Wireless NFC Access Credential Validation Without Central Controllers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current access control systems rely on wired connections between access point readers and central controllers, leading to high costs, labor requirements, and potential system failures if the central controller malfunctions.
Innovation Solution
A wireless mesh network using Bluetooth Low Energy (BLE) for communication between access devices, enabling decentralized storage and validation of credentials on NFC tags, allowing for secure and efficient access control without reliance on a central controller.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a wired system with a central controller is used for access control, then the system can centrally manage credentials, but the installation cost increases and the system becomes vulnerable to single points of failure
Solution Approach 1:
The patent divides the centralized credential storage into distributed storage across multiple access devices. Each access device maintains its own credential database, eliminating dependency on a single central controller. This segmentation resolves the contradiction by improving reliability through redundancy while reducing the complexity of wired infrastructure connections.
Solution Approach 2:
The patent replaces the mechanical wired connection system with a wireless communication system. Access devices communicate credentials and data wirelessly, eliminating the need for physical cable installations. This substitution reduces installation cost and infrastructure complexity while maintaining system functionality.
2Reliability
If a central controller is used for access decisions, then credential validation can be centralized, but the system response time increases and the controller becomes a single point of failure
Solution Approach 1:
The patent segments the centralized access decision-making into distributed decisions at individual access devices. Each access device independently validates credentials using locally stored data, eliminating the bottleneck of central controller processing. This resolves the contradiction by improving reliability through distributed autonomy while significantly reducing access response time.
Solution Approach 2:
The patent enables access devices to perform self-validation of credentials using locally stored credential databases and encryption keys. Each access device independently verifies user credentials without requiring continuous communication with a central controller. This self-service capability improves system reliability while minimizing access response time by eliminating communication delays.
3Reliability
If credentials are stored securely on access devices, then access security is improved, but the complexity of credential management increases
Solution Approach 1:
The patent replaces complex manual credential management with automated cryptographic operations. Access devices automatically encrypt and decrypt credentials using cryptographic algorithms, eliminating the need for manual handling. This substitution improves access security through strong encryption while reducing management complexity through automation.
Solution Approach 2:
The patent enables access devices to autonomously manage their own credentials through self-service operations. Devices automatically perform encryption, decryption, and credential validation without requiring manual intervention. This self-service capability improves security through consistent cryptographic application while reducing management complexity by eliminating manual processes.
Data Source
AI summary
A system (100) for storing and validating credentials comprising: access devices (104) wirelessly coupled to one another, wherein the access devices (104) comprises memories (122) such that the memories (122) are configured to store user credential information derived from a unique user identifier associated with each user registered to the access device; a server (108) coupled to the access devices (104), and configured to: store a mapping between base keys and unique serial numbers associated with Near Field Communication (NFC) tags (106); and provide each base key to each access device when each access device is registered with the system (100), wherein an access is granted to a NFC tag based on (i) an identification and fetching of the user credential information from a memory of an access device based on the unique user identifier and (ii) an authentication of a base key associated with the NFC tag.


