Event Driven Second Factor Authentication for Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Physical Access Control Systems (PACS) face challenges in securing credentials from theft, loss, and cloning due to the lack of effective secondary authentication factors beyond traditional RFID and biometric methods, which are costly and vulnerable to attacks.

Innovation Solution

Implementing an event-based authentication mechanism that requires users to demonstrate knowledge of specific events, such as LED blinks, beeps, or display patterns, as a second factor of authentication, which can be stored on credentials or calculated by readers, and periodically changed for enhanced security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a biometric reader is deployed to acquire a second factor of authentication, then security is increased, but cost increases significantly compared to using a keypad

Engineering Contradiction:
Improveauthentication securityVSAvoidhardware cost
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces expensive biometric hardware with an event-based authentication system that uses existing reader components (LEDs, displays, audio output) to present events and collect user responses. This substitutes mechanical/biometric systems with an information-processing approach that leverages existing infrastructure, eliminating the need for additional costly hardware while maintaining security through multiple authentication factors

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent creates a virtual copy of biometric authentication functionality through event-based responses. Instead of physically capturing biometric data, the system replicates the security function by observing and analyzing user interactions with presented events (such as timing of responses, sequence of actions), creating a behavioral biometric profile that provides similar security without the hardware cost

Inventive Principle:
Principle #26Copying

2Ease of operation

If traditional RFID credentials are used, then ease of operation is maintained, but security is vulnerable to theft, loss, and cloning

Engineering Contradiction:
Improvecredential usage simplicityVSAvoidcredential security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements preliminary authentication actions by requiring users to respond to events before granting access. The system presents events (LED patterns, audio signals, display information) and requires specific user responses as a preliminary step before the credential is fully authenticated. This preliminary action layer prevents unauthorized use of stolen or cloned credentials while maintaining simplicity for legitimate users who know the expected responses

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces dynamic authentication by making credential validation dependent on real-time user responses to changing events. Rather than static credential verification, the system dynamically presents different events and evaluates user responses, creating a living authentication process that adapts to each interaction. This dynamic approach renders stolen credentials useless without the corresponding knowledge of event responses

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11089012B2Event driven second factor credential authentication
Publication Date: 2021.08.10 ASSA ABLOY AB
  • US11089012B2 patent drawing
  • US11089012B2 patent drawing
  • US11089012B2 patent drawing

AI summary

A reader configured to perform dual-factor authentication is provided. The reader is configured to analyze credential data as well as event-based user inputs. The event-based user inputs are received in response to the reader presenting one or more events to a user and monitoring the user's reaction thereto. Utilization of an event-based user input enables the reader to perform dual-factor authentication without necessarily being provided with a keyboard or other advanced user input device.