Periodic Authentication for Secure Content Sharing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing methods for content sharing in mobile terminals face security and privacy protection issues due to the need for continuous authorization and authentication, leading to potential misuse of shared information.
Innovation Solution
A content sharing method where a server periodically sends authentication identifiers to the requesting terminal, which are then verified by the information management terminal, ensuring secure access permission and terminating access if the connection is disconnected, thus reducing the burden on the mobile terminal.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the cloud end opens permission of accessing shared information to the information requesting terminal all the time, then the information requesting terminal can access information continuously, but security and privacy protection problems occur
Solution Approach 1:
The patent implements periodic authentication by having the information management terminal periodically send authentication requests to the server, and the server periodically verify authentication identifiers with the information requesting terminal. This periodic verification mechanism allows continuous access capability while maintaining security, as the authentication is refreshed at regular intervals rather than being permanently granted.
2Adaptability or versatility
If the mobile terminal forwards shared content between terminals, then information sharing is enabled, but traffic and power consumption increase
Solution Approach 1:
The patent extracts the content forwarding function from the mobile terminal and relocates it to the server. The server directly transmits shared content to the information requesting terminal without routing through the information management terminal. This extraction eliminates the need for the mobile terminal to buffer and forward content, significantly reducing its traffic usage and power consumption while maintaining full information sharing capability.
3Reliability
If authorization and authentication information is required for content sharing, then security is improved, but the complexity of the sharing process increases
Solution Approach 1:
The patent introduces the server as an intermediary that centralizes the authentication and authorization management. Instead of complex peer-to-peer authentication between terminals, the server mediates all authentication requests by verifying authentication identifiers and managing access permissions. This intermediary approach simplifies the overall process by providing a centralized authority that handles security complexities, making the system easier to implement and manage.
Data Source
Figure 1
Figure 2
Figure 3A
AI summary
The present invention discloses a content sharing method, apparatus, and system, and relates to the field of information security. In the present invention, a server receives an access request sent by an information requesting terminal, where the access request carries information about a shared resource that the information requesting terminal requests to access; the server periodically sends a first authentication identifier to the information requesting terminal according to the received access request; the information requesting terminal sends the first authentication identifier to an information management terminal according to the received first authentication identifier; the information management terminal sends a second authentication identifier to the server; the server determines, according to the received second authentication identifier, whether the first authentication identifier sent to the information requesting terminal matches the second authentication identifier; if the first authentication identifier sent to the information requesting terminal matches the second authentication identifier, the server determines access permission of the information requesting terminal. According to the technical solutions provided in the present invention, access by an information requesting terminal is confirmed periodically, thereby implementing secure privacy protection.