Context-Based Challenge-Response Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access control systems fail to adequately authenticate and monitor mobile devices and other entities within secure environments, as they primarily focus on user identity verification without ensuring the device itself is secure, and require complex infrastructure and coordination for dongle-based solutions.

Innovation Solution

Implementing a secure protocol that uses a two-way challenge and response mechanism with digital signatures to authenticate and monitor entities, including mobile devices, by establishing an initial non-repudiable state and continuously verifying changes in the device's state to ensure authorization and security within a controlled environment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional access control systems use badge/password/PIN verification, then user identity authentication is achieved, but device security cannot be ensured and monitoring becomes complicated

Engineering Contradiction:
Improveuser identity authenticationVSAvoidmonitoring complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines user identity verification with device security authentication into a unified challenge-response system. The mobile device itself becomes both the credential holder and the security boundary, merging what were previously separate concerns (user auth and device auth) into a single integrated solution.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The mobile device performs self-authentication by generating and verifying cryptographic proofs locally without requiring external monitoring infrastructure. The device autonomously demonstrates its security state through digital signatures and challenge-response protocols, eliminating the need for complex external monitoring systems.

Inventive Principle:
Principle #25Self-service

2Ease of operation

If smart mobile devices are allowed in secure environments, then user convenience is improved, but device security cannot be guaranteed

Engineering Contradiction:
Improveuser convenienceVSAvoiddevice security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system dynamically evaluates the security state of mobile devices through continuous challenge-response authentication. Rather than statically trusting or blocking devices, the system adaptively verifies security credentials in real-time, adjusting access based on the current security posture of each device.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs preliminary security verification of mobile devices before granting access to secure environments. By validating security credentials, establishing trust boundaries, and configuring security policies in advance, the system ensures device security is proven before the device enters the protected zone.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If dongle-based access control is implemented, then device authentication is achieved, but infrastructure complexity and coordination requirements increase

Engineering Contradiction:
Improvedevice authenticationVSAvoidinfrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the authentication logic from external infrastructure (dongles, centralized servers) and embeds it directly in the mobile device. The device contains its own cryptographic key pairs and security credentials, making it self-sufficient for authentication purposes and eliminating dependence on complex external authentication infrastructure.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces cryptographic proof mechanisms as an intermediary between the mobile device and the access control system. Instead of direct complex infrastructure-based authentication, devices present cryptographic proofs that mediate the trust relationship, simplifying the interaction model and reducing infrastructure requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10297094B2Challenge-response access control using context-based proof
Publication Date: 2019.05.21 GUARDTIME SA
  • US10297094B2 patent drawing
  • US10297094B2 patent drawing
  • US10297094B2 patent drawing

AI summary

Access by a requesting entity to an asset is authorized by an access-controlling entity, which transmits to the requesting entity a challenge data set and then receives from the requesting entity a response purportedly corresponding to a representation of the challenge data set in a non-repudiatable form, obtained from an event validation system. The access-controlling entity queries the event validation system to determine whether the response does correspond to a correct representation of the challenge data set in the non-repudiatable form, and authorizes the requesting entity for access only if the response is correct representation. Non-repudiation can be established through entry into a blockchain, or using a hash-tree-based digital signature infrastructure.