Network Verification via Location-Encrypted Tokens

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The verification server set by the Application Service Provider (ASP) is vulnerable to application-layer-based network attacks, such as man-in-the-middle attacks, due to its digital rights management capabilities, posing a security risk for network application access.

Innovation Solution

A verification method and system that includes a verification server, a forwarding device, and a control device, where the verification server performs user identity verification and generates an encrypted token with location information, which is sent to the control device to verify terminal access, and includes token cancellation requests to manage access permissions and prevent unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the verification server performs application-layer-based digital rights management verification, then user identity verification capability is improved, but vulnerability to network attacks increases

Engineering Contradiction:
Improveuser identity verification capabilityVSAvoidvulnerability to network attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a forwarding device as an intermediary between the terminal and verification server. This device operates at the network layer to forward verification requests and responses, isolating the terminal from direct exposure to the verification server's application-layer vulnerabilities while maintaining verification functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The verification system is segmented into multiple components: the terminal, the forwarding device (operating at network layer), and the verification server (operating at application layer). This segmentation allows the forwarding device to handle traffic forwarding securely at the network layer while the verification server focuses on identity verification, reducing the attack surface.

Inventive Principle:
Principle #1Segmentation

2Device complexity

If the verification server directly verifies terminal identity, then verification process is simplified, but security risk increases

Engineering Contradiction:
Improveverification process complexityVSAvoidsecurity risk
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The forwarding device serves as a mediator that simplifies the terminal's verification process by automatically forwarding requests and responses at the network layer, while the verification server maintains its verification logic. This division reduces complexity for the terminal while enhancing security through layered architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Speed

If the terminal sends verification requests directly to the verification server, then communication efficiency is improved, but exposure to attacks increases

Engineering Contradiction:
Improvecommunication efficiencyVSAvoidexposure to network attacks
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The forwarding device acts as an efficient intermediary that forwards verification requests and responses between the terminal and verification server at the network layer. This maintains communication efficiency through direct forwarding while protecting the terminal from direct exposure to application-layer attacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Adaptability or versatility

If the verification server processes all verification requests, then centralization is improved, but attack surface increases

Engineering Contradiction:
Improvecentralized verification capabilityVSAvoidattack surface
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The centralized verification capability is segmented across multiple layers: the forwarding device handles network-layer traffic forwarding centrally, while the verification server handles application-layer identity verification centrally. This segmentation maintains the benefits of centralization while reducing the attack surface by separating concerns across layers.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP3890266B1Verification method, apparatus, and system used for network application access
Publication Date: 2025.01.01 HUAWEI TECH CO LTD
  • EP3890266B1 patent drawingFigure 1~2
  • EP3890266B1 patent drawingFigure 3~4
  • EP3890266B1 patent drawingFigure 5

AI summary

This application provides a verification method, apparatus, and system that are used for network application access, and the method includes: performing, by a verification server, user identity verification on a terminal, where the user verification request includes first location information; generating, by the verification server, an encrypted token according to the first location information in the user verification request after determining that the terminal succeeds in the user identity verification; and sending, by the verification server, the encrypted token to a control device. In the verification method used for network application access in embodiments of the present invention, application-layer verification needs to be performed, and in addition, it needs to be determined, by using network location information of a terminal, whether the terminal that performs content access is valid. In a terminal verification manner of the embodiments of the present invention, it may be determined whether a terminal that performs content access is a terminal used by a user on which user verification is performed. Therefore, this can effectively avoid an application-layer-based network attack such as an MITM attack, and further effectively improve security of the network application access.