IP Library Granted Patent US 11,777,996
Granted Patent B2
US 11,777,996 · App. 16/458,044 · Granted Oct 3, 2023

Distributed one-time-use entry code generation for physical access control method of operation and mobile systems

Inventors: Hsin-Cheng Chiu (Bethesda, MD); Steven Mark Bryant (Sterling, VA)
Assignee: Brivo Systems LLC
H04L63/205G06F16/2365G06F16/908G07C9/00G07C9/21G07C9/215G07C9/23H04L63/08H04L63/10H04W12/08H04L63/0823H04L63/0838H04L2463/121H04W12/06H04W12/61
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,777,996
App. No.
16/458,044
Granted
Oct 3, 2023
Kind
B2
Abstract

A physical access control system enables acceptable portal entry codes upon receiving each physical access request by operating on the elapsed time from a previous physical access request to generate a temporal credential. The controller receives a plurality of physical access requests from a plurality of mobile application devices. Upon authenticating the first access request, the controller eliminates repetition from the space of acceptable successor requests from each mobile application device. Monotonic nonces advance the range of temporal code matches. Entry code generation is decentralized to distributed application devices and is inherently unknowable until a successor access request is initiated by the same application device.

Claims (18)

1. A method for control of a physical access portal comprising the processes: at a controller,

receiving a plurality of physical access requests (access requests) from a plurality of mobile application devices; at the controller,

determining for each mobile application device (app device) a sequence of access requests comprising at least a first access request and a second access request SOLELY GENERATED BY EACH mobile application DEVICE; at the controller, upon authenticating the first access request (predecessor), writing into non-transitory storage a one-time verification code specific to an immediately subsequent second access request (successor) from the same mobile application device; and at the controller,

upon receiving a successor, performing an authentication process by matching the stored one-time verification code associated with the predecessor; and

on the condition the authentication process passes, writing a newer one-time verification code into non-transitory storage specific to yet another immediately subsequent successor;

wherein each newer one-time verification code is synthesized WITH A MASK OF LEAST SIGNIFICANT BITS TO PROVIDE A RANGE OF TIME RELATING A REQUEST AND THE LAST SUCCESSFUL PHYSICAL ACCESS REQUEST SOLELY AT AND by the mobile application device and transmitted in both a predecessor and successor request; and,

on the condition the authentication process fails,

setting a flag of questionable chain of control associated with the mobile application device.

2. A method for control of a physical access portal comprising the processes: at a controller,

receiving a plurality of physical access requests (access requests) from a plurality of mobile application devices; at the controller,

determining for each mobile application device (app device) a sequence of access requests comprising at least a first access request and a second access request SOLELY GENERATED BY EACH mobile application DEVICE; at the controller, upon authenticating the first access request (predecessor),

writing into non-transitory storage a one-time verification code specific to an immediately subsequent second access request (successor) from the same mobile application device; and at the controller, upon receiving a successor,

performing an authentication process by matching the stored one-time verification code associated with the predecessor; and

on the condition the authentication process passes,

writing a newer one-time verification code into non-transitory storage specific to yet another immediately subsequent successor;

wherein each newer one-time verification code is a transformation SOLELY AT AND BY THE mobile application DEVICE of a timestamp read from the system clock of the mobile application device WITH A MASK OF LEAST SIGNIFICANT BITS TO PROVIDE A RANGE OF TIME; and,

on the condition the authentication process fails,

setting a flag of questionable chain of control associated with the mobile application device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 25, 2023
From: CHIU, HSIN-CHENG, MR; BRYANT, STEVEN MARK, MR
To: BRIVO SYSTEMS LLC
Reel/Frame 062489/0737 →