IP Library Granted Patent US 7,600,129
Granted Patent B2
US 7,600,129 · App. 10/893,150 · Granted Oct 6, 2009

Controlling access using additional data

Assignee: CoreStreet, Ltd.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,600,129
App. No.
10/893,150
Granted
Oct 6, 2009
Kind
B2
Abstract

Determining access includes determining if particular credentials/proofs indicate that access is allowed, determining if there is additional data associated with the credentials/proofs, wherein the additional data is separate from the credentials/proofs, and, if the particular credentials/proofs indicate that access is allowed and if there is additional data associated with the particular credentials/proofs, then deciding whether to deny access according to information provided by the additional data. The credentials/proofs may be in one part or in separate parts. There may be a first administration entity that generates the credentials and other administration entities that generate proofs. The first administration entity may also generate proofs or may not generate proofs. The credentials may correspond to a digital certificate that includes a final value that is a result of applying a one way function to a first one of the proofs.

Claims (55)

1. A method of determining access, comprising:

using at least one processor to determine whether credentials/proofs indicate that access is allowed, wherein the credentials/proofs include credentials and proofs;

using at least one processor to determine whether additional data associated with the credentials/proofs has been received, wherein the additional data is separate from the credentials/proofs; and

using at least one processor to determine whether to deny access according to the credentials/proofs and the additional data that is received, wherein access is denied if the credentials/proofs do not indicate that access is allowed, and wherein access is denied if information provided by the additional data directly indicates revocation of access rights, wherein the information provided by the additional data is obtained by performing a one-way function on the additional data, and wherein the information is locally verifiable at a point of access.

2. A method, according to claim 1 , wherein the credentials/proofs are in one part.

3. A method, according to claim 1 , wherein the credentials/proofs are in separate parts.

4. A method, according to claim 3 , wherein there is a first administration entity that generates the credentials and other administration entities that generate proofs.

5. A method, according to claim 4 , wherein the first administration entity also generates proofs.

6. A method, according to claim 4 , wherein the first administration entity does not generate proofs.

7. A method, according to claim 1 , wherein the credentials correspond to a digital certificate that includes a final value that is a result of applying a one way function to a first one of the proofs.

8. A method, according to claim 7 , wherein each of the proofs is a result of applying a one way function to a future one of the proofs.

9. A method, according to claim 7 , wherein the digital certificate includes an identifier for the electronic device.

10. A method, according to claim 1 , wherein the credentials include a final value that is a result of applying a one way function to a first one of the proofs.

11. A method, according to claim 10 , wherein each of the proofs is a result of applying a one way function to a future one of the proofs.

12. A method, according to claim 1 , wherein the credentials include an identifier for a user requesting access.

13. A method, according to claim 1 , wherein the credentials/proofs include a digital signature.

14. A method, according to claim 1 , wherein access is access to an area enclosed by walls and a door.

15. A method, according to claim 14 , further comprising:

providing a door lock, wherein the door lock is actuated according to whether access is being denied.

16. A method, according to claim 1 , further comprising:

providing a reader that receives credentials/proofs.

17. A method, according to claim 16 , wherein the credentials/proofs are provided on a smart card presented by a user.

18. A method, according to claim 1 , wherein the credentials/proofs include a password entered by a user.

19. A method, according to claim 1 , wherein the credentials/proofs include user biometric information.

20. A method, according to claim 1 , wherein the credentials/proofs include a handwritten signature.

21. A method, according to claim 1 , wherein the credentials/proofs include a secret value provided on a card held by a user.

22. A method, according to claim 1 , wherein the credentials/proofs expire at a predetermined time.

23. A method, according to claim 1 , wherein the additional data is digitally signed.

24. A method, according to claim 1 , wherein the additional data is a message that is bound to the credentials/proofs.

25. A method, according to claim 24 , wherein the message identifies the particular credentials/proofs and includes an indication of whether the particular credentials/proofs have been revoked.

26. A method, according to claim 25 , wherein the indication is the empty string.

27. A method, according to claim 1 , wherein the additional data includes a date.

28. A method, according to claim 1 , wherein the additional data is a message containing information about the particular credentials/proofs and containing information about one or more other credentials/proofs.

29. A method, according to claim 1 , further comprising:

storing the additional data.

30. A method, according to claim 29 , wherein the additional data includes an expiration time indicating how long the additional data is to be saved.

31. A method, according to claim 30 , wherein the expiration time corresponds to an expiration of the particular credentials/proofs.

32. A method, according to claim 1 , further comprising:

storing the additional data for a predetermined amount of time.

33. A method, according to claim 32 , wherein credentials/proofs all expire after the predetermined amount of time.

34. A method, according to claim 1 , wherein the additional data is provided using a smart card.

35. A method, according to claim 34 , wherein the smart card is presented by a user attempting to gain access to an area.

36. A method, according to claim 35 , wherein access to the area is restricted using walls and at least one door.

37. A method, according to claim 35 , wherein the additional data is for a user different from the user attempting to gain access.

38. A method, according to claim 1 , further comprising:

providing a communication link; and

transmitting the additional data using the communication link.

39. A method, according to claim 38 , wherein the communication link is provided the additional data by a smart card.

40. A method, according to claim 39 , wherein the smart card requires periodic communication with the communication link in order to remain operative.

41. A method, according to claim 39 , wherein the smart card is provided with the additional data by another smart card.

42. A method, according to claim 39 , wherein the additional data is selectively provided to a subset of smart cards.

43. A method, according to claim 39 , further comprising:

providing a priority level to the additional data.

