Unified Identity Management for Physical Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current access control systems require multiple physical tokens for different facilities, leading to inconvenience and weakened security due to the lack of continuity of identity across multiple locations, with no practical means to link identities across various institutions or services.

Innovation Solution

A system that leverages existing electronic identities from social media and identity providers to unify physical access management, using a Credentializing and Access Control System (CACS) and Proxy and Gateway Control System (PGCS) to bind identities to physical credentials, enabling seamless access across various resources through standardized APIs and token generation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple physical tokens are used for different facilities, then access control can be implemented at each facility, but the consumer must manage multiple tokens which is inconvenient and weakens security mechanisms

Engineering Contradiction:
Improvesecurity mechanismsVSAvoidtoken management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent merges multiple physical tokens and their associated identity management into a single unified digital identity system. The credential service provider consolidates credentials from multiple access control systems into one digital credential that can be presented across different facilities, eliminating the need for consumers to manage multiple separate tokens while maintaining security through centralized identity verification.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The digital credential system provides universal access across multiple facilities and access control systems. A single digital credential can function across different physical locations and access control platforms, making the credential multi-functional rather than facility-specific. This universality allows one credential to replace multiple location-specific tokens.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If facility-specific tokens are used, then each facility can maintain its own access control system, but there is no continuity of identity across multiple facilities or physical points of service

Engineering Contradiction:
Improveidentity continuityVSAvoidaccess control system architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The credential service provider acts as an intermediary between the consumer's digital identity and multiple access control systems. This intermediary service translates and validates credentials across different facilities, enabling identity continuity without requiring direct integration between all access control systems. The mediator handles the complexity of cross-facility authentication while maintaining simplicity for the end user.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent introduces a new dimensional layer of digital identity management that sits above the traditional facility-specific access control systems. Rather than integrating horizontally across all systems, the solution adds a vertical layer of credential service that manages identity continuity across the entire ecosystem, transforming the architecture from multiple isolated systems to a hierarchical multi-layer system.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Ease of operation

If centralized identity providers are used for physical access control, then identity management can be unified, but these systems are either cost prohibitive for consumer applications or constrained to operate only for specific groups

Engineering Contradiction:
Improveidentity managementVSAvoidapplication scope
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The system enables consumers to self-manage their own digital credentials and identities without requiring expensive centralized infrastructure. The credential service provider allows individuals to control their own access credentials, generate digital tokens, and manage their identity portfolio autonomously. This self-service model eliminates the need for costly centralized identity management infrastructure while maintaining unified identity control.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent uses digital copies and representations of credentials rather than requiring physical token distribution. Digital credentials can be replicated and distributed electronically without the costs associated with physical token manufacturing and distribution. This copying approach allows the system to scale to consumer applications without proportionally increasing infrastructure costs.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS8990889B2System and method for physical access control
Publication Date: 2015.03.24 BRIVO SYSTEMS LLC
  • US8990889B2 patent drawing
  • US8990889B2 patent drawing
  • US8990889B2 patent drawing

AI summary

The present invention provides, in one aspect, a system and method for managing authentication tokens that operate across multiple types or physical resources binding the tokens to one or more external electronic Identity Providers; generating tokens; authenticating the tokens at multiple physical resources; managing access to physical resources by linking the tokens to the electronic identities; translating the tokens to the appropriate physical token type based on infrastructure services available at the point of service; validating tokens at the physical resource; tracking and conveying usage information; and making use of social group relationships and other data defined by individual usage to, among other things, simplify the process of granting user-generated credentials to persons connected to a given individual via the Identity Provider or an external social network, for example.