Preventing unauthorized use while charging

By switching to a protected mode during charging and using a biometric sensor in the charging device for authentication, smart rings prevent unauthorized use and data access, addressing the lack of user authentication in existing technologies.

WO2026092841A1PCT designated stage Publication Date: 2026-05-07TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
Filing Date
2024-10-30
Publication Date
2026-05-07

AI Technical Summary

Technical Problem

Smart rings and similar chargeable devices face unauthorized use during charging, as they lack built-in user authentication means, posing a risk of unauthorized access and data exposure when left on wireless chargers.

Method used

Implement a method where the chargeable device switches to a protected mode upon charging, using extended wireless charging protocols to authenticate the user through a biometric sensor in the charging device, ensuring only authorized users can unlock the device.

Benefits of technology

Prevents unauthorized use by disabling functionality and securing data until user authentication is successful, enhancing security without adding biometric sensors to the chargeable device.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2024080719_07052026_PF_FP_ABST
    Figure EP2024080719_07052026_PF_FP_ABST
Patent Text Reader

Abstract

A method of protecting a chargeable device (100) being charged by a charging device (200) against unauthorized use is provided. The chargeable device (100) is operative to switch between an unprotected mode and a protected mode. The charging device (200) sends a certificate (453) of the charging device (200) to the chargeable device (100), the certificate comprising a public key of the charging device (200). The chargeable device (100) sends a first challenge (405) to the charging device (200). The charging device signs (456) the first challenge with a private key of the charging device (100). The charging device (200) sends the signed first challenge (457) to the chargeable device (100). In response to successfully verifying (408), by the chargeable device (100), the signed first challenge: charging (417) of the chargeable device by the charging device is initiated, the chargeable device (100) sends a second challenge (410) to the charging device (200), and the chargeable device (100) switches (416) to the protected mode. The charging device (200) acquires (469) biometric input data from the user, using a biometric sensor. The chargeable device (100), in response to a successful authentication of the user, switches (431) to the unprotected mode. The authentication of the user is based on the acquired biometric input data, biometric verification data for the user, and the second challenge.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] PREVENTING UNAUTHORIZED USE WHILE CHARGING

[0002] Technical field

[0003] The invention relates to a method of protecting a chargeable device being charged by a charging device against unauthorized use, a chargeable device for charging by a charging device, and a charging device for charging a chargeable device.

[0004] Background

[0005] Smart rings are compact wearable devices integrating sensors and communication capabilities into a ring form factor. Smart rings are designed to provide functionalities such as fitness tracking, health monitoring, contactless payments, notifications, and the ability to control other computing devices, e.g., extended Reality (XR) headsets or televisions, which are wirelessly connected to the smart ring. The latter may, e.g., be achieved by tapping or touching the smart ring, and / or rotating the smart ring around the finger, to control a user interface of an XR headset or a television.

[0006] Smart rings typically include a microcontroller or other type of processor, a memory, various sensors (e.g., accelerometer, gyroscope, heart rate sensor, touch sensors), a battery, and one or more wireless communication modules, e.g., Bluetooth, Radio Frequency Identification (RFID), or Near-Field Communication (NFC). The sensors embedded in the ring may collect data related to physical activity, heart rate, and / or biometric data, which is then processed and transmitted for real-time monitoring, or stored for later analysis or use. Contactless payments may be performed based on NFC or RFID using credit card information or other types of payment credentials which are stored in the memory of the smart ring, e.g., using the EMV standard. A challenge which is associated with the small form factor of smart rings is the limited battery lifetime, which requires users to charge their smart rings frequently, typically one or more times a week, depending on the capabilities of the smart ring and its usage. A common solution for charging smart rings and similar devices is by inductive charging, also referred to as wireless charging, e.g., in accordance with the Qi standard (see, e.g., https: / / www.wirelesspowerconsortium.com / knowledge-base / specifications / ). Wireless charging entails placing the smart ring on a wireless charger, which may be provided with a protrusion such as a rod for receiving the smart ring. Wireless charging offers the advantage of eliminating the need for a physical electrical connector.

[0007] When being placed on a wireless charger, there is an elevated risk that a person other than the authorized user of the smart ring removes the smart ring from the wireless charger. While smart rings with built-in fingerprint sensors, which require the user to authenticate before using the smart ring or at least using specific functionality of the smart ring such has contactless payments, are known, incorporating a fingerprint reader or other means of biometric authentication of the user into a smart ring increases complexity and costs.

[0008] Accordingly, there is a need for preventing unauthorized use of a smart ring, or similar chargeable device, during charging, i.e. , when the smart ring is not worn by its user but is connected to a charging device, e.g., is placed on a wireless charger.

[0009] Summary

[0010] It is an object of the invention to provide an improved alternative to the above techniques and prior art.

[0011] More specifically, it is an object of the invention to provide improved solutions for preventing unauthorized use of a chargeable device, such as a smart ring, while being charged. In particular, it is an object of the invention to provide improved solutions for preventing unauthorized use of a chargeable device without built-in biometric sensors or other means for authenticating the user of the chargeable device.

[0012] These and other objects of the invention are achieved by means of different aspects of the invention, as defined by the independent claims. Embodiments of the invention are characterized by the dependent claims.

