Location-Based Automated Authentication Using BLE Transitory Identifiers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing location-based authentication systems lack secure and efficient methods for identifying and authenticating mobile devices in designated areas, particularly in scenarios where proximity-based access control is required, and are vulnerable to replay attacks.

Innovation Solution

A Location-Based Automated Authentication System (LBAAS) utilizing Bluetooth Low Energy (BLE) signals with encrypted transitory identifiers, where a mobile device broadcasts dynamic and temporary identifiers that are validated by a Backend Account System, using a proprietary algorithm to generate and compare unique and changing encrypted identifiers, ensuring secure and efficient user authentication without network connection between the mobile device and the backend system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication systems are used, then user identification can be achieved, but the system is vulnerable to replay attacks and lacks security

Engineering Contradiction:
Improveauthentication securityVSAvoidreplay attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies dynamics by implementing dynamic identifiers that change over time. The mobile device generates a new identifier each authentication session using a seed value and timestamp, preventing replay attacks since captured identifiers become invalid after use. This dynamic approach transforms static authentication credentials into time-sensitive, one-time-use identifiers.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent utilizes parameter changes by modifying the identifier structure to include time-dependent variables. The authentication identifier incorporates a timestamp and randomly generated seed values, changing parameters from static to dynamic. This ensures each authentication attempt uses unique parameters, making replay attacks ineffective.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If continuous authentication monitoring is implemented, then security is improved, but battery consumption increases

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidmobile device battery consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent implements periodic action by triggering authentication identifier generation and transmission only when the mobile device enters a geofenced area or when proximity to the authentication point is detected. Instead of continuous monitoring, the system periodically checks location conditions and activates authentication only when necessary, significantly reducing battery consumption while maintaining security.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The system applies self-service by using the mobile device's existing GPS and Bluetooth capabilities for location detection and identifier transmission. The device leverages its own built-in services rather than requiring continuous power-intensive external monitoring, achieving authentication reliability through the device's inherent functions.

Inventive Principle:
Principle #25Self-service

3Reliability

If encrypted identifiers are transmitted continuously, then authentication security is enhanced, but network usage and energy consumption increase

Engineering Contradiction:
Improveidentifier securityVSAvoidnetwork transmission energy
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent applies periodic action by transmitting encrypted identifiers only when authentication conditions are met (device enters geofence or approaches authentication point). The system periodically evaluates location triggers and transmits identifiers event-driven rather than continuously, reducing network energy consumption while maintaining encrypted security for when transmissions occur.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The patent implements disposable short-living objects by creating new encrypted identifiers for each authentication session that become invalid after use. Each identifier is designed for single-use or limited-time validity, replacing expensive continuous transmission with cheap, temporary cryptographic credentials that are discarded after authentication.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

The system provides secure and efficient user identification and authentication, preventing replay attacks, with low battery consumption and minimal network usage, enabling convenient and secure access control in various applications such as toll collection, gated entrances, and employee access, while being customizable for different use cases.

Implementation Method 1

The mobile device is operable to continuously transmit Bluetooth Low Energy (BLE) signals comprising encrypted transitory identifiers

Methodology Applied
Scientific EffectBluetooth Low Energy (BLE) signal transmission: Electromagnetic Induction

Data Source

PatentUS9922473B1Systems and methods for location-based automated authentication
Publication Date: 2018.03.20 USCONTRACTING LLC
  • US9922473B1 patent drawing
  • US9922473B1 patent drawing
  • US9922473B1 patent drawing

AI summary

Systems and methods for location-based automated authentication are disclosed. A system comprises a mobile device, a sensor and a backend platform. The sensor and the backend platform is in network communication. The mobile device is operable to continuously transmit Bluetooth Low Energy (BLE) signals comprising encrypted transitory identifiers. The sensor is operable to receive a BLE signal from the mobile device when the mobile device is within a predetermined range, and communicate over a network connection the encrypted transitory identifier comprised in the BLE signal to the backend platform. The backend platform is operable to extract a unique identifier and a changing encrypted identifier from the received encrypted transitory identifier, generate a changing encrypted identifier, and validate a user identification by comparing the generated changing encrypted identifier and the extracted encrypted transitory identifier.