Device Authentication via Trust-Based Parameter Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional device authentication methods for digital transactions are power and time-consuming, and do not effectively verify the presence of the actual user, leading to potential unauthorized access and security breaches.
Innovation Solution
A method and system that categorize device parameters into variable and constant categories, using a trust score to selectively generate and transmit challenges for authentication, with optional and mandatory authentication levels to ensure secure validation and reduce power consumption.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If all device parameters are accessed and transmitted to remote server for authentication, then authentication reliability is improved, but power consumption and time consumption increase
Solution Approach 1:
The patent segments device parameters into two distinct categories: first parameters (less critical, lower power to access) and second parameters (more critical, higher power to access). The system selectively accesses only the necessary category based on trust score, avoiding the need to access all parameters. This segmentation resolves the contradiction by maintaining authentication reliability through selective parameter verification while reducing overall power consumption.
Solution Approach 2:
The patent implements partial authentication action by determining a trust score based on historical challenge-response data and selectively accessing only the necessary parameter category. For devices with high trust scores, only first parameters are accessed; for lower trust scores, second parameters are accessed. This partial action approach maintains sufficient authentication reliability while minimizing power consumption compared to accessing all parameters universally.
2Reliability
If all device parameters are accessed and transmitted to remote server for authentication, then authentication reliability is improved, but time consumption increases
Solution Approach 1:
The patent segments device parameters into first parameters (accessed quickly, lower priority) and second parameters (accessed when needed, higher priority). By segmenting parameters and selectively accessing only the necessary category based on trust score, the system maintains authentication reliability while significantly reducing authentication time compared to accessing all parameters.
Solution Approach 2:
The system performs partial authentication by accessing only the necessary parameter category based on trust score evaluation. This partial action reduces authentication time while maintaining sufficient reliability for the given context.
3Ease of operation
If conventional authentication procedure is used without user presence detection, then ease of operation is improved, but security reliability deteriorates
Solution Approach 1:
The patent performs preliminary user presence detection through biometric or behavioral parameters before completing the authentication process. This preliminary action verifies that the actual user is present and interacting with the device, adding a security layer without significantly impacting ease of operation. The presence detection is integrated into the existing authentication flow, maintaining user convenience while enhancing security reliability.
Data Source
AI summary
A system and a method for authenticating a device of a user is provided. A set of parameters of the device or the user are captured from the device. The set of parameters are categorized into first and second categories including first and second parameters, respectively. One of the first and second categories is selected based on a trust score of the device. The first challenge is generated based on the first parameters, when the first category is selected. The second challenge is generated based on the second parameters, when the second category is selected. The first or the second challenge is transmitted to the device, and a response message is received in response to the first or second challenge. The response message is validated to authenticate the device of the user.


