Access Credential Exchange for Unified Physical Access Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing physical control access systems often require separate authentication and authorization processes, leading to inefficiencies and potential vulnerabilities in securing access to physical spaces.
Innovation Solution
A combined authentication and authorization process using asymmetric authentication and exchange of authorization credentials, incorporating ephemeral key pairs and symmetric session keys, ensures secure and efficient access control by integrating authentication and authorization into a single flow.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If separate authentication and authorization processes are used, then security verification is thorough, but interaction time and system complexity increase
Solution Approach 1:
The patent combines authentication and authorization into a single integrated protocol flow. The access control device performs both authentication (verifying the user device's identity through cryptographic proof) and authorization (determining access rights based on credentials) in one interaction sequence, eliminating the need for separate process steps and reducing overall interaction time while maintaining security thoroughness
2Reliability
If separate authentication and authorization processes are used, then security verification is thorough, but device complexity and protocol interactions increase
Solution Approach 1:
The patent merges authentication and authorization into a unified protocol where both functions are accomplished through a single credential verification flow. This reduces the number of separate protocol interactions and message exchanges required between devices, simplifying the overall system architecture while maintaining comprehensive security verification
Solution Approach 2:
The access control device is designed to perform multiple functions (authentication and authorization) within a single operational mode. The same cryptographic verification mechanism serves both to authenticate the user device's identity and to authorize access based on credentials, eliminating the need for separate specialized processes
3Adaptability or versatility
If traditional authentication methods are used, then compatibility with existing systems is maintained, but security robustness against attacks is reduced
Solution Approach 1:
The patent changes the cryptographic parameters and protocol structure from traditional authentication methods to an integrated authentication-authorization approach using ephemeral key pairs and digital signatures. This enhances security robustness by providing perfect forward secrecy and resistance to replay attacks, while maintaining adaptability through standardized cryptographic interfaces that can work with existing access control infrastructures
4Reliability
If multiple interaction steps are used for authentication and authorization, then verification completeness is ensured, but processing time increases
Solution Approach 1:
The patent combines multiple verification steps into a single streamlined cryptographic exchange. The access control device verifies both authentication credentials and authorization permissions in one atomic operation, ensuring verification completeness while dramatically improving access control speed by eliminating sequential processing delays
Data Source
AI summary
Systems and methods may be used for authenticating and validating a credential for performing an action. A method may include using an access control device to exchange public keys with a user device. The method may include sending, to the user device, a first authentication cryptogram including a first signature, a public key certificate, and a Credential Trust Information (CTI), and receiving, from the user device, a second authentication cryptogram including a second signature, a public key of the user device, and a credential. The access control device may authenticate the user device based on the credential and the second signature The access control device may determine whether the credential received in the second authentication cryptogram is signed by a trusted credential issuer to validate the user device. The method may include causing the action to be performed.


