ID-Based Access Control Offline Operation via Zone Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
ID-based access control systems face challenges in maintaining operation when access control devices or the central server are offline, requiring high storage capacity for positive/negative lists and inability to perform price calculations in offline mode.
Innovation Solution
A method where a data set with minimal memory requirements, containing temporal and zone-related validity information, is written to a customer medium by an online access control device, allowing offline access control devices to determine access authorization using offline data records, and enabling price calculations using stored prices and tariffs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If positive/negative lists are stored in access control devices for offline operation, then the system can operate when the central server is offline, but the storage capacity requirements become excessively high
Solution Approach 1:
The access control system is divided into multiple zones, each with its own zone ID. Instead of storing all positive/negative lists for all zones in each access control device, the system segments the data storage requirement by zone. Each access control device only needs to store and process data relevant to its assigned zone, significantly reducing the storage capacity needed while maintaining offline operation capability.
Solution Approach 2:
The patent introduces a new dimension of zone-based organization to the access control system. By adding the zone ID as a filtering criterion, the system transforms the storage problem from a two-dimensional space (all users vs. all devices) to a more manageable structure where data is organized by zone. This dimensional change allows access control devices to operate offline with minimal storage requirements by only maintaining zone-specific data.
2Ease of operation
If all access control data is processed online through the central server, then centralized control is maintained, but the system cannot operate when the central server is offline
Solution Approach 1:
The system performs preliminary actions by pre-assigning zone IDs to access control devices and pre-configuring zone-specific parameters before offline operation is needed. This preliminary setup enables access control devices to independently process access requests for their assigned zones without real-time communication with the central server, ensuring continuous operation while maintaining centralized control architecture.
Solution Approach 2:
The patent implements local quality by enabling each access control device to have autonomous decision-making capability for its assigned zone. Each device is configured with zone-specific parameters and can independently evaluate access requests against zone-defined criteria. This local autonomy ensures continuous operation in offline scenarios while the centralized server maintains overall system coordination when online.
3Adaptability or versatility
If zone-specific data is stored locally in access control devices, then offline zone-based access control is enabled, but data synchronization complexity increases
Solution Approach 1:
The patent extracts the zone identification and zone-specific parameter data from the central server and places them locally in access control devices. By taking out only the essential zone-related data (zone ID, zone parameters, zone-specific access rules) rather than maintaining complete centralized databases, the system enables zone-based offline control while minimizing data synchronization complexity. The central server only needs to update zone configurations when changes occur, rather than synchronizing complete access control databases.
Data Source
Figure 1~2
Figure 3
AI summary
Within the framework of the procedure for operating an ID-based access control system comprising at least one central server (4) and at least one access control device (2) connectable to the at least one central server (4) for the purpose of data communication, each access control device (2) is assigned a zone which has a unique zone ID, wherein, when a customer medium (1) is detected for the first time with regard to the validity of the access authorization in a zone by an online access control device (2) assigned to that zone, an offline data record is written to the customer medium (1), which, in the event that an access control device (2) in the same zone is offline and detects the customer medium (1), is read by the offline access control device (2) and used to determine the validity of an access authorization assigned to the ID of the customer medium (1).wherein the offline data record contains temporal validity information and, in the case of multiple zones, zone-related validity information, which makes it possible to determine the validity of an access authorization assigned to the ID of the customer medium (1), and wherein the data of the offline access control transaction are stored by the access control device (2) and forwarded to the central server (4) as soon as the access control device (2) is back online.