Bootstrap Erase Architecture for M2M Identity Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In machine-to-machine (M2M) environments, existing bootstrapping processes face challenges with secure key management, device identity exposure, and inefficient service capability layer handovers, particularly in scenarios where devices need to transition between different service capability layers due to changes in network access or geographic location.
Innovation Solution
A bootstrap erase architecture is developed that allows M2M servers to manage policies for access network-specific events, initiate bootstrap erases, and facilitate handovers between service capability layers, using temporary identifiers to secure device identities and handover tokens to transfer resources seamlessly.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If device identities are exposed during bootstrapping for authentication purposes, then authentication can be performed, but security is compromised as device identities become visible to potential attackers
Solution Approach 1:
The patent introduces temporary identifiers (temporary device IDs) as intermediaries between the actual device identity and the authentication process. These temporary identifiers are assigned to devices during bootstrapping and are used in place of permanent device identities when communicating with service capability layers. This mediator approach allows authentication to proceed while preventing direct exposure of permanent device identities, thus resolving the contradiction between authentication capability and security.
2Productivity
If service capability layer handovers are performed without temporary identifiers, then resource transfer can be completed, but device identity security is compromised
Solution Approach 1:
The patent employs temporary identifiers as mediators during service capability layer handovers. When a device transitions between service capability layers, the temporary identifier is included in handover messages instead of the permanent device identity. This allows the handover process to proceed efficiently with resource transfer while the temporary identifier shields the permanent device identity from exposure during the transition, resolving the contradiction between handover efficiency and security.
3Loss of information
If permanent device identifiers are used in all communications, then device identity is always identifiable, but security risks increase from identity theft and tracking
Solution Approach 1:
The patent implements a dynamic identifier system where devices use temporary identifiers during active communication sessions and only reveal permanent identifiers when absolutely necessary. The temporary identifiers are dynamically assigned and invalidated after use, creating a moving target for potential attackers. This dynamic approach maintains device identity traceability for legitimate purposes while significantly reducing security risks associated with permanent identifier exposure, resolving the contradiction between traceability and security.
Data Source
AI summary
Methods, devices, and systems allow for bootstrapping of a machine-to-machine device. In an embodiment, a bootstrap erase architecture allows the machine-to-machine server to manage bootstrap erase policies, detect access network specific events, initiate a bootstrap erase based on these policies and events, and allow for machine-to-machine server handover. In another embodiment, a device or gateway service capability layer may request its network service capability layer fetch data that the device or gateway, previously stored on a different network service capability layer. In another embodiment, when bootstrap erase is performed because the network service capability layer can no longer provide service to the device or gateway, the network service capability layer may recommend other NSCLs to the device or gateway. In another embodiment, a bootstrap erase procedure may be modified so that temporary identifiers may be assigned for a next bootstrapping event.


