Secure Ranging Access Control in Congested Wireless Environments
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing access control methods in crowded environments face inefficiencies and security challenges due to the time-consuming nature of credential authentication, privacy concerns with contactless methods, and interference issues in wireless communication, particularly in congested settings like subways.
Innovation Solution
A method involving contention-based discovery and secure ranging techniques, where mobile devices receive polling messages, select timeslots for response, and establish secure channels with access devices using public keys, allowing efficient and secure credential exchange.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If wireless communication is used for contactless authentication, then authentication speed is improved, but message collision and body attenuation occur in crowded environments
Solution Approach 1:
The communication process is segmented into three distinct phases (polling phase, response phase, final phase) with each phase having dedicated timeslots. This segmentation prevents message collisions by ensuring that only specific devices transmit during specific timeslots, thereby maintaining communication reliability while preserving fast authentication speeds.
Solution Approach 2:
The system dynamically assigns timeslots to devices based on their identification and communication needs. During the polling phase, access devices dynamically select timeslots for the response phase, and during the final phase, timeslots are dynamically assigned for secure ranging. This dynamic allocation optimizes resource usage and prevents collisions in crowded environments.
2Reliability
If physical credentials are used for authentication, then security and privacy are improved, but authentication efficiency deteriorates due to manual presentation
Solution Approach 1:
The patent replaces the mechanical system of physical credential presentation with a wireless communication system. Mobile devices automatically exchange authentication messages with access devices through wireless communication, eliminating the need for manual credential presentation while maintaining security through encrypted message exchange and public key infrastructure.
3Productivity
If facial recognition is used for contactless authentication, then authentication efficiency is improved, but privacy concerns increase
Solution Approach 1:
The patent uses public keys and encrypted messages as intermediaries between the mobile device and access device. Instead of directly exposing personal biometric data, the system exchanges cryptographic credentials that mediate the authentication process, thereby maintaining authentication efficiency while protecting user privacy through cryptographic abstraction.
4Productivity
If multiple mobile devices communicate simultaneously with access devices, then access control throughput is improved, but message collision increases
Solution Approach 1:
The system implements periodic action by organizing communication into distinct phases (polling phase, response phase, final phase) with regular timeslots. Each phase performs a specific function and occurs at predetermined intervals, allowing multiple devices to communicate systematically without collisions while maintaining high throughput.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A mobile device may receive a plurality of polling messages with each polling message including an identifier of a particular access device transmitting the polling message. Each polling message of the plurality of polling messages may be transmitted during a polling phase. The mobile device may select a timeslot of a response phase of a communication session. The mobile device may transmit a response message during the timeslot of the response phase. The mobile device may receive, during a third phase, an assignment message including an assigned timeslot for a response phase of a future session. The mobile device may perform secure ranging with one or more access devices of the plurality of access devices during the future session using the assigned timeslot. The mobile device may provide an access credential to the one or more access devices based on a location determined using the secure ranging.