Door Access Control via Remote Credential Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access control systems for doors often rely on local controllers that store valid credentials, which can be vulnerable to tampering and require complex units near the door, compromising security and efficiency.

Innovation Solution

An access control system comprising a credentials relay unit and a lock controller, where the relay unit transmits credentials to a remote server for validation, and the lock controller only unlocks the door upon receiving explicit instructions from the server, minimizing local functionality and reducing power consumption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a local door controller stores and checks credentials locally, then the door can be unlocked quickly and reliably, but the controller becomes vulnerable to tampering and requires more complex security measures

Engineering Contradiction:
Improvedoor unlocking reliabilityVSAvoidtamper resistance
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The credential validation function is extracted from the local door controller and moved to a remote server. The door controller only performs simple credential receipt and wake-up signal transmission, while the remote server performs the actual validation decision. This extraction eliminates the vulnerability of storing credentials locally while maintaining reliable door unlocking through server-based authorization.

Inventive Principle:
Principle #2Taking out (Extraction)

2Speed

If a local door controller performs all access control functions locally, then the system responds quickly, but the controller unit becomes more complex and consumes more power

Engineering Contradiction:
Improveaccess control response speedVSAvoidcontroller unit complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The access control system is segmented into two functional parts: a simple door controller unit that handles only credential receipt and wake-up signal transmission, and a remote server that handles credential validation and unlock decision-making. This segmentation reduces the complexity and power consumption of the door controller while maintaining quick response through dedicated local components for credential receipt and wake-up signal transmission.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If the door controller continuously monitors and validates credentials, then access control is always available, but power consumption increases

Engineering Contradiction:
Improveaccess control availabilityVSAvoidcontroller power consumption
Core Design Contradiction:
Adaptability or versatilityVSUse of energy by moving object

Solution Approach 1:

The door controller operates in a low-power state and only activates its network interface and wake-up signal transmission function when credentials are presented. The controller periodically checks for credential presentation and only performs network communication when needed, rather than continuously monitoring and validating credentials. This periodic operation maintains access control availability while significantly reducing power consumption.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS11232664B2Door access control
Publication Date: 2022.01.25 AXIS
  • US11232664B2 patent drawing
  • US11232664B2 patent drawing

AI summary

The present application concerns access control for controlling unlocking of a door (102) at the presentation of credentials (108) at the door. A credentials relay unit (112) and a lock controller (114) are mounted in the vicinity of the door. The credentials relay unit transmits received credentials to a pre-configured, first network address, and in addition transmits a wake-up signal (122) to the lock controller, which upon receipt of the wake-up signal will transmit a request (126) for instructions to a pre-configured, second network address. In response to the request, the lock controller receives unlocking or no-action instructions (128a, 128b), and in case unlocking instructions are received, the lock controller transmits an unlocking signal (132).