Offline Mobile Access Tokens for Hierarchical Perimeter Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing access control systems using electronic or optical tokens, such as barcodes and RFID, are vulnerable to security breaches like credential duplication and cloning, compromising the overall system security, especially when using mobile devices.
Innovation Solution
A method and system that utilize a mobile communication device to securely store and manage access control tokens (MACT and ACT) through encrypted communication channels, involving a first reader for validation and a second reader for hierarchical verification, ensuring that the inner perimeter access is granted only after successful validation of both tokens.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If barcodes or 2D barcodes are used as access tokens on mobile devices, then ease of operation is improved, but security is worsened due to vulnerability to credential duplication and screenshotting
Solution Approach 1:
The access control system is segmented into multiple independent components: an outer perimeter system with first readers that issue temporary tokens, and an inner perimeter system with second readers that validate tokens. This segmentation prevents a single point of failure and requires multiple validation steps, thereby improving security while maintaining ease of operation through automated workflows.
Solution Approach 2:
A temporary access control token acts as an intermediary between the mobile device and the inner perimeter access control system. The token is issued by the outer perimeter system after validation and serves as a mediating credential that enables secure access to the inner perimeter without exposing the inner system's security mechanisms.
2Ease of operation
If RFID technology is used for access control tokens, then ease of operation is improved, but security is worsened due to potential token copying and cloning
Solution Approach 1:
The system performs preliminary validation at the outer perimeter before granting access to the inner perimeter. The first readers validate credentials and issue temporary tokens in advance, establishing a pre-authenticated state that prevents unauthorized access attempts at the inner perimeter and mitigates risks of token copying.
Solution Approach 2:
The access control system transitions from static token validation to dynamic temporary token issuance. Tokens are issued temporarily by the outer perimeter system and have limited validity periods, creating a dynamic security model that adapts to access requirements and reduces the window of opportunity for token copying or cloning attacks.
3Reliability
If a new permanent access control system is installed at the venue, then security is improved, but device complexity and infrastructure requirements increase
Solution Approach 1:
The outer perimeter access control system serves multiple functions: it acts as both a primary access control point and a token issuance authority for the inner perimeter system. This multi-functionality eliminates the need for separate infrastructure and reduces overall system complexity while maintaining enhanced security through hierarchical validation.
Solution Approach 2:
The outer perimeter system automatically validates credentials and issues temporary tokens without requiring manual intervention or additional infrastructure. The system self-manages the token lifecycle including issuance, validation, and expiration, reducing operational complexity while improving security through automated hierarchical validation.
Data Source
Figure 1A
Figure 1B
Figure 2A
AI summary
A method, access control system, and readers for use in an access control system are described. One example of the disclosed method providers the ability to securely augment an existing physical access control system that relies on access control tokens (e.g., credentials) with a secure mobile-based solution allowing the secure local offline exchange of a new access control token for another that can be used with the existing installed access control system.