Access Control System Using Trusted Third-Party Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current access control systems face issues with unauthorized access and privacy concerns due to the need for additional hardware and software features like biometric verification, which increase costs and liability, especially in scenarios where individuals may impersonate authorized guests to access restricted areas.
Innovation Solution
An access control system that utilizes a trusted third-party device, such as a portable computing device or smartphone, for authentication, where an authentication application is distributed to the user's device to verify their identity through alphanumeric or biometric means, with data stored remotely, allowing the system to determine and enforce access rights based on verified credentials.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If two-factor authentication or biometric verification features are employed, then security against unauthorized access is improved, but device complexity and cost increase
Solution Approach 1:
The patent introduces a trusted third-party server as an intermediary that handles the complex authentication processes. The control device communicates with this server, which performs biometric verification and two-factor authentication remotely. This transfers the computational and storage complexity from the control device to the server, maintaining security while reducing local device requirements.
Solution Approach 2:
The patent extracts sensitive authentication data and processing requirements from the control device and stores them remotely on a server. The control device only retains minimal credential verification logic, while the server handles biometric data storage, comparison, and authentication decision-making. This extraction reduces device complexity while preserving security functionality.
2Reliability
If biometric verification and additional authentication features are added, then unauthorized access is prevented, but privacy concerns and liability increase
Solution Approach 1:
The trusted third-party server acts as a mediator that handles all sensitive biometric data processing. The control device never stores or processes raw biometric information locally - it only communicates authentication results with the server. This intermediary architecture minimizes privacy exposure at the access control point while maintaining verification security.
Solution Approach 2:
The patent extracts all sensitive authentication data and processing functions from the control device and relocates them to a remote server. This extraction ensures that biometric templates and personal authentication information are stored and processed in a centralized, secure environment with proper privacy safeguards, rather than being distributed across multiple access control devices.
3Reliability
If virtual private network tokens and fingerprint scanners are deployed, then authentication security is improved, but build and maintenance costs increase
Solution Approach 1:
The patent makes the control device universal by removing device-specific authentication hardware requirements. The system works with any credential type (proximity cards, mobile devices, biometric sensors) as long as the authentication is verified by the trusted server. This universality reduces manufacturing costs by standardizing the control device architecture while maintaining strong authentication through server-side verification.
Solution Approach 2:
The trusted third-party server mediates all authentication operations, eliminating the need for each control device to have embedded biometric scanners, token generators, or secure element hardware. The server provides these advanced authentication capabilities remotely, reducing the bill of materials and maintenance requirements for distributed control devices while maintaining high security standards.
Data Source
AI summary
An access control system is provided and includes a control device disposed to restrict access to a secured resource and a networked device disposed in signal communication with the control device. The networked device requests authentication of a user from a trusted device responsive to a presentation of credentials to the control device in a request for access to the secured resource, the credentials are associated with access rights of the user, the networked device is receptive of the authentication, and the control device permits a level of access to the secured resource in accordance with the access rights upon the reception of the authentication.


