NZ574088A - Bluetooth authentication system and method - Google Patents

Bluetooth authentication system and method

Info

Publication number
NZ574088A
NZ574088A NZ57408810A NZ57408810A NZ574088A NZ 574088 A NZ574088 A NZ 574088A NZ 57408810 A NZ57408810 A NZ 57408810A NZ 57408810 A NZ57408810 A NZ 57408810A NZ 574088 A NZ574088 A NZ 574088A
Authority
NZ
New Zealand
Prior art keywords
authorisation
bluetooth
connection
mobile communication
module
Prior art date
Application number
NZ57408810A
Inventor
Nicholas Hedley Willis
Original Assignee
Resonance Holdings Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Resonance Holdings Ltd filed Critical Resonance Holdings Ltd
Priority to NZ57408810A priority Critical patent/NZ574088A/en
Publication of NZ574088A publication Critical patent/NZ574088A/en

Links

Abstract

A method and a central control device for controlling authorisation using an authorisation device and a mobile communication device using a dynamically generated Bluetooth compatible PIN are disclosed. The central control device (101) comprises a control parameter generating module (102), a communication module (103) and a PIN generating module (201). The control parameter generating module is arranged to generate a control parameter (105) and the control parameter is associated with the one or more authorisation devices. The PIN generating module is arranged to generate a Bluetooth compatible PIN based on the control parameter, and the communication module is arranged to communicate the control parameter to the one or more authorisation devices (104A, 104B, 104C) and communicate the PIN to a mobile communication device (203). Also disclosed are a method and an authorisation device for authorising a mobile communication device using an authorisation device. The authorisation device comprises a communication module, response module and control module. The communication module is arranged to discover a mobile communication device using Bluetooth, forward a Bluetooth connection authentication request to the mobile communication device, and receive a Bluetooth authentication response based on a PIN entered on the mobile communication device in response to the authentication request. The response module is arranged to dynamically generate a Bluetooth matching response based on a control parameter, and the control module arranged to determine whether the received Bluetooth authentication response is identical to the Bluetooth matching response and authorise the mobile communication device based upon the determination.

