IP Library Granted Patent US 8,015,597
Granted Patent B2
US 8,015,597 · App. 10/893,165 · Granted Sep 6, 2011

Disseminating additional data used for controlling access

Assignee: CoreStreet, Ltd.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,015,597
App. No.
10/893,165
Granted
Sep 6, 2011
Kind
B2
Abstract

Issuing and disseminating a data about a credential includes having an entity issue authenticated data indicating that the credential has been revoked, causing the authenticated data to be stored in a first card of a first user, utilizing the first card for transferring the authenticated data to a first door, having the first door store information about the authenticated data, and having the first door rely on information about the authenticated data to deny access to the credential. The authenticated data may be authenticated by a digital signature and the first door may verify the digital signature. The digital signature may be a public-key digital signature. The public key for the digital signature may be associated with the credential. The digital signature may be a private-key digital signature. The credential and the first card may both belong to the first user. The credential may be stored in a second card different from the first card, and the first door may rely on information about the authenticated data by retrieving such information from storage. The authenticated data may be first stored in at least one other card different from the first card and the authenticated data may be transferred from the at least one other card to the first card. The authenticated data may be transferred from the at least one other card to the first card by first being transferred to at least one other door different from the first door.

Claims (60)

1. A method for issuing and disseminating data about a credential, comprising:

(a) having an entity issue authenticated data indicating that the credential has been revoked, wherein the authenticated data is different from the credential;

(b) causing the authenticated data to be stored in a first card of a first user;

(c) utilizing the first card for transferring the authenticated data to a first door;

(d) having the first door store the authenticated data; and

(e) having the first door rely on the authenticated data to deny access to the credential, wherein the authenticated data causes denial of access to the credential even if the credential has not expired and is otherwise valid, and wherein, prior to relying on the authenticated data to deny access to the credential, the credential is validated at the first door using a proof of validity of the credential, the proof being different from the authenticated data, wherein validating the credential using the proof includes applying a one way function to the proof a specified number of times and comparing a result thereof to information provided on the credential.

2. The method according to claim 1 , wherein the authenticated data is authenticated by a digital signature and the first door verifies the digital signature.

3. The method according to claim 2 , wherein the digital signature is a public-key digital signature.

4. The method according to claim 3 , wherein the public key for the digital signature is associated with the credential.

5. The method according to claim 2 , wherein the digital signature is a private-key digital signature.

6. The method according to claim 1 , wherein the credential is stored in the first card.

7. The method according to claim 1 , wherein the credential is stored in a second card different from the first card, and wherein the first door relies on the authenticated data by retrieving the authenticated data from storage.

8. The method according to claim 1 , wherein the credential belongs to a second user different from the first user.

9. The method according to claim 1 , wherein the authenticated data is first stored in at least one other card different from the first card and wherein the authenticated data is transferred from the at least one other card to the first card.

10. The method according to claim 9 , wherein the authenticated data is transferred from the at least one other card to the first card by first being transferred to at least one other door different from the first door.

11. The method according to claim 1 , wherein the entity causes the authenticated data to be stored in the first card by first causing the authenticated data to be stored on a responder and then having the first card obtain the authenticated data from the responder.

12. The method according to claim 11 , wherein the responder is unprotected.

13. The method according to claim 1 , wherein the first door receives the authenticated data from the first card by the authenticated data first being transferred to at least one other card different from the first card.

14. The method according to claim 13 , wherein the at least one other card receives the authenticated data from the first card by the authenticated data first being transferred to at least one other door different from the first door.

15. The method according to claim 1 , wherein the first door is totally disconnected.

16. The method according to claim 1 , wherein the first door is intermittently connected.

17. A method for a first door to receive authenticated data about a credential of a first user, comprising:

(a) receiving the authenticated data from a first card belonging to a second user different than the first user, wherein the authenticated data, different from the credential, indicates that the credential of the first user has been revoked;

(b) storing the authenticated data;

(c) receiving the credential of the first user; and

(d) relying on the authenticated data to deny access to the credential, wherein the authenticated data causes denial of access to the credential of the first user even if the credential has not expired and is otherwise valid, and wherein, prior to relying on the authenticated data to deny access to the credential, the credential is validated at the first door using a proof of validity of the credential, the proof being different from the authenticated data, wherein validating the credential using the proof includes applying a one way function to the proof a specified number of times and comparing a result thereof to information provided on the credential.

