IoT Group Key Distribution via Local SKDC Service
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing IoT network key management systems often rely on central key servers or certification authorities, which can be unwieldy and unsuitable for autonomous IoT devices lacking user credentials, posing challenges in secure key distribution and authentication.
Innovation Solution
A group key management architecture using a Simple Key Distribution Center (SKDC) within the IoT network, where devices establish pair-wise keys and a SKDC service for secure key distribution, enabling authenticated group key requests and cross-realm interactions without relying on user credentials or central authorities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a central key server or certification authority is used for key management, then key distribution can be centralized and controlled, but the system becomes unwieldy and unsuitable for autonomous IoT devices
Solution Approach 1:
The patent extracts the key distribution function from a centralized key server and implements it locally within each IoT device through a key distribution module. This allows each device to autonomously generate and distribute group keys without relying on external central authorities, thereby reducing system complexity while maintaining security through distributed key management.
Solution Approach 2:
Each IoT device is equipped with the capability to independently perform key generation and distribution operations through its key distribution module. The devices self-manage their own keying material and can autonomously establish secure group communications without requiring external key servers or user intervention, enabling autonomous operation in constrained environments.
2Reliability
If user credentials are required for authentication, then secure authentication can be achieved, but constrained IoT devices lack user credentials or the ability to solicit them
Solution Approach 1:
The patent replaces traditional user credentials with device-generated keying material that serves as a cryptographic copy or substitute for authentication purposes. The key distribution module generates group keys and distribution keys that function as authentication credentials, allowing constrained devices to authenticate and authorize key exchange without requiring traditional user credentials or credential solicitation capabilities.
3Extent of automation
If autonomous operation is implemented without central control, then device independence is improved, but key management becomes more difficult
Solution Approach 1:
The patent segments the key management functionality into a dedicated key distribution module within each device, separating key generation, key distribution, and key management operations from general device operations. This modular segmentation allows autonomous devices to handle key management independently through specialized local components, reducing the complexity burden on the overall autonomous system while maintaining device independence.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
An embodiment includes receiving, in a first key management device (KMD) of a first autonomous network associated with a first realm, a request for a group key to enable content to be shared between one or more first devices of the first autonomous network and one or more second devices of a second autonomous network associated with a second realm, the second autonomous network having a second KMD; creating the group key and providing the group key to the one or more first devices from the first KMD; establishing a temporal key to be used to establish a secure channel between the first KMD and the second KMD; and delivering the group key to the second KMD from the first KMD via the secure channel, to enable the second KMD to provide the group key to the one or more second devices. Other embodiments are addressed herein.