IoT Terminal Authentication via Proxy and Dual Certificates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The authentication process and communication establishment process of Internet of Things devices are independent of each other, leading to low work efficiency and potential security vulnerabilities due to the use of inherent device information for authentication.

Innovation Solution

An integrated authentication and communication method that uses dual certificates (connection and identity certificates) for Internet of Things terminals, enabling simultaneous identity authentication and connection establishment through a proxy server, enhancing security and efficiency by integrating identity and connection authentication processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If authentication process and communication establishment process are independent, then security can be maintained through separate verification steps, but work efficiency decreases due to multiple sequential operations

Engineering Contradiction:
Improvework efficiencyVSAvoidprocess complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent combines the authentication process and communication establishment process into a single integrated operation. The authentication request message includes both authentication parameters and communication establishment parameters, allowing the authentication server to perform both authentication and communication setup in one transaction, thereby improving work efficiency while reducing process complexity

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If inherent device information is used for authentication, then authentication can be performed using available device data, but security risks increase due to potential key information leakage

Engineering Contradiction:
Improveauthentication securityVSAvoidkey information leakage risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a certificate-based intermediary mechanism between the IoT terminal and the authentication server. Instead of directly using inherent device information for authentication, the system uses certificates that contain authentication information in an encrypted or processed form. This intermediary layer prevents direct exposure of key information while still enabling authentication, thereby reducing security risks associated with key information leakage

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12627636B2Internet of Things system, authentication and communication method therefor, and related device
Publication Date: 2026.05.12 BOE TECHNOLOGY GROUP CO LTD
  • US12627636B2 patent drawing
  • US12627636B2 patent drawing
  • US12627636B2 patent drawing

AI summary

An Internet of Things system, an authentication and communication method therefor, and a related device. The Internet of Things system comprises: an Internet of Things terminal, configured to establish a connection with a proxy server by using a connection certificate of the Internet of Things terminal, and send device information and an authentication identifier of the Internet of Things terminal to the proxy server; the proxy server, configured to receive the device information and the authentication identifier, and send the device information and the authentication identifier to an Internet of Things platform; and the Internet of Things platform, configured to receive the device information and the authentication identifier, perform identity verification on the Internet of Things terminal according to the device information and the authentication identifier, and in response to the fact that the verification passes, return a verification success message to the proxy server.