EP2494440B1

Universal validation module for access control systems

Abstract

This record has no abstract on file.

EP2494440B1, drawing sheet 1
Sheet 1 of 6

Term

4.1 yearsleft in the term

Expires 22 October 2030.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

12 claims: 5 independent, 7 dependent

  1. 1
    An access control system (100, 100') comprising an access decision component (20) and a validation module (50), wherein the validation module (50) comprises:modular communication interfaces that provide coupling to the access control system (100, 100');at least one processor;and a computer readable storage medium storing executable code that is executable by the at least one processor, the computer readable storage medium including: executable code that receives cardholder data (402) in connection with an access request at an access point controlled by the access control system (100, 100');executable code that validates the cardholder data (406);executable code that extracts ID information (410) from the validated cardholder data;executable code that sends the extracted ID information (412) to the access decision component (20) of the access control system (100, 100'), and executable code that determines whether an attribute, that is not on the access control system (100, 100'), corresponding to a cardholder of the cardholder data is present on a database that is separate from the access control system (100, 100');and wherein the access decision component (20) comprises: at least one processor;and a computer readable storage medium storing executable code that is executable by the at least one processor, the computer readable storage medium including: executable code that determines whether access is granted for the cardholder, wherein, even if the cardholder would not be granted access through default behavior of the access control system (100, 100') based on local authority of the access control system (100, 100'), access is granted to the card holder if the attribute indicates an override of the default behavior.
  2. 5
    The access control system (100, 100') according to one of claims 1 - 4, wherein the executable code that validates the cardholder data includes executable code that authenticates the cardholder data according to an authentication mechanism.
  3. 7
    The access control system (100, 100') according to one of claims 1 - 6, wherein the executable code that validates the cardholder data performs certificate path discovery and validation to a trusted authority.
  4. 8
    The access control system (100, 100') according to one of claims 1 - 7, wherein the computer readable storage medium of the validation module (50) further includes:executable code that performs enrollment processing for cardholder data that is identified as being used for a first time with the access control system (100, 100').
  5. 10
    The access control system (100, 100') according to one of claims 1 - 9, wherein the access decision component (20) controls access through an access point, and the access control system (100, 100'), further comprises:a reader (40,42) disposed at the access point that extracts cardholder data from a credential presented at the access point;wherein the validation module (50) is coupled to the reader (40,42) and the access decision component (20).