[0013] According to a first aspect of the invention, a method of protecting a chargeable device being charged by a charging device against unauthorized use is provided. The chargeable device is operative to switch between an unprotected mode of operation and a protected mode of operation. The method comprises the charging device sending a certificate of the charging device to the chargeable device. The certificate comprises a public key of the charging device. The method further comprises the chargeable device sending a first challenge to the charging device. The method further comprises the charging device signing the first challenge with a private key of the charging device, and sending the signed first challenge to the chargeable device. The method further comprises, in response to successfully verifying, by the chargeable device, the signed first challenge, initiating charging of the chargeable device by the charging device, the chargeable device sending a second challenge to the charging device, and the chargeable device switching to the protected mode of operation. The method further comprises the charging device acquiring biometric input data from the user, using a biometric sensor comprised in the charging device. The method further comprises the chargeable device, in response to a successful authentication of a user of the chargeable device, switching to the unprotected mode of operation. The authentication of the user is based on the acquired biometric input data, biometric verification data for the user, and the second challenge.

[0014] According to a second aspect of the invention, a chargeable device for charging by a charging device is provided. The chargeable device is operative to switch between an unprotected mode of operation and a protected mode of operation. The chargeable device comprises processing circuitry operative to cause the chargeable device to be operative to receive a certificate of the charging device from the charging device. The certificate comprises a public key of the charging device. The chargeable device is further operative to send a first challenge to the charging device. The chargeable device is further operative to receive the first challenge, signed with a private key of the charging device, from the charging device. The chargeable device is further operative to, in response to successfully verifying the signed first challenge, initiate charging of the chargeable device by the charging device, send a second challenge to the charging device, and switch to the protected mode of operation. The chargeable device is further operative to, in response to a successful authentication of a user of the chargeable device, switch to the unprotected mode of operation. The authentication of the user is based on biometric input data acquired by the charging device, biometric verification data for the user, and the second challenge.

[0015] According to a third aspect of the invention, a charging device for charging a chargeable device is provided. The chargeable device is operative to switch between an unprotected mode of operation and a protected mode of operation. The charging device comprises a biometric sensor and processing circuitry operative to cause the charging device to be operative to send a certificate of the charging device to the chargeable device. The certificate comprises a public key of the charging device. The charging device is further operative to receive a first challenge from the chargeable device. The charging device is further operative to sign the first challenge with a private key of the charging device. The charging device is further operative to send the signed first challenge to the chargeable device. The charging device is further operative to acquire biometric input data from a user of the chargeable device, using the biometric sensor. The invention makes use of an understanding that existing charging protocols, in particular wireless charging protocols such as Qi, can be extended by additional signaling between a chargeable device (e.g., a smart ring) and a charging device (e.g., a wireless charger) to prevent use of the chargeable device by an unauthorized user while being charged (e.g., a smart ring placed on a wireless charger). This is achieved by the chargeable device switching to a protected mode of operation once charging commences, and using a second challenge which is exchanged between the chargeable device and the charging device to securely establish, collaboratively by the chargeable device and the charging device, that the user has been successfully authenticated before the chargeable device switches to the unprotected mode of operation.

[0016] Even though advantages of the invention have in some cases been described with reference to embodiments of the first aspect of the invention, corresponding reasoning applies to embodiments of other aspects of the invention.

[0017] Further objectives of, features of, and advantages with, the invention will become apparent when studying the following detailed disclosure, the drawings, and the appended claims. Those skilled in the art realize that different features of the invention can be combined to create embodiments other than those described in the following.

[0018] Brief description of the drawings

[0019] The above, as well as additional objects, features and advantages of the invention, will be better understood through the following illustrative and non-limiting detailed description of embodiments of the invention, with reference to the appended drawings, in which:

[0020] Fig. 1 schematically illustrates a chargeable device and a charging device, in accordance with embodiments of the invention. Fig. 2 schematically illustrates the processing circuitry of the chargeable device, in accordance with embodiments of the invention.

[0021] Fig. 3 schematically illustrates the processing circuitry of the charging device, in accordance with embodiments of the invention.

[0022] Fig. 4 shows a sequence diagram illustrating embodiments of the invention.

[0023] Fig. 5 shows a sequence diagram illustrating other embodiments of the invention.

[0024] Fig. 6 shows a sequence diagram illustrating further embodiments of the invention.

[0025] All the figures are schematic, not necessarily to scale, and generally only show parts which are necessary in order to elucidate the invention, wherein other parts may be omitted or merely suggested.

[0026] Detailed description

[0027] The invention will now be described more fully herein after with reference to the accompanying drawings, in which certain embodiments of the invention are shown. This invention may, however, be embodied in many different forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided by way of example so that this disclosure will be thorough and complete, and will fully convey the scope of the invention to those skilled in the art.

[0028] Embodiments of the invention address a problem which arises when chargeable devices such as smart rings, smart wristbands, fitness trackers, smart jewelry, smartwatches, smartphones, etc, without built-in means for authenticating the user of the chargeable device, are being placed on a wireless charging device or connected to a (wired) charging device for charging. Since the user of the smart ring has removed his or her smart ring from the finger and placed the smart ring on a charging device such as a wireless charger, there is a risk that the smart ring is removed from the charging device, and / or used, by a person other than the authorized user. Accordingly, there is a risk that the smart ring is used by an unauthorized user and / or that data of the authorized user which is stored on the smart ring can be accessed by someone who is not the unauthorized user.

