Resource Request Authentication via Check Data in OCF Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication solutions in OCF networks lack adequate security for data transmitted between control devices and remote reference nodes, making them vulnerable to tampering and replay attacks.
Innovation Solution
A resource request method that generates and sends a resource collection request message with first check data, encrypted using an encryption key, to verify the reliability of the source of the request, thereby enhancing security through symmetric or asymmetric encryption algorithms.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing communication solutions are used in OCF networks, then device connectivity and interoperability are achieved, but data security and authentication reliability deteriorate
Solution Approach 1:
The control device performs preliminary actions by generating and attaching check data (encryption or signature) to resource requests before sending them to remote reference nodes. This preliminary security preparation ensures that data integrity and authentication are established before the actual data transmission, preventing tampering and replay attacks while maintaining a clear separation of security functions from the core communication protocol.
Solution Approach 2:
The patent introduces check data as an intermediary element between the control device and remote reference node. This check data (encryption or signature) acts as a mediator that carries security information without altering the fundamental structure of the resource request message, allowing security enhancement without excessive protocol complexity.
2Reliability
If encryption is applied to resource requests, then data authentication and integrity are improved, but processing time and computational overhead increase
Solution Approach 1:
The patent applies local quality by implementing encryption or signature only on specific critical fields of the resource request message (such as request parameters and identifiers) rather than encrypting the entire message payload. This selective approach ensures data authentication for essential information while minimizing computational overhead and processing time for less critical data.
Solution Approach 2:
The system allows parameter changes in the encryption/signature approach based on the specific requirements of different resource types and communication scenarios. The control device can adjust the strength and type of check data (encryption vs. signature) according to the sensitivity and requirements of each resource request, optimizing the balance between security and processing efficiency.
Data Source
Figure 1~3
Figure 4~5
Figure 6
AI summary
Embodiments of the present application provide a resource request method, a device, and a storage medium, where the method applied to a control device includes: generating a resource collection request message, the resource collection request message including a resource request for at least one remote reference node and corresponding first check data of the resource request, and sending the resource collection request message to a resource collection device. Through generation of the first check data and carrying the first check data in the resource collection request message by the control device, a remote service device is enabled to determine reliability of a source of the resource request according to the first check data, thus improving security of data transmitted between the control device and the remote reference node.