Reader Unit Credential Routing for Multi-Organization Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current access control systems require a central control function for multiple organizations to share automatic doors or access components, which is inefficient and poses security risks.
Innovation Solution
A reader unit that communicates with multiple credential data receivers, allowing credential data to be forwarded based on linked addresses, enabling independent control of access decisions by different organizations without a common central control function.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a central control function is used to enable multiple organizations to share automatic doors, then access control functionality is achieved, but system complexity and security risks increase
Solution Approach 1:
The patent segments the access control system by allowing each organization to have its own credential data receiver and decision-making logic, while sharing the reader unit. This divides the centralized control function into distributed independent units that can operate autonomously, reducing overall system complexity and eliminating single points of failure.
Solution Approach 2:
The reader unit is designed with multi-functionality to serve multiple organizations simultaneously. It can read credential data and forward it to different credential data receivers based on the type of credential presented, enabling one device to perform multiple organizational access control functions without requiring separate infrastructure for each organization.
2Adaptability or versatility
If a central control function is implemented for shared access control, then coordination between organizations is achieved, but security risks increase
Solution Approach 1:
By segmenting the control function into separate credential data receivers for each organization, the patent eliminates the security risks associated with centralized control. Each organization maintains independent security policies and decision-making authority, so a security breach in one organization's system does not compromise other organizations' access control.
Solution Approach 2:
The reader unit acts as an intermediary that forwards credential data to the appropriate credential data receiver without making access decisions itself. This mediator role allows coordination between multiple organizations while maintaining their security independence, as the reader simply routes data without accessing or controlling the sensitive decision-making logic of any single organization.
3Reliability
If separate access control systems are used by each organization, then security independence is maintained, but hardware requirements and costs increase
Solution Approach 1:
The patent merges the reading function into a single shared reader unit that serves multiple organizations, while keeping the credential data receivers separate. This combination reduces hardware quantity by eliminating duplicate readers for each organization, while maintaining security independence through separate credential data receivers that make autonomous access decisions.
Solution Approach 2:
The shared reader unit is designed with universal functionality to handle credential data from multiple organizations simultaneously. It can identify the type of credential presented and forward it to the appropriate credential data receiver, enabling one hardware device to replace multiple organization-specific readers while maintaining the ability to enforce separate security policies.
4Adaptability or versatility
If credential data is forwarded to multiple credential data receivers, then access decisions can be made independently by each organization, but communication complexity increases
Solution Approach 1:
The reader unit serves as an intelligent intermediary that reduces communication complexity by determining which credential data receiver should receive the credential data based on the type of credential presented. Instead of broadcasting to all receivers, the reader selectively forwards data only to the relevant organization's credential data receiver, simplifying the communication architecture while enabling independent decision-making.
Data Source
Figure 1~2
Figure 3a~4
Figure 5~6
AI summary
A reader unit (R) registers credential data (CD) representing users seeking access to a well-defined space. The reader unit (R) is associated with an access control related building component (e.g. a lockable door). Each piece of credential data (CD) is further associated with a linked address (A) identifying one of a first credential data receiver (EAC1) and at least one second credential data receiver (EAC2). The linked address (A) Is stored in a memory module (M, M1, M2) associated with the reader unit (R, R1, R2) or on a portable carrier (C) holding the piece of credential data (CD). If the linked address (A) identifies the first credential data receiver (EAC1), the reader unit (R) forwards the registered credential data (CD) to a first credential data receiver (EAC1), and if the linked address (A) identifies a particular one of the at least one second credential data receiver (EAC2), the reader unit (R) forwards the registered credential data (CD) to the particular one of the at least one second credential data receiver (EAC2). In response to the credential data (CD), the first credential data receiver (EAC1) is configured to effect at least one decision (AG) in respect of the well-defined space independently of the at least one second credential data receiver (EAC2) (e.g. opening a door), and vice versa.