Time-bound Secure Access Using Cryptographic Tokens
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing access control systems face challenges in securely granting access to locations without physical keys or entry cards, especially in densely populated areas or areas with limited network access, leading to potential unauthorized access due to reliance on PINs and manual transmission methods.
Innovation Solution
A time-bound secure access system using cryptographic tokens and digital signatures, where a user device generates and stores a token after a request is made via a network, allowing access through a digital signature verification process even without network connectivity, ensuring secure and authorized access within a specified time frame.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If PIN transmission methods are used for access control, then access can be granted without physical keys, but security is compromised in densely populated areas or areas without network access
Solution Approach 1:
The system performs preliminary actions by generating and storing cryptographic tokens and digital signatures in advance on the user's device. The access control system receives and verifies these pre-generated credentials before granting access, eliminating the need for real-time PIN transmission and ensuring security even without network connectivity during access.
Solution Approach 2:
The patent replaces the mechanical/manual PIN transmission system with a cryptographic system using digital signatures and tokens. Instead of transmitting PINs through potentially insecure channels (including manual writing), the system uses cryptographic verification where the user's device generates a digital signature that the access control system can verify without needing to receive the actual PIN.
2Extent of automation
If network communication is required for access control, then centralized authentication is possible, but access cannot be granted in areas without network connectivity
Solution Approach 1:
The system performs preliminary authentication by having the user's device generate cryptographic tokens and digital signatures before the actual access attempt. These pre-generated credentials are stored locally on the device, enabling the user to access the premises even when network connectivity is unavailable at the time of access, while still maintaining centralized authentication architecture.
Solution Approach 2:
The cryptographic token and digital signature act as intermediaries between the user and the access control system. Instead of requiring direct network communication between the user's device and the access control system at the moment of access, the digital signature serves as a mediator that carries the authentication information, allowing verification to occur offline.
3Adaptability or versatility
If manual PIN maintenance methods are used, then users can access locations without network access, but security is compromised due to potential unauthorized access
Solution Approach 1:
The patent replaces manual PIN maintenance methods with an automated cryptographic system. The user's device automatically generates digital signatures using stored cryptographic keys, eliminating the need for manual PIN writing and maintenance. This substitution provides both offline access capability and enhanced security through cryptographic verification.
Solution Approach 2:
The user's device performs self-service by generating and storing its own cryptographic tokens and digital signatures locally. The device can independently create authentication credentials without requiring external input or manual maintenance, and the access control system can verify these self-generated credentials, providing both convenience and security.
Data Source
AI summary
Described herein is a system and remote server that may enable a user device to gain access to a secure physical area or physical resource. The remote server may generate, store, and send a first access token to a user device in response to a request to access the physical area or physical resource. The remote server can receive an authentication request from a universal access control device at the location of the physical area or physical resource. The authentication request can contain a second access token and location information of the user device. The remote server can verify the second access token by comparing it to the stored first access token and location information about the access control device. Upon authentication and verification, the user device may gain entry to the secure area.


