IoT Device Authentication via Pre-shared Keys and Secure Elements

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication methods for IoT devices connecting to cellular networks are cumbersome, expensive, and vulnerable to attacks, particularly due to the reliance on manual interactions, SMS-based systems, and the high cost of Certificate Authority (CA) signed certificates.

Innovation Solution

A system and method for secure authentication using pre-shared server and client keys to establish identities and generate session keys for secure data exchange between IoT devices and network operator servers, leveraging cryptographic techniques and established SIM management to facilitate secure token-based mutual authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual username/password authentication is used for IoT devices, then application-level security is improved, but operational complexity and cost increase due to cumbersome provisioning and OTA time requirements

Engineering Contradiction:
Improveapplication-level securityVSAvoidauthentication provisioning
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies preliminary action by pre-provisioning authentication credentials (username and password) in the IoT device during manufacturing or initial setup, stored in a secure element. This eliminates the need for manual username/password provisioning at deployment time, allowing the device to automatically authenticate with the application server without requiring OTA intervention or manual configuration.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements self-service by enabling the IoT device to autonomously perform authentication using pre-stored credentials. The device automatically extracts the username from its identity and retrieves the corresponding password from its secure storage, then uses these credentials to authenticate with the application server without requiring manual intervention, reducing operational complexity.

Inventive Principle:
Principle #25Self-service

2Reliability

If CA signed certificates are used for mutual authentication, then security is improved, but cost increases due to the high price of certificates

Engineering Contradiction:
Improvemutual authentication securityVSAvoidauthentication cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent applies this principle by replacing expensive CA-signed certificates with simpler, cheaper authentication credentials (username-password pairs) stored in the device's secure element. These credentials provide sufficient security for the application layer without requiring costly certificate infrastructure, thereby reducing per-device authentication costs while maintaining adequate security levels.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The patent uses copying by storing the password in the device's secure element during manufacturing or initial provisioning. This pre-copied credential is then reused for authentication without requiring expensive real-time certificate verification, eliminating the need for CA infrastructure and reducing authentication costs while maintaining security.

Inventive Principle:
Principle #26Copying

3Reliability

If SMS-based authentication systems are used, then device identity verification is improved, but vulnerability to attacks and operational complexity increase

Engineering Contradiction:
Improvedevice identity verificationVSAvoidvulnerability to attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the authentication mechanism from vulnerable SMS-based systems and relocates it to the device's secure element. By storing credentials locally in a hardware-protected environment rather than relying on SMS transmission, the system eliminates vulnerabilities associated with SMS interception and manipulation while maintaining robust device identity verification.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies preliminary action by pre-provisioning authentication credentials in the secure element during manufacturing or initial setup, eliminating the need for SMS-based authentication at runtime. This pre-established secure credential storage removes the device from vulnerable SMS authentication flows while maintaining strong identity verification capabilities.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If traditional authentication protocols are used, then network connectivity is established, but data consumption and authentication time increase

Engineering Contradiction:
Improvenetwork connectivityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-provisioning authentication credentials in the device during manufacturing or initial setup. This allows the device to immediately authenticate with the application server using pre-stored credentials without requiring time-consuming credential distribution or manual configuration, thereby reducing authentication time while maintaining network connectivity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements self-service by enabling the device to autonomously perform authentication using pre-stored credentials in its secure element. The device automatically extracts the username from its identity and retrieves the corresponding password, then uses these credentials to authenticate with the application server without requiring manual intervention or extended OTA time, reducing authentication time and data consumption.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11582233B2Secure authentication of devices for Internet of Things
Publication Date: 2023.02.14 AERIS COMM INC
  • US11582233B2 patent drawing
  • US11582233B2 patent drawing
  • US11582233B2 patent drawing

AI summary

A computer-implemented system and method for secure authentication of IoT devices are disclosed. The method for secure authentication of IoT devices comprises establishing a network connection with a network operator server via a control channel, establishing identity of the network operator server using a pre-shared server key from one or more of pre-shared server keys, establishing identity of the IoT device using a pre-shared client key from one or more of pre-shared client keys and cryptographically generating a session key for a network session to allow secure data exchange between the network operator server and the IoT device. The cryptographically generated session key is used for securely authenticating application running on the authenticated IoT device.