Mobile Credential Beacon Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing contactless access control technologies, such as passive smart cards, are limited by physical and power constraints, which hinder the implementation of strong security measures and dynamic access control, making them vulnerable to breaches and unable to modify stored information without reissuing the card.
Innovation Solution
The use of a mobile credential data payload encoded with a hash-based message authentication code (HMAC) and a beacon-based system that leverages near-field communication and proximity signals to provide dynamic access control, allowing for secure and scalable access management by generating and validating mobile credentials on mobile devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If passive smart cards are used for access control, then physical access control is achieved, but security is weak and dynamic control is not possible due to physical and power constraints
Solution Approach 1:
The patent replaces physical smart cards with mobile devices that store digital copies of credentials. The mobile device acts as a copy of the traditional card but with significantly enhanced capabilities including larger memory, processing power, and wireless communication abilities, enabling both strong security and dynamic access control.
Solution Approach 2:
The system changes the fundamental parameters of the access control medium by transitioning from passive cards with fixed storage to active mobile devices with computational capabilities. This allows the system to implement dynamic credential generation, cryptographic operations, and real-time access decisions that were impossible with traditional cards.
2Device complexity
If passive smart cards store information statically, then device complexity is reduced, but the ability to modify information without reissuing is lost
Solution Approach 1:
The patent implements dynamic credential storage and modification in mobile devices. Credentials can be updated, modified, and regenerated without physical reissuing of cards. The system supports dynamic access control policies that can change over time, allowing the same device to adapt to different access requirements.
Solution Approach 2:
The system incorporates feedback mechanisms where the access control server can detect when a credential needs updating and push modifications to the mobile device. This allows the system to respond to changing security requirements and automatically update credentials without requiring user action or physical card replacement.
3Reliability
If mobile devices with large memory and processing power are used, then strong security and dynamic control are enabled, but device complexity and power requirements increase
Solution Approach 1:
The patent leverages the existing multi-functional capabilities of mobile devices (smartphones and tablets) that people already carry. These devices provide the necessary security features, storage capacity, and processing power as standard functionality, eliminating the need for specialized access control hardware while achieving strong security and dynamic control.
Solution Approach 2:
The mobile device serves multiple functions: storing credentials, performing cryptographic operations, displaying information, and communicating with the access control system. The device is self-sufficient for access control operations, eliminating the need for separate specialized hardware and reducing overall system complexity.
4Reliability
If authentication time is increased to improve security, then breach probability decreases, but user convenience deteriorates and friction increases
Solution Approach 1:
The system performs preliminary authentication actions in the background, such as pre-generating credentials, pre-establishing security contexts, and pre-validating access policies. This allows rapid authentication at the point of use without requiring users to undergo lengthy verification processes, maintaining both security and convenience.
Solution Approach 2:
The patent implements rapid authentication mechanisms that skip unnecessary verification steps for trusted users and contexts. For example, the system can use cached credentials, trusted device fingerprints, and pre-established security contexts to authenticate users quickly without repeating full authentication procedures, thereby reducing friction while maintaining security.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
This solution enhances security and scalability by enabling dynamic access control, preventing unauthorized access, and reducing the need for physical card reissuance, while providing an additional layer of security through dual-custody authentication and triangulation of user location.
Implementation Method 1
a beacon transmitter that transmits a low-energy proximity beacon signal that is periodically broadcast
Implementation Method 2
the mobile device, upon receiving the beacon signal, transmitting a data packet indicative of a relative position characteristic of the mobile device
Implementation Method 3
The mobile payment mechanisms using, for example, close proximity communications protocols (e.g., near-field communications)
Data Source
AI summary
Systems, devices, methods, and computer readable media for electronically controlling a user's access to one or more controlled resources are provided. A near-field communication-based mobile credential data payload is provisioned on a mobile device capable of establishing a contactless payment transaction and a low energy proximity beacon signal is periodically broadcasted. The beacon signal and an emulated contactless payment transaction can be utilized in concert to determine that the identity is authorized to access the one or more controlled resources.


