Mobile Token Access Control for Location-Based Revalidation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing access control systems face challenges in managing the granularity of access and monitoring presence effectively, leading to potential security breaches, especially when visitors are involved, without creating unnecessary obstacles.
Innovation Solution
An intelligent access control system that utilizes mobile devices and access control devices, where a security token is generated and transmitted to a client module, monitoring the device's location, and determining revalidation based on physical location, distance from a controlling user, and time within access areas, prompting alerts or additional security measures as necessary.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional access control systems are used, then access control is maintained, but security breaches occur due to inability to monitor visitor presence and access granularity
Solution Approach 1:
The access control device serves multiple functions: it acts as both an access control mechanism and a tracking device. The mobile device paired with the access control device provides location monitoring, proximity detection, and communication capabilities. This multi-functionality enhances security by enabling real-time monitoring of access and presence without requiring separate dedicated systems for each function.
Solution Approach 2:
The mobile device serves as an intermediary between the access control device and the central access control system. It receives security tokens, monitors location, detects proximity to controlled users, and communicates access status. This intermediary approach allows the system to monitor visitors and enforce access policies without direct complex interactions between all system components.
2Reliability
If access control is strictly enforced, then security is improved, but unnecessary obstacles are created to legitimate access
Solution Approach 1:
The access control system dynamically adjusts access policies based on real-time conditions. The access control device monitors location and proximity continuously, and the system responds dynamically by granting or revoking access rights based on current presence data. This dynamic approach allows strict security enforcement when needed while maintaining convenience for legitimate users through automated, context-aware access decisions.
Solution Approach 2:
The system implements continuous feedback loops where location data from mobile devices and proximity detection from access control devices provide real-time information about user presence and status. This feedback enables the access control system to automatically adjust access policies, ensuring that security is enforced based on actual conditions rather than static rules, thereby reducing unnecessary access denials.
3Measurement precision
If real-time monitoring of physical location is implemented, then presence control is improved, but system complexity and processing requirements increase
Solution Approach 1:
The system monitors location and proximity continuously but only performs detailed analysis and triggers revalidation when specific thresholds are met, such as when a visitor enters a controlled area or approaches a controlled user. This partial action approach maintains high measurement precision for critical moments while avoiding unnecessary processing during irrelevant periods, thereby managing system complexity effectively.
Solution Approach 2:
The mobile devices and access control devices autonomously perform location monitoring and proximity detection without requiring constant centralized processing. The devices independently track their own positions and communicate status changes to the access control system, reducing the processing burden on central servers while maintaining precise presence monitoring.
Data Source
AI summary
A method, by an intelligent access control system, of implementing access control to a controlled area having a plurality access areas divided by at least one access point includes the following operations. A security token is generated. The security token is transmitted to a client module executing on a client device associated with a first user, and the client module is caused to pair with an access control device associated with the first user. The client module is caused to transfer the security token to the access control device. A physical location of the client device within the controlled area is monitored. A determination is made, by an access control system and based upon the physical location, that the first user is to be revalidated. The client module causes, based upon the determining, the client device to generate an alert.


