PUF-Based Device and User Authentication Binding
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authentication methods in telehealth systems fail to securely bind user and device identities, leading to potential misuse of data and compromised healthcare decisions due to the lack of secure user and device authentication, allowing for impersonation and device forgery.
Innovation Solution
A method and system that utilize Physically Unclonable Functions (PUFs) in combination with user inputs, such as biometric measurements or passwords, to generate unique keys for both users and devices, ensuring secure authentication by binding device and user identities through a secure key generation process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If device ID is used as user identifier or mapped to user ID in telehealth systems, then device identification is enabled, but secure authentication and data provenance cannot be established
Solution Approach 1:
The system performs preliminary binding of device ID to user ID during device registration. A unique identifier is generated and stored in association with both the device and user, establishing the relationship before any measurements are taken. This preliminary action ensures that subsequent measurements are automatically linked to the correct user-device pair without requiring complex authentication mechanisms during actual use.
Solution Approach 2:
The patent introduces a unique identifier as an intermediary element that mediates between the device ID and user ID. This intermediary binding mechanism allows secure authentication without requiring direct complex interactions between the device and user during measurement taking. The unique identifier serves as a trusted intermediary that establishes the relationship once and maintains it throughout the measurement process.
2Reliability
If manual mapping between device ID and user ID is required, then user identification is possible, but mistakes can be made and malicious users can impersonate real users
Solution Approach 1:
The system performs the mapping action in advance during device registration rather than requiring manual mapping during each measurement. The unique identifier is pre-bound to both device and user, eliminating the need for manual intervention during actual use. This preliminary binding prevents both accidental mistakes and intentional impersonation while maintaining ease of operation.
Solution Approach 2:
The system automatically performs the identification and binding operations without requiring manual user intervention. The unique identifier is automatically generated and bound to the device during registration, and subsequently automatically associated with measurements taken by that device. This self-service mechanism eliminates human error while maintaining simplicity for the end user.
3Reliability
If device ID can be copied to forged devices, then device identification is enabled, but device authentication and data reliability are compromised
Solution Approach 1:
The system performs preliminary binding of the unique identifier to the specific device during its initial registration. This binding is established before the device can be used for measurements, ensuring that only the legitimate device can perform authenticated measurements. The preliminary action prevents copying or forging because the binding is established through secure cryptographic mechanisms that are difficult to replicate.
Solution Approach 2:
The patent employs cryptographic parameters and unique identifiers that change or vary in a way that prevents copying. The unique identifier is generated through cryptographic operations that produce values with specific properties making them impossible to replicate. This parameter transformation ensures device authentication while maintaining ease of manufacture, as the cryptographic operations are performed automatically during registration without adding complex manufacturing steps.
Data Source
AI summary
A method of authenticating a device and a user comprises receiving a user input, generating a first key from the user input, performing a physical measurement of the device, obtaining helper data for the device, computing a second key from the physical measurement and the helper data, and performing an operation using the first and second keys. In a preferred embodiment, the method comprises performing a defined function on the first and second keys to obtain a third key. Additionally security can be provided by the step of receiving a user input comprising performing a biometric measurement of the user and the step of generating a first key from the user input comprises obtaining helper data for the user and computing the first key from the biometric measurement and the user helper data.


