Permission Verification Using Physical Properties for IoT Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In wireless Internet of Things applications, the existing methods for device authentication, such as using two-dimensional codes, are inconvenient as they require users to manually scan codes with their mobile devices, which is not user-friendly and can be vulnerable to rogue program simulations.

Innovation Solution

A method and device for verifying permission using physical properties displayed on a terminal, such as indicator lights, random numbers, or voice outputs, where the user inputs these properties to a network-side server to establish a control relationship, simplifying the verification process and enhancing security by preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If two-dimensional code scanning is used for device authentication, then device ownership verification is achieved, but user operation convenience deteriorates

Engineering Contradiction:
Improvedevice authentication reliabilityVSAvoiduser operation convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces the mechanical scanning operation with voice-based authentication. Instead of requiring users to manually scan two-dimensional codes with mobile devices, the system uses voice recognition to verify device ownership, substituting physical scanning actions with vocal commands that are processed by the authentication system

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system enables self-service authentication where the device itself participates in the verification process through voice recognition. The user's voice serves as the authentication credential, eliminating the need for external scanning devices and manual code entry, making the authentication process self-contained and more convenient

Inventive Principle:
Principle #25Self-service

2Reliability

If manual code scanning is required, then authentication security is maintained, but operation complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidoperation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent substitutes the complex mechanical process of scanning and entering codes with a simple voice recognition system. The voice-based authentication eliminates multiple operational steps (opening camera, scanning code, entering verification code) and replaces them with a single natural language command, significantly reducing operational complexity while maintaining security through voice biometrics

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If traditional authentication methods are used, then device control verification is achieved, but vulnerability to rogue program simulation increases

Engineering Contradiction:
Improvecontrol verification reliabilityVSAvoidrogue program simulation vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent changes the authentication parameter from visual code recognition to voice biometric recognition. By using voice characteristics (tone, frequency, timbre) as the authentication parameter instead of two-dimensional codes, the system creates a more difficult target for rogue programs to simulate, as voice biometrics require actual physiological characteristics that are harder to replicate programmatically

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3059899B1Permission verification method and device
Publication Date: 2020.09.23 XIAOMI INC
  • EP3059899B1 patent drawingFigure 1
  • EP3059899B1 patent drawingFigure 2
  • EP3059899B1 patent drawingFigure 3~4

AI summary

A method and a device for verifying permission are provided by embodiments of the present disclosure and may simplify a verification operation of permission, make a user complete a permission verification by a simple button clicking operation, and have a high safety. The method for verifying permission includes: executing a binding verification operation according to a physical property displayed in a terminal to be bound; and reporting verification information of the executed binding verification operation to a network-side server.