Biometric Key Binding for Secure User-Device Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for user and device authentication in telehealth systems fail to securely establish data origin, leading to potential incorrect associations and vulnerabilities to malicious data impersonation, as they do not effectively bind user and device identities, resulting in unreliable data provenance and increased risks in healthcare decision-making.
Innovation Solution
The method involves binding user and device identities using Global Unique IDs combined with biometric information to generate secure keys, ensuring that data can be authenticated as originating from a specific device and user, utilizing fuzzy extractors to derive reliable keys from noisy biometric data and helper data, and encrypting device IDs to ensure secure transmission and authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If device ID is used as user identifier or to derive user ID, then device identification is simplified, but user and device authentication security is compromised
Solution Approach 1:
The patent segments the authentication process into two distinct components: device identification (using device ID) and user authentication (using biometric data). This separation allows the system to maintain simple device identification while implementing strong user authentication through biometric verification, resolving the contradiction between operational simplicity and authentication security.
Solution Approach 2:
The patent introduces biometric data as an intermediary element that binds the user to the device measurement process. The biometric data acts as a mediator that cannot be easily replicated or impersonated, thereby establishing secure authentication of both user and device origin without complicating the basic device identification mechanism.
2Adaptability or versatility
If manual mapping between user ID and device ID is required, then user-device association flexibility is improved, but potential for incorrect associations and mistakes increases
Solution Approach 1:
The patent implements self-service authentication where the system automatically performs the binding of user identity to device measurements through biometric verification. Instead of requiring manual mapping operations that are prone to errors, the system autonomously authenticates the user-device relationship through irreversible biometric data, eliminating mistakes while maintaining association flexibility.
Solution Approach 2:
The patent performs preliminary binding of user identity to device measurements during the authentication phase before data transmission occurs. By establishing the correct user-device association in advance through biometric verification, the system prevents incorrect associations from occurring in the first place, rather than relying on error-prone manual mapping operations.
3Productivity
If device ID transmission is performed without strong authentication, then data transmission efficiency is improved, but vulnerability to malicious impersonation increases
Solution Approach 1:
The patent applies partial authentication by using biometric data specifically for binding user identity to device measurements, rather than requiring full authentication for all data transmission operations. This selective approach maintains efficient data transmission while providing sufficient security against impersonation for the critical authentication phase.
Solution Approach 2:
The patent changes the authentication parameter from simple device ID matching to biometric-based user verification. This parameter change transforms the authentication mechanism from one that is vulnerable to impersonation to one that is resistant to malicious attacks, while maintaining efficient data transmission through the use of established authentication results.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method of authenticating a device and a user comprises obtaining a device ID for the device, performing a biometric measurement of the user, obtaining helper data for the user, and generating a key from the biometric measurement and helper data. There is then generated a message comprising the key or a component derived from the key, which transmitted to a remote service, and at the service there is carried out the step of authenticating the device and the user with the message. In a preferred embodiment, the generating of the key further comprises generating the key from the device ID.