IoT Authentication System Using Identity-Based Cryptography

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Legacy authentication and access control mechanisms are inadequate for the Internet of Things (IoT) devices, particularly due to high CPU, memory, storage, and communication overheads, inability to operate in low-power environments, and lack of comprehensive solutions throughout the device life-cycle.

Innovation Solution

The AoT system employs Identity-Based Cryptography and Attribute-Based Cryptography to provide authentication and access control across multiple domains, enabling secure device authentication, ownership transfer, and inter-domain operations, using cryptographic protocols that do not rely on explicit public-key infrastructure, thus reducing overhead and supporting the entire IoT device life-cycle.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication mechanisms based on public key infrastructure are used, then security is improved, but CPU overhead, memory overhead, storage overhead, and communication overhead increase significantly

Engineering Contradiction:
Improveauthentication securityVSAvoidcomputational overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication process into multiple stages: device manufacturing stage with lightweight cryptographic material embedding, and operational stage with simplified authentication protocols. This segmentation allows complex security operations to be performed only during manufacturing, while runtime operations remain lightweight for resource-constrained devices.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts the computationally intensive public key infrastructure operations from the IoT devices and relocates them to external authentication servers or trusted execution environments. Devices retain only essential cryptographic primitives, removing the burden of full PKS implementation from resource-constrained endpoints.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If public key cryptosystem is applied to authenticate IoT devices, then authentication capability is improved, but energy consumption and computational cost increase making it difficult to apply to low-power devices

Engineering Contradiction:
Improvedevice authenticationVSAvoidenergy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent changes the cryptographic parameters used in authentication from traditional PKS with large key sizes to lightweight cryptographic schemes with smaller key sizes and simpler mathematical operations. This parameter change reduces computational complexity and energy consumption while maintaining acceptable security levels for IoT applications.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If comprehensive authentication mechanisms are implemented throughout the IoT device life-cycle, then security coverage is improved, but system complexity and management overhead increase

Engineering Contradiction:
Improvelife-cycle security coverageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal authentication framework that handles multiple authentication scenarios (device-to-cloud, device-to-device, ownership transfer, revocation) through a single integrated system. The same lightweight cryptographic primitives and protocol structure serve all authentication needs throughout the device life-cycle, from manufacturing to retirement, reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10523437B2System and method for authentication of things
Publication Date: 2019.12.31 LG ELECTRONICS INC
  • US10523437B2 patent drawing
  • US10523437B2 patent drawing
  • US10523437B2 patent drawing

AI summary

An Authentication Of Things (AOT) system includes a cloud server configured to control a cloud domain connected with a plurality of devices, a home server configured to control a home server connected with a plurality of devices, a first device corresponding to a new device, and a second device of a root user connected with the home domain while authentication is completed in the home server. In this case, the first device loads cryptographic material of the cloud server from the cloud server in a pre-deployment stage, the cryptographic material includes at least one selected from the group consisting of an identifier of the first device in the cloud server, a first private key of an ID-based cryptography system of the first device in the cloud server, a first pairwise key of the first device in the cloud server, and a counter of the first device, and if the first device is shipped to a trader, the cloud server deletes the first private key from the cloud server.