44. A method, according to claim 43 , wherein the additional data is selectively provided to a subset of smart cards according to the priority level provided to the additional data.

45. A method, according to claim 39 , wherein the additional data is randomly provided to a subset of smart cards.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 11, 2014
From: CORESTREET LTD
To: ASSA ABLOY AB
Reel/Frame 032404/0759 →
RELEASE OF SECURITY INTEREST Recorded Oct 8, 2013
From: ASSA ABLOY AB
To: CORESTREET, LTD.
Reel/Frame 031361/0975 →
ASSIGNMENT OF SECURITY AGREEMENT Recorded Jan 26, 2007
From: ASSA ABLOY IDENTIFICATION TECHNOLOGY GROUP AB
To: ASSA ABLOY AB
Reel/Frame 018806/0814 →
SECURITY AGREEMENT Recorded Dec 16, 2005
From: CORESTREET, LTD.
To: ASSA ABLOY IDENTIFICATION TECHNOLOGY GROUP AB
Reel/Frame 016902/0444 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 21, 2004
From: LIBIN, PHIL; MICALI, SILVIO; ENGBERG, DAVID; SINELNIKOV, ALEX
To: CORESTREET, LTD.
Reel/Frame 015904/0536 →
Continuity (73)
Continuation In Part 1087627500 · Jun 24, 2004
Continuation In Part 0991518000 · Jul 25, 2001
Continuation 0948312500 · Jan 14, 2000
Continuation 0935674500 · Jul 19, 1999
Continuation 0882335400 · Mar 24, 1997
Continuation 0855953300 · Nov 16, 1995
Continuation 1089315000
Continuation In Part 1040963800 · Apr 8, 2003
Continuation In Part 1089315000
Continuation In Part 1010354100 · Mar 20, 2002
Continuation In Part 0991518000 · Jul 25, 2001
Continuation In Part 0899289700 · Dec 18, 1997
Continuation In Part 0871571200 · Sep 19, 1996
Continuation In Part 0872961900 · Oct 11, 1996
Continuation In Part 0880486800 · Feb 24, 1997
Continuation 0874160100 · Nov 1, 1996
Continuation In Part 0887290000 · Jun 11, 1997
Continuation 0874600700 · Nov 5, 1996
Continuation In Part 0890646400 · Aug 5, 1997
Continuation In Part 0876353600 · Dec 9, 1996
Continuation In Part 0863685400 · Apr 23, 1996
Continuation In Part 0875672000 · Nov 26, 1996
Continuation In Part 0871571200 · Sep 19, 1996
Continuation In Part 0855953300 · Nov 16, 1995
Continuation In Part 0875222300 · Nov 19, 1996
Continuation In Part 0880486900 · Feb 24, 1997
Continuation 0874160100 · Nov 1, 1996
Continuation In Part 0882335400 · Mar 24, 1997
Continuation 0855953300 · Nov 16, 1995
Continuation In Part 0991518000 · Jul 25, 2001
Continuation In Part 1039501700 · Mar 21, 2003
Continuation 1024469500 · Sep 16, 2002
Continuation 0899289700 · Dec 18, 1997
Continuation In Part 0871571200 · Sep 19, 1996
Continuation In Part 0872961900 · Oct 11, 1996
Continuation In Part 0880486800 · Feb 24, 1997
Continuation 0874160100 · Nov 1, 1996
Continuation In Part 0887290000 · Jun 11, 1997
Continuation 0874600700 · Nov 5, 1996
Continuation In Part 0890646400 · Aug 5, 1997
Continuation 0876353600 · Dec 9, 1996
Continuation 0835685400 · Apr 23, 1996
Continuation In Part 0875672000 · Nov 26, 1996
Continuation In Part 0855953300 · Nov 16, 1995
Continuation In Part 0875222300 · Nov 16, 1996
Provisional Application 6048864500 · Jul 18, 2003
Provisional Application 6050564000 · Sep 24, 2003
Provisional Application 6048217900 · Jun 24, 2003
Provisional Application 6000603800 · Oct 24, 1995
Provisional Application 6037086700 · Apr 8, 2002
Provisional Application 6037295100 · Apr 16, 2002
Provisional Application 6037321800 · Apr 17, 2002
Provisional Application 6037486100 · Apr 23, 2002
Provisional Application 6042079500 · Oct 23, 2002
Provisional Application 6042119700 · Oct 25, 2002
Provisional Application 6042175600 · Oct 28, 2002
Provisional Application 6042241600 · Oct 30, 2002
Provisional Application 6042750400 · Nov 19, 2002
Provisional Application 6044340700 · Jan 29, 2003
Provisional Application 6044614900 · Feb 10, 2003
Provisional Application 6000603800 · Oct 24, 1995
Provisional Application 6003341500 · Dec 18, 1996
Provisional Application 6000479600 · Oct 2, 1995
Provisional Application 6000614300 · Nov 2, 1995
Provisional Application 6002512800 · Aug 29, 1996
Provisional Application 6003511900 · Feb 3, 1997
Provisional Application 6002478600 · Sep 10, 1996
Provisional Application 6002512800 · Aug 29, 1996
Provisional Application 6027724400 · Mar 20, 2001
Provisional Application 6030062100 · Jun 25, 2001
Provisional Application 6034424500 · Dec 27, 2001
Provisional Application 6003511900 · Feb 3, 1997
Related Publication 20050044386A1 · Feb 24, 2005