Mobile Radio Device Access Control via Local Cryptographic Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access control methods for security devices are time-consuming and complex, leading to queues and reduced security, particularly in managing large numbers of users and terminals, and are prone to latency issues due to decentralized structures and network communication.

Innovation Solution

A method utilizing a mobile radio device with a first mobile radio interface, communication interface, and application to authenticate terminals by sending access tokens, verifying signatures, and generating temporary keys for secure access to attributes, minimizing the need for complex signature checks and reducing network communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods (password entry, biometric capture, authorization card data exchange) are used, then security is maintained, but authentication time increases significantly causing queues and reduced productivity

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary authentication actions by storing authentication data in advance on authorization cards and using pre-configured cryptographic keys in terminals. This allows rapid verification without real-time computation or network communication during the actual authentication moment, thus reducing authentication time while maintaining security through pre-established trust relationships.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The invention extracts the cryptographic verification process from centralized server dependency and implements it locally in terminals using stored public keys. This extraction eliminates network communication latency and allows independent, rapid authentication decisions at the terminal level, significantly reducing authentication time while maintaining security through distributed cryptographic verification.

Inventive Principle:
Principle #2Taking out (Extraction)

2Productivity

If decentralized terminal structure with local cryptographic data is used, then authentication speed improves, but device complexity and maintenance difficulty increase significantly

Engineering Contradiction:
Improveauthentication speedVSAvoidterminal configuration complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

Terminals are configured with self-service capabilities through automated key pair generation and storage. The system automatically manages cryptographic keys and authentication data without requiring manual configuration, reducing device complexity while maintaining fast local authentication. The terminal autonomously performs verification using stored public keys without needing complex external configuration.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The invention creates universal terminals with standardized cryptographic interfaces that can authenticate multiple different authorization cards using the same verification mechanism. This universality simplifies terminal design and maintenance while enabling fast authentication across diverse user credentials, as all terminals use the same public key verification approach regardless of the specific authorization card type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If centralized server control for authentication is implemented, then security management is simplified, but network communication latency increases authentication time

Engineering Contradiction:
Improvesecurity managementVSAvoidnetwork communication time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The system performs preliminary security management actions by pre-distributing public keys to terminals and pre-configuring authorization data on cards during enrollment. This preliminary setup enables fast local verification without real-time server communication during authentication, eliminating network latency while maintaining centralized security management through the initial key distribution infrastructure.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The invention introduces cryptographic keys as intermediaries between the centralized security management system and the distributed terminals. Public keys serve as mediators that enable secure verification without requiring direct network communication during authentication. The intermediary cryptographic infrastructure allows centralized security policy enforcement while enabling fast decentralized verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3699791B1Access control with a mobile radio device
Publication Date: 2022.10.05 BUNDESDRUCKEREI GMBH
  • EP3699791B1 patent drawingFigure 1
  • EP3699791B1 patent drawingFigure 2
  • EP3699791B1 patent drawingFigure 3

AI summary

The invention relates to a method for controlling access by a terminal (118) to an attribute (112) stored in a mobile communication device (100, 800, 802, 804), wherein the mobile communication device (100, 800, 802, 804) comprises a mobile communication interface (105), a communication interface (104), and an application (108) configured to control the mobile communication device (100, 800, 802, 804) to execute the method, wherein the method comprises authentication of the terminal (118) by the mobile communication device (100, 800, 802, 804) and authentication of the mobile communication device (100, 800, 802, 804) by the terminal (118).