Authentication Module for IoT Security and Processor Overhead

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security solutions for IoT devices, such as cellular M2M systems and public key cryptography, are inadequate for providing robust authentication and encryption, especially for devices operating on Local Area Networks (LANs), and often require complex management and processor overhead, which can be a challenge for simple IoT processors.

Innovation Solution

An authentication module using IMSI, secret keys, and algorithms according to mobile telephony standards, connected to a processor via a serial I/O module, allowing for direct access to authentication and encryption functionality, enabling end-to-end encryption and flexible programming for secure communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If public key cryptography is used for securing IoT communications, then security is improved, but processor overhead and network load increase significantly

Engineering Contradiction:
ImprovesecurityVSAvoidprocessor overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the cryptographic functionality from the main processor by implementing a dedicated authentication module that handles all authentication and key generation operations. This separation removes the computational burden from the processor while maintaining security functions, directly resolving the contradiction between security and processor overhead.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The authentication module acts as an intermediary between the processor and the security requirements. It handles complex cryptographic operations using lightweight algorithms, providing security functionality without requiring the main processor to handle heavy computational loads, thus resolving the overhead issue.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If a network-wide key is programmed into all devices, then security management is simplified, but all devices become vulnerable if the key is compromised

Engineering Contradiction:
Improvesecurity managementVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the security architecture by providing each device with a unique authentication module containing individual authentication credentials (IMSI and secret key). This segmentation allows simplified management through standardized modules while ensuring that compromise of one device's key does not affect others, resolving the contradiction between management simplicity and security vulnerability.

Inventive Principle:
Principle #1Segmentation

3Reliability

If separate keys are programmed into each device, then security is improved against device compromise, but key management becomes complex and difficult to maintain

Engineering Contradiction:
Improvesecurity against compromiseVSAvoidkey management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The authentication module is designed as a universal component that can be deployed across all IoT devices with the same interface and functionality. Each device gets its own key pair through standardized provisioning, maintaining individual security while allowing centralized management through uniform protocols, thus resolving the contradiction between individual security and management complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If conventional cellular encryption is used, then communication security is provided, but end-to-end encryption to remote servers is not achieved

Engineering Contradiction:
Improvecommunication securityVSAvoidend-to-end encryption capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The authentication module dynamically generates session keys and encryption keys based on the communication context. It can adapt to different communication scenarios (cellular, Wi-Fi, direct server communication) and provide appropriate encryption levels, enabling both cellular security and end-to-end encryption versatility without requiring separate fixed solutions.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10652738B2Authentication module
Publication Date: 2020.05.12 ESEYE
  • US10652738B2 patent drawing
  • US10652738B2 patent drawing
  • US10652738B2 patent drawing

AI summary

A device 2 is connected to server 34 using encryption exposed at the application layer of device 2. The encryption takes place using a mobile telephony standard encryption. An authentication module is provided in device 2 comprising an IMSI and software to connect to a mobile telephony-like home location register using conventional mobile telephony protocols, except that the mobile telephony-like home location register is adapted simply to authenticate the device 2 and deliver a communication key Kc using the mobile telephony standard without also authorising access to a mobile telephone network.