IoT Device Identity Binding for Pre-Authenticated Transactions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing IoT devices lack effective mechanisms to authenticate and authorize users before initiating transactions, leading to potential unauthorized use and fraud.

Innovation Solution

A system and method for binding a user's identity to an IoT device through an identity network, using a communication device to verify and authenticate the user before allowing transactions, ensuring only authorized users can initiate actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If IoT devices are made accessible for use, then ease of operation is improved, but security and authorization control deteriorate

Engineering Contradiction:
Improvedevice accessibilityVSAvoidauthorization control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary actions by binding the user's identity to the IoT device before allowing any transactions or actions to occur. This pre-authentication mechanism ensures that only authorized users can access and operate the device, resolving the contradiction by establishing security controls in advance while maintaining ease of operation for authenticated users.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary authentication mechanism that mediates between the user and the IoT device. This intermediary layer verifies the user's identity and binds it to the device before allowing access, thus maintaining both ease of operation for legitimate users and strong authorization control against unauthorized access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If user authentication is implemented, then security is improved, but device complexity increases

Engineering Contradiction:
Improveuser authenticationVSAvoidauthentication system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent employs an intermediary authentication system that simplifies the authentication process while maintaining security. This intermediary layer handles the complex authentication logic centrally, allowing the IoT device to remain relatively simple while still providing robust user verification through the intermediary's coordinated effort.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication mechanism is designed with universality, serving multiple functions: it authenticates users, binds identities to devices, and enables transactions. This multi-functionality reduces overall system complexity by consolidating authentication-related operations into a unified mechanism rather than requiring separate complex subsystems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If identity binding mechanism is added, then fraud protection is improved, but ease of manufacture deteriorates

Engineering Contradiction:
Improvefraud protectionVSAvoidsystem implementation
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent introduces an intermediary binding mechanism that facilitates fraud protection without complicating the core IoT device manufacturing. This intermediary layer handles the complex identity binding and verification processes, allowing manufacturers to produce standard devices while the intermediary system provides the necessary fraud protection through centralized identity management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12363101B2Systems and methods for use in binding internet of things devices with identities associated with users
Publication Date: 2025.07.15 MASTERCARD INT INC
  • US12363101B2 patent drawing
  • US12363101B2 patent drawing
  • US12363101B2 patent drawing

AI summary

Systems and methods are provided for binding an IoT device with an identity of a user, whereby action by the IoT device may be attributed to the user. One example computer-implemented method includes verifying a user and, in response to the verification, compiling and storing identifying data for the user. The method also includes receiving an IoT device ID associated with an IoT device, from a communication device associated with the user, and appending the IoT device ID to the identifying data for the user. The method then includes receiving a request indicator from the IoT device, seeking authentication of the user at the communication device, and in response to the request indicator and the authentication of the user, provisioning, to the IoT device, at least a portion of the identifying data for the user.