Offline Authentication Control Device for Drone Cargo Delivery
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional authentication systems fail to authenticate users in disaster areas where communication facilities are damaged, preventing the secure delivery of cargo by movable information processors like drones.
Innovation Solution
An authentication control system that includes a portable terminal, a service server, and a drone device, which uses stored authentication keys to decode information and perform user authentication even when the drone device is uncommunicable with the server, employing biometric authentication and proximity communication to verify user identity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If online authentication via server device is used, then authentication security is improved, but authentication cannot be performed in disaster areas where communication facilities are damaged
Solution Approach 1:
The authentication key is registered in advance in the authentication control device before disaster occurs. This preliminary action enables the device to perform authentication locally using stored keys when communication with the server is unavailable, thus resolving the contradiction between security and availability in disaster areas.
Solution Approach 2:
The authentication control device acts as an intermediary between the terminal and the server. It stores authentication keys and can perform decoding and authentication processes locally, mediating between the need for secure server-based authentication and the requirement for offline authentication capability in disaster scenarios.
2Adaptability or versatility
If authentication key is stored in authentication control device, then offline authentication capability is improved, but security risk increases if the device is compromised
Solution Approach 1:
The authentication system is segmented into multiple components: the server device holds the master authentication key, while the authentication control device stores a first authentication key that is derived from but distinct from the master key. This segmentation allows offline authentication while limiting the impact of compromise to a single device.
Solution Approach 2:
The authentication key is transformed through parameter changes - the server's second authentication key is used to generate the first authentication key stored in the authentication control device. This transformation ensures that even if the stored key is compromised, the master key remains secure, and the compromised key can be revoked and regenerated.
3Extent of automation
If communication with server is required for authentication, then centralized control is improved, but authentication speed decreases due to communication delays
Solution Approach 1:
Authentication keys and verification data are preliminarily loaded into the authentication control device before authentication is needed. This eliminates the need for real-time communication with the server during authentication, thereby increasing authentication speed while maintaining centralized control over the authentication logic.
Solution Approach 2:
The authentication system dynamically adapts its operation mode based on communication availability. When the server is accessible, it performs centralized authentication; when the server is inaccessible, it switches to using locally stored keys for offline authentication, thus optimizing both speed and control based on conditions.
Data Source
AI summary
An authentication control device includes one or more memories, and one or more processors coupled to the one or more memories and the one or more processor configured to perform storing of a first authentication key received from a server device in the one or more memories, the first authentication key relating to a second authentication key stored in a terminal of a user, in communication between the authentication control device and the terminal in the state where the authentication control device is uncommunicable with the server device, in response to receiving, from the terminal, first information encoded in accordance with the second authentication key, perform decoding of the first information by the stored first authentication key, and execute an authentication process of the user in accordance with second information acquired by the decoding.


