Offline Access Control via Credential Token Caveats
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Access control systems face difficulties when dealing with offline electronic locks and mobile devices in areas without communication signals, as they rely on wireless communication to authenticate and authorize access, leading to security and functionality issues.
Innovation Solution
The implementation of a method and system that uses credential tokens with caveats, which include a credential identifier, a user code, and a keyed hash, to authorize specific actions on an access control device, allowing for secure wireless credential access even in offline conditions by determining the credential type and validating actions against predefined rules.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If wireless communication is used for credential authentication, then security and real-time authorization are improved, but system reliability deteriorates in areas without communication signals
Solution Approach 1:
The system pre-loads credential tokens with caveats and authorization rules into the access control device before offline operation is needed. This preliminary action ensures that the device has all necessary authentication data stored locally, enabling it to function reliably without wireless communication signals while maintaining security through pre-configured validation rules.
2Adaptability or versatility
If offline electronic locks are deployed to enable operation without signals, then adaptability to offline environments is improved, but security validation capability deteriorates
Solution Approach 1:
The credential token acts as an intermediary that carries embedded caveats and authorization rules from the online system to the offline access control device. This intermediary structure enables the offline device to validate credentials securely using the embedded rules, bridging the gap between offline operation needs and online security validation requirements.
Solution Approach 2:
The system creates a local copy of the credential validation logic and authorization rules within the offline access control device. By copying the essential validation capabilities into the offline device, the system maintains security validation functionality without requiring continuous connection to the central system, enabling reliable offline operation.
3Measurement precision
If credential tokens with caveats are implemented, then security control and authorization precision are improved, but device complexity increases
Solution Approach 1:
The authorization system is segmented into distinct components: credential tokens containing specific caveats, separate authorization rules, and validation logic. This segmentation allows the system to process and validate individual authorization conditions independently, improving precision while managing complexity through modular organization of authorization data and validation steps.
Data Source
AI summary
A method according to one embodiment includes receiving, by an access control device, a credential token from a mobile device, wherein the credential token includes an access credential, a credential identifier, and a caveat that instructs the access control device to perform an associated action, determining, by the access control device, a credential type associated with the access credential based on the credential identifier, determining, by the access control device, a set of caveat rules associated with the credential type, wherein the set of caveat rules identifies one or more actions authorized for an access credential of the credential type, and performing, by the access control device, the associated action identified by the caveat in response to a determination that the associated action is an action authorized by the set of caveat rules associated with the credential type.


