Validation Module for HSPD-12 Access Control Compliance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access control systems face challenges in efficiently and flexibly implementing identity verification that complies with federal security standards, such as HSPD-12 and FIPS 201-1, for secure access to government facilities and electronic systems.

Innovation Solution

A validation device with modular communication interfaces, a processor, and a computer-readable storage medium that validates cardholder data using authentication mechanisms like CHUID, CAK, PKI, and biometric authentication, and performs enrollment processing by capturing and storing certificates, enabling integration with existing access control systems without modification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing access control systems are used, then basic access control functionality is provided, but they cannot efficiently and flexibly implement identity verification compliant with federal security standards

Engineering Contradiction:
Improvecompliance with federal security standardsVSAvoidflexibility in implementing identity verification
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system segments the access control functionality by introducing a separate validation device that interfaces between the readers and the access decision component. This validation device is responsible for certificate path discovery, validation to trusted authority, and authentication mechanism selection, allowing the core access control system to remain unchanged while adding federal compliance capabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The validation device serves multiple functions: it validates cardholder data using multiple authentication mechanisms (CHUID, CAK, PKI, biometric), performs certificate path discovery and validation, enables enrollment processing for first-time cardholders, and interfaces with various readers and management stations. This multi-functional approach provides both reliability through comprehensive validation and adaptability through support for multiple authentication types.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If federal compliance validation is added to access control systems, then security assurance is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity assuranceVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The validation device acts as an intermediary component between the readers and the access decision component. It handles all complex federal compliance requirements including certificate validation, authentication mechanism selection, and enrollment processing, thereby isolating the complexity from the core access control system while maintaining security assurance.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The validation device performs self-service by automatically discovering certificate paths, validating certificates against trusted authorities, and selecting appropriate authentication mechanisms without requiring manual configuration. This automation reduces the operational complexity of implementing federal compliance while maintaining high security assurance.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If multiple authentication mechanisms are supported, then versatility of identity verification is improved, but processing time increases

Engineering Contradiction:
Improveauthentication mechanism optionsVSAvoidvalidation processing time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The validation device implements partial action by not all authentication mechanisms simultaneously for every transaction. Instead, it selects the appropriate authentication mechanism based on the cardholder data type and security requirements, performing only the necessary validation steps. This reduces processing time while maintaining versatility by having multiple mechanisms available when needed.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system performs preliminary action by pre-establishing certificate paths and validating certificates against trusted authorities during enrollment and system initialization. This preliminary validation reduces the processing time during actual access transactions, as the heavy computational work of certificate validation has already been completed.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9769164B2Universal validation module for access control systems
Publication Date: 2017.09.19 ASSA ABLOY AB
  • US9769164B2 patent drawing
  • US9769164B2 patent drawing
  • US9769164B2 patent drawing

AI summary

A validation module provides for the upgrading of a physical access control system (PACS) to full HSPD-12 compliance without requiring modification or replacement of the existing PACS. The validation module may contain all of the validation functionality required by federal specifications and technical requirements. The validation module may be installed between an existing PACS panel and a supported card/biometric reader. Readers may be selected based on assurance level requirements, e.g., contactless or contact readers for low and medium assurance level areas and full biometric readers for high assurance areas. The validation module may validate a card according to the assurance level setting, extract ID information from data on the card and then pass the ID information to the PACS panel for an access decision. Cardholder data captured by one validation module may be distributed to other validation modules of the PACS using a management station.