[0029] Fig. 1 schematically illustrates a chargeable device 100 and a charging device 200, in accordance with embodiments of the invention, which are described in further detail below. Although embodiments of the invention are herein described as relying on wireless charging, embodiments relying in wired charging, e.g., via Universal Serial Bus (USB), can easily be envisaged.

[0030] In the present context, it is assumed that embodiments of the chargeable device 100 described herein are operative to switch between an unprotected mode of operation and a protected mode of operation. When in the protected mode of operation (in other words, the chargeable device 100 is “locked”), at least part of a functionality of the chargeable device 100 is unavailable or disabled, and / or at least part of a memory 112 comprised in the chargeable device 100 is inaccessible. Functionality being unavailable or disabled means that a user of the chargeable device 100 who is not authenticated cannot use such functionality. For example, if an unauthorized user who attempts to perform a contactless payment using a chargeable device 100 such as smart ring, the smart ring would not execute the relevant software code, i.e., executable instructions, to initiate a contactless payment while the smart ring is in protected mode. Alternatively, the credit card information or other payment credentials could be in a protected part of the memory 112 of the chargeable device 100 which is inaccessible, such that an attempt to initiate a contactless payment will fail, as payment credentials are not available.

[0031] More specifically, the at least part of the functionality of the chargeable device 100 which is unavailable or disabled may comprise one or more of contactless payments, collecting physiological data of the user, controlling an operation of the chargeable device 100, controlling an external computing device, and configuring the chargeable device 100. Furthermore, the at least part of a memory 112 comprised in the chargeable device 100 which is inaccessible may be operative to store one or more of payment credentials, physiological data of the user, biometric information of the user, user credentials, and executable instructions 113.

[0032] Embodiments of the invention solve this problem by switching the chargeable device 100, e.g., a smart ring, a smart wristband, a fitness tracker, a smart jewelry, a smartwatch, a smartphone, or the like, to the protected mode of operation when the chargeable device 100 is brought in proximity of, or is connected to, a charging device 200, in particular a wireless charging device 200, such that (wireless) charging commences. This is achieved by extending the signaling procedure which commences between the chargeable device 100 and the charging device 200 during setting up wireless charging, e.g., in accordance with the Qi standard which is implemented by many chargeable devices and charging devices (see, e.g., https: / / www.wirelesspowerconsortium.com / knowledge-base / specifications / ). In the Qi standard, the terms Power Transmitter (Product) and Power Receiver (Product) are used, which correspond to the charging device 200 and the chargeable device 100, respectively (see, e.g., “3.1 Basic concepts”, Qi Specification, Introduction, Version 2.0, April 2023, WIRELESS POWER CONSORTIUM).

[0033] When the chargeable device 100, e.g., the smart ring, is removed from the charging device 200, authentication of the user of the chargeable device 100 is required in order for the chargeable device 100 to switch to the unprotected mode of operation. If the chargeable device 100 lacks means for authenticating the user, such as a fingerprint reader or the like, embodiments of the invention rely on a biometric sensor 240 which is comprised in the charging device 200 for acquiring biometric input data (e.g., a dataset containing the response from a capacitive, ultrasonic, or thermal, fingerprint scan, image, or other representation of a fingerprint) from the user. Upon successfully authenticating the user of the chargeable device 100, by verifying the acquired biometric input data against biometric verification data for the user (which is acquired by enrolling the authorized user, e.g., by obtaining at least one biometric input data of the authorized user which is stored as a reference for later biometric authentication of the user), the chargeable device 100 switches to the unprotected mode of operation. The authentication of the user based on the acquired biometric input data is done in collaboration between the chargeable device 100 and the charging device 200.

[0034] With reference to Fig. 1 , which illustrates embodiments of the chargeable device 100 for charging by a charging device 200, the chargeable device 100 being operative to switch between an unprotected mode of operation and a protected mode of operation, the chargeable device 100 comprises processing circuitry 110 operative to cause the chargeable device 100 to be operative to perform in accordance with embodiments of the invention described herein, in particular further below with reference to Figs. 4 to 6. The chargeable device 100 further comprises charging circuitry 120 which is operative to receive a charging current from the charging device 200, e.g., via an inductive coupling 300 between a primary coil 230 comprised in the charging device 200 and a secondary coil 130 comprised in the chargeable device 100, as is known in the art. Wireless charging via the inductive coupling 300 may, e.g., be effected in accordance with the Qi standard, which utilizes the inductive coupling 300 for exchange of signals and messages between the chargeable device 100 and the charging device 200 for setting up and maintaining the charging procedure to transfer energy via the inductive coupling 300, from the charging device 200 to the chargeable device 100. For example, according to the Qi standard (see, e.g., “4.5 Communication protocol”, Qi Specification, Introduction, Version 2.0, April 2023, WIRELESS POWER CONSORTIUM, to set up power transfer and assist in its control, the Power Transmitter (corresponding to the charging device 200) and the Power Receiver (corresponding to the chargeable device 100) execute a communication protocol with each other. The Power Receiver uses amplitude shift keying to communicate requests and other information to the Power Transmitter by modulating its reflected impedance. The Power Transmitter uses Frequency Shift Keying (FSK) to provide synchronization and other information to the Power Receiver by modulating its operating frequency.

