IoT User Device Security with Continuous Premises Trust Scoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing IoT devices lack effective security measures to prevent unauthorized access while maintaining convenience for authorized users, as current authentication methods often require cumbersome credentials and decrease user experience.
Innovation Solution
Implement continuous biometric authentication through biometric-capable devices connected to a local network to determine a premises trust score, indicating the likelihood of an authorized user's presence, thereby dynamically controlling access to device functionality.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If authentication credentials are required to be provided by the user, then security is improved, but user convenience and access time are worsened
Solution Approach 1:
The system performs authentication automatically without requiring user action. Biometric-capable devices continuously monitor and authenticate users in the background, eliminating the need for manual credential entry while maintaining security. The system serves itself by autonomously determining premises trust scores and controlling device access.
Solution Approach 2:
Authentication is performed in advance and continuously before access is needed. The system pre-establishes premises trust scores by continuously monitoring biometric data from multiple devices, so that when functionality is requested, authentication has already been completed and access can be granted immediately without delay.
2Reliability
If authentication credentials are required to be provided by the user, then security is improved, but access time is worsened
Solution Approach 1:
Authentication is made continuous rather than periodic or on-demand. Biometric-capable devices continuously monitor user presence and authenticate users throughout their stay at the premises, maintaining constant verification without interrupting user flow. This eliminates repeated authentication delays while sustaining security.
Solution Approach 2:
Authentication is completed in advance before functionality is requested. The system continuously calculates premises trust scores beforehand, so when a user requests device functionality, the authentication decision has already been made and access can be granted instantly without waiting for credential verification.
3Ease of operation
If physical access to premises is assumed as authorization, then ease of operation is improved, but security is worsened
Solution Approach 1:
An intermediary authentication layer is introduced between physical presence and device access. Instead of directly equating physical access with authorization, the system uses biometric data from multiple devices as an intermediary to calculate premises trust scores, which then determine whether device functionality should be granted. This mediates between ease of access and security requirements.
Solution Approach 2:
Multiple biometric-capable devices are used to collectively determine authentication status. Instead of relying on a single device or simple presence detection, the system aggregates data from multiple independent biometric sources (smartphones, tablets, laptops) to form a comprehensive premises trust score, making the system both more secure and universally applicable to various user scenarios.
Data Source
Figure 1
Figure 2A~2D
Figure 3
AI summary
The present disclosure relates to the security of user devices connected to local networks, such as devices comprised in the 'Internet of Things' (IoT). An aspect relates to a computer-implemented method of securing functionality of a user device connected to a local network provided at a premises, the method comprising: determining a premises trust score indicative of a likelihood that an authorised user of the user device is present at the premises, the determining being in dependence on: (i) data received from one or more biometric-capable devices, distinct from the user device, connected to the local network, that data being indicative of continuous biometric authentication of a current user of the respective biometric-capable device; or (ii) a lack thereof; then causing the user device to respond to a request for functionality made through a local user interface it comprises in a manner which depends on the premises trust score.