Dynamic Trust Establishment for IoT Hub Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Establishing trust between short-range communication devices and hub devices in IoT environments is challenging due to the lack of prior trust relationships and knowledge of each other, especially when devices are manufactured by different entities and are not pre-configured for compatibility.
Innovation Solution
The system dynamically establishes two-way trust relationships between short-range communication devices and hub devices without direct network connection, using a hub device as a proxy to communicate with a computer resource service provider for authentication, and ensuring cryptographic protection of messages to prevent tampering.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual trust establishment is used between devices, then security is improved, but operation complexity and time consumption increase significantly
Solution Approach 1:
The patent introduces a server as an intermediary that facilitates automatic trust establishment between devices. The server receives authentication requests from devices, verifies their identities, and returns authentication results, thereby eliminating the need for manual pairing operations while maintaining security through centralized verification.
Solution Approach 2:
The patent enables devices to perform self-authentication by automatically generating and transmitting authentication requests to the server. The devices independently complete the trust establishment process without requiring manual intervention from users, thus improving ease of operation while maintaining security through automated verification procedures.
2Reliability
If manual pairing is performed for each device, then authentication security is maintained, but time consumption and productivity decrease
Solution Approach 1:
The server acts as a centralized intermediary that can authenticate multiple devices simultaneously or in rapid succession. Instead of requiring sequential manual pairing for each device, the server processes authentication requests automatically, dramatically increasing the productivity of device connections while maintaining security through consistent verification procedures.
Solution Approach 2:
The system performs preliminary authentication setup during device manufacturing or initial registration with the server. This preliminary action stores authentication credentials in advance, allowing devices to be quickly connected to the network without requiring time-consuming manual pairing operations at the point of use, thus improving productivity while maintaining security.
3Adaptability or versatility
If devices from different manufacturers are integrated, then system adaptability improves, but trust establishment difficulty increases
Solution Approach 1:
The patent implements a universal authentication server that can handle devices from different manufacturers using a standardized authentication protocol. The server provides multi-functional capabilities to verify various device types and manufacturers through a common interface, thereby enabling system adaptability across diverse devices while simplifying trust establishment through protocol standardization.
Data Source
AI summary
A method and system for establishing two-way trust between a short-range communication device and a hub device. The method includes: obtaining, from a hub device, a digitally signed request for determining whether the hub device is a trusted communication device for a short-range communication device and a cryptographic key generated by the short-range communication device; generating a response to the request; encrypting the response to the request by using the cryptographic key provided by the short-range communication device, so that the encrypted response can be decrypted only by the short-range communication device; and providing the encrypted response to the hub device. The short-range communication device may decrypt the response and determine whether the hub device is the trusted communication device based on information indicated in the response.


