IoT Device Authentication via Segmented Control Area Keys
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In the context of IoT, there is a need for enhanced information security and authentication procedures to prevent unauthorized control of equipment by users, particularly as IoT technology evolves and integrates with cloud servers and various industrial applications.
Innovation Solution
A method and apparatus that generate an authentication key based on user information and control area characteristics, allowing for differentiated security levels and service provision by registering control devices and granting authority only after successful authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If authentication procedures are simplified for ease of use, then ease of operation is improved, but information security deteriorates
Solution Approach 1:
The authentication process is segmented into distinct phases: device identification, authentication key generation, and authority grant. This segmentation allows each phase to be optimized independently, maintaining security while improving user experience through clear progression steps.
Solution Approach 2:
An authentication key acts as an intermediary between the user and the control authority. Instead of direct authentication, the system uses this intermediate credential to bridge the user's identity with the equipment control rights, enhancing both security and ease of operation.
2Adaptability or versatility
If control authority is granted broadly for versatility, then adaptability is improved, but information security deteriorates
Solution Approach 1:
Control authority is not granted uniformly but is locally tailored to specific equipment and areas. The system assigns different levels of access rights based on the specific control area and equipment type, allowing versatility in access patterns while maintaining security through localized authorization policies.
Solution Approach 2:
The system changes the parameters of control authority based on the authentication result. Instead of binary authorized/unauthorized states, the system adjusts the scope, duration, and level of control granted, enabling adaptable access while maintaining security through parameterized authorization levels.
Data Source
Figure 1
Figure 2
Figure 3~4
AI summary
A server and method for supporting device registration by the server are provided. The method includes receiving an authentication information generation request from a user terminal; determining a control allowance area of the user terminal in response to the authentication information generation request; generating authentication information based on a predetermined authentication method for the determined control allowance area; and requesting a control device to register the generated authentication information. The authentication method includes information on an object to be authenticated for the determined control allowance area. The present disclosure relates to a sensor network, Machine Type Communication (MTC), Machine-to-Machine (M2M) communication, and technology for Internet of Things (IoT). The present disclosure may be applied to intelligent services based on the above technologies, such as smart home, smart building, smart city, smart car, connected car, health care, digital education, smart retail, security and safety services.