IoT Device Credential Self-Management via Automated Updates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

IoT devices often use default passwords that are not changed, leading to potential unauthorized access due to lack of easy password management, resulting in prolonged security breaches.

Innovation Solution

IoT devices are equipped with the ability to automatically update their credentials, such as passwords or cryptographic keys, based on predetermined schedules or detected conditions like reboot commands or software updates, ensuring continuous security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If IoT devices use default passwords that are not changed, then ease of operation is improved, but security reliability deteriorates

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system enables automated credential management where the IoT device itself initiates and completes credential updates without requiring user intervention. The device automatically detects credential expiration, requests new credentials from a credential service, and updates its authentication information, thereby maintaining security while eliminating the need for user action.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs credential updates in advance before credentials expire or are compromised. By monitoring credential validity periods and automatically initiating renewal processes beforehand, the system ensures continuous security coverage and prevents authentication gaps that could occur with manual updates.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If IoT devices implement manual password change mechanisms, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system introduces a credential service as an intermediary that handles the complex operations of credential generation, validation, and distribution. The IoT device simply interacts with this service through standardized requests, offloading the computational and procedural complexity of secure credential management to the external service while maintaining enhanced security.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If IoT devices automatically update credentials without user intervention, then security is improved, but loss of time occurs due to automated processes

Engineering Contradiction:
ImprovesecurityVSAvoidtime
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system implements periodic credential updates based on predetermined time intervals or usage thresholds. The device automatically initiates credential renewal at scheduled intervals or after specific numbers of operations, ensuring security maintenance through regular updates without requiring continuous user attention or intervention.

Inventive Principle:
Principle #19Periodic action

4Ease of operation

If IoT devices use default credentials indefinitely, then ease of operation is maintained, but harmful factors increase due to unauthorized access

Engineering Contradiction:
Improveease of operationVSAvoidunauthorized access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system takes preliminary anti-action by automatically updating credentials before they can be compromised or exploited. By proactively renewing authentication information based on time intervals or detected usage patterns, the system prevents potential security breaches rather than responding to them after occurrence.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS10594482B2Self management of credentials by IoT devices
Publication Date: 2020.03.17 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10594482B2 patent drawing
  • US10594482B2 patent drawing
  • US10594482B2 patent drawing

AI summary

A method, a device and a computer program product are provided. A networked device determines whether a condition occurred. In response to detecting the condition, the networked device requests information to update a current credential of the networked device. The networked device updates the current credential with the requested information to maintain security of the networked device. The networked device accesses at least one networked service based on the updated credential. The current credential includes either a cryptographic key or a password. When the current credential includes the password, the condition includes a usage rate including one or more from a group of a quantity of reboot commands for the networked device and a quantity of software update commands for the networked device.