IoT Ownership Token Transfer via Near-Field Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
IoT devices are vulnerable to unauthorized access due to default login credentials, which are often publicly known or easily guessed, leading to significant distributed denial-of-service (DDOS) attacks, as seen with the Mirai botnet.
Innovation Solution
An ownership token system is introduced, which generates a unique authentication token bound to each IoT device, requiring a first and second authentication factor and a device identifier, preventing unauthorized access by using near-field communication to transfer the ownership token to a mobile device, thereby securing the device's configuration settings and input/output resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If default access credentials are used for IoT devices, then device deployment and setup are simplified, but security against unauthorized access deteriorates
Solution Approach 1:
The patent implements preliminary action by pre-configuring unique authentication credentials (device identifier and authentication factor) in the IoT device during manufacturing, before deployment. This eliminates the need for default credentials while maintaining ease of deployment, as the device is ready for secure authentication out of the box without requiring post-deployment configuration.
Solution Approach 2:
The patent applies local quality by making each IoT device have its own unique authentication credentials specific to that device instance. Instead of using universal default credentials across all devices, each device has locally unique authentication factors that are specific to its identity, thereby improving security while maintaining individual device autonomy.
2Reliability
If unique authentication credentials are implemented for each IoT device, then security against unauthorized access is improved, but device complexity and setup procedures increase
Solution Approach 1:
The patent extracts the complex authentication management from the IoT device itself and places it on the external system (server or controlling device). The device only needs to store and present its unique authentication factors, while the complex verification logic and credential management are handled externally, reducing the authentication mechanism's complexity within the device.
Solution Approach 2:
The patent introduces an intermediary authentication server that mediates between the IoT device and the authorization system. This server handles the complex authentication logic, credential verification, and token generation, allowing the IoT device to maintain simplicity while achieving strong security through the intermediary's sophisticated authentication mechanisms.
3Speed
If authentication factors are stored locally in IoT devices, then authentication speed is improved, but vulnerability to local attacks increases
Solution Approach 1:
The patent segments the authentication system into multiple components: the IoT device stores only authentication factors, the authentication server stores and verifies credentials, and tokens are generated separately. This segmentation ensures that even if the device is compromised, attackers cannot obtain complete authentication information, as the critical credential verification and token generation occur on the secure server.
Solution Approach 2:
The patent uses token copying as a security mechanism where the authentication server creates a temporary copy of authentication credentials in the form of access tokens that are granted to authorized devices. These tokens can be revoked independently of the original credentials, providing a layer of security that limits the impact of credential compromise while maintaining fast authentication through token presentation.
Data Source
AI summary
A mobile device that includes an ownership token application program receives user input indicative of a first authentication factor associated with an ownership token bound to an Internet of Things (IoT) device. Responsive to detecting the IoT device in close proximity, the mobile device may obtain a second authentication factor and an IoT device identifier from the IoT device. The mobile device may then provide the obtained factors as authenticating credentials to a token server via a trust application program interface (API). After the server authenticates the mobile device, the server may send the token to the mobile device thereby transferring ownership rights, including access rights, to recipient. The application program and/or the trust API may be configured for one-time access wherein, after the token has been transferred to the mobile device. The discrete electronic device may comprise an Internet of Things (IoT device) that supports wireless, near field communication.


