AIoT Authentication via Verification MAC for Low-Power Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Zero-power Internet of Things (AIoT) devices face challenges in performing high-complexity authentication with network sides due to limited computing power, necessitating a low-complexity method that ensures security.

Innovation Solution

A method involving the transmission of authentication parameters to AIoT devices, allowing them to calculate verification MACs using shared root keys, thereby simplifying the authentication process without compromising security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods are used with high-complexity calculation functions, then security is ensured, but zero-power AIoT devices cannot perform authentication due to limited computing power

Engineering Contradiction:
Improveauthentication securityVSAvoidcomputational complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a first network device as an intermediary that performs complex authentication calculations on behalf of the zero-power AIoT device. The first network device receives authentication requests, performs the high-complexity verification using its computational resources, and returns authentication results to the AIoT device, enabling authentication without requiring the AIoT device to have sufficient computing power

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the complex calculation functions from the zero-power AIoT device and relocates them to the first network device. By separating the authentication calculation functionality from the resource-constrained device, the system enables authentication while maintaining the AIoT device's zero-power characteristic

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If traditional authentication methods are used with complex key architectures, then security is maintained, but processing efficiency is reduced for AIoT devices

Engineering Contradiction:
Improveauthentication securityVSAvoidprocessing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The first network device acts as an intermediary that manages complex key architectures and performs key-related operations. The AIoT device simply provides authentication parameters without needing to perform complex key management operations, thereby maintaining security while improving processing efficiency for the resource-constrained device

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the authentication process into multiple stages: the AIoT device performs simple parameter generation, the first network device performs complex key management and verification, and the core network device performs final authentication. This segmentation allows each component to operate at its optimal complexity level, improving overall processing efficiency

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP4694260A1Authentication methods, key generation method, and device
Publication Date: 2026.02.11 GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTD
  • EP4694260A1 patent drawingFigure 1~5
  • EP4694260A1 patent drawingFigure 6~7b
  • EP4694260A1 patent drawingFigure 8~9

AI summary

The present application relates to authentication methods, a key generation method, a device, a computer-readable storage medium, a computer program product and a computer program. An authentication method comprises: a first device receiving a first message from a first network device, the first message carrying a MAC, an authentication parameter, and an identifier of a second device; and the first device sending a second message to the second device, the second message carrying the MAC and the authentication parameter, the authentication parameter being used for the second device to obtain a verification MAC on the basis of a root key, the verification MAC being used for the second device to authenticate, in combination with the MAC, a core network side device, and the root key being a key shared by the second device and the core network side device.