Proximity-Based Token Authentication for Unsecured Channels

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current communication systems lack a secure method for transferring data between unidentified devices over unsecured channels, particularly in scenarios where devices are not constantly connected to secure servers or are in proximity to each other.

Innovation Solution

A secure communication system that involves a server sending an access token over a secured channel to a device, which then sends a second token over an unsecured channel to a terminal for authentication, allowing secure communication between unidentified devices using a communication module and sensors to detect proximity and manage token validity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If devices communicate over an unsecured channel to enable occasional data transfer between unidentified devices, then communication flexibility and accessibility are improved, but security and data protection deteriorate

Engineering Contradiction:
Improvecommunication flexibilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

A server acts as an intermediary between the first device and terminal. The server receives a request from the first device, generates a secure access token, and provides it to the first device over a secured channel. This intermediary mechanism enables secure communication between unidentified devices over unsecured channels without requiring direct pairing or constant connection to secure servers.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary actions by generating and distributing access tokens before the actual data transfer occurs. The server creates the access token in advance based on the request, and this token is then used to authenticate and protect the subsequent communication over the unsecured channel. The token includes expiration time and other security parameters prepared beforehand.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If devices are required to have constant secure connection with servers to ensure security, then security is improved, but device complexity and connection requirements worsen

Engineering Contradiction:
ImprovesecurityVSAvoidconnection requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system extracts the security verification function from the communication channel itself and relocates it to the access token. Instead of requiring constant secure connection verification, the security parameters (authentication, authorization, expiration) are extracted into a self-contained token that can be verified independently during communication over unsecured channels.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The access token enables the first device to self-authenticate with the terminal without requiring continuous server verification. The token contains all necessary security credentials that allow the device to prove its identity and authority independently, reducing the need for constant connection to secure servers.

Inventive Principle:
Principle #25Self-service

3Reliability

If proximity detection is implemented to ensure secure local communication, then security is improved, but device complexity and sensor requirements worsen

Engineering Contradiction:
ImprovesecurityVSAvoidsensor requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The access token mechanism serves multiple functions simultaneously: it provides authentication, authorization, proximity verification (through embedded location data), and communication protection. This multi-functional approach consolidates what would otherwise require separate sensor systems into a single token-based solution that works with existing communication hardware.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11924249B2System and method for distance based secured communication over an unsecure communication channel
Publication Date: 2024.03.05 SENSEPASS LTD
  • US11924249B2 patent drawing
  • US11924249B2 patent drawing
  • US11924249B2 patent drawing

AI summary

Methods and systems for secure communication over an unsecure communication channel, including a server, to send at least one access token to a computerized device over a secured communication channel, and a terminal, to receive from the computerized device, over an unsecure communication channel, at least a second token, where said second token is based on the access token received from the server.