Credential-Based Access Control for Host-Managed Visitor Permissions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access control systems require administrator intervention for adding or changing access rights, which can be cumbersome for hosts who need to manage access for visitors.

Innovation Solution

An access control system and method that allows hosts to dynamically grant and modify access rights by using initiating and finalizing access request credentials at credential readers, simplifying the process without administrator involvement.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If administrator intervention is required for adding or changing access rights, then access control security is maintained, but operational complexity and time consumption increase

Engineering Contradiction:
Improveaccess control securityVSAvoidoperational complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The host is empowered to independently add, remove, and modify visitor access rights using initiating and finalizing credentials without requiring administrator intervention. The access control system automatically processes these changes, allowing the host to manage access rights autonomously while maintaining system security through the credential verification mechanism.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces an intermediary credential-based mechanism where the host uses initiating and finalizing credentials as mediators to communicate access control changes to the system. This intermediary approach allows the host to safely modify access rights without direct administrator involvement, as the credentials act as authorized proxies for the host's decisions.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If administrator intervention is required for adding or changing access rights, then centralized control is maintained, but response time and efficiency decrease

Engineering Contradiction:
Improveresponse timeVSAvoidsystem structure
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the access control authority by separating the functions of initiating access requests and finalizing them through credential-based authentication. This segmentation allows the host to independently manage access rights without requiring centralized administrator intervention for each change, thereby reducing response time while maintaining controlled access through the credential verification process.

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If dynamic access rights management is enabled without administrator involvement, then user convenience is improved, but system security control may be weakened

Engineering Contradiction:
Improveuser convenienceVSAvoidsystem security control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary authentication by requiring the host to present initiating and finalizing credentials before any access rights changes are processed. This preliminary action ensures that only authorized hosts can modify access rights, maintaining system security control while enabling convenient dynamic management for authenticated users.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12408034B2Access control system and a method therein for handling access to an access-restricted physical resource
Publication Date: 2025.09.02 AXIS
  • US12408034B2 patent drawing
  • US12408034B2 patent drawing
  • US12408034B2 patent drawing

AI summary

An access control system and a method performed therein, for handling access to an access-restricted physical resource. The method comprises, by means of a first credential reader, receiving an initiating access request credential initiating a request to give one or more visitors access to a first access-restricted physical resource. The method further comprises, by means of the first credential reader, receiving a visitor credential for each visitor for which access is requested, and, by means of a second credential reader, receiving a finalising access request credential finalising the request to give the one or more visitors access. Furthermore, the method comprises, by means of a first resource controller, allowing a visitor to access the first access-restricted physical resource upon presenting the visitor's visitor credential to the first credential reader.