Multi-Factor Authentication for Internet of Things Devices
The multi-factor authentication method of obtaining identity credentials through the interaction between IoT devices and adjacent devices to generate second-factor credentials has been solved, and the problem of IoT device identity authentication in the prior art is vulnerable to attacks, achieving higher security identity authentication.
Patent Information
- Application Number
- CN202180069181.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-10-21
- Filing Date
- 2021-10-21
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2041-10-21
AI Technical Summary
The prior art lacks effective means of multi-factor authentication in protecting the security of information between Internet of Things (IoT) devices. Traditional single-factor authentication methods such as user names and passwords are vulnerable to attacks, and time-based password authentication is vulnerable to time source manipulation.
IoT devices obtain identity credentials by interacting with adjacent devices, generate second-factor credentials, and perform multi-factor authentication by combining the identity credentials of adjacent devices to ensure the security of identity verification.
Improve the identity authentication security of IoT devices, prevent unauthorized access, enhance information security, and reduce the risk of information leakage.
Smart Images

Figure CN116325841B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure generally relates to information security, and more particularly to authenticating Internet of Things (IoT) devices by leveraging multi-factor authentication, which generates a second factor credential by utilizing identity credentials from neighboring IoT devices. Background Art
[0002] Information security (sometimes abbreviated as infosec) is the practice of protecting information by mitigating information risks. For example, information security, as part of information risk management, attempts to prevent or at least reduce the probability of unauthorized / inappropriate access to data or the illegal use, disclosure, interruption, deletion, corruption, modification, inspection, recording, or devaluation of information. It also involves actions aimed at reducing the adverse effects of such events.
[0003] One technique for providing information security is through multi-factor authentication, which is an electronic authentication method where, for example, a computer user can be authorized to access a website or application only after successfully presenting two or more pieces of evidence (or factors) to the authentication mechanism: knowledge (something the user and only the user knows), personal possession (something the user and only the user has), and inherent (something the user and only the user is). It protects users from attacks by unknown individuals attempting to access their data, such as personal identity information or financial assets.
[0004] Two-factor authentication (also known as 2FA) is a type or subset of multi-factor authentication. It is a method of confirming a user's claimed identity by using a combination of two different factors: 1) something they know, 2) something they have, or 3) something they are. Third-party authenticator (TPA) applications can implement two-factor authentication, typically by displaying a randomly generated and continuously refreshed code that the user can use.
[0005] Although multi-factor authentication has been used to protect information in attempts to grant access to websites or applications only by authenticated computer users, there has been no major development in protecting information stored between Internet of Things (IoT) devices. Summary of the Invention
[0006] In one embodiment of the present disclosure, a computer-implemented method for authenticating an Internet of Things (IoT) device using multi-factor authentication includes: obtaining, by the IoT device, identity credentials from one or more other IoT devices over a period of time to generate a second-factor credential. The method further includes providing a request to an authentication system to prove the identity of the IoT device. The method additionally includes providing a first-factor credential to the authentication system. Further, the method includes receiving a challenge from the authentication system for providing the second-factor credential. Further, the method includes returning the second-factor credential generated based on the identity credentials obtained from one or more other IoT devices. Further, the method includes receiving an indication from the authentication system that the IoT device has proven the identity of the IoT device in response to the second-factor credential including a minimum number of required identity credentials.
[0007] Other forms of embodiments of the computer-implemented method described above are in systems and computer program products.
[0008] The features and technical advantages of one or more embodiments of the present disclosure have been outlined rather broadly above so that the detailed description of the present disclosure that follows may be better understood. Additional features and advantages of the present disclosure will be described hereinafter, which may form the subject matter of the claims of the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS
[0009] A better understanding of the present disclosure may be obtained when the following detailed description is considered in conjunction with the following drawings, in which:
[0010] Figure 1 An Internet of Things (IoT) environment for practicing the principles of the present disclosure in accordance with an embodiment of the present disclosure is shown;
[0011] Figure 2 An embodiment of the hardware configuration of an IoT device of the present disclosure is shown;
[0012] Figure 3 An embodiment of the present disclosure showing the hardware configuration of an authentication system representative of a hardware environment for implementing the present disclosure is shown;
[0013] Figure 4 is a flowchart of a method for establishing requirements for generating a second-factor credential by an IoT device during authentication of the IoT device during an establishment phase; and
[0014] Figure 5 is a flowchart of a method for authenticating an IoT device in an execution phase by the IoT device providing a second-factor credential to an authentication system using a minimum number of required identity credentials of adjacent IoT devices. DETAILED DESCRIPTION
[0015] As described in the background art section, information security (sometimes abbreviated as infosec) is the practice of protecting information by mitigating information risks. For example, information security, as part of information risk management, attempts to prevent or at least reduce the probability of unauthorized / inappropriate access to data or the illegal use, disclosure, interruption, deletion, corruption, modification, inspection, recording, or devaluation of information. It also involves actions aimed at reducing the adverse effects of such events.
[0016] One technique for providing information security is via multi-factor authentication, which is an electronic authentication method where a computer user can be authorized to access a website or application only after successfully presenting two or more pieces of evidence (or factors) to the authentication mechanism: knowledge (something the user and only the user knows), personal possession (something the user and only the user has), and inherence (something the user and only the user is). It protects users from attacks by unknown individuals attempting to access their data such as personal identity information or financial assets.
[0017] Two-factor authentication (also known as 2FA) is a type or subset of multi-factor authentication. It is a method of verifying the identity claimed by a user by using a combination of two different factors: 1) something they know, 2) something they have, or 3) something they are. A third-party authenticator (TPA) application can implement two-factor authentication, typically by displaying a randomly generated and continuously refreshed code that the user can use.
[0018] Although multi-factor authentication has been used to protect information in attempts to grant access to websites or applications only by authenticated computer users, there has been no major development in protecting information stored between Internet of Things (IoT) devices.
