Reader Unit Credential Routing for Multi-Organization Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current access control systems require a central control function for multiple organizations to share automatic doors or access components, which is inefficient and poses security risks.

Innovation Solution

A reader unit that communicates with multiple credential data receivers, allowing credential data to be forwarded based on linked addresses, enabling independent control of access decisions by different organizations without a common central control function.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a central control function is used to enable multiple organizations to share automatic doors, then access control functionality is achieved, but system complexity and security risks increase

Engineering Contradiction:
ImproveAbility of multiple organizations to share access componentsVSAvoidCentral control system structure
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the access control system by allowing each organization to have its own credential data receiver and decision-making logic, while sharing the reader unit. This divides the centralized control function into distributed independent units that can operate autonomously, reducing overall system complexity and eliminating single points of failure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The reader unit is designed with multi-functionality to serve multiple organizations simultaneously. It can read credential data and forward it to different credential data receivers based on the type of credential presented, enabling one device to perform multiple organizational access control functions without requiring separate infrastructure for each organization.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If a central control function is implemented for shared access control, then coordination between organizations is achieved, but security risks increase

Engineering Contradiction:
ImproveMulti-organization access coordinationVSAvoidSystem security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

By segmenting the control function into separate credential data receivers for each organization, the patent eliminates the security risks associated with centralized control. Each organization maintains independent security policies and decision-making authority, so a security breach in one organization's system does not compromise other organizations' access control.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The reader unit acts as an intermediary that forwards credential data to the appropriate credential data receiver without making access decisions itself. This mediator role allows coordination between multiple organizations while maintaining their security independence, as the reader simply routes data without accessing or controlling the sensitive decision-making logic of any single organization.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If separate access control systems are used by each organization, then security independence is maintained, but hardware requirements and costs increase

Engineering Contradiction:
ImproveOrganizational security independenceVSAvoidHardware components
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent merges the reading function into a single shared reader unit that serves multiple organizations, while keeping the credential data receivers separate. This combination reduces hardware quantity by eliminating duplicate readers for each organization, while maintaining security independence through separate credential data receivers that make autonomous access decisions.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The shared reader unit is designed with universal functionality to handle credential data from multiple organizations simultaneously. It can identify the type of credential presented and forward it to the appropriate credential data receiver, enabling one hardware device to replace multiple organization-specific readers while maintaining the ability to enforce separate security policies.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Adaptability or versatility

If credential data is forwarded to multiple credential data receivers, then access decisions can be made independently by each organization, but communication complexity increases

Engineering Contradiction:
ImproveIndependent access decision-makingVSAvoidCommunication architecture
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The reader unit serves as an intelligent intermediary that reduces communication complexity by determining which credential data receiver should receive the credential data based on the type of credential presented. Instead of broadcasting to all receivers, the reader selectively forwards data only to the relevant organization's credential data receiver, simplifying the communication architecture while enabling independent decision-making.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3058554B1Communication and processing of credential data
Publication Date: 2017.11.22 ASSA ABLOY AB
  • EP3058554B1 patent drawingFigure 1~2
  • EP3058554B1 patent drawingFigure 3a~4
  • EP3058554B1 patent drawingFigure 5~6

AI summary

A reader unit (R) registers credential data (CD) representing users seeking access to a well-defined space. The reader unit (R) is associated with an access control related building component (e.g. a lockable door). Each piece of credential data (CD) is further associated with a linked address (A) identifying one of a first credential data receiver (EAC1) and at least one second credential data receiver (EAC2). The linked address (A) Is stored in a memory module (M, M1, M2) associated with the reader unit (R, R1, R2) or on a portable carrier (C) holding the piece of credential data (CD). If the linked address (A) identifies the first credential data receiver (EAC1), the reader unit (R) forwards the registered credential data (CD) to a first credential data receiver (EAC1), and if the linked address (A) identifies a particular one of the at least one second credential data receiver (EAC2), the reader unit (R) forwards the registered credential data (CD) to the particular one of the at least one second credential data receiver (EAC2). In response to the credential data (CD), the first credential data receiver (EAC1) is configured to effect at least one decision (AG) in respect of the well-defined space independently of the at least one second credential data receiver (EAC2) (e.g. opening a door), and vice versa.