IoT Device Authentication via Pre-shared Keys and Secure Elements
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication methods for IoT devices connecting to cellular networks are cumbersome, expensive, and vulnerable to attacks, particularly due to the reliance on manual interactions, SMS-based systems, and the high cost of Certificate Authority (CA) signed certificates.
Innovation Solution
A system and method for secure authentication using pre-shared server and client keys to establish identities and generate session keys for secure data exchange between IoT devices and network operator servers, leveraging cryptographic techniques and established SIM management to facilitate secure token-based mutual authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual username/password authentication is used for IoT devices, then application-level security is improved, but operational complexity and cost increase due to cumbersome provisioning and OTA time requirements
Solution Approach 1:
The patent applies preliminary action by pre-provisioning authentication credentials (username and password) in the IoT device during manufacturing or initial setup, stored in a secure element. This eliminates the need for manual username/password provisioning at deployment time, allowing the device to automatically authenticate with the application server without requiring OTA intervention or manual configuration.
Solution Approach 2:
The patent implements self-service by enabling the IoT device to autonomously perform authentication using pre-stored credentials. The device automatically extracts the username from its identity and retrieves the corresponding password from its secure storage, then uses these credentials to authenticate with the application server without requiring manual intervention, reducing operational complexity.
2Reliability
If CA signed certificates are used for mutual authentication, then security is improved, but cost increases due to the high price of certificates
Solution Approach 1:
The patent applies this principle by replacing expensive CA-signed certificates with simpler, cheaper authentication credentials (username-password pairs) stored in the device's secure element. These credentials provide sufficient security for the application layer without requiring costly certificate infrastructure, thereby reducing per-device authentication costs while maintaining adequate security levels.
Solution Approach 2:
The patent uses copying by storing the password in the device's secure element during manufacturing or initial provisioning. This pre-copied credential is then reused for authentication without requiring expensive real-time certificate verification, eliminating the need for CA infrastructure and reducing authentication costs while maintaining security.
3Reliability
If SMS-based authentication systems are used, then device identity verification is improved, but vulnerability to attacks and operational complexity increase
Solution Approach 1:
The patent extracts the authentication mechanism from vulnerable SMS-based systems and relocates it to the device's secure element. By storing credentials locally in a hardware-protected environment rather than relying on SMS transmission, the system eliminates vulnerabilities associated with SMS interception and manipulation while maintaining robust device identity verification.
Solution Approach 2:
The patent applies preliminary action by pre-provisioning authentication credentials in the secure element during manufacturing or initial setup, eliminating the need for SMS-based authentication at runtime. This pre-established secure credential storage removes the device from vulnerable SMS authentication flows while maintaining strong identity verification capabilities.
4Reliability
If traditional authentication protocols are used, then network connectivity is established, but data consumption and authentication time increase
Solution Approach 1:
The patent applies preliminary action by pre-provisioning authentication credentials in the device during manufacturing or initial setup. This allows the device to immediately authenticate with the application server using pre-stored credentials without requiring time-consuming credential distribution or manual configuration, thereby reducing authentication time while maintaining network connectivity.
Solution Approach 2:
The patent implements self-service by enabling the device to autonomously perform authentication using pre-stored credentials in its secure element. The device automatically extracts the username from its identity and retrieves the corresponding password, then uses these credentials to authenticate with the application server without requiring manual intervention or extended OTA time, reducing authentication time and data consumption.
Data Source
AI summary
A computer-implemented system and method for secure authentication of IoT devices are disclosed. The method for secure authentication of IoT devices comprises establishing a network connection with a network operator server via a control channel, establishing identity of the network operator server using a pre-shared server key from one or more of pre-shared server keys, establishing identity of the IoT device using a pre-shared client key from one or more of pre-shared client keys and cryptographically generating a session key for a network session to allow secure data exchange between the network operator server and the IoT device. The cryptographically generated session key is used for securely authenticating application running on the authenticated IoT device.


