Mobile Device Multifactor Authentication Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Multifactor authentication in access control systems increases costs and complexity, and existing solutions lack flexibility, as they require additional hardware such as keypads and biometric devices at access points.

Innovation Solution

Utilizing mobile computing devices like smartphones and tablets to provide multifactor authentication through a bridge between on-premise access control systems and remote authenticating servers, leveraging OAuth standards for secure authentication, eliminating the need for additional hardware at access points.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multifactor authentication is implemented using traditional hardware (keypads, biometric devices), then authentication security is improved, but system cost and complexity increase

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a mobile device as an intermediary component that bridges the access control reader and the authentication server. The mobile device contains an authenticating application that performs multifactor authentication locally, then communicates the result to the access control system. This intermediary approach enables sophisticated authentication without requiring complex hardware at the access point itself.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces physical mechanical authentication devices (keypads, fingerprint scanners, iris cameras) with a software-based authentication system running on the mobile device. The mechanical interface of traditional hardware is substituted with the mobile device's touchscreen, camera, and processor, which perform authentication functions through software algorithms rather than physical mechanisms.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If traditional multifactor authentication hardware is installed at access points, then authentication capability is improved, but installation cost increases

Engineering Contradiction:
Improveauthentication capabilityVSAvoidinstallation cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent uses the mobile device as a portable copy of the authentication server functionality. Instead of installing expensive authentication hardware at each access point, the system creates a virtual copy of the authentication server on the user's mobile device. This copy performs all authentication processing locally and communicates results to the access control system, eliminating the need for duplicate hardware installations.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The mobile device serves multiple functions: it acts as the authentication server, stores authentication credentials, performs biometric scanning, and communicates with the access control system. This single universal device replaces what would traditionally require multiple specialized hardware components (fingerprint scanner, keypad, card reader, server), significantly reducing installation costs.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If physical authentication devices are commissioned at doors, then authentication is provided, but system flexibility is reduced

Engineering Contradiction:
Improveauthentication provisionVSAvoidsystem flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates a dynamic authentication system where the authentication server functionality can be remotely provisioned, updated, and configured on mobile devices through wireless communication. Unlike static hardware installed at fixed locations, the authentication capability can be dynamically assigned to different users and devices, and the system can be reconfigured without physical hardware changes at access points.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP3374918B1Access and automation control systems with mobile computing device
Publication Date: 2024.03.13 JOHNSON CONTROLS TYCO IP HLDG LLP
  • EP3374918B1 patent drawingFigure 1
  • EP3374918B1 patent drawingFigure 2
  • EP3374918B1 patent drawingFigure 3

AI summary

A system and method for providing multi-factor authentication that requires a user provide credentials via an authenticating server when attempting access or to control local functions and then, based on the success with the authenticating server, provides the access or control of local functions at subsequent attempts at access or control of the local functions.