Decoupled Authorization for Mobile Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile devices experience delays in authorizing access to restricted resources compared to keycards, and there is a security risk due to the lack of user intent authorization in automated access initiation.

Innovation Solution

Implementing decoupled authorization, where access permission and intent to access are authorized separately and independently, allowing one to be completed before or simultaneously with the other, using an access control system that includes a processor, memory, and network connectivity to grant access only upon successful authorization within a timeout interval.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If mobile device automatically initiates access authorization when detecting reader, then authorization speed improves, but security deteriorates due to lack of user intent verification

Engineering Contradiction:
Improveauthorization speedVSAvoidsecurity
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent segments the authorization process into two independent phases: access permission authorization (automated when device detects reader) and intent to access authorization (requires user action). This segmentation allows each phase to be optimized independently - the first phase enables fast automated authorization while the second phase ensures security through user intent verification, resolving the contradiction between speed and security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary action by performing access permission authorization in advance when the mobile device detects the reader, before the user actually needs to access the resource. This preliminary automated authorization establishes permission status ahead of time, so when the user intends to access, only the faster intent verification is needed, improving overall speed while maintaining security through the subsequent user-action required step.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If mobile device performs wireless connection establishment and security handshaking, then connection security improves, but authorization time increases

Engineering Contradiction:
Improveconnection securityVSAvoidauthorization time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the authorization workflow into permission establishment (can use pre-established connections) and intent verification (can use faster direct authentication). By separating these functions, the system can leverage secure pre-established wireless connections for permission authorization while using faster authentication mechanisms for intent verification, reducing overall time while maintaining security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs wireless connection establishment and security handshaking as a preliminary action during the access permission authorization phase, before the actual access attempt. This way, the secure connection is already in place when the user initiates access, eliminating the need to repeat these time-consuming steps during the faster intent verification phase, thus reducing overall authorization time while maintaining connection security.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If user performs multiple physical actions to initiate authorization, then user control improves, but authorization speed deteriorates

Engineering Contradiction:
Improveuser controlVSAvoidauthorization speed
Core Design Contradiction:
Ease of operationVSSpeed

Solution Approach 1:

The patent segments user interaction into two parts: minimal user action for intent authorization (speed critical) and background automated permission authorization (user control maintained). The user only needs to perform a simple intent indication when actually accessing the resource, while the system handles the more complex permission verification automatically in the background, achieving both speed and ease of operation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements self-service by having the mobile device automatically perform access permission authorization without requiring user action - the device detects the reader, establishes connection, and completes permission verification autonomously. This self-service approach eliminates time-consuming user actions while maintaining security, as the device serves itself in handling the automated permission phase while requiring minimal user input only for the critical intent verification phase.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10599826B2Decoupled authorization for restricted resource access
Publication Date: 2020.03.24 OPENPATH SECURITY INC
  • US10599826B2 patent drawing
  • US10599826B2 patent drawing
  • US10599826B2 patent drawing

AI summary

Systems and methods for performing decoupled authorization, whereby authorizing access permissions of a user to a resource is performed separate and independent from authorizing intent of the user to access the resource. Once both authorizations are successfully completed within a specified timeout interval, the access state of the resource is changed, thereby granting the user access to the resource. The decoupled authorizations are independently performed over different networks, in response to different triggers, or by leveraging different hardware. Access to the resource can therefore be provided prior to the user arriving before the resource, with little to no action by the user, and without comprising security as the resources will remain restricted or locked if the either of the user's intent or access permissions cannot be verified.