NFC/UWB Non-Contact Authentication for Automated Key Recovery

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication methods for key recovery and platform security provisioning often require manual intervention and secure connections, which can be time-consuming and costly, especially when relying on cloud-based storage and VPN connections.

Innovation Solution

Implementing non-contact authentication through secure near-field communication (NFC) and ultra-wideband (UWB) interfaces for automated backup and synchronization of access credentials to personal accessories, utilizing a secure component as a secondary root of trust, with geo-location presence detection for enhanced security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual intervention and secure connections (VPN) are used for key recovery and platform security provisioning, then security is maintained, but time consumption and costs increase

Engineering Contradiction:
ImprovesecurityVSAvoidtime consumption
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by automatically backing up access credentials to a secure component before they are needed for recovery. The secure component stores authentication keys and credentials in advance, eliminating the need for manual intervention during key recovery operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The secure component autonomously manages the backup and recovery of access credentials without requiring manual intervention. The system self-services by automatically synchronizing credentials between the secure component and external credential stores, reducing both time consumption and operational costs.

Inventive Principle:
Principle #25Self-service

2Adaptability or versatility

If cloud-based storage and VPN connections are used for credential management, then centralized control is achieved, but operational costs increase

Engineering Contradiction:
Improvecentralized controlVSAvoidoperational costs
Core Design Contradiction:
Adaptability or versatilityVSLoss of energy

Solution Approach 1:

The system extracts the critical security function of credential storage from the cloud-based infrastructure and places it in a local secure component. This extraction maintains centralized control through the authentication manager while eliminating the need for continuous VPN connections and cloud storage operations, thereby reducing operational costs.

Inventive Principle:
Principle #2Taking out (Extraction)

3Productivity

If automated backup and synchronization is implemented through non-contact authentication, then time and costs are reduced, but system complexity increases

Engineering Contradiction:
Improveautomation efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The authentication manager serves as an intermediary that coordinates between the secure component and external credential stores. It manages the automated backup and synchronization processes, handling the complexity of secure communications and credential management while presenting a simplified interface for key recovery operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250317295A1Non-contact authentication for key recovery and platform security provisioning
Publication Date: 2025.10.09 MICROSOFT TECHNOLOGY LICENSING LLC
  • US20250317295A1 patent drawing
  • US20250317295A1 patent drawing
  • US20250317295A1 patent drawing

AI summary

Secure AI authentication is implemented for selectable environments with a selectable combination of ML models processing selectable input credentials, e.g., biometric and/or non-biometric credentials, such as a key associated with a secure model, user location information, a user gesture credential, and/or a user movement pattern credential. ML models may be selectively applied in serial or parallel in a selected authorization procedure. ML model applicability may vary based on one or more parameters, such as time of day, or one or more detected input credentials, such as user gestures, secure model keys, or biometric voice or face recognition. For example, AI authorization (e.g., for biometric credentials) augmented with an ultra-wideband (UWB) communication protocol provides robust user authentication via a native cryptographic exchange and accurate user location credentials for proximity and geo-fenced confirmation of other user credentials, such as biometric credentials, thereby preventing false positives by spoofing.