Description

Received at IPONZ 22 June 2012 Our Kef: ECK010NZ Patents Form No. 5 PATENTS ACT 1953 Complete After Provisional No. 574088 Filed 7 January 2009 COMPLETE SPECIFICATION BLUETOOTH AUTHENTICATION SYSTEM AND MFTHOD We, ECKey Corporation, a company incorporated under the laws of Delaware, United States of America, of 3422 Old Capitol Trail, Suite 700, county of New Castle, City of Wilmington 19808-6192, Delaware, United States of America, do hereby declare the invention for which we pray that a patent may be granted to us, and the method by which it is to be performed, to be particularly described in and by the following statement: 1 Received by IPONZ on 15 July 2011 2 BLUETOOTH AUTHENTICATION SYSTEM AND METHOD FIELD OF THE INVENTION The present invention relates to a Bluetooth authentication system and method. In particular, the present invention relates to a method of controlling an authorisation device, a central control device for controlling authorisation using an authorisation device and a mobile communication device, a method of authorising a mobile communication device using an authorisation device, and an 10 authorisation device for authorising a mobile communication device.
BACKGROUND Bluetooth pairing is a simple authentication method that is used by mobile 15 communication devices, such as a mobile (cell) telephones, PDAs and the like. It is a relatively easy to use system that enables two Bluetooth compatible devices to communicate with each other in a local space.
In order to communicate, the two devices are required to link together by way of a 20 Bluetooth pairing mechanism. That is, an authentication request is sent by a first device. This authentication request is based on a PIN set by the user of the first device. The first user also tells the second user the PIN that was used.
An authentication response is returned by the second device using the same PIN. 25 Therefore, the authentication response returned by the second device is based on the same PIN and so the connection is authenticated and established.
Once established a 128 bit link key is used to avoid the need to enter the PIN each time the two devices wish to communicate with each other.
However, as the PIN is fixed, once one person knows the PIN they can share it with others and anyone is then able to gain access. Also, to change the PIN every time requires an authorised user to enter the PIN to validate a user. That is, an administrator who wishes to authorise a user to access a site using a 35 specific Bluetooth access device provides the user with a PIN which allows them to pair their Bluetooth device with the Bluetooth access device. However, the Received by IPONZ on 15 July 2011 3 administrator then needs to provide a new PIN at the access device each time a new user requires access.
PCX application WO 02/095689 describes a security system that includes a 5 central controller, mobile device and access device. The central controller transmits the same authorisation code to both the mobile device and access device. When the mobile device requests access through the access device, the access device forwards an authentication challenge that includes a randomly generated number that is not known by the mobile device. The mobile device 10 uses a portion of the authentication challenge in combination with the authorisation code to create a response. This static response is compared with the expected response by the access device, and access is provided if they are the same. However, this system sends and uses the same static authorisation code for both the mobile device and access device. Further, the system requires 15 the mobile device to be fitted with specific technology that enables it to generate the required response.
US patent US 7,360,248 describes a system that compares the location of a user using their GPS device with the location of the access device to determine if they 20 correspond, and so make the determination of whether to allow access. However, the system does not utilise a Bluetooth compatible PIN to verify the user.
The present invention aims to overcome, or at least alleviate, some or all of the 25 afore-mentioned problems, or to at least provide the public with a useful choice.
SUMMARY OF THE INVENTION According to one aspect, the present invention provides a method of controlling 30 an authorisation device arranged to authorise a mobile communication device using a dynamically generated Bluetooth compatible PIN, the method including the steps of: a central control device generating a control parameter associated with the one or more authorisation devices, the central control device communicating the control parameter to the one or more authorisation devices, 35 the central control device generating a Bluetooth compatible PIN based on the Received by IPONZ on 15 July 2011 4 control parameter, and the centra! control device communicating the PIN to a mobile communication device.
According to a further aspect, the present invention provides a method of 5 authorising a mobile communication device using an authorisation device, the method including the steps of: the authorisation device discovering a mobile communication device using Bluetooth, the authorisation device forwarding a Bluetooth connection authentication request to the mobile communication device, the authorisation device receiving a Bluetooth authentication response based on 10 a PIN entered on the mobile communication device in response to the authentication request, the authorisation device dynamically generating a Bluetooth matching response based on a control parameter, the authorisation device determining whether the received Bluetooth authentication response is identical to the Bluetooth matching response and authorising based upon the 15 determination.
According to yet a further aspect, the present invention provides a central control device for controlling authorisation using an authorisation device and a mobile communication device using a dynamically generated Bluetooth compatible PIN, 20 the central control device including a control parameter generating module, a communication module and a PIN generating module, wherein: the control parameter generating module is arranged to generate a control parameter, the control parameter being associated with the one or more authorisation devices, the PIN generating module is arranged to generate a 25 Bluetooth compatible PIN based on the control parameter, and the communication module is arranged to communicate the control parameter to the one or more authorisation devices and communicate the PIN to a mobile communication device.
According to yet a further aspect, the present invention provides an authorisation device for authorising a mobile communication device, the authorisation device including a communication module, response module and control module: the communication module arranged to discover a mobile communication device using Bluetooth, forward a Bluetooth connection authentication request to the 35 mobile communication device, and receive a Bluetooth authentication response based on a PIN entered on the mobile communication device in response to the Received by IPONZ on 15 July 2011 authentication request, the response module arranged to dynamically generate a Bluetooth matching response based on a PIN generated from a control parameter, and the control module arranged to determine whether the received Bluetooth authentication response is identical to the Bluetooth matching 5 response and authorise the mobile communication device based upon the determination.
BRIEF DESCRIPTION OF THE DRAWINGS Embodiments of the present invention will now be described, by way of example only, with reference to the accompanying drawings, in which: Figure 1 shows a system block diagram of an authorisation system according to 15 an embodiment of the present invention; Figure 2 shows a further system block diagram of an authorisation system according to an embodiment of the present invention; Figure 3 shows a further system block diagram of an authorisation system according to an embodiment of the present invention; DETAILED DESCRIPTION OF THE INVENTION First Embodiment Figure 1 shows a system block diagram of an authorisation system. The system includes a central control device in the form of a management system 101. The central control device includes a control parameter generating module 102 and a communication module 103.
