Asymmetric Device Identification via User-Linked Fingerprints

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current device identification methods are vulnerable to hijacking and information leakage, as they do not consider application characteristics and rely on simple hardware/software environment characteristics, leading to potential identity falsification and security risks.

Innovation Solution

A server-implemented method using asymmetric encryption and decryption algorithms to generate and verify device characteristic information based on user identifiers and random numbers, enhancing security by comparing resolved identifiers and numbers to ensure accurate device identification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If device identifiers are generated based on simple hardware/software environment characteristics, then device identification can be implemented, but the identification is vulnerable to hijacking and information leakage

Engineering Contradiction:
Improvedevice identification securityVSAvoididentification method complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by generating device fingerprints before actual identification occurs. Multiple characteristics (hardware, software, application) are collected and processed in advance to create a comprehensive device identifier that is difficult to hijack or reproduce

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent combines multiple different characteristics (hardware environment, software environment, application installation status) into a composite device fingerprint. This multi-component approach makes the identification more reliable and resistant to hijacking compared to simple single-characteristic identifiers

Inventive Principle:
Principle #40Composite materials

2Reliability

If device identifiers are captured by applications, then device identification can be performed, but there is a risk of information leakage and identity falsification

Engineering Contradiction:
Improveuser identity authenticityVSAvoidinformation leakage risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary mechanism where the device fingerprint is generated by combining multiple characteristics through a deterministic algorithm. This intermediary process ensures that no single application can directly capture or falsify the identifier, as it depends on the combined state of multiple system components

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system changes the parameters used for identification from simple captured identifiers to comprehensive device fingerprints that include hardware characteristics, software environment, and application installation status. This parameter transformation makes it difficult for attackers to falsify or intercept the identification information

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3321837B1Method, apparatus and system for deviceidentification
Publication Date: 2019.07.24 BAIDU ONLINE NETWORK TECH (BEIJIBG) CO LTD
  • EP3321837B1 patent drawingFigure 1
  • EP3321837B1 patent drawingFigure 2a
  • EP3321837B1 patent drawingFigure 2b

AI summary

The present disclosure discloses a method, an apparatus and a system for device identification. A specific implementation of the method comprises: receiving a device identification request sent from a terminal device, the device identification request comprising a current user identifier of a current user of the terminal device; acquiring a public key in a preset asymmetric key pair to serve as a first public key; sending the first public key and a randomly-generated first random number to the terminal device; receiving device characteristic information sent from the terminal device, the device characteristic information being generated by the terminal device based on the current user identifier, the first public key, the first random number and a device identifier of the terminal device; and identifying the terminal device based on the current user identifier, the first random number and the device characteristic information. The implementation increases difficulty in intercepting, by attackers, the device characteristic information of the terminal device and enhancing the security of accessing the server by the terminal device.