Globally Unique Identity Token for Cross-Entity Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security systems limit access to restricted areas within a domain and do not allow seamless access across enterprise network boundaries between different companies or entities, restricting user access to multiple connected sites.
Innovation Solution
A distributed security system that generates globally unique identity tokens for users, which can be loaded onto devices and used to access access control systems of both the originating entity and third-party entities, enabling secure and unified access across multiple sites by utilizing a cloud-based token identity service.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a distributed security system with globally unique identity tokens is implemented, then access versatility across multiple entities is improved, but device complexity increases
Solution Approach 1:
The patent introduces a token issuance service as an intermediary component that manages the creation, distribution, and verification of globally unique identity tokens. This service acts as a mediator between access control systems and user devices, handling the complexity of token management centrally while allowing individual access control systems to remain relatively simple. The token itself serves as an intermediary credential that enables cross-entity access without requiring complex inter-system communication protocols.
Solution Approach 2:
The identity token is designed as a universal credential that can be used across multiple access control systems belonging to different entities. Instead of requiring separate credentials for each entity, the single token provides multi-functional access rights that work across the federated network of access control systems, thereby improving versatility without proportionally increasing complexity at each individual system.
2Device complexity
If traditional domain-limited credentials are used, then system complexity is reduced, but access versatility across enterprise boundaries is limited
Solution Approach 1:
The patent extends the traditional credential system by adding a new dimension of scope - transitioning from domain-limited credentials to globally unique identity tokens that operate across a federated network of entities. This dimensional expansion allows credentials to function not just within a single organization's boundaries but across multiple organizational boundaries, effectively adding a cross-entity dimension to access control without fundamentally complicating the underlying authentication mechanism.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
An identity token based access control system and method is disclosed. A distributed security system that manages access to business and/or governmental entities creates an identity credential for a user and obtains or generates a globally unique identity token for the user, and loads the identity credential and the identity token onto a user device. The user then presents the user device including the identity credential and the identity token to an access control system (ACS) of the security system of the business entity that generated the identity token to obtain access to its security system, or to an ACS of a security system of one or more third party business entities that support the use of identity tokens to obtain access to the security systems of the third party business entities. The identity tokens are preferably random numbers or strings. The identity credentials typically include biometric information for users.