IoT Electronic Apparatus Secure Key Exchange via Intermediate Server

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In IoT networks, existing technologies face vulnerabilities as encryption keys are transmitted directly between devices, making them susceptible to manipulation by attackers, and manual certificate management is cumbersome, leading to a need for a more secure data transmission and reception method.

Innovation Solution

An electronic apparatus and network system that utilize an intermediate server to securely transmit and receive encryption keys, where the keys are encrypted using an intermediate encryption key stored on both the server and devices, ensuring secure network formation and data exchange.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption keys are transmitted directly between devices in IoT networks, then data transmission can be established, but the system becomes vulnerable to attacker manipulation and key compromise

Engineering Contradiction:
Improvesecurity of key transmissionVSAvoidvulnerability to attacker manipulation
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a server as an intermediary component that facilitates secure key exchange between devices. The server stores encryption keys and manages the key distribution process, preventing direct key transmission between devices that would be vulnerable to attackers. This mediator architecture ensures that keys never traverse the potentially compromised network channel between end devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary key generation and storage on a secure server before any data transmission occurs. Encryption keys are pre-established and stored securely on the server, allowing devices to derive session keys without transmitting actual key material over the network. This preliminary setup eliminates the vulnerability of in-transit key exposure.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If certificate chain technology and manual public key fingerprint verification are implemented, then security is improved, but user operation complexity and management burden increase

Engineering Contradiction:
Improvesecurity verificationVSAvoidmanual certificate management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements automated certificate management where the server automatically handles key generation, storage, and distribution without requiring manual user intervention. The system performs self-service security operations including automatic fingerprint verification and certificate management, eliminating the need for users to manually configure security parameters while maintaining high security standards.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The server acts as a trusted intermediary that automates the certificate verification process. Instead of requiring users to manually verify public key fingerprints, the server mediates the authentication process by automatically verifying device identities and managing certificate chains, thus maintaining security while simplifying user operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11463244B2Electronic apparatus, method of controlling the same, and network system thereof
Publication Date: 2022.10.04 SAMSUNG ELECTRONICS CO LTD
  • US11463244B2 patent drawing
  • US11463244B2 patent drawing
  • US11463244B2 patent drawing

AI summary

An electronic apparatus includes: a communicator configured to communicate with an intermediate server and an other electronic apparatus; a memory in which an encryption key and a decryption key generated by the electronic apparatus are stored; and a controller configured to transmit the encryption key generated by the electronic apparatus to the other electronic apparatus through the intermediate server and performs control such that a network with the other electronic apparatus is formed.