IoT Device Authentication via Hardware Identifier and Secure Channel

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

IoT devices face security vulnerabilities during network attachment, particularly due to plain text communication of identifiers, and existing authentication methods fail to detect breaches promptly, leading to potential misuse and resource allocation challenges for network service providers.

Innovation Solution

An authentication service that authenticates IoT devices using a hardware identifier via a secure channel before network access, invoking detachment if the identifier is invalid, and providing a token for secure communication, thereby minimizing security risks and ensuring timely breach detection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If IoT devices communicate identifiers in plain text during network attachment, then network access is simplified and fast, but security is compromised and devices become vulnerable to spoofing attacks

Engineering Contradiction:
Improvenetwork access simplicityVSAvoidsecurity authentication
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an authentication service as an intermediary between IoT devices and the network. This service validates device identifiers through secure channels before granting network access, thereby maintaining operational simplicity while enhancing security authentication reliability

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication service performs preliminary validation of device identifiers before network attachment is completed. By conducting security verification in advance through secure channels, the system prevents spoofing attacks while maintaining fast network access for authenticated devices

Inventive Principle:
Principle #10Preliminary action

2Speed

If authentication is performed after network attachment, then devices can connect quickly, but security breaches are detected too late leading to resource misuse

Engineering Contradiction:
Improveconnection speedVSAvoidbreach detection timing
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The authentication service performs identifier validation before network attachment is finalized. By conducting security verification in advance through secure channels, the system ensures fast connection speed for authenticated devices while detecting and preventing security breaches before they can compromise network resources

Inventive Principle:
Principle #10Preliminary action

3Reliability

If network service providers implement strict authentication protocols, then security is improved, but device complexity and resource requirements increase

Engineering Contradiction:
Improvesecurity authenticationVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication service acts as an intermediary that handles complex validation protocols between devices and the network. This centralized approach improves security authentication reliability while keeping individual device complexity low, as devices only need to communicate their identifiers through the standardized secure channel provided by the authentication service

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10986083B2Hardware identification-based security authentication service for IoT devices
Publication Date: 2021.04.20 VERIZON PATENT & LICENSING INC
  • US10986083B2 patent drawing
  • US10986083B2 patent drawing
  • US10986083B2 patent drawing

AI summary

A method, a device, and a non-transitory storage medium are provided to store a hardware identifier that uniquely identifies an IoT device; perform an attachment procedure with a wireless network, wherein the attachment procedure includes authenticating the IoT device by the wireless network and establishing a bearer connection; establish a secure channel with an authentication device via the bearer connection, in response to successfully completing the attachment procedure; transmit, to the authentication device, a first request to authenticate the IoT device, wherein the first request includes the hardware identifier; receive, from the authentication device, a first response that indicates whether the IoT device is authenticated; and determine that the IoT device is authenticated based on the first response.