[0035] The processing circuitry 110, which is schematically illustrated in Fig. 2, may comprise one or more processors 111 , such as Central Processing Units (CPUs), microprocessors, application processors, application-specific processors, or a combination thereof, and a memory 112 comprising a computer program 113, i.e., software, comprising instructions. When executed by the processor(s) 111 , the instructions cause the chargeable device 110 to become operative in accordance with embodiments of the invention disclosed herein. The processing circuitry 110 may alternatively or additionally comprise one or more Application-Specific Integrated Circuits (ASICs), Field-Programmable Gate Arrays (FPGAs), or the like, which are operative to cause the chargeable device 100 become operative in accordance with embodiments of the invention disclosed herein.

[0036] With further reference to Fig. 1 , which illustrates embodiments of the charging device 200 for charging a chargeable device 100, the chargeable device 100 being operative to switch between an unprotected mode of operation and a protected mode of operation, the charging device 200 comprises a biometric sensor 240 and processing circuitry 210 operative to cause the charging device 200 to be operative to perform in accordance with embodiments of the invention described herein, in particular further below with reference to Figs. 4 to 6. The biometric sensor 240 may, e.g., be a fingerprint sensor, a camera (for authentication by means of face, retina and / or iris recognition), or a microphone (for authentication by means of voice recognition). The charging device 200 further comprises charging circuitry 220 which is operative to pass a charging current from the charging device 200, via the inductive coupling 300 between the primary coil 230 comprised in the charging device 200 and the secondary coil 130 comprised in the chargeable device 100, as is known in the art. Wireless charging via the inductive coupling 300 may, e.g., be effected in accordance with the Qi standard as described hereinbefore, which utilizes the inductive coupling 300 for exchange of signals and messages between the chargeable device 100 and the charging device 200 for setting up and maintaining the charging procedure to transfer energy via the inductive coupling 300, from the charging device 200 to the chargeable device 100.

[0037] The processing circuitry 210, which is schematically illustrated in Fig. 3, may comprise one or more processors 211 , such as CPUs, microprocessors, application processors, application-specific processors, or a combination thereof, and a memory 212 comprising a computer program 213, i.e. , software, comprising instructions. When executed by the processor(s) 211 , the instructions cause the charging device 200 to become operative in accordance with embodiments of the invention disclosed herein. The processing circuitry 210 may alternatively or additionally comprise one or more ASICs, FPGAs, or the like, which are operative to cause the charging device 200 to become operative in accordance with embodiments of the invention disclosed herein.

[0038] Further disclosed herein, in particular below with reference to Figs. 4 to 6, are embodiments of a method of protecting a chargeable device 100 being charged by a charging device 200 against unauthorized use, the chargeable device 100 being operative to switch between an unprotected mode of operation and a protected mode of operation.

[0039] Embodiments of the invention which are described with reference to Figs. 4 to 6 differ with respect to how authentication of an authorized user is collaboratively performed by the chargeable device 100 and the charging device 200.

[0040] More specifically, Fig. 4 illustrates embodiments of the invention which rely on biometric verification data for the user which has been acquired by the charging device 200, i.e. , the authorized user is enrolled with the charging device 200, and the charging device 200 verifies the biometric input data acquired from the user against the biometric verification data for the user.

[0041] Embodiments which are illustrated in Fig. 5, on the other hand, utilize biometric verification data for the user which has been acquired by the chargeable device 100, i.e., the authorized user is enrolled with the chargeable device 100, which sends the biometric verification data to the charging device 200 for verifying the biometric input data acquired from the user against the biometric verification data for the user.

[0042] As yet a further alternative, Fig. 6 illustrates embodiments which utilize biometric verification data for the user which has been acquired by the chargeable device 100, i.e., the authorized user is enrolled with the chargeable device 100, and the chargeable device 100 performs verification of the biometric input data, which is acquired by the charging device 200 and sent to the chargeable device 100, against the biometric verification data for the user.

[0043] In the following, operations of the chargeable device 100 and the charging device 200 are described. Together, these operations make up the method of protecting a chargeable device 100 being charged by a charging device 200 against unauthorized use.

[0044] The charging device 200 sends a certificate 453 of the charging device to the chargeable device 100. The certificate comprises a public key of the charging device 200. Advantageously, the charging device 200 may send its certificate to the chargeable device 100 as part of, or subsequent to, the handshake procedure 402 which commences between the chargeable device 100 and the charging device 200 during setup of the charging procedure, e.g., in accordance with the Qi standard (e.g., as a part of the power transfer phase, or subsequent to the negotiation phase). For example, according to the Qi standard (see, e.g., “3 Power Receiver and Power Transmitter identification” and “7.2.4.7 Authentication”, Qi Specification, Communications Protocol, Version 2.0, April 2023, WIRELESS POWER CONSORTIUM), the Power Receiver (corresponding to the chargeable device 100) can request the Power Transmitter (corresponding to the charging device 200) to identify itself to the Power Receiver with a Power Transmitter Certificate, if the Qi Extended Protocol is used.

[0045] In the case of wireless charging, i.e., the charging device 200 is a wireless charger, such handshake 402 may start when the chargeable device 100 and the charging device 200 are brought into proximity, typically a distance of a few centimeters.

