Access Control Server Using Payment Network Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems lack an efficient method for authenticating and controlling access to physical assets, particularly in scenarios requiring secure authorization, as they often rely on outdated infrastructure and do not effectively integrate with existing payment networks for token-based access control.

Innovation Solution

A computer server system that processes access requests by generating authentication verification requests using token data elements, leveraging the ISO8583 standard, and incorporating second-factor authentication, allowing access control terminals to determine authorization through a payment network, thereby enabling secure access to physical assets.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing systems use outdated infrastructure for access control, then implementation is simpler with fewer integration requirements, but security and efficiency are insufficient

Engineering Contradiction:
Improveaccess control securityVSAvoidsystem integration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system uses the existing payment network infrastructure for dual purposes: both financial transactions and access control authentication. By making the payment network universal, it can handle both traditional payment functions and new access control functions, eliminating the need for separate dedicated access control infrastructure and thereby improving security without proportionally increasing complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces an access control processing server as an intermediary that translates access requests into payment network authentication protocols. This mediator bridges the gap between access control terminals and the payment network, enabling secure access control through existing infrastructure while managing the integration complexity through a dedicated translation layer

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If token-based authentication is implemented without second-factor authentication, then ease of operation is improved, but security is compromised

Engineering Contradiction:
Improveauthorization securityVSAvoidaccess control process simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary authentication through the payment network using token-based verification before granting access. This preliminary check establishes a secure baseline authorization that validates the user's identity and permissions in advance, creating a foundation for enhanced security

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system dynamically adjusts authentication requirements based on risk assessment and access context. Second-factor authentication is triggered conditionally based on the access request characteristics, user profile, and security policies, making the system adaptable rather than statically requiring all users to undergo the same authentication process

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11017398B2Systems and methods for processing an access request
Publication Date: 2021.05.25 MASTERCARD INT INC
  • US11017398B2 patent drawing
  • US11017398B2 patent drawing
  • US11017398B2 patent drawing

AI summary

A system for controlling access to a physical asset and associated servers and methods are provided. The system includes an access control terminal coupled to the physical asset and operable to read a token from a user token device associated with a user, and generate control signals to allow access to the physical asset, an access control processing server operable to receive an access request from the access control terminal, the access request including the token, generate an authentication verification request including the token, send the authentication verification request to a network, receive an authentication response from the network, generate an access control response to cause the access control terminal to allow access to the asset in response to the authentication response, and send the access control response to the access control response.