IoT User Equipment Authentication via Scanner Intermediary

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In IoT environments, unsecured wireless communication of user identities and passwords during authentication makes users vulnerable to eavesdropping and unauthorized access, as potential intruders can intercept and misuse the transmitted information.

Innovation Solution

A method and system utilizing a user-service mapping model, where user equipment encrypts and transmits a user ID, which is decrypted by a server to authenticate and provide services tailored to individual user needs, incorporating encryption and proximity authentication to prevent replay and man-in-the-middle attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If user equipment transmits user identity and password through unsecured wireless communication for authentication, then authentication can be performed automatically and conveniently, but the transmitted information becomes vulnerable to eavesdropping and unauthorized access

Engineering Contradiction:
Improveautomatic authenticationVSAvoideavesdropping and unauthorized access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a scanner as an intermediary device between the user equipment and the server. The scanner captures the encrypted user ID from the user equipment and forwards it to the server for authentication. This intermediary approach allows automatic authentication while enhancing security, as the scanner acts as a trusted mediator that verifies proximity and forwards only validated authentication data, preventing direct eavesdropping on the user-server communication channel.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If encryption is implemented to protect transmitted user information, then security against eavesdropping is improved, but the complexity of the authentication system increases

Engineering Contradiction:
Improvesecurity against eavesdroppingVSAvoidauthentication system complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent extracts the sensitive password transmission from the authentication process. Instead of transmitting passwords over the network, the system uses encrypted user IDs that are captured locally by the scanner. The actual authentication credentials remain stored securely in the user equipment and server, while only encrypted identifiers are transmitted. This extraction approach maintains security without requiring complex encryption protocols for the entire authentication flow.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The user equipment performs self-service by automatically generating and transmitting encrypted user IDs without requiring user intervention for password entry. The encryption process is handled automatically by the device's security module, and the scanner automatically captures and forwards the encrypted data. This self-service mechanism reduces system complexity by eliminating manual password handling while maintaining strong encryption protection.

Inventive Principle:
Principle #25Self-service

3Object-affected harmful factors

If proximity authentication is implemented to prevent replay attacks, then security against unauthorized access is improved, but the authentication process requires additional verification steps

Engineering Contradiction:
Improvereplay attacks and unauthorized accessVSAvoidauthentication process complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent replaces traditional mechanical proximity verification methods with wireless signal-based proximity authentication. The scanner detects the encrypted user ID transmitted by the user equipment through wireless communication, automatically determining proximity without requiring physical contact or manual verification. This substitution maintains strong security against replay attacks while reducing the complexity of the user interaction required for proximity verification.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentEP3223452B1Method and apparatus for providing service on basis of identifier of user equipment
Publication Date: 2021.06.09 SAMSUNG ELECTRONICS CO LTD
  • EP3223452B1 patent drawingFigure 1
  • EP3223452B1 patent drawingFigure 2A
  • EP3223452B1 patent drawingFigure 2B

AI summary

The present disclosure relates to technologies for sensor networks, machine to machine (M2M) communication, machine type communication (MTC), and Internet of Things (IoT). The present disclosure may be utilized for intelligent services based on the above technologies (smart homes, smart buildings, smart cities, smart or connected cars, health care, digital education, retail businesses, security and safety-related services). The present invention relates to a method and apparatus that, when a user equipment notifies its identification information using an unsecured connection, enable the user equipment to notify the identification information in a secure manner using a one-time password (OTP) algorithm and proximity authentication and to receive services customized to user needs.