IoT Thing Information Transmission via Verification Token
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In the Internet of Things (IoT), there is a risk of sensitive information leakage, such as device identification or account information, when thing information is acquired, due to insecure communication channels, allowing potential interception and unauthorized access.
Innovation Solution
A method and system for thing information transmission in IoT, where verification information is used to authenticate device and user attributes without including device identification or user identity details, ensuring secure access and preventing unauthorized data acquisition. This involves a first device acquiring thing identification information, determining verification information, and sending a request to a third device for permission-based information retrieval, while ensuring that device and user identities are not exposed.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If device identification or user identity information is transmitted to acquire thing information, then access permission can be verified, but sensitive information may be intercepted and leaked through insecure communication channels
Solution Approach 1:
The patent extracts and removes sensitive device identification and user identity information from the transmission process. Instead of transmitting actual identifiers, the system uses verification information that proves authorization without exposing the underlying identity data, thus preventing information leakage while maintaining access control
Solution Approach 2:
The patent introduces an intermediary verification mechanism where verification information acts as a mediator between the requesting device and the information storage device. This verification information proves authorization without directly transmitting sensitive identity information, thereby securing the communication channel
2Object-affected harmful factors
If verification information is used instead of device identification, then sensitive information leakage is prevented, but the complexity of the authentication process increases
Solution Approach 1:
The patent applies preliminary action by pre-establishing verification information that proves device authorization before actual information retrieval. The verification information is generated in advance based on device attributes and authorization levels, so that during the actual information access process, only this pre-prepared verification data needs to be transmitted, simplifying the real-time authentication while maintaining security
Data Source
Figure 1~2
Figure 3
Figure 4~5
AI summary
The present invention relates to the technical field of information processing of the Internet of Things and, in particular, to a thing information transmission method, apparatus and system in the Internet of Things, for reducing the risk of leakage of sensitive information such as device identification or account when thing information is acquired in the current Internet of Things. In a thing information transmission method, a second device sends thing identification information to a first device, and the first device sends a thing information request message to a third device, the thing information request message comprising verification information and the thing identification information, wherein the verification information does not comprise device identification information about the second device and also does not comprise identity identification information about a user. The third device sends thing information to the first device when determining that the thing information request message has a permission of the acquired thing information according to the verification information. The leakage of the device identification and user identity can be effectively avoided.