IP Library Granted Patent US 8,474,026
Granted Patent B2
US 8,474,026 · App. 12/724,071 · Granted Jun 25, 2013

Realization of access control conditions as boolean expressions in credential authentications

Inventor: Scott B. Guthery (Chestnut Hill, MA)
Assignee: Assa Abloy AB
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,474,026
App. No.
12/724,071
Granted
Jun 25, 2013
Kind
B2
Abstract

A method, reader, and system are provided for performing group authentication processes. In particular, a group access decision can be made upon the analysis of a group rule. The group rule may contain a Boolean expression including one or more Boolean conditions. If an appropriate group of credentials are presented to a reader such that the Boolean expression is satisfied, then the group of credentials and the holders thereof are allowed access to a protected asset.

Claims (43)

1. A method comprising:

detecting the presence of a group of credentials comprising at least one of a first credential and a second credential in proximity to a reader, wherein at least one of the first and second credentials are a portable device;

determining that group authentication is required to make an access control decision;

invoking a group authentication process at a selected one of the first and second credentials that includes:

determining if sequential processing is allowed;

obtaining a first value based on an exchange of data between the reader and the first credential;

obtaining a second value based on an exchange of data between the reader and the second credential;

analyzing a group authentication rule with the first and second values; and

making a group authentication decision based on the analysis step;

wherein in response to determining that sequential processing is allowed, group access is permitted in the absence of exchanging data between the reader and at least one credential in the group of credentials;

wherein in response to determining that sequential processing is not allowed, group access is conditioned upon each credential in the group of credentials exchanging data with the reader;

implementing an action consistent with the group authentication decision, wherein the action is one of admitting access to an asset protected by the reader, denying access to the asset protected by the reader, communicating an indication to the reader admitting access to an asset protected by the reader, and communicating an indication to the reader denying access to the asset protected by the reader.

2. The method of claim 1 , wherein sequential processing is allowed in the group authentication process when the group authentication rule does not contain one or both of a NOT and XOR operation.

3. The method of claim 1 , wherein the group authentication rule comprises a Boolean expression and at least one Boolean operation.

4. The method of claim 1 , wherein the first credential performs the group authentication process because it is one of a designated credential and a randomly selected credential.

5. The method of claim 1 , wherein the second credential performs the group authentication process.

6. The method of claim 1 , wherein determining that group authentication is required involves determining that one or more of the following conditions exist:

a plurality of credentials are detected within proximity of the reader;

a plurality of users are detected within proximity of the reader; and

access to an asset protected by the reader is only allowed upon satisfaction of a group rule.

7. An access control system, comprising:

memory including instructions in the form of machine-readable code, the instructions including an authentication module and authentication data;

a processor, configured to execute the instructions stored in the memory; and

wherein the authentication module is configured to detect the presence of a group of credentials comprising at least one of a first credential and a second credential in proximity to a reader, determine that group authentication is required to make an access control decision, and invoke a group authentication process at a selected one of the first and second credentials that includes:

determining if sequential processing is allowed;

obtaining a first value based on an exchange of data between the reader and the first credential;

obtaining a second value based on an exchange of data between the reader and the second credential;

analyzing a group authentication rule contained within the authentication data with the first and second values; and

making a group authentication decision based on the analysis step;

wherein in response to determining that sequential processing is allowed, group access is permitted in the absence of exchanging data between the reader and at least one credential in the group of credentials;

wherein in response to determining that sequential processing is not allowed, group access is conditioned upon each credential in the group of credentials exchanging data with the reader;

wherein the authentication module is configured to communicate an indication of an access control decision to the reader, the access control decision consistent with the group authentication decision and is one of admitting access to an asset protected by the reader and denying access to the asset protected by the reader.

8. The system of claim 7 , wherein sequential processing is allowed in the group authentication process when the group authentication rule does not contain one or both of a NOT and XOR operation. and condition group access upon each credential in the group of credentials exchanging data with the reader.

9. The system of claim 7 , wherein the group authentication rule comprises a Boolean expression and at least one Boolean operation.

10. The system of claim 7 , wherein the authentication module is configured to determine that group authentication is required by determining that one or more of the following conditions exist:

a plurality of credentials are detected within proximity of the reader;

a plurality of users are detected within proximity of the reader; and

access to an asset protected by the reader is only allowed upon satisfaction of a group rule.

11. The method of claim 1 , wherein the first credential performs the group authentication process.

12. The method of claim 1 , wherein the second credential performs the group authentication process.

13. The system of claim 7 , wherein the first credential performs the group authentication process because it is one of a designated credential and a randomly selected credential.

14. The system of claim 7 , wherein the first credential performs the group authentication process.

15. The system of claim 7 , wherein the second credential performs the group authentication process.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 22, 2010
From: GUTHERY, SCOTT B.
To: ASSA ABLOY AB
Reel/Frame 024113/0907 →
Continuity (2)
Provisional Application 61160194 · Mar 13, 2009
Related Publication 20100235905A1 · Sep 16, 2010