Mobile Credential Distribution via Proximity Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The logistical burden of provisioning physical and logical access credentials using traditional methods, such as smart cards, is high due to costs, productivity losses, and inefficiencies in deployment and management.

Innovation Solution

A method and system where a server selects and assigns access credentials to mobile communication devices over a secure and authenticated channel, allowing these devices to use proximity technologies to present credentials to access nodes, thereby simplifying the distribution and management of access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional smart card provisioning methods are used, then access credentials can be securely distributed, but logistical burden and costs increase significantly

Engineering Contradiction:
Improvesecure credential distributionVSAvoidlogistical burden
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Users automatically receive access credentials on their mobile devices through push notifications or automated enrollment processes, eliminating the need for manual distribution at manned issuance stations. The system performs self-service provisioning by automatically enrolling devices and distributing credentials without requiring user travel or manual intervention.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the mechanical distribution system (physical smart cards requiring manual handling and issuance stations) with an electronic/digital system that automatically transmits credentials over networks. Mobile devices receive credentials electronically through authenticated channels, substituting physical card distribution with digital transmission.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If manned issuance stations are deployed, then credential distribution can be controlled, but productivity is reduced due to user travel and coordination requirements

Engineering Contradiction:
Improvecontrolled credential distributionVSAvoiduser productivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system enables automated credential enrollment and distribution without requiring users to visit issuance stations. Mobile devices are automatically enrolled in the access control system through electronic processes, allowing users to maintain their normal workflows without interruption or travel to designated locations.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Mobile devices serve multiple functions: they act as both communication devices and access control credentials. The same device users already carry for communication purposes is also used for access control, eliminating the need for separate smart cards or dedicated issuance infrastructure.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If physical smart cards are distributed, then access control can be implemented, but costs increase due to card production and distribution infrastructure

Engineering Contradiction:
Improveaccess control functionalityVSAvoiddistribution costs
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

Instead of distributing physical smart cards, the system creates and transmits electronic copies of access credentials to mobile devices. The credential data is replicated and delivered digitally through authenticated channels, eliminating the need for physical card production, storage, and distribution infrastructure.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent uses inexpensive mobile devices that users already possess rather than expensive physical smart cards. The mobile device platform is a commodity product with low marginal cost, replacing costly specialized access control hardware with widely available consumer technology.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentEP2383955B1Assignment and distribution of access credentials to mobile communication devices
Publication Date: 2019.10.30 BLACKBERRY LTD
  • EP2383955B1 patent drawingFigure 1-1
  • EP2383955B1 patent drawingFigure 1-2
  • EP2383955B1 patent drawingFigure 1-3

AI summary

A server (102) storing a pool (416) of unassigned access credentials selects an access credential (822) from the pool, assigns it to an individual (126), transmits the access credential to a mobile communication device (110) associated with the individual over a secure and authenticated channel such that the access credential is receivable by the mobile communication device. If the mobile communication device supports a proximity technology and is proximate to an access node (158) that supports the proximity technology, the mobile communication device may employ the proximity technology to present the access credential to the access node.