Terminal Authentication via Data Stream Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing terminal authentication methods for web cameras in monitoring networks are inefficient, causing disruptions in normal monitoring due to the need for manual addition of MAC addresses to whitelists, leading to a heavy workload and poor operability when new cameras are not initially allowed access.

Innovation Solution

An apparatus and method where an authenticator sends a data stream to a security gateway to detect trusted terminals, which then instructs the authentication server to update the MAC address list, allowing re-authentication without manual MAC address addition, thereby reducing the workload and enhancing operability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If MAC address whitelist authentication is used to ensure network security, then network security is improved, but new web cameras cannot access the network without manual whitelist updates, causing monitoring disruptions

Engineering Contradiction:
Improvenetwork securityVSAvoidaccess operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system enables self-service authentication by allowing web cameras to automatically authenticate themselves through data stream analysis. The security gateway automatically detects trusted terminals by analyzing data streams and performs self-updates to the authentication server, eliminating the need for manual MAC address whitelist updates by administrators.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces a security gateway as an intermediary component between the authenticator and the authentication server. This gateway analyzes data streams from web cameras, determines trustworthiness, and automatically manages whitelist updates, thereby mediating between security requirements and ease of access operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If manual MAC address whitelist updates are performed for each new web camera, then network security is maintained, but the workload becomes extremely large and operability deteriorates

Engineering Contradiction:
Improvenetwork securityVSAvoidauthentication efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The authentication system performs self-updates automatically. When the security gateway detects a trusted web camera through data stream analysis, it automatically adds the device to the authentication server's whitelist without requiring administrator intervention, thereby maintaining security while dramatically improving authentication efficiency.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary authentication by analyzing data streams before formal network access is granted. The security gateway pre-evaluates web cameras by examining their data stream characteristics, allowing trusted devices to be automatically recognized and added to the whitelist before they need full network access, thus improving overall system productivity.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If web cameras are frequently replaced in the monitoring network, then monitoring coverage is improved, but the authentication system becomes burdensome due to continuous whitelist updates

Engineering Contradiction:
Improvedevice replacement flexibilityVSAvoidauthentication management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system handles device replacements automatically through self-service authentication. When new web cameras are deployed, the security gateway autonomously analyzes their data streams, determines their trustworthiness, and manages whitelist updates without requiring administrators to manually track and update each device, thereby maintaining adaptability while reducing management complexity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements a feedback mechanism where the security gateway continuously monitors data streams from web cameras and provides feedback to the authentication server. This automatic feedback loop enables the system to adapt to frequent device replacements by dynamically updating authentication credentials based on real-time data stream analysis, simplifying authentication management despite high device turnover.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3021549B1Terminal authentication apparatus and method
Publication Date: 2018.02.28 HUAWEI TECH CO LTD
  • EP3021549B1 patent drawingFigure 1~2
  • EP3021549B1 patent drawingFigure 3~4
  • EP3021549B1 patent drawingFigure 5

AI summary

The present invention relates to the field of communication security, and discloses a terminal authentication apparatus and method. The method includes: sending, by an authenticator, a MAC address of a terminal to an authentication server, and authenticating, by the authentication server, the MAC address according to a preset MAC address list; when an authentication result indicates that the terminal does not belong to the preset MAC address list, detecting, by a security gateway according to a data stream of the terminal, whether the terminal is a trusted terminal, and instructing, according to a detection result, the authentication server to update the MAC address list; and after the MAC address list is updated, triggering the authenticator to re-authenticate the terminal. The present invention resolves a problem that normal monitoring is seriously affected due to the fact that a terminal that is not in a whitelist is directly not allowed to access a monitoring network; whether the terminal is a trusted terminal is detected according to the data stream of the terminal, the terminal accessing the network is allowed or rejected according to a detection result, and the MAC address of the terminal does not need to be manually added to the authentication server, thereby reducing a workload.