Periodic Authentication for Secure Content Sharing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing methods for content sharing in mobile terminals face security and privacy protection issues due to the need for continuous authorization and authentication, leading to potential misuse of shared information.

Innovation Solution

A content sharing method where a server periodically sends authentication identifiers to the requesting terminal, which are then verified by the information management terminal, ensuring secure access permission and terminating access if the connection is disconnected, thus reducing the burden on the mobile terminal.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the cloud end opens permission of accessing shared information to the information requesting terminal all the time, then the information requesting terminal can access information continuously, but security and privacy protection problems occur

Engineering Contradiction:
Improvecontinuous access capabilityVSAvoidsecurity and privacy protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements periodic authentication by having the information management terminal periodically send authentication requests to the server, and the server periodically verify authentication identifiers with the information requesting terminal. This periodic verification mechanism allows continuous access capability while maintaining security, as the authentication is refreshed at regular intervals rather than being permanently granted.

Inventive Principle:
Principle #19Periodic action

2Adaptability or versatility

If the mobile terminal forwards shared content between terminals, then information sharing is enabled, but traffic and power consumption increase

Engineering Contradiction:
Improveinformation sharing capabilityVSAvoidtraffic and power consumption
Core Design Contradiction:
Adaptability or versatilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts the content forwarding function from the mobile terminal and relocates it to the server. The server directly transmits shared content to the information requesting terminal without routing through the information management terminal. This extraction eliminates the need for the mobile terminal to buffer and forward content, significantly reducing its traffic usage and power consumption while maintaining full information sharing capability.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If authorization and authentication information is required for content sharing, then security is improved, but the complexity of the sharing process increases

Engineering Contradiction:
ImprovesecurityVSAvoidauthorization process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces the server as an intermediary that centralizes the authentication and authorization management. Instead of complex peer-to-peer authentication between terminals, the server mediates all authentication requests by verifying authentication identifiers and managing access permissions. This intermediary approach simplifies the overall process by providing a centralized authority that handles security complexities, making the system easier to implement and manage.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2863612B1Content sharing method, device and system
Publication Date: 2018.01.03 HUAWEI TECH CO LTD
  • EP2863612B1 patent drawingFigure 1
  • EP2863612B1 patent drawingFigure 2
  • EP2863612B1 patent drawingFigure 3A

AI summary

The present invention discloses a content sharing method, apparatus, and system, and relates to the field of information security. In the present invention, a server receives an access request sent by an information requesting terminal, where the access request carries information about a shared resource that the information requesting terminal requests to access; the server periodically sends a first authentication identifier to the information requesting terminal according to the received access request; the information requesting terminal sends the first authentication identifier to an information management terminal according to the received first authentication identifier; the information management terminal sends a second authentication identifier to the server; the server determines, according to the received second authentication identifier, whether the first authentication identifier sent to the information requesting terminal matches the second authentication identifier; if the first authentication identifier sent to the information requesting terminal matches the second authentication identifier, the server determines access permission of the information requesting terminal. According to the technical solutions provided in the present invention, access by an information requesting terminal is confirmed periodically, thereby implementing secure privacy protection.