US2005138380A1PendingUtilityA1

Entry control system

Priority: Dec 22, 2003Filed: Dec 22, 2003Published: Jun 23, 2005
Est. expiryDec 22, 2023(expired)· nominal 20-yr term from priority
G07C 9/27H04L 63/10H04L 63/08
52
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

An integrated security system which seamlessly assimilates with current generation logical security systems. The integrated security system incorporates a security controller having standard network interface capabilities including EEE 802.x and takes advantage of the convenience and security offered by smart cards and related devices for both physical and logical security purposes. The invention is based on standard remote authentication dial-in service (RADIUS) protocols or TCP/IP using SSL, TLS, PCT or IPsec and stores a shared secret required by the secure communication protocols in a secure access module coupled to the security controller. The security controller is intended to be a networked client or embedded intelligent device controlled remotely by to an authentication server. In another embodiment of the invention one or more life cycle management transactions are performed with the secure access module. These transactions allow for the updating, replacement, deletion and creation of critical security parameters, cryptographic keys, user data and applications used by the secure access module and/or security token. In another embodiment of the invention a security access module associated with the security controller locally performs local authentication transactions which are recorded in a local access list used to update a master access list maintained by the authentication server.

Claims

exact text as granted — not AI-modified
1 . A method for physically controlling access to a protected location comprising the steps of; 
 a. establishing a secure communications connection over a network between a security controller and at least an authentication server,    b. operatively coupling a security token to said security controller,    c. sending a critical security parameter from said security token to said security controller for authentication,    c. sending said critical security parameter to at least said authentication server via said secure communications connection,    d. performing an authentication transaction by said authentication server for said critical security parameter, and    e. sending a result of said authentication transaction from said authentication server to said security controller via said secure communications connection.    
   
   
       2 . The method according to  claim 1  wherein said secure communications connection includes a shared secret established between said security controller which is securely maintained by a secure access module operatively coupled to said security controller.  
   
   
       3 . The method according to  claim 1  further including the step of energizing an electromechanical circuit controlled by said security controller if said result is affirmative of said authentication transaction being successful.  
   
   
       4 . The method according to  claim 1  wherein said security controller is one of a plurality of security controllers, wherein said plurality of security controllers are networked clients of at least said authentication server.  
   
   
       5 . The method according to  claim 3  wherein said electromechanical circuit is associated with a physical access gateway.  
   
   
       6 . The method according to  claim 3  wherein energizing said electromechanical circuit is limited to a pre-established duration specific to said security token.  
   
   
       7 . The method according to  claim 6  wherein energizing said electromechanical circuit opens said physical access gateway.  
   
   
       8 . The method according to  claim 1  wherein at least a portion of said secure communications connection is established over a wireless telecommunications link.  
   
   
       9 . The method according to  claim 1  wherein said secure communications connection incorporates a security protocol including SSL, IPsec, PCT, TLS or RADIUS.  
   
   
       10 . The method according to  claim 2  wherein said security controller is further in secure communications over said network with a life cycle management server.  
   
   
       11 . The method according to  claim 10  wherein said life cycle management server is adapted to perform life cycle management functions related to applications, critical security parameters or user data installed in either said security token or said secure access module.  
   
   
       12 . A method for physically controlling access to a protected location comprising the steps of: 
 a. establishing a secure communications connection over a network between at least an authentication server and a secure access module associated with a security controller, wherein said secure communications connection incorporates a shared secret which is maintained by said authentication server and said secure access module,    b. operatively coupling a security token to said secure access module via an interface coupled to said security controller,    c. sending a critical security parameter from said security token to said secure access module,    d. sending said critical security parameter to said authentication server via said secure communications connection, a secure communications    e. performing an authentication transaction by said authentication server via a process which incorporates said critical security parameter,    f. sending a result of said authentication transaction from said authentication server to said security controller via said secure communications connection, and    g. energizing an electromechanical circuit controlled by said security controller if said result is affirmative of said authentication transaction being successful.    
   
   
       13 . The method according to  claim 12  wherein energizing said electromechanical circuit opens a physical access gateway.  
   
   
       14 . The method according to  claim 12  wherein said secure communications connection incorporates a security protocol including SSL, IPsec, PCT, TLS or RADIUS.  
   
   
       15 . The method according to  claim 12  wherein said secure access module is further in secure communications over said network with a life cycle management server.  
   
   
       16 . The method according to  claim 15  wherein said life cycle management server is adapted to perform life cycle management functions related to applications, critical security parameters or user data installed in either said security token or said secure access module.  
   
   
       17 . A method for performing one or more life cycle management transactions with a secure access module coupled to a security controller and a life cycle management server comprising the steps of: 
 a. establishing a secure communications connection between a secure access module and at least a life cycle management server, and    b. performing one or more life cycle management transactions with said secure access module in conjunction with said at least a life cycle management server.    
   
   
       18 . The method according to  claim 17  wherein said one or more life cycle management transactions comprises distributing, exchanging, deleting, adding or modifying one or more critical security parameters, applications or user data installed in said secure access module.  
   
