Multi-Level IoT Authentication Using Server Mediation and Biometrics

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current IoT user authentication systems are insecure, making them susceptible to data breaches and cyber threats, as passwords can be easily hacked, and existing solutions fail to provide robust authorization, allowing unauthorized access to sensitive information.

Innovation Solution

A multi-level user authentication system that includes server authentication followed by a second level of authentication using a variable formula based on parameters like stock symbols, system time, or temperature, and biometric verification, ensuring secure access to IoT devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If password-based authentication is used for IoT devices, then ease of operation is improved, but security is worsened as passwords can be easily hacked

Engineering Contradiction:
Improveauthentication processVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication system is divided into multiple independent layers: device credentials verification, server authentication, and optional biometric authentication. Each layer operates independently and contributes to the overall security, allowing the system to maintain ease of use while enhancing security through layered verification

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A server acts as an intermediary between the IoT device and the user, performing background verification of device credentials and authentication tokens. This intermediary handles the complex security verification processes, keeping the user interface simple while maintaining strong security through the server's mediation

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multi-level authentication with biometric verification is implemented, then security is improved, but device complexity is worsened

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system is designed to support multiple authentication methods (device credentials, server authentication, biometric verification) within a single unified framework. This multi-functional approach allows the system to adapt to different security requirements without requiring separate systems, managing complexity through universality

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system implements optional biometric authentication as an additional layer that can be enabled or disabled based on specific security needs. Not all IoT devices or use cases require the full multi-level authentication, allowing partial implementation that balances security enhancement with complexity management

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If strong authentication measures are applied, then security is improved, but ease of operation is worsened due to multiple verification steps

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

Device credentials and authentication tokens are verified by the server in advance, before the user needs to access the IoT device. This preliminary verification handles the complex security checks behind the scenes, so when the user attempts to connect, the authentication process is streamlined and faster, maintaining ease of operation while ensuring security

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12028335B2Multi-level user device authentication system for internet of things (IoT)
Publication Date: 2024.07.02 KRISHAN BALDEV
  • US12028335B2 patent drawing
  • US12028335B2 patent drawing
  • US12028335B2 patent drawing

AI summary

The present invention describes the user authentication system comprising of multiple levels of security which is used to authorize the user. The system uses more than one levels of authentication process which receives the credentials from the user and authorizes them to allow access to the IoT devices which are used by the user.The connected devices represent individual targets for the cyber-criminals who 20 would hack the devices to retrieve the secure information of the users. Such insecurities about the IoT devices and the system are eliminated by using the multiple level user authentication system which is described in the present invention.