Wearable IoT Identity Protection via Distributed Key Fragmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current user identification methods, such as document-based and biometrics, are prone to errors, expensive, and vulnerable to theft or loss, especially in the context of wearable IoT devices, which can expose users to privacy risks and identity theft.

Innovation Solution

Implementing a secret sharing algorithm across multiple personal IoT devices to create a user's digital identity, ensuring that it can only be unlocked with a pre-defined number of devices in proximity, using fragmented keys for secure authentication and encryption, and a trusted execution environment to manage and filter identity communications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If biometrics-based identification is used, then identification reliability is improved, but system cost and complexity increase due to expensive databases and sensitive data storage requirements

Engineering Contradiction:
Improveidentification reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The identification system is segmented into multiple independent wearable devices, each storing only a fragment of the authentication key rather than the complete key or entire biometric database. This segmentation eliminates the need for centralized expensive databases while maintaining identification reliability through distributed key verification.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts the critical authentication function from centralized biometric databases and relocates it to distributed wearable devices. Each device contains only the necessary key fragment for authentication, removing the dependency on expensive centralized storage infrastructure while preserving identification reliability.

Inventive Principle:
Principle #2Taking out (Extraction)

2Ease of operation

If document-based identification is used, then ease of operation is maintained, but security and reliability deteriorate due to theft, loss, and human error

Engineering Contradiction:
Improveease of operationVSAvoidsecurity reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication key is segmented into multiple fragments distributed across different wearable devices. This maintains ease of operation as users simply wear the devices, while dramatically improving security reliability since no single device contains the complete key, preventing theft and loss vulnerabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary key fragmentation and distribution to wearable devices before authentication is needed. This preliminary action ensures that when authentication is required, the process is simple and reliable, while the security is already established through the pre-distributed key fragments.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If centralized identity databases are used, then identification accuracy is improved, but vulnerability to data breaches and identity theft increases

Engineering Contradiction:
Improveidentification accuracyVSAvoiddata breach vulnerability
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The centralized identity database is segmented into distributed key fragments across multiple wearable devices. This maintains identification accuracy through cryptographic verification while eliminating the single point of failure and data breach vulnerability inherent in centralized databases.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts the vulnerable centralized database component and replaces it with distributed key fragments in wearable devices. This extraction removes the target for data breaches while preserving identification accuracy through the cryptographic key verification process.

Inventive Principle:
Principle #2Taking out (Extraction)

4Ease of operation

If manual pairing and connection processes are used, then ease of operation deteriorates due to complexity and user burden, but security control is improved

Engineering Contradiction:
Improvepairing easeVSAvoidsecurity control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The wearable devices perform self-service authentication by automatically presenting their key fragments and verifying identity through cryptographic protocols. This eliminates complex manual pairing processes while maintaining strong security control, as the devices autonomously manage their own authentication credentials.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The key fragmentation and distribution to wearable devices is performed as a preliminary action during device provisioning. This preliminary setup enables automatic, simple authentication processes later while the security control is already established through the pre-configured key fragments.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11496450B2Protecting user identity and personal information by sharing a secret between personal IoT devices
Publication Date: 2022.11.08 MCAFEE LLC
  • US11496450B2 patent drawing
  • US11496450B2 patent drawing
  • US11496450B2 patent drawing

AI summary

A wearable device provides protection for personal identity information by fragmenting a key needed to release the personal identity information among members of a body area network of wearable devices. A shared secret algorithm is used to allow unlocking the personal identity information with fragmental keys from less than all of the wearable devices in the body area network. The wearable devices may also provide protection for other personal user data by employing a disconnect and erase protocol that causes wearable devices to drop connections with an external personal data space and erase locally stored personal information if a life pulse from a connectivity root device is not received within a configurable predefined period.