Key Delegation Access Control Without Central Server Dependence

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access control systems are vulnerable to central server attacks and lack flexibility, with offline systems being simple and non-flexible, and both types facing issues with centralized management and security.

Innovation Solution

A decentralized access control system using an access control device that verifies access rights locally, utilizing short-range wireless communication with electronic key devices, and employs a challenge-response scheme for authentication, along with key delegation and digital signatures to manage access rights, allowing for flexible and secure access control without reliance on a central server.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If central access control server is used to manage access rights, then access management flexibility is improved, but system security vulnerability increases

Engineering Contradiction:
Improveaccess management flexibilityVSAvoidsystem security vulnerability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the centralized access control system into distributed components. Each access control device stores and processes access rights locally, eliminating the single point of failure at the central server. This segmentation maintains management flexibility while removing the vulnerability associated with centralized storage of access credentials.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces access control devices as intermediary components between users and access objects. These devices locally store and verify access rights, acting as mediators that eliminate the need for a central server while maintaining secure access control functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If offline access control system is used, then system simplicity is improved, but flexibility deteriorates

Engineering Contradiction:
Improvesystem simplicityVSAvoidflexibility
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent implements local quality by enabling each access control device to independently store and process access rights specific to its associated access objects. This local processing capability provides flexibility in access management while keeping the overall system simple and offline-capable, eliminating the need for complex centralized server infrastructure.

Inventive Principle:
Principle #3Local quality

3Ease of operation

If centralized access control server is used, then access right management is improved, but user control over access deteriorates

Engineering Contradiction:
Improveaccess right managementVSAvoiduser control over access
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent enables self-service by allowing access control devices to autonomously manage and verify access rights without requiring central server intervention. Each device independently handles access control operations, giving users full control over their access rights while simplifying the management process through localized processing.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3742667B1Key delegation for controlling access
Publication Date: 2026.01.28 ASSA ABLOY AB
  • EP3742667B1 patent drawingFigure 1~2
  • EP3742667B1 patent drawingFigure 3
  • EP3742667B1 patent drawingFigure 4~5

AI summary

It is provided a method for controlling access to an access object. The method is performed in an electronic key device and comprises the steps of: communicating with an access control device to obtain an identity of the access control device; sending an access request to a server, the access request comprising an identity of the electronic key device and the identity of the access control device; receiving a response from the server, the response comprising a key delegation to the electronic key device; and sending a grant access request to the access control device, the grant access request comprising the key delegation, to allow the access control device to evaluate whether to grant access to the access object based on a plurality of delegations comprising a sequence of delegations.