Intelligent Terminal Signature Authentication Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current intelligent terminal equipment methods for information transmission have security issues, as stolen passwords can be used to access servers, leading to potential information breaches.
Innovation Solution
The method involves generating a signature based on local contact information, which is transmitted to a server for saving and later used for identification, ensuring that only authorized access can occur by comparing the original signature with a saved signature, thus preventing unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a password is transmitted for authentication, then the access service can be provided, but the security is compromised because stolen passwords can be used to access the server
Solution Approach 1:
The patent extracts the contact information from the terminal and uses it to generate a signature that is transmitted to the server. This replaces the traditional password transmission model, where the password itself is sent. The signature is derived from the contact information through a hashing process, so the actual contact information never leaves the terminal, while still enabling authentication.
Solution Approach 2:
The patent introduces a signature as an intermediary element between the terminal and server authentication. Instead of directly transmitting passwords or contact information, the terminal generates a signature based on contact information and transmits this signature to the server for verification. This intermediary mechanism enables authentication without exposing sensitive data.
2Device complexity
If the vendor can access the terminal to steal passwords, then the authentication process is simple, but the information security is compromised
Solution Approach 1:
The patent extracts only the necessary authentication credential (signature) from the contact information and transmits it to the server. The contact information itself remains securely stored in the terminal and is never transmitted. This extraction approach minimizes the attack surface even if the vendor has access to the terminal, as the sensitive contact information cannot be obtained through simple access.
Solution Approach 2:
The patent performs a preliminary hashing operation on the contact information to generate a signature before transmission. This preliminary action transforms the sensitive contact information into a non-reversible form, so that even if the signature is intercepted or the vendor accesses the terminal, the original contact information cannot be recovered from the signature.
3Adaptability or versatility
If the password is used for identification, then the access control is implemented, but the stolen password allows unauthorized access
Solution Approach 1:
The patent segments the authentication process into two independent parts: the terminal generates a signature from contact information, and the server verifies the signature against stored values. This segmentation separates the credential generation (terminal-side) from credential verification (server-side), allowing access control to be implemented without transmitting or storing sensitive passwords centrally.
Solution Approach 2:
The patent creates a cryptographic copy (signature) of the contact information that can be transmitted and verified without exposing the original. The signature is a derived representation that serves the authentication function while being non-reversible to the original contact information, enabling authorization control without the risks of copying sensitive data.
Data Source
AI summary
Intelligent terminal equipment and information transmission method and system using the same are disclosed. The method includes that intelligent terminal equipment reads the local contact information, generates a signature to be an original signature which has a corresponding terminal identifier based on the local contact information, and transmits the original signature and the terminal identifier to the server for saving the original signature and the terminal identifier in the server. The method further includes that intelligent terminal equipment captures the information transmission request, accesses the original signature generated by the local contact information, and transmits a processing information to the server to compare with the saved signature in the server for an identification process, in which the processing information includes the terminal identifier, the transmission information and the original signature. The present invention can improve the security of the information transmission for the intelligent terminal equipment.


