IoT Device Pairing via Server-Mediated Cryptographic Keys
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security measures for remote operations of IoT devices, such as connected vehicles, are inadequate in preventing unauthorized access and unintended commands, which can lead to hazardous situations, as traditional user authentication and authorization methods may not distinguish between authorized users or prevent accidental transmissions from trusted devices.
Innovation Solution
A computer-implemented method and system for securely pairing source devices with IoT devices using cryptographic techniques, such as device authentication and authorization, to ensure that only authorized and authenticated devices can perform specific remote operations, employing techniques like shared key generation and public/private key pairs for secure encryption and validation of remote commands.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional user authentication and authorization methods are used for remote operations of IoT devices, then ease of operation is improved, but security against unauthorized access and accidental commands deteriorates
Solution Approach 1:
The patent segments the authentication process into multiple distinct stages: initial device pairing with cryptographic key exchange, separate user authentication, and specific operation authorization. This multi-layered segmentation ensures that each aspect (device trust, user identity, operation permission) is independently verified, resolving the contradiction by maintaining ease of use through automated processes while significantly improving security through comprehensive verification at each stage.
Solution Approach 2:
The patent implements preliminary pairing and cryptographic key exchange between devices before any remote operations can occur. This preliminary action establishes a secure cryptographic foundation in advance, so that subsequent operations can be securely authenticated without adding complexity to the actual operation process. The pairing resource is generated and stored beforehand, enabling both ease of operation and high security.
2Reliability
If cryptographic pairing resources are generated and stored on devices, then security against unauthorized access is improved, but device complexity increases
Solution Approach 1:
The patent introduces a server as an intermediary that manages the generation, distribution, and storage of cryptographic pairing resources. Rather than requiring each device to independently manage complex cryptographic key pairs, the server acts as a trusted mediator that handles the cryptographic infrastructure. This reduces device complexity while maintaining or improving security, as the server centralizes the management of pairing resources and can implement security policies across the entire system.
Solution Approach 2:
The patent creates cryptographic pairing resources as digital copies that can be securely stored and transmitted. Instead of requiring complex hardware security modules or physical security tokens, the system uses software-based cryptographic copies of keys and pairing information. These digital copies can be securely stored in device memory and used for authentication, significantly reducing hardware complexity while maintaining cryptographic security.
3Measurement precision
If device identifiers are collected and verified through a server, then authorization accuracy is improved, but loss of time increases
Solution Approach 1:
The patent performs device identifier collection, verification, and pairing resource generation as preliminary actions during an initial setup phase. Once the pairing is established and cryptographic resources are exchanged, subsequent remote operations can proceed with faster authentication using the pre-established cryptographic keys. This preliminary verification ensures high authorization accuracy for the initial pairing while minimizing time loss for actual operational commands.
Solution Approach 2:
The patent uses cryptographic copies of device identifiers and authentication tokens that can be quickly verified without requiring real-time server intervention for each operation. The server verifies device identifiers once during pairing and creates cryptographic tokens that prove authorization. These tokens can be validated locally or with minimal server communication, maintaining high authorization accuracy while significantly reducing the time required for subsequent operations compared to repeated full verification cycles.
Data Source
AI summary
A computer-implemented method and system for pairing one or more source devices with at least one target device are disclosed. The computer implemented method for pairing one or more source devices with at least one target device, the method includes receiving device identifiers for the one or more source devices and the at least one target device; generating pairing resource for at least one of the one or more source devices and the at least one target device; and using the pairing resource to allow authenticated and authorized users to perform a remote operation on the at least one target device from the at least one of the one or more source devices.