18. The method according to claim 17 , wherein the authenticated data is authenticated by a digital signature and the first door verifies the digital signature.

19. The method according to claim 18 , wherein the digital signature is a public-key digital signature.

20. The method according to claim 19 , wherein the public key for the digital signature is associated with the credential.

21. The method according to claim 18 , wherein the digital signature is a private-key digital signature.

22. The method according to claim 17 , wherein the authenticated data is stored in the first card by being first stored in at least one other card and then transferred from the at least one other card to the first card.

23. The method according to claim 22 , wherein the authenticated data is transferred from the at least one other card to the first card by first being transferred to at least one door different from the first door.

24. The method according to claim 17 , wherein the authenticated data is stored in the first card by first being stored on a responder and then obtained by the first card from the responder.

25. The method according to claim 24 , wherein the responder is unprotected.

26. The method according to claim 17 , wherein the first door receives the authenticated data from the first card by the authenticated data first being transferred to at least one other card different from the first card.

27. The method according to claim 26 , wherein the at least one other card receives the authenticated data from the first card by the authenticated data first being transferred to at least one other door different from the first door.

28. The method according to claim 17 , wherein the first door is totally disconnected.

29. The method according to claim 17 , wherein the first door is intermittently connected.

30. A method for assisting in an immediate revocation of access, comprising:

(a) receiving authenticated data about a credential indicating that the credential has been revoked, wherein the authenticated data is different from the credential;

(b) storing the authenticated data on a first card; and

(c) causing a first door to receive the authenticated data, wherein the authenticated data causes denial of access to the credential even if the credential has not expired and is otherwise valid, and wherein, prior to the authenticated data causing the denial of access to the credential, the credential is validated at the first door using a proof of validity of the credential, the proof being different from the authenticated data, wherein validating the credential using the proof includes applying a one way function to the proof a specified number of times and comparing a result thereof to information provided on the credential.

31. The method according to claim 30 , wherein the authenticated data is authenticated by a digital signature.

32. The method according to claim 31 , wherein the digital signature is a public-key digital signature.

33. The method according to claim 32 , wherein the public key for the digital signature is associated with the credential.

34. The method according to claim 31 , wherein the digital signature is a private-key digital signature.

35. The method according to claim 30 , wherein the credential is stored in the first card.

36. The method according to claim 35 , wherein the first card becomes unusable for access if the first card fails to receive a prespecified type of signal in a prespecified amount of time.

37. The method according to claim 30 , wherein the credential belongs to an other user different from the first user.

38. The method according to claim 30 , wherein the authenticated data is received by the first card by being first stored in at least one other card different from the first card and then transferred from the at least one other card to the first card.

39. The method according to claim 38 , wherein the authenticated data is transferred from the at least one other card to the first card by first being transferred to at least one other door different from the first door.

40. The method according to claim 30 , wherein the first card obtains the authenticated data from a responder.

41. The method according to claim 40 , wherein the responder is unprotected.

42. The method according to claim 30 , wherein the first card causes the first door to receive the authenticated data by first transferring the authenticated data to at least one other card different from the first card.

43. The method according to claim 42 , wherein the first card causes the at least one other card to receive the authenticated data by first transferring the authenticated data to at least one other door different from the first door.

44. The method according to claim 30 , wherein the first door is totally disconnected.

45. The method according to claim 30 , wherein the first door is intermittently connected.

46. The method according to claim 30 , wherein the first card eventually removes the authenticated data from storage.

47. The method according to claim 46 , wherein the credential has an expiration date, and first card removes the authenticated data from storage after the credential expires.

