Biometric Authentication for IoT Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

IoT devices are vulnerable to cyber attacks due to their simple computing functions and weak security, which can lead to unauthorized access and control, potentially causing significant damage, especially in critical infrastructure and personal devices.

Innovation Solution

A method using encrypted biometric data stored on a user's device, combined with a public key certificate for authentication, which includes additional factors like one-time passwords, keystroke dynamics, and location information to enhance security, ensuring secure user and IoT device authentication both online and offline.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multi-factor authentication is implemented, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple authentication factors (biometric data, public key certificates, one-time passwords, location information) into a unified authentication system. The server integrates these diverse elements into a single authentication protocol, allowing secure multi-factor authentication without requiring separate systems for each factor.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The server acts as an intermediary that manages the complexity of multi-factor authentication. It receives various authentication factors from the user device, processes them according to the authentication policy, and makes authorization decisions. This mediator approach shields users from the complexity while maintaining strong security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If additional authentication factors are added, then authentication security is improved, but ease of operation deteriorates

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication process simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system implements selective multi-factor authentication where not all factors are required for every authentication attempt. The server evaluates the risk level and authentication policy to determine which factors are necessary, applying only the appropriate level of authentication scrutiny needed for each transaction.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The authentication requirement is dynamic rather than static. The system adjusts which authentication factors are required based on the transaction context, user profile, and risk assessment. This allows the authentication process to be simpler for low-risk operations while maintaining strict security for high-risk operations.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP3373554B1Authentication in ubiquitous environment
Publication Date: 2022.11.02 CHOI OK
  • EP3373554B1 patent drawingFigure 1A
  • EP3373554B1 patent drawingFigure 1B
  • EP3373554B1 patent drawingFigure 2A~2C

AI summary

In some embodiments, encrypted biometric data are stored in advance in a device that is possessed or carried by a user based on a public key certificate, and a user authentication (S703) is performed by a biometric matching in the device. A public key certificate matching the encrypted biometric data is used to perform a user authentication (S704,S705,S706,S707) for a transaction authorization in a service providing server. According to some embodiments, one time password, keystroke, dynamic signature, location information, and the like are employed as additional authentication factors to tighten the security of the first and second user authentications. According to some embodiments, an authentication mechanism including the first user authentication and the second user authentication is applied to control an access to the IoT device.