Proximity-Based Access Using Server-Mediated Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication methods for devices and resources often require user input, such as passwords or biometrics, which can be inconvenient and introduce latency due to power-saving modes in mobile devices that limit frequent wireless transmissions, leading to delays in detecting proximity and granting access.

Innovation Solution

A method that uses proximity-based access, where a trusted device serves as a security token, allowing automatic access by detecting the presence of a designated mobile device through wireless communication, leveraging a second communication channel to enhance transmission frequency and reliability, and utilizing a server to forward authentication data for seamless access without direct wireless connection establishment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Use of energy by moving object

If power-saving modes are used in mobile devices to limit frequent wireless transmissions, then power consumption is reduced, but proximity detection latency increases

Engineering Contradiction:
Improvepower consumptionVSAvoidproximity detection latency
Core Design Contradiction:
Use of energy by moving objectVSLoss of time

Solution Approach 1:

The mobile device performs preliminary actions by maintaining a low-power listening mode where it periodically checks for proximity signals without engaging in full wireless communication. This allows the device to be ready for quick authentication when needed while consuming minimal power during normal operation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The wireless transmission frequency is made dynamic rather than static. The mobile device transitions between low-power listening mode and active transmission mode based on whether proximity authentication is required. This dynamic adjustment resolves the contradiction by adapting power consumption and detection speed to actual operational needs.

Inventive Principle:
Principle #15Dynamics

2Reliability

If direct wireless communication channels are established between devices for proximity detection, then authentication reliability is improved, but connection establishment latency increases

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidconnection establishment latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Device identifiers and authentication credentials are exchanged and cached in advance during an initial pairing phase. When proximity authentication is needed later, the devices can immediately use the pre-exchanged credentials without establishing a full direct wireless connection, thus maintaining reliability while reducing latency.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

A server acts as an intermediary to facilitate authentication by relaying verification requests and responses. This allows the mobile device and resource device to authenticate through the server without requiring a direct wireless connection between them, reducing connection establishment latency while maintaining authentication reliability through server-mediated verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If manual authentication input is required from users, then security is improved, but ease of operation deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidease of access
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The authentication system performs self-service by automatically verifying the mobile device's proximity to the resource device and completing the authentication process without requiring manual user input. The system uses pre-configured credentials and proximity detection to automatically grant or deny access, maintaining security through cryptographic verification while dramatically improving ease of operation.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The manual mechanical action of typing passwords or entering biometrics is replaced with an automated electronic proximity detection system. The mobile device's location and authentication status are determined through wireless signal analysis and server-mediated verification, substituting manual authentication mechanisms with automated electronic processes that maintain security while improving convenience.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This approach enables quick and reliable automatic access to resources by reducing latency and conserving power, allowing users to access devices and logical resources without manual input, while maintaining security and power efficiency.

Implementation Method 1

Proximity between two devices can be detected based on direct, wireless communication between the devices. For example, the devices can communicate over a short-range wireless communication protocol, such as Bluetooth.

Methodology Applied
Scientific EffectElectromagnetic radiation: Electromagnetic Induction

Implementation Method 2

A device may determine that another device is within a predetermined level of proximity of communications from the other device are received with a signal strength above a predetermined minimum threshold.

Methodology Applied
Scientific EffectElectromagnetic signal detection: Electromagnetic Induction

Implementation Method 3

A communication over the second communication channel can also enable the mobile device to provide authentication data, such as a password, over this second communication channel rather than the direct wireless communication channel.

Methodology Applied
Scientific EffectElectromagnetic signal transmission: Electromagnetic Induction

Data Source

PatentUS11520870B2Proximity-based access
Publication Date: 2022.12.06 STRATEGY INC
  • US11520870B2 patent drawing
  • US11520870B2 patent drawing
  • US11520870B2 patent drawing

AI summary

Methods, systems, and apparatus, including computer programs encoded on a computer storage medium, for proximity-based access. In some implementations, a computing device detects an attempt to access the computing device while the computing device is in a secured state. In response to detecting the attempt to access the computing device, the computing device sends a first message to a server system over a network. After sending the message, the computing device receives a second message from the server system over the network, the second message comprising authentication data for the computing device. The computing device determines that a mobile device that was previously designated as an authentication factor for accessing the computing device is located within a predetermined level of proximity of the computing device, and the computing device grants access to the computing device.