Secure Device Communication via DICE-RIoT Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current communication systems between network management devices and network attached devices are vulnerable to security threats such as man-in-the-middle attacks, which can lead to unauthorized access and safety concerns, particularly in wireless communication mechanisms.

Innovation Solution

Implementing a DICE-RIoT protocol that uses public and private keys for secure encryption and verification, allowing devices to authenticate each other through NFC or other short-range wireless communication methods, ensuring the integrity and authenticity of messages exchanged between network management devices and network attached devices without requiring additional hardware or circuitry.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If wireless communication mechanisms are used for device pairing and control, then ease of operation is improved, but security vulnerability increases due to man-in-the-middle attacks

Engineering Contradiction:
Improvewireless communicationVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary authentication actions before establishing wireless communication. The network attached device and network management device exchange and verify cryptographic credentials (public keys, certificates) in advance through a secure channel (NFC or wired connection), ensuring that subsequent wireless communications are protected against man-in-the-middle attacks.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces cryptographic intermediaries (digital certificates, public keys) that mediate the authentication process between devices. These cryptographic elements act as trusted intermediaries that verify the identity of communicating parties, preventing unauthorized interception and manipulation of wireless communications.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If additional hardware or circuitry is added to enhance security, then security reliability is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidhardware complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes existing hardware components multi-functional by enabling them to perform both traditional communication functions and cryptographic authentication functions. The same processor and memory that handle data communication also execute cryptographic algorithms, eliminating the need for dedicated security hardware while maintaining security reliability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system implements self-service security where the devices automatically perform authentication and encryption operations without requiring additional user actions or specialized hardware. The existing device resources (processor, memory, communication interfaces) are utilized to execute security protocols, making security a self-contained function of the device itself.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12166899B2Secure device communication
Publication Date: 2024.12.10 MICRON TECHNOLOGY INC
  • US12166899B2 patent drawing
  • US12166899B2 patent drawing
  • US12166899B2 patent drawing

AI summary

The present disclosure includes secure device communication. An embodiment includes a processing resource, a memory, and a network management device communication component configured to, send public information to a network attached device communication component, and receive a network attached device public key and an encrypted random string value from the network attached device communication component. The network attached device public key and the random string value are received independent of a type of the network attached device communication component due to the public information. The network management communication component is further configured to decrypt the random string value from the network attached device communication component and send, to the network attached device communication component, a message and a signature to authenticate independent of the type of the network attached device communication component due to the public information.