Group Trust Model for 5G IoT Security Key Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

IoT devices in 5G systems face resource depletion and increased overhead due to frequent establishment of new security keys each time they wake up to transmit data, leading to battery depletion and high load on access points.

Innovation Solution

Implementing a trust model where IoT devices are organized into groups, maintaining security keys instead of discarding them after each transmission, allowing for an 'always on' connection between devices and access points, reducing the need for frequent key establishment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If new security keys are established each time an IoT device wakes up to transmit data, then security is maintained, but device battery is depleted and access point load increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice battery
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent applies preliminary action by pre-establishing security keys during device initialization and registration phases. These pre-configured security credentials are stored in the IoT device's memory, eliminating the need for repeated key establishment during operational wake cycles. This preliminary setup reduces subsequent energy consumption while maintaining security requirements.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements universality by creating a group-based security model where a single set of security keys serves multiple IoT devices simultaneously. Instead of each device requiring individual key pairs, a group security context is established that can be shared across devices, reducing the overall key management overhead and energy consumption for security operations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If new security keys are established each time an IoT device wakes up to transmit data, then security is maintained, but access point resource load increases

Engineering Contradiction:
ImprovesecurityVSAvoidaccess point throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The access point benefits from preliminary action by receiving and storing security context information during initial device registration. This pre-configured security data is cached in the access point's memory, allowing rapid authentication and data transmission without requiring computationally intensive key establishment operations during each device wake cycle, thereby improving overall throughput.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent merges security management for multiple IoT devices into a unified group security context. Instead of managing individual security relationships with each device, the access point maintains a consolidated security context that covers multiple devices, reducing memory usage and processing overhead while maintaining security enforcement.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If security keys are discarded after each transmission, then security is compromised less, but key establishment overhead increases

Engineering Contradiction:
ImprovesecurityVSAvoidkey establishment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies partial action by maintaining security keys for a limited duration or scope rather than discarding them completely. Security contexts are retained for the duration of device groups or specific operational sessions, providing a balance between security compromise risk and operational efficiency. This partial retention eliminates repeated key establishment while limiting exposure through controlled validity periods.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10219152B2Security architecture and solution for handling internet of things devices in a fifth generation system
Publication Date: 2019.02.26 FUTUREWEI TECHNOLOGIES INC
  • US10219152B2 patent drawing
  • US10219152B2 patent drawing
  • US10219152B2 patent drawing

AI summary

A method of establishing a group trust relationship in an Internet of Things (IoT) system using a first IoT device within a group of IoT devices is provided. The method includes generating, by the first IoT device, a first set of keys corresponding to the first IoT device, deriving, by the first IoT device, a group set of keys corresponding the group of IoT devices, and discarding the first set of keys and storing the group set of keys after the first IoT device transmits data toward a base station and goes idle, wherein the group set of keys is used by each IoT device within the group of IoT devices for subsequent transmissions of data to the base station.