Device Authentication via Identifier Matching and Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
There is no effective method to prevent user data on a device from being read by unauthorized devices, compromising information security.
Innovation Solution
An authentication method and apparatus that transmit a control message between devices to verify matching identifiers, disabling data access if they do not match, and notifying users of authentication failures by encrypting and uploading data to a network storage system.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If device sharing is allowed for normal use, then device accessibility and usability are improved, but information security and data protection deteriorate
Solution Approach 1:
The patent applies preliminary action by performing authentication before allowing data access. The first device transmits an authentication control message to the second device beforehand, and only after successful authentication (matching device identifiers) does the system enable data reading. This prevents unauthorized access while allowing legitimate sharing.
Solution Approach 2:
The patent uses an intermediary mechanism where the authentication control message acts as a mediator between the first device (data owner) and the second device (data access requester). This intermediary message carries authentication information that enables the second device to prove its identity without directly exposing the data, thus resolving the contradiction between accessibility and security.
2Reliability
If authentication control messages are transmitted between devices, then data protection against unauthorized access is improved, but device complexity and communication overhead increase
Solution Approach 1:
The patent extracts the authentication function from the data storage and access mechanisms. Instead of embedding complex authentication logic within the data system, the authentication control message is separated and transmitted independently. This allows the authentication mechanism to be simplified and reused without increasing overall system complexity.
Solution Approach 2:
The authentication control message serves multiple functions: it carries device identifier information, enables authentication verification, and controls data access rights. By making this single message multi-functional, the patent reduces the need for separate authentication protocols and data protection mechanisms, thereby lowering system complexity.
3Reliability
If device identifiers are verified before data access, then unauthorized data reading is prevented, but authentication time and processing delay increase
Solution Approach 1:
The authentication verification is performed in advance before data access is granted. The first device transmits the authentication control message containing device identifier information, and the second device verifies the match beforehand. This preliminary authentication ensures security while minimizing the time required during actual data access operations.
Solution Approach 2:
The patent uses device identifier information as a copy or representation of the actual device identity. Instead of requiring complex cryptographic proofs or hardware-level verification, the system uses transmitted identifier data that can be quickly compared. This copying approach speeds up authentication while maintaining security.
Data Source
AI summary
The embodiment of the present document provides an authentication method, an authentication apparatus and an authentication device. The method includes: a first device determining an authentication preparation parameter; and according to the authentication preparation parameter, the first device transmitting a first authentication control message including a first device identifier stored in the first device to a second device with a second device identifier, controlling the second device to judge whether the first device identifier matches the second device identifier according to the first authentication control message, obtaining a judgment result, and when the judgment result is NO, performing a control operation to disable the second device from reading all or some user data from the first device.