[0019] An IoT device is a piece of hardware with sensors that transfers data from one place to another via the Internet. Types of IoT devices include wireless sensors, software, actuators, and computer devices. For example, IoT devices can be used in the following areas: connected applicants, smart home security systems, autonomous farming equipment, wearable health monitors, smart factory devices, wireless inventory trackers, ultra-high-speed wireless Internet, biometric cybersecurity scanners, and shipping containers and logistics tracking.
[0020] Typically, to authenticate or prove the identity of an IoT device, the IoT device simply uses a traditional username and password, which is a single factor and does not provide the security level of multi-factor authentication.
[0021] However, there have been some recent advancements in using multi-factor authentication to provide a higher level of security for data stored on IoT devices. For example, an IoT device stores a key used to generate time-based passwords. An authenticated identification device may also have the same key. The IoT device establishes a secure connection with the identification device via a wireless network. The IoT device then uses the key and the current access time to generate a time-based password and receives a second time-based password from the identification device via the secure connection. If the two time-based passwords match, the identification device is authenticated.
[0022] This method is similar to the method in which an RSA key fob is used to provide the second factor. Unfortunately, such a method is vulnerable to unauthorized manipulation of the time source within the IoT device.
[0023] Currently, there is no means for using multi-factor authentication to authenticate Internet of Things (IoT) devices in a more secure manner than previous attempts.
[0024] Embodiments of the present disclosure provide a means for using multi-factor authentication to authenticate IoT devices in a more secure manner than previous attempts.
[0025] In some embodiments of the present disclosure, the present disclosure includes computer-implemented methods, systems, and computer program products for authenticating Internet of Things (IoT) devices using multi-factor authentication. In one embodiment of the present disclosure, identity credentials of adjacent IoT devices are obtained by the IoT device to be authenticated. Such identity credentials can be used to generate a second factor credential during the multi-factor authentication process. In one embodiment, during a trust state, such as when the IoT device and its adjacent IoT devices are installed, the authentication system pairs the IoT device with a designated adjacent IoT device to be in constant communication. The authentication system may require that the second factor credential generated by the IoT device be based on identity credentials obtained from at least a minimum number of these adjacent IoT devices or from a designated IoT device among these adjacent IoT devices. In one embodiment, such identity credentials are obtained by the IoT device during a "neighbor observation period" corresponding to a designated duration that may occur periodically, such as at a designated time interval. After providing a request to prove its identity to the authentication system, the IoT device provides the authentication system with a first factor credential, such as a username and password, that can be embedded within the IoT device. After the authentication system confirms the accuracy of the first factor credential, such as via a lookup table listing the username and password associated with the IoT device, the authentication system challenges the IoT device to provide a second factor credential. After receiving the challenge to provide the second factor credential from the authentication system, the IoT device returns the second factor credential to the authentication system, which is generated based on identity credentials obtained from adjacent IoT devices. After determining that the received second factor credential includes the identity credentials of the designated adjacent IoT device or the minimum number of the designated adjacent IoT devices, the authentication system approves the authentication. The IoT device then receives an indication from the authentication system that the IoT device has proven its identity. In this manner, the IoT device authenticates using multi-factor authentication in a more secure manner than previous attempts.
[0026] In the following description, numerous specific details are set forth in order to provide a thorough understanding of the present disclosure. However, it will be apparent to one of ordinary skill in the art that the present disclosure may be practiced without such specific details. In other instances, well-known circuits are shown in block diagram form in order not to obscure the present disclosure with unnecessary detail. For the most part, details such as timing considerations have been omitted, since such details are not necessary for obtaining a complete understanding of the present disclosure and are within the skill of the ordinary artisan in the relevant art.
[0027] Now referring in detail to the drawings, Figure 1 illustrates an Internet of Things (IoT) environment 100 for practicing the principles of the present disclosure in accordance with an embodiment of the present disclosure. The IoT environment 100 includes IoT devices 102A - 102D connected via a network 103 (inFigure 1 An authentication system 101 (identified as "IoT Device A", "IoT Device B", "IoT Device C", and "IoT Device D" respectively). The IoT devices 102 can be collectively or individually referred to as IoT devices 102 (plural) or IoT device 102.
[0028] The authentication system 101 is configured to authenticate or prove the identity of the IoT device 102 without human interaction. In one embodiment, the authentication system 101 requires multi-factor authentication in addition to simple username and password to authenticate or prove the identity of the IoT device 102. As discussed herein, examples of authentication systems that can be modified to authenticate the IoT device 102 without human interaction include HID and Duo Security by The following provides a description of the hardware configuration of the authentication system 101 in conjunction with Figure 3 further.
[0029] In one embodiment, as further discussed below, the authentication system 101 is connected to a database 104 for storing identity credentials of the registered IoT devices 102.
[0030] In one embodiment, the IoT device 102 is a type of hardware having sensors that transfer data from one place to another via the Internet. The types of IoT devices 102 include wireless sensors, software, actuators, and computer devices. For example, the IoT device 102 can be used in the following fields: networked applicants, smart home security systems, autonomous farming equipment, wearable health monitors, smart factory equipment, wireless inventory trackers, ultra-high-speed wireless Internet, biometric network security scanners, and shipping containers and logistics tracking.
[0031] The following provides a description of the hardware configuration of an exemplary IoT device 102 in conjunction with Figure 2 further.
[0032] Figure 2 An embodiment of the present disclosure showing the hardware configuration of the IoT device 102 ( Figure 1 ) is presented, and the IoT device 102 represents a hardware environment for implementing the present disclosure.
[0033] Refer to Figure 2 , the IoT device 102 includes a processor 201 and a data storage device 202 (e.g., magnetic storage device, optical storage device, flash storage device), which is enabled to main store and run software programs or applications 203 (such as lightweight applications), and communicate with other IoT devices 102 and the authentication system 101 via a network 103, as Figure 1As shown. As used herein, a "lightweight application" refers to a computer program that is designed to have a small memory footprint and low CPU usage, thus having an overall low usage of system resources. In one embodiment, the program instructions of application 203 (including its components discussed herein) are executed by processor 201.
