In-field Credential Encoding via Secure Cloud Intermediary
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for encoding access credentials to credential devices are either inefficient, requiring new devices for updates or relying on limited specialized equipment and administrators for in-field encoding.
Innovation Solution
A method for in-field encoding of credentials that involves receiving a request to add or update credentials, providing an invitation code for an in-field device, establishing a secure communication channel, generating encoding commands, and sending these commands to the credential device through the in-field device.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If credentials are preprogrammed at the factory, then credential encoding is reliable, but credential updates require new devices and replacement
Solution Approach 1:
A cloud service acts as an intermediary between the credential device and the encoding system. The cloud service receives encoding requests, generates secure communication channels, and transmits credential data to the credential device remotely, eliminating the need for physical device replacement while maintaining security.
Solution Approach 2:
The patent replaces the mechanical/physical system of device replacement with an electronic/digital system of remote credential encoding. Instead of physically replacing credential cards at the factory, the system uses electronic communication through cloud services to update credentials in the field.
2Ease of operation
If specialized in-field encoding equipment is used, then credential encoding can be performed in the field, but access is limited to administrators with specialized equipment
Solution Approach 1:
The cloud service provides a universal platform that can encode credentials for multiple credential devices without requiring specialized equipment. Any user with a standard computing device and internet connection can initiate credential encoding through the cloud service, making the system universally accessible.
Solution Approach 2:
The cloud service acts as an intermediary that eliminates the need for specialized in-field encoding equipment. By mediating between the user's standard device and the credential device, the cloud service provides encoding capability without requiring administrators to possess specialized equipment.
3Reliability
If credential devices are replaced for updates, then credential security is maintained, but time and cost increase
Solution Approach 1:
The system performs preliminary actions by establishing secure communication channels and preparing credential data through the cloud service before actual encoding. This preliminary preparation allows credential updates to be executed quickly and securely without requiring time-consuming physical device replacement procedures.
Solution Approach 2:
The patent substitutes the time-consuming mechanical process of device replacement with an electronic credential encoding process. The cloud service enables credential updates to be performed remotely and instantaneously, maintaining security while dramatically reducing the time required for credential updates.
Data Source
AI summary
A method and system for in-field encoding of credentials to a credential device. An example method comprises receiving a request to at least one of add or update credentials to a credential device; providing an invitation code for an in-field device, the in-field device being separate from the credential device; receiving, from the in-field device, the invitation code along with information from the credential device for establishing a secure communication channel with the credential device; establishing a secure communication channel with the credential device using the in-field device as an intermediate; generating one or more commands for encoding credentials to the credential device based on the request; and sending the one or more commands, via the secure communication channel using the in-field device as an intermediate, to the credential device.


