Mobile Credential Access Control for Secured Spaces

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing employee access privileges to secured locations and devices within a workplace is challenging due to the large number of employees, making it difficult to efficiently control access to locations such as storage closets or vaults.

Innovation Solution

A provider computing system that includes a network interface and processing circuit to manage access requests by identifying users and retrieving authentication and credential data to determine access decisions, coupled with a device authenticator that generates authentication signals and proximity sensors to grant or deny access to external devices based on user privileges.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional access management methods are used for large numbers of employees, then security control is maintained, but management complexity and time consumption increase significantly

Engineering Contradiction:
Improveaccess control securityVSAvoidaccess management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables employees to self-register and manage their own access credentials through mobile devices. The automatic provisioning and deprovisioning of access rights eliminates the need for manual administrative intervention, reducing management complexity while maintaining security through automated authentication and authorization processes.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces traditional mechanical access control systems (physical keys, manual badges) with mobile-based digital credentials and biometric authentication. This substitution automates the access management process, allowing seamless integration with existing directory services and enabling remote provisioning without physical presence.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If manual access provisioning is implemented for each employee, then access security is controlled, but time consumption and administrative burden increase

Engineering Contradiction:
Improveaccess authorization accuracyVSAvoidaccess provisioning time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary authentication and credential provisioning automatically when employees are hired or assigned new roles. Access rights are pre-configured based on job functions and automatically activated when needed, eliminating the need for manual, time-consuming provisioning processes while maintaining accurate security controls.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system continuously monitors and tracks employee access requests and credentials, providing real-time feedback to administrators. This automated feedback loop enables rapid response to access changes, ensuring security policies are enforced while minimizing administrative time consumption through automated workflow management.

Inventive Principle:
Principle #23Feedback

3Reliability

If centralized access management is implemented across the organization, then security policy enforcement is improved, but system complexity and implementation difficulty increase

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoidsystem implementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system employs a universal mobile platform that can serve multiple access control functions across different locations and devices. A single mobile credential can provide access to multiple secured resources, and the system integrates with existing directory services and authentication infrastructure, reducing implementation complexity while maintaining centralized security policy enforcement.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11682251B1Systems and methods for remotely accessing secured spaces
Publication Date: 2023.06.20 WELLS FARGO BANK NA
  • US11682251B1 patent drawing
  • US11682251B1 patent drawing
  • US11682251B1 patent drawing

AI summary

Systems, methods, and apparatuses for authenticating devices and using an authenticated device to determine an access decision include a computing system including a network interface circuit that facilitates communication via a network and a processing circuit comprising a processor and memory. The processing circuit approves or denies a request to access a secured device. The processing circuit comprises an access management circuit that receives and interprets the access request to identify a user, an authentication database storing authentication data, and a workforce database storing credential data. The access management circuit retrieves the authentication data from the authentication database to determine the user device associated with the access request. The access management circuit retrieves the credential data from the workforce database based on the identification of the user and the authentication data to determine an access decision and approve or deny access to the secured device.