End-to-End Service Authentication via Credential Authority
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current oneM2M specifications only provide for hop-by-hop authentication, which limits the ability of entities to authenticate each other end-to-end, leading to potential impersonation by intermediate nodes and increased operational overhead due to hop-by-hop security mechanisms.
Innovation Solution
Implementing an End-to-End (E2E) authentication process that involves Service Enablement and Security Configuration, Security Credential Provisioning, Third-party Credential Requisition, and End-to-End Authentication, using direct or delegated modes to establish secure associations between entities across multiple service layers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If hop-by-hop authentication is used, then security association can be established between adjacent entities, but end-to-end authentication capability is limited and intermediate nodes can impersonate
Solution Approach 1:
The patent introduces a Credential Authority (CA) as an intermediary entity that issues End-to-End credentials to Application Entities (AEs). This CA acts as a trusted third party that enables AEs to authenticate each other directly across multiple hops without requiring security associations at every intermediate node, thus resolving the contradiction between authentication reliability and system complexity
Solution Approach 2:
The authentication mechanism is segmented into two independent parts: hop-by-hop authentication for local communication and end-to-end authentication for cross-hop verification. The end-to-end credential is divided into components that can be independently issued, stored, and verified, allowing the system to achieve both local security and global authentication without overwhelming complexity
2Reliability
If hop-by-hop security mechanisms are implemented, then security association can be established at each step, but operational overhead increases
Solution Approach 1:
The patent merges the security functions by combining hop-by-hop authentication with end-to-end authentication in a single integrated mechanism. The end-to-end credential contains all necessary information for both local and remote authentication, eliminating the need for separate security associations at each hop and reducing operational overhead while maintaining comprehensive security protection
Solution Approach 2:
Instead of creating new security associations at each hop, the system copies and reuses the end-to-end credential across multiple hops. The credential is validated at each intermediate node without requiring re-establishment of security contexts, significantly reducing the operational overhead associated with traditional hop-by-hop mechanisms
3Reliability
If direct end-to-end authentication is enabled, then access control and impersonation prevention improve, but credential distribution and provisioning complexity increases
Solution Approach 1:
The system implements self-service through automated credential provisioning where Application Entities automatically obtain end-to-end credentials from the Credential Authority without manual configuration. The CA automatically issues credentials based on entity identification, and the credential validation process is automated at each node, eliminating complex manual setup while ensuring accurate access control
Solution Approach 2:
End-to-end credentials are issued in advance before the actual authentication process. The Credential Authority pre-issues credentials to Application Entities during registration or initialization, so that when authentication is needed, the credentials are already available and can be immediately used for both hop-by-hop and end-to-end verification without adding configuration complexity
Data Source
AI summary
A variety of mechanisms to perform End-to-End authentication between entities having diverse capabilities (E.g. processing, memory, etc.) and with no prior security associations are used. Security provisioning and configuration process is done such that appropriate security credentials, functions, scope and parameters may be provisioned to an Entity. Mechanisms to distribute the security credentials to other entities which could then use the credentials to perform an End-to-End authentication at the Service Layer or the Session Layer and using Direct or Delegated modes are developed.


