Proximity-Based Authentication for Automatic Logoff

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional username/password authentication processes are cumbersome and often lead to insecure situations where users forget to log off, leaving systems vulnerable to unauthorized access, prompting the need for more efficient and secure login methods.

Innovation Solution

The implementation of an efficient logon system utilizing radio frequency identification (RFID), near-field communications (NFC), Bluetooth, or other short-range communications to detect user devices and request additional authentication, such as PINs or biometric information, to securely log users into systems, with automatic logoff mechanisms triggered by proximity or calendar events.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional username/password authentication is used, then users can access the system, but the process is cumbersome and users may forget to log off, creating security vulnerabilities

Engineering Contradiction:
Improvelogin convenienceVSAvoidsystem security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces the mechanical interaction of typing username and password with automatic detection technologies (RFID, NFC, Bluetooth, cameras, microphones) that automatically identify users through their devices or biometric characteristics, eliminating manual credential entry and improving both convenience and security

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system performs automatic user identification and authentication without requiring active user participation in the credential entry process. The detection devices automatically scan for and identify user devices or biometric traits, and the system automatically manages logoff based on detected presence or absence, reducing human error and improving security

Inventive Principle:
Principle #25Self-service

2Reliability

If manual username/password entry is required, then authentication can be performed, but user convenience is reduced and security risks increase due to human error

Engineering Contradiction:
Improveauthentication securityVSAvoidlogin time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary detection of user devices or biometric characteristics before authentication is formally required. RFID tags, NFC devices, or biometric data are detected and pre-validated, so that when the user approaches or uses the system, authentication is already prepared or automatically completed, reducing login time while maintaining security

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Manual typing of credentials is replaced with automatic detection and recognition systems that instantly identify users through their devices or physical characteristics, eliminating the time-consuming process of manual entry while enhancing security through more reliable identification methods

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Extent of automation

If automatic detection of user presence is implemented, then logoff can be automated, but additional authentication mechanisms are required

Engineering Contradiction:
Improveautomatic logoffVSAvoidauthentication system complexity
Core Design Contradiction:
Extent of automationVSDevice complexity

Solution Approach 1:

The patent employs multi-functional detection devices that can perform both authentication and presence detection using the same hardware (RFID readers, NFC antennas, cameras, microphones). These devices serve multiple purposes: identifying user credentials for login and continuously monitoring user presence for automatic logoff, reducing overall system complexity despite the enhanced automation capabilities

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

User devices equipped with RFID tags, NFC capabilities, or biometric sensors serve as intermediaries that carry authentication information and presence indicators. These intermediary devices enable the system to automatically authenticate and monitor users without requiring complex centralized verification systems, simplifying the overall architecture while enabling automatic logoff functionality

Inventive Principle:
Principle #24Intermediary (Mediator)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This approach enhances security by reducing the need for manual username/password entry, improving user convenience, and automatically managing access based on user presence or absence, thereby minimizing unauthorized access and improving system security.

Implementation Method 1

The efficient logon system may utilize radio frequency identification (RFID), near-field communications (NFC), Bluetooth, or other short-range communications to detect that a user device is near an enterprise device

Methodology Applied
Scientific EffectRadio frequency identification (RFID): Electromagnetic Induction

Implementation Method 2

The efficient logon system may utilize radio frequency identification (RFID), near-field communications (NFC), Bluetooth, or other short-range communications to detect that a user device is near an enterprise device

Methodology Applied
Scientific EffectNear-field communications (NFC): Electromagnetic Induction

Data Source

PatentUS11816199B1Efficient logon
Publication Date: 2023.11.14 UNITED SERVICES AUTOMOBILE ASSOCIATION (USAA)
  • US11816199B1 patent drawing
  • US11816199B1 patent drawing
  • US11816199B1 patent drawing

AI summary

The technology described herein detects a first device associated with a user that is within a detectable range of a second device. The system requests authentication information. In response to receiving the authentication information, a token generator associated with the user can generate a secure token. The secure token can be sent to the server. Once the secure token is verified, the user is granted access to one or more services.