IoT Authentication Mediation via SIM Intermediary Key Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The secure embedding of authentication information in IoT devices is complex and costly, especially as the number of connected devices increases exponentially, making it challenging to facilitate secure authentication for IoT services over IP networks.

Innovation Solution

An intervening apparatus that mediates the configuration of authentication information between IoT devices and service provider apparatuses over IP networks, using a SIM authentication process to generate and verify keys, thereby enabling secure and cost-effective authentication without sharing sensitive information during manufacturing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If authentication information is securely embedded in each IoT device during manufacturing, then security is improved, but device complexity and manufacturing cost increase

Engineering Contradiction:
Improveauthentication securityVSAvoidmanufacturing process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-configuring authentication information in a SIM card before the IoT device is manufactured. The SIM card is provisioned with authentication credentials in advance, and this pre-configured SIM card is then integrated into the IoT device. This eliminates the need for complex post-manufacturing authentication setup and avoids embedding complex authentication mechanisms directly in the device manufacturing process, thereby maintaining security while reducing manufacturing complexity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses a SIM card as an intermediary component that mediates authentication between the IoT device and the network. Instead of embedding authentication logic and credentials directly in the IoT device, the SIM card serves as a separate, standardized authentication module that can be easily replaced and managed. This intermediary approach simplifies the IoT device design while maintaining robust security through the SIM card's dedicated authentication capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If authentication information is securely embedded in each IoT device, then security is improved, but manufacturing cost increases exponentially with device quantity

Engineering Contradiction:
Improveauthentication securityVSAvoidmanufacturing cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent applies universality by using a standardized SIM card that can serve multiple IoT devices across different manufacturers and service providers. The SIM card is a universal authentication component that can be provisioned with different authentication credentials depending on the service required, eliminating the need for custom authentication mechanisms for each device or manufacturer. This standardization significantly reduces manufacturing costs while maintaining security through proven authentication protocols.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent uses copying by replicating the same SIM card authentication mechanism across all IoT devices. Instead of embedding unique, device-specific authentication logic in each IoT device, the system copies the proven SIM card authentication approach across millions of devices. This allows secure authentication to be achieved through a standardized, mass-producible component rather than custom engineering for each device, thereby reducing costs while maintaining security.

Inventive Principle:
Principle #26Copying

3Reliability

If complex authentication mechanisms are embedded in IoT devices, then security is improved, but ease of operation deteriorates

Engineering Contradiction:
Improveauthentication securityVSAvoidconfiguration simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies self-service by enabling the SIM card to automatically perform authentication operations without requiring user intervention or complex device configuration. The SIM card autonomously manages authentication credentials, generates security tokens, and communicates with network authentication servers. This self-service capability eliminates the need for users to manually configure complex authentication parameters, thereby maintaining high security while ensuring ease of operation.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11943213B2Device and method for mediating configuration of authentication information
Publication Date: 2024.03.26 SORACOM INC
  • US11943213B2 patent drawing
  • US11943213B2 patent drawing
  • US11943213B2 patent drawing

AI summary

Facilitate configuration of authentication information for a service provided over IP network when there is no shared authentication information between IoT device and service provider device for a service used by IoT device, an intermediary device capable of authenticating legitimate access mediates between devices. An example: a cipher key CK stored in intermediary device and IoT device, as a result of SIM authentication of the SIM of the IoT device, is used as master key for services used by IoT device. By generating unique application key for a service used by IoT device on the intermediary device and IoT device on the basis of master key, and sending it to service provider apparatus from intermediary device by secure connection, common keys are set as authentication information to IoT device and service provider apparatus. A SIM authentication process for generating cipher key can suppress SQN attack based on a bad request.