Network Verification via Location-Encrypted Tokens
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The verification server set by the Application Service Provider (ASP) is vulnerable to application-layer-based network attacks, such as man-in-the-middle attacks, due to its digital rights management capabilities, posing a security risk for network application access.
Innovation Solution
A verification method and system that includes a verification server, a forwarding device, and a control device, where the verification server performs user identity verification and generates an encrypted token with location information, which is sent to the control device to verify terminal access, and includes token cancellation requests to manage access permissions and prevent unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the verification server performs application-layer-based digital rights management verification, then user identity verification capability is improved, but vulnerability to network attacks increases
Solution Approach 1:
The patent introduces a forwarding device as an intermediary between the terminal and verification server. This device operates at the network layer to forward verification requests and responses, isolating the terminal from direct exposure to the verification server's application-layer vulnerabilities while maintaining verification functionality.
Solution Approach 2:
The verification system is segmented into multiple components: the terminal, the forwarding device (operating at network layer), and the verification server (operating at application layer). This segmentation allows the forwarding device to handle traffic forwarding securely at the network layer while the verification server focuses on identity verification, reducing the attack surface.
2Device complexity
If the verification server directly verifies terminal identity, then verification process is simplified, but security risk increases
Solution Approach 1:
The forwarding device serves as a mediator that simplifies the terminal's verification process by automatically forwarding requests and responses at the network layer, while the verification server maintains its verification logic. This division reduces complexity for the terminal while enhancing security through layered architecture.
3Speed
If the terminal sends verification requests directly to the verification server, then communication efficiency is improved, but exposure to attacks increases
Solution Approach 1:
The forwarding device acts as an efficient intermediary that forwards verification requests and responses between the terminal and verification server at the network layer. This maintains communication efficiency through direct forwarding while protecting the terminal from direct exposure to application-layer attacks.
4Adaptability or versatility
If the verification server processes all verification requests, then centralization is improved, but attack surface increases
Solution Approach 1:
The centralized verification capability is segmented across multiple layers: the forwarding device handles network-layer traffic forwarding centrally, while the verification server handles application-layer identity verification centrally. This segmentation maintains the benefits of centralization while reducing the attack surface by separating concerns across layers.
Data Source
Figure 1~2
Figure 3~4
Figure 5
AI summary
This application provides a verification method, apparatus, and system that are used for network application access, and the method includes: performing, by a verification server, user identity verification on a terminal, where the user verification request includes first location information; generating, by the verification server, an encrypted token according to the first location information in the user verification request after determining that the terminal succeeds in the user identity verification; and sending, by the verification server, the encrypted token to a control device. In the verification method used for network application access in embodiments of the present invention, application-layer verification needs to be performed, and in addition, it needs to be determined, by using network location information of a terminal, whether the terminal that performs content access is valid. In a terminal verification manner of the embodiments of the present invention, it may be determined whether a terminal that performs content access is a terminal used by a user on which user verification is performed. Therefore, this can effectively avoid an application-layer-based network attack such as an MITM attack, and further effectively improve security of the network application access.