IoT User Authentication via Dynamic Biometric Questionnaires
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In the IoT environment, there is a lack of intuitive and foolproof methods for user authentication, particularly in multi-user scenarios, where remembering numerous pins/passwords is challenging, and biometric authentications struggle with liveness detection and fake identity issues.
Innovation Solution
A method and system for authenticating users in IoT environments that involve generating questions based on user and device data, presenting them for response, and scoring the authenticity to provide access levels, utilizing a combination of user and device interactions, activity logs, and biometric data to ensure seamless and secure access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional pin/password authentication is used for each IoT device, then device security is maintained, but user convenience deteriorates due to the need to remember numerous pins/passwords
Solution Approach 1:
The patent implements a universal authentication system where a single set of biometric credentials (fingerprint, facial recognition, or iris scan) can authenticate users across multiple IoT devices and applications. The authentication server maintains user profiles that are recognized by different devices, allowing one biometric identity to serve multiple authentication purposes throughout the IoT ecosystem, thereby eliminating the need for device-specific pins and passwords.
Solution Approach 2:
The patent replaces traditional mechanical authentication methods (typing pins/passwords on keyboards or entering codes) with biometric authentication systems. Fingerprint sensors, facial recognition cameras, or iris scanners capture biological characteristics and compare them against stored templates in the authentication server, substituting manual input mechanisms with automated biological verification that is both more secure and more convenient.
2Speed
If biometric authentication is implemented, then authentication speed is improved, but reliability deteriorates due to liveness detection failures and fake identity issues
Solution Approach 1:
The patent incorporates liveness detection mechanisms that provide feedback to verify the authenticity of biometric samples in real-time. The system analyzes characteristics such as blood flow patterns, skin texture dynamics, or facial muscle movements to distinguish living subjects from spoofing attempts. This feedback loop ensures that only genuine biometric data from living users is accepted, maintaining high authentication accuracy while preserving rapid verification speeds.
Solution Approach 2:
The patent performs preliminary verification of biometric data quality and liveness characteristics before completing the authentication process. The system pre-processes captured biometric images or signals to detect potential spoofing attempts, validates the authenticity of the biometric sample against established criteria, and only proceeds with authentication if the preliminary checks pass. This preliminary action prevents fake identities from bypassing security while maintaining efficient authentication flow for genuine users.
3Adaptability or versatility
If multi-user access is enabled, then device versatility is improved, but security management complexity increases due to lack of standard procedures for multi-level access
Solution Approach 1:
The patent segments user access rights into hierarchical levels and assigns specific permissions to each level. The authentication server maintains a structured database of user profiles with defined access tiers (e.g., admin, user, guest), where each tier has predetermined permissions for different devices and functions. This segmentation allows multiple users to access the same IoT ecosystem simultaneously with appropriate access controls, enabling versatile multi-user support while maintaining organized and manageable security policies through standardized permission levels.
Data Source
Figure 1
Figure 2~3
Figure 4
AI summary
The present disclosure relates to a sensor network, machine type communication (MTC), machine-to-machine (M2M) communication, and technology for Internet of things (IoT). The present disclosure may be applied to intelligent services based on the above technologies, such as smart home, smart building, smart city, smart car, connected car, health care, digital education, smart retail, security and safety services. A method and an authenticating system for authenticating users in an IoT environment are provided. The method includes receiving an access request to at least one device present in the IoT environment, identifying a type of questions based on at least one of a user interface (UI) type of the at least one device, or an authentication level of the at least one device, generating at least one question corresponding to the type of questions based on at least one of user data of a user associated with the access request, or device data of one or more devices associated with the user, presenting the at least one question to at least one of the user and the one or more devices, and authenticating the user to access the at least one device based on a response for the at least one question received from the at least one of the user and the one or more devices.