Proximity-Based Access Using Server-Mediated Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication methods for devices and resources often require user input, such as passwords or biometrics, which can be inconvenient and introduce latency due to power-saving modes in mobile devices that limit frequent wireless transmissions, leading to delays in detecting proximity and granting access.
Innovation Solution
A method that uses proximity-based access, where a trusted device serves as a security token, allowing automatic access by detecting the presence of a designated mobile device through wireless communication, leveraging a second communication channel to enhance transmission frequency and reliability, and utilizing a server to forward authentication data for seamless access without direct wireless connection establishment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Use of energy by moving object
If power-saving modes are used in mobile devices to limit frequent wireless transmissions, then power consumption is reduced, but proximity detection latency increases
Solution Approach 1:
The mobile device performs preliminary actions by maintaining a low-power listening mode where it periodically checks for proximity signals without engaging in full wireless communication. This allows the device to be ready for quick authentication when needed while consuming minimal power during normal operation.
Solution Approach 2:
The wireless transmission frequency is made dynamic rather than static. The mobile device transitions between low-power listening mode and active transmission mode based on whether proximity authentication is required. This dynamic adjustment resolves the contradiction by adapting power consumption and detection speed to actual operational needs.
2Reliability
If direct wireless communication channels are established between devices for proximity detection, then authentication reliability is improved, but connection establishment latency increases
Solution Approach 1:
Device identifiers and authentication credentials are exchanged and cached in advance during an initial pairing phase. When proximity authentication is needed later, the devices can immediately use the pre-exchanged credentials without establishing a full direct wireless connection, thus maintaining reliability while reducing latency.
Solution Approach 2:
A server acts as an intermediary to facilitate authentication by relaying verification requests and responses. This allows the mobile device and resource device to authenticate through the server without requiring a direct wireless connection between them, reducing connection establishment latency while maintaining authentication reliability through server-mediated verification.
3Reliability
If manual authentication input is required from users, then security is improved, but ease of operation deteriorates
Solution Approach 1:
The authentication system performs self-service by automatically verifying the mobile device's proximity to the resource device and completing the authentication process without requiring manual user input. The system uses pre-configured credentials and proximity detection to automatically grant or deny access, maintaining security through cryptographic verification while dramatically improving ease of operation.
Solution Approach 2:
The manual mechanical action of typing passwords or entering biometrics is replaced with an automated electronic proximity detection system. The mobile device's location and authentication status are determined through wireless signal analysis and server-mediated verification, substituting manual authentication mechanisms with automated electronic processes that maintain security while improving convenience.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
This approach enables quick and reliable automatic access to resources by reducing latency and conserving power, allowing users to access devices and logical resources without manual input, while maintaining security and power efficiency.
Implementation Method 1
Proximity between two devices can be detected based on direct, wireless communication between the devices. For example, the devices can communicate over a short-range wireless communication protocol, such as Bluetooth.
Implementation Method 2
A device may determine that another device is within a predetermined level of proximity of communications from the other device are received with a signal strength above a predetermined minimum threshold.
Implementation Method 3
A communication over the second communication channel can also enable the mobile device to provide authentication data, such as a password, over this second communication channel rather than the direct wireless communication channel.
Data Source
AI summary
Methods, systems, and apparatus, including computer programs encoded on a computer storage medium, for proximity-based access. In some implementations, a computing device detects an attempt to access the computing device while the computing device is in a secured state. In response to detecting the attempt to access the computing device, the computing device sends a first message to a server system over a network. After sending the message, the computing device receives a second message from the server system over the network, the second message comprising authentication data for the computing device. The computing device determines that a mobile device that was previously designated as an authentication factor for accessing the computing device is located within a predetermined level of proximity of the computing device, and the computing device grants access to the computing device.


