WPAN Proximity Authentication for Secure Device Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional authentication systems fail to provide secure proximity access and often require users to re-authenticate for each device, with devices remaining active even when the user is not present.

Innovation Solution

A wireless personal area network (WPAN) system using encrypted communication between WPAN devices, where a WPAN identity reader authenticates users and enables/disables devices based on proximity, employing a token with encryption data and supporting devices like computers, printers, and personal digital assistants.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional authentication mechanisms are used, then user access control is provided, but devices remain active even when the user is not present

Engineering Contradiction:
Improveaccess controlVSAvoidunauthorized access
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system continuously monitors proximity between the authentication token and the electronic device. When the token moves beyond a predetermined distance, the system automatically disables wireless communication capabilities, creating a feedback loop that maintains security based on real-time spatial conditions.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The authentication system transitions from a static one-time authentication model to a dynamic continuous verification model. The device's operational state changes dynamically based on the real-time proximity of the authentication token, enabling or disabling wireless communications as the token enters or exits the proximity zone.

Inventive Principle:
Principle #15Dynamics

2Reliability

If authentication is required for each device, then security is maintained, but user convenience is reduced

Engineering Contradiction:
ImprovesecurityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The authentication token is designed as a universal credential that works across multiple electronic devices within the group. A single token can authenticate and maintain continuous access across different devices, eliminating the need for separate authentication processes for each device while maintaining security through proximity-based verification.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system merges multiple authentication instances into a single continuous authentication session. Instead of requiring separate authentication for each device, the system combines them into one unified proximity-based authentication that covers all devices in the group, reducing repetitive user actions while maintaining security.

Inventive Principle:
Principle #5Merging (Combining)

3Ease of operation

If wireless communication is always enabled, then device accessibility is maintained, but security vulnerabilities increase

Engineering Contradiction:
Improvedevice accessibilityVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

Instead of continuous wireless communication, the system implements periodic proximity verification. The device checks for the presence of the authentication token at regular intervals and only maintains wireless communication when the token is detected within the predetermined proximity distance, creating periodic security checks rather than continuous operation.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The authentication token acts as an intermediary that mediates between the user and the electronic device's wireless communication capabilities. The token's presence or absence controls whether wireless communication is enabled or disabled, serving as a security gatekeeper that allows accessibility only when properly authenticated.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8553885B2Wireless personal area network having authentication and associated methods
Publication Date: 2013.10.08 BLACKBERRY LTD
  • US8553885B2 patent drawing
  • US8553885B2 patent drawing
  • US8553885B2 patent drawing

AI summary

A wireless personal area network (WPAN) system includes a plurality of WPAN devices using encrypted wireless communication therebetween when in an enabled state and not wirelessly communicating when in a disabled state. At least one of the WPAN devices includes a WPAN identity reader for reading at least one identifying parameter of a user, for confirming that the user is an authorized user based upon reading the at least one identifying parameter, and for wirelessly communicating with at least one other WPAN device to switch the at least one other WPAN device from the disabled state to the enabled state based upon confirming the user is an authorized user.