Context-Based Challenge-Response Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing access control systems fail to adequately authenticate and monitor mobile devices and other entities within secure environments, as they primarily focus on user identity verification without ensuring the device itself is secure, and require complex infrastructure and coordination for dongle-based solutions.
Innovation Solution
Implementing a secure protocol that uses a two-way challenge and response mechanism with digital signatures to authenticate and monitor entities, including mobile devices, by establishing an initial non-repudiable state and continuously verifying changes in the device's state to ensure authorization and security within a controlled environment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional access control systems use badge/password/PIN verification, then user identity authentication is achieved, but device security cannot be ensured and monitoring becomes complicated
Solution Approach 1:
The patent combines user identity verification with device security authentication into a unified challenge-response system. The mobile device itself becomes both the credential holder and the security boundary, merging what were previously separate concerns (user auth and device auth) into a single integrated solution.
Solution Approach 2:
The mobile device performs self-authentication by generating and verifying cryptographic proofs locally without requiring external monitoring infrastructure. The device autonomously demonstrates its security state through digital signatures and challenge-response protocols, eliminating the need for complex external monitoring systems.
2Ease of operation
If smart mobile devices are allowed in secure environments, then user convenience is improved, but device security cannot be guaranteed
Solution Approach 1:
The system dynamically evaluates the security state of mobile devices through continuous challenge-response authentication. Rather than statically trusting or blocking devices, the system adaptively verifies security credentials in real-time, adjusting access based on the current security posture of each device.
Solution Approach 2:
The system performs preliminary security verification of mobile devices before granting access to secure environments. By validating security credentials, establishing trust boundaries, and configuring security policies in advance, the system ensures device security is proven before the device enters the protected zone.
3Reliability
If dongle-based access control is implemented, then device authentication is achieved, but infrastructure complexity and coordination requirements increase
Solution Approach 1:
The patent extracts the authentication logic from external infrastructure (dongles, centralized servers) and embeds it directly in the mobile device. The device contains its own cryptographic key pairs and security credentials, making it self-sufficient for authentication purposes and eliminating dependence on complex external authentication infrastructure.
Solution Approach 2:
The patent introduces cryptographic proof mechanisms as an intermediary between the mobile device and the access control system. Instead of direct complex infrastructure-based authentication, devices present cryptographic proofs that mediate the trust relationship, simplifying the interaction model and reducing infrastructure requirements.
Data Source
AI summary
Access by a requesting entity to an asset is authorized by an access-controlling entity, which transmits to the requesting entity a challenge data set and then receives from the requesting entity a response purportedly corresponding to a representation of the challenge data set in a non-repudiatable form, obtained from an event validation system. The access-controlling entity queries the event validation system to determine whether the response does correspond to a correct representation of the challenge data set in the non-repudiatable form, and authorizes the requesting entity for access only if the response is correct representation. Non-repudiation can be established through entry into a blockchain, or using a hash-tree-based digital signature infrastructure.


