Decoupled Authorization for Mobile Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Mobile devices experience delays in authorizing access to restricted resources compared to keycards, and there is a security risk due to the lack of user intent authorization in automated access initiation.
Innovation Solution
Implementing decoupled authorization, where access permission and intent to access are authorized separately and independently, allowing one to be completed before or simultaneously with the other, using an access control system that includes a processor, memory, and network connectivity to grant access only upon successful authorization within a timeout interval.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If mobile device automatically initiates access authorization when detecting reader, then authorization speed improves, but security deteriorates due to lack of user intent verification
Solution Approach 1:
The patent segments the authorization process into two independent phases: access permission authorization (automated when device detects reader) and intent to access authorization (requires user action). This segmentation allows each phase to be optimized independently - the first phase enables fast automated authorization while the second phase ensures security through user intent verification, resolving the contradiction between speed and security.
Solution Approach 2:
The patent implements preliminary action by performing access permission authorization in advance when the mobile device detects the reader, before the user actually needs to access the resource. This preliminary automated authorization establishes permission status ahead of time, so when the user intends to access, only the faster intent verification is needed, improving overall speed while maintaining security through the subsequent user-action required step.
2Reliability
If mobile device performs wireless connection establishment and security handshaking, then connection security improves, but authorization time increases
Solution Approach 1:
The patent segments the authorization workflow into permission establishment (can use pre-established connections) and intent verification (can use faster direct authentication). By separating these functions, the system can leverage secure pre-established wireless connections for permission authorization while using faster authentication mechanisms for intent verification, reducing overall time while maintaining security.
Solution Approach 2:
The patent performs wireless connection establishment and security handshaking as a preliminary action during the access permission authorization phase, before the actual access attempt. This way, the secure connection is already in place when the user initiates access, eliminating the need to repeat these time-consuming steps during the faster intent verification phase, thus reducing overall authorization time while maintaining connection security.
3Ease of operation
If user performs multiple physical actions to initiate authorization, then user control improves, but authorization speed deteriorates
Solution Approach 1:
The patent segments user interaction into two parts: minimal user action for intent authorization (speed critical) and background automated permission authorization (user control maintained). The user only needs to perform a simple intent indication when actually accessing the resource, while the system handles the more complex permission verification automatically in the background, achieving both speed and ease of operation.
Solution Approach 2:
The patent implements self-service by having the mobile device automatically perform access permission authorization without requiring user action - the device detects the reader, establishes connection, and completes permission verification autonomously. This self-service approach eliminates time-consuming user actions while maintaining security, as the device serves itself in handling the automated permission phase while requiring minimal user input only for the critical intent verification phase.
Data Source
AI summary
Systems and methods for performing decoupled authorization, whereby authorizing access permissions of a user to a resource is performed separate and independent from authorizing intent of the user to access the resource. Once both authorizations are successfully completed within a specified timeout interval, the access state of the resource is changed, thereby granting the user access to the resource. The decoupled authorizations are independently performed over different networks, in response to different triggers, or by leveraging different hardware. Access to the resource can therefore be provided prior to the user arriving before the resource, with little to no action by the user, and without comprising security as the resources will remain restricted or locked if the either of the user's intent or access permissions cannot be verified.