The control parameter generating module generates a control parameter 105 for use by authorisation devices 104A, 104B, 104C etc. It will be understood that there may be one or more readers or authorisation devices 104.
The control parameter 105 is generated at the central control device and then 35 forwarded or communicated to one or more specific authorisation devices. Groups of authorisation devices may receive the same control parameter or different control parameters. The control parameter 105 is produced using a predefined code (for example a number) that is uniquely associated with the Received by IPONZ on 15 July 2011 6 authorisation device or groups of authorisation devices. The code may be randomly generated, or produced using any other suitable method.
The communication module 103 of the central control device 101 in this 5 embodiment is a wireless GSM communication module that is arranged to communicate with a mutually compatible communication module in the authorisation devices over the telecommunications GSM network using the known protocols.
It will be understood that, as an alternative, any other suitable form of wireless data communication connections may also be implemented, such as, for example, a Bluetooth connection, a Wi-Fi connection, any form of radio frequency connection, etc.
Alternatively, the communication module 103 in the central control device may be arranged to communicate with the communication modute(s) in authorisation device(s) over a wired communication link, for example, by using known protocols in the form of an internet protocol connection, a serial bus connection, or a universal serial bus connection, for example.
In this embodiment, the authorisation devices are access devices that allow a user to access a secure area upon a positive authorisation. The authorisation devices are located at specific points where it is required to authorise a user prior to allowing them access to the secure area.
However, it will be understood that the present invention is not limited to any specific process after authorisation, and that the authorisation devices may be used for any other post-authorisation process. For example, the process may be of the form whereby, upon authentication, data is transmitted, an event is triggered, a door is opened, and an event is logged in an audit trail or may be of any other suitable form. The authorisation devices enable the authentication of a user, which then allows the authorisation device to perform a further act or provide an output upon that authorisation.
Figure 2 shows the authorisation system at the next stage of authentication. The central control device 101 is shown to have a PIN generating module 201. The Received by IPONZ on 15 July 2011 7 PIN generated by this module is a Bluetooth compatible PIN for use when discovering Bluetooth communication devices. The PIN generating module 201 generates a PIN for use on a mobile communication device 203, such as a mobile telephone or cell device for example. The PIN, once generated by the 5 PIN generating module, is communicated to the mobile communication device using the communication module 103. In this embodiment, the communication module forwards the PIN to the mobile communication device by SMS.
It will be understood that the PIN may be forwarded to the mobile communication device by any other suitable means. For example, the PIN may be forwarded by displaying the PIN on a page accessed via the Internet where the page is only accessible using suitable login details specific to the user. Alternatively, the PIN may be transmitted via an e-mail message to the user, by voice message, or in a written communication via a postal delivery service, for example.
The PIN generating module 201 generates a PIN based on a number of different parameters. The first parameter is the control parameter 105 that is sent to the authorisation devices.
A second parameter 205 is based on location information for the authorisation device(s) or groups of devices. For example, the location information may be the GPS co-ordinates of the location of the authorisation device. In this embodiment, the location information is retrieved from a database store where each location is associated with a specific authorisation device or group of authorisation devices.
As an alternative, the system may request the latest location information from the authorisation device to ensure that any recent changes in the location of the authorisation device do not affect the ability to enable the authorisation device to correctly authenticate the required users. This is particularly useful where the authorisation devices are not always in a fixed location.
The third parameter 207 is based on temporal information associated with when a user is able to gain authentication. For example, the temporal information may be the time, day or date when it has been determined the user is able to gain authentication.
Received by IPONZ on 15 July 2011 8 The fourth parameter 209 is based on the Bluetooth address of the mobile communication device 203 that will be used to gain authentication, as will be explained later. In this embodiment, the Bluetooth address of the mobile communication device is retrieved from a database 211 that is used to store the 5 parameters discussed above. That is, the administrator of the system has a database record of all Bluetooth addresses of all mobile communication devices for users of the system. Alternatively, the Bluetooth address of the mobile communication device 203 may also be retrieved directly from the mobile communication device via the communication module 103, for example, via Bluetooth discovery, prior to generating the PIN.
The fifth parameter 210 is the required level of privileges that will be assigned to a successful authentication. Different levels of privileges may require different PIN to be used.
The control parameter may be one or a combination of temporal parameters (for example from a clock), spatial parameters (for example from a Global Positioning System), specific the address of the mobile communication device (for example Bluetooth address) and secret key.
The PIN generating module may therefore generate a PIN that is unique based on one or more of the time of the request, the location of the request, the mobile communication device making the requested and private information.
The PIN required for the authorisation device can be distributed to a mobile communication device and can be distributed unencrypted (for example email or text message) without any significant loss of security. This is because the PIN is only valid on the authorisation device for the specific combination of control parameters from which it was generated. The system allows requests for the PIN to be made with an alternative set of unique identifiers, such as the mobile phone number through a text message request or proximity card number through a proximity reader, and if that alternative identifier is allowed the PIN can be sent to the mobile communications device.
In this embodiment, all of the parameters, the code, the location information, the temporal information and the Bluetooth address are used as data inputs to a Received by IPONZ on 15 July 2011 cryptographic hash function (for example MD5 or SHA) to generate a hash value (such as a 128 bits value) from which a Bluetooth compatible PIN can be obtained (for example the first four numerals), which is then communicated to the mobile communication device via the communication module 103.
Referring to figure 3, the authentication or authorisation method using the system will now be described. The authorisation device 104 includes a communication module, which also includes a Bluetooth address reading module 303. Also included are a response module 305, a control parameter storage module 307 for 10 storing the control parameter received from the central control device 101, a location determination module 309 for determining the current location of the authorisation device, a temporal information determination module 311 for determining the current time, day or date, a control module 313 and an authorisation output module 315. Further, optionally an external input device 319 15 may be provided to detect an external input and forward that detection to the response module 305.
When a user approaches the authorisation device with a Bluetooth enabled mobile communication device 203. The communication module 301 on the 20 authorisation device detects (or discovers) the mobile communication device 203 and initiates a Bluetooth connection sequence.
