UWB Access Control Authentication Without Host Processor Delays
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
UWB access control operations in public transport systems experience delays due to the need for session tokens to be routed via a host processor, leading to inefficiencies and user inconvenience.
Innovation Solution
A UWB system that facilitates direct interaction between a user device and an access control device, utilizing a secure element and UWB anchor to perform mutual authentication and secure data exchange without relying on the host processor, thereby reducing the need for processor involvement and streamlining access control operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If session tokens are routed via the host processor for access control operations, then authentication can be performed, but access delay increases
Solution Approach 1:
The patent segments the authentication process into two parts: secure element handles token generation and validation, while host processor handles other tasks. This segmentation allows authentication to proceed independently without blocking the host processor, reducing access delay while maintaining reliability
Solution Approach 2:
The secure element acts as an intermediary between the UWB communication interface and the host processor. It receives authentication requests, validates session tokens, and communicates results back, eliminating the need for the host processor to handle time-sensitive authentication operations directly
2Reliability
If the host processor handles access control operations, then authentication can be performed, but user experience deteriorates due to prompts
Solution Approach 1:
The patent extracts the authentication handling from the host processor and places it in the secure element. This extraction eliminates the host processor's ability to prompt the user during authentication, as the secure element operates autonomously to validate tokens and grant access without user intervention
Solution Approach 2:
The secure element performs self-service authentication by independently validating session tokens and making access decisions. This self-service capability eliminates the need for host processor intervention and user prompts, creating a seamless authentication experience
3Reliability
If the host processor is occupied with access control operations, then authentication can be performed, but overall system productivity decreases
Solution Approach 1:
The patent segments system responsibilities by assigning authentication operations to the secure element and other tasks to the host processor. This segmentation enables parallel execution of authentication and other productivity-critical operations, improving overall system efficiency without compromising authentication reliability
Solution Approach 2:
The secure element serves as an intermediary that handles authentication operations independently, allowing the host processor to remain available for other tasks. This intermediary architecture ensures authentication reliability while maintaining high system productivity through concurrent operation
Data Source
AI summary
An ultra-wideband (UWB) system of a user device is disclosed. The UWB system receives a session identifier associated with a first session key from an access control device to facilitate an access control operation for the user device. Based on successful mutual authentication between the user device and the access control device, a secure data exchange session is scheduled between the user device and the access control device based on the first session key and a second session key that is generated by a secure element of the user device. First transaction payloads that include the session identifier are received from the access control device during the secure data exchange session. The first transaction payloads are decrypted by way of a ranging payload set, to generate second transaction payloads. The access control operation is executed based on the second transaction payloads.


