentification (30) comportant une liste (4) de tous les utilisateurs qui sont dotés, dans la ou les banques de données d'autorisation, de droits d'accès propres aux utilisateurs,
    ∘ la liste (4) contenant, pour chaque utilisateur doté de droits d'accès, les bâtiments ou complexes de bâtiments (5) pour lesquels l'utilisateur dispose de droits d'accès,
    le service de validation de communication étant destiné à valider une communication entre un utilisateur et les bâtiments ou complexes de bâtiments (5) stockés pour lui dans la liste (4), et
    le service d'autorisation de bâtiment étant destiné à valider les droits d'accès spécifiques de l'utilisateur à des données de fonctionnement et/ou de commande du bâtiment ou du complexe de bâtiments (5) sur la base des droits d'accès stockés dans la banque de données d'autorisation (20),
    caractérisé en ce que les droits d'accès spécifiques pour un utilisateur sont définis par l'identité de celui-ci et un rôle associé à ladite identité, et l'utilisateur, en fonction de son rôle, peut avoir accès à des données de composants du bâtiment ou complexe de bâtiments par lecture ou manipulation.
  2. Système selon la revendication 1, dans lequel
    • le service de validation de communication fonctionne sur un serveur central (3) et est destiné à valider la communication d'utilisateurs enregistrés, pour plusieurs bâtiments ou complexes de bâtiments (5),
    • chaque bâtiment ou complexe de bâtiments (5) dispose de son propre serveur décentralisé (2) pour le service d'autorisation de bâtiment, et
    • entre le serveur central (3) et chaque serveur décentralisé (2) est prévue une liaison de communication (23).
  3. Système selon la revendication 1 ou 2, dans lequel le service de validation de communication dispose d'au moins une interface de données (6) pour recevoir les identités des utilisateurs mis en mémoire dans une banque de données d'autorisation (20) d'un service d'autorisation de bâtiment avec des droits d'accès propres aux utilisateurs.
  4. Système selon l'une des revendications précédentes, dans lequel le service de validation de communication comporte une surface d'utilisateur (7) pour la demande de connexion d'un utilisateur à l'aide d'une identité.
  5. Système selon la revendication 4, dans lequel la surface d'utilisateur (7) est destinée à offrir un environnement d'utilisateur adapté aux droits d'accès propres aux utilisateurs.
  6. Système selon la revendication 4 ou 5, dans lequel la surface d'utilisateur (7), lors de la demande de connexion d'utilisateur, est prête à offrir une sélection de rôles propres aux utilisateurs.
  7. Procédé pour le fonctionnement d'un système pour gérer des droits d'accès d'utilisateurs à des données de fonctionnement et/ou de commande de bâtiments ou de complexes de bâtiments (5) selon l'une des revendications 1 à 6, selon lequel
    • un service de validation de communication qui fonctionne sur un premier serveur (3) valide une communication entre un utilisateur qui a fait une demande de connexion avec une identité, et les bâtiments ou complexes de bâtiments (5) stockés pour lui dans une liste (4), si son identité correspond à une identité stockée dans la liste (4), et
    • un service d'autorisation de bâtiment qui fonctionne sur un deuxième serveur (2) valide, après validation de la communication par le service de validation de communication, des droits d'accès spécifiques de l'utilisateur à des données de fonctionnement et/ou de commande du bâtiment ou complexe de bâtiments (5) sur la base de droits d'accès stockés dans une banque de données d'autorisation (20),
    caractérisé en ce que les droits d'accès spécifiques pour l'utilisateur sont définis par l'identité de celui-ci et un rôle associé à ladite identité, et l'utilisateur, en fonction de son rôle, peut avoir accès à des données de composants du bâtiment ou complexe de bâtiments par lecture ou manipulation.
  8. Procédé selon la revendication 7, selon lequel
    • le service de validation de communication qui fonctionne sur un serveur central (3) valide la communication d'utilisateurs pour plusieurs bâtiments ou complexes de bâtiments (5),
    • par l'intermédiaire de la liaison de communication (23), le serveur central (2) transmet un message concernant la validation de la communication à un serveur décentralisé (2) du bâtiment ou complexe de bâtiments (5) sur lequel fonctionne le service d'autorisation de bâtiment.
  9. Procédé selon la revendication 7 ou 8, selon lequel un environnement d'utilisateur adapté aux droits d'accès propres aux utilisateurs est offert, après validation de la communication, à un utilisateur qui a fait une demande de connexion à l'aide d'une identité par l'intermédiaire d'une surface d'utilisateur (7) du service de validation de communication.
  10. Procédé selon la revendication 7 ou 8, selon lequel une sélection de rôles propres aux utilisateurs est offerte à un utilisateur qui a fait une demande de connexion à l'aide d'une identité par l'intermédiaire d'une surface d'utilisateur (7) du service de validation de communication.
  11. Procédé selon l'une des revendications 7 à 10, selon lequel pour l'enregistrement d'un nouvel utilisateur,
    • le service d'autorisation de bâtiment accorde des droits d'accès propres aux utilisateurs, pour des bâtiments ou complexes de bâtiments (5) définis,
    • les droits d'accès propres aux utilisateurs sont mis en mémoire dans au moins une banque de données d'autorisation, une identité, un rôle et une étendue des droits d'accès étant stockés pour chaque utilisateur doté de droits d'accès,
    • les identités des utilisateurs auxquels des droits d'accès propres aux utilisateurs ont été accordés sont transmises par l'intermédiaire de l'interface de données (6) au service de validation de communication,
    les identités sont stockées dans la liste (4) de la banque de données d'authentification (30) du service de validation de communication, avec une identification pour le bâtiment défini ou le complexe de bâtiments (5) pour lequel les utilisateurs ont des droits d'accès.
EP12709625.3A 2011-03-29 2012-03-16 Gestion de droits d'accès à des données de fonctionnement et/ou de commande de bâtiments ou complexes de bâtiments Active EP2691940B1 (fr)

