Globally Unique Identity Token for Cross-Entity Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security systems limit access to restricted areas within a domain and do not allow seamless access across enterprise network boundaries between different companies or entities, restricting user access to multiple connected sites.

Innovation Solution

A distributed security system that generates globally unique identity tokens for users, which can be loaded onto devices and used to access access control systems of both the originating entity and third-party entities, enabling secure and unified access across multiple sites by utilizing a cloud-based token identity service.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a distributed security system with globally unique identity tokens is implemented, then access versatility across multiple entities is improved, but device complexity increases

Engineering Contradiction:
Improveaccess versatilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a token issuance service as an intermediary component that manages the creation, distribution, and verification of globally unique identity tokens. This service acts as a mediator between access control systems and user devices, handling the complexity of token management centrally while allowing individual access control systems to remain relatively simple. The token itself serves as an intermediary credential that enables cross-entity access without requiring complex inter-system communication protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The identity token is designed as a universal credential that can be used across multiple access control systems belonging to different entities. Instead of requiring separate credentials for each entity, the single token provides multi-functional access rights that work across the federated network of access control systems, thereby improving versatility without proportionally increasing complexity at each individual system.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Device complexity

If traditional domain-limited credentials are used, then system complexity is reduced, but access versatility across enterprise boundaries is limited

Engineering Contradiction:
Improvesystem complexityVSAvoidaccess versatility
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent extends the traditional credential system by adding a new dimension of scope - transitioning from domain-limited credentials to globally unique identity tokens that operate across a federated network of entities. This dimensional expansion allows credentials to function not just within a single organization's boundaries but across multiple organizational boundaries, effectively adding a cross-entity dimension to access control without fundamentally complicating the underlying authentication mechanism.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentEP3338427B1Identity token based security system and method
Publication Date: 2021.05.05 SENSORMATIC ELECTRONICS CORP
  • EP3338427B1 patent drawingFigure 1
  • EP3338427B1 patent drawingFigure 2
  • EP3338427B1 patent drawingFigure 3

AI summary

An identity token based access control system and method is disclosed. A distributed security system that manages access to business and/or governmental entities creates an identity credential for a user and obtains or generates a globally unique identity token for the user, and loads the identity credential and the identity token onto a user device. The user then presents the user device including the identity credential and the identity token to an access control system (ACS) of the security system of the business entity that generated the identity token to obtain access to its security system, or to an ACS of a security system of one or more third party business entities that support the use of identity tokens to obtain access to the security systems of the third party business entities. The identity tokens are preferably random numbers or strings. The identity credentials typically include biometric information for users.