[0046] In general, a certificate comprising a public key, also known as a digital certificate or identity certificate, is an electronic document which is used to prove the validity of a public key. The certificate typically includes the public key and information about it, e.g., the cryptographic algorithm used, information about the identity of its owner (called the subject, in this case the charging device 200), and the digital signature of an entity which has verified the certificate's contents (called the issuer, e.g., a Certificate Authority). Upon receiving the certificate from the charging device 200, the chargeable device 100 can verify validity of the signature. If the chargeable device 100 trusts the issuer and finds the signature to be a valid signature of the issuer, it can use the public key to communicate securely with the charging device 200. The most common format for public key certificates is defined by X.509, with additional profiles being defined in RFC 5280.

[0047] The chargeable device 100 sends a first challenge 405 to the charging device 200. The first challenge may, e.g., be a nonce, sometimes called “number used once”, such as a random number or a pseudo-random number which is derived 404 by the chargeable device 100, using a pseudo-random number generator. In general, a nonce is an arbitrary number which can be used just once in a cryptographic communication. For example, in accordance with the Qi standard (see, e.g., “5.2.3 CHALLENGE”, Qi Specification, Authentication Protocol, Version 2.0, April 2023, WIRELESS POWER CONSORTIUM), a 128-bit nonce may be used.

[0048] The charging device 200 signs 456 the first challenge with a private key of the charging device 200. The private key corresponds to the public key comprised in the certificate of the charging device 200, and can be used to prove ownership of the certificate. Then, the charging device 200 sends the signed first challenge 457 to the chargeable device 100. For example, according to the Qi standard (e.g., “5.3.3 CHALLENGE_AUTH“, Qi Specification, Authentication Protocol, Version 2.0, April 2023, WIRELESS POWER CONSORTIUM) Power Transmitters (corresponding to the charging device 200) use CHALLENGE_AUTH to respond to a CHALLENGE request from Power Receivers (corresponding to the chargeable device 100).

[0049] In response to successfully verifying 408, by the chargeable device 100, the signed first challenge, charging 417 of the chargeable device 100 by the charging device 200 is initiated. This is achieved by the chargeable device 100 and the charging device 200 in a collaborative manner as is known in the art, e.g., in accordance with the Qi standard. Further in response to successfully verifying 408 the signed first challenge, the chargeable device 100 sends a second challenge 410 to the charging device 200. Similar to the first challenge, the second challenge is a nonce, and preferably different from the first challenge. The second challenge may be derived 409 by the chargeable device 100, using the same pseudorandom number generator that is used for deriving 404 the first challenge, or a separate pseudo-random number generator. Even further in response to successfully verifying 408 the signed first challenge, the chargeable device 100 switches 416 to the protected mode of operation. When in the protected mode of operation, at least part of a functionality of the chargeable device 100 is unavailable or disabled, and / or at least part of a memory 112 comprised in the chargeable device 100 is inaccessible. For example, the at least part of functionality of the chargeable device 100 which is unavailable or disabled may comprise one or more of: contactless payments, collecting physiological data of the user, controlling an operation of the chargeable device 100, controlling an external computing device, and configuring the chargeable device 100. Further, the at least part of the memory 112 comprised in the chargeable device 100 which is inaccessible may be operative to store, e.g., one or more of: payment credentials, physiological data of the user, biometric information of the user, user credentials, and executable instructions. When in the unprotected mode of operation, these limitations on the functionality and / or memory 112 of the chargeable device 100 are not effective.

[0050] The verifying 408, by the chargeable device 100, the signed first challenge, preferably comprises checking validity of the signature of the signed first challenge using the public key of the charging device 200, as well as checking that the signed first challenge 457 which the chargeable device 100 has received from the charging device 200 is the same (number) as the first challenge 405 which the chargeable device 100 has sent to the charging device 200.

[0051] Optionally, the charging device 200 sends a signed lock signal 464 to the chargeable device 100. The charging device 200 sends the signed lock signal 464 in response to receiving the second challenge 410 from the chargeable device 100. In this case, the chargeable device 100 switches 416 to the protected mode of operation in response to successfully verifying 415 the signed lock signal. In practice, the chargeable device 100 may verify 415 the signed lock signal by verifying validity of the signature, using the public key of the charging device 200. The lock signal may be a static message, but may optionally comprise a freshness indicator such as a nonce or a timestamp.

[0052] So far, setting up the charging procedure between the chargeable device 100 and the charging device 200 has been described, in addition to switching the chargeable device 100 to its protected mode of operation, in other words “locking” the chargeable device 100 while being charged by the charging device 200. In the following, “unlocking” of the chargeable device 100 in response to successful authentication of the authorized user of the chargeable device 100 is described.

[0053] The charging device 200 acquires 469 biometric input data from the user, using a biometric sensor 240 comprised in the charging device 200. The biometric sensor may, e.g., be a fingerprint sensor, a camera (for authentication by means of face retina and / or iris recognition), or a microphone (for authentication by means of voice recognition). This may be achieved by the charging device 200 retrieving sensor data from the biometric sensor 240, and optionally processing the sensor data, e.g., to extract features which can later be used for verifying 427 / 470 the acquired biometric input data against the biometric verification data for the user.

