Proxy Authentication via Location-Constrained Service Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems for providing services based on user presence at specific locations, such as shops or NFC tags, often result in users who are not physically present receiving benefits intended for others, leading to inefficiencies and incorrect authentication of user locations.

Innovation Solution

A proxy authentication method where a communication device acquires equipment identification information from a site equipment, transmits it to a server, and provides this information to another device within a confined range based on conditions related to time and distance, ensuring that services are only provided to users who are physically present.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a communication device reads equipment identification information from a terminal or tag to provide services, then service provision convenience is improved, but authentication accuracy deteriorates because users not physically present can receive benefits

Engineering Contradiction:
Improveservice provision convenienceVSAvoidauthentication accuracy
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent introduces a server as an intermediary between the communication device and the service provision system. The server receives equipment identification information from the communication device, determines whether the device exists in a specific place based on this information, and then provides services accordingly. This intermediary layer ensures that service provision is tied to actual physical presence while maintaining ease of operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements a feedback mechanism where the server sends determination results about the communication device's physical presence back to the communication device. This feedback loop ensures that services are only provided when the device is confirmed to be in the specific location, thereby maintaining authentication accuracy while allowing convenient service access.

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If equipment identification information is transmitted to multiple communication devices, then service accessibility is improved, but service security deteriorates because information can be shared beyond the designated range

Engineering Contradiction:
Improveservice accessibilityVSAvoidservice security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies local quality by providing services to communication devices based on their specific local context - whether they are in the predetermined place or range. The server determines service eligibility individually for each device based on its location, allowing broad accessibility while maintaining security through location-specific validation.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system changes the parameter of service provision from universal access to conditional access based on location parameters. The server evaluates whether the communication device meets the location criteria before providing services, thereby maintaining security while allowing flexible access to multiple devices that satisfy the location condition.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10362014B2Proxy authentication method and communication device
Publication Date: 2019.07.23 FUJITSU LTD
  • US10362014B2 patent drawing
  • US10362014B2 patent drawing
  • US10362014B2 patent drawing

AI summary

A proxy authentication method executed by a communication device includes acquiring equipment identification information from equipment, the equipment identification identifying the equipment, transmitting the equipment identification information to a server that provides a service according to the equipment, receiving, from at least one of the server and the equipment, a condition relating to a range confined based on at least one of time and distance, and providing, based on the condition, at least one of the equipment identification information and a value relating to the equipment identification information to another communication device estimated to exist in the range.