Multifactor Device Authentication via Sensor and Traffic Signatures

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication systems in communication networks face vulnerabilities due to the ease of spoofing IP or MAC addresses, especially with IoT devices, and regulatory risks associated with using these addresses as identifiers, leading to inadequate security and privacy concerns.

Innovation Solution

Implementing a multifactor authentication system that uses sensor data signatures and traffic pattern signatures, generated through deep learning models, to uniquely identify devices, providing continuous authentication without requiring additional user input.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If IP or MAC addresses are used for device authentication, then device identification is simple, but security is compromised due to ease of spoofing

Engineering Contradiction:
Improveease of device identificationVSAvoidsecurity
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent replaces traditional mechanical/authentication-based identification methods (IP/MAC addresses) with sensor-based biometric authentication. Sensors capture physiological or behavioral characteristics that are difficult to spoof, thereby substituting a more secure authentication mechanism while maintaining ease of identification.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent changes the authentication parameter from network address (IP/MAC) to sensor-derived characteristics (biometric or behavioral data). This parameter change makes authentication more secure because sensor data reflects actual device usage patterns and physical characteristics that cannot be easily replicated.

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If IP or MAC addresses are used as device identifiers, then device tracking is straightforward, but privacy regulations are violated

Engineering Contradiction:
Improveease of device trackingVSAvoidprivacy risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent substitutes network address-based tracking with sensor-based identification. Sensors capture device-specific characteristics that enable tracking without relying on assignable network addresses, thereby reducing privacy risks associated with IP/MAC address collection and compliance with regulations like GDPR.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces sensor data as an intermediary between the device and the authentication system. Instead of directly using identifiable network addresses, the system mediates through sensor-captured characteristics, which provide device identification while reducing direct exposure of personal identifiable information.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If traditional authentication methods are used, then user input is required, but continuous authentication is not achieved

Engineering Contradiction:
Improveuser input requirementVSAvoidauthentication continuity
Core Design Contradiction:
Ease of operationVSDuration of action of stationary object

Solution Approach 1:

The patent enables continuous authentication by continuously capturing sensor data during device usage. Instead of requiring periodic user input, the system continuously monitors sensor characteristics (such as device handling patterns, biometric data, or behavioral metrics) to maintain authentication status throughout the session, ensuring uninterrupted secure access.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The patent implements self-service authentication where the device itself provides authentication data through its sensors. The device's natural usage generates sensor data that automatically serves as authentication evidence, eliminating the need for separate user authentication actions while maintaining continuous verification.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11546328B2Continuous multifactor device authentication
Publication Date: 2023.01.03 HEWLETT PACKARD ENTERPRISE DEV LP
  • US11546328B2 patent drawing
  • US11546328B2 patent drawing
  • US11546328B2 patent drawing

AI summary

A device is authenticated for communication over a network based on a sensor data signature and a traffic pattern signature. The sensor data signature and the traffic pattern signature identify the device. A determination is made whether the sensor data signature corresponds to one of a plurality of recognized sensor data signatures. A determination is also made whether the traffic pattern signature of the device corresponds to one of a plurality of recognized traffic pattern signatures. The device is authenticated for communication over the network responsive to determining that the sensor data signature corresponds to one of the plurality of recognized sensor data signatures and the traffic pattern signature corresponds to one of the plurality of recognized traffic pattern signatures.