IoT Challenge-Response Authentication Using Dynamic Behavioral Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current user authentication methods, such as challenge questions, are vulnerable to attackers who can discover personal information online or steal devices, leading to security breaches, and two-step authentication can be foiled by device theft or misplacement.

Innovation Solution

Implementing a challenge-response authentication system that uses data points tracked and stored by a user's IoT devices, generating authentication questions based on this data, which only a genuine user can answer by accessing their devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional challenge questions based on personal information are used for authentication, then the authentication process is simple and easy to implement, but the security is vulnerable to attackers who can discover personal information online

Engineering Contradiction:
Improveauthentication process simplicityVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent changes the parameter basis of authentication from static personal information (grandmother's maiden name, first car make) to dynamic IoT device data (location history, exercise routines, shopping patterns). This parameter transformation makes authentication data unique to each user and difficult for attackers to obtain, while maintaining the challenge-response format that keeps the process simple and user-friendly.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces IoT devices as an intermediary layer between the user and the authentication system. These devices continuously collect and store behavioral data that serves as the basis for challenge questions. The intermediary devices make authentication security dependent on physical possession and usage patterns rather than discoverable personal information, while the system automatically generates challenges from this data without requiring complex user setup.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If two-step authentication using a pre-designated device is implemented, then security is heightened, but the system becomes vulnerable to device theft or misplacement

Engineering Contradiction:
Improveauthentication securityVSAvoiddevice theft vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent transforms static device-based authentication into dynamic behavioral authentication. Instead of relying on possession of a specific device, the system uses continuously changing behavioral patterns (location, exercise, shopping) captured by IoT devices. This dynamic approach ensures that even if a device is stolen, the attacker cannot replicate the user's unique behavioral patterns, making authentication resilient to device theft while maintaining high security.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent creates a behavioral fingerprint that is difficult to copy or replicate. By analyzing multiple dimensions of user behavior across different IoT devices and time periods, the system generates authentication challenges that reflect the user's unique patterns. This behavioral copying resistance ensures that stolen devices cannot be used to impersonate the user, as the behavioral data is intrinsic to the user's actions rather than the device itself.

Inventive Principle:
Principle #26Copying

3Ease of operation

If challenge questions use commonly known personal information, then users can easily answer them, but attackers can also easily discover the answers through online research

Engineering Contradiction:
Improveuser ability to answerVSAvoidattackers' ability to discover information
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent fundamentally changes the parameter space from publicly accessible personal information to private behavioral data generated by IoT device usage. Challenges are based on parameters such as specific location coordinates, exercise routine details, and shopping patterns that are unique to each user and not available through online research. This parameter transformation maintains ease of answering for legitimate users while making information discovery by attackers infeasible.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent performs preliminary data collection and analysis by IoT devices before authentication is needed. Devices continuously gather behavioral data in the background, building a rich profile of user patterns over time. This preliminary action ensures that when authentication is required, the system can generate challenging yet answerable questions from pre-collected data, eliminating the need for users to recall personal information while preventing attackers from obtaining answers through research.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11096050B2Challenge-response user authentication based on information collected by internet of things devices
Publication Date: 2021.08.17 KYNDRYL INC
  • US11096050B2 patent drawing
  • US11096050B2 patent drawing
  • US11096050B2 patent drawing

AI summary

Approaches presented herein enable challenge-response authentication of a user based on information captured by devices associated with the user. Specifically, in one approach, a plurality of devices associated with the user that each dynamically track and store on-device data points over a period of time are identified. A request initiated by a party claiming to be the user is received to authenticate the party as the user. An authentication question is generated in a natural language, the answer to which is a data point selected from data points on at least one device of the plurality, wherein the selected data point is discoverable by viewing data points on the at least one device. The requesting party is prompted to find the data point by presenting the authentication question to the requesting party. In the case that the requesting party returns the answer, the requesting party is authenticated as the user.