[0054] In response to successfully authenticating the user of the chargeable device 100, the chargeable device 100 switches 431 to the unprotected mode of operation. The authentication of the user is based on the acquired biometric input data, biometric verification data for the user, and the second challenge.

[0055] For example, the authentication of the user of the chargeable device 100 may be performed as follows. The charging device 200 may verify 470 that the biometric input data matches the biometric verification data, and send the second challenge 472, signed 471 with the private key of the charging device 200, to the chargeable device 100. In practice, the charging device 200 may verify 470 that the biometric input data matches the biometric verification data in different ways. For example, for an exact match, all features identified in the biometric verification data are required to be identified in the biometric input data. For a partial match, the number of features which are identified in the biometric input data and which match corresponding features in the biometric input data is required to exceed a threshold number, or a threshold percentage of the total number of features identified in the biometric verification data. As yet a further alternative, if verification is done by means of distance-based matching, the total distance between features identified in the biometric input data and corresponding features identified in the biometric verification data is required to be below a threshold total distance.

[0056] The charging device 200 may sign 471 the second challenge either in response to successfully verifying 470 that the biometric input data matches the biometric verification data for the user of the chargeable device 100, or at an earlier point in time, e.g., after receiving the second challenge 410 from the chargeable device 100. The chargeable device 100 switches 431 to the unprotected mode of operation in response to successfully verifying 423 the signed second challenge. Similar to verifying 408 the signed first challenge by the chargeable device 100, verifying 423 the signed second challenge may comprise checking validity of the signature of the signed second challenge using the public key of the charging device 200, as well as checking that the signed second challenge 472 which the chargeable device 100 has received from the charging device 200 is the same (number) as the second challenge 410 which the chargeable device 100 has sent to the charging device 200.

[0057] The biometric verification data which is used in authenticating the user of the chargeable device 100 may be acquired either by the charging device 200 or by the chargeable device 100. If the charging device 200 acquires 451 the biometric verification data for the user, as is illustrated in Fig. 4, this may be achieved by enrolling the user directly on the charging device 200. For example, the charging device 200 may be operative to conduct an enrollment procedure during which the biometric verification data for the user is acquired and stored for later use. Alternatively, the charging device 200 may be paired with a smartphone or other device of the user, and the user enrolls on the smartphone which then shares the biometric verification data with the charging device 200. In some cases, the biometric verification data may be modified or complemented to have the same format as the biometric input data acquired from the biometric sensor 240 of the charging device 200.

[0058] Alternatively, if the chargeable device 100 acquires 401 the biometric verification data for the user, as is illustrated in Fig. 5, the chargeable device 100 sends the biometric verification data 413 to the charging device 200 for use by the charging device 200 to authenticate the user of the chargeable device 100 by verifying 470 that the biometric input data matches the biometric verification data for the user. Optionally, the chargeable device 100 may send the biometric verification data 413 for the user in response to receiving a request 461 for biometric verification data from the charging device 200. Further optionally, the chargeable device 100 may encrypt the biometric verification data before sending the encrypted biometric verification data 413 to the charging device 200. The biometric verification data may, e.g., be encrypted using a shared (cryptographic) key which is derived 412 / 462 both by the chargeable device 100 and the charging device 200, using credentials which the chargeable device 100 has received from the charging device 200 with the request for biometric verification data for the user or at an earlier point in time. Alternatively, the shared key may be established 412 / 462 during an enrollment phase or pairing of the chargeable device 100 and the charging device 200.

[0059] As a further alternative, which is illustrated in Fig. 6, the chargeable device 100 may acquire 401 biometric verification data for the user, and the charging device 200 transforms 474 the biometric input data which it has acquired 469 using the second challenge, and sends the transformed biometric input data 476 to the chargeable device 100. In this case, the chargeable device 100 performs the authentication of the user of the chargeable device 100 by verifying 427 that the transformed biometric input data matches the biometric verification data, which in turn has been transformed with the second challenge using the same algorithm as is used by the charging device 200 for transforming 474 the biometric input data acquired 469 from the user. Similar to what is described hereinbefore, the chargeable device 100 may verify 427 that the transformed biometric input data matches the transformed biometric verification data based on an exact match, a partial match, or a distance-based matching, criterion. Optionally, the charging device 200 may sign 475 the transformed biometric input data before the signed transformed biometric input data 476 is sent to the chargeable device 100.

[0060] Optionally, the chargeable device 100 sends a signal 428 to the charging device 200 which is indicative of the successful verification 423 of the signed second challenge (cf. Figs. 4 and 5) or the successful verification 427 that the transformed biometric input data matches the transformed biometric verification data (cf. Fig. 6), respectively. The chargeable device 100 sends the signal 428 in response to successfully verifying 423 the signed second challenge or in response to verifying 427 that the transformed biometric input data matches the transformed biometric verification data, respectively. Further optionally, the charging device 200 sends a signed unlock signal 479 to the chargeable device 100. The charging device 200 sends the signed unlock signal 479 in response to receiving the signal 428 indicative of the successful verification of the signed second challenge, or the successful verification that the transformed biometric input data matches the transformed biometric verification data, respectively. In this case, the chargeable device 100 switches 431 to the unprotected mode of operation in response to successfully verifying 430 the signed unlock signal. The signal 428 indicative of the successful verification of the signed second challenge, or the successful verification that the transformed biometric input data matches the transformed biometric verification data, respectively, may be a static message, but may optionally comprise a freshness indicator such as a nonce or a timestamp.

