Portable Credential Access Control Decision Logic

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access control systems rely heavily on centralized databases, leading to high installation costs, network dependency, and inefficient energy consumption, especially in large systems with non-networked locks, where policy information management and data transfer slow down the access control process and consume energy.

Innovation Solution

The credential holds policy information and uses its processor to make access decisions, minimizing communication with a local host that contains no database, allowing it to autonomously enforce access control and reduce data transfer, thereby reducing energy consumption and installation costs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If policy information is distributed among non-networked locks, then network dependency is reduced, but data management becomes problematic and requires expensive reprogramming visits

Engineering Contradiction:
Improvenetwork independenceVSAvoiddata management
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The credential device autonomously manages its own policy information and makes access decisions without requiring external database updates or reprogramming visits. The credential stores policy information locally and processes access requests independently, eliminating the need for centralized data management infrastructure.

Inventive Principle:
Principle #25Self-service

2Ease of operation

If database records are passed from card to lock, then access decisions can be made locally, but the process slows down and consumes energy

Engineering Contradiction:
Improvelocal access controlVSAvoidenergy consumption
Core Design Contradiction:
Ease of operationVSUse of energy by moving object

Solution Approach 1:

The invention extracts only the essential policy information needed for access decisions from the credential and transfers it to the lock device. This selective data transfer minimizes communication overhead and energy consumption while enabling local access control decisions.

Inventive Principle:
Principle #2Taking out (Extraction)

3Ease of manufacture

If centralized database is used, then data management is easy and consistent, but installation costs are high due to networking requirements

Engineering Contradiction:
Improvedata managementVSAvoidnetwork infrastructure
Core Design Contradiction:
Ease of manufactureVSDevice complexity

Solution Approach 1:

The system segments the centralized database functionality into distributed credential devices, each storing its own policy information. This eliminates the need for network infrastructure connecting locks to a central server, reducing installation costs while maintaining data management capabilities through local storage and processing.

Inventive Principle:
Principle #1Segmentation

4Reliability

If credential processor verifies biometric data before communication, then security is improved, but the reader still makes the ultimate access control decision

Engineering Contradiction:
Improveauthentication securityVSAvoiddecision autonomy
Core Design Contradiction:
ReliabilityVSExtent of automation

Solution Approach 1:

The invention inverts the traditional architecture by placing the access control decision-making capability in the credential device rather than the reader. The credential processor not only verifies biometric data but also autonomously makes the final access control decision, eliminating the need for the reader to have decision-making authority.

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentEP1895445B1Method and apparatus for making a decision on a card
Publication Date: 2021.01.06 ASSA ABLOY AB
  • EP1895445B1 patent drawingFigure 1
  • EP1895445B1 patent drawingFigure 2
  • EP1895445B1 patent drawingFigure 3

AI summary

Method and devices for making access decisions in a secure access network are provided. The access decisions are made by a portable credential using data and algorithms stored on the credential. Since access decisions are made by the portable credential non-networked hosts or local hosts can be employed that do not necessarily need to be connected to a central access controller or database thereby reducing the cost of building and maintaining the secure access network.