Public Key Credential Enrollment for Interoperable Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing access control systems rely on proprietary formats that require multiple credentials, leading to inconvenience, increased administrative burden, limited interoperability, and security risks due to misplacement of credentials, and lack of flexibility and vendor lock-in.
Innovation Solution
Implementing a public key as a credential (PKAAC) system that allows devices to generate PKI key pairs, with the private key stored securely on the device, enabling a unified, interoperable, and user-friendly access control solution through dynamic enrollment and authorization based on pre-enrollment information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If proprietary access control credentials are used for different buildings and locations, then access control security is provided, but users need multiple credentials which increases complexity and reduces ease of operation
Solution Approach 1:
The patent implements a universal credential system where a single access control credential can be used across multiple buildings, locations, and digital resources. The credential is based on a public key that can be enrolled with multiple access control readers, eliminating the need for multiple proprietary credentials while maintaining security through cryptographic verification
2Reliability
If proprietary access control formats are used, then access control functionality is provided, but interoperability between different systems is limited
Solution Approach 1:
The system uses a universal public key credential format that can be enrolled with different access control readers across multiple buildings and systems. The credential structure is designed to be system-agnostic, allowing the same credential to work across different vendors and platforms while maintaining secure access control functionality
Solution Approach 2:
The patent changes the fundamental parameter of credential format from proprietary binary formats to a universal public key cryptographic format. This parameter change enables the credential to be universally recognized across different systems while maintaining security through cryptographic signatures and verification
3Reliability
If multiple access control credentials are required, then comprehensive access control coverage is achieved, but administrative burden increases
Solution Approach 1:
The patent merges the functionality of multiple access control credentials into a single unified credential. Instead of managing separate credentials for different buildings and locations, the system combines all access rights into one public key credential that can be enrolled with multiple access control readers, significantly reducing administrative burden
4Reliability
If traditional access control credentials are used, then access authorization is provided, but security risks exist due to credential misplacement
Solution Approach 1:
The patent replaces physical access control credentials (cards, badges, tokens) with a digital public key credential stored on a mobile device. This substitution eliminates the security risks associated with physical credential misplacement, loss, or theft, as the cryptographic credential can be remotely revoked and regenerated without physical replacement
Data Source
AI summary
Example aspects include techniques for enrollment of a public key for use as a physical or logical credential. These techniques may include receiving, at a first PKAAC access control reader with enrollment capabilities, a PKAAC authentication request from a PKAAC-enabled client application of a client device, and determining that the PKAAC authentication request corresponds to an identity that is unenrolled. In addition, the techniques may include collecting pre-enrollment information in response to the PKAAC authentication request corresponding to the identity that is unenrolled, and generating enrollment information based upon the pre-enrollment information, the enrollment information including authorization information indicating that the identity is authorized to access an access point. Further, the techniques may include providing, via a second PKAAC access control reader, access to the access point based on the authorization information.


