AIoT Uplink Message Protection Using Derived Device Keys
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless communication systems in ambient Internet of Things (AIoT) architectures face security vulnerabilities, particularly in unsecured uplink communications from AIoT devices to AIoT controllers, which can be intercepted or compromised by bad actors.
Innovation Solution
Deriving a protection key using a provisioned device credential and a key derivation parameter to generate confidentiality and integrity protection keys, encrypting messages, and verifying their integrity to secure uplink communications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If unsecured uplink communications are used in AIoT architecture, then device complexity is reduced and ease of operation is improved, but security and reliability deteriorate due to interception and compromise by bad actors
Solution Approach 1:
The system performs preliminary key derivation before communication occurs. The AIoT device and AIoT controller each independently derive the same protection key using the provisioned device credential and key derivation parameter, enabling secure communication to be established in advance without requiring complex real-time authentication protocols during actual data transmission.
Solution Approach 2:
The patent introduces a protection key as an intermediary element that mediates between the AIoT device and AIoT controller. This key serves as a shared secret that enables both parties to encrypt and verify messages without requiring direct complex authentication mechanisms, thereby simplifying the overall communication architecture while maintaining security.
2Reliability
If message encryption and integrity verification are implemented, then communication security and reliability are improved, but device complexity and processing requirements increase
Solution Approach 1:
The patent segments the security function into distinct operations: encryption of the message payload and separate integrity verification through MAC calculation. The AIoT device encrypts only the message content using the protection key, while the AIoT controller separately verifies integrity using the same key. This segmentation allows each component to be implemented independently and simplifies the overall processing complexity.
Solution Approach 2:
The system employs self-service security mechanisms where the AIoT device and AIoT controller autonomously derive and use the protection key without requiring external authentication services. The device independently encrypts messages and the controller independently verifies them, eliminating the need for complex centralized security management and reducing overall system complexity.
Data Source
AI summary
Various aspects of the present disclosure generally relate to wireless communication. In some aspects, an ambient Internet of Things (AIoT) device may generate a protected message using a protection key, where the protection key is derived using a provisioned device credential and a key derivation parameter. The AIoT device may transmit the protected message, via an AIoT reader, for delivery to an application function. Numerous other aspects are described.


