Dual-Security System for Secure Data Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems for securing data on user devices lack sufficient security measures to prevent unauthorized access, particularly in scenarios where proximity-based systems are compromised or lack trusted time sources.
Innovation Solution
A dual-security system combining proximity detection and limited-use passcodes, where a passcode is generated and validated using a shared seed value, ensuring that both proximity and local user input are verified, eliminating the need for a trusted time source and reducing replay attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If proximity-based security system is used, then convenience to user is improved, but security against unauthorized access is worsened
Solution Approach 1:
The patent combines proximity detection (second module detecting third module) with limited-use passcode verification (fourth module receiving valid passcode from first module) into a unified security system. Both conditions must be satisfied simultaneously for data access, merging two security mechanisms to overcome the weaknesses of either approach alone.
Solution Approach 2:
The security system uses a composite authentication approach where proximity detection and passcode verification work together as complementary security layers. The proximity system provides convenient automatic authentication while the limited-use passcode adds a second layer that prevents replay attacks, creating a stronger combined security posture.
2Reliability
If traditional security systems are used, then security control is improved, but convenience to user is worsened
Solution Approach 1:
The security system is segmented into distinct functional modules: first module generates passcode, second module detects proximity, third module is the proximity device, and fourth module verifies passcode. This segmentation allows each module to perform its specific function efficiently while maintaining overall system security and user convenience.
Solution Approach 2:
The limited-use passcode acts as an intermediary between the proximity detection system and the secure data access. It mediates the authentication process by providing a verifiable credential that confirms both proximity and local user presence, bridging the gap between convenient proximity-based access and rigorous security verification.
3Reliability
If passcode is made available to user, then local user verification is improved, but risk of replay attacks is worsened
Solution Approach 1:
The passcode parameters are changed after each use - the system generates a new limited-use passcode that cannot be reused. This parameter change ensures that even if a passcode is intercepted or recorded, it becomes invalid after the first authentication, preventing replay attacks while maintaining strong local user verification.
Solution Approach 2:
The passcode functions as a disposable authentication credential that is generated, used once, and then becomes invalid. This short-lived nature of the passcode eliminates the risk of replay attacks since each passcode can only be used a single time, making the authentication process both secure and convenient.
Data Source
AI summary
Systems, methods and apparatus for enabling access to secure data. A first module is arranged to generate a limited use passcode and make the passcode available to a user. A second module and a third module are arranged to communicate whereby to enable detection of the third module being in proximity to the second module. A fourth module is arranged to receive a passcode via user input. The apparatus is arranged to enable access to secure data in dependence on the fourth module receiving a valid passcode generated by the first module and the third module being in proximity to the second module.


