Trusted Device Authentication Circuitry for Seamless IoT Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing digital systems face challenges in establishing trusted communication with target devices, particularly in environments with a large number of devices, such as the internet-of-things, where users must manage multiple passwords and frequent authentication is burdensome and insecure.
Innovation Solution
A trusted device with authentication circuitry that verifies user possession, retention monitoring circuitry that ensures continued user possession, communication triggering circuitry that detects communication requests, and communication circuitry that securely communicates with target devices using appropriate credentials.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a user stores multiple passwords for different target devices, then the ability to communicate with multiple devices is improved, but the burden of frequent password entry and management increases
Solution Approach 1:
The trusted device automatically performs authentication with target devices using stored credentials, eliminating the need for manual password entry by the user. The device self-manages the authentication process by presenting credentials when connecting to target devices, thereby reducing operational burden while maintaining versatility.
Solution Approach 2:
The user performs authentication and credential storage in advance when initially setting up the trusted device. This preliminary action establishes trust relationships with multiple target devices beforehand, so that subsequent communications occur automatically without requiring repeated user intervention.
2Reliability
If a password is used to protect the trusted device, then security is improved, but the vulnerability increases if the password becomes known to another party
Solution Approach 1:
The patent extracts the password protection function from the trusted device itself, using a separate security element or hardware module to store and manage credentials. This separation means that even if the trusted device is compromised, the core authentication credentials remain protected in a secure, isolated location that is resistant to software-based attacks.
Solution Approach 2:
A secure element or hardware security module acts as an intermediary between the user and the trusted device, managing credential storage and authentication independently. This intermediary layer provides enhanced security by isolating sensitive credentials from the main device software, reducing vulnerability to attacks on the trusted device itself.
3Reliability
If a token device is used for authentication, then security is improved, but the complexity of the authentication process increases
Solution Approach 1:
The patent combines the trusted device with credential storage and authentication capabilities into a single integrated unit. Instead of requiring separate physical tokens and manual code entry, the trusted device automatically manages authentication credentials and performs verification, merging multiple authentication functions into one streamlined process that maintains security while reducing complexity.
Data Source
AI summary
A trusted device, such as a wristwatch, is provided with authentication circuitry, used to perform an authentication operation to switch the trusted device into an authenticated state. Retention monitoring circuitry monitors the physical possession of the trusted device by the user following the authentication operation and switches the trusted device out of an authenticated state if the trusted device does not remain in the physical possession of the user. While the trusted device remains in the physical possession of the user, communication triggering circuitry is used to detect a request to establish communication with a target device that is one of a plurality of different target devices and communication circuitry is used to communicate with that target device using an authenticated identity of the user.


