IoT Command Authentication Using Shared Secrets for Restricted Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Ambient power-enabled IoT devices, lacking a USIM, are vulnerable to spoofed command messages, leading to potential Denial of Service (DOS) scenarios due to their inability to discern between legitimate and nefarious sources.

Innovation Solution

Implementing signature generation using a shared secret parameter, such as a private device identity, to ensure secure communications between IoT devices and network functions, ensuring command messages originate from trusted entities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If ambient power-enabled IoT devices use simple communication without USIM, then device complexity and energy consumption are reduced, but security reliability deteriorates making devices vulnerable to spoofed commands

Engineering Contradiction:
Improvedevice complexityVSAvoidsecurity reliability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The system performs preliminary actions by pre-configuring shared secret parameters between the AIoT device and network function before communication occurs. This allows the device to verify command authenticity using pre-established cryptographic keys without requiring complex USIM hardware or continuous authentication overhead, thus maintaining simplicity while improving security reliability through advance security setup

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces cryptographic signature verification as an intermediary mechanism between the network function and AIoT device. The signature verification process acts as a mediator that authenticates commands without requiring the device to have complex authentication hardware, thereby maintaining low device complexity while enhancing security through the intermediary verification layer

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If AIoT devices lack USIM and authentication capabilities, then ease of operation and deployment are improved, but vulnerability to spoofed commands and DOS attacks increases

Engineering Contradiction:
Improveease of operationVSAvoidvulnerability to spoofed commands
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The AIoT device performs self-service by autonomously verifying command authenticity using its own shared secret parameter and signature verification capability. The device independently authenticates commands without requiring external authentication servers or complex USIM-based procedures, thereby maintaining ease of operation while simultaneously protecting against spoofed commands through self-performed security verification

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system changes the authentication parameter from complex USIM-based authentication to simpler shared secret parameter verification. This parameter change allows the device to maintain ease of operation with minimal configuration while improving security by using cryptographic signatures that can be verified with simple computational operations rather than complex authentication hardware

Inventive Principle:
Principle #35Parameter changes

3Use of energy by moving object

If AIoT devices have limited energy storage and harvest energy from environment, then energy efficiency is improved, but ability to perform secure authentication operations is reduced

Engineering Contradiction:
Improveenergy efficiencyVSAvoidauthentication capability
Core Design Contradiction:
Use of energy by moving objectVSReliability

Solution Approach 1:

The system uses disposable or short-lived cryptographic operations that consume minimal energy. Instead of requiring continuous authentication sessions or heavy cryptographic computations, the device performs quick signature verification using pre-shared secrets, which are computationally lightweight and can be executed with the limited energy available from environmental harvesting, thus maintaining both energy efficiency and authentication reliability

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS20250350935A1Secure transmission of commands to restricted devices
Publication Date: 2025.11.13 LENOVO (SINGAPORE) PTE LTD
  • US20250350935A1 patent drawing
  • US20250350935A1 patent drawing
  • US20250350935A1 patent drawing

AI summary

Various aspects of the present disclosure relate to providing secure communications with restricted devices, such as ambient-powered Internet of Things (IoT) devices. For example, an IoT device and associated network function may employ signature generation by utilizing a shared secret parameter, such as a private device identity (e.g., a unique string or random number), to ensure secure communications, such as when the network function sends commands to the IoT device.