[0034] In one embodiment, application 203 may include different components, such as listener 204, broadcaster 205, recorder 206, and sensing / actuating component 207. Generally, listener 204 is used to receive data or other inputs via network 103 ( Figure 1 ), while broadcaster 205 is used to broadcast data or other outputs via network 103. Recorder 206 is used to record data. Sensing / actuating component 207 undertakes the sensing and actuating functions conventionally associated with IoT devices. Generally, sensing / actuating component 207 can be used to sense or measure environmental parameters (such as temperature, brightness, sound, etc.), as may be appropriate in the context of the device.
[0035] In one embodiment, storage device 202 also includes the storage of a username and password 208, which is used as the first factor credential provided to authentication system 101 in combination with the multi-factor authentication techniques discussed herein.
[0036] Return Figure 1 , network 103 can be, for example, a local area network, a wide area network, a wireless wide area network, a circuit-switched telephone network, a Global System for Mobile Communications (GSM) network, a Wireless Application Protocol (WAP) network, a WiFi network, an IEEE 802.11 standard network, different combinations thereof, etc. Without departing from the scope of the present invention, other networks (the description of which is omitted herein for brevity) can also be used in conjunction with Figure 1 system 100.
[0037] Environment 100 is not limited in scope to any one particular network architecture. Environment 100 can include any number of authentication systems 101, IoT devices 102, and networks 103.
[0038] Now refer to Figure 3 , Figure 3 illustrates an embodiment of the present disclosure representing the hardware configuration of authentication system 101 ( Figure 1 ) for implementing the present disclosure.
[0039] Authentication system 101 has a processor 301 connected to different other components via a system bus 302. Operating system 303 runs on processor 301 and provides access to Figure 3Control and coordination of the functions of different components. The application 304 according to the principles of the present disclosure runs in conjunction with the operating system 303 and provides calls to the operating system 303, where the calls implement different functions or services to be performed by the application 304. The application 304 may include, for example, a program for authenticating the IoT device 102 ( Figure 1 ) using multi-factor authentication, as further discussed below in conjunction with Figures 4 - 5 .
[0040] Referring again to Figure 3 , the read-only memory (“ROM”) 305 is connected to the system bus 302 and includes a basic input / output system (“BIOS”) that controls certain basic functions of the authentication system 101. The random access memory (“RAM”) 306 and the disk adapter 307 are also connected to the system bus 302. It should be noted that software components including the operating system 303 and the application 304 can be loaded into the RAM 306, and the RAM 306 can be the main memory of the authentication system 101 for execution. The disk adapter 307 can be an integrated drive electronics (“IDE”) adapter that communicates with a disk unit 308 (e.g., a disk drive). Note that, as further discussed below in conjunction with Figures 4 - 5 , the program for authenticating the IoT device 102 using multi-factor authentication can reside in the disk unit 308 or in the application 304.
[0041] The authentication system 101 may also include a communication adapter 309 connected to the bus 302. The communication adapter 309 interconnects the bus 302 with an external network (e.g., Figure 1 's network 103) to communicate with other devices such as the IoT device 102.
[0042] The present invention can be a system, method, and / or computer program product of any possible degree of integration of technical details. The computer program product may include a computer-readable storage medium (or media) having computer-readable program instructions thereon for causing a processor to execute aspects of the present invention.
[0043] A computer-readable storage medium can be a tangible device that can retain and store instructions for use by an instruction execution device. The computer-readable storage medium can be, for example but not limited to, an electronic storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination of the foregoing. A non-exhaustive list of more specific examples of the computer-readable storage medium includes the following: a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a static random access memory (SRAM), a portable compact disk read-only memory (CD-ROM), a digital versatile disk (DVD), a memory stick, a floppy disk, a mechanical encoding device such as a punched card, or a raised structure in a groove having instructions recorded thereon, and any suitable combination of the foregoing. As used herein, a computer-readable storage medium should not be construed as a transient signal per se, such as a radio wave or other freely propagating electromagnetic wave, an electromagnetic wave propagating through a waveguide or other transmission medium (e.g., an optical pulse passing through an optical fiber cable), or an electrical signal transmitted through a wire.
[0044] The computer-readable program instructions described herein can be downloaded from a computer-readable storage medium to a corresponding computing / processing device via a network (e.g., the Internet, a local area network, a wide area network, and / or a wireless network), or to an external computer or an external storage device. The network can include a copper transmission cable, an optical transmission fiber, a wireless transmission, a router, a firewall, a switch, a gateway computer, and / or an edge server. A network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards the computer-readable program instructions for storage in a computer-readable storage medium within the corresponding computing / processing device.
[0045] The computer-readable program instructions for carrying out operations of the present invention may be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-related instructions, microcode, firmware instructions, state-setting data, configuration data for integrated circuits, or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages such as Smalltalk, C++, etc. and procedural programming languages such as the "C" programming language or similar programming languages. The computer-readable program instructions may be executed entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer, or entirely on the remote computer or server. In the latter case, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., through the Internet using an Internet service provider). In some embodiments, an electronic circuit, including, for example, a programmable logic circuit, a field-programmable gate array (FPGA), or a programmable logic array (PLA), can execute the computer-readable program instructions by using the state information of the computer-readable program instructions to personalize the electronic circuit, so as to perform various aspects of the present invention.
[0046] The present invention will be described below with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to embodiments of the present invention. It should be understood that each block of the flowcharts and / or block diagrams, and the combinations of blocks in the flowcharts and / or block diagrams, can be implemented by computer-readable program instructions.
