Credential Activation for Multi-Factor Physical-Digital Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access control systems, such as proximity cards and biometrics, are vulnerable to hacking and cloning, leading to unauthorized access and data breaches, with high upgrade costs and compliance issues, and lack effective multi-factor authentication.

Innovation Solution

A system and method for credential activation layered security that integrates with existing access control systems, using multi-factor and multi-modal authentication (physical and digital presence) to activate and deactivate credentials based on user verification, and allows users to control their credentials and consent to their use.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If proximity cards are used as primary secure access control method, then ease of operation is improved, but reliability deteriorates due to vulnerability to hacking and cloning

Engineering Contradiction:
Improveease of operationVSAvoidreliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent combines multiple authentication factors (biometric data, proximity card credentials, location information, device identifiers) into a unified authentication system. This merging of different security layers ensures that even if one factor is compromised, the overall system remains secure while maintaining ease of use through automatic multi-factor verification.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a composite authentication credential that integrates multiple security elements (biometric templates, encrypted card data, location data, device fingerprints) into a single credential structure. This composite credential provides enhanced security compared to traditional proximity cards while maintaining the same user experience.

Inventive Principle:
Principle #40Composite materials

2Reliability

If biometric systems are employed to further secure physical structures, then reliability is improved, but ease of operation deteriorates and users lose control over their biometric templates

Engineering Contradiction:
ImprovereliabilityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements dynamic credential activation where biometric templates are only activated and stored on user devices when explicitly authorized by the user. The system dynamically adjusts security levels and authentication requirements based on context (location, time, risk assessment), providing both high reliability and user control without requiring permanent biometric storage in centralized databases.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent enables users to self-manage their biometric credentials through mobile applications, allowing them to control which devices have access to their biometric data, revoke access when needed, and understand how their data is being used. This self-service approach gives users direct control over their biometric templates while maintaining security.

Inventive Principle:
Principle #25Self-service

3Reliability

If existing access control systems are upgraded to combat vulnerabilities, then reliability is improved, but device complexity and cost increase

Engineering Contradiction:
ImprovereliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces complex hardware-based security systems with software-based authentication mechanisms that run on existing mobile devices. Instead of requiring new specialized hardware, the system uses software applications that leverage the processing power and sensors already present in smartphones and tablets, thereby improving security without significantly increasing device complexity or cost.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent creates a universal authentication system that works across multiple platforms (iOS, Android), different device types (smartphones, tablets, wearables), and various access control scenarios (physical access, logical access, time-based access). This multi-functional approach eliminates the need for separate specialized systems for different security needs, reducing overall complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If multi-factor authentication is implemented, then reliability is improved, but device complexity and compliance requirements increase

Engineering Contradiction:
ImprovereliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent performs preliminary authentication actions in the background before actual access is required. Biometric data is captured and verified in advance, location information is pre-checked, and device credentials are validated before the user even attempts to access secured resources. This preliminary action reduces the perceived complexity for users while maintaining strong multi-factor security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a middleware authentication service that coordinates between multiple authentication factors and the various access control systems. This intermediary layer handles the complexity of multi-factor authentication logic, credential validation, and security policy enforcement, shielding users from complexity while ensuring reliable security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12361777B2System and method for providing credential activation layered security
Publication Date: 2025.07.15 SOLOINSIGHT
  • US12361777B2 patent drawing
  • US12361777B2 patent drawing
  • US12361777B2 patent drawing

AI summary

A system for providing credential activation layered security is disclosed. In particular, the system adds a layer of additional security at ingress and egress points of a location, such as a building. When a user attempts to check in at the location, the user may provide a proof of physical presence, a proof of digital presence, or a combination thereof, such as at a device at the location. In order to activate a credential for accessing physical and/or logical access control systems of the location, the system may authenticate the proof of physical presence, the proof of digital presence, or both. If the system authenticates the user, the user may be checked-in and the credential may be activated so that the user may access the physical and/or logical access control systems of the location so as to gain access to the ingress point or exit via the egress point.