Anti-passback Algorithm for UHF Access Control Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Access control systems that rely on smart cards or UHF tags can be compromised by passback schemes, where credentials are used by an authorized individual and then passed to others for unauthorized access, leading to security breaches and revenue loss.

Innovation Solution

An anti-passback mechanism is implemented in UHF access control systems using firmware-based algorithms, counters, and timers to distinguish between intentional and stray tag presentations, ensuring that credentials are reported only once during an intended tag presentation, thereby preventing repeated data reporting and unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If access control systems use smart cards or UHF tags for authentication, then access control functionality is provided, but the system becomes vulnerable to passback schemes where credentials are reused for unauthorized access

Engineering Contradiction:
Improveaccess control securityVSAvoidpassback attack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by establishing anti-passback rules and monitoring credential usage patterns before unauthorized access can occur. The system tracks when credentials are used and proactively prevents reuse within a specified time window, addressing the security vulnerability before it can be exploited.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms by continuously monitoring credential presentations and comparing them against recorded usage patterns. When a credential is presented, the system checks whether it has been recently used and provides feedback by either granting or denying access based on this analysis, thereby preventing passback attacks.

Inventive Principle:
Principle #23Feedback

2Reliability

If the system monitors and tracks credential usage to prevent passback schemes, then security is improved, but system complexity increases due to additional monitoring and control mechanisms

Engineering Contradiction:
Improveanti-passback securityVSAvoidmonitoring system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The access control system performs multiple functions using the same hardware infrastructure. The reader device not only authenticates credentials but also tracks usage patterns, enforces anti-passback rules, and maintains security logs. This multi-functionality reduces the need for separate dedicated monitoring equipment, thereby limiting complexity increase.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system manages complexity by adjusting operational parameters such as the time window for credential validity and the number of allowed presentations. These parameter changes allow flexible control over security strictness without requiring fundamental changes to system architecture, enabling adaptation to different security requirements while maintaining manageable complexity.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3009991B1Anti-passback algorithm for an access control system
Publication Date: 2020.04.01 ASSA ABLOY AB
  • EP3009991B1 patent drawingFigure 1
  • EP3009991B1 patent drawingFigure 2
  • EP3009991B1 patent drawingFigure 3

AI summary

An anti-passback algorithm for an access control system is described. The anti-passback algorithm prevents the use of valid credentials to gain access to an access-controlled area by more than one person within a given period of time. The algorithm is capable of distinguishing between credentials intentionally presented to the access control system and credentials that are unintentionally read by the access control system. Certain variables may be set by the access control system manufacturer or a trusted individual to adapt the algorithm for applications.