[0047] These computer-readable program instructions can be provided to a processor of a computer or other programmable data processing apparatus to produce a machine, such that the instructions executed via the processor of the computer or other programmable data processing apparatus create a means for implementing the functions / acts specified in one or more blocks of the flowcharts and / or block diagrams. These computer-readable program instructions can also be stored in a computer-readable storage medium, which instructions cause a computer, a programmable data processing apparatus, and / or other devices to work in a particular manner, so that the computer-readable storage medium storing the instructions includes a manufacture including instructions for implementing aspects of the functions / acts specified in one or more blocks of the flowcharts and / or block diagrams.
[0048] The computer-readable program instructions can also be loaded onto a computer, other programmable data processing apparatus, or other device, such that a series of operation steps are executed on the computer, other programmable apparatus, or other device to produce a computer-implemented process, so that the instructions executed on the computer, other programmable apparatus, or other device implement the functions / acts specified in one or more blocks of the flowcharts and / or block diagrams.
[0049] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of the possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in the flowchart or block diagram may represent a module, segment, or portion of instructions, which includes one or more executable instructions for implementing the specified logical function. In some alternative implementations, the functions noted in the blocks may occur out of the order noted in the figures. For example, two blocks shown in succession may in fact be completed as one step, executed simultaneously, substantially simultaneously, in partial or complete temporal overlap, or the blocks may sometimes be executed in the reverse order, depending on the functionality involved. It should also be noted that each block of the block diagrams and / or flowchart illustrations, and combinations of blocks in the block diagrams and / or flowchart illustrations, can be implemented by special purpose hardware-based systems that perform the specified functions or acts or combinations of special purpose hardware and computer instructions.
[0050] As described above, generally, in order to authenticate or prove the identity of an IoT device, the IoT device simply uses traditional usernames and passwords, which is a single factor and does not provide the security level of multi-factor authentication. However, there have been some recent advancements in using multi-factor authentication to provide a higher level of security for data stored on IoT devices. For example, the IoT device stores a key for generating time-based passwords. The authenticated identification device may also have the same key. The IoT device establishes a secure connection with the identification device via a wireless network. Then, the IoT device uses the key and the current access time to generate a time-based password and receives a second time-based password from the identification device via the secure connection. If the two time-based passwords match, the identification device is authenticated. This method is similar to the method where an RSA key card is used to provide the second factor. Unfortunately, such a method is vulnerable to unauthorized manipulation of the time source within the IoT device. Currently, there is no means for using multi-factor authentication to authenticate Internet of Things (IoT) devices in a more secure manner than previous attempts.
[0051] Embodiments of the present disclosure provide a means for using multi-factor authentication to authenticate an IoT device 102 in a more secure manner than previous attempts that used interactions with adjacent IoT devices 102 ( Figure 1 and Figure 2 ), as discussed below in conjunction with Figures 4 - 5 . Figure 4 is a flowchart of a setup phase when establishing a requirement for the IoT device 102 to generate a second factor credential during authentication of the IoT device 102. Figure 5 is a flowchart of an execution phase for authenticating the IoT device 102 by the IoT device 102 providing a second factor credential using the identity credential of an adjacent IoT device 102.
[0052] Figure 4 It is a flowchart of a method 400 for establishing a requirement for an IoT device 102 to generate a second factor credential when authenticating the IoT device 102 during a setup phase according to an embodiment of the present disclosure.
[0053] Although the following description describes the authentication system 101 using two-factor authentication to authenticate the IoT device 102, the authentication system 101 may utilize multiple other authentication factors to authenticate the IoT device 102, such as three-factor authentication. A person of ordinary skill in the art will be able to apply the principles of the present disclosure to such implementations. Further, embodiments that apply the principles of the present disclosure to such implementations will fall within the scope of the present disclosure.
[0054] See Figure 4 in conjunction with Figures 1 - 3 the authentication system 101 defines the minimum number of required neighboring IoT devices 102 to be used to generate a second factor credential or defines the minimum number of required sets for generating the second factor credential and the minimum number of IoT devices from the minimum number of the required sets. As used herein, a "neighbor" or "proximate" IoT device 102 (e.g., IoT device 102A) of an IoT device 102 (e.g., IoT device 102B, IoT device 102C, IoT device 102D) refers to those IoT devices 102 (e.g., IoT device 102B) that have been paired with the IoT device 102 (e.g., IoT device 102A) during a trust state (discussed below). Further, such "adjacent" IoT devices 102 are positioned close enough to communicate with the IoT device 102 whose identity is to be authenticated, such as via the network 103. Such communication requires the IoT device 102 (e.g., IoT device 102A) whose identity is to be authenticated to request an identity credential from the adjacent IoT devices 102 (e.g., IoT device 102B, IoT device 102C, IoT device 102D). As used herein, an "identity credential" refers to a security key, digital signature, or characteristic of the IoT device 102, such as but not limited to sensor characteristics (e.g., electrochemical, gyroscopic, pressure, light sensor, global positioning system (GPS), pressure, radio frequency identification (RFID), etc.), the strength of signal characteristics (e.g., -60 dBm, -75 dBm, etc.), signal modulation characteristics (e.g., 2.4 GHz Wi-Fi, 5 GHz Wi-Fi, Ethernet), and signal coding characteristics (e.g., ASC11, HEX, etc.).
[0055] In one embodiment, adjacent IoT devices 102 are required to register with the authentication system 101, such as during a trust state, which requires providing such identity credentials to the authentication system 101. In one embodiment, such identity credentials may be provided to the authentication system 101 periodically, such as during a neighbor observation period (discussed below) in which the IoT device 102 obtains the identity credentials of its adjacent IoT devices 102.
[0056] In one embodiment, these credentials are stored in a table, which may reside in a storage device (e.g., memory 305, disk drive 308). Such credentials may be associated with a particular IoT device 102 in the table, such as by an identifier of the IoT device 102 (e.g., an object identifier (such as a barcode), a communication identifier (such as an Internet Protocol (IP) address), and an application identifier (such as a Uniform Resource Identifier (URI) and a Uniform Resource Locator (URL))). In an alternative embodiment, such identity credentials and associated IoT device identifiers may be stored in a database (such as database 104 connected to the authentication system 101).
