Time-bound Secure Access Using Cryptographic Tokens

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access control systems face challenges in securely granting access to locations without physical keys or entry cards, especially in densely populated areas or areas with limited network access, leading to potential unauthorized access due to reliance on PINs and manual transmission methods.

Innovation Solution

A time-bound secure access system using cryptographic tokens and digital signatures, where a user device generates and stores a token after a request is made via a network, allowing access through a digital signature verification process even without network connectivity, ensuring secure and authorized access within a specified time frame.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If PIN transmission methods are used for access control, then access can be granted without physical keys, but security is compromised in densely populated areas or areas without network access

Engineering Contradiction:
Improveaccess method flexibilityVSAvoidaccess security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary actions by generating and storing cryptographic tokens and digital signatures in advance on the user's device. The access control system receives and verifies these pre-generated credentials before granting access, eliminating the need for real-time PIN transmission and ensuring security even without network connectivity during access.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces the mechanical/manual PIN transmission system with a cryptographic system using digital signatures and tokens. Instead of transmitting PINs through potentially insecure channels (including manual writing), the system uses cryptographic verification where the user's device generates a digital signature that the access control system can verify without needing to receive the actual PIN.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Extent of automation

If network communication is required for access control, then centralized authentication is possible, but access cannot be granted in areas without network connectivity

Engineering Contradiction:
Improvecentralized authenticationVSAvoidaccess availability
Core Design Contradiction:
Extent of automationVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary authentication by having the user's device generate cryptographic tokens and digital signatures before the actual access attempt. These pre-generated credentials are stored locally on the device, enabling the user to access the premises even when network connectivity is unavailable at the time of access, while still maintaining centralized authentication architecture.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The cryptographic token and digital signature act as intermediaries between the user and the access control system. Instead of requiring direct network communication between the user's device and the access control system at the moment of access, the digital signature serves as a mediator that carries the authentication information, allowing verification to occur offline.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If manual PIN maintenance methods are used, then users can access locations without network access, but security is compromised due to potential unauthorized access

Engineering Contradiction:
Improveoffline access capabilityVSAvoidaccess security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent replaces manual PIN maintenance methods with an automated cryptographic system. The user's device automatically generates digital signatures using stored cryptographic keys, eliminating the need for manual PIN writing and maintenance. This substitution provides both offline access capability and enhanced security through cryptographic verification.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The user's device performs self-service by generating and storing its own cryptographic tokens and digital signatures locally. The device can independently create authentication credentials without requiring external input or manual maintenance, and the access control system can verify these self-generated credentials, providing both convenience and security.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11438169B2Time-bound secure access
Publication Date: 2022.09.06 AMAZON TECH INC
  • US11438169B2 patent drawing
  • US11438169B2 patent drawing
  • US11438169B2 patent drawing

AI summary

Described herein is a system and remote server that may enable a user device to gain access to a secure physical area or physical resource. The remote server may generate, store, and send a first access token to a user device in response to a request to access the physical area or physical resource. The remote server can receive an authentication request from a universal access control device at the location of the physical area or physical resource. The authentication request can contain a second access token and location information of the user device. The remote server can verify the second access token by comparing it to the stored first access token and location information about the access control device. Upon authentication and verification, the user device may gain entry to the secure area.