Method, data processing system and computer program for securing functionality of user equipment connected to a local network
By implementing continuous biometric authentication and home trust score calculation in IoT devices, the problem of unauthorized use of IoT devices in homes or workplaces is solved, improving device security and user experience.
Patent Information
- Application Number
- CN202180015408.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-02-27
- Filing Date
- 2021-02-17
- Publication Date
- 2025-12-12
- Estimated Expiration
- 2041-02-17
AI Technical Summary
Existing IoT devices are easily used by unauthorized users in homes or workplaces, and existing authentication methods affect user experience and security.
Continuous biometric authentication uses biometric-enabled devices connected to the local network to collect users' biometric data, calculate a home trust score to determine the user's authorization status, and then decide on the function response strategy.
It improves the security of IoT devices and prevents unauthorized use without affecting the authorized user experience.
Smart Images

Figure CN115136627B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present disclosure relates to security of user devices connected to a local network, such as devices included in the "Internet of Things" (IoT).
[0002] More specifically, one aspect relates to a computer-implemented method of securing functionality of a user device connected to a local network provided at a premises. Another aspect relates to a data processing system comprising: a processor configured to perform such a method; a computer program comprising instructions which, when the program is executed by the computer, cause the computer to carry out such a method; a computer-readable data carrier having stored thereon such a computer program; and a data carrier signal carrying such a computer program. BACKGROUND
[0003] As more and more devices are connected, premises such as homes and workplaces are increasingly becoming "smart" environments that support IoT devices to communicate over a network local to the premises in the sense that they are provided with means for transmitting data. Such a local network can also provide access to remote systems and networks, e.g. via providing Internet access.
[0004] Individuals inhabiting a smart environment are becoming increasingly accustomed to the convenience provided by their local IoT and familiar with the opportunities to perform tasks by means of connected devices. For example, a connected fridge can provide a convenient online grocery shopping function, a smart TV can provide easy access to pay-per-view and / or age-restricted content, and a voice-assisted device can provide access to data that can be confidential, such as details of meetings stored in a personal electronic calendar.
[0005] It can be seen that certain IoT device functionalities, including all of the above examples, can need to be secured against unauthorised use. Currently, authorisation to access functionality is typically assumed when requested via a user interface of a device connected to a local network associated with a premises, based on only authorised users having physical access to the premises. However, these devices are susceptible to being used by unauthorised individuals. Such individuals include, for example, criminals who have illegally entered the premises, individuals who have a legitimate reason to physically access the premises but do not use the IoT devices therein, such as dishonest tradesmen, and categories of individuals who can be authorised to use some IoT device functionality but are restricted from others, such as children (in their home) or non-management staff (at their workplace).
[0006] Some IoT devices secure their functionality by requiring a user to provide authentication credentials. However, this reduces the convenience of the user experience and increases the time taken to access secure functionality.
[0007] What is needed is a way to provide appropriate security for IoT device functionality without adversely affecting the experience of authorized users. SUMMARY
[0008] According to a first aspect, there is provided a computer-implemented method of securing functionality of a user device connected to a local network provided at a premises, the method comprising:
[0009] determining a premises trust score indicative of a likelihood that an authorized user of the user device is present at the premises, the determining being dependent on:
[0010] (i) data received from one or more biometric-capable devices connected to the local network, different from the user device, the data being indicative of continuous biometric authentication of a current user of the respective biometric-capable device; or
[0011] (ii) a lack thereof;
[0012] then causing the user device to respond to a request for functionality, made through a local user interface comprised thereby, in a manner dependent on the premises trust score.
[0013] The determining step can be performed periodically.
[0014] When the determining is dependent on the above option (i), the method can further comprise:
[0015] establishing a connection with one of the one or more biometric-capable devices through the local network; and
[0016] subsequently receiving data from the biometric-capable device, the determining step being responsive thereto.
[0017] The method can further comprise receiving an indication that a request for functionality has been made at the user device; the determining step being performed in response thereto.
