Tiered Device Access via Dynamic Unlock Mechanisms

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional computing devices either remain locked with no access or fully unlocked, exposing sensitive content when shared, with static containerization methods being cumbersome in device sharing scenarios.

Innovation Solution

Implementing a system with multiple unlock interfaces (e.g., voice command, gesture, PIN) that dynamically adjust access levels based on user input, using a processor with a request module and policy module to select appropriate security levels and authenticate users, allowing for tiered access to content.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the device is fully unlocked to allow access, then ease of operation is improved, but security is worsened as sensitive content becomes accessible

Engineering Contradiction:
Improvedevice accessVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments device access into multiple levels (first level and second level access) corresponding to different unlock mechanisms. The first unlock mechanism provides access to a first set of applications, while the second unlock mechanism provides access to a second set of applications. This segmentation allows the device to be unlocked for general use while protecting sensitive content behind an additional authentication layer.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different security qualities to different parts of the device ecosystem. The first unlock mechanism has a first timeout value and provides standard access, while the second unlock mechanism has a second timeout value and provides enhanced access to specific applications. Each application or data set can have its own security requirements, allowing localized security policies rather than a blanket approach.

Inventive Principle:
Principle #3Local quality

2Object-affected harmful factors

If containerization applications are used to secure data, then security is improved, but device complexity is worsened due to static and cumbersome implementation

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent implements dynamic security policies that adjust based on runtime conditions. The system monitors usage patterns, device state, and contextual information to dynamically determine which unlock mechanism and timeout values to apply. This replaces static containerization with a flexible, adaptive security framework that automatically adjusts protection levels without requiring complex manual configuration.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes security parameters (timeout values, access levels, unlock mechanisms) based on runtime conditions and policy evaluations. The system can modify timeout durations, switch between different unlock mechanisms, and adjust access permissions dynamically. This parameter-based approach simplifies security management compared to fixed containerization schemes while maintaining strong security controls.

Inventive Principle:
Principle #35Parameter changes

3Object-affected harmful factors

If multiple unlock mechanisms are implemented for tiered access, then security is improved, but ease of operation is worsened due to additional authentication steps

Engineering Contradiction:
Improvesecurity protectionVSAvoidauthentication process
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent applies partial authentication for partial access. Users can unlock the device with a first mechanism (such as a simple PIN or biometric) to access commonly used applications without providing full authentication. The second unlock mechanism (such as a password or more complex biometric verification) is only required when accessing specific protected applications. This partial action approach provides adequate security for most operations while maintaining ease of use.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system automatically determines which unlock mechanism and timeout policy to apply based on the requested operation and current device state. Rather than requiring users to manually select authentication methods or configure security settings, the system self-manages the authentication process, selecting appropriate security levels and timeout values based on embedded policies and runtime conditions.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP2901352B1Allowing varied device access based on different levels of unlocking mechanisms
Publication Date: 2020.08.19 INTEL CORP
  • EP2901352B1 patent drawingFigure 1
  • EP2901352B1 patent drawingFigure 2
  • EP2901352B1 patent drawingFigure 3

AI summary

Systems and methods may provide for receiving runtime input from one or more unlock interfaces of a device and selecting a level of access with regard to the device from a plurality of levels of access based on the runtime input. The selected level of access may have an associated security policy, wherein an authentication of the runtime input may be conducted based on the associated security policy. In one example, one or more cryptographic keys are used to place the device in an unlocked state with regard to the selected level of access if the authentication is successful. If the authentication is unsuccessful, on the other hand, the device may be maintained in a locked state with regard to the selected level of access.