[0057] As discussed above, the authentication system 101 defines the minimum number of required adjacent IoT devices 102 to be used to generate a second factor credential. For example, in the two-factor authentication technique of the present disclosure, the authentication system 101 may require that the IoT device 102 to be authenticated needs to use the identity credentials from a minimum number of three adjacent IoT devices (e.g., IoT device 102B, IoT device 102C, IoT device 102D) to generate a second factor credential.
[0058] In addition, as discussed above, the authentication system 101 defines the minimum number of required sets to be used to generate a second factor credential. As used herein, a "set" refers to a group of adjacent IoT devices 102. For example, a set ("A") may correspond to the set of {A, B, C, D, and E}, where A, B, C, D, and E are each individual adjacent IoT devices 102. The authentication system 101 may define the minimum number of such sets to be used when generating a second factor credential by the IoT device 102 whose identity is to be authenticated. In addition, the authentication system 101 may further define the minimum number of adjacent IoT devices from the minimum number of sets to be used to generate a second factor credential. For example, the authentication system 101 may define a minimum number of three adjacent IoT devices from the minimum number of sets in the two-factor authentication technique of the present disclosure to generate a second factor credential.
[0059] In step 402, the authentication system 101 defines the identities of the required adjacent IoT devices 102 corresponding to the minimum number of required IoT devices 102 to be used to generate the second factor credential, or defines the identities of the required IoT devices 102 within the set of the required minimum number to be used to generate the second factor credential.
[0060] For example, the authentication system 101 may require that an IoT device 102 (e.g., IoT device 102A) be authenticated to use the identity credentials of IoT devices 102B, IoT device 102C, and IoT device 102D to generate a second factor credential corresponding to the required minimum number of three adjacent IoT devices 102 needed to generate the second factor credential. As used herein, "generating" the second factor credential means producing a credential that includes the required identity credentials of the adjacent IoT devices 102. "Generating" may be performed by appending the identifiers of the adjacent IoT devices 102 (e.g., object identifiers such as barcodes, communication identifiers such as Internet Protocol (IP) addresses, and application identifiers such as Uniform Resource Identifiers (URI) and Uniform Resource Locators (URL)) and their identity credentials. Thus, the second factor credential may include a series of identifiers (identifiers of the adjacent IoT devices 102) appended with their associated identity credentials.
[0061] In one embodiment, such a requirement is stored in a table associated with the IoT device 102 to be authenticated (e.g., IoT device 102A), which may be stored in a storage medium (e.g., memory 305, disk drive 308) or database 104. In this way, the authentication system 101 will be able to determine whether the second factor credential received from the IoT device 102 to be authenticated is correct because the authentication system 101 can access the identity credentials of each of the adjacent IoT devices 102 and will be able to construct the second factor credential using the identity credentials of the required adjacent IoT devices 102 needed to generate the second factor credential. Additionally, as discussed above, such identity credentials may be continuously updated, such as during a neighbor observation period (discussed further below), so that the identity credentials are up-to-date.
[0062] In another example, the authentication system 101 may require that the IoT device 102 (e.g., IoT device 102A) be authenticated to use a required minimum number of sets (e.g., three sets) composed of the defined adjacent IoT devices 102. For example, the authentication system 101 may define the set "R" as the set including {A, B, C, D, and E}, the set "S" as the set including {A, B, E, and F}, and the set "T" as the set including {A, E, I, O, and U}, where each letter corresponds to a specific adjacent IoT device 102. The authentication requirement may be that at least 3 adjacent IoT devices 102 are required to be used to generate the second factor credential, including any adjacent IoT device 102 listed within each of these sets. Thus, IoT devices A and E need to be used, and a third IoT device 102 is selected from the set of {B, C, D, F, {I, O, and U}}.
[0063] Thus, in step 402, the authentication system 101 notifies the IoT device 102 to be authenticated about the specific requirements for generating the second factor credential. Thus, the IoT device 102 has knowledge of the adjacent IoT devices 102 from which the IoT device 102 should obtain its identity credentials to generate the second factor credential. Such identity credentials can be obtained from the required adjacent IoT devices 102 during the neighbor observation period.
[0064] In step 403, the authentication system 101 defines a "neighbor observation period" during which the IoT device 102 to be authenticated obtains identity credentials from the required adjacent IoT devices for generating the second factor credential. In one embodiment, the neighbor observation period includes a duration. In one embodiment, the neighbor observation period is defined to occur periodically, such as at a specified time interval.
[0065] During this time period, the IoT device 102 to be authenticated collects the identity credentials of its adjacent IoT devices 102, such as the identity credentials of its adjacent IoT devices 102 required by the authentication system 101.
[0066] In addition, in one embodiment, during this time period, those adjacent IoT devices 102 transmit their identity credentials to the authentication system 101 such that the authentication system 101 will be able to determine the second factor credential to be received from the IoT device 102 for authentication. As previously discussed, such identity credentials can be stored in a table (which may reside in a storage device (e.g., memory 305, disk drive 308) or database 104).
[0067] In step 404, the authentication system 101 establishes a trust state for the IoT device 102 (e.g., IoT device 102A) to be authenticated paired with adjacent IoT devices, where the identity credentials of at least a subset of these adjacent IoT devices are used to generate a second factor credential. In one embodiment, once such IoT devices 102 are paired, they maintain continuous communication. In one embodiment, such IoT devices 102 are installed during the trust state.
[0068] In one embodiment, during the trust state, the username and password 208 that serve as the first factor credential for the IoT device 102 can be provided to the authentication system 101 to verify the accuracy of the first factor credential when the IoT device 102 provides the first factor credential to the authentication system 101. In one embodiment, such username and password are stored in a table (which may reside in a storage device (e.g., memory 305, disk drive 308) or database 104) together with the identifier of the associated IoT device 102 (e.g., an object identifier (such as a barcode), a communication identifier (such as an Internet Protocol (IP) address), and an application identifier (such as a Uniform Resource Identifier (URI) and a Uniform Resource Locator (URL))). By associating the username and password with the corresponding IoT device 102, the authentication system 101 can identify the username and password associated with the IoT device 102 by performing a lookup in the table based on the identifier of the IoT device 102.