Priority Applications (2)

Application Number Priority Date Filing Date Title
PL12709625T PL2691940T3 (pl) 2011-03-29 2012-03-16 Zarządzanie prawami dostępu do danych eksploatacyjnych i/lub sterujących budynków lub kompleksów budynków
EP12709625.3A EP2691940B1 (fr) 2011-03-29 2012-03-16 Gestion de droits d'accès à des données de fonctionnement et/ou de commande de bâtiments ou complexes de bâtiments

Applications Claiming Priority (3)

Application Number Priority Date Filing Date Title
EP11160155 2011-03-29
PCT/EP2012/054679 WO2012130640A1 (fr) 2011-03-29 2012-03-16 Gestion de droits d'accès à des données de fonctionnement et/ou de commande de bâtiments ou complexes de bâtiments
EP12709625.3A EP2691940B1 (fr) 2011-03-29 2012-03-16 Gestion de droits d'accès à des données de fonctionnement et/ou de commande de bâtiments ou complexes de bâtiments

Publications (2)

Publication Number Publication Date
EP2691940A1 EP2691940A1 (fr) 2014-02-05
EP2691940B1 true EP2691940B1 (fr) 2017-10-18

Family

ID=44170245

Family Applications (1)

Application Number Title Priority Date Filing Date
EP12709625.3A Active EP2691940B1 (fr) 2011-03-29 2012-03-16 Gestion de droits d'accès à des données de fonctionnement et/ou de commande de bâtiments ou complexes de bâtiments

Country Status (5)

Country Link
US (1) US8689353B2 (fr)
EP (1) EP2691940B1 (fr)
ES (1) ES2647295T3 (fr)
PL (1) PL2691940T3 (fr)
WO (1) WO2012130640A1 (fr)

