Host Device Challenge-Response Authentication for Secure Network Deployment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current monitoring systems face challenges in authorization, device authentication, location identification, authenticity verification, and preventing unauthorized use of devices during deployment in local networks, particularly in environments like elevator and building automation systems.
Innovation Solution
A method and system employing challenge-response authentication to securely deploy devices into local networks, where a host device requests information from a new device, determines if it matches an expected pattern, and initiates pairing only if verified, with user authentication and communication through a control device or data center to ensure secure connection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If challenge-response authentication is implemented to verify device authenticity, then security against unauthorized access is improved, but deployment complexity increases
Solution Approach 1:
The patent implements preliminary action by pre-configuring devices with unique identifiers and cryptographic keys before deployment. The host device is pre-programmed with authentication protocols and expected data patterns, allowing it to immediately verify incoming devices without requiring complex real-time authentication setup. This pre-preparation simplifies the actual deployment process while maintaining strong security.
Solution Approach 2:
The patent introduces an intermediary authentication mechanism where the host device acts as a mediator between the control device and the new device. The host device receives the new device's identifier, compares it against expected patterns, and mediates the pairing decision. This intermediary role simplifies the overall system by centralizing authentication logic in the host device, reducing complexity in other components.
2Reliability
If multiple authentication checks are performed during device pairing, then authorization security is improved, but deployment time increases
Solution Approach 1:
The patent applies preliminary action by pre-establishing the host device's authentication criteria and expected data patterns before deployment begins. The host device is pre-configured with a list of authorized device identifiers and cryptographic verification parameters. This allows for rapid authentication during deployment, as the host device can immediately compare incoming device information against pre-loaded criteria without requiring time-consuming setup or consultation of external authentication servers.
3Reliability
If device identifiers are verified against expected patterns, then device authenticity is improved, but information processing requirements increase
Solution Approach 1:
The patent extracts only the essential authentication elements from the device communication protocol. Instead of processing entire data packets or complex device profiles, the host device extracts and verifies only the critical identifier field against pre-stored expected patterns. This extraction approach significantly reduces data processing requirements while maintaining strong authentication, as only the most essential verification data is handled.
Solution Approach 2:
The patent implements local quality by making the authentication verification highly selective and targeted. The host device focuses its processing resources on verifying specific critical fields (device identifier, cryptographic signature) rather than analyzing all device data. This localized verification approach minimizes overall data processing load while ensuring authenticity of the most important authentication parameters.
Data Source
Figure 1~4
Figure 2
Figure 3A~3B
AI summary
The present invention relates to a method for deploying a device (120) to a local network hosted by a host device (110). The method comprises: receiving (210) a message (310; 307) causing the host device (110) to request (220) a piece of information from the device (120); requesting a determination if the received piece of information comprises data corresponding to an expected data pattern; if the received piece of information comprises data corresponding to the expected data pattern initiating a pairing (250) with the device (120); and in response to the pairing generating an indication (260) that the device (120) is paired with the host device (110). The invention also relates to a host device (110), to a system and to a computer program product.