IoT Device ID via Public Key Cryptography
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing methods for obtaining device IDs in IoT systems are complex, costly, and insecure, with preconfiguration requirements and high risks of ID theft and forgery due to simple ID generation.
Innovation Solution
A method where a terminal requests a device ID from a network device, which sends an encrypted key pair, with the public key being used as the unique device ID, eliminating preconfiguration and registration needs, and utilizing physical unclonable functions (PUFs) for enhanced security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If device ID is preconfigured using conventional methods, then device ID can be obtained, but configuration process becomes complex and registration costs increase
Solution Approach 1:
The terminal device autonomously generates its own device ID using the public key from the key pair, without requiring manual configuration or registration authority intervention. The system performs self-service by automatically obtaining device ID through the network device, eliminating complex preconfiguration processes.
2Ease of operation
If simple device ID generation method is used, then configuration is simplified, but security risks increase due to ID theft and forgery
Solution Approach 1:
The device ID is transformed from a simple identifier to a cryptographic public key, fundamentally changing the parameter structure. This parameter change enhances security properties while maintaining the ability to uniquely identify devices, resolving the contradiction between simplicity and security.
Solution Approach 2:
The conventional mechanical/configuration-based ID assignment is replaced with a cryptographic system. The public key infrastructure substitutes the traditional ID configuration mechanism, providing inherent security properties without complex manual processes.
3Reliability
If registration authority is used for unique device ID, then device ID uniqueness is ensured, but registration costs and time increase
Solution Approach 1:
Each terminal device independently generates its own unique device ID through autonomous key pair generation, eliminating the need for centralized registration authority intervention. This self-service approach ensures device ID uniqueness while significantly reducing registration time and costs.
Solution Approach 2:
The device ID generation is performed in advance during key pair generation, before the device needs to access the network. This preliminary action eliminates the need for subsequent registration processes, saving time and reducing dependency on registration authorities.
4Reliability
If conventional device ID is used, then device identification is achieved, but ID forgery becomes easy when ID is stolen
Solution Approach 1:
The conventional device ID system is replaced with a cryptographic public key. This substitution provides inherent security properties where the public key can be freely shared for identification, while the corresponding private key remains secure and cannot be derived, preventing ID forgery even if the public key is compromised.
Solution Approach 2:
The device ID parameter is transformed from a simple identifier to a cryptographic public key, fundamentally changing the security characteristics. This parameter change ensures that identification functionality is maintained while making forgery computationally infeasible due to the one-way nature of cryptographic key pairs.
Data Source
AI summary
A device identifier (ID) obtaining method, a terminal, and a network device, where the method includes sending, by a terminal to a network device, a first message used to obtain a device ID, where the device ID is used to globally identify the terminal uniquely, receiving, by the terminal, an encrypted key pair sent by the network device, where the key pair includes a first public key and a first private key, receiving, by the terminal, information sent by the network device, where the information is used to identify that the first public key is the device ID of the terminal, and determining, by the terminal, that the first public key is the device ID.