   
       19 . A method for physically controlling access to a protected location comprising the steps of: 
 a. sending one or more critical security parameters from one or more security tokens to a secure access module operatively coupled to a security controller for authentication,    b. performing one or more authentication transactions by said secure access module using said one or more critical security parameters,    c. temporarily maintaining a local access list of at least the said one or more critical security parameters which have been authenticated by said secure access module,    d. sending said local access list to an authentication server, and    e. updating a master access list maintained by said authentication server.    
   
   
       20 . The method according to  claim 19  wherein said local access list is sent to said authentication server via a secure communications channel.  
   
   
       21 . The method according to  claim 19  wherein said local access list is sent over an IEEE 802.x standard network arrangement.  
   
   
       22 . A system for physically controlling access to a protected location comprising: 
 a security token operatively coupled to a security controller and including means for sending a critical security parameter to said security controller for authentication;    a secure access module operatively coupled to said security controller and including means for securely maintaining a shared secret established by an authentication server and incorporating said shared secret into a secure communications connection established with at least an authentication server;    an electromechanical control means operatively coupled to said security controller including means for opening a physical access gateway when energized;    said security controller including means for; 
 establishing said secure communications connection with at least said authentication server, sending said critical security parameter to said authentication server via said secure communications connection and energizing said electromechanical control means in response to an affirmative authentication result received from said authentication server; and,  
   said authentication server including means for; 
 establishing said secure communications with said security controller, performing an authentication transaction in response to receiving said critical security parameter from said security controller, and supplying said affirmative authentication result to said security controller via said secure communications connection following a successful authentication of said critical security parameter.  
   
   
   
       23 . The system according to  claim 22  wherein said at least a portion of said secure communications connection is established over a wireless telecommunications link.  
   
   
       24 . The system according to  claim 22  wherein said secure communications connection incorporates a security protocol including SSL, IPsec, PCT, TLS or RADIUS.  
   
   
       25 . The system according to  claim 22  wherein said secure access module further includes means for locally performing said authentication transaction.  
   
   
       26 . The system according to  claim 25  wherein either said security controller or said secure access module further includes means for maintaining at least an access list of locally authenticated critical security parameters.  
   
   
       27 . The system according  claim 26  wherein said authentication server further includes means for receiving said at least an access list of locally authenticated critical security parameters and updating a master access associated with said authentication server.  
   
   
       28 . The system according to  claim 22  further comprising a life cycle management server including means for; 
 a. establishing a secure communications connection between either said secure access module or said security, and    b. performing one or more life cycle management transactions with said secure access module in conjunction with said at least a life cycle management server.    
   
   
       29 . The system according to  claim 28  wherein said one or more life cycle management transactions comprises distributing, exchanging, deleting, adding or modifying one or more critical security parameters, applications or user data installed in said secure access module.  
   
   
       30 . A security apparatus for physically controlling access to a protected location comprising: 
 a security controller including; 
 a processor,  
 a memory coupled to said processor,  
 a security token interface coupled to said processor,  
 a network transceiver coupled to said processor,  
 a secure access module coupled to said processor,  
 an electromagnetic control circuit coupled to said processor, and  
 at least one application installed in at least a portion of said memory having logical instructions executable by said processor to; 
 establish a secure communications connection over a network with at least an authentication server over a network via said network transceiver,  
 perform an authentication transaction in conjunction with said authentication server for a critical security parameter received via said security token interface,  
 receive and maintain a shared secret in said secure access module,  
 incorporate said shared secret into said secure communications connection, and  
 energize said electromechanical control circuit upon receipt of an affirmative authentication result associated with said authentication transaction.  
 
   
   
   
       31 . The apparatus according to  claim 30  wherein said secure communications connection incorporates a security protocol including SSL, IPsec, PCT, TLS or RADIUS.  
   
   
       32 . The apparatus according to  claim 30  wherein energizing said electromechanical control circuit opens a physical access gateway.  
   
   
       33 . The apparatus according to  claim 30  wherein said secure access module includes means for performing one or more life cycle management transactions in conjunction with either said authentication server or a life cycle management server.  
   
   
       34 . The system according to  claim 30  wherein said one or more life cycle management transactions comprises distributing, exchanging, deleting, adding or modifying one or more critical security parameters, applications or user data installed in said secure access module.  
   
   
       35 . A system for performing one or more life cycle management transactions with 
 a secure access module coupled to a security controller and a life cycle management server comprising:    a secure access module operatively coupled to a security controller and including means for securely performing life cycle management functions in conjunction with a life cycle management server;    said security controller including means for exchanging communications between said secure access module and said life cycle management server; and,    said life cycle server including means for securely performing one or more life cycle management transactions in conjunction with said secure access module, wherein said one or more life cycle management transactions comprises distributing, exchanging, deleting, adding or modifying one or more critical security parameters, applications or user data installed in said secure access module.    
   
   
       36 . The system according to  claim 35  wherein said security controller and said life cycle server are in processing communications over a wireless telecommunications link.

Join the waitlist — get patent alerts

Track US2005138380A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.