Credential Gateway for Multi-Protocol Mobile Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing physical access control systems require users to be in close proximity to access devices, introducing latency and complexity due to diverse proprietary credential technologies and lack of standardization, limiting the range and types of secure resources accessible by mobile devices.

Innovation Solution

A credential gateway system that manages the delivery and storage of digital credentials across various secure resources, unifying the delivery mechanism by coordinating with device manufacturers to securely store credentials in trusted execution environments or secure elements, supporting multiple protocols and ensuring secure access to a broader range of resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If physical access control systems use close proximity credential exchange, then security is maintained, but user convenience and access speed deteriorate due to latency

Engineering Contradiction:
ImprovesecurityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a credential gateway as an intermediary component that mediates between the client device and secure resources. The gateway manages credential delivery, validation, and coordination, enabling long-range access while maintaining security through standardized protocols and centralized control mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If diverse proprietary credential technologies are supported, then device compatibility improves, but system complexity increases due to lack of standardization

Engineering Contradiction:
Improvedevice compatibilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal credential gateway that can handle multiple credential types and communication protocols through a single standardized interface. The gateway is designed to work with various secure resources (door locks, ticketing systems, vehicle access) and different client devices, eliminating the need for device-specific integrations while supporting diverse credential technologies.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If mobile devices access secure resources over long distances, then user flexibility improves, but credential delivery security and reliability worsen

Engineering Contradiction:
Improveuser flexibilityVSAvoidcredential delivery security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements preliminary credential provisioning where credentials are securely delivered and stored in the client device before actual access is needed. The credential gateway establishes secure communication channels in advance, validates credentials beforehand, and prepares access tokens, ensuring that when long-range access is required, the credential delivery has already been secured through pre-established trust relationships.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP4062619B1Credential gateway
Publication Date: 2025.09.03 ASSA ABLOY AB
  • EP4062619B1 patent drawingFigure 1
  • EP4062619B1 patent drawingFigure 2
  • EP4062619B1 patent drawingFigure 3

AI summary

Methods and systems are provided for performing operations comprising: receiving, by a credential gateway from a client device, a request to obtain a digital credential for accessing a secure resource, the credential gateway being configured to coordinate an exchange of digital credentials associated with different secure resource types with a plurality of client devices; communicating the request to a server associated with the secure resource; receiving, by the credential gateway from the server associated with the secure resource, a data object that includes the digital credential; selecting, by the credential gateway, based on the data object, a security protocol from a plurality of security protocols; and providing, by the credential gateway, the digital credential to the client device in accordance with the selected security protocol.