Unified Access Control Server for Physical and Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current access control systems for physical and network security are fragmented, leading to vulnerabilities as they fail to unify physical and network access control, resulting in inadequate security policies and increased risk of unauthorized access and breaches.

Innovation Solution

A unified access control system and method that integrates physical and network access control through a single server, enabling credential verification, policy enforcement, and event monitoring across both domains, thereby eliminating the need for separate access control panels and network access control servers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If separate physical access control systems and network access control systems are used, then each system can be independently managed, but security vulnerabilities increase due to lack of unified policy enforcement

Engineering Contradiction:
ImproveIndependent system managementVSAvoidSecurity vulnerability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent combines separate physical access control and network access control systems into a unified access control system. The system integrates credential verification for both physical doors and network resources through a single platform, enabling centralized policy enforcement and eliminating security gaps that exist when systems operate independently.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The access control system is designed to perform multiple functions: verifying credentials for physical access control devices (badges, biometrics), verifying credentials for network access control devices (computers, mobile devices), and enforcing unified security policies across both domains. This multi-functional approach replaces the need for separate specialized systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If a unified access control system integrates both physical and network access control, then security is enhanced through correlated event monitoring, but system complexity increases

Engineering Contradiction:
ImproveSecurity enhancementVSAvoidSystem integration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system employs a universal credential verification mechanism that handles both physical access control credentials (badges, biometric data) and network access control credentials (device identifiers, user accounts) through the same verification process. This standardized approach simplifies the integration complexity despite the system's enhanced security capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The server acts as an intermediary between various access control devices (physical and network) and the centralized policy enforcement mechanism. It receives credential verification requests from diverse devices, processes them through a unified framework, and returns authorization decisions, thereby managing system complexity through a centralized mediation layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of manufacture

If separate access control panels are used for physical access, then device deployment is straightforward, but the need for multiple separate servers increases infrastructure complexity

Engineering Contradiction:
ImproveDevice deployment simplicityVSAvoidInfrastructure complexity
Core Design Contradiction:
Ease of manufactureVSDevice complexity

Solution Approach 1:

The patent merges the functions of separate physical access control servers and network access control servers into a single unified access control server. This consolidation eliminates the need for multiple separate servers while maintaining the ability to deploy access control devices straightforwardly, as they all communicate with the same centralized system through standardized protocols.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS7437755B2Unified network and physical premises access control server
Publication Date: 2008.10.14 CISCO TECHNOLOGY INC
  • US7437755B2 patent drawing
  • US7437755B2 patent drawing
  • US7437755B2 patent drawing

AI summary

The present invention provides an access control server that holds information pertaining to both network access and facility access. The access control server enforces policies based on location, type of resource, time of day, duration, or other events, and logs all successful and unsuccessful attempts to access a given resource whether it be on the network or at the facility. The access control server operates off a common list or table of attributes and policies, or separate lists or tables of attributes and policies that are arbitrated by a credential verification and policy engine. This unified access control server implements protocols that work with network and/or physical premises-based devices. The unified access control server allows events in the facility to be associated with events on the network and vice versa and direct policies that may be executed in the physical or network realm.