[0018] When the determining is dependent on the above option (i) and data is received from a plurality of biometric-capable devices, the method can further comprise receiving data from the plurality of biometric-capable devices; and the determining step can comprise calculating a weighted average of device trust scores indicated by the data for respective ones of the plurality of biometric-capable devices, each device trust score being indicative of a likelihood that the authorized user of the user device is a current user of the respective biometric-capable device.
[0019] The step of causing the user device to respond to the request for functionality can comprise one of:
[0020] controlling the user device to respond to requests for functionality in a particular way;
[0021] selecting one of a plurality of policies defining a permission response to a request for functionality, the selection being made in dependence on the house trust score, and then sending the selected policy to the user device for enforcement by the user device; and
[0022] indicating the house trust score to the user device.
[0023] According to a second aspect, there is provided a data processing system comprising a processor configured to perform the method of the first aspect.
[0024] The data processing system can comprise:
[0025] a local network access point for a local network; and / or
[0026] a server external to the local network but in communication with the local network; and / or
[0027] a user device.
[0028] According to a third aspect, there is provided a computer program comprising instructions which, when the program is executed by a computer, cause the computer to carry out the method of the first aspect.
[0029] According to a fourth aspect, there is provided a computer readable data carrier having stored thereon the computer program of the third aspect.
[0030] According to a fifth aspect, there is provided a data carrier wave signal carrying the computer program of the third aspect. BRIEF DESCRIPTION OF DRAWINGS
[0031] Various aspects of the disclosure will now be described, by way of example only, with reference to the accompanying drawings. In the drawings:
[0032] Figure 1 An example system in which the methods of the disclosure can be employed is shown schematically;
[0033] Figure 2A An example access point is shown schematically;
[0034] Figure 2B An example biometrically enabled device is shown schematically;
[0035] Figure 2C An example user device is shown schematically;
[0036] Figure 2D An example server is shown schematically; and
[0037] Figure 3is a flowchart showing a computer-implemented method of ensuring functionality of user devices connected to a local network provided at a premises. DETAILED DESCRIPTION
[0038] The following description is presented to enable any person skilled in the art to make and use the system, and is provided in the context of particular applications. Various modifications to the disclosed embodiments will be readily apparent to those skilled in the art.
[0039] According to the present disclosure, appropriate security is provided for IoT device functionality without adversely affecting the experience of authorized users. This is achieved through continuous biometric authentication, in which a user of a device is authenticated "in the background" by monitoring their biometrics over time. The biometrics are collected by one or more biometric-enabled devices connected to a local network provided at a premises, such as a home or commercial property. The biometric data is then aggregated to determine a premises trust score, which indicates the likelihood that an authorized user of a user device connected to the local network is present at the premises. This premises trust score is then used to determine how to respond to requests for functionality received by the user device.
[0040] Biometrics are measurable, unique characteristics of a human that can be used to mark and describe individuals. Thus, one or a combination of biometrics of an individual can be used to identify the individual. Biometrics include both physiological and behavioral characteristics. The term "biometric-enabled device" is used here to refer to any device that includes functionality to measure one or more biometrics.
[0041] Continuous authentication refers to authentication that is performed on an ongoing basis. This is in contrast to traditional authentication, which is prompted by a specific external stimulus indicating that authentication is required for a request for a function. (In the traditional case, the request for a function can be specific, such as a request to access a protected file, or more general, such as a request to log in to a device that enables multiple functions of the device.) Continuous authentication is based on measurements that are passively obtained from the user, i.e., without requiring the user to intentionally perform any specific prompted or remembered action. The measurements for continuous biometric authentication can be implemented by sampling one or more continuous sensor outputs and / or by triggering one or more sensors as needed. The measurements can be performed continuously; i.e., one after the other, as fast as the measurement apparatus allows. Alternatively, they can be performed on a regular basis. For example, a measurement or series of measurements can accompany any action or any class of action (as opposed to a specific action) on or by the biometrically enabled device, such as processing by the biometrically enabled device and / or use of any user input devices included in the device and / or receipt or transmission of communications by the biometrically enabled device. Optionally, the measurements can be performed based on a specific time (e.g., regularly (e.g., periodically)), can be performed according to some other time pattern, or be triggered randomly (e.g., according to a random variable).
