Authentication Module for IoT Security and Processor Overhead
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security solutions for IoT devices, such as cellular M2M systems and public key cryptography, are inadequate for providing robust authentication and encryption, especially for devices operating on Local Area Networks (LANs), and often require complex management and processor overhead, which can be a challenge for simple IoT processors.
Innovation Solution
An authentication module using IMSI, secret keys, and algorithms according to mobile telephony standards, connected to a processor via a serial I/O module, allowing for direct access to authentication and encryption functionality, enabling end-to-end encryption and flexible programming for secure communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If public key cryptography is used for securing IoT communications, then security is improved, but processor overhead and network load increase significantly
Solution Approach 1:
The patent extracts the cryptographic functionality from the main processor by implementing a dedicated authentication module that handles all authentication and key generation operations. This separation removes the computational burden from the processor while maintaining security functions, directly resolving the contradiction between security and processor overhead.
Solution Approach 2:
The authentication module acts as an intermediary between the processor and the security requirements. It handles complex cryptographic operations using lightweight algorithms, providing security functionality without requiring the main processor to handle heavy computational loads, thus resolving the overhead issue.
2Ease of operation
If a network-wide key is programmed into all devices, then security management is simplified, but all devices become vulnerable if the key is compromised
Solution Approach 1:
The patent segments the security architecture by providing each device with a unique authentication module containing individual authentication credentials (IMSI and secret key). This segmentation allows simplified management through standardized modules while ensuring that compromise of one device's key does not affect others, resolving the contradiction between management simplicity and security vulnerability.
3Reliability
If separate keys are programmed into each device, then security is improved against device compromise, but key management becomes complex and difficult to maintain
Solution Approach 1:
The authentication module is designed as a universal component that can be deployed across all IoT devices with the same interface and functionality. Each device gets its own key pair through standardized provisioning, maintaining individual security while allowing centralized management through uniform protocols, thus resolving the contradiction between individual security and management complexity.
4Reliability
If conventional cellular encryption is used, then communication security is provided, but end-to-end encryption to remote servers is not achieved
Solution Approach 1:
The authentication module dynamically generates session keys and encryption keys based on the communication context. It can adapt to different communication scenarios (cellular, Wi-Fi, direct server communication) and provide appropriate encryption levels, enabling both cellular security and end-to-end encryption versatility without requiring separate fixed solutions.
Data Source
AI summary
A device 2 is connected to server 34 using encryption exposed at the application layer of device 2. The encryption takes place using a mobile telephony standard encryption. An authentication module is provided in device 2 comprising an IMSI and software to connect to a mobile telephony-like home location register using conventional mobile telephony protocols, except that the mobile telephony-like home location register is adapted simply to authenticate the device 2 and deliver a communication key Kc using the mobile telephony standard without also authorising access to a mobile telephone network.


