Central Platform Access Control for Physical Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access control systems for physical units, such as vehicles, are vulnerable to unauthorized access due to the lack of secure verification processes, allowing attackers to obtain unauthorized access to devices and their functions.

Innovation Solution

A system comprising a central control platform, a technical access control unit, and a mobile electronic access unit, which establishes a secure communication network to verify user identities through multiple steps, ensuring that access is granted only when the identity of the user is confirmed by the central platform, and not just the mobile access device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a mobile access device is used to verify user identity, then access control is enabled, but the system becomes vulnerable to unauthorized access attacks

Engineering Contradiction:
Improveaccess control securityVSAvoidunauthorized access vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The verification process is segmented into multiple independent steps: first verifying the mobile access device, then separately verifying the user's identity through additional authentication factors. This segmentation ensures that compromising one element does not grant unauthorized access, as each segment acts as an independent security layer that must be breached separately.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A central control platform is introduced as an intermediary between the mobile access device and the access control system. This intermediary verifies both the device and the user identity before granting access, preventing direct attacks on the access control system and adding a layer of mediation that enhances security while maintaining system functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If access rights are tied to the mobile device, then convenient access is provided, but transferring the device grants unauthorized access to others

Engineering Contradiction:
Improveaccess convenienceVSAvoidauthorization security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

Authorization is segmented into device verification and user identity verification as separate steps. The system first confirms the mobile device's legitimacy, then independently verifies the user's identity through additional authentication factors. This ensures that even if the device is transferred, unauthorized access is prevented because the user identity verification layer remains intact and cannot be bypassed by simple device transfer.

Inventive Principle:
Principle #1Segmentation

3Reliability

If a central control platform verifies both device and user identity, then security is enhanced, but system complexity increases

Engineering Contradiction:
Improveidentity verification securityVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The central control platform is designed as a universal system that handles multiple verification functions: device authentication, user identity verification, and access rights management. By consolidating these functions into a single multi-functional platform rather than separate specialized systems, the architecture manages complexity while maintaining comprehensive security verification capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10589718B2System and method for controlling access
Publication Date: 2020.03.17 HUF HÜLSBECK & FÜRST GMBH & CO KG
  • US10589718B2 patent drawing
  • US10589718B2 patent drawing
  • US10589718B2 patent drawing

AI summary

A method for controlling access of a user to a physical device which is provided with an access control unit that can block and release access to functions of the physical device includes the provision of a central control platform and a mobile access device. An identification check of the user is carried out, the user being identified by the mobile access device. Following a successful identification check, a wireless communication link is established between the mobile access device and the access control unit of the physical device. Identification information and unique access data are transmitted from the mobile access device to the access control unit. The access control unit ascertains the access rights of the user to the physical device using the received information and additional information from the central control platform.