End-to-End Service Authentication via Credential Authority

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current oneM2M specifications only provide for hop-by-hop authentication, which limits the ability of entities to authenticate each other end-to-end, leading to potential impersonation by intermediate nodes and increased operational overhead due to hop-by-hop security mechanisms.

Innovation Solution

Implementing an End-to-End (E2E) authentication process that involves Service Enablement and Security Configuration, Security Credential Provisioning, Third-party Credential Requisition, and End-to-End Authentication, using direct or delegated modes to establish secure associations between entities across multiple service layers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hop-by-hop authentication is used, then security association can be established between adjacent entities, but end-to-end authentication capability is limited and intermediate nodes can impersonate

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidauthentication mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a Credential Authority (CA) as an intermediary entity that issues End-to-End credentials to Application Entities (AEs). This CA acts as a trusted third party that enables AEs to authenticate each other directly across multiple hops without requiring security associations at every intermediate node, thus resolving the contradiction between authentication reliability and system complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication mechanism is segmented into two independent parts: hop-by-hop authentication for local communication and end-to-end authentication for cross-hop verification. The end-to-end credential is divided into components that can be independently issued, stored, and verified, allowing the system to achieve both local security and global authentication without overwhelming complexity

Inventive Principle:
Principle #1Segmentation

2Reliability

If hop-by-hop security mechanisms are implemented, then security association can be established at each step, but operational overhead increases

Engineering Contradiction:
Improvesecurity protectionVSAvoidoperational efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent merges the security functions by combining hop-by-hop authentication with end-to-end authentication in a single integrated mechanism. The end-to-end credential contains all necessary information for both local and remote authentication, eliminating the need for separate security associations at each hop and reducing operational overhead while maintaining comprehensive security protection

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

Instead of creating new security associations at each hop, the system copies and reuses the end-to-end credential across multiple hops. The credential is validated at each intermediate node without requiring re-establishment of security contexts, significantly reducing the operational overhead associated with traditional hop-by-hop mechanisms

Inventive Principle:
Principle #26Copying

3Reliability

If direct end-to-end authentication is enabled, then access control and impersonation prevention improve, but credential distribution and provisioning complexity increases

Engineering Contradiction:
Improveaccess control accuracyVSAvoidsystem configuration ease
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The system implements self-service through automated credential provisioning where Application Entities automatically obtain end-to-end credentials from the Credential Authority without manual configuration. The CA automatically issues credentials based on entity identification, and the credential validation process is automated at each node, eliminating complex manual setup while ensuring accurate access control

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

End-to-end credentials are issued in advance before the actual authentication process. The Credential Authority pre-issues credentials to Application Entities during registration or initialization, so that when authentication is needed, the credentials are already available and can be immediately used for both hop-by-hop and end-to-end verification without adding configuration complexity

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10601594B2End-to-end service layer authentication
Publication Date: 2020.03.24 IPLA HLDG INC
  • US10601594B2 patent drawing
  • US10601594B2 patent drawing
  • US10601594B2 patent drawing

AI summary

A variety of mechanisms to perform End-to-End authentication between entities having diverse capabilities (E.g. processing, memory, etc.) and with no prior security associations are used. Security provisioning and configuration process is done such that appropriate security credentials, functions, scope and parameters may be provisioned to an Entity. Mechanisms to distribute the security credentials to other entities which could then use the credentials to perform an End-to-End authentication at the Service Layer or the Session Layer and using Direct or Delegated modes are developed.