IoT User Equipment Authentication via Scanner Intermediary
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In IoT environments, unsecured wireless communication of user identities and passwords during authentication makes users vulnerable to eavesdropping and unauthorized access, as potential intruders can intercept and misuse the transmitted information.
Innovation Solution
A method and system utilizing a user-service mapping model, where user equipment encrypts and transmits a user ID, which is decrypted by a server to authenticate and provide services tailored to individual user needs, incorporating encryption and proximity authentication to prevent replay and man-in-the-middle attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If user equipment transmits user identity and password through unsecured wireless communication for authentication, then authentication can be performed automatically and conveniently, but the transmitted information becomes vulnerable to eavesdropping and unauthorized access
Solution Approach 1:
The patent introduces a scanner as an intermediary device between the user equipment and the server. The scanner captures the encrypted user ID from the user equipment and forwards it to the server for authentication. This intermediary approach allows automatic authentication while enhancing security, as the scanner acts as a trusted mediator that verifies proximity and forwards only validated authentication data, preventing direct eavesdropping on the user-server communication channel.
2Object-affected harmful factors
If encryption is implemented to protect transmitted user information, then security against eavesdropping is improved, but the complexity of the authentication system increases
Solution Approach 1:
The patent extracts the sensitive password transmission from the authentication process. Instead of transmitting passwords over the network, the system uses encrypted user IDs that are captured locally by the scanner. The actual authentication credentials remain stored securely in the user equipment and server, while only encrypted identifiers are transmitted. This extraction approach maintains security without requiring complex encryption protocols for the entire authentication flow.
Solution Approach 2:
The user equipment performs self-service by automatically generating and transmitting encrypted user IDs without requiring user intervention for password entry. The encryption process is handled automatically by the device's security module, and the scanner automatically captures and forwards the encrypted data. This self-service mechanism reduces system complexity by eliminating manual password handling while maintaining strong encryption protection.
3Object-affected harmful factors
If proximity authentication is implemented to prevent replay attacks, then security against unauthorized access is improved, but the authentication process requires additional verification steps
Solution Approach 1:
The patent replaces traditional mechanical proximity verification methods with wireless signal-based proximity authentication. The scanner detects the encrypted user ID transmitted by the user equipment through wireless communication, automatically determining proximity without requiring physical contact or manual verification. This substitution maintains strong security against replay attacks while reducing the complexity of the user interaction required for proximity verification.
Data Source
Figure 1
Figure 2A
Figure 2B
AI summary
The present disclosure relates to technologies for sensor networks, machine to machine (M2M) communication, machine type communication (MTC), and Internet of Things (IoT). The present disclosure may be utilized for intelligent services based on the above technologies (smart homes, smart buildings, smart cities, smart or connected cars, health care, digital education, retail businesses, security and safety-related services). The present invention relates to a method and apparatus that, when a user equipment notifies its identification information using an unsecured connection, enable the user equipment to notify the identification information in a secure manner using a one-time password (OTP) algorithm and proximity authentication and to receive services customized to user needs.