Credential Distribution in Access Control Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users are burdened with remembering multiple credentials for various services on different controllers in access control systems, leading to complexity and inefficiency in managing and updating user credentials across multiple devices.
Innovation Solution
A device with a processor and communication interface that stores and updates transformed user credential databases, allowing for peer-to-peer distribution of encrypted credentials to generate corresponding transformed databases for authenticating users across multiple services, using cryptographic one-way functions for authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If users are assigned separate credentials for each service on each controller, then authentication security is improved, but user complexity and management burden increase
Solution Approach 1:
The patent merges multiple service-specific credentials into a single user credential that can be used across multiple services on different controllers. The credential database stores unified user credentials that are transformed and distributed to various services, eliminating the need for users to manage separate credentials for each service while maintaining authentication security through cryptographic transformation.
Solution Approach 2:
The patent implements universal credentials that can authenticate users across multiple services and controllers. The transformed credential database enables a single user credential to serve multiple authentication purposes across different services (e.g., door access, elevator control, parking garage) without requiring service-specific credential variations.
2Reliability
If credentials are updated on one controller, then user security is improved, but propagation time to other controllers increases
Solution Approach 1:
The patent implements a feedback mechanism where credential updates on one controller automatically trigger propagation to other controllers through the peer-to-peer network. The system monitors for credential changes and initiates automatic distribution to ensure all controllers have the latest credentials, reducing propagation time and ensuring real-time security updates.
Solution Approach 2:
The patent pre-distributes transformed credentials to multiple controllers in advance before they are actually needed. When a user is granted access to a service, the necessary credentials are already present on the target controller, eliminating the need for real-time propagation during authentication events and reducing overall credential update time.
3Productivity
If transformed credentials are distributed to multiple services, then authentication efficiency is improved, but network communication overhead increases
Solution Approach 1:
The patent extracts only the necessary transformed credential data from the user credential database and distributes only those specific credentials needed for particular services. Rather than distributing entire credential databases to all controllers, the system extracts and sends only the relevant credential portions, reducing network overhead while maintaining authentication efficiency.
Data Source
Figure 1
Figure 2A
Figure 2B
AI summary
A method relates to distributing user credentials in a distributed physical access control system, and more generally to distributing user credentials in a distributed system. A method may include storing a user credential database (DB) (360), a first transformed credential DB (356) and a second transformed credential DB (358) for authenticating users to access a first (332) and a second service (334) provided by the device (115). The method may include generating the first transformed credential DB (356) and the second transformed credential DB (358) based on the user credential DB (360) and comparing a credential received from a user to the first (356) or the second transformed credential DB (358) to determine whether to grant access to the first (332) or the second service (334). The method may include distributing the user credential DB (360) to a plurality of other devices (115/210) connected in a network for the other devices to generate transformed credential DBs for authenticating users to access services.