[0061] Optionally, the chargeable device 100 sends a request 418 to the charging device 200 to acquire biometric input from the user. The request 418 to acquire biometric input from the user may be sent in response to detecting a user input to the chargeable device, e.g., a touch input or a spoken instruction, or a displacement of the chargeable device 100. For example, the chargeable device 100 may detect a movement or displacement, using a built-in accelerometer or Inertial Measurement Unit (IMU), or by detecting a change in signal strength of the inductive coupling 300. As a further alternative, the chargeable device 100 may detect an attempt that it is being used while being charged, e.g., a contactless payment being initiated. In this case, the charging device 200 acquires 469 the biometric input data from the user in response to receiving the request 418 to acquire biometric input from the user.

[0062] It will be appreciated that the method of protecting a chargeable device being charged by a charging device against unauthorized use may comprise additional, alternative, or modified, steps in accordance with what is described throughout this disclosure. Correspondingly, embodiments of the chargeable device 100 and the charging device 200 may be operative to perform additional, alternative, or modified, steps in accordance with what is described throughout this disclosure.

[0063] Embodiments of the invention may be implemented as computer programs comprising instructions which, when the computer programs 113 and 213 are executed by one or more processor(s) 111 and 211 comprised in the chargeable device 100 and the charging device 200, respectively, cause the chargeable device 100 and the charging device 200 to become operative in accordance with embodiments of the invention described herein. The computer programs 113 / 213 may be stored in a computer-readable data carriers, such as the memories 12 and 212. Alternatively, the computer programs 113 / 213 may be carried by data carrier signals, e.g., downloaded to the memories 112 / 212 via communications interfaces comprised in the chargeable device 100 and the charging device 200.

[0064] The person skilled in the art realizes that the invention by no means is limited to the embodiments described above. On the contrary, many modifications and variations are possible within the scope of the appended claims.

Claims

22CLAIMS1 . A method of protecting a chargeable device being charged by a charging device against unauthorized use, the chargeable device operative to switch between an unprotected mode of operation and a protected mode of operation, the method comprising: the charging device sending a certificate of the charging device to the chargeable device, the certificate comprising a public key of the charging device, the chargeable device sending a first challenge to the charging device, the charging device signing the first challenge with a private key of the charging device, the charging device sending the signed first challenge to the chargeable device, in response to successfully verifying, by the chargeable device, the signed first challenge: initiating charging of the chargeable device by the charging device, the chargeable device sending a second challenge to the charging device, and the chargeable device switching to the protected mode of operation, the charging device acquiring biometric input data from the user, using a biometric sensor comprised in the charging device, and the chargeable device, in response to a successful authentication of a user of the chargeable device, switching to the unprotected mode of operation, wherein the authentication of the user is based on the acquired biometric input data, biometric verification data for the user, and the second challenge.

2. The method according to claim 1 , wherein the authentication of the user of the chargeable device comprises, by the charging device:verifying that the biometric input data matches the biometric verification data, sending the second challenge, signed with the private key of the charging device, to the chargeable device, wherein the chargeable device switches to the unprotected mode of operation in response to successfully verifying the signed second challenge.

3. The method according to claim 2, further comprising: the charging device acquiring the biometric verification data for the user.

4. The method according to claim 2, further comprising: the chargeable device: acquiring the biometric verification data for the user, and sending the biometric verification data to the charging device.

5. The method according to claim 1 , further comprising: the chargeable device acquiring biometric verification data for the user, the charging device: transforming the biometric input data using the second challenge, sending the transformed biometric input data to the chargeable device, wherein the authentication of the user of the chargeable device comprises, by the chargeable device, verifying that the transformed biometric input data matches the biometric verification data, transformed with the second challenge.

6. The method according to any one of claims 1 to 5, when in the protected mode of operation, at least part of a functionality of the chargeabledevice is unavailable or disabled, and / or at least part of a memory comprised in the chargeable device is inaccessible.

7. The method according to claim 6, wherein the at least part of functionality of the chargeable device which is unavailable or disabled comprises one or more of: contactless payments, collecting physiological data of the user, controlling an operation of the chargeable device, controlling an external computing device using the chargeable device, and configuring the chargeable device.

8. The method according to claim 6, wherein the at least part of the memory comprised in the chargeable device which is inaccessible is operative to store one or more of: payment credentials, physiological data of the user, biometric information of the user, user credentials, and executable instructions.

9. The method according to any one of claims 1 to 8, the method further comprising: the charging device, in response to receiving the second challenge from the chargeable device, sending a signed lock signal to the chargeable device, wherein the chargeable device switches to the protected mode of operation in response to successfully verifying the signed lock signal.

10. The method according to any one of claims 1 to 9, the method further comprising: the chargeable device, in response to successfully verifying the signed second challenge, sending a signal to the charging device which is indicative of the successful verification of the signed second challenge,25 the charging device, in response to receiving the signal indicative of the successful verification of the signed second challenge, sending a signed unlock signal to the chargeable device, wherein the chargeable device switches to the unprotected mode of operation in response to successfully verifying the signed unlock signal.11 . The method according to any one of claims 1 to 10, further comprising: the chargeable device, in response to detecting a user input or a displacement of the chargeable device, sending a request to the charging device to acquire biometric input from the user, wherein the charging device acquires biometric input data from the user in response to receiving the request to acquire biometric input from the user.

