Group Key Authentication for IoT Network Load Reduction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication network authentication mechanisms consume significant network resources and server computing resources when multiple terminal nodes with similar behavioral characteristics attempt to access the network simultaneously, leading to increased network load and decreased availability of services, particularly in the Internet of Things (IoT) context.

Innovation Solution

A method for one-time group authentication, where a representative node generates a group key from sub-key information of multiple terminal nodes and performs a group authentication with the network side, allowing multiple nodes to be authenticated simultaneously, thereby reducing resource consumption and maintaining logical relevance among nodes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If one-to-one authentication mode is used for each terminal node, then individual node authentication can be completed, but network resource consumption and server computing resource consumption increase significantly when large numbers of nodes access simultaneously

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidnetwork resource consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

Multiple individual authentication processes are merged into a single group authentication process. The patent combines authentication requests from multiple terminal nodes into one group authentication request, which is processed by the network side as a single operation, thereby reducing redundant signaling interactions and resource consumption while maintaining authentication reliability for each node.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The group authentication mechanism serves multiple terminal nodes simultaneously with a single authentication process. The authentication request and response mechanisms are designed to handle multiple nodes universally, allowing the same authentication protocol to serve both individual and group authentication needs without requiring separate dedicated processes for each node.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If one-to-one authentication is performed for each terminal node, then individual identity verification is achieved, but network load increases and service availability decreases when many nodes access simultaneously

Engineering Contradiction:
Improveidentity verification accuracyVSAvoidservice availability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent merges multiple identity verification operations into a single group authentication operation. By combining the authentication requests and processing them collectively, the system maintains accurate identity verification for each node while significantly reducing the cumulative network load and improving overall service availability during simultaneous access scenarios.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If traditional authentication mechanisms are used, then security requirements are met, but signaling interaction consumes excessive network resources and server computing resources

Engineering Contradiction:
ImprovesecurityVSAvoidsignaling interaction complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent reduces signaling interaction complexity by merging multiple separate authentication signaling exchanges into a single group authentication signaling interaction. This approach maintains the necessary security verification steps while eliminating redundant signaling messages that would otherwise be required for each individual node, thereby reducing overall network resource consumption and server processing burden.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP2566204B1Authentication method and device, authentication centre and system
Publication Date: 2021.01.13 CHINA MOBILE COMM GRP CO LTD
  • EP2566204B1 patent drawingFigure 1~2
  • EP2566204B1 patent drawingFigure 3~4
  • EP2566204B1 patent drawingFigure 5

AI summary

An authentication method and device, authentication centre and system are provided. The method comprises: receiving at least one access request and obtaining sub-key information from the access request; generating a group key according to the obtained sub-key information, and interacting with the network side according to the group key to perform the group authentication. The solution can solve the problem that the one-to-one authentication causes network load in the present art, implement the authentication of multiple nodes at one time, reduce network resources and the network load of the server, and can be appropriate for the authentication of the terminal nodes in the internet of things, and can greatly improve the availability of services in the internet of things.