Device Authentication via Utilization Code for Secure Data Exchange

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Server applications face challenges in authenticating devices without requiring users to log in, while protecting copyrighted data from piracy and unauthorized access, especially when providing access to non-password protected web or app pages.

Innovation Solution

A utilization code is provided to client devices, which serves as a unique identifier for device authentication, allowing the server application to authenticate devices without user login, and is used to generate encryption keys for secure data exchange.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If device authentication is implemented without user login, then ease of operation is improved, but security and data protection may be compromised

Engineering Contradiction:
Improveease of accessVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary device identification and authentication before data transmission begins. The server identifies the client device using device-specific information (IP address, user agent, etc.) and establishes security parameters in advance, allowing seamless access while maintaining security controls throughout the data exchange process

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary authentication mechanism that mediates between the client device and server. This intermediary process uses device identification data and encryption keys to verify authenticity without requiring traditional user login, thus maintaining security while improving ease of operation

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If copyrighted data is sent to unauthenticated devices, then ease of operation is improved, but piracy and digital theft increase

Engineering Contradiction:
Improveaccess convenienceVSAvoidpiracy risk
Core Design Contradiction:
Ease of operationVSObject-generated harmful factors

Solution Approach 1:

The system applies preliminary anti-action by implementing device authentication and data encryption before copyrighted data is transmitted. The server verifies device legitimacy and establishes secure communication channels in advance, preventing piracy and digital theft before they can occur during data access

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The patent changes the security parameters by transitioning from traditional user-login-based authentication to device-based authentication using identification data such as IP addresses and user agents. This parameter change maintains access convenience while significantly reducing piracy risk through automated device verification and encryption

Inventive Principle:
Principle #35Parameter changes

3Reliability

If traditional user login is required for authentication, then security is improved, but ease of operation deteriorates

Engineering Contradiction:
Improveauthentication securityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system implements self-service authentication where the client device automatically provides device identification information (IP address, user agent, etc.) and the server autonomously verifies this information against stored device profiles. This eliminates the need for manual user login while maintaining security through automated verification processes

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent substitutes the mechanical interaction of traditional login (user manually entering credentials) with an automated electronic authentication mechanism. The server uses device identification data and cryptographic verification to authenticate devices programmatically, replacing manual authentication processes with automated security protocols that maintain reliability while improving convenience

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentEP3453136B1Methods and apparatus for device authentication and secure data exchange between a server application and a device
Publication Date: 2021.11.10 PEGASUS MEDIA SECURITY LLC
  • EP3453136B1 patent drawingFigure 1
  • EP3453136B1 patent drawingFigure 2
  • EP3453136B1 patent drawingFigure 3

AI summary

In some embodiments, a method includes sending an authentication request to a client device to obtain a utilization code in response to a request from the client device to access data. The utilization code is uniquely associated with the client device. The method includes obtaining an authentication response including the utilization code from the client device and authenticating the client device if the utilization code matches a utilization identifier stored in a database. The method includes generating an encryption key using a seed based at least in part on the utilization code and encrypting the data with the encryption key to generate encrypted data and sending, when the utilization code matches the utilization identifier stored in the database, the encrypted data to the client device without requiring a user of the client device to login.