Chip Identification Device for IoT Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing number of nodes in IoT/IoE systems makes central control-based cybersecurity vulnerable to identification code theft, posing risks to critical infrastructure like auto-driving vehicles and air traffic control systems, as conventional methods are impractical for managing trillions of nodes and detecting stealthy malware attacks.

Innovation Solution

A chip identification device using nonvolatile memory cells with physical randomness to generate output codes, ensuring output independence, input independence, output unpredictability, and input-output reliability, reducing the risk of identification code theft by using semiconductor devices for local identification management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If central control-based identification management is used, then system coordination is improved, but security vulnerability increases due to identification code theft risk

Engineering Contradiction:
Improvesystem coordinationVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent divides the identification management system into two independent parts: central control nodes that coordinate systems and peripheral devices that generate their own unique identification codes locally. This segmentation allows central coordination to continue while eliminating the single point of failure vulnerability where all identification codes were centrally stored and susceptible to theft.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Each peripheral device is equipped with the capability to independently generate and manage its own identification code through local hardware operations. This self-service approach eliminates the need for devices to obtain identification codes from the central system, thereby removing the vulnerability of centralized code storage and distribution while maintaining system coordination.

Inventive Principle:
Principle #25Self-service

2Adaptability or versatility

If conventional identification methods are used, then device compatibility is improved, but detection capability deteriorates against stealthy malware attacks

Engineering Contradiction:
Improvedevice compatibilityVSAvoiddetection capability
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent replaces software-based identification methods with hardware-based physical operations. Identification codes are generated through physical hardware operations (such as electrical resistance measurements or other physical phenomena) rather than software algorithms, making the identification process inherently more difficult for malware to intercept or manipulate while maintaining compatibility through standardized interfaces.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The identification code generation uses periodic or random physical operations that are inherently unpredictable. This periodic/random action ensures that even if malware attempts to intercept or predict identification codes, the physical randomness makes detection and prevention of stealthy attacks significantly more difficult while maintaining device compatibility.

Inventive Principle:
Principle #19Periodic action

3Adaptability or versatility

If software-based identification management is used, then flexibility is improved, but security risk increases due to firmware vulnerability

Engineering Contradiction:
ImproveflexibilityVSAvoidfirmware vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent replaces software-based identification management with hardware-based physical operations. Instead of using firmware to generate and manage identification codes, the system uses physical hardware characteristics and operations, eliminating the firmware vulnerability that allows malware like BadUSB to steal identification codes while maintaining the flexibility needed for IoT device management.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentEP3070875B1Method of physical chip identification for networks of electronic appliance
Publication Date: 2019.05.01 WATANABE HIROSHI
  • EP3070875B1 patent drawingFigure 1
  • EP3070875B1 patent drawingFigure 2
  • EP3070875B1 patent drawingFigure 3

AI summary

A technology precluding attacks through peripheral devices (410, 420, 430, 440, 450) thefts to a network of electronic appliance, by utilizing physical chip identification devices (60, 21, 22), is disclosed. The electronic appliance in the network are divided into the peripheral devices (410, 420, 430, 440, 450) and stem servers (400, 1400, 2400, 3400) managing registration information of the peripheral devices (410, 420, 430, 440, 450), wherein the stem servers (400, 1400, 2400, 3400) serve as central control using software, and the peripheral devices (410, 420, 430, 440, 450) are managed at device-level by having physical chip identification devices (60, 21, 22), thus the security of the whole network is efficiently reinforced.