The authorisation device forwards a Bluetooth connection authentication request to the mobile communication device. The mobile communication device returns a 25 Bluetooth authentication response back to the authorisation device in the form of a PIN entered on the keyboard of the mobile communication device. The PIN entered by the user should be the same PIN that was previously forwarded to the user by the central control device 101.
As part of the communication sequence, the Bluetooth address of the mobile communication device 203 is also transmitted to the Bluetooth address reading module 303 of the authorisation device. The Bluetooth address of the mobile communication device 203 is communicated to the response module. Also communicated to the response module are the control parameter 105, which is 35 stored in the control parameter storage module 307, the current location of the authorisation device in terms of GPS co-ordinates as determined by the location Received by IPONZ on 15 July 2011 determination module 309 and the current time, day or date (or any combination thereof) received from the temporal information determination module 311. The level of privileges 310 can be affected by using the external input device 319. The signal received from the external input device may also be used in the 5 response module 305.
Upon receiving these five parameters the response module 305 dynamically generates a Bluetooth matching response in the form of a suitable Bluetooth compatible PIN. The PIN is dynamically generated based on the five parameters.
The level of privileges based on those parameters can also be determined. For example the external input device 319 could determine if the authorisation device finds the mobile communications device or if the mobile communications device finds the authorisation. Alternatively the external input device 319 could detect a 15 button press on the authorisation device. Different privileges may also relate to an authentication process in the authorisation output module 315 For example, there may be two access privileges, one for guests and one for property managers. Property managers may have the privileges that allow them 20 to administer the unit while the privileges assigned to guests do not allow them to administer the unit. Both forms of privileges require pairing to be set up and both have different PINs. In Bluetooth the PIN is never transmitted over the air and can not be used by the reader to distinguish between whether it is a guest or a manager that is trying to pair. The external input lets the system know whether it 25 is a guest or a manager trying to pair. Therefore, the external input device provides the information in advance as to whether a guest or a manager is being paired to the device. The external input device may be a switch, button or key switch etc.
The step of dynamically generating a Bluetooth matching response includes the steps of: the authorisation device dynamically generating a Bluetooth pairing PIN based on the control parameter. The authorisation device then dynamically generates an internal Bluetooth authentication matching response based on the dynamically generated Bluetooth pairing PIN.
Received by IPONZ on 15 July 2011 11 The authorisation device has thus received the Bluetooth authentication response from the mobile communication device as well as determining the internally dynamically generated Bluetooth matching response based on the five parameters. These two responses are forwarded to the control module 313 5 where it is determined if the responses are identical. If the authentication and matching responses are identical, then the user is authenticated or authorised.
The control module 313 outputs a control signal to the authorisation output module 315 to produce the desired authentication output. In this embodiment the 10 output is that of unlocking a secure area to which the user has been granted access.
Therefore, the system can be set up to allow users to be authorised by one or more authorisation devices or groups of authorisation devices based on a 15 number of factors. For example, a user may only be authorised at certain times or periods of the day or night, on certain days, or certain months. The system may also be set up to positively refuse access at certain specific times or periods as opposed to positively authenticating at certain times or periods. The time periods may be re-occurring or a single occurrence time period.
Also, the user may only be given authorisation for specific single or groups of authorisation devices. Also, the user may only be authorised when their location matches that of the location of the authorisation device being communicated with. Further, only certain mobile communication devices may be used for 25 authorisation purposes.
A number of advantages are provided by embodiments of the present invention. In particular, a keyless authorisation device is provided which results in a device that can be more robust and more secure. Further, a separate PIN is not 30 required each time a mobile communication device requires authorisation with a particular authorisation device, but the PINs are specific to a reader or group of readers.
Also, the level of security can easily be increased by using further parameters to 35 dynamically create the PIN, such as time, geography, Bluetooth address, length of PIN etc.
Received by IPONZ on 15 July 2011 12 Different privileges can be associated with different authorisation behaviours such as the following.
The control parameter could be changed regularly at certain intervals to ensure that previous users provided with PINs are not able to gain access at later times.
Further options include allowing the authorisation device to authorise the mobile communication device so that the authorisation remains valid for a predefined 10 number of authorisation attempts. Further, the authorisation device may request a further authorisation after the predefined number of authorisation attempts have been made.
Also, upon the authorisation device authorising the mobile communication device, 15 the authorisation may remain valid for a predefined temporal period. Further, the authorisation device may request further authorisation after the predefined temporal period has expired.
Also, upon the authorisation device authorising the mobile communication device, 20 the authorisation may remain valid until manually de-authorised. Further, the manual de-authorisation may be by way of a third party in control of the authorisation device or the user of the mobile communication device.
The authorisation device may also record all authorisation event information in a 25 storage module. The event information may be transmitted via a wired or wireless data connection as described herein upon receiving a third party request via a wired or wireless data connection. The third party may be an administrator, for example.
Also, requests for the PIN can be made from a parallel authentication system such as the mobile phone number (MSISDN) through a text message request or proximity card number through a proximity reader, or login into a website or a purchase process. If that parallel authentication process is successful the appropriate PIN for the appropriate privileges can be sent to the mobile 35 communications device.
Received by IPONZ on 15 July 2011 13 Further Embodiments It will be understood that the embodiments of the present invention described herein are by way of example only, and that various changes and modifications 5 may be made without departing from the scope of invention.
Although the above described embodiment uses five separate parameters to dynamically generate the PIN at the central control device to be transmitted to the mobile communication device and to generate the matching response at the 10 authorisation device, it will be understood that as a minimum, only the control parameter is required. Optionally, one or more of the temporal parameters may be used to generate the PIN. These parameters, temporal, location and Bluetooth address, are optional parameters that provide an increased level of security and control. That is, an administrator can select which of the optional 15 parameters are required and select to use these if they desire.
Received by IPONZ on 15 July 2011 14

