Smart Lock Authentication via Server-Mediated One-Time Passwords
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Bluetooth-based intelligent lock unlocking methods are insecure due to the risk of monitoring and replaying encryption commands, which can lead to significant property damage once encryption is deciphered.
Innovation Solution
A method involving a mobile terminal that receives an initial key and communication key from a server, encrypts them with preset key data to generate an unlocking verification code, and sends it to an intelligent lock, which verifies the code's legality based on timestamp or counter values to ensure secure unlocking operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If Bluetooth wireless communication is used for unlocking, then ease of operation is improved, but security deteriorates due to monitoring and replaying risks
Solution Approach 1:
The patent applies preliminary action by pre-establishing a one-time password (OTP) binding relationship between the mobile terminal and intelligent lock before the unlocking operation. The server pre-generates and binds an OTP to the terminal, ensuring that only authenticated terminals can perform unlocking operations. This preliminary authentication prevents replaying attacks while maintaining convenient Bluetooth-based unlocking operations.
2Ease of manufacture
If encryption algorithms are made public for Bluetooth unlocking, then ease of manufacture is improved, but security deteriorates as encryption can be deciphered
Solution Approach 1:
The patent introduces a server as an intermediary that manages the key distribution and authentication process. Instead of using public encryption algorithms directly between devices, the server acts as a mediator that issues one-time passwords and verifies authentication credentials. This intermediary approach maintains implementation simplicity while preventing decryption of communication content, as the server controls all cryptographic operations.
3Ease of operation
If initial keys and communication keys are transmitted wirelessly, then ease of operation is improved, but security deteriorates due to tampering risks
Solution Approach 1:
The patent applies preliminary action by pre-establishing a one-time password (OTP) binding relationship between the mobile terminal and intelligent lock before the unlocking operation. The server pre-generates and binds an OTP to the terminal, ensuring that only authenticated terminals can perform unlocking operations. This preliminary authentication prevents replaying attacks while maintaining convenient Bluetooth-based unlocking operations.
4Difficulty of detecting and measuring
If Bluetooth unlocking commands are monitored and replayed, then ease of detection is improved, but security deteriorates as property damage can occur
Solution Approach 1:
The patent applies preliminary action by pre-establishing a one-time password (OTP) binding relationship between the mobile terminal and intelligent lock before the unlocking operation. The server pre-generates and binds an OTP to the terminal, ensuring that only authenticated terminals can perform unlocking operations. This preliminary authentication prevents replaying attacks while maintaining convenient Bluetooth-based unlocking operations.
Solution Approach 2:
The patent introduces a server as an intermediary that manages the key distribution and authentication process. Instead of using public encryption algorithms directly between devices, the server acts as a mediator that issues one-time passwords and verifies authentication credentials. This intermediary approach maintains implementation simplicity while preventing decryption of communication content, as the server controls all cryptographic operations.
Data Source
AI summary
Provided are a method for unlocking an intelligent lock, a mobile terminal, an intelligent lock and a server. The method includes following steps. A mobile terminal receives an initial key and a communication key from a server. The mobile terminal encrypts the initial key and preset key data by using the communication key to generate an unlocking verification code. The mobile terminal attaches the preset key data to the unlocking verification code, to obtain an unlocking verification code attached with the preset key data. The mobile terminal sends the unlocking verification code attached with the preset key data to the intelligent lock. The intelligent lock performs an unlocking operation based on the unlocking verification code attached with the preset key data.