[0069] At the completion of the establishment phase, the following combination Figure 5 discusses the execution phase of authenticating the IoT device 102 (e.g., IoT device 102A) by the IoT device 102 providing a second factor credential to the authentication system 101 using the required identity credentials of the adjacent IoT devices 102.
[0070] Figure 5 is a flowchart of a method 500 for the execution phase of authenticating the IoT device 102 (e.g., IoT device 102A) by the IoT device 102 providing a second factor credential to the authentication system 101 using the identity credentials of a minimum number of required adjacent IoT devices 102 according to an embodiment of the present disclosure.
[0071] See Figure 5 , in combination with Figures 1 - 4 In step 501, the IoT device 102 to be authenticated obtains identity credentials from the required adjacent IoT devices 102 during a neighbor observation period, and the identity credentials are used to generate a second factor credential, as discussed above.
[0072] In step 502, the IoT device 102 provides a request to the authentication system 101 to prove the identity of the IoT device 102. In one embodiment, the request is provided to the authentication system 101 periodically. In one embodiment, in response to a trigger event (e.g., an event generated when an item is added, updated, or deleted in the registry), the request is provided to the authentication system 101.
[0073] In step 503, the IoT device 102 provides a first-factor credential (e.g., a username, a password) to the authentication system 101. In one embodiment, the username and password 208 are embedded in the IoT device 102, such as stored within the storage device 202.
[0074] In one embodiment, after the authentication system 101 confirms the accuracy of the first-factor credential (such as via a lookup in a table listing the username and password associated with the IoT device 102), the authentication system 101 challenges the IoT device 102 to provide a second-factor credential.
[0075] In step 504, the IoT device 102 receives a challenge from the authentication system 101 to provide a second-factor credential.
[0076] In step 505, the IoT device 102 returns a second-factor credential to the authentication system 101, which is generated based on the identity credentials obtained from the required adjacent IoT devices 102. For example, the authentication system 101 may require the IoT device 102 (e.g., IoT device 102A) to be authenticated to generate a second-factor credential using the identity credentials of IoT devices 102B, IoT devices 102C, and IoT devices 102D, where the second-factor credential corresponds to the required minimum number of three adjacent IoT devices 102 needed to generate the second-factor credential. Thus, the second-factor credential includes the identity credentials of IoT devices 102B, IoT devices 102C, and IoT devices 102D provided to the authentication system 101.
[0077] In another example, as discussed above, the authentication system 101 may require that the IoT device 102 (e.g., IoT device 102A) be authenticated to use a required minimum number of sets (e.g., three sets) composed of the defined adjacent IoT devices 102. For example, the authentication system 101 may define set "R" as the set including {A, B, C, D, and E}, set "S" as the set including {A, B, E, and F}, and set "T" as the set including {A, E, I, O, and U}, where each letter corresponds to a specific IoT device 102. The authentication requirement may be that at least 3 adjacent IoT devices 102 are required to be used to generate the second factor credential, including any adjacent IoT device 102 listed within each of these sets. Therefore, IoT devices A and E need to be used, and the third IoT device 102 is selected from the set of {B, C, D, F, {I, O, and U}}. Thus, the IoT device 102 obtains the identity credentials of IoT devices A and B and one selected from IoT devices C, D, E, F, I, O, and U. Then, a second factor credential is generated using such identity credentials, and the second factor credential is provided to the authentication system 101.
[0078] As discussed above, as used herein, "generating" the second factor credential refers to generating a credential that includes the required identity credentials of the adjacent IoT devices 102. "Generating" may be performed by appending the identifiers of the adjacent IoT devices 102 (e.g., object identifiers (such as barcodes), communication identifiers (such as Internet Protocol (IP) addresses), and application identifiers (such as Uniform Resource Identifiers (URIs) and Uniform Resource Locators (URLs))) and their identity credentials. Thus, the second factor credential may include a series of identifiers (identifiers of the adjacent IoT devices 102) appended with their associated identity credentials.
[0079] In step 506, the authentication system 101 receives the second factor credential from the IoT device 102.
[0080] In step 507, the authentication system 101 determines whether the received second factor credential contains the minimum number of required identity credentials.
[0081] For example, if the authentication system 101 requires that the IoT device 102 (e.g., IoT device 102A) be authenticated to use at least the identity credentials of IoT device 102B, IoT device 102C, and IoT device 102D to generate the second factor credential, then as long as those identity credentials are included in the second factor credential, the authentication system 101 will approve the authentication; otherwise, the authentication system 101 will not approve the authentication.
[0082] As described above, if the authentication system 101 requires that the IoT device 102 (e.g., IoT device 102A) be authenticated to collect the identity credentials of at least 3 adjacent IoT devices 102 that are members of each of the sets R, S, and T (set "R" includes the set {A, B, C, D, and E}, set "S" includes the set {A, B, E, and F}, and set "T" includes the set {A, E, I, O, and U}), including any adjacent IoT device 102 listed in each of the sets. Thus, IoT devices A and E need to be used, and the third IoT device 102 is selected from the set {B, C, D, F, {I, O, and U}}. Therefore, as long as the second-factor credentials include the identity credentials of IoT devices A and E and the identity credentials of an IoT device 102 selected from IoT devices C, D, E, F, I, O, and U, the authentication system 101 will approve the authentication; otherwise, the authentication system 101 will not approve the authentication.
[0083] If the received second-factor credentials contain the minimum number of required identity credentials, then at step 508, the authentication system 101 approves the authentication and issues an indication to the IoT device 102 that the authentication of the IoT device 102 has been approved. In this way, the IoT device 102 is authenticated using multi-factor authentication in a more secure manner than previous attempts. In one embodiment, as a result of being authenticated, the authentication system 101 establishes a secure connection for the IoT device 102 within the IoT environment 100, such as between itself and another IoT device 102.