48. The method according to claim 47 , wherein the expiration date of the credential is inferred from information specified within the credential.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 11, 2014
From: CORESTREET LTD
To: ASSA ABLOY AB
Reel/Frame 032404/0759 →
RELEASE OF SECURITY INTEREST Recorded Oct 8, 2013
From: ASSA ABLOY AB
To: CORESTREET, LTD.
Reel/Frame 031361/0975 →
ASSIGNMENT OF SECURITY AGREEMENT Recorded Jan 26, 2007
From: ASSA ABLOY IDENTIFICATION TECHNOLOGY GROUP AB
To: ASSA ABLOY AB
Reel/Frame 018806/0814 →
SECURITY AGREEMENT Recorded Dec 16, 2005
From: CORESTREET, LTD.
To: ASSA ABLOY IDENTIFICATION TECHNOLOGY GROUP AB
Reel/Frame 016902/0444 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 21, 2004
From: LIBIN, PHIL; MICALI, SILVIO; ENGBERG, DAVID; SINELNIKOV, ALEX
To: CORESTREET, LTD.
Reel/Frame 015906/0654 →
Continuity (76)
Continuation In Part 10876275 · Jun 24, 2004
Continuation In Part 10409638 · Apr 8, 2003
Continuation In Part 10103541 · Mar 20, 2002
Continuation In Part 09915180 · Jul 25, 2001
Continuation In Part 09915180
Continuation 09483125 · Jan 14, 2000
Continuation 09356745 · Jul 19, 1999
Continuation 08823354 · Mar 24, 1997
Continuation 08559533 · Nov 16, 1995
Continuation In Part 08992897 · Dec 18, 1997
Continuation In Part 08715712 · Sep 19, 1996
Continuation In Part 08906464 · Aug 5, 1997
Continuation In Part 08872900 · Jun 11, 1997
Continuation In Part 08804868 · Feb 24, 1997
Continuation In Part 08763536 · Dec 9, 1996
Continuation In Part 08756720 · Nov 26, 1996
Continuation 08746007 · Nov 5, 1996
Continuation 08741601 · Nov 1, 1996
Continuation In Part 08729619 · Oct 11, 1996
Continuation In Part 08715712 · Sep 19, 1996
Continuation In Part 08636854 · Apr 23, 1996
Continuation In Part 08559533
Continuation In Part 08823354 · Mar 24, 1997
Continuation In Part 08804869 · Feb 24, 1997
Continuation In Part 08752223 · Nov 19, 1996
Continuation 08741601 · Nov 1, 1996
Continuation 08599533
Continuation In Part 10395017 · Mar 21, 2003
Continuation 10244695 · Sep 16, 2002
Continuation In Part 09915180 · Jul 25, 2001
Continuation 09483125 · Jan 14, 2000
Continuation 09356745 · Jul 19, 1999
Continuation 08992897 · Dec 18, 1997
Continuation 08823354 · Mar 24, 1997
Continuation In Part 08715712 · Sep 19, 1996
Continuation 08559533
Continuation In Part 08906464 · Aug 5, 1997
Continuation In Part 08872900 · Jun 11, 1997
Continuation In Part 08823354 · Mar 24, 1997
Continuation In Part 08804868 · Feb 24, 1997
Continuation In Part 08804869 · Feb 24, 1997
Continuation 08763536 · Dec 9, 1996
Continuation In Part 08756720 · Nov 26, 1996
Continuation In Part 08752223 · Nov 19, 1996
Continuation 08746007 · Nov 5, 1996
Continuation In Part 08741601 · Nov 1, 1996
Continuation In Part 08729619 · Oct 11, 1996
Continuation In Part 08715712 · Sep 19, 1996
Continuation 08636854 · Apr 23, 1996
Continuation In Part 08559533
Continuation 08559533
Provisional Application 60488645 · Jul 18, 2003
Provisional Application 60505640 · Sep 24, 2003
Provisional Application 60482179 · Jun 24, 2003
Provisional Application 60006038 · Oct 24, 1995
Provisional Application 60370867 · Apr 8, 2002
Provisional Application 60372951 · Apr 16, 2002
Provisional Application 60373218 · Apr 17, 2002
Provisional Application 60374861 · Apr 23, 2002
Provisional Application 60420795 · Oct 23, 2002
Provisional Application 60421197 · Oct 25, 2002
Provisional Application 60421756 · Oct 28, 2002
Provisional Application 60422416 · Oct 30, 2002
Provisional Application 60427504 · Nov 19, 2002
Provisional Application 60443407 · Jan 29, 2003
Provisional Application 60446149 · Feb 10, 2003
Provisional Application 60033415 · Dec 18, 1996
Provisional Application 60004796 · Oct 2, 1995
Provisional Application 60006143 · Nov 2, 1995
Provisional Application 60025128 · Aug 29, 1996
Provisional Application 60035119 · Feb 3, 1997
Provisional Application 60024786 · Sep 10, 1996
Provisional Application 60277244 · Mar 20, 2001
Provisional Application 60300621 · Jun 25, 2001
Provisional Application 60344245 · Dec 27, 2001
Related Publication 20050044376A1 · Feb 24, 2005