Credential Proxy Verification for Access Control Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional access control systems lack sufficient security and user convenience, as they often rely solely on pin codes or passwords, which can be compromised, and two-factor authentication systems complicate user access with multiple input requirements.
Innovation Solution
An access control system that uses a verification computing system to store and manage access rights information, generates and compares credential proxies derived from user input and stored credentials using an algorithm, to authorize users securely and efficiently.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If conventional access control systems use pin codes or passwords, then ease of operation is improved, but security deteriorates
Solution Approach 1:
The patent introduces credential proxies as intermediary values that mediate between the original credentials and the verification process. These proxies are derived from credentials using one-way algorithms, allowing verification without exposing the actual credentials, thus maintaining both ease of operation and security
Solution Approach 2:
The system transforms credentials into different parameter forms (credential proxies) through one-way derivation algorithms. This parameter transformation allows the same credential to be verified multiple times without revealing the original value, resolving the contradiction between operational ease and security
2Reliability
If two-factor authentication systems require multiple inputs, then security is improved, but device complexity increases
Solution Approach 1:
The authentication process is segmented into distinct components: original credentials, derived credential proxies, and verification algorithms. This segmentation allows the system to maintain security through multiple verification steps while organizing complexity into manageable, modular components
Solution Approach 2:
Credential proxies are derived and stored in advance before the verification process. This preliminary action prepares the verification data beforehand, so that during actual authentication, the system only needs to perform simple proxy comparisons rather than complex multi-step verification, reducing operational complexity
3Reliability
If credential proxies are irreversibly derived using algorithms, then security is improved, but loss of information occurs
Solution Approach 1:
The patent converts the apparent harm of irreversible derivation (loss of information) into a security benefit. The one-way derivation ensures that even if credential proxies are compromised, the original credentials remain secure. The system accepts information loss as a necessary trade-off for achieving unbreakable security
Data Source
AI summary
An access control system includes a verification computing system that stores access rights information and credential proxies received from user devices, receives from a local access control subsystem an input credential and input credential proxy derived therefrom and received from a present user, identifies the access rights information associated with the user according to the input credential proxy and the stored credential proxy, requests and receives a stored credential from the user device of the present user, and compares the stored credential to the input credential to authorize the present user. The access rights information is for each of the users to access spaces with the local access control subsystems. The stored credential proxies are derived from stored credential received by the user devices using an algorithm. The input credential proxies are derived from the input credentials using the algorithm.