Claims (103)

CLAIMS:
1. A method of controlling an authorisation device arranged to authorise a mobile communication device using a dynamically generated Bluetooth 5 compatible PIN, the method including the steps of: a central control device generating a control parameter associated with the one or more authorisation devices, the central control device communicating the control parameter to the one or more authorisation devices, 10 the central control device generating a Bluetooth compatible PIN based on the control parameter, and the central control device communicating the PIN to a mobile communication device. 15
2. The method of claim 1 further including the steps of assigning the one or more authorisation devices to one or more groups, and assigning each group a unique control parameter.
3. The method of claim 1, wherein the control parameter is communicated to 20 the one or more authorisation devices by at least one of a wired or wireless data connection.
4. The method of claim 3, wherein the wired data connection includes the use of at least one of an internet protocol connection, a serial bus connection, 25 and a universal serial bus connection.
5. The method of claim 3, wherein the wireless data connection includes at least one of a GSM connection, a Bluetooth connection, a Wi-Fi connection and a radio frequency connection. 30
6. The method of claim 1, wherein the PIN is communicated to the mobile communication device by one or more of an SMS, internet page, e-mail message, voice message, and postal delivery. 35 7. The method of claim 1, wherein the central control device generates the PIN based on the control parameter and one or more further parameters.
Received by IPONZ on 15 July 2011 15
8. The method of claim 7, wherein the further parameter includes a
Bluetooth address of the mobile communication device. 5 9. The method of claim 8, wherein the Bluetooth address is detected over a Bluetooth connection established between the mobile communication device and central control device.
10. The method of claim 8, wherein the Bluetooth address is retrieved from a 10 database store.
11. The method of claim 7, wherein the further parameter includes location information associated with the location of the one or more authorisation devices. 15
12. The method of claim 11, wherein the location information for each of the one or more authorisation devices is retrieved from a database store.
13. The method of claim 11, wherein the location information for each of the one or more authorisation devices is retrieved from the one or more authorisation 20 devices.
14. The method of claim 11, wherein the location information is a GPS coordinate. 25
15. The method of claim 7, wherein the further parameter includes temporal information.
16. The method of claim 15, wherein the temporal information is based on a time period during which the authorisation device may authorise. 30
17. The method of claim 15, wherein the temporal information is based on a time period during which the authorisation device may not authorise.
18. The method of claim 15, wherein the temporal information is a re-35 occurring time period. Received by IPONZ on 15 July 2011 16
19. The method of claim 15, wherein the temporal information is a single occurrence time period.
20. The method of claim 7, wherein the further parameter includes information 5 based on a level of privileges assigned to the user.
21. A method of authorising a mobile communication device using an authorisation device, the method including the steps of: the authorisation device discovering a mobile communication device using 10 Bluetooth, the authorisation device forwarding a Bluetooth connection authentication request to the mobile communication device, the authorisation device receiving a Bluetooth authentication response based on a PIN entered on the mobile communication device in response to the 15 authentication request, the authorisation device dynamically generating a Bluetooth matching response based on a control parameter, the authorisation device determining whether the received Bluetooth authentication response is identical to the Bluetooth matching response and 20 authorising based upon the determination.
22. The method of claim 21, wherein the step of dynamically generating a Bluetooth matching response includes the steps of: the authorisation device dynamically generating a Bluetooth pairing PIN based on the control parameter, 25 and the authorisation device dynamically generating an internal Bluetooth authentication matching response based on the dynamically generated Bluetooth pairing PIN to enable the authorisation device to determine whether the received Bluetooth authentication response is identical to the internal Bluetooth authentication matching response. 30
23. The method of claim 21, wherein the authorisation device receives the control parameter from a central control device by at least one of a wired or wireless data connection. Received by IPONZ on 15 July 2011 17
24, The method of claim 23, wherein the wired data connection includes the use of at least one of an internet protocol connection, a serial bus connection, and a universal serial bus connection. 5
25. The method of claim 23, wherein the wireless data connection includes at least one of a GSM connection, a Bluetooth connection, a Wi-Fi connection and a radio frequency connection.
26. The method of claim 21, wherein the control parameter is based on a 10 random number assigned to the authorisation device.
27. The method of claim 21 further including the step of the authorisation device dynamically generating the Bluetooth matching response based on the control parameter and one or more further parameters. 15
28. The method of claim 27, wherein the further parameter includes a Bluetooth address of the mobile communication device.
29. The method of claim 28 further including the step of detecting the 20 Bluetooth address of the mobile communication device over a Bluetooth connection established between the mobile communication device and the authorisation device.
30. The method of claim 27, wherein the further parameter includes location 25 information associated with the location of the authorisation device.
31. The method of claim 30 further including the step of the authorisation device retrieving the location information from a database store. 30
32. The method of claim 30 further including the step of the authorisation device dynamically determining the location information.
33. The method of claim 30, wherein the location information is a GPS coordinate. 35 Received by IPONZ on 15 July 2011 18
34. The method of claim 27, wherein the further parameter includes temporal information.
35. The method of claim 34, wherein the temporal information is based on a 5 time period during which the authorisation device may authorise.
36. The method of claim 34, wherein the temporal information is based on a time period during which the authorisation device may not authorise. 10
