Master Device Group Authentication for IoT Overhead Reduction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current LTE authentication and NAS security protocols require individual authentication for each IoT device, leading to high overhead in radio access networks, which is inefficient for authenticating large numbers of IoT devices.

Innovation Solution

A method for massive IoT group authentication is introduced, where a master device aggregates UE identifiers and sends authentication requests to a base station, which then coordinates with a Security Anchor Node and Home Subscriber Server to authenticate a group of IoT devices using a group authentication vector and individual response parameters, reducing overhead by coordinating authentication through a master device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If individual authentication is performed for each IoT device using current LTE authentication protocols, then security and authorization are ensured for each device, but authentication overhead in the radio access network becomes very high

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication overhead
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent merges multiple individual authentication processes into a single group authentication process. A master device represents a group of IoT devices, and the network performs one authentication with the master device to authenticate the entire group, significantly reducing the number of authentication transactions and overhead in the radio access network while maintaining security through individual response parameters.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The master device acts as an intermediary between the network and the group of IoT devices. It receives group authentication requests from the network, coordinates the authentication process for all devices in the group, and manages the distribution of authentication credentials, thereby reducing direct communication overhead between the network and each individual device.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If individual authentication requests are sent to each IoT device, then each device can be authenticated securely, but the time and signaling overhead increase significantly for large numbers of devices

Engineering Contradiction:
Improvedevice authenticationVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Multiple individual authentication requests are merged into a single group authentication request. The network sends one authentication request to the master device, which then coordinates authentication for all devices in the group simultaneously, reducing the total authentication time from proportional to the number of devices to a constant time operation regardless of group size.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

Devices are pre-configured with group credentials and individual response parameters before authentication. The master device is pre-provisioned with the ability to represent the group, and individual devices have pre-stored authentication material that enables rapid verification without lengthy setup procedures during the actual authentication process.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If traditional LTE authentication protocols are used for IoT devices, then individual security is maintained, but the system becomes inefficient for massive IoT deployments with limited spectrum resources

Engineering Contradiction:
Improveindividual securityVSAvoidauthentication efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent combines individual security requirements with group authentication efficiency. By using a master device to represent the group while maintaining individual response parameters for each device, the system achieves both individual security and collective authentication efficiency, enabling scalable IoT deployments without sacrificing security.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The master device serves multiple functions: it acts as an authentication representative for the entire group, manages individual device credentials, coordinates authentication responses, and reduces signaling overhead. This multi-functional approach enables a single device to perform what would otherwise require multiple individual device interactions.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3513526B1System and method for massive IoT group authentication
Publication Date: 2024.05.15 HUAWEI TECH CO LTD
  • EP3513526B1 patent drawingFigure 1~2
  • EP3513526B1 patent drawingFigure 3
  • EP3513526B1 patent drawingFigure 4

AI summary

It is possible to reduce singling overhead in a radio access network by coordinating authentication of a group of UEs (e.g., IoT devices, etc. ) via a master device. In particular, the master device may aggregate UE identifiers (UE_IDs) for UEs in the group, and send an identity message carrying the UE_IDs and a master device identifier (MD_ID) to a base station, which may then relay the identity message to a Security Anchor Node (SeAN). The SeAN may send an authentication data request carrying the UE_IDs and MD_ID to a Home Subscriber Server (HSS), which may return an authentication data response that includes a group authentication information. The group authentication information may then be used to achieve mutual authentication between the SeAN and each of the master device, group of UEs, and individual UEs.