US2018324166A1PendingUtilityA1
Presence-based credential updating
Est. expiryJul 27, 2032(~6 yrs left)· nominal 20-yr term from priority
H04W 12/08H04L 63/0492H04W 12/04H04L 63/062H04L 63/107H04L 63/08H04W 12/64H04W 12/63H04W 12/0431
52
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
Methods, systems, and devices for updating access permissions of users in an access control system are described. The access permissions are capable of being updated based on rules and thresholds that include as at least one variable presence or contextual information associated with a user. The presence or contextual information associated with a user may be analyzed to trigger a credential update process for that user or other users within the access control system.
Claims
exact text as granted — not AI-modified1 . A method, comprising:
receiving contextual information regarding a first user; based on the received contextual information, determining a credential update to perform in connection with at least one device associated with the first user; generating a first message that contains at least one instruction to update at least one credential; and transmitting the first message to the at least one device associated with the first user.
2 . The method of claim 1 , wherein the at least one device comprises a user device that is capable of exchanging messages via a communication network.
3 . The method of claim 2 , wherein the first message is transmitted to the at least one device via the communication network in at least one of an SMS message, an email, and an HTTP request.
4 . The method of claim 2 , wherein the user device comprises an NFC-enabled smart phone.
5 . The method of claim 4 , wherein the user device further comprises a secure element that stores the at least one credential as sensitive data.
6 . The method of claim 5 , wherein the secure element corresponds to at least one of a SIM card, microSD card, removeable IC, and embedded IC.
7 . The method of claim 1 , wherein the at least one device comprises a local host that is protecting at least one asset.
8 . The method of claim 1 , wherein the at least one instruction to update the at least one credential comprises an instruction to at least one of modify, add, remove, activate, and deactivate a logical credential on the at least one device.
9 . The method of claim 1 , wherein the contextual information regarding the first user comprises presence information.
10 . The method of claim 1 , wherein the contextual information regarding the first user comprises location information.
11 . The method of claim 1 , wherein the contextual information regarding the first user comprises information regarding the first user's usage of the at least one device.
12 . The method of claim 1 , further comprising:
based on the received contextual information, determining a credential update to perform in connection with at least one device associated with a second user, the second user being different than the first user; generating a second message that contains at least one instruction to update at least one credential for the second user; and transmitting the second message to the at least one device associated with the second user.
13 . The method of claim 1 , further comprising:
generating a second message that contains the at least one instruction to update the at least one credential; and transmitting the second message to a local host within an access control system, the local host protecting at least one asset and conditioning availability of the at least one access to users that present a physical credential having a valid logical credential stored thereon.
14 . A computer-readable medium comprising processor-executable instructions that, when executed by a processor, perform the method of claim 1 .
15 . An access control system, comprising:
a credential control authority configured to receive at least one of presence information and contextual information associated with a first user of the access control system and then determine whether a credential update process is to be performed for at least one device associated with the first user, the credential control authority further configured to invoke the credential update process upon determining that the first user has crossed at least one of a physical and logical threshold based on the received at least one of presence information and contextual information.
16 . The system of claim 15 , wherein the at least one of a physical and logical threshold corresponds to a predetermined distance away from a predetermined location.
17 . The system of claim 15 , wherein the at least one of a physical and logical threshold corresponds to a predetermined action of the first user detected at the at least one device associated with the first user.
18 . The system of claim 15 , further comprising one or more local hosts configured to control access to one or more assets.
19 . The system of claim 18 , wherein the one or more assets include at least one of a physical and logical asset.
20 . The system of claim 18 , wherein the one or more local hosts correspond to an RFID reader, wherein the at least one device associated with the first user comprises an NFC-enabled communication device, and wherein the credential update process includes transmitting a first credential update message to the one or more local hosts as well as transmitting a second credential update message to the at least one device associated with the first user.
21 . A credential control authority configured to communicate with a contextual information source and based on information received from the contextual information source, determine whether a credential update process is to be performed for at least one device associated with a first user, the credential control authority further configured to invoke the credential update process upon determining that the first user has crossed at least one of a physical and logical threshold based on the information received from the contextual information source.
22 . The credential control authority of claim 21 , wherein the contextual information source is executed on a server that is separate from a server on which the credential control authority is operated.
23 . The credential control authority of claim 22 , wherein the contextual information source is connected with the credential control authority via a communication network.
24 . The credential control authority of claim 21 , wherein the information received from the contextual information source includes at least one of presence information, communication context information, location context information, group context information, and calendar information.Join the waitlist — get patent alerts
Track US2018324166A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.