Biometric IoT Trust via Mediator Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems lack methods for establishing trust between federated networks of computing devices and enabling secure communication between Internet of Things (IoT) devices from different networks, leading to security vulnerabilities and limited interoperability between devices from various brands and types.

Innovation Solution

The implementation of a system that uses biometric authentication and a hierarchical addressing scheme to establish trust relationships between IoT devices, allowing secure communication by verifying user and device identities through a registrar computer system and trust management system, which generates and manages tokens for secure connections across different networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If biometric authentication and trust verification procedures are implemented before communication between IoT devices, then security and trust reliability are improved, but device complexity and authentication time increase

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a trust management system as an intermediary that handles biometric authentication and trust verification between IoT devices. This mediator centralizes the complex authentication process, allowing devices to outsource trust verification to a dedicated system rather than implementing complex authentication logic within each device. The trust management system verifies biometric credentials and establishes trust relationships, reducing the authentication burden on individual devices while maintaining high security standards.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If biometric authentication is performed for each device and user before communication, then trust reliability is improved, but authentication time and processing duration increase

Engineering Contradiction:
Improvetrust verificationVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary trust verification and biometric authentication before actual communication between IoT devices occurs. The trust management system performs trust establishment and verification in advance, creating pre-authenticated connections that can be quickly established for subsequent communications. This preliminary action ensures that when devices need to communicate, the authentication infrastructure is already in place, reducing real-time authentication delays while maintaining thorough security checks.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If communication is restricted to devices within the same network or brand, then security is maintained, but adaptability and interoperability between different device types are limited

Engineering Contradiction:
ImprovesecurityVSAvoidinteroperability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal trust management system that serves multiple functions: it authenticates devices from different networks and brands, establishes trust relationships across heterogeneous device types, and enables secure communication between any authorized devices. This universal system replaces brand-specific or network-specific authentication mechanisms with a common framework that can handle diverse IoT devices uniformly, thereby achieving both security and broad interoperability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11870775B2Biometric identification and verification among IoT devices and applications
Publication Date: 2024.01.09 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US11870775B2 patent drawing
  • US11870775B2 patent drawing
  • US11870775B2 patent drawing

AI summary

One embodiment of the invention is directed to a computer-implemented method comprising, receiving a first request that includes a token associated with a first computing device to utilize a shared resource implemented by a federated network of computing devices. The method further comprises identifying that the first computing device is an unknown entity based in part on the token and one or more signature used to sign the token. The method further comprises transmitting, to a trust management system, a second request to authenticate the first computing device using the token. The method further comprises, receiving an authentication message that verifies the first computing device within an open trust network. The authentication message may be generated in response to the trust management system communicating with a plurality of registrar computers in the open trust network about the signatures associated with the token.