IP Library Granted Patent US 10,685,526
Granted Patent B2
US 10,685,526 · App. 16/105,462 · Granted Jun 16, 2020

Architecture for access management

Inventors: Richard Campero (Gilroy, CA); Sean Davis (San Jose, CA); Graeme Jarvis (Marblehead, MA); Terezinha Rumble (Jensen Beach, FL)
Assignee: TYCO INTEGRATED SECURITY, LLC
G07F7/0826G06F9/451G06F16/27G06F17/142G06F21/31G06F21/6218G06Q20/363G06Q20/3674G06Q20/389G07C9/00G07C9/00182G07C9/28G08B13/19682H04L9/06H04L9/0825H04L9/30H04L9/3213H04L9/3242H04L63/0428H04L63/083H04L63/0823H04L63/0853H04L63/0861H04L63/101H04L63/102H04L63/18H04L63/20H04W12/06H04W12/08G06F21/34G06F21/45G06F21/6263G06Q2220/00H04L9/08H04L9/32H04L51/38H04L63/107H04W4/021
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,685,526
App. No.
16/105,462
Granted
Jun 16, 2020
Kind
B2
Abstract

Disclosed are techniques that use devices with corresponding identity wallet applications that execute on an electronic processor device of the devices, and which identity wallets store identity information and encrypt the stored identity information. A distributed ledger system, and a broker system that interfaces to the wallet and the distributed ledger are used for various information exchange cases pertaining to access to facilities. In particular, disclosed is a registration process to register an identity wallet with a facility.

Claims (46)

1. A method comprising:

initiating by a user device a transaction with an application with the transaction including a request from the application to send a user public key stored in a user wallet to the application;

requesting by the user wallet from a security wallet of a building system an access code having a facility public key and a universal identifier;

testing the facility public key and the universal identifier to determine whether they are legitimate;

sending by the user wallet a user profile corresponding a user associated with the user device to the building system when the facility public key and the universal identifier are determined to be legitimate; and

storing the facility public key and the universal identifier on the user device, with the device being now registered with the building system.

2. The method of claim 1 further comprising:

storing the transaction in a distributed ledger system that is a sequential transaction database that comprises plural distributed database systems and network interface device that stores records of personally identifiable information.

3. The method of claim 1 wherein the user public key is embedded in a code.

4. The method of claim 1 wherein the access code having an embedded facility public key is in a matrix barcode.

5. The method of claim 1 wherein the facility public key and the universal identifier are specific to a single physical facility.

6. The method of claim 1 wherein the universal identifier is based on a Universally Unique Identifier (UUID) identifier standard that uses a 128-bit value.

7. The method of claim 1 further comprising:

producing a user identity in a distributed ledger system based on the received profile information, by the building system producing the user identity and sending the produced user identity to the distributed ledger, along with the received user public key and a user type.

8. A system comprising:

a building system that executes an application, the building system comprising a processor and memory configured to:

receive from a device a request to initiate a transaction with the application;

send by the application in response to the transaction request a request to send a user public key stored in a user wallet to the application;

receive a request from the user wallet for building system credentials from a building wallet of the building system;

send the building system credentials including an access code having a facility public key and a universal identifier;

receive from the user wallet a user profile comprising user credentials corresponding a user associated with the user device; and

store the user credentials from the user device to register the user device with the building system.

9. The system of claim 8 further configured to:

store the transaction in a distributed ledger system that is a sequential transaction database that comprises plural distributed database systems and network interface device that stores records of personally identifiable information.

10. The system of claim 8 wherein system receives the user public key is embedded in a code.

11. The system of claim 10 wherein the code is a matrix barcode.

12. The system of claim 8 further configured to:

test whether the user is registered with the system.

13. The system of claim 12 wherein when the user is not registered, the system is further configured to:

produce a user identity based on the user's received profile information; and

send by the building system the produced user identity to the distributed ledger, along with the received user public key and a user type.

14. A method comprising:

receiving from a device a request to initiate a transaction with an application executable by a building system;

sending by the application in response to the transaction request a request to send a user key stored in a user wallet to the application;

receiving a request from the user wallet for building system credentials from a building wallet of the building system;

sending the building system credentials including an access code having a facility public key and a universal identifier;

receiving from the user wallet a user profile comprising user credentials corresponding a user associated with the user device; and

storing the user credentials from the user device to register the user device with the building system.

15. The method of claim 14 , further comprising:

storing the transaction in a distributed ledger system that is a sequential transaction database that comprises plural distributed database systems and network interface device that stores records of personally identifiable information.

16. The method of claim 15 , wherein the user public key is embedded in a code.

17. The method of claim 16 , wherein the code is a matrix barcode.

18. The method of claim 14 , further comprising testing whether the user is registered with a security server.

19. The method of claim 18 , in response to determining that the user is not registered with the security server, further comprising:

producing a user identity based on the user's received profile information; and

sending by the building system the produced user identity to the distributed ledger, along with the received user public key and a user type.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 23, 2024
From: JOHNSON CONTROLS TYCO IP HOLDINGS LLP
To: TYCO FIRE & SECURITY GMBH
Reel/Frame 068494/0384 →
NUNC PRO TUNC ASSIGNMENT Recorded Feb 4, 2022
From: JOHNSON CONTROLS SECURITY SOLUTIONS LLC
To: JOHNSON CONTROLS US HOLDINGS LLC
Reel/Frame 058887/0969 →
NUNC PRO TUNC ASSIGNMENT Recorded Feb 4, 2022
From: JOHNSON CONTROLS US HOLDINGS LLC
To: JOHNSON CONTROLS, INC.
Reel/Frame 058889/0353 →
NUNC PRO TUNC ASSIGNMENT Recorded Feb 4, 2022
From: JOHNSON CONTROLS, INC.
To: JOHNSON CONTROLS TYCO IP HOLDINGS LLP
Reel/Frame 058889/0556 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 30, 2019
From: CAMPERO, RICHARD; DAVIS, SEAN; JARVIS, GRAEME; RUMBLE, TEREZINHA
To: TYCO INTEGRATED SECURITY, LLC
Reel/Frame 050553/0332 →
Continuity (3)
Continuation 15594861 · May 15, 2017
Provisional Application 62385387 · Sep 9, 2016
Related Publication 20190188941A1 · Jun 20, 2019