Closed-Loop Identity and Location Certification for Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access control mechanisms for sensitive data or systems are vulnerable to identity theft and location circumvention, particularly through password-based and IP address verification, which can be easily compromised.

Innovation Solution

A method involving a terminal with dual processing circuits for separate location and identity verification using short-range telecommunications, where a first verification checks the terminal's location and a second verification confirms the requester's identity, followed by an output signal to an access management platform.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If password-based or IP address verification is used for access control, then ease of operation is improved, but security and reliability deteriorate due to vulnerability to identity theft and location circumvention

Engineering Contradiction:
Improveease of access controlVSAvoidsecurity against identity theft and location circumvention
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The verification process is segmented into three independent components: location verification via short-range wireless signal reception, identity verification through authentication token validation, and access decision-making by the access control system. This segmentation ensures that no single verification method can be compromised alone, as all three must succeed for access to be granted.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A terminal device acts as an intermediary between the user and the access control system. The terminal receives and verifies location information through short-range wireless communication, validates authentication tokens, and only then communicates with the access control system. This intermediary layer prevents direct attacks on the access control system and adds multiple verification stages.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple verification actions are required for multi-factor access control, then security is improved, but ease of operation deteriorates due to increased voluntary actions required from users

Engineering Contradiction:
Improvesecurity level of access controlVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The terminal device automatically performs location verification by receiving and processing short-range wireless signals without requiring user intervention. The authentication token is automatically validated by the terminal or access control system. These automated processes eliminate the need for users to manually perform multiple verification actions while maintaining high security standards.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Location verification is performed preliminarily before identity verification and access decision-making. The terminal device pre-verify the user's location through short-range wireless signal reception and stores this information for subsequent verification stages. This preliminary action streamlines the overall process by preparing verification data in advance.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If certificates and important data are stored directly on user terminals, then ease of operation is improved, but security deteriorates due to risk of compromise

Engineering Contradiction:
Improvelocal access capabilityVSAvoidprotection against data compromise
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The terminal device serves as an intermediary that holds and processes authentication tokens locally for convenient access, while sensitive certificates and important data remain stored securely on the access control system or secure servers. The terminal communicates with these secure storage locations only when necessary for verification, minimizing exposure risks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication token, which is less sensitive than certificates, is extracted and stored locally on the terminal device to enable convenient access operations. The more sensitive certificates and important data are extracted from the terminal and stored securely on remote systems, separating the functions of local convenience and secure storage.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12452678B2Identity and location certification by multifactor verification based on a closed loop of exchanges
Publication Date: 2025.10.21 ORANGE SA
  • US12452678B2 patent drawing
  • US12452678B2 patent drawing
  • US12452678B2 patent drawing

AI summary

A method and devices for certifying identity and location and a method and devices for managing access requests. A first verification relating to a location of a requester is carried out by a terminal upon reception of a code received by the terminal via at least one short-range telecommunication channel. A second verification relating to an identity of the requester is also triggered and carried out by the terminal. After these two verifications, an output signal is sent to an access management platform in order to trigger a requested access.