Access Control Validation Module for HSPD-12 Reader Upgrades

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access control systems face challenges in efficiently and flexibly implementing identity verification that complies with federal security standards, such as HSPD-12 and FIPS 201, to selectively grant access to registered individuals while ensuring security assurance levels.

Innovation Solution

An access control system with a validation device featuring modular communication interfaces, a processor, and a computer-readable storage medium that validates cardholder data using authentication mechanisms like CHUID, CAK, PKI, and biometric authentication, and performs enrollment processing, while determining access decisions based on attributes from a separate database, allowing override of default access behaviors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a validation device is integrated into the access control system, then HSPD-12 compliance and security assurance are improved, but system complexity and infrastructure modification requirements increase

Engineering Contradiction:
Improvesecurity assuranceVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The validation device serves as an intermediary component that sits between the reader and the access control system. It receives cardholder data from the reader, performs validation according to HSPD-12 standards, and communicates validation results to the access control system. This intermediary approach allows compliance functionality to be added without fundamentally redesigning the existing access control infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The validation device is designed with modular communication interfaces that can couple to various readers and access control systems, making it universally applicable. The device performs multiple functions including receiving cardholder data, validating credentials, extracting ID information, and communicating with both readers and access control systems, thereby reducing the need for multiple specialized components.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If the validation device uses multiple authentication mechanisms, then compliance with federal standards is improved, but device complexity increases

Engineering Contradiction:
Improveauthentication flexibilityVSAvoiddevice complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The validation device supports multiple authentication mechanisms (CHUID, CAK, PKI, biometric) by changing operational parameters rather than requiring fundamentally different hardware for each mechanism. The device can switch between different validation algorithms and credential formats based on the type of credential being validated, allowing flexible support for various authentication methods within a single unified device architecture.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If the system validates cardholder data externally, then access control security is improved, but processing time increases

Engineering Contradiction:
Improveaccess control securityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The validation device performs credential validation as a preliminary action before the access control system makes its access decision. By validating cardholder data upfront and extracting ID information in advance, the system prepares verification results before they are needed for the final access determination, streamlining the overall process and reducing delays at the access point.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2494440B1Universal validation module for access control systems
Publication Date: 2022.04.13 ASSA ABLOY AB
  • EP2494440B1 patent drawingFigure 1
  • EP2494440B1 patent drawingFigure 2
  • EP2494440B1 patent drawingFigure 3

AI summary

A validation module provides for the upgrading of a physical access control system (PACS) to full HSPD-12 compliance without requiring modification or replacement of the existing PACS. The validation module may contain all of the validation functionality required by federal specifications and technical requirements. The validation module may be installed between an existing PACS panel and a supported card/biometric reader. Readers may be selected based on assurance level requirements, e.g., contactless or contact readers for low and medium assurance level areas and full biometric readers for high assurance areas. The validation module may validate a card according to the assurance level setting, extract ID information from data on the card and then pass the ID information to the PACS panel for an access decision. Cardholder data captured by one validation module may be distributed to other validation modules of the PACS using a management station.