Key Delegation Access Control Without Central Server Dependence
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing access control systems are vulnerable to central server attacks and lack flexibility, with offline systems being simple and non-flexible, and both types facing issues with centralized management and security.
Innovation Solution
A decentralized access control system using an access control device that verifies access rights locally, utilizing short-range wireless communication with electronic key devices, and employs a challenge-response scheme for authentication, along with key delegation and digital signatures to manage access rights, allowing for flexible and secure access control without reliance on a central server.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If central access control server is used to manage access rights, then access management flexibility is improved, but system security vulnerability increases
Solution Approach 1:
The patent segments the centralized access control system into distributed components. Each access control device stores and processes access rights locally, eliminating the single point of failure at the central server. This segmentation maintains management flexibility while removing the vulnerability associated with centralized storage of access credentials.
Solution Approach 2:
The patent introduces access control devices as intermediary components between users and access objects. These devices locally store and verify access rights, acting as mediators that eliminate the need for a central server while maintaining secure access control functionality.
2Device complexity
If offline access control system is used, then system simplicity is improved, but flexibility deteriorates
Solution Approach 1:
The patent implements local quality by enabling each access control device to independently store and process access rights specific to its associated access objects. This local processing capability provides flexibility in access management while keeping the overall system simple and offline-capable, eliminating the need for complex centralized server infrastructure.
3Ease of operation
If centralized access control server is used, then access right management is improved, but user control over access deteriorates
Solution Approach 1:
The patent enables self-service by allowing access control devices to autonomously manage and verify access rights without requiring central server intervention. Each device independently handles access control operations, giving users full control over their access rights while simplifying the management process through localized processing.
Data Source
Figure 1~2
Figure 3
Figure 4~5
AI summary
It is provided a method for controlling access to an access object. The method is performed in an electronic key device and comprises the steps of: communicating with an access control device to obtain an identity of the access control device; sending an access request to a server, the access request comprising an identity of the electronic key device and the identity of the access control device; receiving a response from the server, the response comprising a key delegation to the electronic key device; and sending a grant access request to the access control device, the grant access request comprising the key delegation, to allow the access control device to evaluate whether to grant access to the access object based on a plurality of delegations comprising a sequence of delegations.