End-to-End Authentication for IoT Messaging Overhead

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current M2M and IoT network deployments lack effective end-to-end authentication mechanisms, particularly for entities with diverse capabilities, leading to insecure message transmission and potential impersonation attacks due to hop-by-hop security associations, which fail to verify the origin of messages with high assurance.

Innovation Solution

The implementation of a Service Enablement and Security Configuration (SESC) method that identifies appropriate security features and credentials for entities within a M2M network, enabling dynamic credential requisition and registration, and performing end-to-end authentication processes, including one-way or mutual authentication, to ensure message origin authenticity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hop-by-hop secure connections are established at each network node, then security associations are maintained between adjacent nodes, but end-to-end authentication of message originators cannot be achieved and messaging overhead increases

Engineering Contradiction:
Improvemessage originator authenticationVSAvoidsecurity association management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments security functionality into distinct components: hop-by-hop security associations for adjacent node protection, and end-to-end credentials for message originator authentication. This allows each component to serve its specific purpose without conflating the two security models, resolving the contradiction between maintaining security associations and achieving end-to-end authentication.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary credential registry that stores end-to-end credentials separately from hop-by-hop security associations. This intermediary structure enables message originator authentication without requiring complex security association management at each node, as credentials are retrieved from the registry rather than established through multi-hop negotiations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If end-to-end authentication is implemented for all messages, then message origin authenticity is verified, but messaging overhead and computational cost increase significantly

Engineering Contradiction:
Improvemessage origin authenticity verificationVSAvoidmessaging efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies different security measures to different message types and contexts. Critical messages requiring strong authentication use end-to-end credentials, while less sensitive messages can rely on hop-by-hop security alone. This localized application of security reduces overall messaging overhead while maintaining authentication where necessary.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements partial end-to-end authentication by allowing messages to include optional authentication indicators. Receivers can determine whether full end-to-end verification is necessary based on message criticality, enabling selective application of authentication mechanisms rather than requiring it for all messages, thus improving messaging efficiency.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If constrained IoT devices perform complex security functions, then end-to-end authentication can be achieved, but device resource consumption and processing overhead increase

Engineering Contradiction:
Improveend-to-end authentication capabilityVSAvoiddevice energy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent introduces credential registries and trusted third parties as intermediaries that handle complex credential management and verification tasks. Constrained devices can obtain pre-configured credentials from these intermediaries without performing complex security negotiations, reducing their computational burden and energy consumption while maintaining authentication capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary credential provisioning where end-to-end credentials are configured in devices during manufacturing or initial setup, before the devices need to perform authentication. This preliminary action eliminates the need for constrained devices to perform complex real-time credential management, reducing their processing overhead and energy consumption during operation.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If expensive E2E authentication processes are applied to non-critical services, then maximum security assurance is provided, but system resource utilization and operational cost increase

Engineering Contradiction:
Improvesecurity assurance levelVSAvoidsystem resource consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent applies different security assurance levels to different services based on their criticality. Non-critical services use simplified authentication mechanisms, while critical services require full end-to-end authentication. This localized quality approach ensures maximum security assurance for essential services while minimizing resource consumption for less important communications.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent changes authentication parameters dynamically based on service criticality and message importance. For non-critical services, authentication can be skipped or use lighter-weight mechanisms, while critical services trigger full E2E authentication processes. This parameter adjustment resolves the contradiction by adapting security levels to actual needs rather than applying uniform maximum security.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3272094B1End-to-end authentication at the service layer using public keying mechanisms
Publication Date: 2021.06.23 CONVIDA WIRELESS LLC
  • EP3272094B1 patent drawingFigure 1
  • EP3272094B1 patent drawingFigure 2
  • EP3272094B1 patent drawingFigure 3

AI summary

In a machine-to-machine / Internet-of-things environment, end-to-end authentication of devices separated by multiple hops is achieved via direct or delegated/intermediated negotiations using pre-provisioned hop-by -hop credentials, uniquely generated hop-by -hop credentials, and-or public key certificates, whereby remote resources and services may be discovered via single-hop communications, and then secure communications with the remote resources may be established using secure protocols appropriate to the resources and services and capabilities of end devices, and communication thereafter conducted directly without the overhead or risks engendered hop- by-hop translation.