IoT Command Authentication Using Shared Secrets for Restricted Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Ambient power-enabled IoT devices, lacking a USIM, are vulnerable to spoofed command messages, leading to potential Denial of Service (DOS) scenarios due to their inability to discern between legitimate and nefarious sources.
Innovation Solution
Implementing signature generation using a shared secret parameter, such as a private device identity, to ensure secure communications between IoT devices and network functions, ensuring command messages originate from trusted entities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If ambient power-enabled IoT devices use simple communication without USIM, then device complexity and energy consumption are reduced, but security reliability deteriorates making devices vulnerable to spoofed commands
Solution Approach 1:
The system performs preliminary actions by pre-configuring shared secret parameters between the AIoT device and network function before communication occurs. This allows the device to verify command authenticity using pre-established cryptographic keys without requiring complex USIM hardware or continuous authentication overhead, thus maintaining simplicity while improving security reliability through advance security setup
Solution Approach 2:
The patent introduces cryptographic signature verification as an intermediary mechanism between the network function and AIoT device. The signature verification process acts as a mediator that authenticates commands without requiring the device to have complex authentication hardware, thereby maintaining low device complexity while enhancing security through the intermediary verification layer
2Ease of operation
If AIoT devices lack USIM and authentication capabilities, then ease of operation and deployment are improved, but vulnerability to spoofed commands and DOS attacks increases
Solution Approach 1:
The AIoT device performs self-service by autonomously verifying command authenticity using its own shared secret parameter and signature verification capability. The device independently authenticates commands without requiring external authentication servers or complex USIM-based procedures, thereby maintaining ease of operation while simultaneously protecting against spoofed commands through self-performed security verification
Solution Approach 2:
The system changes the authentication parameter from complex USIM-based authentication to simpler shared secret parameter verification. This parameter change allows the device to maintain ease of operation with minimal configuration while improving security by using cryptographic signatures that can be verified with simple computational operations rather than complex authentication hardware
3Use of energy by moving object
If AIoT devices have limited energy storage and harvest energy from environment, then energy efficiency is improved, but ability to perform secure authentication operations is reduced
Solution Approach 1:
The system uses disposable or short-lived cryptographic operations that consume minimal energy. Instead of requiring continuous authentication sessions or heavy cryptographic computations, the device performs quick signature verification using pre-shared secrets, which are computationally lightweight and can be executed with the limited energy available from environmental harvesting, thus maintaining both energy efficiency and authentication reliability
Data Source
AI summary
Various aspects of the present disclosure relate to providing secure communications with restricted devices, such as ambient-powered Internet of Things (IoT) devices. For example, an IoT device and associated network function may employ signature generation by utilizing a shared secret parameter, such as a private device identity (e.g., a unique string or random number), to ensure secure communications, such as when the network function sends commands to the IoT device.