37. The method of claim 34, wherein the temporal information is a re-occurring time period.
38. The method of claim 34, wherein the temporal information is a single occurrence time period. 15
39. The method of claim 34 further including the step of the authorisation device dynamically determining a current time.
40. The method of claim 21, whereupon the authorisation device authorising 20 the mobile communication device, the authorisation remains valid for a predefined number of authorisation attempts.
41. The method of claim 40 including the further step of the authorisation device requesting further authorisation after the predefined number of 25 authorisation attempts have been made.
42. The method of claim 21, whereupon the authorisation device authorising the mobile communication device, the authorisation remains valid for a predefined temporal period. 30
43. The method of claim 42 including the further step of the authorisation device requesting further authorisation after the predefined temporal period has expired. Received by IPONZ on 15 July 2011 19
44. The method of claim 21 whereupon the authorisation device authorising the mobile communication device, the authorisation remains valid until manually de-authorised. 5
45. The method of claim 44, wherein the manual de-authorisation is by way of a third party in control of the authorisation device or the user of the mobile communication device.
46. The method of claim 21, wherein the authorisation device records 10 authorisation event information.
47. The method of claim 46, further including the step of transmitting the event information via a wired or wireless data connection upon receiving a third party request via a wired or wireless data connection. 15
48. The method of claim 47, wherein the third party is an administrator.
49. The method of claim 47, wherein the wired data connection includes the use of at least one of an internet protocol connection, a serial bus connection, 20 and a universal serial bus connection.
50. The method of claim 47, wherein the wireless data connection includes at least one of a GSM connection, a Bluetooth connection, a Wi-Fi connection and a radio frequency connection. 25
51. The method of claim 27, wherein the further parameter includes information based on a level of privileges assigned to the user.
52. A central control device for controlling authorisation using an authorisation 30 device and a mobile communication device using a dynamically generated
Bluetooth compatible PIN, the central control device including a control parameter generating module, a communication module and a PIN generating module, wherein:
Received by IPONZ on 15 July 2011 20 the control parameter generating module is arranged to generate a control parameter, the control parameter being associated with the one or more authorisation devices, the PIN generating module is arranged to generate a Bluetooth compatible PIN 5 based on the control parameter, and the communication module is arranged to communicate the control parameter to the one or more authorisation devices and communicate the PIN to a mobile communication device. 10 53. The central control device of claim 52, wherein the one or more authorisation devices are assigned to one or more groups and the communication moduie is arranged to communicate a unique control parameter to each group. 15 54. The central control device of claim 52, wherein the communication module is arranged to communicate the control parameter to the one or more authorisation devices via a wired or wireless data connection.
55. The central control device of claim 54, wherein the wired data connection 20 includes the use of at least one of an internet protocol connection, a serial bus connection, and a universal serial bus connection.
56. The central control device of claim 54, wherein the wireless data connection includes at least one of a GSM connection, a Bluetooth connection, a 25 Wi-Fi connection and a radio frequency connection.
57. The central control device of claim 52, wherein the control parameter is based on a random number assigned to each authorisation device. 30 58. The central control device of claim 52, wherein the communication module is arranged to communicate the PIN to the mobile communication device by one or more of an SMS, internet page, e-mail message, voice message, and postal delivery.
Received by IPONZ on 15 July 2011 21
59. The central control device of claim 52, wherein the PIN generating module is arranged to generate the PIN based on the control parameter and one or more further parameters. 5
60. The central control device of claim 59, wherein the further parameter includes a Bluetooth address of the mobile communication device.
61. The central control device of claim 60, wherein the communication module is arranged to detect the Bluetooth address over a Bluetooth connection 10 established between the mobile communication device and central control device.
62. The central control device of claim 60, wherein the communication module is arranged to retrieve the Bluetooth address from a database store. 15
63. The central control device of claim 59, wherein the further parameter includes location information associated with the location of the one or more authorisation devices. 20
64. The central control device of claim 63, wherein the communication module is arranged to retrieve the location information for each of the one or more authorisation devices from a database store.
65. The central control device of claim 63, wherein the communication 25 module is arranged to retrieve the location information for each of the one or more authorisation devices from the one or more authorisation devices.
66. The central control device of claim 63, wherein the location information is a GPS co-ordinate. 30
67. The central control device of claim 59, wherein the further parameter includes temporal information.
68. The central control device of claim 67, wherein the temporal information is 35 based on a time period during which the authorisation device may authorise. Received by IPONZ on 15 July 2011 22
69. The centra! control device of claim 67, wherein the temporal information is based on a time period during which the authorisation device may not authorise.
70. The central control device of claim 67, wherein the temporal information is 5 a re-occurring time period.
71. The central control device of claim 67, wherein the temporal information is a single occurrence time period. 10
72. An authorisation device for authorising a mobile communication device, the authorisation device including a communication module, response module and control module: the communication module arranged to discover a mobile communication device using Bluetooth, forward a Bluetooth connection authentication request to the 15 mobile communication device, and receive a Bluetooth authentication response based on a PIN entered on the mobile communication device in response to the authentication request, the response module arranged to dynamically generate a Bluetooth matching response based on a control parameter, and 20 the control module arranged to determine whether the received Bluetooth authentication response is identical to the Bluetooth matching response and authorise the mobile communication device based upon the determination.
