Terminal Device Authentication Using Sensor Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for authenticating terminal devices in communication networks often require complex configurations, pre-shared secrets, and public key infrastructures, which can be insecure and inconvenient, especially for residential users without Internet access.

Innovation Solution

A method that authenticates terminal devices without pre-configured secrets or complex algorithms, using symmetrical or asymmetrical key generation and sensor-based interactions to establish a secure connection, leveraging existing secure connections and user interactions to ensure legitimacy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods (passwords, pre-shared secrets, public key infrastructure) are used, then security can be achieved, but device complexity and configuration difficulty increase significantly

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The terminal device generates authentication credentials autonomously using its own sensor data without requiring external key distribution or certificate management. The device serves itself by creating the authentication proof from its unique physical characteristics, eliminating the need for complex pre-configuration or infrastructure support.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Sensor data acts as an intermediary that bridges the terminal device and the authentication server. Instead of directly exchanging secrets or certificates, the sensor data serves as a neutral mediator that proves the device's identity through its unique physical characteristics, simplifying the authentication protocol.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If pre-shared secrets or passwords are used for authentication, then security can be established, but vulnerability to attacks (invasive, side-channel, eavesdropping) increases

Engineering Contradiction:
Improveauthentication securityVSAvoidvulnerability to attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the authentication proof from static secrets and embeds it in dynamic sensor data that reflects the device's unique physical characteristics. By taking out the vulnerability of pre-shared secrets and replacing them with ephemeral sensor-based credentials, the system eliminates the attack vectors that target stored secrets.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The authentication credentials are made dynamic by using sensor data that changes with each measurement. Instead of static passwords or keys, the system uses continuously varying sensor readings that reflect the device's physical state, making it impossible for attackers to reuse captured credentials or perform replay attacks.

Inventive Principle:
Principle #15Dynamics

3Reliability

If complex authentication algorithms and certificate verification are implemented, then security is improved, but computational energy consumption increases

Engineering Contradiction:
Improveauthentication securityVSAvoidcomputational energy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent uses inexpensive, easily measurable sensor data instead of computationally intensive cryptographic operations. The sensor readings serve as disposable, single-use authentication credentials that require minimal processing to generate and verify, dramatically reducing energy consumption compared to public key infrastructure.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The patent replaces complex computational authentication mechanisms with simple physical measurements. Instead of running heavy cryptographic algorithms, the system uses straightforward sensor readings that naturally encode the device's identity, substituting mechanical/physical processes for computational ones to reduce energy usage.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Reliability

If traditional authentication methods requiring configuration are used, then security can be established, but ease of operation decreases, especially for residential users

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication configuration ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The terminal device automatically generates its authentication credentials using its own sensor data without requiring user configuration. The device serves itself by extracting unique identifiers from its physical characteristics, eliminating the need for users to manually set up passwords or certificates.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The sensor data serves multiple functions: it characterizes the device's physical identity, provides authentication credentials, and proves the device's legitimacy. This multi-functional use of sensor data eliminates the need for separate configuration steps for different authentication mechanisms, simplifying the user experience.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10567960B2Method and apparatus for authenticating a terminal device in a communication network
Publication Date: 2020.02.18 ROBERT BOSCH GMBH
  • US10567960B2 patent drawing
  • US10567960B2 patent drawing

AI summary

A method for authenticating a terminal device in a communication network, wherein a communication connection is established between the terminal device and a network access node of the communication network; upon a sensory stimulation of the terminal device, the terminal device performs a recording of sensor data; the terminal device transmits the sensor data via the communication connection to the network access node; and the terminal device is authenticated by the network access node as a function of a confirmation or rejection of a playback of the sensor data.