Dual Card Access Control Programming for Secure Mode Upgrades

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional access control systems face challenges in efficiently upgrading to high-security modes without operational disruption, managing encryption keys, and ensuring secure expiration of configuration cards, often requiring factory pre-configuration or specialized devices.

Innovation Solution

A method involving a dual card system where an access card and a configuration card are encrypted together, ensuring the configuration card expires with the access card, allowing secure switching to high-security mode, and enabling key management without factory pre-configuration or specialized devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If a single configuration card is used to program encryption keys, then the programming operation can be performed without factory pre-configuration, but the configuration card cannot be expired and requires careful control

Engineering Contradiction:
Improveprogramming operationVSAvoidconfiguration card expiration
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent combines the access card and configuration card into a single dual-card system where both cards must be present simultaneously. The configuration card contains encryption keys that are tied to the access card's expiration date, ensuring that when the access card expires, the configuration card becomes unusable. This merging approach resolves the contradiction by enabling flexible programming operations while maintaining security through expiration control.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system segments the functionality into two separate cards: an access card for authentication and a configuration card for programming operations. Each card has distinct responsibilities, but they work together through a combined validation process. This segmentation allows the configuration card to have expiration control linked to the access card while maintaining operational flexibility.

Inventive Principle:
Principle #1Segmentation

2Reliability

If encryption keys are pre-loaded in the factory, then the system is secure from the start, but the operational process becomes cumbersome for the factory to manage

Engineering Contradiction:
Improvesystem securityVSAvoidfactory management process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary configuration actions at the factory by embedding the capability to store encryption keys in the configuration card, but the actual key programming is deferred to the field operation. The factory prepares the hardware with the necessary storage and validation mechanisms, while the actual key loading is done later using the dual-card method. This approach maintains security while simplifying factory management.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If a reader without real-time clock is used, then the system can operate offline, but the configuration card cannot be expired

Engineering Contradiction:
Improveoffline operationVSAvoidconfiguration card expiration
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The access card acts as an intermediary that carries expiration information which is then validated by the configuration card. Even though the reader lacks a real-time clock, the expiration logic is embedded in the card validation process itself. The access card's expiration date serves as the mediator that enables expiration control without requiring external time-keeping infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If high-security mode is implemented, then the system security is improved, but the operational complexity increases

Engineering Contradiction:
Improvesystem securityVSAvoidprogramming operation
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The dual-card system enables self-service programming where the configuration card automatically provides the necessary encryption keys when presented with a valid access card. The system performs self-validation and self-configuration without requiring external programming devices or complex setup procedures. This self-service approach maintains high security while reducing operational complexity.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3411854B1Dual card programming for access control system
Publication Date: 2025.07.09 HONEYWELL INTERNATIONAL INC
  • EP3411854B1 patent drawingFigure 1
  • EP3411854B1 patent drawingFigure 2
  • EP3411854B1 patent drawingFigure 3~4

AI summary

A method of programming an access control system including presenting an access card and a configuration card to a device; determining a validity of the access card at the device; process the configuration card at the device; decrypting a payload on the configuration card based on information from the access card; using the payload form the configuration card to switch the device to a high security mode of operation.