Mobile Credential Beacon Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing contactless access control technologies, such as passive smart cards, are limited by physical and power constraints, which hinder the implementation of strong security measures and dynamic access control, making them vulnerable to breaches and unable to modify stored information without reissuing the card.

Innovation Solution

The use of a mobile credential data payload encoded with a hash-based message authentication code (HMAC) and a beacon-based system that leverages near-field communication and proximity signals to provide dynamic access control, allowing for secure and scalable access management by generating and validating mobile credentials on mobile devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If passive smart cards are used for access control, then physical access control is achieved, but security is weak and dynamic control is not possible due to physical and power constraints

Engineering Contradiction:
ImprovesecurityVSAvoiddynamic access control
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent replaces physical smart cards with mobile devices that store digital copies of credentials. The mobile device acts as a copy of the traditional card but with significantly enhanced capabilities including larger memory, processing power, and wireless communication abilities, enabling both strong security and dynamic access control.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system changes the fundamental parameters of the access control medium by transitioning from passive cards with fixed storage to active mobile devices with computational capabilities. This allows the system to implement dynamic credential generation, cryptographic operations, and real-time access decisions that were impossible with traditional cards.

Inventive Principle:
Principle #35Parameter changes

2Device complexity

If passive smart cards store information statically, then device complexity is reduced, but the ability to modify information without reissuing is lost

Engineering Contradiction:
Improvecard electronicsVSAvoidinformation modification
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic credential storage and modification in mobile devices. Credentials can be updated, modified, and regenerated without physical reissuing of cards. The system supports dynamic access control policies that can change over time, allowing the same device to adapt to different access requirements.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system incorporates feedback mechanisms where the access control server can detect when a credential needs updating and push modifications to the mobile device. This allows the system to respond to changing security requirements and automatically update credentials without requiring user action or physical card replacement.

Inventive Principle:
Principle #23Feedback

3Reliability

If mobile devices with large memory and processing power are used, then strong security and dynamic control are enabled, but device complexity and power requirements increase

Engineering Contradiction:
ImprovesecurityVSAvoidmobile device requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent leverages the existing multi-functional capabilities of mobile devices (smartphones and tablets) that people already carry. These devices provide the necessary security features, storage capacity, and processing power as standard functionality, eliminating the need for specialized access control hardware while achieving strong security and dynamic control.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The mobile device serves multiple functions: storing credentials, performing cryptographic operations, displaying information, and communicating with the access control system. The device is self-sufficient for access control operations, eliminating the need for separate specialized hardware and reducing overall system complexity.

Inventive Principle:
Principle #25Self-service

4Reliability

If authentication time is increased to improve security, then breach probability decreases, but user convenience deteriorates and friction increases

Engineering Contradiction:
Improvebreach protectionVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary authentication actions in the background, such as pre-generating credentials, pre-establishing security contexts, and pre-validating access policies. This allows rapid authentication at the point of use without requiring users to undergo lengthy verification processes, maintaining both security and convenience.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements rapid authentication mechanisms that skip unnecessary verification steps for trusted users and contexts. For example, the system can use cached credentials, trusted device fingerprints, and pre-established security contexts to authenticate users quickly without repeating full authentication procedures, thereby reducing friction while maintaining security.

Inventive Principle:
Principle #21Skipping (Rushing through)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This solution enhances security and scalability by enabling dynamic access control, preventing unauthorized access, and reducing the need for physical card reissuance, while providing an additional layer of security through dual-custody authentication and triangulation of user location.

Implementation Method 1

a beacon transmitter that transmits a low-energy proximity beacon signal that is periodically broadcast

Methodology Applied
Scientific EffectElectromagnetic radiation: Electromagnetic Induction

Implementation Method 2

the mobile device, upon receiving the beacon signal, transmitting a data packet indicative of a relative position characteristic of the mobile device

Methodology Applied
Scientific EffectSignal strength detection:

Implementation Method 3

The mobile payment mechanisms using, for example, close proximity communications protocols (e.g., near-field communications)

Methodology Applied
Scientific EffectNear-field communication: Electromagnetic Induction

Data Source

PatentUS11570623B2Secure communication platform
Publication Date: 2023.01.31 MEDIXSAFE INC
  • US11570623B2 patent drawing
  • US11570623B2 patent drawing
  • US11570623B2 patent drawing

AI summary

Systems, devices, methods, and computer readable media for electronically controlling a user's access to one or more controlled resources are provided. A near-field communication-based mobile credential data payload is provisioned on a mobile device capable of establishing a contactless payment transaction and a low energy proximity beacon signal is periodically broadcasted. The beacon signal and an emulated contactless payment transaction can be utilized in concert to determine that the identity is authorized to access the one or more controlled resources.