Biometric Authentication for IoT Security via Encrypted Certificates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

IoT devices are vulnerable to cyber attacks due to their simple computing functions and lack of robust security measures, which can lead to unauthorized access and control, posing risks to critical infrastructure and personal data.

Innovation Solution

Implementing an authentication system that uses encrypted biometric data stored on a user's device, combined with a public key certificate for secure user authentication, and additional factors like one-time passwords and location information to enhance security, ensuring that only authorized users can access IoT devices and networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If IoT devices use simple computing functions and basic security measures, then device complexity is reduced and ease of manufacture is improved, but security reliability deteriorates and vulnerability to cyber attacks increases

Engineering Contradiction:
Improveease of manufactureVSAvoidsecurity reliability
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent introduces a biometric authentication intermediary system that mediates between the user and the IoT device. The biometric data (fingerprints, iris, voice) serves as an intermediary verification layer, allowing simple IoT devices to achieve secure authentication without complex security hardware. The authentication server acts as a mediator that verifies biometric data and manages authentication tokens, enabling basic devices to participate in secure multi-factor authentication.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the authentication parameter from traditional passwords or simple PINs to biometric parameters (fingerprints, iris patterns, voice characteristics). This parameter change fundamentally improves security reliability while maintaining device simplicity, as biometric data is inherently difficult to steal or replicate compared to traditional credentials. The system transforms the authentication basis from easily compromised digital secrets to difficult-to-replicate biological characteristics.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If multi-factor authentication is implemented with biometric data and public key certificates, then security reliability is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication system into distinct functional components: the IoT device (which remains simple), the authentication server (which handles complex verification), and the user's biometric data (which serves as a separate authentication factor). This segmentation allows the complexity to be concentrated in the server infrastructure while keeping individual IoT devices simple. The public key certificate system is segmented into certificate issuance, verification, and token generation components distributed across the network.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The authentication server acts as an intermediary that absorbs the complexity of multi-factor authentication verification. Instead of embedding complex security logic in each IoT device, the server mediates the authentication process by verifying biometric data, validating public key certificates, and coordinating the multi-factor authentication flow. This intermediary approach allows simple devices to benefit from sophisticated security without carrying the computational burden.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If traditional authentication methods are used, then ease of operation is improved, but security against theft and tampering deteriorates

Engineering Contradiction:
Improveease of operationVSAvoidvulnerability to theft and tampering
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent changes the authentication parameter from easily stolen passwords or PINs to biometric parameters that are inherent to the user's body. Biometric data such as fingerprints, iris patterns, and voice characteristics cannot be easily stolen, lost, or forgotten like traditional credentials. This parameter change maintains ease of operation (users simply provide their biometric trait) while dramatically improving resistance to theft and tampering, as biometric data is difficult to replicate or compromise.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11664996B2Authentication in ubiquitous environment
Publication Date: 2023.05.30 CHOI OK
  • US11664996B2 patent drawing
  • US11664996B2 patent drawing
  • US11664996B2 patent drawing

AI summary

A method of registering a person as an authorized user of a portable device includes acquiring biometric data or a combination of pieces of biometric data of a person, encrypting the acquired biometric data or the combination of pieces of biometric data of the person, generating a code from the encrypted biometric data or the combination of pieces of biometric data of the person, inserting the code in an extension field of a public key certificate stored in the portable device, generating a private key and a public key that corresponds to the private key, based on the public key certificate, wherein the private key contains the code, transmitting the public key to a remote entity that is in communication with the portable device, thereby enabling the remote entity to register the person as an authorized user of the portable device, and modifying the public key to generate a modified public key configured to be used in case that the remote entity is disconnected from a service providing server.