Wireless Device Interaction Security via Server Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless communication devices face security risks due to untrusted connections, where the identity of nearby devices is not reliably verified, leading to potential cyber attacks and false identification during device discovery operations.

Innovation Solution

A method involving a computer server that verifies the registration and proximity of devices through a database, providing a system identifier and decoding message to ensure secure access, with modes of access based on biunivocal or univocal detection, reducing the risk of malicious connections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If direct connection is made between untrusted devices, then device interaction and service access is enabled, but security risks and cyber attacks increase

Engineering Contradiction:
Improvedevice interactionVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

A server acts as an intermediary between untrusted devices, verifying device attributes and proximity before allowing interactions. The server mediates the trust relationship by validating device information against stored data and confirming physical proximity through wireless channel detection, thereby enabling secure device interaction without requiring direct trust between devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If device attributes are published on wireless channel for discovery, then device visibility and discoverability is improved, but false identification and malicious connections increase

Engineering Contradiction:
Improvedevice discoverabilityVSAvoiddevice identification accuracy
Core Design Contradiction:
Adaptability or versatilityVSMeasurement precision

Solution Approach 1:

The system implements feedback mechanisms where the server continuously monitors and validates device attributes published on wireless channels. By comparing published attributes against stored data and verifying proximity conditions, the server provides feedback to distinguish legitimate devices from malicious ones, maintaining accurate device identification while preserving discoverability.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

Device attributes are verified and validated in advance before allowing interactions to proceed. The server performs preliminary verification of device identity and proximity conditions, ensuring that only authenticated devices can establish connections, thereby preventing false identification and malicious connections while maintaining open discovery operations.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If proximity detection is performed without verification, then device discovery speed is improved, but false proximity claims and security vulnerabilities increase

Engineering Contradiction:
Improvedevice discovery speedVSAvoidproximity detection accuracy
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs partial verification of proximity conditions rather than complete validation for all interactions. By implementing selective verification based on interaction type and risk level, the system maintains efficient device discovery while providing sufficient proximity detection accuracy to prevent security breaches, balancing speed and reliability through partial action.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP2859699B1Method for performing an interaction from a communicating device configured to establish a wireless communication channel and corresponding telecommunication system
Publication Date: 2021.04.21 PROXTOME
  • EP2859699B1 patent drawingFigure 1
  • EP2859699B1 patent drawingFigure 2~3
  • EP2859699B1 patent drawingFigure 4~5

AI summary

A method is described for performing an interaction, in particular 'trusted', between a first- communication device (21) configured to establish a first wireless communication channel (30) and one or more second devices (22) configured to operate on said first wireless communication channel (30), said wireless communication channel (30) being suitable to allow the execution of discovery operations, or discovery, to search for devices that are visible, or discoverable, on said wireless communication channel within a radius of operation of said first wireless communication channel (30), said method envisioning that said first communication device (21) publish its device attributes on said wireless communication channel (30) to become visible, and detects (260) through said wireless communication channel (30) attributes (AS) published by said one or more second devices (22) to become visible, said first communication device (21) by accessing a database (60) which comprises stored attributes (AM, AS) of visible devices (22). According to the invention, said first communication device (21) is configured to establish a second communication channel (41) to communicate in a client-server relationship with a remote processor (50) which is associated with said database (60), said first communication device (21), after a discovery operation (260) of one or more second devices (22) sends over said second communication channel (41) to said remotely located computer (50) a corresponding decoding request (M263) comprising at least a system identifier ( IDM), assigned in the database (60) to said first device (21), and said attributes (AS) of the one or more second devices (22) detected on said first wireless communication channel (30), said remote computer server (50) performs with respect to said decoding request (M263) a decoding operation (600) which includes a step of obtaining from said database (60) a respective system identifier (IDS) of the one or more second detected devices (22), said remote server (50) sends (690) on said second communications channel (41) to said first device (21) a decoding message (M630, M650, M675, M685) comprising the result of said decoding operation (600), at the first communication device (21) according to the result indicated in said decoding message (M630, M650, M675, M685) received by the computer server (50) the availability is signalled of a determined mode (800, 900, 100) of access to information or services of the one or more second devices that may be detected (22).