Cryptographic Certificate Authentication for Segmented IoT Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

IoT networks face security challenges due to their dynamic and resource-constrained nature, making them vulnerable to attacks like counterfeiting, eavesdropping, and identity spoofing, with centralized security systems creating a single point of failure and high-end security protocols incurring large overheads.

Innovation Solution

A decentralized identity (DID) system using cryptographic certificates and distributed ledger technology for device authentication, enabling continuous multi-factor authentication (CMFA) and dynamic policy enforcement, supporting macro- and micro-segmentation, and avoiding a single point of failure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If centralized security service providers are used for authentication and key exchange, then security management is simplified, but a single point of failure is created making the system vulnerable to DoS and DDOS attacks

Engineering Contradiction:
Improvesecurity managementVSAvoidvulnerability to DoS attacks
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent divides the centralized security provider into multiple distributed security nodes that operate autonomously. Each node maintains its own security functions (authentication, key exchange) without requiring a central coordinator, thereby eliminating the single point of failure while preserving security management capabilities through distributed consensus mechanisms.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a blockchain-based distributed ledger as an intermediary that enables secure communication and trust between autonomous security nodes. This intermediary allows nodes to verify each other's identities and maintain security functions without direct centralized control, resolving the contradiction between operational simplicity and attack vulnerability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If high-end security protocols like elliptic curve cryptography are implemented, then security against counterfeiting and eavesdropping is improved, but computational overhead and energy consumption increase on resource-constrained devices

Engineering Contradiction:
Improvesecurity against counterfeitingVSAvoidenergy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent dynamically adjusts cryptographic parameter strength based on device capabilities and threat models. Instead of uniformly applying high-end cryptography to all devices, the system selects appropriate cryptographic algorithms and key lengths tailored to each device's computational resources, thereby maintaining security while minimizing energy consumption on resource-constrained IoT devices.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent applies security measures selectively rather than universally. Critical authentication functions use strong cryptography, while non-critical operations use lighter-weight algorithms. This partial application of security protocols reduces overall computational overhead and energy consumption while maintaining adequate protection for essential functions.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If complex security algorithms are used for digital signatures and key exchange, then authentication security is enhanced, but device complexity and operational overhead increase

Engineering Contradiction:
Improveauthentication securityVSAvoidsecurity protocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a blockchain-based distributed ledger as an intermediary that simplifies complex authentication operations. The ledger stores verified identities and cryptographic proofs, allowing devices to authenticate each other by querying pre-computed data rather than executing complex real-time cryptographic protocols, thereby reducing device complexity while maintaining authentication security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent performs complex cryptographic operations in advance during device onboarding and initial authentication. Once verified, devices receive simplified tokens or credentials that can be used for subsequent communications without repeating the complex authentication process, thereby reducing operational overhead while maintaining security.

Inventive Principle:
Principle #10Preliminary action

4Adaptability or versatility

If IoT devices operate in physically unprotected environments, then deployment flexibility is improved, but vulnerability to security attacks such as eavesdropping and identity spoofing increases

Engineering Contradiction:
Improvedeployment flexibilityVSAvoidvulnerability to eavesdropping
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent replaces physical security measures with cryptographic and blockchain-based digital security mechanisms. Instead of relying on physical protection for device authentication and data integrity, the system uses distributed cryptographic protocols and immutable ledgers to prevent eavesdropping and identity spoofing, thereby enabling flexible deployment in unprotected environments while maintaining security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS12425391B2Authentication of device in network using cryptographic certificate
Publication Date: 2025.09.23 ANDRO COMPUTATIONAL SOLUTIONS LLC
  • US12425391B2 patent drawing
  • US12425391B2 patent drawing
  • US12425391B2 patent drawing

AI summary

Embodiments of the disclosure provide distributed authentication with network segmentation and dynamic authorization for networks. The system may include a device within a network of devices. An identifier is within the device and includes a cryptographic certificate. The device is configured to transmit the identifier to an authenticator as a security proof. The authenticator is configured to disable the device from performing at least one operation within the network before verifying an identity of the device via the identifier.