IoT Device Authentication via Mobile Agent and Server
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current payment technologies using mobile devices and IoT devices lack secure authentication methods, particularly for verifying the authenticity of both the customer and the IoT device, leading to potential security vulnerabilities such as barcode piracy during transactions.
Innovation Solution
An authentication system comprising a device authentication agent on the IoT device, a mobile agent on the user's mobile device, and an authentication server, which generate and verify device authentication information using seed information and a predesignated algorithm, ensuring the authenticity of both the IoT device and the user through wireless communication, utilizing beacon or NFC technology.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If barcode based payment technology is used, then payment convenience is improved, but security is worsened due to barcode piracy vulnerability
Solution Approach 1:
The patent introduces an authentication server as an intermediary between the mobile device and the point of sale system. This server verifies device authenticity through authentication tokens before allowing transactions, thereby maintaining payment convenience while adding a security layer that prevents barcode piracy by validating the source of payment requests.
Solution Approach 2:
The patent implements preliminary authentication of the IoT device before the actual payment transaction occurs. The authentication server verifies device credentials and generates authentication tokens in advance, ensuring that only authenticated devices can initiate payments. This preliminary security check prevents unauthorized transactions while maintaining the convenience of contactless payment.
2Reliability
If authentication systems are added to verify IoT device authenticity, then transaction security is improved, but system complexity is worsened
Solution Approach 1:
The authentication server acts as a centralized intermediary that handles all authentication logic, keeping the complexity contained in one component rather than distributing it across multiple devices. The mobile device and point of sale systems remain relatively simple, while the server manages device registration, token generation, and verification, thereby improving security without significantly increasing overall system complexity.
Solution Approach 2:
The patent uses authentication tokens as digital copies of device credentials that can be verified without exposing the actual device identity. These tokens are generated by the authentication server and used for verification, allowing the system to confirm device authenticity through simplified copy-based verification rather than complex direct authentication protocols.
3Reliability
If both user and IoT device authenticity are verified, then payment safety is improved, but operation time is worsened due to additional authentication steps
Solution Approach 1:
The patent performs device authentication in advance before the payment transaction, so that when a payment is initiated, the device's authenticity is already confirmed. The authentication server verifies device credentials and issues tokens that can be quickly validated during transactions, thereby ensuring payment safety through comprehensive authentication while minimizing the time required during actual payment operations.
Solution Approach 2:
The authentication token serves as a pre-validated copy of device credentials that can be quickly verified during transactions. Instead of performing full authentication protocols during each payment, the system uses these pre-generated tokens for rapid verification, maintaining high payment safety through dual authentication while reducing the time penalty to minimal validation operations.
Data Source
AI summary
Provided is an authentication system including: a device authentication agent installed in an Internet of things (IoT) device with a communication module and generating first device authentication information for authenticating the corresponding IoT device; an authentication server connected with the IoT device through wired or wireless communication and generating second device authentication information for authenticating the IoT device; and a mobile agent installed in a mobile device of a user, connected with the IoT device and the authentication server through the wireless communication, and verifying whether the IoT device or a message determined to be received from the IoT device is authentic according to whether the first device authentication information transmitted from the IoT device and the second device authentication information transmitted from the authentication server coincide with each other.


