Self-configuring Key Management for IoT Inter-domain Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Internet of Things (IoT) networks face challenges in interoperability and scalable key management due to varying device management schemes and security mechanisms across different IoT frameworks, which complicates network expansion and security policy enforcement as the network grows in size and complexity.

Innovation Solution

A self-configuring key management system that integrates symmetric and asymmetric cryptography, allowing for dynamic assignment of key management roles and credentials based on network complexity, enabling secure communication across diverse IoT devices and networks through a common key management context structure that accommodates multiple transport and network technologies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If different IoT frameworks use different device management schemes and security mechanisms, then each framework can be optimized for its specific requirements, but interoperability between IoT networks deteriorates

Engineering Contradiction:
Improveframework-specific optimizationVSAvoidinteroperability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a key management service as an intermediary component that mediates between different IoT frameworks and their security requirements. This service provides a standardized interface for key generation, storage, and management across diverse frameworks, enabling interoperability while allowing each framework to maintain its own security optimizations through the unified key management interface

Inventive Principle:
Principle #24Intermediary (Mediator)

2Quantity of substance

If IoT networks scale up by adding hundreds of thousands of nodes, then network coverage and capability improve, but key management complexity increases dramatically

Engineering Contradiction:
Improvenetwork sizeVSAvoidkey management complexity
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The patent segments key management complexity by introducing hierarchical key management structures and separating key generation, storage, and usage functions across different system components. This segmentation allows large-scale IoT networks to manage cryptographic keys through distributed, modular operations rather than centralized complex management

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The key management service acts as an intermediary that abstracts the complexity of managing cryptographic keys in large-scale networks. It provides standardized interfaces for key operations, handling the complexity internally while presenting simple, consistent functionality to numerous network nodes

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If diverse IoT devices with different transport technologies are integrated, then system versatility improves, but consistent security policy enforcement becomes difficult

Engineering Contradiction:
Improvedevice compatibilityVSAvoidsecurity policy enforcement
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent implements a universal key management service that handles multiple transport technologies (Bluetooth, Wi-Fi, cellular, etc.) through a single standardized interface. This multi-functional service maintains consistent security policies across diverse devices and transport protocols, eliminating the need for separate security management for each technology

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10469464B2Self-configuring key management system for an internet of things network
Publication Date: 2019.11.05 INTEL CORP
  • US10469464B2 patent drawing
  • US10469464B2 patent drawing
  • US10469464B2 patent drawing

AI summary

In one embodiment, a method includes receiving, in a first device, at least one of a first symmetric key and a first asymmetric key in a common key management structure, the common key management structure to accommodate asymmetric keys and symmetric keys, and further including security policy information to enable communication between the first device of a first domain of an Internet of Things (IoT) network and a second device of a second domain of the IoT network according to an inter-domain security policy; and sending a first message directly from the first device to the second device according to the security policy information of the common key management structure. Other embodiments are described and claimed.