[0042] Figure 1 An example system 1000 in which this approach can be employed is shown. A local network is provided for a house 1100 by an access point 1110. One or more biometrically enabled devices 1120 are provided with access to the local network of the house 1100 by wired and / or wireless connections to the access point 1110. These biometrically enabled devices 1120 can include one or more of a desktop computer, a laptop computer, and a tablet computer, a smart phone, a smart watch, smart glasses, smart clothing, and a smart sports device, for example. One or more user devices 1130 are also provided with access to the local network of the house 1100 by wired and / or wireless connections to the access point 1110. These user devices 1130 can include one or more of a smart television (TV), a smart refrigerator, a connected printer, and a voice-assisted device, for example.
[0043] The access point 1110 can optionally be connected to a wider network (e.g., the Internet 1200) in order to communicate with one or more remote servers 1300.
[0044] Although only a single access point 1110 is shown in Figure 1 , a local network can employ multiple access points and / or signal boosters to perform this function.
[0045] Figure 2AAn example access point 2110 is illustrated schematically (which may correspond, for example, to...). Figure 1 Access point 1110), an example access point includes a processor 2112 operatively connected to each of memory 2114 and transceiver 2116.
[0046] Figure 2B An example biometric identification enabling device 2120 is illustrated schematically (which may, for example, correspond to...). Figure 1 One or more biometric enabling devices 1120, the biometric enabling device including a processor 2122 operatively connected to each of a memory 2124, a transceiver 2126 and one or more biometric enabling sensors 2128.
[0047] Figure 2C An example user device 2130 is illustrated schematically (which may correspond, for example, to...). Figure 1 One or more user devices 1130), the user devices including a processor 2132 operatively connected to each of a memory 2134, a transceiver 2136 and one or more user interfaces 2138.
[0048] Figure 2D An example server 2300 is illustrated schematically (which may correspond to, for example, a...). Figure 1 The example server (1300) includes a processor 2302 operatively connected to each of the memory 2304 and the transceiver 2306.
[0049] Access point 2110, biometric enabling device 2120, user equipment 2130, and server 2300 may include any or all of them. Figure 2A through Figure 2D Additional components are not shown; only those most relevant to this disclosure are shown.
[0050] Figure 3 It shows the connection to the house (such as) Figure 1 User equipment (such as, respectively) provided on the local network at house 1100) Figure 1 and Figure 2C The flowchart of the computer implementation method of the security functions of user equipment 1130, 2130) 3000.
[0051] Method 3000 can be executed by a appropriately configured processor of the data processing system, such as... Figure 2A The processor 2112 of the access point 2110 Figure 2C The processor 2132 of the user equipment 2130 or Figure 2Dby the processor 2302 of the server 2300. The method steps can all be performed by one or more processors of a single device, or can be distributed among multiple devices. Particular tasks can be assigned to devices according to system needs and resource availability. For example, tasks requiring low latency can be performed as locally as possible to the user device requesting the function (e.g., at an access point or the user device itself), while resource intensive processing tasks (i.e., tasks requiring significant processing power and / or memory and / or power) can be performed by devices with more resources available (e.g., at an access point or a server).
[0052] The method 3000 comprises determining, at step S310, a premises trust score (PTS) indicative of a likelihood of an authorized user of the user device being present at the premises. The premises trust score determination depends on data received from one or more biometrically enabled devices connected to the local network, different from the user device, such as the biometrically enabled devices 1120, 2120 of Figure 1 and Figure 2B The data is indicative of a continuous biometric authentication (or lack thereof, as the case can be) of the current user of the respective biometrically enabled device.
[0053] The data can for example comprise one or more of:
[0054] i) a plurality of biometric measurements collected over a time interval;
[0055] ii) one or more biometric trust scores, each biometric trust score being based on a comparison of biometric measurements of a particular biometric by a particular biometrically enabled device over the time interval with corresponding reference biometric data; and
[0056] iii) one or more device trust scores, each device trust score being based on one or more biometric trust scores determined by a particular biometrically enabled device, optionally each biometric trust score being weighted according to a respective confidence level associated with the respective biometric.
