Boolean Expression Access Control via RFID Credentials

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current access control systems are impractical for implementing arbitrary Boolean expressions, require all keys or individuals to be physically present, expose authentication conditions to onlookers, and struggle to support NOT conditions, making them insecure and inflexible for group authentication scenarios.

Innovation Solution

A system that allows multiple digital credentials to be presented either simultaneously or sequentially, with a reader configured to evaluate a specific Boolean expression before authorizing access, using portable authentication credentials that can enforce complex Boolean combinations, including NOT and XOR conditions, to ensure secure group authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional access control systems are used with physical keys and pin-tumbler locks, then authentication can be performed, but the Boolean expression for access control is baked into the system making it impossible to change access conditions

Engineering Contradiction:
Improveability to change access conditionsVSAvoidsystem flexibility
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent replaces the mechanical pin-tumbler lock system with an electronic authentication system using RFID readers, credentials, and a backend server. This substitution enables dynamic Boolean expressions to be implemented through software rather than being fixed in hardware, allowing access conditions to be modified without physical system changes.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system implements dynamic access control by allowing Boolean expressions to be modified at runtime through the backend server. Access conditions can be changed, added, or removed without reconfiguring the physical system, enabling the access control logic to adapt to changing security requirements.

Inventive Principle:
Principle #15Dynamics

2Reliability

If all keys must be physically present in the vault to open the box, then security is maintained, but it requires all individuals to be present simultaneously which is impractical

Engineering Contradiction:
ImprovesecurityVSAvoidaccess convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments the authentication process by allowing credentials to be presented sequentially rather than requiring all credentials to be present simultaneously. The system can evaluate Boolean expressions with OR conditions, meaning that if one credential satisfies the access condition, authentication can proceed without requiring all other credentials to be physically present.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The backend server acts as an intermediary that receives credentials sequentially, evaluates the Boolean expressions, and determines access authorization. This mediator enables the system to process authentication requests even when not all credential holders are present, by evaluating the access conditions based on the credentials that have been presented.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If physical keys are used in a pin-tumbler system, then authentication is obvious to onlookers when the key turns, but this exposes the authentication condition and creates security risks

Engineering Contradiction:
Improveauthentication visibilityVSAvoidsecurity exposure
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent replaces the mechanical key-turning action with electronic credential presentation through RFID readers. The authentication process occurs electronically without visible mechanical action, preventing onlookers from observing whether authentication succeeded or failed. The system provides feedback through authorized interfaces rather than physical key movement.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Adaptability or versatility

If traditional access control systems are used, then simple authentication is possible, but implementing NOT conditions and XOR operations is very difficult or impossible

Engineering Contradiction:
ImproveBoolean expression capabilityVSAvoidaccess control logic
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent replaces mechanical access control with an electronic system that uses a backend server to evaluate arbitrary Boolean expressions. The server can process NOT conditions, XOR operations, and other complex logical operations through software, enabling sophisticated access control logic that would be impossible to implement with mechanical key systems.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system implements dynamic Boolean expression evaluation through the backend server, allowing complex access conditions including NOT and XOR operations to be defined and modified through software configuration. This enables the access control logic to adapt to complex security requirements without increasing physical system complexity.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8474026B2Realization of access control conditions as boolean expressions in credential authentications
Publication Date: 2013.06.25 ASSA ABLOY AB
  • US8474026B2 patent drawing
  • US8474026B2 patent drawing
  • US8474026B2 patent drawing

AI summary

A method, reader, and system are provided for performing group authentication processes. In particular, a group access decision can be made upon the analysis of a group rule. The group rule may contain a Boolean expression including one or more Boolean conditions. If an appropriate group of credentials are presented to a reader such that the Boolean expression is satisfied, then the group of credentials and the holders thereof are allowed access to a protected asset.