IoT MPC Security for Automated MitM-Resistant Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing IoT security solutions, such as PKI and DH key exchange, are resource-intensive, vulnerable to man-in-the-middle attacks, and require human intervention, making them unsuitable for decentralized IoT networks.

Innovation Solution

A decentralized multi-party computation (MPC) method for secure peer-to-peer communication between IoT devices, using a Diffie-Hellman key exchange with automatic SAS verification through MPC modules, eliminating the need for PKI and human interaction.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If PKI-based centralized security solutions are used in IoT devices, then authentication and security validation are improved, but device complexity and resource consumption increase significantly

Engineering Contradiction:
Improveauthentication securityVSAvoidsecurity infrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the trusted third party (CA) from the security infrastructure, removing the need for centralized certificate validation. Devices perform direct mutual authentication using ephemeral key pairs and SAS comparison, eliminating the complex PKI hierarchy while maintaining security reliability

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system enables devices to perform self-authentication without external CA intervention. Each device generates its own key pairs and validates authentication through local SAS comparison, making the security system self-sufficient and reducing infrastructure complexity

Inventive Principle:
Principle #25Self-service

2Reliability

If manual SAS verification is implemented in key exchange protocols, then security against MitM attacks is improved, but ease of operation deteriorates due to required human intervention

Engineering Contradiction:
Improveprotection against MitM attacksVSAvoidautomation level
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system implements automatic SAS verification where devices autonomously compare authentication strings without human intervention. The SAS is automatically generated, transmitted, and validated through cryptographic protocols, maintaining MitM protection while achieving full automation suitable for IoT deployments

Inventive Principle:
Principle #25Self-service

3Reliability

If PKI-based authentication is deployed in resource-constrained IoT devices, then security validation is improved, but energy consumption and processing load increase

Engineering Contradiction:
Improvesecurity validationVSAvoiddevice energy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system uses ephemeral key pairs that are generated and discarded for each authentication session, replacing expensive long-term PKI infrastructure. The temporary nature of these cryptographic objects reduces computational overhead and energy consumption while maintaining security validation

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The patent changes the cryptographic parameters from fixed long-term keys to dynamic ephemeral keys with shorter lifecycles. This parameter change reduces the computational burden of key management and certificate validation, lowering energy consumption in resource-constrained devices

Inventive Principle:
Principle #35Parameter changes

4Reliability

If centralized CA-based certificate validation is used, then security certificate authenticity is improved, but the system creates single points of failure and reduces network resilience

Engineering Contradiction:
Improvecertificate authenticityVSAvoidnetwork resilience
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent removes the centralized CA from the authentication architecture, eliminating the single point of failure. Devices authenticate each other directly through mutual key exchange and SAS verification, distributing trust across the network and improving resilience to attacks and failures

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12388627B2Internet of Things security with multi-party computation (MPC)
Publication Date: 2025.08.12 U PORTO - UNIV DO PORTO
  • US12388627B2 patent drawing
  • US12388627B2 patent drawing
  • US12388627B2 patent drawing

AI summary

A method and device for establishing a communication along a communications channel between a first device (200A) and a second device (200B). The method comprises mutually discovering the first device (200A) and the second device (200B), validating (F5, F6, F7) the communications channel between the first device (200A) and the second device (200B) by exchange of data messages, exchanging a secret between the first device (200A) and the second device (200B) and then exchanging encrypted messages along the communications channel.