Distributed Trust Validation for IoT Authentication Scaling
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security systems, particularly those using public key infrastructure (PKI), face challenges in scaling with the increasing number of devices, are vulnerable to single-point failures, and struggle with authenticating large numbers of IoT devices, as well as being susceptible to hacking and eavesdropping.
Innovation Solution
A system that validates entities by associating trust levels with entity details, using multiple communication channels and dynamic recalculations of trust based on events and timers, and employs secret sharing to secure communication channels without exposing secrets over networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a certificate authority (RA) is used to authenticate devices in a PKI system, then device authentication is provided, but the system cannot scale to large numbers of IoT devices due to increased load on the RA
Solution Approach 1:
The patent segments the authentication function by introducing edge devices that perform local authentication of IoT devices without requiring direct communication with the central RA. The RA only needs to authenticate edge devices, while edge devices handle authentication of multiple IoT devices locally, enabling system scaling.
Solution Approach 2:
The patent introduces edge devices as intermediary components between the central RA and IoT devices. These edge devices act as local authentication authorities, reducing the load on the central RA while maintaining authentication reliability through trusted intermediary nodes.
2Ease of operation
If a central RA issues digital certificates to all devices, then authentication is centralized and manageable, but the RA becomes a single point of failure that can compromise entire system security
Solution Approach 1:
The patent segments the authentication authority function across multiple edge devices rather than concentrating it solely in the central RA. Each edge device can independently authenticate IoT devices, distributing trust and eliminating the single point of failure while maintaining centralized management through the RA's oversight of edge devices.
Solution Approach 2:
The patent changes the trust model parameter from centralized certificate issuance to distributed trust validation. Edge devices maintain local authentication capabilities and can validate IoT devices without requiring real-time communication with the central RA, changing the system from centralized to distributed trust architecture.
3Reliability
If encryption keys are stored centrally or on individual devices, then secure communication is enabled, but keys are vulnerable to theft and eavesdropping attacks
Solution Approach 1:
The patent segments encryption keys into multiple shares distributed across different devices (edge devices and IoT devices). No single device holds the complete key, making it impossible for attackers to compromise security by stealing from a single device. The key is reconstructed only when sufficient shares are combined during authentication.
Solution Approach 2:
The patent introduces edge devices as intermediaries that facilitate secure key sharing between the central system and IoT devices. The edge devices securely distribute key shares and manage the secret sharing protocol, preventing direct exposure of keys over vulnerable network channels while enabling secure communication.
Data Source
AI summary
A system and method for validating an entity may include obtaining by at least a first system, a set of entity details related to the entity; associating with the entity, by the first system, a first trust level based on at least some of the entity details; and validating the entity based on the first trust level. A system and method for validating an entity may include providing at least one of first and second values to a respective at least one of first and second devices; providing the entity, by at least one of the first and second devices, with the at least one of first and second values; and using the at least one of first and second values, by the entity, to identify the entity to an identifying entity.


