Digital Key Access Extension for Offline Multi-Resource Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing access-controlled systems often require staff intervention, continuous network connectivity, or costly hardware/software replacements to extend user credentials for additional resources, lack capacity to store large user lists, and struggle with per-resource permissions and security requirements, while also exposing user identifiers and financial information.
Innovation Solution
A system and method that uses a user authenticator to receive and store altered access rights for a second resource, allowing offline access operations without exposing user identifiers or financial information, and includes a digital key server to generate and verify digital keys for access-controlled systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If existing credentials are extended to control additional resources, then access flexibility is improved, but system complexity and cost increase due to requiring staff intervention, continuous network connectivity, or hardware/software replacements
Solution Approach 1:
The digital key stored in the user authenticator is designed to work across multiple distinct access systems and resources simultaneously. A single digital key can provide access to different types of resources (doors, compartments, devices) through different access systems without requiring separate credentials for each, thereby improving access flexibility while avoiding the need for staff intervention or system replacements.
Solution Approach 2:
Instead of modifying existing credentials or requiring hardware replacements, the system creates a digital key that replicates access functionality across multiple systems. The digital key contains encoded access rights that can be recognized by different access systems, effectively copying the access control function across multiple resources without altering the original systems.
2Ease of operation
If user identifiers and financial information are stored in issued digital keys, then access control functionality is improved, but security and privacy are worsened due to exposure of sensitive data to readers, receivers, or edge devices
Solution Approach 1:
The system extracts and removes sensitive user identifiers and financial information from the digital key stored in the user authenticator. The digital key retains only the necessary access control functionality (encoded access rights) while excluding sensitive personal data. This extraction eliminates the security risk of exposing sensitive information to access control systems while maintaining full access control functionality.
3Reliability
If online dependencies are imposed on access systems, then security and validation are improved, but cost and complexity increase due to network requirements
Solution Approach 1:
The digital key is pre-loaded with encoded access rights and validity information before the user needs access. The user authenticator stores this digital key locally, enabling offline validation of access rights. This preliminary action eliminates the need for continuous network connectivity during access operations, reducing network dependency while maintaining validation security through pre-configured access control data.
Data Source
AI summary
Systems and methods control access across access systems. A reader receives a token from a user authenticator, and permission is determined by validating the token. When permitted, a digital key bound to a target resource is generated. A receiver of an access system obtains and verifies the digital key—optionally offline—and actuates the access system to perform an authorized operation. The token may include a first identifier portion usable by a first access system and an appended extension portion encoding data usable by one or more additional access systems. Extensions may be written or removed via a server-supplied amendment package or a locally unlocked package on a device or a first or third-party application, thereby augmenting or revoking privileges while preserving usability of the token by the first access system. The approach applies to locks, enclosures, compartments, devices, vehicles, and other access-controlled resources.


