Authentication Token Linking Identity and Location via Physical Contact

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication methods for mobile entities in transactions lacking location reference are insecure, as they cannot differentiate individuals using one-time-tokens and fail to ensure authentic parties in transactions via communication channels without precise location referencing.

Innovation Solution

A method and communication system that utilize a token, such as a part of a mobile device or a human, coupled with a secret (e.g., fingerprint or PIN code) to establish physical contact with an access point, linking the secret with location information to create an authentication token for secure identity and location verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If one-time-tokens are used for authentication, then access control is simplified, but individual identification capability is lost

Engineering Contradiction:
Improveauthentication processVSAvoidindividual identification
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The authentication system is segmented into two distinct components: a one-time-token component for access control and an identification component (fingerprint, face recognition, or RFID) for individual differentiation. This segmentation allows each component to fulfill its specific function optimally while working together to resolve the contradiction between ease of operation and identification precision.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent merges the one-time-token mechanism with biometric or RFID identification systems to create a composite authentication solution. The one-time-token provides the security and access control, while the additional identification layer provides individual differentiation, thus combining the advantages of both approaches to resolve the technical contradiction.

Inventive Principle:
Principle #5Merging (Combining)

2Adaptability or versatility

If communication channels without location reference are used, then mobile accessibility is improved, but transaction security is degraded

Engineering Contradiction:
Improvemobile accessibilityVSAvoidtransaction security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces an intermediary authentication mechanism that bridges mobile communication channels without location reference and secure transaction verification. The one-time-token system acts as an intermediary that provides security assurance even when precise location data is unavailable, allowing mobile accessibility to be maintained while transaction security is restored through the token verification process.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If physical contact authentication is implemented, then location verification is achieved, but device complexity increases

Engineering Contradiction:
Improvelocation verificationVSAvoidauthentication system
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The access point is designed with multi-functionality, serving both as a location verification device through physical contact detection and as a communication interface for one-time-token transmission. This universal design reduces the need for separate dedicated devices for each function, thereby achieving location verification while minimizing the increase in overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11915507B2Location- and identity-referenced authentication method and communication system
Publication Date: 2024.02.27 NXP BV
  • US11915507B2 patent drawing
  • US11915507B2 patent drawing
  • US11915507B2 patent drawing

AI summary

A method for authenticating a first party to a second party, the method comprising: i) providing a token, wherein the token is at least a part of a mobile entity and wherein the token is coupled to a secret being indicative for the identity of the first party, ii) coupling the token with an access point by establishing a physical contact, iii) transferring the secret to the access point, iv) linking the secret with a location information of the access point, thereby providing an authentication token being indicative for the identity and the location of the first party, and v) providing the authentication token to the second party.