Dual Interface Access Token for Secure Credential Updates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Access control tokens cannot be securely updated 'in the field' without specialized equipment and online connection to a database, making off-line systems cumbersome and impractical for management and distribution of cryptographic keys.

Innovation Solution

A dual-interface access control device with a USB Mass Storage Device (MSD) virtual file system and contact-less RFID/NFC interface, allowing secure remote updates of access control credentials and cryptographic keys using a standard PC, eliminating the need for additional hardware or software, and enabling unified physical and digital identification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If off-line access control systems are used to simplify installation and reduce wiring requirements, then ease of installation and cost savings are improved, but the ability to securely update access credentials and cryptographic keys deteriorates

Engineering Contradiction:
Improveease of installationVSAvoidability to update credentials
Core Design Contradiction:
Ease of manufactureVSEase of operation

Solution Approach 1:

The access control device is designed with dual interfaces: a contact-less interface for access control operations and a USB Mass Storage Device interface for credential updates. This multi-functionality allows the same device to operate independently as an off-line access control token while also enabling secure credential updates through standard USB connections to host systems, eliminating the need for specialized programming equipment.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If specialized equipment and online connection are required to update access control tokens, then security of credential updates is improved, but device complexity and administrative overhead increase

Engineering Contradiction:
Improvesecurity of credential updatesVSAvoidcomplexity of update system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The USB Mass Storage Device interface acts as an intermediary that enables secure credential updates through standard PC connections. The device presents a virtual file system that allows host systems to securely write access credentials and cryptographic keys without requiring specialized programming equipment or online connections to centralized databases, thus maintaining security while reducing complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If centralized card re-configuration is required for off-line systems, then control over access credentials is improved, but loss of time and user convenience deteriorate

Engineering Contradiction:
Improvecontrol over access credentialsVSAvoidtime for credential updates
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The device enables users to perform their own credential updates by connecting the access control token to any standard PC with a USB port. The virtual file system interface allows users to add, remove, and manage access credentials independently without needing to visit centralized locations or require administrative personnel, thus maintaining control while significantly reducing time loss.

Inventive Principle:
Principle #25Self-service

4Adaptability or versatility

If hybrid on-line/off-line systems are implemented to allow remote re-configuration, then adaptability is improved, but device complexity and cost increase

Engineering Contradiction:
Improveflexibility of access controlVSAvoidcomplexity of hybrid system
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The access control device integrates both off-line operational capability and on-line update capability within a single unified system. The dual-interface design allows the device to function independently as an off-line token while also supporting remote credential management through standard USB connections, providing hybrid system flexibility without requiring separate systems or specialized equipment.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

Enables flexible and secure management of access control credentials and keys, reducing administrative overhead, allowing users to update credentials remotely and securely, similar to on-line systems, with enhanced security and cost savings by integrating physical and digital access control.

Implementation Method 1

The device comprises a contact-less interface for contact-less identification and authentication

Methodology Applied
Scientific EffectElectromagnetic induction: Electromagnetic Induction

Data Source

PatentUS9462470B2Dual interface device for access control and a method therefor
Publication Date: 2016.10.04 YUBICO
  • US9462470B2 patent drawing
  • US9462470B2 patent drawing

AI summary

The invention provides a low-cost access control device for identification and authentication in both the “digital” and “physical” worlds by contact-bound respectively contact-less interfaces and where individual users of the device can securely update access control credentials and cryptographic keys from a remote system without the need for any additional hardware or specialized software. The access control credentials and the at least one cryptographic key shall be readable by an access control system via the contact-less interface of the device, thereby enabling or denying the holder of the device access.