Families Citing this family (29)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7706778B2 (en) 2005-04-05 2010-04-27 Assa Abloy Ab System and method for remotely assigning and revoking access credentials using a near field communication equipped mobile phone
US8074271B2 (en) 2006-08-09 2011-12-06 Assa Abloy Ab Method and apparatus for making a decision on a card
US9985950B2 (en) 2006-08-09 2018-05-29 Assa Abloy Ab Method and apparatus for making a decision on a card
US8914851B2 (en) * 2010-12-06 2014-12-16 Golba Llc Method and system for improved security
US8924713B2 (en) 2012-03-30 2014-12-30 Golba Llc Method and system for state machine security device
US20140152631A1 (en) 2012-12-05 2014-06-05 Braeburn Systems Llc Climate control panel with non-planar display
DK2821970T4 (da) 2013-07-05 2019-09-16 Assa Abloy Ab Kommunikationsapparat til access-styring, fremgangsmåde, computerprogram og computerprogram-produkt
EP2821972B1 (fr) 2013-07-05 2020-04-08 Assa Abloy Ab Dispositif à clé et procédé associé, programme informatique et produit de programme informatique
US9443362B2 (en) 2013-10-18 2016-09-13 Assa Abloy Ab Communication and processing of credential data
MX357098B (es) 2014-06-16 2018-06-26 Braeburn Systems Llc Realce luminoso para programar un control.
US8966578B1 (en) * 2014-08-07 2015-02-24 Hytrust, Inc. Intelligent system for enabling automated secondary authorization for service requests in an agile information technology environment
AU2015313921B2 (en) 2014-09-10 2019-01-24 Assa Abloy Ab First entry notification
MX2015014860A (es) 2014-10-22 2017-03-13 Braeburn Systems Llc Sistema de entrada del codigo de termostato y metodo para el mismo que utiliza el identificador del conjunto de servicios.
US10055323B2 (en) 2014-10-30 2018-08-21 Braeburn Systems Llc System and method for monitoring building environmental data
US10430056B2 (en) 2014-10-30 2019-10-01 Braeburn Systems Llc Quick edit system for programming a thermostat
RU2706620C2 (ru) 2014-12-02 2019-11-19 Инвенцио Аг Способ обеспечения контролируемого доступа посетителей в здание
CA2920281C (fr) 2015-02-10 2021-08-03 Daniel S. Poplawski Systeme de duplication de configuration de thermostat
US10317867B2 (en) 2016-02-26 2019-06-11 Braeburn Systems Llc Thermostat update and copy methods and systems
WO2017175020A1 (fr) 2016-04-06 2017-10-12 Otis Elevator Company Gestion de visiteur mobile
US10317919B2 (en) 2016-06-15 2019-06-11 Braeburn Systems Llc Tamper resistant thermostat having hidden limit adjustment capabilities
MX2017011987A (es) 2016-09-19 2018-09-26 Braeburn Systems Llc Sistema de gestion de control que tiene calendario perpetuo con excepciones.
EP3550791B1 (fr) * 2018-04-03 2023-12-06 Palantir Technologies Inc. Contrôle d'accès à des ressources informatiques
US10921008B1 (en) 2018-06-11 2021-02-16 Braeburn Systems Llc Indoor comfort control system and method with multi-party access
BR102018068736A2 (pt) * 2018-09-14 2020-03-24 Haganá Comércio De Sistemas Eletrônicos Ltda. Método para controle de acesso através de dispositivos de comunicação remota
US10802513B1 (en) 2019-05-09 2020-10-13 Braeburn Systems Llc Comfort control system with hierarchical switching mechanisms
US11704441B2 (en) 2019-09-03 2023-07-18 Palantir Technologies Inc. Charter-based access controls for managing computer resources
CN111192393B (zh) * 2019-09-19 2022-04-22 腾讯科技(深圳)有限公司 网络开门方法、装置和计算机设备
CN113900753B (zh) * 2021-10-09 2023-09-22 国家电网有限公司客户服务中心 一种智能能源信息的管理系统和方法
US11925260B1 (en) 2021-10-19 2024-03-12 Braeburn Systems Llc Thermostat housing assembly and methods

Family Cites Families (13)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US5850518A (en) * 1994-12-12 1998-12-15 Northrup; Charles J. Access-method-independent exchange
US7194554B1 (en) * 1998-12-08 2007-03-20 Nomadix, Inc. Systems and methods for providing dynamic network authorization authentication and accounting
SE516208C2 (sv) * 2000-03-30 2001-12-03 Vattenfall Ab Förfarande och system för identifiering
US8479258B2 (en) * 2011-01-06 2013-07-02 Martin Herman Weik, III Garage management system
CA2324679A1 (fr) * 2000-10-26 2002-04-26 Lochisle Inc. Methode et systeme de controle d'acces physique utlisant une connection sans fils a un reseau
JP3474548B2 (ja) * 2001-04-09 2003-12-08 アライドテレシス株式会社 集合建築物
US7183894B2 (en) * 2002-07-31 2007-02-27 Sony Corporation Communication system for accessing shared entrance of multiple dwelling house
US7831628B1 (en) * 2005-06-01 2010-11-09 Osiris Quintana System and method for management of building department services
US20090138953A1 (en) * 2005-06-22 2009-05-28 Dennis Bower Lyon User controlled identity authentication
GB0623842D0 (en) * 2006-11-29 2007-01-10 British Telecomm Secure access
US8239922B2 (en) * 2007-08-27 2012-08-07 Honeywell International Inc. Remote HVAC control with user privilege setup
TWI389536B (zh) * 2008-11-07 2013-03-11 Ind Tech Res Inst 階層式金鑰為基礎之存取控制系統與方法,以及其認證金鑰交換方法
FI122260B (fi) * 2010-05-10 2011-11-15 Kone Corp Menetelmä ja järjestelmä kulkuoikeuksien rajoittamiseksi

