IoT Authentication System Using Identity-Based Cryptography
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Legacy authentication and access control mechanisms are inadequate for the Internet of Things (IoT) devices, particularly due to high CPU, memory, storage, and communication overheads, inability to operate in low-power environments, and lack of comprehensive solutions throughout the device life-cycle.
Innovation Solution
The AoT system employs Identity-Based Cryptography and Attribute-Based Cryptography to provide authentication and access control across multiple domains, enabling secure device authentication, ownership transfer, and inter-domain operations, using cryptographic protocols that do not rely on explicit public-key infrastructure, thus reducing overhead and supporting the entire IoT device life-cycle.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication mechanisms based on public key infrastructure are used, then security is improved, but CPU overhead, memory overhead, storage overhead, and communication overhead increase significantly
Solution Approach 1:
The patent segments the authentication process into multiple stages: device manufacturing stage with lightweight cryptographic material embedding, and operational stage with simplified authentication protocols. This segmentation allows complex security operations to be performed only during manufacturing, while runtime operations remain lightweight for resource-constrained devices.
Solution Approach 2:
The patent extracts the computationally intensive public key infrastructure operations from the IoT devices and relocates them to external authentication servers or trusted execution environments. Devices retain only essential cryptographic primitives, removing the burden of full PKS implementation from resource-constrained endpoints.
2Reliability
If public key cryptosystem is applied to authenticate IoT devices, then authentication capability is improved, but energy consumption and computational cost increase making it difficult to apply to low-power devices
Solution Approach 1:
The patent changes the cryptographic parameters used in authentication from traditional PKS with large key sizes to lightweight cryptographic schemes with smaller key sizes and simpler mathematical operations. This parameter change reduces computational complexity and energy consumption while maintaining acceptable security levels for IoT applications.
3Reliability
If comprehensive authentication mechanisms are implemented throughout the IoT device life-cycle, then security coverage is improved, but system complexity and management overhead increase
Solution Approach 1:
The patent implements a universal authentication framework that handles multiple authentication scenarios (device-to-cloud, device-to-device, ownership transfer, revocation) through a single integrated system. The same lightweight cryptographic primitives and protocol structure serve all authentication needs throughout the device life-cycle, from manufacturing to retirement, reducing overall system complexity.
Data Source
AI summary
An Authentication Of Things (AOT) system includes a cloud server configured to control a cloud domain connected with a plurality of devices, a home server configured to control a home server connected with a plurality of devices, a first device corresponding to a new device, and a second device of a root user connected with the home domain while authentication is completed in the home server. In this case, the first device loads cryptographic material of the cloud server from the cloud server in a pre-deployment stage, the cryptographic material includes at least one selected from the group consisting of an identifier of the first device in the cloud server, a first private key of an ID-based cryptography system of the first device in the cloud server, a first pairwise key of the first device in the cloud server, and a counter of the first device, and if the first device is shipped to a trader, the cloud server deletes the first private key from the cloud server.


