Offline Access Control via Credential Token Caveats

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Access control systems face difficulties when dealing with offline electronic locks and mobile devices in areas without communication signals, as they rely on wireless communication to authenticate and authorize access, leading to security and functionality issues.

Innovation Solution

The implementation of a method and system that uses credential tokens with caveats, which include a credential identifier, a user code, and a keyed hash, to authorize specific actions on an access control device, allowing for secure wireless credential access even in offline conditions by determining the credential type and validating actions against predefined rules.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If wireless communication is used for credential authentication, then security and real-time authorization are improved, but system reliability deteriorates in areas without communication signals

Engineering Contradiction:
Improveaccess control system reliabilityVSAvoidoffline operation capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system pre-loads credential tokens with caveats and authorization rules into the access control device before offline operation is needed. This preliminary action ensures that the device has all necessary authentication data stored locally, enabling it to function reliably without wireless communication signals while maintaining security through pre-configured validation rules.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If offline electronic locks are deployed to enable operation without signals, then adaptability to offline environments is improved, but security validation capability deteriorates

Engineering Contradiction:
Improveoffline environment operationVSAvoidcredential validation security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The credential token acts as an intermediary that carries embedded caveats and authorization rules from the online system to the offline access control device. This intermediary structure enables the offline device to validate credentials securely using the embedded rules, bridging the gap between offline operation needs and online security validation requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates a local copy of the credential validation logic and authorization rules within the offline access control device. By copying the essential validation capabilities into the offline device, the system maintains security validation functionality without requiring continuous connection to the central system, enabling reliable offline operation.

Inventive Principle:
Principle #26Copying

3Measurement precision

If credential tokens with caveats are implemented, then security control and authorization precision are improved, but device complexity increases

Engineering Contradiction:
Improveauthorization precisionVSAvoidaccess control device complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The authorization system is segmented into distinct components: credential tokens containing specific caveats, separate authorization rules, and validation logic. This segmentation allows the system to process and validate individual authorization conditions independently, improving precision while managing complexity through modular organization of authorization data and validation steps.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11665151B2Utilizing caveats for wireless credential access
Publication Date: 2023.05.30 SCHLAGE LOCK CO LLC
  • US11665151B2 patent drawing
  • US11665151B2 patent drawing
  • US11665151B2 patent drawing

AI summary

A method according to one embodiment includes receiving, by an access control device, a credential token from a mobile device, wherein the credential token includes an access credential, a credential identifier, and a caveat that instructs the access control device to perform an associated action, determining, by the access control device, a credential type associated with the access credential based on the credential identifier, determining, by the access control device, a set of caveat rules associated with the credential type, wherein the set of caveat rules identifies one or more actions authorized for an access credential of the credential type, and performing, by the access control device, the associated action identified by the caveat in response to a determination that the associated action is an action authorized by the set of caveat rules associated with the credential type.