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
None *

Also Published As

Publication number Publication date
US8689353B2 (en) 2014-04-01
WO2012130640A1 (fr) 2012-10-04
ES2647295T3 (es) 2017-12-20
US20120278901A1 (en) 2012-11-01
PL2691940T3 (pl) 2018-04-30
EP2691940A1 (fr) 2014-02-05

Similar Documents

Publication Publication Date Title
EP2691940B1 (fr) Gestion de droits d'accès à des données de fonctionnement et/ou de commande de bâtiments ou complexes de bâtiments
WO2018091354A1 (fr) Système de contrôle d'accès avec mise à jour d'état automatique
EP1942466A2 (fr) Dispositif de communication, d'accès et de surveillance ainsi que procédé de communication, d'accès et de surveillance
AT516188B1 (de) Service- und Informationssystem für Gebäude sowie Verfahren hierzu
EP2956913A1 (fr) Ensemble permettant un contact autorisé avec au moins un élément se trouvant dans un immeuble
EP1321901B1 (fr) Méthode pour contrôler les droits d'accès à un objet
EP3647887B1 (fr) Procédé et dispositif de diffusion d'informations d'accès pour un accès à un appareil de terrain de l'industrie de transformation
EP3009992B1 (fr) Procede et dispositif de gestion d'autorisations d'acces
DE102016107450A1 (de) Sicheres Gateway
AT503783B1 (de) System zur kontrolle von berechtigungen von personen, zu autorisierende tätigkeiten durchzuführen
DE102005015792A1 (de) Diagnosesystem mit Identifikationsanzeigeeinrichtung
WO2018114102A1 (fr) Procédé de vérification d'une attribution à un mandant, produit programme informatique et dispositif
EP0904644A1 (fr) Dispositif de regulation et/ou de commande a repartition pour la gestion de systemes avec bus reseau et bus local
EP3358802B1 (fr) Procédé de fourniture sécurisée d'une clé cryptographique
EP1658704B1 (fr) Actualisation d'une information de presence affectee a un utilisateur d'un service de communication
DE102006018889A1 (de) Verfahren zum Beschränken des Zugriffs auf Daten von Gruppenmitgliedern und Gruppenverwaltungsrechner
DE102014005945A1 (de) Verfahren zur Übermittlung von Informationen
WO2018114101A1 (fr) Procédé de vérification d'une attribution à un mandant, produit programme informatique et système d'automatisation comportant des appareils de terrain
BE1030391B1 (de) Dienstleister-Kunden-Kommunikationssystem mit zentraler Datenspeicherung und -verwaltung, integriertem-synchronisiertem Zeiterfassungssystem sowie lokalen Terminals
DE602004010754T2 (de) Erweiterbares, lokales, mit einem Gebäude assoziiertes, Netz
WO1999063697A2 (fr) Dispositif commande par programme
EP4050545A1 (fr) Procédé d'installation d'une pluralité de composants de porte
DE102006051878B4 (de) Vorrichtung und Verfahren zum Herstellen einer gesicherten Verbindung zwischen einem Endgerät und einem Internetserver
DE102013112730B4 (de) Rechnerzentrum und Verfahren zum Betrieb eines Rechnerzentrums
WO2022180088A1 (fr) Procédé d'installation d'une pluralité de composants de porte

Legal Events

Date Code Title Description
PUAI Public reference made under article 153(3) epc to a published international application that has entered the european phase

Free format text: ORIGINAL CODE: 0009012

17P Request for examination filed

Effective date: 20130814

AK Designated contracting states

Kind code of ref document: A1

Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR

DAX Request for extension of the european patent (deleted)
17Q First examination report despatched

