Biometric Authentication for IoT Security via Encrypted Certificates
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
IoT devices are vulnerable to cyber attacks due to their simple computing functions and lack of robust security measures, which can lead to unauthorized access and control, posing risks to critical infrastructure and personal data.
Innovation Solution
Implementing an authentication system that uses encrypted biometric data stored on a user's device, combined with a public key certificate for secure user authentication, and additional factors like one-time passwords and location information to enhance security, ensuring that only authorized users can access IoT devices and networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If IoT devices use simple computing functions and basic security measures, then device complexity is reduced and ease of manufacture is improved, but security reliability deteriorates and vulnerability to cyber attacks increases
Solution Approach 1:
The patent introduces a biometric authentication intermediary system that mediates between the user and the IoT device. The biometric data (fingerprints, iris, voice) serves as an intermediary verification layer, allowing simple IoT devices to achieve secure authentication without complex security hardware. The authentication server acts as a mediator that verifies biometric data and manages authentication tokens, enabling basic devices to participate in secure multi-factor authentication.
Solution Approach 2:
The patent changes the authentication parameter from traditional passwords or simple PINs to biometric parameters (fingerprints, iris patterns, voice characteristics). This parameter change fundamentally improves security reliability while maintaining device simplicity, as biometric data is inherently difficult to steal or replicate compared to traditional credentials. The system transforms the authentication basis from easily compromised digital secrets to difficult-to-replicate biological characteristics.
2Reliability
If multi-factor authentication is implemented with biometric data and public key certificates, then security reliability is improved, but device complexity increases
Solution Approach 1:
The patent segments the authentication system into distinct functional components: the IoT device (which remains simple), the authentication server (which handles complex verification), and the user's biometric data (which serves as a separate authentication factor). This segmentation allows the complexity to be concentrated in the server infrastructure while keeping individual IoT devices simple. The public key certificate system is segmented into certificate issuance, verification, and token generation components distributed across the network.
Solution Approach 2:
The authentication server acts as an intermediary that absorbs the complexity of multi-factor authentication verification. Instead of embedding complex security logic in each IoT device, the server mediates the authentication process by verifying biometric data, validating public key certificates, and coordinating the multi-factor authentication flow. This intermediary approach allows simple devices to benefit from sophisticated security without carrying the computational burden.
3Ease of operation
If traditional authentication methods are used, then ease of operation is improved, but security against theft and tampering deteriorates
Solution Approach 1:
The patent changes the authentication parameter from easily stolen passwords or PINs to biometric parameters that are inherent to the user's body. Biometric data such as fingerprints, iris patterns, and voice characteristics cannot be easily stolen, lost, or forgotten like traditional credentials. This parameter change maintains ease of operation (users simply provide their biometric trait) while dramatically improving resistance to theft and tampering, as biometric data is difficult to replicate or compromise.
Data Source
AI summary
A method of registering a person as an authorized user of a portable device includes acquiring biometric data or a combination of pieces of biometric data of a person, encrypting the acquired biometric data or the combination of pieces of biometric data of the person, generating a code from the encrypted biometric data or the combination of pieces of biometric data of the person, inserting the code in an extension field of a public key certificate stored in the portable device, generating a private key and a public key that corresponds to the private key, based on the public key certificate, wherein the private key contains the code, transmitting the public key to a remote entity that is in communication with the portable device, thereby enabling the remote entity to register the person as an authorized user of the portable device, and modifying the public key to generate a modified public key configured to be used in case that the remote entity is disconnected from a service providing server.


