IoT Device Ecosystem Authentication via Confidence Scoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current IoT technologies provide limited methods for authenticating users, making them vulnerable to unauthorized access, especially when devices like smartphones are stolen, and existing biometric solutions are expensive and inefficient.

Innovation Solution

A system and method that creates a unique device ecosystem using a combination of biometric technologies and presence information from devices in proximity to each other, calculating a confidence score for authentication, allowing access with a two-part authentication process involving a mesh network of devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional biometric devices are used for authentication, then security reliability is improved, but implementation cost increases significantly

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidimplementation cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent combines multiple ordinary devices (smartphone, smartwatch, key ring) into a device ecosystem that works together for authentication. Instead of using a single expensive biometric device, the system merges the capabilities of multiple affordable devices to achieve comparable or superior security reliability through collective verification.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The authentication system uses universal devices that users already possess (smartphones, smartwatches, key rings) for multiple purposes including authentication, notification, and device control. These everyday devices serve the additional function of security authentication, eliminating the need for dedicated expensive biometric hardware.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If simple authentication methods are used, then ease of operation is improved, but security vulnerability increases

Engineering Contradiction:
Improveauthentication convenienceVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication process is segmented into two distinct parts: automatic authentication when the device ecosystem is complete and confident, and manual authentication (log on sequence) when confidence is insufficient. This segmentation allows the system to adapt to different security situations, maintaining ease of operation for normal cases while enhancing security for suspicious cases.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The authentication requirement dynamically adjusts based on the calculated confidence score. When the device ecosystem shows high confidence (all devices present and communicating normally), automatic authentication is enabled for convenience. When confidence is low (missing devices or abnormal states), the system dynamically requires manual log on sequence for enhanced security.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10798106B2System for providing layered security
Publication Date: 2020.10.06 AT&T INTELLECTUAL PROPERTY I L P
  • US10798106B2 patent drawing
  • US10798106B2 patent drawing
  • US10798106B2 patent drawing

AI summary

A system for providing layered security is disclosed. In particular, the system may include determining a state of a first device of a device ecosystem and a state of a second device of the device ecosystem. Based on the states of the first and second devices, the system may include calculating a confidence score for the device ecosystem. If the confidence score satisfies a threshold score for enabling access to a selected system, the system may include transmitting an access code to the device ecosystem. Based on the access code, the system may enable the device ecosystem to access the selected system. If, however, the confidence score does not satisfy the threshold score, the system may include requiring the device ecosystem to provide additional authentication information in order to access the selected system.