Secure Relay Access Control via Mobile BLE and NFC

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional physical access control systems require intrusive user actions and complex backend systems for authentication, which can be cumbersome and inefficient.

Innovation Solution

An automatic identity authentication system utilizing a mobile device, a secure relay device, and cloud infrastructure, employing out-of-band signaling like Bluetooth Low Energy (BLE) and Near Field Communication (NFC) for secure and efficient access control, where the mobile device stores access credentials and the secure relay device grants access based on verified information without needing a backend server connection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional physical access control systems use card readers or PIN entry, then authentication security is maintained, but user convenience and operation speed deteriorate due to intrusive actions

Engineering Contradiction:
Improveuser convenienceVSAvoidauthentication time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent replaces mechanical interaction systems (card swiping, button pressing for PIN entry) with contactless wireless communication systems. The mobile device communicates with the access control system via wireless signals, eliminating the need for physical card insertion or manual keypress operations, thereby significantly improving user convenience and reducing authentication time.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The mobile device automatically performs authentication functions without requiring manual user intervention. The system utilizes the mobile device's existing capabilities (wireless communication, onboard processor) to self-authenticate the user's identity and grant access, eliminating the need for separate authentication devices or manual operations.

Inventive Principle:
Principle #25Self-service

2Device complexity

If physical access control systems use traditional card readers and backend servers, then authentication reliability is maintained, but system complexity increases

Engineering Contradiction:
Improvesystem complexityVSAvoidauthentication reliability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent extracts and removes the backend server component from the traditional access control system architecture. The authentication logic and credential verification capabilities are transferred to the mobile device itself, which contains an onboard processor and secure storage. This eliminates the need for complex server infrastructure while maintaining authentication reliability through device-based security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The mobile device serves multiple functions: it acts as both the credential storage medium and the authentication processor. The single device performs identity verification, secure credential management, and communication with the access control system, replacing multiple separate components (ID cards, card readers, backend servers) with a universal multi-functional platform.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If access control systems require backend server connections, then centralized control is maintained, but operational speed and offline capability deteriorate

Engineering Contradiction:
Improveaccess speedVSAvoidoffline operation capability
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The mobile device pre-stores authentication credentials and security certificates in its secure storage infrastructure before needing to access controlled areas. This preliminary preparation allows the device to perform instant local authentication without requiring real-time network connections or backend server communication, enabling both rapid access and offline operation.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20240054836A1Physical access control system with secure relay
Publication Date: 2024.02.15 ASSA ABLOY AB
  • US20240054836A1 patent drawing
  • US20240054836A1 patent drawing
  • US20240054836A1 patent drawing

AI summary

A method of operating an access control system comprises receiving, by a mobile device, an identification of a physical access portal; verifying access credential information stored in the mobile device using a verification application of the mobile device; establishing a secure communication channel with a secure relay device associated with the physical access portal; sending an encrypted access token stored in the mobile device to the secure relay device; and granting access by the secure relay device to the physical access portal according to the encrypted access token.