Distributed Remote Attestation for Mobile IoT Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing remote attestation methods for IoT devices are inefficient in large-scale networks with limited resources and mobility, leading to high communication loads and inability to perform real-time monitoring due to reliance on centralized communication and the need for accurate device state information.

Innovation Solution

Each node performs self-remote attestation and monitors attestation results using a Bloom filter and consensus protocols, allowing for efficient data structure collection and network state estimation without requiring accurate device state information, reducing communication load and enabling mobility.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If centralized communication is used for remote attestation in IoT networks, then verification of device integrity can be performed, but communication load increases and real-time monitoring becomes difficult in large-scale networks

Engineering Contradiction:
Improvedevice integrity verificationVSAvoidcommunication load
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent divides the centralized verification process into distributed peer-to-peer verification among nodes. Each node performs self-remote attestation and shares results with neighbors, eliminating the need for a central verifier and reducing communication overhead by localizing verification tasks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Each node performs self-remote attestation independently, generating and verifying its own attestation results. This self-service approach eliminates dependency on centralized verification infrastructure, reducing communication load while maintaining verification reliability.

Inventive Principle:
Principle #25Self-service

2Loss of information

If accurate device state information is collected from all nodes, then comprehensive network monitoring is achieved, but communication overhead and processing requirements increase significantly

Engineering Contradiction:
Improvenetwork state informationVSAvoiddata collection and processing
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent applies local quality by having each node maintain and share only locally relevant attestation information with its immediate neighbors rather than collecting comprehensive global state data. This localized information sharing reduces communication overhead while providing sufficient monitoring coverage through distributed consensus.

Inventive Principle:
Principle #3Local quality

3Reliability

If traditional remote attestation protocols are used, then device integrity can be verified, but the system cannot efficiently handle device mobility and dynamic network topology changes

Engineering Contradiction:
Improveintegrity verificationVSAvoidmobility support
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic verification by allowing nodes to perform self-remote attestation and share results with neighboring nodes in real-time. This dynamic peer-to-peer verification mechanism adapts to topology changes and device mobility without requiring centralized coordination, maintaining verification reliability while supporting network dynamics.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12425860B2Apparatus and method for performing remote attestation by taking into account mobility
Publication Date: 2025.09.23 ELECTRONICS & TELECOMM RES INST
  • US12425860B2 patent drawing
  • US12425860B2 patent drawing
  • US12425860B2 patent drawing

AI summary

Provided are an apparatus and method for performing remote attestation by taking into account mobility. The method includes obtaining, by each node constituting a network, a remote attestation result value by performing self-remote attestation, obtaining, by each of the nodes, remote attestation result values from the other nodes by broadcasting the obtained remote attestation result value to at least one neighboring node, and monitoring, by each of the nodes, remote attestation of each of the nodes on the basis of the obtained remote attestation result values of the nodes.