[0084] In step 509, the IoT device 102 receives an indication from the authentication system 101 that the IoT device 102 has proven its identity. In one embodiment, such an indication can be in the form of an alert or a message. As discussed above, due to being authenticated, the IoT device 102 has a secure connection within the IoT environment 100 (such as between itself and another IoT device 102). Therefore, it is permissible to securely transfer the data stored in the IoT device 102 to another device within the secure system, such as another IoT device 102. That is, upon receiving such an indication, the data stored in the IoT device 102 can become accessible to another device (such as another IoT device 102) within the protected IoT environment 100.
[0085] However, if the received second-factor credentials do not contain the minimum number of required identity credentials, then at step 510, the authentication system 101 does not approve the authentication and issues an indication to the IoT device 102 that the authentication of the IoT device 102 has not been approved.
[0086] In step 511, the IoT device 102 receives an indication from the authentication system 101 that the IoT device 102 has not yet proven its identity. In one embodiment, such an indication may be in the form of an alert or a message. In one embodiment, after receiving such an indication, data stored in the IoT device 102 may not be allowed to be transmitted to another device, such as another IoT device 102. That is, when such an indication is received, the data stored in the IoT device 102 may not be accessible by another device (such as another IoT device 102).
[0087] As a result of the foregoing, embodiments of the present disclosure provide a means for improving information security in a technology or technical field for authenticating IoT devices utilizing multi-factor authentication in a more secure manner than previous attempts.
[0088] Moreover, the present disclosure improves techniques or technical fields related to information security. As described above, information security (sometimes abbreviated as infosec) is the practice of protecting information by mitigating information risks. For example, information security, as part of information risk management, attempts to prevent or at least reduce the probability of unauthorized / inappropriate access to data or the illegal use, disclosure, interruption, deletion, corruption, modification, inspection, recording, or depreciation of information. It also involves actions aimed at reducing the adverse effects of such events. One technique for providing information security is via multi-factor authentication, which is an electronic authentication method where a computer user can be authorized to access a website or application only after successfully presenting two or more pieces of evidence (or factors) to the authentication mechanism: knowledge (something the user and only the user knows), personal possession (something the user and only the user has), and inherence (something the user and only the user is). It protects users from attacks by unknown persons attempting to access their data, such as personal identity information or financial assets. Although multi-factor authentication has been used to protect information in attempts to grant access to websites or applications only by authenticated computer users, there has been no major development in protecting information stored between Internet of Things (IoT) devices. Typically, to authenticate or prove the identity of an IoT device, the IoT device simply uses a traditional username and password, which is a single factor and does not provide the security level of multi-factor authentication. However, there have been some recent advancements in leveraging multi-factor authentication to provide a higher level of security for data stored on IoT devices. For example, an IoT device stores a key for generating time-based passwords. The authenticated identification device may also have the same key. The IoT device establishes a secure connection with the identification device via a wireless network. Then, the IoT device uses the key and the current access time to generate a time-based password and receives a second time-based password from the identification device via the secure connection. If the two time-based passwords match, the identification device is authenticated. This method is similar to the method where an RSA key card is used to provide the second factor. Unfortunately, such a method is vulnerable to unauthorized manipulation of the time source within the IoT device. Currently, there is no means for leveraging multi-factor authentication to authenticate Internet of Things (IoT) devices in a more secure manner than previous attempts.
[0089] Embodiments of the present disclosure improve this technique by having an IoT device obtain an identity credential of an adjacent IoT device to be authenticated. In one embodiment of the present disclosure, an identity credential of an adjacent IoT device is obtained by the IoT device to be authenticated. Such an identity credential can be used to generate a second factor credential during a multi-factor authentication process. In one embodiment, during a trust state, such as when the IoT device and its adjacent IoT devices are installed, the authentication system pairs the IoT device with a designated adjacent IoT device to be in constant communication. The authentication system may require that the second factor credential generated by the IoT device be based on an identity credential obtained from at least a minimum number of these adjacent IoT devices or from a designated IoT device among these adjacent IoT devices. In one embodiment, such an identity credential is obtained by the IoT device during a "neighbor observation period" that corresponds to a designated duration, which may occur periodically, such as at a designated time interval. After providing a request to prove its identity to the authentication system, the IoT device provides a first factor credential, such as a username and password, that can be embedded within the IoT device to the authentication system. The authentication system challenges the IoT to provide a second factor credential after confirming the accuracy of the first factor credential, such as via a lookup table listing the username and password associated with the IoT device. After receiving the challenge to provide a second factor credential from the authentication system, the IoT device returns the second factor credential to the authentication system, which is generated based on the identity credential obtained from the adjacent IoT device. After determining that the received second factor credential includes the identity credential of the designated adjacent IoT device or the minimum number of the designated adjacent IoT devices, the authentication system approves the authentication. The IoT device then receives an indication from the authentication system that the IoT device has proven its identity. In this way, the IoT device authenticates using multi-factor authentication in a more secure manner than previous attempts. Additionally, in this way, there is an improvement in the technical field related to information security.
[0090] The technical solution provided by this application cannot be performed in a human mind or by a human using pen and paper. That is, without using a computer, it cannot be achieved within any reasonable amount of time and with any reasonable accuracy expectation in a person's mind or when a person uses pen and paper.
[0091] The description of the different embodiments of the present disclosure has been presented for purposes of illustration but is not intended to be exhaustive or limited to the disclosed embodiments. Many modifications and variations will be apparent to a person of ordinary skill in the art without departing from the scope of the described embodiments. The terms used herein have been chosen to best explain the principles of the embodiments, the practical application, or a technical improvement of the technology found in the marketplace, or to enable a person of ordinary skill in the art to understand the embodiments disclosed herein.