Effective date: 20160719

GRAP Despatch of communication of intention to grant a patent

Free format text: ORIGINAL CODE: EPIDOSNIGR1

INTG Intention to grant announced

Effective date: 20170515

GRAS Grant fee paid

Free format text: ORIGINAL CODE: EPIDOSNIGR3

GRAA (expected) grant

Free format text: ORIGINAL CODE: 0009210

AK Designated contracting states

Kind code of ref document: B1

Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR

REG Reference to a national code

Ref country code: GB

Ref legal event code: FG4D

Free format text: NOT ENGLISH

REG Reference to a national code

Ref country code: CH

Ref legal event code: EP

REG Reference to a national code

Ref country code: AT

Ref legal event code: REF

Ref document number: 938557

Country of ref document: AT

Kind code of ref document: T

Effective date: 20171115

Ref country code: IE

Ref legal event code: FG4D

Free format text: LANGUAGE OF EP DOCUMENT: GERMAN

REG Reference to a national code

Ref country code: DE

Ref legal event code: R096

Ref document number: 502012011476

Country of ref document: DE

REG Reference to a national code

Ref country code: ES

Ref legal event code: FG2A

Ref document number: 2647295

Country of ref document: ES

Kind code of ref document: T3

Effective date: 20171220

REG Reference to a national code

Ref country code: NL

Ref legal event code: FP

REG Reference to a national code

Ref country code: LT

Ref legal event code: MG4D

REG Reference to a national code

Ref country code: FR

Ref legal event code: PLFP

Year of fee payment: 7

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: LT

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20171018

Ref country code: NO

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20180118

Ref country code: SE

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20171018

Ref country code: FI

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20171018

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: LV

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20171018

Ref country code: IS

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20180218

Ref country code: RS

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20171018

Ref country code: HR

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20171018

Ref country code: GR

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20180119

Ref country code: BG

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20180118

PGFP Annual fee paid to national office [announced via postgrant information from national office to epo]

Ref country code: AT

Payment date: 20180322

Year of fee payment: 7

REG Reference to a national code

Ref country code: DE

Ref legal event code: R097

Ref document number: 502012011476

Country of ref document: DE

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: DK

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20171018

Ref country code: CZ

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20171018

Ref country code: EE

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20171018

Ref country code: SK

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20171018

PLBE No opposition filed within time limit

Free format text: ORIGINAL CODE: 0009261

STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: NO OPPOSITION FILED WITHIN TIME LIMIT

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: RO

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20171018

Ref country code: SM

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20171018

26N No opposition filed

Effective date: 20180719

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: MT

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20171018

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: MC

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20171018

Ref country code: SI

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20171018

REG Reference to a national code

Ref country code: IE

Ref legal event code: MM4A

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: LU

Free format text: LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES

Effective date: 20180316

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: IE

Free format text: LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES

Effective date: 20180316

REG Reference to a national code

Ref country code: AT

Ref legal event code: MM01

Ref document number: 938557

Country of ref document: AT

Kind code of ref document: T

Effective date: 20190316

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: AT

Free format text: LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES

Effective date: 20190316

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: TR

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20171018

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: PT

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20171018

Ref country code: HU

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT; INVALID AB INITIO

Effective date: 20120316

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: CY

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20171018

Ref country code: MK

Free format text: LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES

Effective date: 20171018

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: AL

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20171018

PGFP Annual fee paid to national office [announced via postgrant information from national office to epo]

Ref country code: CH

Payment date: 20220324

Year of fee payment: 11

PGFP Annual fee paid to national office [announced via postgrant information from national office to epo]

Ref country code: PL

Payment date: 20220304

Year of fee payment: 11

Ref country code: NL

Payment date: 20220325

Year of fee payment: 11

Ref country code: IT

Payment date: 20220323

Year of fee payment: 11

Ref country code: BE

Payment date: 20220325

Year of fee payment: 11

PGFP Annual fee paid to national office [announced via postgrant information from national office to epo]

Ref country code: ES

Payment date: 20220418

Year of fee payment: 11

PGFP Annual fee paid to national office [announced via postgrant information from national office to epo]

Ref country code: FR

Payment date: 20230323

Year of fee payment: 12

REG Reference to a national code

Ref country code: CH

Ref legal event code: PL

REG Reference to a national code

Ref country code: NL

Ref legal event code: MM

Effective date: 20230401

REG Reference to a national code

Ref country code: BE

Ref legal event code: MM

Effective date: 20230331

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: NL

Free format text: LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES

Effective date: 20230401

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: LI

Free format text: LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES

Effective date: 20230331

Ref country code: CH

Free format text: LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES

Effective date: 20230331

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: BE

Free format text: LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES

Effective date: 20230331

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: IT

Free format text: LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES

Effective date: 20230316

PGFP Annual fee paid to national office [announced via postgrant information from national office to epo]

Ref country code: DE

Payment date: 20240328

Year of fee payment: 13

Ref country code: GB

Payment date: 20240319

Year of fee payment: 13

REG Reference to a national code

Ref country code: ES

Ref legal event code: FD2A

Effective date: 20240507