Sequential Access Control Key Validation on Mobile Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access control systems require users to carry and manage multiple credentials and personal identification numbers for different locations, leading to security risks and operational inefficiencies, such as lost credentials and forgotten PINs, which can result in unauthorized access and downtime.

Innovation Solution

A method and system where access control keys are managed on a single mobile device, with keys becoming valid sequentially based on previous key usage, location, time, or other criteria, allowing users to access multiple locations with a preplanned route, minimizing the need to carry multiple credentials and simplifying access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple access credentials are required for different locations, then access control functionality is achieved, but security risk increases due to lost credentials falling into unauthorized hands

Engineering Contradiction:
Improveaccess control functionalityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

Multiple access credentials for different locations are merged into a single mobile device. The system stores multiple credentials (first access control key, second access control key, etc.) in one secure location, allowing users to access multiple protected assets without carrying multiple separate credentials. This reduces the security risk of losing individual credentials while maintaining access control functionality across multiple locations.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The access control system segments credentials by validity conditions rather than storing them all as equally accessible. Credentials are divided into different validity states (valid, invalid, future-dated) based on temporal and spatial conditions. This segmentation allows the system to control which credential is active at any given time, preventing unauthorized use of credentials for locations or times when access should be denied.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If multiple access credentials are carried for different locations, then access to multiple assets is enabled, but device complexity increases

Engineering Contradiction:
Improveaccess to multiple assetsVSAvoidcredential management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

A single mobile device is designed to perform multiple access control functions across different locations and time periods. The device can store and execute multiple different access control keys, each with its own validity conditions. This multi-functionality eliminates the need for separate credentials for each location while maintaining the ability to access multiple protected assets with appropriate security controls.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system automatically manages credential validity based on pre-programmed conditions without requiring user intervention. The mobile device and access control system automatically determine which credential is valid based on location, time, and usage sequence. This self-service capability eliminates the complexity of manual credential management, including remembering which credential to use for which location and when credentials expire.

Inventive Principle:
Principle #25Self-service

3Reliability

If sequential validity of access keys is implemented, then security is enhanced, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidkey management system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system pre-programs validity conditions and sequential relationships between access credentials before they are needed. Each credential is associated with predetermined conditions (time of day, location, previous credential usage) that automatically determine its validity. This preliminary configuration allows the system to enforce security through sequential validity without requiring complex real-time decision-making or user input during access attempts.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2974416B1Sequencing the validity of access control keys
Publication Date: 2024.05.22 ASSA ABLOY AB
  • EP2974416B1 patent drawingFigure 1
  • EP2974416B1 patent drawingFigure 2A~2B
  • EP2974416B1 patent drawingFigure 3

AI summary

Mechanisms are provided to sequence one or more access control keys residing on a mobile device to be used with an access control reader. In particular, solutions are described which allow a mobile device to receive one or more access control keys and receive additional sequence data. The sequence data may be created for a particular route or course such that a user is require to present the received access control keys to an access control reader in a particular order to gain access to a protected asset.