Access Management System Using Public Key Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access management systems require users to provide personal data for registration, leading to privacy concerns and liability for service providers, and fail to address dynamic pricing and prepaid account issues.

Innovation Solution

An access management system that uses public keys to authenticate users without transmitting personal information, enabling secure access to electronic resources using blockchain transactions and dynamic validation criteria for pricing adjustments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional registration requiring personal data is used, then service provider can verify user identity, but user privacy is compromised and service provider faces liability

Engineering Contradiction:
Improveuser identity verificationVSAvoiduser privacy exposure
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts only the essential authentication element (public key) from the complete set of personal data, allowing identity verification without storing or transmitting sensitive user information such as names, addresses, or social security numbers

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a cryptographic public key as an intermediary that mediates between user identity verification and privacy protection, enabling the service provider to verify user identity without directly accessing personal information

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If universal login with third party is used, then registration process is simplified, but systemic reliance on third parties is created

Engineering Contradiction:
Improveregistration processVSAvoidservice availability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the authentication system into two independent parts: the service provider's authorization list and the user's private key, eliminating dependence on third-party centralized authentication services

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent enables users to authenticate themselves using their own private keys without requiring intervention from third-party authentication services, making the system self-sufficient and resilient to external outages

Inventive Principle:
Principle #25Self-service

3Quantity of substance

If prepaid account with fixed pricing is used, then service provider can collect funds in advance, but cannot adjust to market fluctuations

Engineering Contradiction:
Improveprepaid fundsVSAvoidpricing flexibility
Core Design Contradiction:
Quantity of substanceVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic pricing by allowing the service provider to update authorization criteria and pricing terms in real-time, enabling adjustment to market fluctuations while maintaining prepaid account functionality

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent incorporates feedback mechanisms where the service provider monitors market conditions and adjusts pricing and authorization criteria accordingly, allowing prepaid accounts to adapt to changing market values

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP4184864B1Access management system and associated computer-implemented methods
Publication Date: 2025.12.24 NAGRAVISION SRL
  • EP4184864B1 patent drawingFigure 1
  • EP4184864B1 patent drawingFigure 2
  • EP4184864B1 patent drawingFigure 3

AI summary

An access management system for controlling access to an electronic resource is provided, wherein the electronic resource accessible at a resource address, and provided by a service provider having associated therewith an electronic provider address, the system comprising: a request management module, configured to determine whether a registration request received at the electronic provider address is a valid registration request, wherein: the registration request includes a public key or data identifying the public key, associated with a client device or user thereof from which the registration request is received; and an authorized client management module configured to add the public key of the user, or data identifying the public key, to an authorized list, if the request management module determines that the registration request is a valid registration request, wherein: when a public key or data identifying the public key of the client device is on the authorized list, the client device or user thereof is permitted to access the electronic resource. Another similar access management system and associated computer-implemented methods are also provided.