Beacon Device Security via Access Token Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Beacon information can be altered by unauthorized users during Bluetooth Low-Energy (BLE) communication, compromising security in conventional beacon management applications.
Innovation Solution
Implementing user authentication and data encryption during communication between terminals and beacon devices, using access tokens encrypted with public keys to ensure only authorized changes can be made to beacon information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If beacon management application allows open access to change beacon information, then ease of operation is improved, but security is deteriorated
Solution Approach 1:
The patent introduces an access token as an intermediary mechanism between the beacon management application and beacon information. The access token mediates access control by requiring authentication before allowing beacon information changes, thus maintaining ease of operation for authorized users while preventing unauthorized access.
Solution Approach 2:
The patent implements preliminary authentication action by requiring users to obtain an access token before they can modify beacon information. This preliminary security check ensures that only authenticated users can change beacon settings, resolving the contradiction between easy operation and security by establishing security prerequisites before operation.
2Ease of operation
If beacon communication uses simple identification, then ease of operation is improved, but security is deteriorated
Solution Approach 1:
The patent implements nested security by embedding multiple layers of identification within the beacon system. The beacon identifier contains nested elements including UUID, major value, and minor value, creating a hierarchical structure where each layer provides additional security while maintaining the simplicity of single-point access for users.
Solution Approach 2:
The patent uses composite identification structure combining multiple identification elements (UUID, major value, minor value) into a single beacon identifier. This composite approach maintains the simplicity of single identifier usage while incorporating multiple security layers that prevent unauthorized access.
3Productivity
If beacon data is transmitted without encryption, then productivity is improved, but security is deteriorated
Solution Approach 1:
The patent extracts the security-critical authentication data (access token) from the general beacon communication stream and handles it separately with encryption. This allows most beacon data to communicate efficiently without encryption overhead while protecting only the essential authentication information.
Solution Approach 2:
The patent applies encryption selectively only to the access token and authentication-related data rather than encrypting all beacon communications. This local application of encryption maintains high productivity for general beacon operations while ensuring security for critical authentication information.
Data Source
AI summary
Provided are a method of reinforcing the security of a beacon device and a system and apparatus thereof. In particular, the stability of security is increased by performing user authentication and encrypting data during communication with a beacon device, so that identification information of the beacon device may be changed by establishing Bluetooth Low Energy (BLE) communication after the beacon device and a terminal are connected. Also, a user can be exactly identified using a beacon signal and authenticated, thereby conveniently providing additional services. Also, the location of a terminal may be determined using a BLE beacon signal terminal to reduce resources consumed to measure the location of the terminal. A service device may simplify logic for extracting information to be applied to a service. That is, when various information is provided to a client's terminal that receives an identifier of a beacon device broadcast from the beacon device, information provided to the client's terminal may be prevented from being changed by an unauthorized person.


