IoT Device Identity Binding for Authenticated Transactions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing IoT devices lack effective mechanisms to authenticate users before initiating transactions, leading to unauthorized access and potential fraud.

Innovation Solution

A system and method for binding a user's identity to an IoT device through an identity network, where user credentials are verified and securely linked to the device, ensuring only authorized users can initiate transactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If IoT devices are made accessible to users for convenient operation, then ease of operation is improved, but security and authorization control deteriorate

Engineering Contradiction:
Improvedevice accessibilityVSAvoiduser authentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary actions by pre-establishing binding relationships between user identities and IoT device identifiers before any transactions occur. The identity network stores these pre-bound associations, enabling automatic authentication without requiring manual intervention during transaction operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The identity network serves as an intermediary between users and IoT devices. Instead of direct access, users interact with the identity network which validates their identity against bound device identifiers. This intermediary layer enables convenient access while maintaining security through centralized identity verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If user authentication is implemented to prevent unauthorized access, then security is improved, but device complexity increases

Engineering Contradiction:
Improvetransaction authorizationVSAvoidauthentication mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication logic is extracted from the IoT devices and relocated to the identity network. Devices only store their identifiers and receive authentication results, while the complex verification of user identities against bound relationships occurs centrally at the identity network, simplifying device architecture.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Instead of implementing complex authentication protocols directly in each device, the system uses simplified device identifiers (copies of essential identification information) that are verified against stored binding relationships in the identity network. This copying approach reduces device complexity while maintaining authorization capability.

Inventive Principle:
Principle #26Copying

3Reliability

If binding mechanisms are implemented to link users with devices, then authorization control is improved, but information processing requirements increase

Engineering Contradiction:
Improveuser-device authorizationVSAvoididentity verification data
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system merges user identity information with device identifier information into unified binding relationships stored at the identity network. This consolidation allows the system to verify authorization by processing combined identity-device linkage data rather than handling separate verification processes, reducing overall information processing requirements.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS20250317437A1Systems and methods for use in binding internet of things devices with identities associated with users
Publication Date: 2025.10.09 MASTERCARD INT INC
  • US20250317437A1 patent drawing
  • US20250317437A1 patent drawing
  • US20250317437A1 patent drawing

AI summary

Systems and methods are provided for binding an IoT device with an identity of a user. One example computer-implemented method includes receiving a request to pair the IoT device with a communication device associated with a user and, in response, detecting one or more devices within range of the IoT device via wireless communication. The method also includes displaying the one or more detected devices to the user, receiving a selection of the user's communication device, and displaying a passcode to the user. The method also includes establishing pairing with the communication device, by the IOT device, via the passcode entered at the communication device, and sharing a device ID of the IoT device with the communication device, based on the paring. The method further includes receiving identifying data including a verified identity of the user and storing the identifying data in memory of the IoT device.