Mobile Identification Credential Access Control System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access control systems rely on physical keys or identification documents that can be duplicated or stolen, lacking a secure and efficient method for verifying identities, especially in unattended secure locations, and do not provide a comprehensive record of access.

Innovation Solution

A system utilizing mobile identification credentials (MICs) that allow users to securely verify their identity through a User Mobile-Identification-Credential Device (UMD) connected to a Relying Party System (RPS), enabling secure access to restricted areas while maintaining a record of access by approved individuals.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If physical keys or identification documents are used for access control, then ease of operation is improved, but security and reliability deteriorate due to duplication and theft risks

Engineering Contradiction:
Improveease of accessVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces mechanical physical keys and identification documents with a mobile identification credential system using cryptographic authentication. The mobile device stores cryptographic credentials and communicates with the relying party system through secure protocols, eliminating the need for physical mechanical access control elements while improving both security and operational convenience.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Ease of operation

If physical identification documents are used, then ease of operation is improved, but loss of information increases due to documents being lost or stolen

Engineering Contradiction:
Improveease of accessVSAvoidaccess record
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent implements a feedback mechanism where the relying party system automatically records and stores access information whenever authentication occurs. The system maintains a digital log of authenticated users, access times, and locations, providing continuous feedback and verification of access records without requiring physical documentation. This eliminates the risk of lost access records while maintaining operational ease.

Inventive Principle:
Principle #23Feedback

3Reliability

If mobile identification credentials are implemented, then security and reliability are improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent leverages the mobile device's existing multi-functionality and ubiquitous presence in users' lives. The mobile identification credential system utilizes standard mobile device capabilities (processor, memory, communication interfaces) already present in smartphones and tablets, avoiding the need for specialized hardware devices. This reduces overall system complexity while maintaining high security through cryptographic operations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11599872B2System and network for access control to real property using mobile identification credential
Publication Date: 2023.03.07 THE GOVERNMENT OF THE UNITED STATES OF AMERICA AS REPRESENTED BY THE SEC OF HOMELAND SECURITY
  • US11599872B2 patent drawing
  • US11599872B2 patent drawing
  • US11599872B2 patent drawing

AI summary

A provider system is connected to one or more readers corresponding to one or more access points. A secure local connection is established between the user device and the provider system via one reader. The provider system receives from the user device a request for user access via one access point corresponding to the one reader, the provider system sends to the user device a request for identification information of the user, and the user device sends user information associated with a first mobile identification credential (MIC) which the user device received from an authorizing party system (APS), the user having consented to release the user information to the provider system, and the user information having been verified. The provider system uses the verified user information associated with the first MIC to verify or not verify the identity of the user before granting or denying the request to the user.