Mobile Device Cryptographic Key Pairing for Secure System Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional methods for accessing system functionality, such as physical keys or RFID fobs, are inconvenient and vulnerable to loss or theft, lacking secure and efficient authentication mechanisms.

Innovation Solution

The use of a mobile device with asymmetric cryptography to establish a secure channel for authentication, enabling secure access to systems through pairing procedures involving secure elements and key exchanges, allowing for secure communication and authorization processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional physical keys or RFID fobs are used for authentication, then access control functionality is provided, but the system is vulnerable to loss or theft and requires carrying physical objects

Engineering Contradiction:
Improveauthentication securityVSAvoidconvenience of access
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces mechanical authentication systems (physical keys, RFID fobs) with a mobile-based authentication system using asymmetric cryptography. The mobile device stores private keys in a secure element and performs cryptographic operations to authenticate with the locking mechanism, eliminating the need for physical objects while maintaining security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent creates a digital copy of the authentication credential in the form of cryptographic key pairs. The private key is stored in the mobile device's secure element, and the corresponding public key is registered with the locking mechanism, allowing the mobile device to serve as a digital equivalent of traditional physical keys.

Inventive Principle:
Principle #26Copying

2Reliability

If asymmetric cryptography with secure elements is implemented, then authentication security is improved, but device complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the cryptographic functionality into a separate secure element within the mobile device. This secure element is a dedicated hardware component that stores private keys and performs cryptographic operations, isolating the complex security functions from the main device architecture and reducing overall system complexity.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a pairing server as an intermediary that facilitates the key exchange and registration process between the mobile device and the locking mechanism. The server manages the public key registration and verification, simplifying the direct communication requirements between the mobile device and locking mechanism.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11522695B2Sharing system access using a mobile device
Publication Date: 2022.12.06 APPLE INC
  • US11522695B2 patent drawing
  • US11522695B2 patent drawing
  • US11522695B2 patent drawing

AI summary

Techniques are disclosed relating to using a device to gain access to another system. In some embodiments, a first mobile device performs a pairing operation with a control unit that controls access to a system, the pairing operation including the first mobile device establishing a first cryptographic key with the control unit. The first mobile device receives a request to enable a second mobile device to communicate with the control unit, and in response to receiving the request, the first mobile device generates a second cryptographic key from the first cryptographic key. The first mobile device provides the second cryptographic key to the second mobile device. The second mobile device is configured to send a beacon including a payload encrypted with the second cryptographic key, and the encrypted payload is usable to authenticate the second mobile device to the control unit.