Dynamic Authorization Data for Wireless Access Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing access control systems for technical installations, particularly those using wireless solutions, face challenges in ensuring the validity and up-to-date status of authorization data without incurring significant hardware costs or complexity, especially in meeting high safety standards.
Innovation Solution
Incorporating a dynamic component into access authorization data that continuously changes, allowing the access control device to validate the data's validity by comparing it with predefined expectations, thus enabling secure and cost-effective access control without requiring additional hardware or complex safety protocols.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If wireless access control using mobile data carriers is implemented, then ease of operation and handling is improved, but reliability in verifying current authorization status deteriorates
Solution Approach 1:
The patent applies dynamics by making the authorization data time-dependent. The mobile data carrier stores authorization data that is valid only for a specific time window. The system dynamically verifies whether the current time falls within the valid time range of the authorization data, thereby ensuring reliability in wireless access control without requiring physical key insertion.
2Reliability
If secure device mechanisms are integrated into the reader to verify key presence, then reliability of authorization verification is improved, but device complexity and costs increase
Solution Approach 1:
The patent replaces mechanical verification methods (physical key insertion and detection) with electronic/time-based verification. Instead of using mechanical switches or physical presence detection, the system uses time-dependent authorization data that can be verified electronically through comparison of time stamps, thereby reducing device complexity while maintaining reliability.
Solution Approach 2:
The patent introduces time as an intermediary element in the authorization verification process. Rather than directly verifying key presence through complex hardware mechanisms, the system uses time-dependent authorization data as an intermediary that indirectly confirms valid authorization. The mobile data carrier contains authorization data with time validity information, and the reader verifies authorization by checking whether the current time falls within the valid range, thereby simplifying the verification mechanism.
3Reliability
If the reader is designed as a fully-fledged secure device according to security standards, then reliability and security are improved, but manufacturing costs and certification effort increase
Solution Approach 1:
The patent employs a cost-effective approach by using relatively simple mobile data carriers with time-dependent authorization data rather than requiring expensive, fully-certified secure readers. The security is achieved through the time-limited nature of the authorization data itself rather than through expensive hardware security modules. This allows for lower-cost implementation while maintaining high security standards through cryptographic verification of time-dependent data.
Data Source
Figure 1
Figure 2a~2b
Figure 3
AI summary
Access control system (10) for controlling a user's access to one or more operating functions of a technical system (12). The access control system (10) comprises a receiving device (22) for reading access authorization data (26) from a mobile data carrier (24) and an access control device (28) configured to receive and validate the access authorization data (26) from the receiving device (22). Furthermore, the receiving device (22) is configured to continuously supplement the access authorization data (26) with a dynamic component (46) and to send the dynamic access authorization data (48) to the access control device (28).The access control device (28) is configured to generate an authorization for those operating functions for which the access authorization data (26) are valid, when the dynamic access authorization data meets a defined expectation.