Device Authentication via Utilization Code for Secure Data Exchange
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Server applications face challenges in authenticating devices without requiring users to log in, while protecting copyrighted data from piracy and unauthorized access, especially when providing access to non-password protected web or app pages.
Innovation Solution
A utilization code is provided to client devices, which serves as a unique identifier for device authentication, allowing the server application to authenticate devices without user login, and is used to generate encryption keys for secure data exchange.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If device authentication is implemented without user login, then ease of operation is improved, but security and data protection may be compromised
Solution Approach 1:
The system performs preliminary device identification and authentication before data transmission begins. The server identifies the client device using device-specific information (IP address, user agent, etc.) and establishes security parameters in advance, allowing seamless access while maintaining security controls throughout the data exchange process
Solution Approach 2:
The patent introduces an intermediary authentication mechanism that mediates between the client device and server. This intermediary process uses device identification data and encryption keys to verify authenticity without requiring traditional user login, thus maintaining security while improving ease of operation
2Ease of operation
If copyrighted data is sent to unauthenticated devices, then ease of operation is improved, but piracy and digital theft increase
Solution Approach 1:
The system applies preliminary anti-action by implementing device authentication and data encryption before copyrighted data is transmitted. The server verifies device legitimacy and establishes secure communication channels in advance, preventing piracy and digital theft before they can occur during data access
Solution Approach 2:
The patent changes the security parameters by transitioning from traditional user-login-based authentication to device-based authentication using identification data such as IP addresses and user agents. This parameter change maintains access convenience while significantly reducing piracy risk through automated device verification and encryption
3Reliability
If traditional user login is required for authentication, then security is improved, but ease of operation deteriorates
Solution Approach 1:
The system implements self-service authentication where the client device automatically provides device identification information (IP address, user agent, etc.) and the server autonomously verifies this information against stored device profiles. This eliminates the need for manual user login while maintaining security through automated verification processes
Solution Approach 2:
The patent substitutes the mechanical interaction of traditional login (user manually entering credentials) with an automated electronic authentication mechanism. The server uses device identification data and cryptographic verification to authenticate devices programmatically, replacing manual authentication processes with automated security protocols that maintain reliability while improving convenience
Data Source
Figure 1
Figure 2
Figure 3
AI summary
In some embodiments, a method includes sending an authentication request to a client device to obtain a utilization code in response to a request from the client device to access data. The utilization code is uniquely associated with the client device. The method includes obtaining an authentication response including the utilization code from the client device and authenticating the client device if the utilization code matches a utilization identifier stored in a database. The method includes generating an encryption key using a seed based at least in part on the utilization code and encrypting the data with the encryption key to generate encrypted data and sending, when the utilization code matches the utilization identifier stored in the database, the encrypted data to the client device without requiring a user of the client device to login.