Dynamic Context Tokens for Replay-Resistant IoT Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication methods in IoT and M2M networks rely on static keys, which are vulnerable to replay attacks and require complex key management, and human-generated passwords are insecure, necessitating improved, autonomous, and dynamic authentication mechanisms.

Innovation Solution

A method using contextual information and timestamps to generate dynamic authentication tokens, resistant to replay attacks and brute-force attacks, eliminating the need for user-generated passwords.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If static keys are used for authentication, then authentication can be performed, but the system becomes vulnerable to replay attacks and requires complex key management

Engineering Contradiction:
Improveauthentication securityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies dynamics by transitioning from static authentication keys to dynamic authentication tokens. Each token is generated based on contextual information (device identifiers, network information, location data, timestamp) that changes with each authentication event, making the credentials dynamic rather than static. This resolves the contradiction by providing secure authentication without requiring complex key management, as tokens are automatically generated from contextual data.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes parameters by using multiple varying contextual parameters (device identifiers, network information, location data, timestamp) to generate authentication tokens. Instead of relying on a single static key, the system combines multiple parameters that naturally change over time and context, thereby improving security while avoiding complex key management through automatic parameter-based token generation.

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If human-generated passwords are used for authentication, then users can authenticate themselves, but security is compromised due to weak password choices

Engineering Contradiction:
Improveuser authentication capabilityVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies self-service by enabling devices to automatically generate their own authentication tokens using their inherent contextual information (device identifiers, network information, location data). Instead of relying on human users to create and manage passwords, the system allows devices to self-authenticate using dynamically generated tokens, thereby maintaining ease of operation while significantly improving security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces an intermediary mechanism - the authentication token - that mediates between the user/device and the authentication system. Rather than directly using weak human-generated passwords, the system uses contextual information as an intermediary to generate secure tokens, thereby maintaining user-friendly authentication while eliminating password-related security vulnerabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If dynamic authentication tokens are generated using contextual information, then security is enhanced against replay attacks, but computational overhead increases

Engineering Contradiction:
Improveauthentication securityVSAvoidcomputational energy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent applies universality by using contextual information that serves multiple purposes: device identification, network registration verification, location tracking, and authentication token generation. By making the contextual data multi-functional, the system avoids the need for separate dedicated authentication credentials, thereby reducing computational overhead while maintaining enhanced security against replay attacks.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12463954B2Authentication of an entity
Publication Date: 2025.11.04 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US12463954B2 patent drawing
  • US12463954B2 patent drawing
  • US12463954B2 patent drawing

AI summary

There is provided a method performed by a first entity of a network. Contextual information for the first entity and a timestamp for the contextual information is acquired (102). An authentication token is generated (104) using the acquired contextual information. Transmission of an authentication request message is initiated (106) towards a second entity of the network requesting authentication of the first entity with the second entity. The authentication request message comprises the generated authentication token and the timestamp for use in the authentication. An authentication response message indicative of whether authentication of the first entity with the second entity is successful or unsuccessful received (108).