73. The authorisation device of claim 72, wherein the response module is 25 arranged to dynamically generate the Bluetooth matching response by dynamically generating a Bluetooth pairing PIN based on the control parameter, and dynamically generate an internal Bluetooth authentication matching response based on the dynamically generated Bluetooth pairing PIN so the control module is enable to determine whether the received Bluetooth 30 authentication response is identical to the internal Bluetooth authentication matching response.
74. The authorisation device of claim 72, wherein the communication module is arranged to receive the control parameter from a central control device via a 35 wired or wireless data connection. Received by IPONZ on 15 July 2011 23
75, The authorisation device of claim 74, wherein the wired data connection includes the use of at least one of an internet protocol connection, a serial bus connection, and a universal serial bus connection. 5
76. The authorisation device of claim 74, wherein the wireless data connection includes at least one of a GSM connection, a Bluetooth connection, a Wi-Fi connection and a radio frequency connection.
77. The authorisation device of claim 72, wherein the control parameter is 10 based on a random number assigned to the authorisation device.
78. The authorisation device of claim 72, wherein the response module is arranged to dynamically generate the matching response based on the control parameter and one or more further parameters. 15
79. The authorisation device of claim 78, wherein the authorisation device further includes a Bluetooth address reading module, and the further parameter includes a Bluetooth address of the mobile communication device. 20
80. The authorisation device of claim 79, wherein the Bluetooth address reading module is arranged to detect the Bluetooth address of the mobile communication device over a Bluetooth connection established between the mobile communication device and the authorisation device. 25
81. The authorisation device of claim 78, wherein the authorisation device further includes a location determination module (e.g. a GPS device) arranged to dynamically determine location information associated with the location of the authorisation device, and the further parameter includes the location information. 30
82. The authorisation device of claim 81, wherein the location determination module is a GPS module and the location information is a GPS co-ordinate.
83. The authorisation device of claim 78, wherein the authorisation device further includes a temporal information determination module (i.e. a clock reader) 35 and the further parameter includes temporal information. Received by IPONZ on 15 July 2011 24
84. The authorisation device of claim 83, wherein the temporal information is based on a time period during which the authorisation device may authorise.
85. The authorisation device of claim 83, wherein the temporal information is 5 based on a time period during which the authorisation device may not authorise.
86. The authorisation device of claim 83, wherein the temporal information is a re-occurring time period. 10
87. The authorisation device of claim 83, wherein the temporal information is a single occurrence time period.
88. The authorisation device of claim 83, wherein the temporal information determination module is arranged to dynamically determine a current time. 15
89. The authorisation device of claim 72, whereupon the authorisation device authorising the mobile communication device, the authorisation remains valid for a predefined number of authorisation attempts. 20
90. The authorisation device of claim 89, wherein the communication module is arranged to request further authorisation after the predefined number of authorisation attempts have been made.
91. The authorisation device of claim 72, whereupon the authorisation device 25 authorising the mobile communication device, the authorisation remains valid for a predefined temporal period.
92. The authorisation device of claim 91, wherein the communication module is arranged to request further authorisation after the predefined temporal period 30 has expired.
93. The authorisation device of claim 72, whereupon the authorisation device authorising the mobile communication device, the authorisation remains valid until manually de-authorised.' 35 Received by IPONZ on 15 July 2011 25
94, The authorisation device of claim 93, wherein the manual de-authorisation is by way of a third party in control of the authorisation device or the user of the mobile communication device. 5
95. The authorisation device of claim 72, wherein the authorisation device is arranged to record authorisation event information.
96. The authorisation device of claim 95, wherein the communication module is arranged to transmit the event information via a wired or wireless data 10 connection upon receiving a third party request via a wired or wireless data connection.
97. The authorisation device of claim 96, wherein the third party is an administrator. 15
98. The authorisation device of claim 96, wherein the wired data connection includes the at least one of an internet protocol connection, a serial bus connection, and a universal serial bus connection. 20
99. The authorisation device of claim 96, wherein the wireless data connection includes at least one of a GSM connection, a Bluetooth connection, a Wi-Fi connection and a radio frequency connection.
100. A method of controlling an authorisation device arranged to authorise a 25 mobile communication device substantially as herein described with reference to the accompanying figures.
101. A method of authorising a mobile communication device using an authorisation device substantially as herein described with reference to the 30 accompanying figures.
102. A central control device for controlling authorisation using an authorisation device and a mobile communication device substantially as herein described with reference to the accompanying figures. 35 Received at IPONZ 22 June 2012 26
103. An authorisation device for authorising a mobile communication device, the authorisation dev'ce including a communication module substantially as herein described with reference to the accompanying figures. 5 ECKEY LIMITED By their Attorneys 10 ELLIS TERRY /
NZ57408810A 2010-03-08 2010-03-08 Bluetooth authentication system and method NZ574088A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
NZ57408810A NZ574088A (en) 2010-03-08 2010-03-08 Bluetooth authentication system and method

