Host-Independent Wireless Authentication for IoT Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security systems for electronic devices and storage media face challenges in providing robust, host-independent user authentication and encryption, as they often rely on host computers for authentication, making them susceptible to hacking and lacking in remote management and monitoring capabilities, especially for portable and industrial tools.

Innovation Solution

A security system (SECSYS) that includes a data security transceiver, an authentication subsystem, and a storage subsystem, enabling autonomous user authentication through wireless communication, independent of the host device or operating system, with a remote management system for securing and managing electronic devices, such as power tools and IoT devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If host-dependent authentication is used, then device complexity is reduced, but security reliability deteriorates due to susceptibility to hacking and host architecture dependencies

Engineering Contradiction:
Improveauthentication system complexityVSAvoidauthentication security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The authentication system is segmented into independent components: a host-independent authentication subsystem within the storage device that can independently verify user credentials without relying on the host computer's authentication mechanisms. This segmentation isolates the security-critical functions from potential host-based attacks while maintaining overall system simplicity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

An intermediary authentication subsystem is introduced between the user and the stored data. This intermediary layer performs verification independently of the host, acting as a mediator that enhances security without significantly increasing the perceived complexity for end users. The intermediary can be a separate authentication device or an isolated subsystem within the storage device.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If wireless authentication is implemented, then remote management capability is improved, but device complexity increases due to additional communication subsystems

Engineering Contradiction:
Improveremote management capabilityVSAvoidcommunication subsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The wireless communication subsystem is designed to perform multiple functions: authentication, data transfer, and remote management. By making the communication subsystem universal, the patent avoids adding separate dedicated systems for each function, thereby limiting the increase in overall device complexity while maximizing adaptability and remote management capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The authentication and data transfer functions are merged into a unified wireless communication process. Instead of separate subsystems for authentication and data communication, the patent combines these functions into a single integrated wireless interface, reducing the number of components needed while enabling both local and remote management operations.

Inventive Principle:
Principle #5Merging (Combining)

3Speed

If encryption key is stored on media, then authentication speed is improved, but security deteriorates as the key becomes vulnerable to direct media reading

Engineering Contradiction:
Improveauthentication speedVSAvoidencryption security
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The encryption key is extracted from the storage media and placed in a separate, secure location within the authentication subsystem. This extraction prevents direct access to the key through media reading attempts, as the key resides in a protected authentication module rather than being stored alongside user data on the vulnerable media surface.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The encryption key is nested within a protected authentication subsystem that is itself nested within the storage device. This nested structure provides multiple layers of protection: the key is hidden within the authentication module, which is accessible only through authenticated channels, preventing both direct media reading and unauthorized access while maintaining fast authentication through the nested architecture.

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentUS11190936B2Wireless authentication system
Publication Date: 2021.11.30 CLEVX LLC
  • US11190936B2 patent drawing
  • US11190936B2 patent drawing
  • US11190936B2 patent drawing

AI summary

Methods, systems, and computer programs are presented for managing electronic devices with autonomous wireless authentication. In one example, the security system includes one or more computer processors, a memory, and a communication channel configured to be coupled to an electronic system. The security system further includes a radio frequency (RF) transceiver configured to receive user-authentication information from a wireless device, and an authentication subsystem for authenticating a user. The authentication subsystem enables the use of the electronic system based on the received user-authentication information. Further, the authentication subsystem sends, over the communication channel, an enable command to the electronic system after the user is authenticated, and the electronic system is not operable until the enable command is received.