Hardware Security Module for IoT Device Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

IoT devices connected to public networks are vulnerable to malicious attacks, necessitating robust authentication mechanisms to ensure security and authenticity.

Innovation Solution

A device authentication system utilizing a hardware security module (HSM) to generate pairs of public and private keys, which are used to create device certificates through an IoT cloud, enhancing security by encrypting and decrypting certificate generation requests and storing private keys and certificates securely.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If IoT devices are connected to public networks for data transmission and cloud services, then the functionality and connectivity of the IoT system is improved, but the devices become vulnerable to malicious attacks and security threats

Engineering Contradiction:
ImproveconnectivityVSAvoidsecurity vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a Hardware Security Module (HSM) as an intermediary component between the IoT device and the network environment. The HSM acts as a dedicated security processor that handles cryptographic operations, key management, and authentication, isolating these critical security functions from the main IoT device processor and network interface. This intermediary structure allows the device to maintain network connectivity while the HSM provides a secure boundary that protects against attacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system is segmented into distinct functional components: the IoT device itself, the HSM for security operations, and the cloud server for authentication. By dividing the authentication and security management functions into a separate HSM module and cloud-based authentication server, the patent creates a distributed security architecture that reduces the attack surface on individual devices while maintaining overall system connectivity.

Inventive Principle:
Principle #1Segmentation

2Reliability

If security measures such as authentication mechanisms are implemented in IoT devices, then the security and authenticity of devices are improved, but the device complexity and resource consumption increase

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The HSM serves as an intermediary that offloads complex cryptographic operations and key management tasks from the main IoT device processor. By delegating these computationally intensive security functions to a specialized HSM module, the main device can maintain simpler architecture while still achieving robust authentication security through the HSM's dedicated security processing capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The HSM is designed as a self-contained security module that autonomously performs key generation, storage, and cryptographic operations without requiring direct intervention from the main device processor. The module manages its own security state and operations independently, reducing the complexity burden on the overall IoT device while maintaining high security standards through specialized self-managing security logic.

Inventive Principle:
Principle #25Self-service

3Reliability

If private keys and certificates are stored in IoT devices for authentication, then the authentication capability is improved, but the risk of key compromise and security breaches increases

Engineering Contradiction:
Improveauthentication capabilityVSAvoidkey compromise risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The HSM acts as an intermediary security vault that stores private keys and certificates in a protected environment isolated from the main device memory and processor. This intermediary storage structure allows authentication capabilities to function normally while physically and logically separating the sensitive cryptographic materials from potential attack vectors in the main device, thereby reducing the risk of key compromise.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the sensitive key storage function from the main IoT device into a separate HSM module. By taking out the private key storage responsibility from the general-purpose device and placing it in a dedicated security module with enhanced physical and logical protection, the system maintains authentication capability while minimizing the attack surface for potential key compromise.

Inventive Principle:
Principle #2Taking out (Extraction)

4Reliability

If encryption is used for certificate generation requests to enhance security, then the security against attacks is improved, but the processing time and computational overhead increase

Engineering Contradiction:
Improverequest securityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent replaces general-purpose software-based encryption operations with hardware-accelerated cryptographic processing in the HSM. By substituting software cryptographic implementations with dedicated hardware cryptographic engines, the system achieves stronger security through hardware-level protection while simultaneously reducing processing time through optimized hardware encryption algorithms that operate faster than software equivalents.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11336635B2Systems and methods for authenticating device through IoT cloud using hardware security module
Publication Date: 2022.05.17 SIOT
  • US11336635B2 patent drawing
  • US11336635B2 patent drawing
  • US11336635B2 patent drawing

AI summary

Provided are a system and method for authenticating a device through an Internet of Things (IoT) cloud by using a hardware security module. The system includes an IoT device connectable to a cloud which provides an IoT service and a security module connected to the IoT device and configured to generate a pair of public and private keys for authenticating the IoT device. The IoT device transmits a certificate generation request including the public key and a device identifier to an authentication server through the cloud in order to generate a device certificate.