Device Capability Authentication via Verification Codes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing proliferation and diversity of mobile electronic devices make it difficult for security administrators to quickly identify their capabilities, particularly in restricted access areas, leading to potential unauthorized access.

Innovation Solution

A system and method where an administrator computing device generates a security code, which is verified by a guest computing device, and vice versa, using a verification code, to authenticate and identify device capabilities securely, reducing the risk of fraudulent information disclosure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If visual inspection and asking the person carrying the device about the device are used to identify device capabilities, then the security administrator can obtain information about the device, but the process becomes time-consuming and may not be reliable

Engineering Contradiction:
Improveaccuracy of device capability identificationVSAvoidtime required for security check
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The mobile device automatically generates and displays a verification code that identifies its own capabilities. The security administrator simply needs to scan this code using a camera or input it manually, eliminating the need for the administrator to manually inspect or ask the user about device capabilities. This self-service approach provides accurate capability identification while significantly reducing the time required for security checks.

Inventive Principle:
Principle #25Self-service

2Reliability

If the security administrator restricts the device from entering the court room due to inability to identify capabilities, then security is maintained, but legitimate devices may be incorrectly denied access

Engineering Contradiction:
Improvesecurity assuranceVSAvoidaccess approval process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The manual inspection process is replaced with an automated code verification system. The mobile device generates a unique verification code that encodes its capabilities, and the security administrator's device automatically scans and verifies this code using optical or digital input methods. This substitution provides reliable security verification while simplifying the access approval process, ensuring that legitimate devices are not incorrectly denied access.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If a verification system is implemented to authenticate device capabilities, then the authenticity of device capabilities is ensured, but the system complexity increases

Engineering Contradiction:
Improveauthenticity of device capabilitiesVSAvoidcomplexity of verification system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The complex capability verification logic is extracted from the security administrator's device and placed within the mobile device itself. The mobile device generates a verification code that encapsulates its capabilities, and the administrator's device only needs to scan and verify this pre-generated code. This extraction ensures the authenticity of device capabilities while minimizing the complexity of the verification system on the administrator side.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP2407904B1Method for authenticating device capabilities to a verified third party
Publication Date: 2017.11.22 BLACKBERRY LTD
  • EP2407904B1 patent drawingFigure 1A~1B
  • EP2407904B1 patent drawingFigure 2
  • EP2407904B1 patent drawingFigure 3

AI summary

A system, devices and methods for verifying an administrator computing device to a guest computing device, verifying the guest device to the administrator device and outputting a list of the guest device capabilities for the administrator device such that the guest device is capable of verifying the administrator device, for example to ensure it does not divulge its capabilities to imposters, and the administrator device is capable of identifying whether the list of device capabilities is authentic. Verification can be achieved through cryptographic hashes of private certificates, digital signatures or expected output from verified modules. The list of device capabilities may be restricted based on the authorization granted to the administrator computer and may be altered or watermarked for verification. A failure to verify the administrator device may restrict execution of instructions on the guest device to prevent unauthorized access to the guest device's capabilities.