Ambient Power Authentication Frames for Private Secure Sessions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Wireless communication sessions with ambient power (AMP) devices are often unencrypted due to limited power availability, risking privacy and security, especially in IoT devices, and existing handshake protocols are power-intensive, making them impractical for AMP devices.
Innovation Solution
AMP devices initiate encrypted communication sessions using initialization and ID request frames with random MAC addresses, and a network server performs authentication and key management to minimize power consumption and maintain privacy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If encrypted communication sessions are implemented with AMP devices, then privacy and security are improved, but power consumption increases
Solution Approach 1:
The patent applies preliminary action by performing authentication and key management before actual data transmission. The network server authenticates the AMP device and establishes encryption keys in advance, so that when communication occurs, the AMP device only needs to use lightweight encryption operations rather than performing complex authentication protocols during data transmission, thereby reducing overall power consumption while maintaining security.
Solution Approach 2:
The patent introduces a network server as an intermediary that handles computationally intensive authentication and key management tasks. This mediator performs the heavy lifting of security protocols on the powered device side, while the AMP device only participates in simplified, low-power verification processes, thus enabling encrypted communication without burdening the power-constrained AMP device with full authentication overhead.
2Reliability
If traditional handshake protocols are used for secure communication, then security is improved, but device complexity and power consumption increase
Solution Approach 1:
The patent extracts the complex authentication and key management functions from the AMP device and relocates them to the network server. This extraction removes the burden of processing extensive handshake protocols from the AMP device, reducing its operational complexity and power consumption while maintaining robust security through server-based authentication mechanisms.
Solution Approach 2:
The patent changes the parameters of the communication protocol by using simplified authentication mechanisms and reduced frame exchange sequences. Instead of traditional multi-step handshakes requiring numerous back-and-forth messages, the system employs streamlined authentication parameters that achieve security with fewer communication steps, directly reducing device complexity and energy usage.
3Reliability
If device identifiers are transmitted in communication frames, then communication reliability is improved, but privacy is worsened
Solution Approach 1:
The patent applies dynamics by using dynamic, changing identifiers instead of static device IDs. The system employs temporary or random identifiers that change between communication sessions, so that while device identification is maintained for reliable communication within a session, long-term tracking and privacy inference are prevented. This dynamic approach allows communication reliability to be maintained without compromising privacy.
Data Source
AI summary
A method includes determining, by an ambient power (AMP) device that harvests environmental energy, one or more first authentication and key management (AKM) parameters. The method includes broadcasting, to powered wireless devices, an initialization request frame including one or more frame-exchange parameters, the one or more first AKM parameters, and encrypted content with which a powered wireless device of the powered wireless devices is to establish an encrypted wireless communication session with the AMP device. The content that was encrypted can include an identifier of the AMP device that is also known to the powered wireless device. The method includes using, by the AMP device within the initialization request frame, a first random address as a source media access control (MAC) address and one of a broadcast address or a group address as a destination MAC address.


