Forward one-time-use physical access verification apparatus, system, and method of operation
Abstract
A wireless apparatus controls physical access through a portal by forward verification of one-time-use codes submitted by a mobile application device. A system forward verifies a single physical access control code upon each successful physical access request. The apparatus sets a flag that triggers an action when a one-time-use code is received out of sequence. The controller receives a plurality of physical access requests from a plurality of mobile application devices. The controller determines for each mobile application device a sequence of access requests comprising at least a first access request and a second access request. Upon authenticating the first access request, the controller writes into storage a forward verification code specific to an immediately subsequent second access request from the same app device. Upon receiving a successor, the controller performs an authentication process by matching the stored forward verification code associated with the predecessor.
Claims
exact text as granted — not AI-modified1 . A mobile application device (app device) for physical access comprises:
a wireless transceiver; a processor and a system clock; a non-transitory store configured with authentication certificates; a physical access application; and a non-transitory store for at least two one-time verification codes.
2 . The apparatus of claim 1 further comprising:
a non-transitory store for a system authentication value (SAV), a credential, a user ID, and executable code for hashing and transacting requests;
a circuit to transform indicia into a physical access control request.
3 . The apparatus of claim 1 further comprising:
a circuit to synthesize a forward one-time verification code from a timestamp of its system clock.
4 . The apparatus of claim 1 further comprising:
a circuit to synthesize a forward one-time verification code upon a successful physical access control request.
5 . A system comprises:
a plurality of mobile application devices (app devices); a physical access controller (access controller) communicatively coupled to said devices; and a cloud security service server; wherein said access controller comprises:
a non-transitory store of sequential access codes associated with each user id and credentials verified by the cloud security service server;
a transceiver to receive and acknowledge physical access requests;
a circuit to operate a portal actuator; and
a non-transitory store of security policies.
6 . The system of claim 5 further comprising:
a circuit to verify a physical access request with a stored forward verification code.
7 . The system of claim 5 further comprising:
a circuit to perform a security policy on the condition the verification of a physical access request fails.
8 . The system of claim 5 further comprising:
a circuit to cause app devices and access controllers to advance a system authentication value.
9 . The system of claim 5 further comprising:
a circuit to extract and store a forward verification code from a last successful physical access request.
10 . The system of claim 5 further comprising:
a circuit to determine a forward verification code for a user upon last successful physical access request.
11 . A method for control of a physical access portal comprising the processes:
at a controller, receiving a plurality of physical access requests (access requests) from a plurality of mobile application devices; at the controller, determining for each mobile application device (app device) a sequence of access requests comprising at least a first access request and a second access request; at the controller, upon authenticating the first access request (predecessor), writing into non-transitory storage a one-time verification code specific to an immediately subsequent second access request (successor) from the same app device; and at the controller, upon receiving a successor, performing an authentication process by matching the stored one-time verification code associated with the predecessor.
12 . The method of claim 11 further comprising:
on the condition the authentication process passes,
writing a newer one-time verification code into non-transitory storage specific to yet another immediately subsequent successor.
13 . The method of claim 11 further comprising:
on the condition the authentication process fails,
setting a flag of questionable chain of control associated with the app device.
14 . The method of claim 12 wherein each newer one-time verification code is synthesized by the app device and transmitted in both a predecessor and successor request.
15 . The method of claim 12 wherein each newer one-time verification code is a transformation of a timestamp read from the system clock of the app device.
16 . The method of claim 12 wherein each newer one-time verification code is synthesized as transformation of the predecessor and transmitted only in the successor.
17 . The method of claim 12 wherein each newer one-time verification code is a transformation of the result of authentication of the predecessor request.
18 . The method of claim 13 wherein, a flag of questionable chain of control causes an access control policy to be performed at the portal actuator wherein, an access control policy includes at least one of an access denial to a request from a user, or a device; an iteration of system authentication value; a version update; reauthentication process at a mobile application device; and transmitting a notification to an access control system administrator.
19 . The method of claim 11 wherein the app device transmits a first forward verification code from the app device that is determined by a first approximate elapsed time from a first access request to a second access request measured at the app device and the portal controller compares the first forward verification code with a second forward verification code read from non-transitory storage that was previously received as a component of the most recently successful access request.
20 . The method of claim 11 wherein the app device transmits a first forward verification code from the app device that is determined by a first approximate elapsed time from a first access request to a second access request measured at the app device and the portal controller compares the first forward verification code with a second forward verification code that is determined by a second approximate elapsed time from the first access request to the second access request measured at the portal controller.Join the waitlist — get patent alerts
Track US2018183835A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.