Access Management Device for Remote Locations
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Access management systems face challenges in remote locations where updating authorization data is time-consuming and difficult due to lack of connectivity, making it hard to manage temporary access permissions effectively.
Innovation Solution
An access management device and method that generates and distributes encrypted access information with a variable time validity, using a secret key and encryption algorithm, allowing independent evaluation without needing a connection to the administration center, and using a temporary storage medium for secure transmission.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If access control systems use external storage or centralized server connections to manage access credentials, then access authorization can be updated and controlled centrally, but the system becomes inoperable or difficult to manage at remote locations without communication infrastructure
Solution Approach 1:
The patent divides the access control system into two independent parts: a central administration unit that generates access information, and a local evaluation device at the remote location that stores and processes this information independently. The access information is segmented into a first part (identifying the user and object) and a second part (verification data), which can be processed locally without external connection, thus enabling operation at remote locations while maintaining centralized control capabilities.
Solution Approach 2:
The patent introduces an intermediary mechanism - encrypted access information that is generated centrally but can be processed locally. This access information acts as a mediator between the central administration unit and the local evaluation device, carrying all necessary authorization data in a self-contained manner that enables independent operation at remote locations without requiring continuous connection to external storage.
2Ease of operation
If access control systems require connection to external storage for updating permissions, then centralized authorization management is achieved, but time restrictions and temporary access rights cannot be effectively imposed at remote locations
Solution Approach 1:
The patent applies preliminary action by embedding all necessary access control data - including time restrictions, validity periods, and authorization conditions - into the access information before it is transmitted to the remote location. The evaluation device at the remote location can then independently evaluate these pre-configured parameters and enforce time restrictions without requiring real-time connection to external storage, thus eliminating delays in permission updates.
3Productivity
If access information is transmitted and stored locally without encryption, then processing is simpler and faster, but security against unauthorized access and manipulation is compromised
Solution Approach 1:
The patent applies parameter changes by transforming the access information through encryption, changing its mathematical representation while preserving its functional meaning. The encrypted first part and second part can be processed locally with minimal overhead, maintaining fast access evaluation, while the cryptographic transformation provides strong security against unauthorized access and manipulation. The verification process remains efficient as it involves straightforward cryptographic comparison rather than complex decryption.
Data Source
Figure 1
Figure 2a)~2f)
AI summary
An access control system for buildings consists of a central control unit, at least one intermediate storage medium, and at least one device for evaluating access information and controlling an access door. The central control unit comprises a computer that generates access information consisting of a fixed, person-specific component and a variable, time-related component and transmits it to the intermediate storage medium. The device for evaluating access information comprises a computer not connected to the central control unit, equipped with a clock. This computer uses the access information read from the intermediate storage medium and compared with the clock's time signal to unlock the access door. The central control unit's computer uses an encryption algorithm to generate verification information, which is also transmitted to the intermediate storage medium.The device's computer for evaluating access information uses the same encryption algorithm to generate variants of comparison information and compare them with the test information read from the intermediate storage medium. The access door is only unlocked if one of the variants of comparison information matches the test information.