US2023142058A1PendingUtilityA1

Converged logical and physical security

Assignee: VETRIX LLCPriority: Apr 25, 2006Filed: Dec 21, 2022Published: May 11, 2023
Est. expiryApr 25, 2026(expired)· nominal 20-yr term from priority
G06F 16/29G07C 9/28G07C 9/257G07C 9/26G06F 21/32G06F 21/35G06F 21/34G06F 21/71G06F 21/602H04L 63/20G07C 9/22G06F 21/6218G06K 19/06028
71
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A security management system that includes a hierarchical security platform, converged IT and physical security management, unified credentialing, credential issuance and incident(s) management. An exemplary aspect of the invention also relates to physical and logical security management and information technology/network security management, with a credential issuance and integrity checking system as well as associated readers and printers of the credential. Still further aspects of the invention relate to obtaining, assembling and analyzing one or more of data, video information, image information, biometric information, sensor information, terrorist information, profile information, and/or other types of information to provide a comprehensive platform for all aspects of security management. A toolkit is also provided that allows complete management, integration, scalability, interoperability and centralized control of all aspects of security including personnel credentialing, personnel management, personnel tracking, task management, security system integration, security information exchange and scalability.

Claims

exact text as granted — not AI-modified
1 . A converged physical and logical security management server, comprising:
 at least one microprocessor, input device and output device and capable of storing data in and retrieving data from a data store and two-way communication with a plurality of security management devices and with one or more access controllers and configured to store a unique identifier having associated therewith authentication and authorization information that includes at least two configuration options to control at least one access decision for a physical area and for a logical area and a directory service associated with the data store and configured to make a physical area access decision using one of the at least two configuration options and a logical area access decision using a second authentication and authorization information.   
     
     
         2 . The server of  claim 1 , further comprising a credential issuance system that can associate additional information with the unique identifier. 
     
     
         3 . The server of  claim 2 , wherein the additional information pertains to one or more of personnel and equipment. 
     
     
         4 . The server of  claim 3 , wherein additional information about the personnel comprises one or more of fingerprint information, name, credentials, certifications, biometric information, access information, a picture, background information and medical information. 
     
     
         5 . The server of  claim 1 , wherein the unique identifier is associated with at least one of a contact or contactless chip, a bar code, printed data, a proximity chip, a magnetic stripe, a token and computer readable information. 
     
     
         6 . The server of  claim 1 , wherein the configuration options include one or more of a card ID, card certificate, username and AccessID. 
     
     
         7 . The server of  claim 1 , wherein one or more of personnel, tasks, equipment, and access to a secure area are controlled. 
     
     
         8 . The server of  claim 1 , wherein one or more of a fingerprint capture system, a camera, a PIN capture system, a signature capture system, a document scanner, a card reader/writer, a card printer and a report printer is capable on communicating therewith through an input device. 
     
     
         9 . The server of  claim 1 , wherein the server is capable of being used in a system where the unique identifier is stored on a smart card, smart chip, embedded chip, mobile device or implanted chip. 
     
     
         10 . The server of  claim 1 , wherein the information associated with the unique identifier is verified through a government entity. 
     
     
         11 . The server of  claim 1 , further comprising a rules toolkit, the toolkit allowing a user to construct one or more rules. 
     
     
         12 . The server of  claim 1 , further comprising an interface configured to communicate with the one or more of an existing enterprise physical security system and an existing enterprise computer system. 
     
     
         13 . The server of  claim 1 , further being configured for two-way communication with one or more of a satellite, VOIP system, switch-based network communication system and packet-based network system. 
     
     
         14 . The server of  claim 1 , further being configured to be booted into a plurality of modes. 
     
     
         15 . The server of  claim 1 , wherein the server provides security for one or more of chemical, drinking water and wastewater treatment systems, energy facilities, dams, commercial nuclear reactors, water sectors, process manufacturing, emergency services, public health and healthcare, continuity of government, government facilities, defense facilities, defense industrial base, information technology, telecommunications, converged facilities, national monuments and icons, postal and shipping, banking and finance, commercial facilities, materials and waste facilities, transportation systems, port security, aviation security, cargo, cruise ships, trains, mass transit, Intermodal, food and agriculture facilities, military facilities, first responders, police, fire control access to a machine and OSHA Compliance. 
     
     
         16 . The server of  claim 1 , wherein the data store is one of located within and without the server. 
     
     
         17 . The server of  claim 1 , wherein the physical area is one of a room, a hallway, a closet, a paddock, a building, a vehicle, and a secure space. 
     
     
         18 . The server of  claim 1 , wherein the at least two configuration options relate to networks, systems and/or physical access control to include one or more of hours of access, security zones, and accessible domains. 
     
     
         19 . The server of  claim 1 , wherein the one or more access controllers is one of located within and without the server. 
     
     
         20 . The server of  claim 1 , wherein the one or more access controllers is at least one of connected to the at least one microprocessor by an ethernet connector. 
     
     
         21 . The server of  claim 1 , wherein the one or more access controllers communicate with remote with the one or more security management devices as directed by the one or more microprocessors. 
     
     
         22 . The server of  claim 21 , wherein the communication occurs in a protocol native to the one or more security management devices. 
     
     
         23 . The server of  claim 1 , wherein the server is one of a traditional server and an appliance. 
     
     
         24 . The server of  claim 1  is at least one of logically connected, directly connected, indirectly connected via one or more intermediary components, and wirelessly connected to one or more access controllers. 
     
     
         25 . The server of  claim 1 , wherein the data store is coded in the SQL language. 
     
     
         26 . The server of  claim 1 , wherein the directory service is active directory. 
     
     
         27 . The server of  claim 1 , wherein the security management devices include at least one of an electronic lock, a firewall, a camera, or a password protected, a laptop, a workstation, a tablet, and a smart phone. 
     
     
         28 . A converged physical and logical security management system comprising:
 a security management server including at least one microprocessor and at least one input device and at least two output devices;   the security management server capable of storing data in a data store and retrieving data from said data store;   the security management server capable of two-way communication with one or more security management devices;   the security management server configured to store a unique identifier having associated therewith authentication and authorization information that controls access decisions for a physical area and logical access to one or more of a computer, computer network or network resource, the authentication and authorization information including at least two configuration options;   the security management server further configured to determine at least one access decision for the physical area and at least one logical access decision for the one or more of the computer, the computer network and the network resource;   the security management server connected to one or more access controllers that are capable of communicating in a standard protocol and capable of communicating with the one or more access controllers in the standard protocol;   wherein the security management server also includes a directory service associated with said data store and configurable to make the at least one access decision for an access request to the physical area, utilizing a first authentication and authorization information to select one of the at least two configuration options within said data store of the security management server for a physical access decision, and for logical access, a second, separate access decision, utilizing a second authentication and authorization information of the at least two configuration options within the directory service of the security management server for a logical access decision;   wherein the security management server is configured to perform artificial intelligence (AI) processes that attempt to emulate the decision making abilities of a human expert using knowledge (facts) and inference procedures (rules), said AI processes comprising one or more of neural networking, data clumping, and associative discovery; and   wherein and the security management server is further configured to perform a trending/prediction reporting process in cooperation with said AI processes to generate trending and/or prediction reporting.

Join the waitlist — get patent alerts

Track US2023142058A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.