Biometric Key Binding for Secure User-Device Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for user and device authentication in telehealth systems fail to securely establish data origin, leading to potential incorrect associations and vulnerabilities to malicious data impersonation, as they do not effectively bind user and device identities, resulting in unreliable data provenance and increased risks in healthcare decision-making.

Innovation Solution

The method involves binding user and device identities using Global Unique IDs combined with biometric information to generate secure keys, ensuring that data can be authenticated as originating from a specific device and user, utilizing fuzzy extractors to derive reliable keys from noisy biometric data and helper data, and encrypting device IDs to ensure secure transmission and authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If device ID is used as user identifier or to derive user ID, then device identification is simplified, but user and device authentication security is compromised

Engineering Contradiction:
Improvedevice identification simplicityVSAvoiddata origin authentication
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the authentication process into two distinct components: device identification (using device ID) and user authentication (using biometric data). This separation allows the system to maintain simple device identification while implementing strong user authentication through biometric verification, resolving the contradiction between operational simplicity and authentication security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces biometric data as an intermediary element that binds the user to the device measurement process. The biometric data acts as a mediator that cannot be easily replicated or impersonated, thereby establishing secure authentication of both user and device origin without complicating the basic device identification mechanism.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If manual mapping between user ID and device ID is required, then user-device association flexibility is improved, but potential for incorrect associations and mistakes increases

Engineering Contradiction:
Improveuser-device association flexibilityVSAvoidcorrect data association
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements self-service authentication where the system automatically performs the binding of user identity to device measurements through biometric verification. Instead of requiring manual mapping operations that are prone to errors, the system autonomously authenticates the user-device relationship through irreversible biometric data, eliminating mistakes while maintaining association flexibility.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent performs preliminary binding of user identity to device measurements during the authentication phase before data transmission occurs. By establishing the correct user-device association in advance through biometric verification, the system prevents incorrect associations from occurring in the first place, rather than relying on error-prone manual mapping operations.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If device ID transmission is performed without strong authentication, then data transmission efficiency is improved, but vulnerability to malicious impersonation increases

Engineering Contradiction:
Improvedata transmission efficiencyVSAvoidmalicious data impersonation
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent applies partial authentication by using biometric data specifically for binding user identity to device measurements, rather than requiring full authentication for all data transmission operations. This selective approach maintains efficient data transmission while providing sufficient security against impersonation for the critical authentication phase.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent changes the authentication parameter from simple device ID matching to biometric-based user verification. This parameter change transforms the authentication mechanism from one that is vulnerable to impersonation to one that is resistant to malicious attacks, while maintaining efficient data transmission through the use of established authentication results.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP2417546B1Combined authentication of a device and a user
Publication Date: 2018.01.03 KONINKLIJKE PHILIPS NV
  • EP2417546B1 patent drawingFigure 1
  • EP2417546B1 patent drawingFigure 2
  • EP2417546B1 patent drawingFigure 3

AI summary

A method of authenticating a device and a user comprises obtaining a device ID for the device, performing a biometric measurement of the user, obtaining helper data for the user, and generating a key from the biometric measurement and helper data. There is then generated a message comprising the key or a component derived from the key, which transmitted to a remote service, and at the service there is carried out the step of authenticating the device and the user with the message. In a preferred embodiment, the generating of the key further comprises generating the key from the device ID.