IoT Hub Trusted Code Execution for Secure Device Updates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Internet of Things (IoT) devices face challenges in implementing a strong security perimeter due to limited resources, leading to higher costs and complexity, and existing techniques rely on localized security measures that are resource-intensive.

Innovation Solution

The system employs a hub that communicates with devices using trusted code protected by encryption and integrity, allowing devices with limited resources to execute and delete messages securely, enhancing the security perimeter without permanent storage, and establishing a secure binding between the hub and devices using binding keys.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If localized security measures are implemented in IoT devices, then security perimeter strength is improved, but device complexity and cost increase

Engineering Contradiction:
Improvesecurity perimeter strengthVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a hub as an intermediary that performs the complex security operations. The hub executes trusted code to establish security perimeters and manage device authentication, while devices themselves remain simple. This mediator approach allows strong security without burdening resource-constrained devices with complex security implementations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the complex security processing functions from the IoT devices and relocates them to the hub. By removing the trusted code execution and security perimeter management from devices, the system achieves strong security through the hub while keeping devices simple and low-cost.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If trusted code is permanently stored in devices, then security is improved, but memory requirements and device cost increase

Engineering Contradiction:
ImprovesecurityVSAvoidmemory
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent implements a mechanism where trusted code is temporarily loaded into device memory, executed to perform security operations, and then discarded. The hub manages the trusted code lifecycle, sending it to devices only when needed for specific security tasks. This approach provides strong security through trusted code execution without requiring devices to permanently store it, thus minimizing memory requirements.

Inventive Principle:
Principle #34Discarding and recovering

3Reliability

If encryption and integrity protection are implemented, then security is improved, but processing capacity and power consumption increase

Engineering Contradiction:
ImprovesecurityVSAvoidpower consumption
Core Design Contradiction:
ReliabilityVSPower

Solution Approach 1:

The hub acts as an intermediary that performs computationally intensive encryption and integrity verification operations. Devices communicate through the hub, which handles the cryptographic processing. This distribution of computational burden allows devices to maintain strong security through encryption and integrity protection without experiencing excessive power consumption, as the heavy processing occurs at the hub with greater resources.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10356129B2Simple trusted transfer to internet of things device
Publication Date: 2019.07.16 SYNOPSYS INC
  • US10356129B2 patent drawing
  • US10356129B2 patent drawing

AI summary

A system and method for updating multiple devices that are coupled to a network by a hub provides a trusted platform module in each of the devices, sends messages from the network to the hub for updating the devices, sends each of the devices messages from the hub to update the device, executes the content of each message in the device to which that message is sent, and deletes each message after it has been executed. Each of the messages preferably includes trusted code, and the device receiving each message executes the trusted code in the trusted platform module. The trusted code may include an update function, an image, and control data, and preferably has integrity. The hub may receive trusted code from a remote server, execute the trusted code to send a message to one of the devices, and then delete the trusted code.