Decentralized Access Control via Nested Delegation Paths
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing access control systems face scalability issues and vulnerability due to reliance on central servers for managing access rights, particularly in wireless electronic lock systems, and offline systems lack flexibility and are prone to similar problems to varying degrees.
Innovation Solution
A method and device that utilize a sequence of delegations with an auxiliary condition authenticated by a digital signature to grant access, where the delegator is the access control device and the receiver is the electronic key, ensuring that access is approved by an authorized party, such as an employer or access right coordinator, without relying on a central server.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a central server is used to verify access rights for electronic keys, then access control flexibility and management capability are improved, but system scalability and vulnerability are worsened due to server availability requirements and communication path dependencies
Solution Approach 1:
The patent segments the centralized access control system into distributed components. Each access control device and electronic key contains local access rights and delegation information, eliminating the single point of failure (central server). The system divides access verification into multiple independent delegation checks, where each delegation represents a separate access authorization that can be validated locally without server communication.
2Reliability
If access rights are stored in the lock or key for offline operation, then system vulnerability is reduced, but access control flexibility and management capability are worsened due to simplicity limitations
Solution Approach 1:
The patent implements a nested delegation structure where delegations are embedded within delegations to create hierarchical access control. Each delegation can contain sub-delegations, allowing complex access scenarios to be represented through nested authorization layers. This enables flexible access management (similar to centralized systems) while maintaining offline operation capability, as the nested delegation structure is self-contained within the electronic key and access control device.
3Adaptability or versatility
If a centralized access control system is deployed, then access management capability is improved, but scalability is worsened as the server and communication paths need to be scaled when new locks and devices are deployed
Solution Approach 1:
The patent enables self-service access control where each device and key autonomously validates access rights using locally stored delegations. When new access control devices or electronic keys are deployed, they independently contain their authorization information through delegations and do not require server configuration or communication infrastructure scaling. The system automatically validates access through delegation verification, eliminating the need to scale central server resources as the system expands.
Data Source
AI summary
It is provided a method for controlling access to a physical space. The method is performed in an access control device and comprises the steps of: communicating with an electronic key to obtain an identity of the electronic key; obtaining a plurality of delegations; determining, from one of the delegations, that there is an auxiliary condition, wherein the auxiliary condition is that access is approved for the electronic key by an auxiliary party, authenticated by a digital signature by the auxiliary party; and granting access to the physical space when the plurality of delegations comprises a sequence of delegations covering a delegation path from the access control device to the electronic key such that, in the sequence of delegations, the delegator of the first delegation is the access control device, the receiver of the last delegation is the electronic key, and the auxiliary condition is fulfilled.


