Mobile Device Network Credential Physical Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security systems in local area networks require separate physical identity proofs, such as smart cards or RFID tokens, for accessing physical resources, which is inefficient with the increasing use of personal mobile devices.
Innovation Solution
A method and system that utilizes validated user network identity on mobile devices as physical identity proof, allowing mobile devices to authenticate and control physical access systems through short-range wireless technologies like NFC, eliminating the need for additional physical identity proofs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If separate physical identity proofs (smart cards, RFID tokens) are used for physical access control, then physical security is maintained, but device complexity and operational efficiency deteriorate due to managing multiple separate identity systems
Solution Approach 1:
The patent merges network identity validation with physical access control by integrating the network access server's validated identity into the physical access system. The mobile device's network credential, already validated by the network access server, is reused for physical access authentication, combining two separate identity management functions into one unified system.
Solution Approach 2:
The patent makes the network credential multi-functional by enabling it to serve both network access authentication and physical access control purposes. The same validated network identity on the mobile device is used across different access control contexts (network and physical), eliminating the need for separate physical identity proofs.
2Productivity
If separate smart card management systems are used for physical identity, then physical access control is maintained, but productivity and time efficiency worsen due to manual identity management
Solution Approach 1:
The system enables self-service identity management by automatically leveraging the network access server's validated identity for physical access control. When a user's network identity is validated, the system automatically provisions the corresponding physical access credentials without requiring manual intervention from identity management administrators, reducing both time and operational overhead.
Solution Approach 2:
The patent performs preliminary identity validation through the network access server before physical access is needed. The network credential is validated in advance during network authentication, and this pre-validated identity is then reused for physical access control, eliminating the need for separate real-time validation processes.
3Adaptability or versatility
If network identity and physical identity are managed separately, then security boundaries are maintained, but adaptability worsens as personal mobile devices cannot serve as validated physical identity
Solution Approach 1:
The patent enables the mobile device's network credential to serve multiple functions including both network access and physical access control. The same validated network identity on the mobile device is recognized across different access control systems, making the mobile device a universal access credential that works for both digital and physical resources.
Solution Approach 2:
The network access server acts as an intermediary that bridges network identity validation and physical access control. It validates the mobile device's network credential and communicates this validation status to the physical access control system, enabling the mobile device to function as a validated physical identity proof while maintaining security boundaries through the intermediary's coordination.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
Enables secure and efficient use of mobile devices for physical access control, integrating network identity validation with physical access management, allowing users to access resources like secure doors or vending machines without separate identity tokens, while maintaining policy enforcement and revocation capabilities.
Implementation Method 1
using short-range wireless technologies like NFC
Data Source
AI summary
The present disclosure discloses a method and network device for using mobile devices with validated user network identity as physical identity proof. Responsive to successfully authenticating a client device for network access, a system generates a network credential for the client device and transmits the network credential to the client device. Further, the system detects that the client device is within a range of a short range wireless device that is associated with a particular physical action. Consequently, the system validates the network credential that the client device possesses. Based on the network credential, the system determines that the client device has permissions for performing the particular physical action, and causes performance of the particular physical action.