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
NZ57408810A NZ574088A (en) 2010-03-08 2010-03-08 Bluetooth authentication system and method

Publications (1)

Publication Number Publication Date
NZ574088A true NZ574088A (en) 2011-08-26

Family

ID=45220142

Family Applications (1)

Application Number Title Priority Date Filing Date
NZ57408810A NZ574088A (en) 2010-03-08 2010-03-08 Bluetooth authentication system and method

Country Status (1)

Country Link
NZ (1) NZ574088A (en)

Similar Documents

Publication Publication Date Title
US20120108208A1 (en) Bluetooth authentication system and method
US10614199B2 (en) Online account access control by mobile device
KR102390410B1 (en) Techniques for enabling computing devices to identify when they are in close proximity to each other
CN107852599B (en) Selective pairing of wireless devices using shared secret keys
CN101120569B (en) Remote access system and method for user to remotely access terminal equipment from subscriber terminal
US9842446B2 (en) Systems and methods for lock access management using wireless signals
EP2687036B1 (en) Permitting access to a network
JP6093102B1 (en) Authentication system and program
US20050266798A1 (en) Linking security association to entries in a contact directory of a wireless device
US20090028082A1 (en) Systems and Methods for Wireless Network Selection Based on Attributes Stored in a Network Database
US20060190991A1 (en) System and method for decentralized trust-based service provisioning
CN102739643A (en) Permitting access to a network
CN102143492B (en) Method for establishing virtual private network (VPN) connection, mobile terminal and server
KR20230010704A (en) Maintain access to services via SIM card
CN104488302A (en) Wireless connection authentication method and server
Knight et al. Lock picking in the era of internet of things
CN101554029B (en) Methods and device for associating first device with second device
KR102171377B1 (en) Method of login control
US9143513B2 (en) Portable electronic device and associated method for making information available
NZ574088A (en) Bluetooth authentication system and method
Maia et al. CROSS: loCation pROof techniqueS for consumer mobile applicationS
KR100923909B1 (en) Method and apparatus for remotely controlling of a mobile device
JP4104610B2 (en) Authentication information providing server and authentication information providing method
JP6835312B2 (en) Authentication system and program
KR20200127428A (en) Authentication server to communicate access point through network and method of operating thereof

Legal Events

Date Code Title Description
PSEA Patent sealed
ASS Change of ownership

Owner name: ECKEY CORPORATION, US

Free format text: OLD OWNER(S): RESONANCE HOLDINGS LIMITED

S883 Correction of error according to section 88(3) (mistake in register caused on part of patentee or applicant)

Free format text: CORRECTION TO SPECIFICATION (51)

RENW Renewal (renewal fees accepted)

Free format text: PATENT RENEWED FOR 3 YEARS UNTIL 08 MAR 2017 BY PATENT + TRADE MARK RENEWAL SERVICES LTD

Effective date: 20140306

LAPS Patent lapsed