Dynamic Domain Key Exchange for IoT Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authentication methods for IoT devices are difficult to provision, administer, and maintain, especially in decentralized and dynamic environments, and centralized management is not viable for billions of heterogeneous systems, requiring a decentralized, distributed, and dynamic authentication mechanism that ensures data integrity and privacy.
Innovation Solution
The proposed method uses autonomous domains with a Domain Key Agent and Domain Key Broker to generate a group public key and multiple member private keys for dynamic enrollment, leveraging Public Key Infrastructure (PKI) and blockchain technology for secure communication between IoT devices, allowing for dynamic key management and privacy protection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If centralized management of IoT devices is implemented, then authentication and key management can be simplified, but it becomes unviable for billions of heterogeneous systems
Solution Approach 1:
The patent segments the centralized authentication system into distributed autonomous domains. Each domain operates independently with its own key management, eliminating the need for a single centralized authority while maintaining authentication capabilities across billions of devices. This segmentation resolves the contradiction by enabling scalability without sacrificing ease of operation.
Solution Approach 2:
The patent introduces domain key agents and domain key brokers as intermediary components that facilitate authentication between devices without requiring direct centralized management. These intermediaries enable simplified authentication operations while supporting large-scale heterogeneous systems through decentralized domain-based architecture.
2Adaptability or versatility
If dynamic key enrollment is implemented for decentralized domains, then scalability is improved, but key management complexity increases
Solution Approach 1:
The patent implements dynamic key enrollment where domain key agents can dynamically join and leave autonomous domains. Keys are generated and distributed on-demand rather than pre-configured, enabling the system to adapt to changing network conditions and device additions without manual intervention, thus improving scalability while managing complexity through automation.
Solution Approach 2:
The patent enables self-service key management where domain key agents autonomously discover domains, generate their own keys, and enroll themselves without centralized provisioning. This self-service mechanism reduces key management complexity by eliminating manual configuration while maintaining dynamic adaptability for decentralized environments.
3Reliability
If group PKI is used for domain-based authentication, then data integrity and privacy are ensured, but provisioning and maintenance difficulty increases
Solution Approach 1:
The patent segments the PKI system into domain-specific group key hierarchies rather than using a single centralized PKI. Each autonomous domain maintains its own group key structure, which ensures data integrity and privacy within the domain while simplifying provisioning and maintenance by limiting the scope of key management to individual domains rather than the entire IoT ecosystem.
Solution Approach 2:
The patent introduces domain key agents as intermediaries that handle the complex PKI operations within each domain. These agents manage key generation, distribution, and revocation locally, ensuring data integrity through cryptographic verification while reducing the provisioning and maintenance burden by confining complex PKI operations to domain-level intermediaries rather than requiring system-wide management.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method of dynamically generating a domain based public group key and private member keys using a domain key agent, a domain key service of a domain key broker, and a domain key distribution center. The method includes: sending to the domain key service of a domain key broker a request for a private member key for the domain, wherein the request includes proof of possession of a vehicle private key associated with a vehicle certificate and a vehicle public key; receiving from the domain key service a private member key and a public group key; sending a message digitally signed using the member private key; verifying the digital signature on the received message using the public group key; and dynamically renewing the public group key and private member key based on the domain.