IoT Device Identity Burning via Trusted Execution Environment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing Internet of Things (IoT) devices face security vulnerabilities due to direct recording of identities and private keys, which can be stolen, leading to unauthorized device impersonation and compromised service security.
Innovation Solution
A recording and verification apparatus verifies the production line before assigning identities and private keys to IoT devices, recording them in a trusted execution environment, and generates a unique authorization code using a random number for secure identity authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If identities and private keys are directly recorded in storage spaces of IoT devices, then the recording process is simple and fast, but the security is compromised as identities and keys can be maliciously stolen
Solution Approach 1:
The patent introduces a trusted execution environment as an intermediary layer between the storage space and the identities/private keys. This TEE acts as a mediator that protects the keys while allowing authorized access, resolving the contradiction between simple storage and secure protection
Solution Approach 2:
The patent changes the security parameter of the storage environment by introducing a trusted execution environment with different security properties. This transforms the storage from a simple, accessible space to a secure, controlled environment that prevents malicious theft while maintaining functional access
2Reliability
If a centralized verification system is introduced to verify recording production lines before assigning identities, then the security is improved, but the complexity of the system increases
Solution Approach 1:
The patent implements preliminary verification of the recording production line before identities are assigned. This advance verification ensures security is established upfront, preventing unauthorized recording while maintaining a relatively simple overall system structure
Solution Approach 2:
The trusted execution environment serves as an intermediary that manages the complexity of verification and key management. It absorbs the system complexity while presenting a simple interface for identity assignment and device operation
3Reliability
If authorization codes with random numbers are generated for each service request, then the security against impersonation is enhanced, but the authentication process becomes more complex
Solution Approach 1:
The patent implements periodic generation of random numbers for each service request rather than using static credentials. This periodic refresh of authentication data prevents impersonation while the underlying TEE infrastructure keeps the implementation relatively simple
Solution Approach 2:
The trusted execution environment automatically manages the generation and protection of random numbers and authorization codes without requiring complex external authentication infrastructure. The TEE performs self-service security functions that enhance protection while maintaining process simplicity
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method and an apparatus for recording and verifying an Internet of Things (IoT) device, a method and an apparatus for identity authentication are provided in the present application. The recording and verification method includes: a recording and verification apparatus receiving a recording request sent by a recording production line, the recording request being used for requesting the recording and verification apparatus to assign an identity identifier and a device key to an IoT device to be recorded, and the device key including a device private key and a device public key; the recording and verification apparatus verifying whether the recording request is legitimate, and assigning the identity identifier and the device key to the IoT device to be recorded if affirmative; and the recording and verification apparatus sending the identity identifier and the device private key to the recording production line, so that the recording production line records the identity identifier and the device private key into the IoT device. Using the embodiments of the present application, the security of identity authentication of an IoT device can be improved, and the cost of a platform side can be reduced.