Peer-Assisted Authentication via Companion Device Proximity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing user validation methods in IoT environments, such as password protection and biometric authentication, are vulnerable to malicious code and spoofing attacks, lacking a secondary authentication process to ensure secure access to personal or confidential information.

Innovation Solution

Implementing a peer-assisted enhanced authentication method that detects the presence of companion devices using proximity protocols like Bluetooth or LTE Direct, which requires the user to be in proximity to specific devices to validate their identity, providing an additional layer of security beyond traditional authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional password or biometric authentication is used, then user access is enabled, but security is vulnerable to malicious code and spoofing attacks

Engineering Contradiction:
Improveauthentication securityVSAvoidvulnerability to spoofing and malicious code
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The authentication system is segmented into multiple independent verification components: traditional credentials (password/biometric) and device presence verification. By dividing the authentication process into separate stages, the system ensures that compromise of one component (e.g., stolen password) does not lead to complete system failure, as the second component (device proximity) remains intact and provides additional security validation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A companion device acts as an intermediary element in the authentication process. This mediator device serves as a physical token that must be present near the primary device for authentication to succeed. The intermediary device adds a layer of security by requiring physical proximity, making remote attacks and spoofing significantly more difficult since the intermediary device cannot be replicated or accessed remotely.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If companion device detection is added to authentication, then security is enhanced, but system complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary pairing and registration of companion devices before authentication is needed. During this preliminary phase, devices establish trusted relationships and exchange cryptographic keys. When authentication is required, the system only needs to verify the presence of already-trusted devices rather than establishing new security relationships, significantly reducing the complexity of the actual authentication moment while maintaining enhanced security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The companion device serves multiple functions: it acts as a security token for authentication, a proximity indicator, and a trusted identity verifier. By making the companion device universal and multi-functional, the system reduces overall complexity because a single device type can fulfill multiple security roles rather than requiring specialized components for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11144627B2Peer assisted enhanced authentication
Publication Date: 2021.10.12 QUALCOMM INC
  • US11144627B2 patent drawing
  • US11144627B2 patent drawing
  • US11144627B2 patent drawing

AI summary

Techniques for validating a user on an electronic device in an Internet of Things (IoT) environment are provided. An example of an apparatus according to the disclosure includes a transceiver configured to detect one or more proximate devices, and at least one processor operably coupled to the transceiver and configured to receive authentication information from the user, determine that the one or more proximate devices is at least one companion device, and validate the user based on the authentication information and a detection of the at least one companion device.