[0057] Which of options i) to iii) is employed can be chosen depending on the resources (i.e. processing power, memory, power, etc.) available at various points in the system implementing the method 3000. For example, a biometrically enabled device with sufficient resources available can do some or all of the processing itself, providing one or more biometric trust scores or device trust scores to the access point. This reduces the load on the device determining the house trust score. However, it requires that the biometrically enabled device is provided with the appropriate functionality, e.g. via a dedicated application. A biometrically enabled device with sparse resources can instead provide only biometric measurements, leaving the processing to be done elsewhere, at least compared to the device determining the house trust score. All biometrically enabled devices connected to the local network can provide the same type of data (in the sense of options i) to iii) above), or the type of data provided can vary between biometrically enabled devices.
[0058] The biometric measurements on which this data is based can for example comprise one or more of:
[0059] • a facial recognition image,
[0060] • an iris recognition image,
[0061] • a skin pattern (e.g. one or more of a fingerprint, a toe print and a palm print) scan,
[0062] • a body geometry measurement (e.g. a hand and / or foot print),
[0063] • a vein (e.g. a palm vein) pattern scan,
[0064] • a pulse measurement,
[0065] • a gait measurement,
[0066] • a breath pattern measurement,
[0067] • a chemical signature measurement (e.g. from breath and / or sweat, including DNA, deoxyribonucleic acid),
[0068] • a voice recognition recording,
[0069] • a signature and / or general handwriting recognition scan,
[0070] • a processing signature measurement (e.g. one or more of orientation, direction and / or speed and / or acceleration of translational and / or rotational motion, hold pressure, interaction frequency and / or changes in one or more of these and / or patterns of changes in one or more of these)
[0071] • User interface interaction signature measurements (e.g., the manner in which one or more of typing, pressing buttons, interacting with touch-sensitive or gesture control devices, and viewing displays are performed), for example, determined by one or more of: force and pressure on a haptic interface; speed, cadence, frequency, style, and duration of touch or gesture based interface interactions; and visual tracking of displays), and
[0072] • Linguistic analysis measurements (e.g., from free text types and / or voice recordings).
[0073] After step S310, at step S320, the user device (UD) is caused to respond to a request for a function in a manner that depends on the house trust score, the request for the function being made through a local user interface comprised by the user device. The requested function can for example involve an outlay of resources, such as one or more of: cash, data allowance, computing resources (e.g., processing time and / or memory and / or power) and personnel time. Alternatively or additionally, the requested function can involve access to sensitive information.
[0074] Step S310 can be performed periodically, so that the house trust score remains up to date. An optional query Q320 illustrates this behavior, in which, after the house trust score is determined at step S310, it is checked whether the age of the house trust score is greater than a predetermined period T. If so, the flow returns to repeat step S310. If not, the query Q320 is repeated.
[0075] Alternatively or additionally, the determination of the house trust score at step S310 can be performed in response to establishing a connection with one of the one or more biometrically enabled devices (BCD) at optional step S302 through the local network, and then receiving data indicative of a continuous biometric authentication of a current user of the respective biometrically enabled device from the biometrically enabled device at optional step S304.
[0076] Alternatively or additionally, the determination of the house trust score at step S310 can be performed in response to receiving an indication at optional step S307 that a request for a function has been made at the user device. If the house trust score is only determined when a response to a request for a function at the user device is required, then resource savings (processing capacity, memory, power, etc.) can be achieved, but the latency of the response to the user request is higher than when the house trust score is determined in advance.
[0077] If data indicative of successive biometric authentication of the current user is received from multiple biometrically enabled devices, the determining of the premises trust score at step S310 can comprise an optional step S312 in which a weighted average of device trust scores indicated by the data for each of the multiple biometrically enabled devices is computed, each device trust score indicating a likelihood that the authorised user of the user device is the current user of the respective biometrically enabled device. The weights may, for example, correspond to confidence levels associated with each device trust score. This may, for example, depend on how vulnerable the device is considered to be to hacking.
