Nova Patents
EP1549020B1

Entry control system

Abstract

This record has no abstract on file.

EP1549020B1, drawing sheet 1
Sheet 1 of 14

Term

Term ended

Expired 22 December 2024, 1.8 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

18 claims: 11 independent, 7 dependent

  1. 1
    A method for physically controlling access to a protected location comprising the steps of:- establishing a secure communications connection over a network between a security controller (110) and at least an authentication server (105). - operatively coupling a security token (75) to said security controller, - sending a critical security parameter from said security token to said security controller for authentication, - sending said critical security parameter to at least said authentication server via said secure communications connection, - performing an authentication transaction by said authentication server for said critical security parameter, - sending a result of said authentication transaction from said authentication server to said security controller via said secure communications connection, and - energizing an electromechanical circuit (130) controlled by said security controller if said result is affirmative of said authentication transaction being successful, characterized in that energizing said electromechanical circuit is limited to a pre-established duration specific to said security token.
  2. 4
    A method according to any of claims 1 to 3, wherein said electromechanical circuit is associated with a physical access gateway and wherein energizing said electromechanical circuit opens said physical access gateway.
  3. 5
    A method according to any of claims 1 to 4, wherein at least a portion of said secure communications connection is established over a wireless telecommunications link.
  4. 6
    A method according to any of claims 1 to 5, wherein said secure communications connection incorporates a security protocol including SSL, IPsec, PCT, TLS or RADIUS.
  5. 8
    A method according to any of claims 1 to 7, wherein said security controller is further in secure communications over said network with a life cycle management server adapted to perform life cycle management functions related to applications, critical security parameters or user data installed in either said security token or said secure access module.
  6. 9
    A method according to claims 2 and 8, wherein said one or more life cycle management transactions comprises distributing, exchanging, deleting, adding or modifying one or more critical security parameters, applications or user data installed in said secure access module.
  7. 10
    A system for physically controlling access to a protected location comprising:- a security token (75) operatively coupled to a security controller (110) and including means for sending a critical security parameter to said security controller for authentication, - a secure access module operatively coupled to said security controller and including means for securely maintaining a shared secret established by an authentication server (105) and incorporating said shared secret into a secure communications connection established with at least an authentication server;- an electromechanical control means (130) operatively coupled to said security controller including means for opening a physical access gateway when energized, said security controller including means for: - establishing said secure communications connection with at least said authentication server, sending said critical security parameter to said authentication server via said secure communications connection and energizing said electromechanical control means in response to an affirmative authentication result received from said authentication server, said authentication server including means for: - establishing said secure communications with said security controller, performing an authentication transaction in response to receiving said critical security parameter from said security controller, and - supplying said affirmative authentication result to said security controller via said secure communications connection following a successful authentication of said critical security parameter, characterized in that the system further comprises means for limiting energizing said electromechanical circuit to a pre-established duration specific to said security token.
  8. 13
    A system according to any of claims 10 to 12, wherein said secure access module further includes means for locally performing said authentication transaction.
  9. 15
    A system according claim 15, wherein said authentication server further includes means for receiving said at least an access list of locally authenticated critical security parameters and updating a master access associated with said authentication server.
  10. 16
    A system according to any of claims 10 to 15, further comprising a life cycle management server including means for:- establishing a secure communications connection with either said secure access module or said security controller, and - performing one or more life cycle management transactions with said secure access module.
  11. 18
    A security controller (110) for physically controlling access to a protected location comprising:- a processor, - a memory coupled to said processor, - a security token interface coupled to said processor, - a network transceiver coupled to said processor, - a secure access module coupled to said processor, - an electromagnetical control circuit coupled to said processor, and - at least one application installed in at least a portion of said memory having logical instructions executable by said processor to: - establish a secure communications connection over a network with at least one authentication server (105) via said network transceiver, - perform an authentication transaction in conjunction with said authentication server for a critical security parameter received via said security token interface, - receive and maintain a shared secret in said secure access module, - incorporate said shared secret into said secure communications connection, and - energize said electromechanical control circuit upon receipt of an affirmative authentication result associated with said authentication transaction, characterized in that it further comprises means for limiting energizing said electromechanical circuit to a pre-established duration specific to said security token.