12. The method according to any one of claims 1 to 11 , wherein the chargeable device is a wirelessly chargeable device, and the charging device is a wireless charging device.

13. A chargeable device for charging by a charging device, the chargeable device operative to switch between an unprotected mode of operation and a protected mode of operation, the chargeable device comprising processing circuitry operative to cause the chargeable device to be operative to: receive a certificate of the charging device from the charging device, the certificate comprising a public key of the charging device, send a first challenge to the charging device, receive the first challenge, signed with a private key of the charging device, from the charging device, in response to successfully verifying the signed first challenge: initiate charging of the chargeable device by the charging device,26 send a second challenge to the charging device, and switch to the protected mode of operation, and, in response to a successful authentication of a user of the chargeable device, switch to the unprotected mode of operation, wherein the authentication of the user is based on biometric input data acquired by the charging device, biometric verification data for the user, and the second challenge.

14. The chargeable device according to claim 13, further operative to: receive the second challenge, signed with the private key of the charging device, from the charging device, wherein the chargeable device switches to the unprotected mode of operation in response to successfully verifying the signed second challenge.

15. The chargeable device according to claim 14, further operative to: acquire the biometric verification data for the user, and send the biometric verification data to the charging device.

16. The chargeable device according to claim 13, further operative to: acquire the biometric verification data for the user, receive the biometric input data, transformed using the second challenge, from the charging device, wherein the authentication of the user of the chargeable device comprises verifying that the transformed biometric input data matches the biometric verification data, transformed with the second challenge.

17. The chargeable device according to any one of claims 13 to 16, operative to, when in the protected mode of operation, make unavailable or disable at least part of a functionality of the chargeable device, and / or27 prevent access to at least part of a memory comprised in the chargeable device.

18. The chargeable device according to claim 17, wherein the at least part of the functionality of the chargeable devices which is made unavailable or is disabled comprises one or more of: contactless payments, collecting physiological data of the user, controlling an operation of the chargeable device, and configuring the chargeable device.

19. The chargeable device according to claim 17, operative to store in the at least part of the memory comprised in the chargeable device to which access is prevented when in the protected mode of operation, one or more of: payment credentials, physiological data of the user, biometric information of the user, user credentials, and executable instructions.

20. The chargeable device according to any one of claims 13 to 19, further operative to: receive a signed lock signal from the charging device, wherein the chargeable device switches to the protected mode of operation in response to successfully verifying the signed lock signal.21 . The chargeable device according to any one of claims 13 to 20, further operative to: in response to successfully verifying the signed second challenge, send a signal to the charging device which is indicative of the successful verification of the signed second challenge, and receive a signed unlock signal from the charging device, wherein the chargeable device switches to the unprotected mode of operation in response to successfully verifying the signed unlock signal.2822. The chargeable device according to any one of claims 13 to 21 , further operative to: in response to detecting a user input or a displacement of the chargeable device, send a request to the charging device to acquire biometric input from the user.

23. The chargeable device according to any one of claims 13 to 22, wherein the chargeable device is a wirelessly chargeable device.

24. A charging device for charging a chargeable device, the chargeable device operative to switch between an unprotected mode of operation and a protected mode of operation, the charging device comprising a biometric sensor and processing circuitry operative to cause the charging device to be operative to: send a certificate of the charging device to the chargeable device, the certificate comprising a public key of the charging device, receive a first challenge from the chargeable device, sign the first challenge with a private key of the charging device, send the signed first challenge to the chargeable device, and acquire biometric input data from a user of the chargeable device, using the biometric sensor.

25. The charging device according to claim 24, further operative to: verify that the biometric input data matches biometric verification data, and send the second challenge, signed with the private key of the charging device, to the chargeable device.

26. The charging device according to claim 25, further operative to: acquire the biometric verification data for the user.2927. The charging device according to claim 25, further operative to: receive the biometric verification data from the chargeable device.

28. The charging device according to claim 24, further operative to: transform the biometric input data using the second challenge, and send the transformed biometric input data to the chargeable device.

29. The charging device according to any one of claims 24 to 28, when in the protected mode of operation, at least part of a functionality of the chargeable device is unavailable or disabled, and / or at least part of a memory comprised in the chargeable device is inaccessible.

30. The charging device according to any one of claims 24 to 29, further operative to: in response to receiving the second challenge from the chargeable device, sending a signed lock signal to the chargeable device.31 . The charging device according to any one of claims 24 to 30, further operative to: in response to receiving a signal from the chargeable device which is indicative of a successful verification of the signed second challenge by the chargeable device, send a signed unlock signal to the chargeable device.

32. The charging device according to any one of claims 24 to 31 , operative to acquire biometric input data from the user in response to receiving, from the chargeable device, a request to acquire biometric input from the user.3033. The charging device according to any one of claims 24 to 32, wherein the charging device is a wireless charging device.

Citation Information

Patent Citations

  • Apparatus, method, and system for securely charging mobile devices

    US20170366026A1

  • Wireless power transfer device authentication

    US20200154275A1

  • Electrical Charger Device for an Electronic Cigarette

    US20230042080A1