Claims
1. A computer-implemented method for authenticating Internet of Things (IoT) devices using multi-factor authentication, the method comprising: Obtaining, by the IoT device, identity credentials from one or more other IoT devices over a period of time to generate a second factor credential; Providing a request to an authentication system to prove the identity of the IoT device; Providing a first factor credential to the authentication system; Receiving, from the authentication system, a challenge to provide the second factor credential; Returning the second factor credential, the second factor credential being generated based on the identity credentials obtained from the one or more other IoT devices; and Receiving, from the authentication system, an indication that the IoT device has proven the identity of the IoT device in response to the second factor credential containing a minimum number of required identity credentials.
2. The method according to claim 1, wherein The identity credentials include security keys, digital signatures, or characteristics of the one or more other IoT devices, where the characteristics include one or more of the following: sensor characteristics, signal strength characteristics, signal modulation characteristics, and signal coding characteristics.
3. The method according to claim 1, wherein, Performing, periodically or in response to a triggering event, the request to the authentication system to prove the identity of the IoT device.
4. The method according to claim 1, further comprising: Defining a minimum number of IoT devices to be used for generating the second factor credential or defining a minimum number of sets to be used for generating the second factor credential, where each of the sets includes a set of identified IoT devices.
5. The method according to claim 4, further comprising: Defining the identity of the required IoT devices corresponding to the minimum number of IoT devices to be used for generating the second factor credential, or defining the identity of the required IoT devices within the required minimum number of sets to be used for generating the second factor credential.
6. The method according to claim 5, further comprising: Defining an observation period during which the IoT device obtains identity credentials from the required IoT devices corresponding to the minimum number of IoT devices to be used for generating the second factor credential, or from the required IoT devices within the required minimum number of sets to be used for generating the second factor credential.
7. The method according to claim 1, further comprising: Establishing a trust state for pairing the IoT device with the one or more other IoT devices, where the IoT device communicates continuously with the one or more other IoT devices.
8. A computer program product for authenticating Internet of Things (IoT) devices using multi-factor authentication, the computer program product comprising one or more computer-readable storage media having program code embodied therein, the program code including program instructions for: Obtaining, by the IoT device, identity credentials from one or more other IoT devices over a period of time to generate a second factor credential; Providing a request to an authentication system to prove the identity of the IoT device; Provide a first factor credential to the authentication system; Receive a challenge from the authentication system to provide the second factor credential; Return the second factor credential, the second factor credential being generated based on identity credentials obtained from the one or more other IoT devices; and In response to the second factor credential containing a minimum number of required identity credentials, receive an indication from the authentication system that the IoT device has proven the identity of the IoT device.
9. The computer program product according to claim 8, wherein, The identity credentials include a security key, a digital signature, or characteristics of the one or more other IoT devices, where the characteristics include one or more of the following: sensor characteristics, strength of signal characteristics, signal modulation characteristics, and signal coding characteristics.
10. The computer program product according to claim 8, wherein, Periodically or in response to a trigger event, perform the request to the authentication system to prove the identity of the IoT device.
11. The computer program product according to claim 8, wherein, Define a minimum number of IoT devices to be used to generate the second factor credential or define a minimum number of sets to be used to generate the second factor credential, where each of the sets includes a set of identified IoT devices.
12. The computer program product according to claim 11, wherein, Define the identity of the required IoT devices corresponding to the minimum number of IoT devices to be used to generate the second factor credential, or define the identity of the required IoT devices within the required minimum number of sets to be used to generate the second factor credential.
13. The computer program product according to claim 12, wherein, Define an observation period during which the IoT device obtains identity credentials from the required IoT devices corresponding to the minimum number of IoT devices to be used to generate the second factor credential, or from the required IoT devices within the required minimum number of sets to be used to generate the second factor credential.
14. The computer program product according to claim 8, wherein, Establish a trust state in which the IoT device is paired with the one or more other IoT devices, where the IoT device communicates continuously with the one or more other IoT devices.
15. An Internet of Things device, comprising: A memory for storing a computer program for authenticating the IoT device using multi-factor authentication; And A processor connected to the memory, where the processor is configured to execute program instructions of the computer program, the program instructions including: The IoT device obtains identity credentials from one or more other IoT devices over a period of time to generate a second factor credential; Provide a request to the authentication system to prove the identity of the IoT device; Provide a first factor credential to the authentication system; Receive a challenge from the authentication system to provide the second factor credential; Return the second factor credential, the second factor credential being generated based on identity credentials obtained from the one or more other IoT devices; and In response to the second factor credential containing a minimum number of required identity credentials, receive an indication from the authentication system that the IoT device has proven the identity of the IoT device.
16. The IoT device according to claim 15, wherein, The identity credential includes a security key, a digital signature, or characteristics of the one or more other IoT devices, where the characteristics include one or more of the following: sensor characteristics, strength of signal characteristics, signal modulation characteristics, and signal coding characteristics.
17. The IoT device according to claim 15, wherein, Periodically or in response to a trigger event, execute the request for the authentication system to authenticate the identity of the IoT device.
18. The IoT device according to claim 15, wherein, Define the minimum number of IoT devices to be used to generate the second factor credential or define the minimum number of sets to be used to generate the second factor credential, where each of the sets includes a set of identified IoT devices.
19. The IoT device according to claim 18, wherein, Define the identity of the required IoT devices corresponding to the minimum number of IoT devices to be used to generate the second factor credential, or define the identity of the required IoT devices within the required minimum number of sets to be used to generate the second factor credential.
20. The IoT device according to claim 19, wherein, Define an observation period during which the IoT device obtains an identity credential from the required IoT devices corresponding to the minimum number of IoT devices to be used to generate the second factor credential, or from the required IoT devices within the required minimum number of sets to be used to generate the second factor credential.
Citation Information
Patent Citations
Internet of Things equipment, Internet of Things authentication platform, and authentication method and system
CN108632231A
Static token systems and methods for representing dynamic real credentials
CN110462663A