Continuous Device Authentication via Trusted Peer Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing continuous authentication systems rely heavily on knowledge-based (human-dependent) authentication as a primary fallback mechanism when devices are disconnected, which is inefficient and insecure.
Innovation Solution
A method for continuous device authentication that utilizes a second device within a network to verify the first device's authenticity without human intervention, using device metrics such as channel state information, device configuration, and clock skewness, and selecting the second device based on proximity and authentication strength.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If knowledge-based (human-dependent) authentication is used as fallback mechanism, then devices can be reconnected after disconnection, but security is compromised and authentication efficiency is reduced
Solution Approach 1:
The system enables devices to authenticate themselves automatically through continuous authentication mechanisms without requiring human intervention. The authentication process is embedded in the device operation, continuously verifying device identity and status, and automatically handling reconnection scenarios without user involvement.
Solution Approach 2:
The patent introduces an intermediary authentication system that mediates between devices and the network. This intermediary continuously monitors device status, performs background authentication, and manages reconnection processes, eliminating the need for direct human intervention while maintaining security.
2Reliability
If continuous biometric authentication is implemented, then real-time imposter detection is improved, but device complexity and implementation cost increase
Solution Approach 1:
The patent applies multi-functionality by using existing device sensors and components for authentication purposes. The same hardware resources are utilized for both normal device operation and continuous authentication, avoiding the need for dedicated complex authentication hardware while maintaining imposter detection capabilities.
Solution Approach 2:
The system changes authentication parameters by transitioning from periodic manual authentication to continuous automated authentication. It monitors multiple device parameters simultaneously (device metrics, connection status, operational behavior) to detect imposters, distributing the complexity across multiple simple measurements rather than one complex biometric system.
3Measurement precision
If device metrics are collected for authentication, then authentication precision is improved, but data processing requirements and system overhead increase
Solution Approach 1:
The patent implements partial action by selectively collecting and processing only the most relevant device metrics for authentication purposes. Instead of continuously monitoring all possible device parameters, the system focuses on key metrics that provide sufficient authentication accuracy while minimizing processing overhead and energy consumption.
Data Source
Figure 1A
Figure 1B
Figure 2
AI summary
An authentication method for authenticating a first device in a network of devices, the method comprising: performing an authentication procedure to attempt to authenticate the first device; determining that the authentication procedure has failed to authenticate the first device; determining that a second device is connected to the first device; requesting authentication of the first device by the second device; receiving an authentication response from the second device; and if the second device verifies the first device in response to receiving the authentication response, authenticating the first device.