Credential Proxy Verification for Access Control Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional access control systems lack sufficient security and user convenience, as they often rely solely on pin codes or passwords, which can be compromised, and two-factor authentication systems complicate user access with multiple input requirements.

Innovation Solution

An access control system that uses a verification computing system to store and manage access rights information, generates and compares credential proxies derived from user input and stored credentials using an algorithm, to authorize users securely and efficiently.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional access control systems use pin codes or passwords, then ease of operation is improved, but security deteriorates

Engineering Contradiction:
Improveease of accessVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces credential proxies as intermediary values that mediate between the original credentials and the verification process. These proxies are derived from credentials using one-way algorithms, allowing verification without exposing the actual credentials, thus maintaining both ease of operation and security

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system transforms credentials into different parameter forms (credential proxies) through one-way derivation algorithms. This parameter transformation allows the same credential to be verified multiple times without revealing the original value, resolving the contradiction between operational ease and security

Inventive Principle:
Principle #35Parameter changes

2Reliability

If two-factor authentication systems require multiple inputs, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication process is segmented into distinct components: original credentials, derived credential proxies, and verification algorithms. This segmentation allows the system to maintain security through multiple verification steps while organizing complexity into manageable, modular components

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Credential proxies are derived and stored in advance before the verification process. This preliminary action prepares the verification data beforehand, so that during actual authentication, the system only needs to perform simple proxy comparisons rather than complex multi-step verification, reducing operational complexity

Inventive Principle:
Principle #10Preliminary action

3Reliability

If credential proxies are irreversibly derived using algorithms, then security is improved, but loss of information occurs

Engineering Contradiction:
ImprovesecurityVSAvoidcredential recovery
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent converts the apparent harm of irreversible derivation (loss of information) into a security benefit. The one-way derivation ensures that even if credential proxies are compromised, the original credentials remain secure. The system accepts information loss as a necessary trade-off for achieving unbreakable security

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Data Source

PatentUS11551496B1Access control systems, devices, and methods therefor
Publication Date: 2023.01.10 PASSIVEBOLT INC
  • US11551496B1 patent drawing
  • US11551496B1 patent drawing
  • US11551496B1 patent drawing

AI summary

An access control system includes a verification computing system that stores access rights information and credential proxies received from user devices, receives from a local access control subsystem an input credential and input credential proxy derived therefrom and received from a present user, identifies the access rights information associated with the user according to the input credential proxy and the stored credential proxy, requests and receives a stored credential from the user device of the present user, and compares the stored credential to the input credential to authorize the present user. The access rights information is for each of the users to access spaces with the local access control subsystems. The stored credential proxies are derived from stored credential received by the user devices using an algorithm. The input credential proxies are derived from the input credentials using the algorithm.