Access Point Personal Encryption Key Generation for IoT Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional communication connection methods for IoT devices with access points are insecure, as they require users to input encryption keys, which can be compromised, and are cumbersome when connecting multiple devices, as each device needs to be manually configured with access point information.

Innovation Solution

An access point system that generates a personal encryption key for each IoT device using a public encryption key, allowing secure communication connections without storing the master encryption key on the device, and enabling multiple devices to be registered with a single user input of their respective public encryption keys.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption key information is stored in external device, then communication connection can be established, but security is compromised due to hacking risk

Engineering Contradiction:
ImprovesecurityVSAvoidhacking risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the encryption key storage function from the external device and relocates it to the access point. The access point generates and stores personal encryption keys for each external device, eliminating the need for external devices to store master encryption keys. This extraction resolves the security vulnerability where stored keys could be compromised by hacking.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The access point acts as an intermediary that generates personal encryption keys for external devices without requiring the external devices to store master keys. The access point mediates the encryption key management process, creating a secure architecture where key generation and storage are centralized in a controlled environment.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If manual input of access point information is required for each device, then connection can be established, but user convenience deteriorates when connecting multiple devices

Engineering Contradiction:
Improveconnection establishmentVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system enables self-service connection where external devices automatically receive their personal encryption keys from the access point without requiring manual user input for each device. The access point automatically generates and transmits encryption keys to external devices, eliminating repetitive manual configuration while maintaining secure connections.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The access point performs preliminary actions by pre-generating and transmitting personal encryption keys to external devices before actual communication begins. This preliminary key generation and transmission process eliminates the need for manual key input during connection establishment, improving user convenience while ensuring security.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If master encryption key is stored in external device, then communication can proceed, but key leakage risk increases

Engineering Contradiction:
Improvecommunication efficiencyVSAvoidkey leakage
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the master encryption key storage function from external devices and relocates it to the access point. Each external device receives a unique personal encryption key generated by the access point, eliminating the need to store master keys in external devices and preventing key leakage through device compromise.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system implements local quality by generating unique personal encryption keys tailored to each external device rather than using a single master key. Each external device has its own dedicated encryption key, isolating the security impact to individual devices and preventing widespread key leakage.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11082836B2Access point and method for connecting communication with external device thereof
Publication Date: 2021.08.03 SAMSUNG ELECTRONICS CO LTD
  • US11082836B2 patent drawing
  • US11082836B2 patent drawing
  • US11082836B2 patent drawing

AI summary

A communication connection method of an access point is provided. The communication connection method according to an embodiment includes acquiring information of a first encryption key corresponding to an external device from a user terminal based on a request for communication connection using the first encryption key being received from the external device, performing a communication connection with the external device using the first encryption key, generating a second encryption key corresponding to the external device while the communication connection using the first encryption key is performed, transmitting the generated second encryption key to the external device, and performing the communication connection with the external device using the generated second encryption key based on a request for communication connection using the generated second encryption key being received from the external device after the communication connection using the first encryption key is terminated.