IoT Payment Gateway Security via Device-Account Binding
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional payment solutions for IoT devices are prone to security vulnerabilities due to a strong binding relationship between payment accounts and gateway devices, making them susceptible to malicious access and theft.
Innovation Solution
A payment method that involves obtaining target identification information and payment amounts from IoT devices connected to a gateway device, sending a payment request to a server with this information, and deducting from a target payment account associated with both the IoT device and gateway device identification, thereby enhancing security and allowing different IoT devices to deduct from different payment accounts.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a payment account is bound to the gateway device for processing payment tasks, then payment convenience is improved, but security deteriorates due to malicious access risks
Solution Approach 1:
The payment authorization mechanism is segmented into device-level (gateway) and account-level (IoT device specific) permissions. The server divides payment processing rights by creating device-specific authorization tokens that are tied to both the gateway device identification and the target IoT device identification, ensuring that each device can only access its designated payment account.
Solution Approach 2:
The server acts as an intermediary between the gateway device and payment accounts. Instead of directly binding payment accounts to gateway devices, the server mediates the connection by verifying device identifications, searching for corresponding payment accounts, and authorizing transactions. This intermediary layer prevents direct access and reduces security risks.
2Device complexity
If payment accounts are uniformly bound to gateway devices, then system complexity is reduced, but payment security deteriorates due to inability to distinguish between different IoT devices
Solution Approach 1:
The payment authorization system implements local quality by providing different permission levels to different IoT devices connected to the same gateway. Each IoT device receives a customized authorization token that contains specific permissions and is bound to that particular device's identification, ensuring that each device has appropriate access rights without exposing other devices' accounts.
Solution Approach 2:
The payment authorization system is dynamic rather than static. Authorization tokens are generated on-demand based on the specific IoT device making the request, the gateway device identification, and the target payment account. These tokens have time limits and can be revoked, allowing the system to adapt to changing security requirements while maintaining simple account binding at the gateway level.
Data Source
AI summary
Embodiments of the present application provide a payment method, a gateway device, a server and a storage medium. The method is applied to the gateway device, and the method includes: obtaining target identification information and payment amount of a target IoT device connected to the gateway device, wherein the target identification information includes a first device identification of the target IoT device and/or a feature identification of a physical layer between the target IoT device and the gateway device; sending a first payment request to the server, wherein the first payment request includes the target identification information, a second device identification of the gateway device and the payment amount, and the first payment request is configured to instruct the server to search a target payment account associated with the target identification information and the second device identification, and to deduct from the target payment account according to the payment amount.