[0078] The determination of one or more of the biometric trust score, the device trust score and the premises trust score may, for example, utilise the Dempster-Shafer theory.
[0079] The causing of the user device to respond to the request for the function at step S330 can comprise controlling the user device to respond to the request for the function in a particular way at optional step S332a. Alternatively, step S330 can comprise selecting one of a plurality of policies defining permissible responses to the request for the function in dependence on the premises trust score, and then sending the selected policy to the user device for enforcement by the user device at optional step S332b. As a further alternative, step S330 can comprise indicating the premises trust score to the user device at optional step S332c, so that the user device can determine an appropriate response to the request for the function itself.
[0080] Any policies applied to determine an appropriate response to the request for the function based on the premises trust score can be stored locally on, or accessible by, one or more of the devices involved in the determination. Such policies can be static or updatable (e.g. with updates requiring specific authentication, such as the provision of a password). They may, for example, be provided by a communications network provider or an administrator of the local network (e.g. a subscriber to a service provided by the communications network provider).
[0081] The policies can refer to a trust hierarchy. For example, the policies for a voice assistant device can be defined as follows.
[0082] Trust score Policy level Explanation 66.6%-100.0% 3 All functions allowed without specific authentication 33.3%-66.5% 2 Purchase requires specific authentication 0.0%-33.2% 1 Purchase and calendar information requires specific authentication
[0083] The method 3000 can be implemented by a computer program comprising instructions which, when the program is executed by a computer, cause the computer to carry out the method. Such a computer program can be stored on a computer-readable data carrier or carried by a data carrier signal. It can be provided, for example, in the form of a dedicated application or as a function within an application managing various aspects of a local network. For example, such an application can be provided by a telecommunication network provider to a subscriber to aid in joining and / or configuring devices and / or connection usage monitoring on a local network.
[0084] Analyzing the biometric recognition measurements to determine one or more of the biometric recognition trust score, the device trust score, and the premises trust score can employ, for example, a classification technique such as an artificial neural network. Machine learning can be used to improve the reliability of one or more of the biometric recognition trust score, the device trust score, and the premises trust score.
[0085] Other implementations will be apparent to those skilled in the art from consideration of the specification and practice of the embodiments disclosed herein. The specification and examples can be considered to be exemplary only.
[0086] Furthermore, where a process or method is described herein with an enumerated list of steps or sequentially arranged steps, it can be possible, in some instances, to change the order of some steps, or, in certain circumstances, even to perform some steps concurrently, and still properly execute the process or method. Also, not all steps are necessarily required to execute a process or method, and not all steps can necessarily be utilized in the execution of a process or method. Further, not all processes or methods necessarily execute all of the steps in the same order as they are listed. Unless otherwise expressly specified, the specific steps of the process or method claims herein are not to be construed as special orderings of steps, unless specifically stated otherwise in the corresponding claim. That is, the operations / steps can be performed in any order, unless otherwise indicated, and embodiments can include more or fewer operations / steps than those disclosed herein. It is further contemplated that a particular operation / steps can be performed or carried out before, concurrently with, or after another operation / steps according to the described embodiments.
[0087] The methods described herein can be encoded as executable instructions embodied in a computer readable medium, including, without limitation, non-transitory computer- readable storage media, storage devices, and / or storage media. These instructions can be executed by a processor (or one or more computers, processors, and / or other devices) to cause the processor (one or more computers, processors, and / or other devices) to perform at least a portion of the methods described herein. Non-transitory computer-readable storage media include, without limitation, volatile and non-volatile storage devices such as random access memory (RAM), read-only memory (ROM), magnetic disks, optical disks, and other storage devices. Non-transitory computer-readable storage media do not include a transitory signal per se.
[0088] Where reference is made herein to a processor, it is understood that reference is being made to a single processor or multiple processors operably connected to each other. Similarly, where reference is made herein to a memory, it is understood that reference is being made to a single memory or multiple memories operably connected to each other.
