Wireless Authentication System with Key Exchange
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Authentication using passwords alone is inadequate for securing corporate resources, and existing solutions like smartcards are inconvenient and prone to security threats such as tailgating and certification storage on mobile devices.
Innovation Solution
A wireless authentication system that uses key exchanges and keyholder verifications, where authentication devices communicate with user devices to securely verify credentials and grant access to resources, incorporating proximity detection and optional additional security measures like PINs or gestures, with an expiration policy for verification validity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If passwords alone are used for authentication, then ease of operation is improved, but security is worsened
Solution Approach 1:
The patent combines multiple authentication factors (proximity-based wireless authentication, key exchanges, keyholder verifications, and optional biometric/PIN verification) into a unified authentication system. This merging of different authentication mechanisms provides both convenience and security by requiring multiple verification steps while maintaining ease of use through automated proximity detection.
Solution Approach 2:
The patent introduces wireless communication as an intermediary mechanism between the user and the authentication system. Instead of direct physical access or manual password entry, the system uses wireless signals to detect proximity and facilitate key exchanges, thereby improving both security through encrypted communication and ease of operation through automatic authentication.
2Reliability
If smartcards are used for authentication, then security is improved, but ease of operation is worsened
Solution Approach 1:
The patent replaces the mechanical smartcard system with a wireless authentication mechanism. Instead of requiring physical insertion of a smartcard into a reader, the system uses wireless communication to detect user proximity and automatically initiate authentication, eliminating the mechanical interface while maintaining security through encrypted key exchanges.
Solution Approach 2:
The authentication system performs self-service by automatically detecting user proximity through wireless signals and initiating authentication without requiring manual intervention. The system autonomously manages the key exchange and verification processes, eliminating the need for users to physically handle smartcards while maintaining strong security.
3Ease of operation
If proximity-based authentication is implemented, then ease of operation is improved, but security is worsened due to tailgating and mobile device storage
Solution Approach 1:
The patent implements preliminary authentication actions by verifying user identity and validating cryptographic keys before granting access based on proximity detection. The system performs preliminary key exchanges and keyholder verifications to ensure that the person detected via wireless signals is indeed the authorized user, preventing tailgating attempts while maintaining convenient access.
Solution Approach 2:
The authentication system dynamically adjusts its verification requirements based on the authentication context. When proximity is detected, the system dynamically initiates key exchanges and optional biometric verifications, creating a flexible authentication flow that adapts to different scenarios while maintaining strong security against unauthorized access.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A wireless authentication system for authenticating a user before allowing access to a protected resource is described herein. An authentication device receives an indication of an intent to access a protected resource. The authentication device sends a request for a key. The wireless user device and the authentication device may engage in a key exchange. The authentication device determines whether the one or more keys obtained via the key exchange are valid and may allow access to the protected resource if the one or more keys are valid. The authentication device may request further verification of the identity of the user, such as a keyholder verification. The authentication device may allow access to the protected resource if the key and the keyholder verification are valid.