Mutual Device Trust Authentication for Continuous Security Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing device authentication methods provide only a low level of mutual trust and cannot guarantee the security state of devices, as they rely on cryptographic keys that do not ensure continuous security verification.
Innovation Solution
Devices exchange security authentication information to evaluate trust levels, perform signature verification, and maintain continuous authentication through profiling user behavior to ensure higher trust levels and reliability in information interaction.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cryptographic key authentication is used for device access, then basic security is ensured, but mutual trust level remains low and continuous security verification cannot be guaranteed
Solution Approach 1:
The authentication process is segmented into multiple independent verification stages: initial cryptographic key authentication, security state information exchange, trust evaluation, and continuous behavior profiling. Each stage operates independently but contributes to the overall authentication reliability, allowing the system to achieve high security verification without requiring a single complex authentication mechanism
Solution Approach 2:
Security state information is collected and evaluated in advance before granting access permissions. The system performs preliminary trust evaluation by analyzing security state information and user behavior patterns beforehand, establishing a baseline trust level that enables continuous security verification without disrupting subsequent operations
2Reliability
If mutual trust evaluation between devices is implemented, then security and reliability of information interaction is enhanced, but the authentication process becomes more complex
Solution Approach 1:
Devices autonomously evaluate each other's trustworthiness by exchanging security state information and performing self-assessment against predefined criteria. The system enables devices to conduct mutual trust evaluation independently without requiring centralized authentication authorities, reducing overall system complexity while maintaining high reliability
Solution Approach 2:
The system implements continuous feedback loops where security state information and user behavior data are constantly monitored, evaluated, and used to adjust trust levels. This feedback mechanism enables dynamic trust management that adapts to changing security conditions without requiring manual intervention or complex reconfiguration
Data Source
Figure 1A~1B
Figure 2
Figure 3
AI summary
An information interaction method includes: sending, by a first device in response to a need to send an authorization request message to a second device, first security authentication information to the second device, where the first security authentication information is configured for the second device to evaluate whether the first device is a trusted device; evaluating, by the first device, whether the second device is a trusted device based on second security authentication information sent by the second device; obtaining, by the first device in response to determining mutual trust with the second device, an authorization pass message sent by the second device based on the authorization request message, where the authorization pass message is configured to authorize the first device to access the second device; and sending, by the first device, an access request message to the second device based on the authorization pass message.