Dynamic Access Rights Adjustment for Anti-Passback Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional access control systems do not account for proximity between users with approved credentials, allowing unauthorized followers into secured zones and failing to limit the number of individuals in sensitive areas, which can compromise security, especially in high-value situations.

Innovation Solution

A method and system that utilize a first access controller or server to temporarily change access rights at an access point from a first set to a second set upon detection of a designated entity, denying access to specific entity categories during this period, thereby preventing unauthorized entry and following.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional access control systems allow any user with approved credentials to enter a zone, then access便利性 is improved, but security against unauthorized following and intruders deteriorates

Engineering Contradiction:
Improveaccess convenienceVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The access control system dynamically changes access rights based on real-time conditions. When a first user enters a zone, the system automatically implements temporary access restrictions for a predetermined period, preventing followers from entering. This dynamic adjustment resolves the contradiction by maintaining ease of access for authorized users while actively preventing unauthorized following and intruder access during critical periods.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs preliminary actions by pre-establishing temporary access restrictions immediately when a user enters a zone. This preliminary restriction is set before any potential follower or intruder can exploit the access point, proactively preventing security breaches while allowing the authorized user to proceed without interruption.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If access rights are temporarily restricted to prevent followers, then security is improved, but access efficiency deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidaccess efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system applies partial restriction by temporarily blocking access for specific entity categories (second entity category) while maintaining access for the first entity category and other authorized users. This partial action ensures security against followers during the predetermined period without completely shutting down access, thus balancing security improvement with minimal impact on overall access efficiency.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If access control systems monitor user proximity, then security against following is improved, but system complexity deteriorates

Engineering Contradiction:
Improvesecurity against followingVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The access control system uses feedback from credential readers to detect when a user with approved credentials approaches or enters an access point. This feedback triggers automatic implementation of temporary access restrictions, creating a closed-loop system that enhances security against following without requiring complex manual monitoring or intervention.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3965076B1Method of controlling access
Publication Date: 2025.05.21 HONEYWELL INTERNATIONAL INC
  • EP3965076B1 patent drawingFigure 1
  • EP3965076B1 patent drawingFigure 2
  • EP3965076B1 patent drawingFigure 3

AI summary

A method of controlling access to a zone 300a, 300b, 300c, wherein the zone is accessed via a first access point 301a, 301b, 301c having an associated first set of access rights, the first set of access rights including permission for a first entity category to access the zone 300a, 300b, 300c, the method comprising: receiving a first signal including a first identifier indicating that a first entity 302 identified by the first identifier and belonging to the first entity category is at the first access point 301a, 301b, 301c; in response to receipt of the first signal, allowing the first entity entry into the zone 300a, 300b, 300c through the first access point 301a, 301b, 301c; and in response to receipt of the first signal, temporarily changing the access rights associated with the first access point 301a, 301b, 301c to a second set of access rights.