Offline Authentication Key Object for Secure Vehicle Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for secure access and authorization to technical apparatuses, such as vehicles, using new identification techniques like magnetic cards, chip cards, and mobile devices are inadequate as they often lack secure validation checks, especially when offline, and are vulnerable to manipulation due to the inherent insecurity of mobile terminals.
Innovation Solution
A method involving a mobile terminal, an external device, and a technical apparatus where a reservation request is encrypted with an apparatus-specific password, allowing authentication and authorization without requiring an online connection, ensuring only the technical apparatus can decrypt and validate the user's access, using radio or wire connections for data transmission.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If online checking is performed to ensure security, then authentication reliability is improved, but system availability deteriorates when connection is unavailable
Solution Approach 1:
The system performs preliminary authentication by embedding validated authorization data into a key object before offline use. The external device checks user credentials and generates an encrypted key object containing authorization information, which is then stored locally in the technical apparatus. This allows the apparatus to authenticate users offline without requiring real-time connection to the external device, resolving the contradiction between authentication reliability and system availability.
2Ease of operation
If mobile terminals are used for key storage, then ease of operation is improved, but security deteriorates due to manipulability
Solution Approach 1:
The system extracts the authorization data from the mobile terminal environment and transfers it to a dedicated key object stored in the technical apparatus. Instead of relying on the mobile terminal's storage and processing capabilities, the authenticated key object is moved to the technical apparatus where it can be securely validated. This separates the convenience of mobile access from the security requirements of authorization validation.
Solution Approach 2:
The key object serves as an intermediary between the mobile terminal and the technical apparatus. The external device creates this intermediary key object that contains all necessary authorization information, which then mediates the authentication process between the user's mobile terminal and the technical apparatus. This intermediary structure eliminates direct trust requirements between the mobile terminal and the technical apparatus, enhancing security while maintaining ease of operation.
3Adaptability or versatility
If keys are digitally transmitted and temporally limited, then adaptability is improved, but device complexity increases
Solution Approach 1:
The system performs preliminary configuration of temporal and contextual constraints within the key object during the authentication process. The external device embeds validity periods, usage conditions, and authorization scopes into the key object before it is transferred to the technical apparatus. This pre-configured key object then automatically enforces these constraints during offline authentication, providing adaptability for different usage scenarios without requiring complex real-time validation logic in the technical apparatus.
Data Source
AI summary
A method and a system transmit data between a technical apparatus which has a reception unit, a transmission unit and a computer unit, an external device which has a reception unit, a transmission unit and a computer unit, and a mobile terminal which has a reception unit, a transmission unit and a memory unit. The method and system allow registered, authenticated users to use the mobile terminal to perform safe reservation or enabling for a technical apparatus, without requiring an online connection and check between the technical apparatus and the external device for the purpose of authorization and authentication of the user.

