Mobile Interrogator Challenge-Response System for Continuous Occupant Authorization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional access control systems provide perimeter-based security, focusing on controlling movement through fixed access points and are limited in continuously authorizing individuals within a premises, with vulnerabilities such as unauthorized access when access cards are stolen.
Innovation Solution
A distributed security system using mobile interrogator devices that broadcast challenge beacons to user devices, combined with image capture and management systems to continuously authenticate users and detect impostors, providing location-independent authorization and enhanced security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional perimeter-based access control systems are used, then access points can be controlled, but continuous authorization of individuals within premises cannot be achieved
Solution Approach 1:
The system transitions from static perimeter-based access control to dynamic continuous authorization by deploying mobile interrogator devices that move through premises, continuously challenging user devices and updating authorization status in real-time based on current location and credentials
Solution Approach 2:
Mobile interrogator devices serve as intermediaries between the central management system and user devices, enabling continuous authorization verification throughout premises without requiring fixed access points or constant connection to central systems
2Reliability
If access card readers are installed at access points, then physical security can be controlled, but stolen cards cannot be detected until deactivation
Solution Approach 1:
The system performs preliminary verification by continuously challenging user devices with security questions or credentials before granting access, allowing detection of stolen cards at the moment of unauthorized use rather than waiting for manual reporting and deactivation
Solution Approach 2:
Real-time feedback is provided through continuous challenge-response interactions between interrogator devices and user devices, immediately identifying and flagging stolen or compromised credentials when they fail to respond correctly to security challenges
3Productivity
If frictionless access control with wireless devices is implemented, then access speed is improved, but vulnerability to stolen credentials remains
Solution Approach 1:
The system maintains continuous security verification through ongoing challenge-response protocols between mobile interrogators and user devices, ensuring that frictionless access does not compromise security by performing multiple rapid verifications rather than single-point authentication
Solution Approach 2:
The system applies excessive security measures by implementing multiple layers of verification including continuous challenges, location verification, and credential validation beyond traditional single-authentication methods, making stolen credentials useless even if obtained
Data Source
AI summary
A system and method for determining authorization of individuals at a premises is disclosed. The system (e.g. security system) includes interrogator devices such as mobile computing devices that are carried through the premises by an interrogator. The interrogator devices send challenge beacons for triggering responses from target user devices carried by users. A management system then confirms whether users of the target user devices are authorized users based on the responses received by the interrogator devices. Examples of target user devices include mobile computing devices such as smart phones/tablet devices, and auxiliary devices such as smart badges and wallets. In embodiments, the interrogator can also carry an auxiliary device having an integrated camera system that captures image data of the users, where the management system additionally confirms whether the users are authorized by comparing the image data along with information in the responses to stored records of authorized users.


