Dual-Security System for Secure Data Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems for securing data on user devices lack sufficient security measures to prevent unauthorized access, particularly in scenarios where proximity-based systems are compromised or lack trusted time sources.

Innovation Solution

A dual-security system combining proximity detection and limited-use passcodes, where a passcode is generated and validated using a shared seed value, ensuring that both proximity and local user input are verified, eliminating the need for a trusted time source and reducing replay attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If proximity-based security system is used, then convenience to user is improved, but security against unauthorized access is worsened

Engineering Contradiction:
Improveconvenience to userVSAvoidsecurity against unauthorized access
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent combines proximity detection (second module detecting third module) with limited-use passcode verification (fourth module receiving valid passcode from first module) into a unified security system. Both conditions must be satisfied simultaneously for data access, merging two security mechanisms to overcome the weaknesses of either approach alone.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The security system uses a composite authentication approach where proximity detection and passcode verification work together as complementary security layers. The proximity system provides convenient automatic authentication while the limited-use passcode adds a second layer that prevents replay attacks, creating a stronger combined security posture.

Inventive Principle:
Principle #40Composite materials

2Reliability

If traditional security systems are used, then security control is improved, but convenience to user is worsened

Engineering Contradiction:
Improvesecurity controlVSAvoidconvenience to user
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The security system is segmented into distinct functional modules: first module generates passcode, second module detects proximity, third module is the proximity device, and fourth module verifies passcode. This segmentation allows each module to perform its specific function efficiently while maintaining overall system security and user convenience.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The limited-use passcode acts as an intermediary between the proximity detection system and the secure data access. It mediates the authentication process by providing a verifiable credential that confirms both proximity and local user presence, bridging the gap between convenient proximity-based access and rigorous security verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If passcode is made available to user, then local user verification is improved, but risk of replay attacks is worsened

Engineering Contradiction:
Improvelocal user verificationVSAvoidreplay attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The passcode parameters are changed after each use - the system generates a new limited-use passcode that cannot be reused. This parameter change ensures that even if a passcode is intercepted or recorded, it becomes invalid after the first authentication, preventing replay attacks while maintaining strong local user verification.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The passcode functions as a disposable authentication credential that is generated, used once, and then becomes invalid. This short-lived nature of the passcode eliminates the risk of replay attacks since each passcode can only be used a single time, making the authentication process both secure and convenient.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS11868169B2Enabling access to data
Publication Date: 2024.01.09 VISA EUROPE
  • US11868169B2 patent drawing
  • US11868169B2 patent drawing
  • US11868169B2 patent drawing

AI summary

Systems, methods and apparatus for enabling access to secure data. A first module is arranged to generate a limited use passcode and make the passcode available to a user. A second module and a third module are arranged to communicate whereby to enable detection of the third module being in proximity to the second module. A fourth module is arranged to receive a passcode via user input. The apparatus is arranged to enable access to secure data in dependence on the fourth module receiving a valid passcode generated by the first module and the third module being in proximity to the second module.