Access Control Device Identifier Reset and Delegation Path Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access control systems face scalability issues and insecurity, particularly when revoking access for all users, as they require centralized server management and can be cumbersome to reset, especially during ownership transfer.

Innovation Solution

An access control method and device that generates a new identifier upon user input, discarding previous ones, and grants access only through a sequence of delegations from the access control device to the electronic key, ensuring privacy and security by invalidating previous access paths, thus allowing secure ownership transfer without central server dependency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If centralized server management is used to control access rights, then access management flexibility is improved, but system scalability and security are worsened due to server availability requirements and complexity

Engineering Contradiction:
Improveaccess management flexibilityVSAvoidsystem security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the centralized access control system into distributed components: local access control devices and electronic keys operate independently without requiring continuous server connectivity. Each device stores and validates access rights locally, eliminating the single point of failure represented by the central server while maintaining flexible access management capabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces cryptographic tokens and delegation certificates as intermediaries between access control devices and electronic keys. These digital intermediaries enable secure access verification without requiring direct communication with a central server, thus improving reliability while preserving access management flexibility through cryptographic validation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If access rights are stored centrally on a server, then access management is improved, but scalability is worsened as the server and communication paths must be scaled when new devices are deployed

Engineering Contradiction:
Improveaccess rights managementVSAvoidsystem scalability
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent extracts access rights management from the centralized server and embeds it directly into local access control devices and electronic keys. Each device independently stores and validates access rights without requiring server intervention, eliminating the scalability bottleneck of centralizing all access control logic while maintaining comprehensive access management capabilities.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent enables access control devices and electronic keys to perform self-validation of access rights using locally stored cryptographic data. Devices can independently verify access permissions without requiring server communication, making the system self-sufficient and eliminating scalability constraints associated with centralized server architecture.

Inventive Principle:
Principle #25Self-service

3Reliability

If a reset function is implemented to invalidate all current users, then security is improved, but ease of operation is worsened as the process is cumbersome and time-consuming

Engineering Contradiction:
ImprovesecurityVSAvoidreset process simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements preliminary action by pre-configuring access control devices with the ability to generate new cryptographic identifiers and invalidate previous ones through a simple reset operation. The device maintains a history of used identifiers and can instantly revoke all previous access rights by generating a new identifier, making the reset process trivial while ensuring comprehensive security validation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces the mechanical complexity of manual user-by-user access revocation with cryptographic substitution: a single reset operation generates a new identifier that automatically invalidates all previous delegations through cryptographic verification. This eliminates the cumbersome manual process while maintaining strong security through cryptographic validation of the delegation chain.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Measurement precision

If unique serial numbers are assigned to devices during manufacturing, then device identification is improved, but privacy is worsened as devices can be tracked between resets

Engineering Contradiction:
Improvedevice identificationVSAvoiduser privacy
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent implements dynamic identification by allowing access control devices to change their identifier through reset operations. Instead of a fixed serial number, the device generates new cryptographic identifiers as needed, making tracking between resets impossible while maintaining precise device identification through the current valid identifier and its cryptographic history.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11763618B2Controlling access to an access object
Publication Date: 2023.09.19 ASSA ABLOY AB
  • US11763618B2 patent drawing
  • US11763618B2 patent drawing
  • US11763618B2 patent drawing

AI summary

It is presented a method for controlling access to an access object. The method is performed in an access control device and comprises the steps of: receiving a user input to reset the access control device; generating a new identifier for the access control device, and discarding any previously used identifier for the access control device; communicating with an electronic key to obtain an identity of the electronic key; obtaining a plurality of delegations, wherein each delegation is a delegation from a delegator to a receiver; and granting access to the access object only when the plurality of delegations comprise a sequence of delegations covering a delegation path from the access control device, identified using the new identifier, to the electronic key such that, in the sequence of delegations, the delegator of the first delegation is the access control device, and the receiver of the last delegation is the electronic key.