Cloud Authentication for Physical Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional physical control access systems face security risks due to insecure communication channels when credentials are exposed, and they require users to physically present a keycard or device for authentication, which is inconvenient and complex.

Innovation Solution

The implementation of cloud-based authentication systems that encode credentials in a secure cloud environment, using out-of-band authentication processes to validate user identities without exposing sensitive information over insecure connections, allowing access to physical spaces through digital resource access credentials.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional physical control access systems use keycards and readers with insecure communication channels, then access control function is achieved, but security is compromised due to credential exposure

Engineering Contradiction:
ImprovesecurityVSAvoidinsecure communication channels
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a cloud-based authentication service as an intermediary between the access control reader and the credential storage. Instead of storing credentials locally in the reader or on the keycard, the system uses a cloud service to validate authentication requests. This intermediary approach eliminates insecure direct communication channels while maintaining access control functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the traditional mechanical keycard insertion/touching mechanism with a wireless communication-based authentication system. The access control reader communicates with a cloud service over secure networks to validate credentials, eliminating the need for physical contact and insecure local storage mechanisms.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If users must physically present keycards for authentication, then access control is enforced, but user convenience is reduced and operation becomes complex

Engineering Contradiction:
Improveaccess control enforcementVSAvoiduser access convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent uses digital copies of authentication credentials stored in cloud-based services rather than physical keycards. The cloud service maintains authenticated user identifiers that can be verified remotely, eliminating the need for users to physically handle and present plastic cards while maintaining secure access control enforcement.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent substitutes the mechanical keycard presentation process with wireless communication-based authentication. Users can authenticate through mobile devices or other electronic terminals that communicate with the cloud service, replacing the need for physical keycard insertion or touching with contactless digital verification.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Speed

If credentials are stored and validated locally in access control readers, then access speed is fast, but system complexity and security risks increase

Engineering Contradiction:
Improveauthentication speedVSAvoidreader complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The patent introduces a cloud-based authentication service as an intermediary that handles credential validation centrally. This allows access control readers to remain simple devices that only perform basic communication functions, while the complex authentication logic resides in the cloud service, reducing local device complexity while maintaining authentication speed through optimized cloud processing.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20240404339A1Physical access using cloud transaction
Publication Date: 2024.12.05 ASSA ABLOY AB
  • US20240404339A1 patent drawing
  • US20240404339A1 patent drawing
  • US20240404339A1 patent drawing

AI summary

Systems and methods may be used for controlling physical access using a cloud transaction. A method may include receiving an authentication attempt for a user from a mobile device, and authenticating the user for access to a physical space based on the authentication attempt. The method may include receiving identification information corresponding to the user from an access control device, and sending authorization to the access control device to permit the user to access the physical space based on the authenticating the user.