[0089] The methods and processes can also be partially or entirely embodied in hardware modules or apparatuses or firmware, such that when the hardware modules or apparatuses are activated, they perform the associated methods and processes. A combination of code, data, and hardware modules or apparatuses can be used to implement the methods and processes.
[0090] Examples of processing systems, environments, and / or configurations that can be suitable for use with the embodiments described herein include, but are not limited to, embedded computer devices, personal computers, server computers (dedicated or cloud (virtual) servers), handheld or laptop devices, multiprocessor systems, microprocessor-based systems, set top boxes, programmable consumer electronics, mobile telephones, network personal computers (PCs), minicomputers, mainframe computers, distributed computing environments that include any of the above systems or devices, and the like. The hardware modules or apparatuses described in this disclosure include, but are not limited to, application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs), dedicated or shared processors, and / or other hardware modules or apparatuses.
[0091] User devices can include, but are not limited to, static user devices such as PCs and mobile user devices such as smartphones, tablets, laptops, and smartwatches.
[0092] The receivers and transmitters described herein can be standalone or can be included in transceivers. The communication links described herein include at least one transmitter capable of sending data to at least one receiver over one or more wired or wireless communication channels. Wired communication channels can be arranged for electrical or optical transmission. Such communication links can optionally further include one or more relay transceivers.
[0093] User input devices can include, but are not limited to, microphones, buttons, keypads, touch screens, touch pads, trackballs, joysticks, mice, gesture control devices, and brain control (e.g., electroencephalography, EEG) devices. User output devices can include, but are not limited to, speakers, buzzers, display screens, projectors, indicator lights, haptic feedback devices, and refreshable Braille displays. User interface devices can include one or more user input devices, one or more user output devices, or both.
Claims
1. A computer-implemented method of securing functionality of a user device connected to a local network provided at a premises, the method comprising: determining a premises trust score indicative of a likelihood that an authorised user of the user device is present at the premises, the determining being dependent on: (i) data received from one or more biometrically-enabled devices connected to the local network other than the user device, the data being indicative of a continuous biometric authentication of a current user of the respective biometrically-enabled device; or (ii) a lack of the data; then causing the user device to respond to a request for functionality in a manner dependent on the premises trust score, the request for functionality being made through a local user interface comprised by the user device.
2. The method of claim 1, wherein, The step of determining is performed periodically.
3. The method of claim 1, wherein, The determining is dependent on option (i) of claim 1, the method further comprising: establishing a connection with one of the one or more biometrically-enabled devices through the local network; and subsequently receiving the data from the biometrically-enabled device, the step of determining being responsive to this.
4. The method of claim 1, The method further comprises: receiving an indication that the request for functionality has been made at the user device; the step of determining being performed in response to this.
5. The method of any of claims 1 to 4, wherein: the determining is dependent on option (i) of claim 1; the data is received from a plurality of the one or more biometrically-enabled devices; the method further comprises receiving the data from the plurality of biometrically-enabled devices; and the step of determining comprises calculating a weighted average of device trust scores indicated by the data for each of the plurality of biometrically-enabled devices, each device trust score being indicative of a likelihood that the authorised user of the user device is a current user of the respective biometrically-enabled device.
6. The method of any one of claims 1 to 4, wherein, The step of causing the user device to respond to the request for functionality comprises one of: controlling the user device to respond to the request for functionality in a particular manner; selecting one of a plurality of policies defining permissible responses to the request for functionality, the selection being made in dependence on the premises trust score, then sending the selected policy to the user device for enforcement by the user device; and indicating the premises trust score to the user device.
7. A data processing system comprising a processor configured to perform the method of any of claims 1 to 6.
8. The data processing system of claim 7, the data processing system comprising: a local network access point for the local network; and / or a server external to the local network but in communication with the local network; and / or the user device. 9. A computer-readable data carrier having stored thereon a computer program, the computer program comprising instructions which, when executed by a computer, cause the computer to carry out the method according to any one of claims 1 to 6.
Citation Information
Patent Citations
System and method for biometric authentication using social network
CN108293054A
Systems and methods for providing security in smart buildings
US10447736B1