Dynamic Authentication via Physical Key Association
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional computer security systems are cumbersome for non-authorized users and users alike, making them less suitable for widespread deployment in ubiquitous computing environments, and they do not effectively provide dynamic authentication methods.
Innovation Solution
A dynamic authentication system that uses a physical key to establish associations between a user, their device, and guest devices through contact-based or contact-less connectors, validating these associations over communication channels and providing access control lists to ensure secure access to user information and services.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional security systems use non-obvious user identifiers, longer passwords, more frequent password changes and smartcards, then security against mis-appropriation of personal information is improved, but ease of operation deteriorates
Solution Approach 1:
The patent uses a physical key that can be copied or replicated to grant access. Instead of requiring complex passwords that must be memorized and changed frequently, the system relies on a physical token that can be easily duplicated, thereby improving ease of operation while maintaining security through physical possession requirements
Solution Approach 2:
The patent replaces the mechanical/electronic smartcard system with a simpler physical key-based system. The physical key interacts with a reader device to establish authentication, eliminating the need for complex password management while maintaining security through physical token distribution
2Reliability
If conventional security systems use longer and more secure passwords, then security is improved, but loss of time increases
Solution Approach 1:
The physical key can be quickly copied or replicated without requiring time-consuming password creation, modification, or verification processes. Authentication is achieved through physical token presentation rather than time-intensive password management cycles
Solution Approach 2:
The system performs preliminary authentication by establishing a physical key-reader connection before accessing user information. This preliminary physical verification is faster than repeated password prompts and eliminates the time loss associated with password reset cycles
3Reliability
If conventional security systems require training for effective use, then security is improved, but ease of manufacture deteriorates
Solution Approach 1:
The physical key system can be easily replicated and distributed without requiring extensive training. Multiple copies of the physical key can be made and assigned to different users, eliminating the need for complex training programs while maintaining security through physical possession control
Solution Approach 2:
The physical key system enables self-service authentication without requiring user training. Users simply present their physical key to the reader device, and the system automatically handles authentication, eliminating the training requirement while maintaining security
Data Source
AI summary
A physical key is used to propose an association between a guest device and user information and services. Contact-based or contact-less connectors are used to establish the proposed association between the physical key and the guest device. The proposed association then communicated to the dynamic authentication system over a first communication channel. The dynamic authentication system determines a user confirmation over a second communications channel based on a user device and previously determined associations between users, user devices and the physical key. The guest device is then authenticated for access to information and/or services associated with the user. The information retrieved from and/or transmitted to the user's personal information repository is optionally protected using various transformations. Optional session identifiers supported on the physical key and/or the user device, ensure the protected information is inaccessible when the physical key is removed and/or the predetermined association with the user device is deleted.


