IoT Device Pairing via Server-Mediated Cryptographic Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security measures for remote operations of IoT devices, such as connected vehicles, are inadequate in preventing unauthorized access and unintended commands, which can lead to hazardous situations, as traditional user authentication and authorization methods may not distinguish between authorized users or prevent accidental transmissions from trusted devices.

Innovation Solution

A computer-implemented method and system for securely pairing source devices with IoT devices using cryptographic techniques, such as device authentication and authorization, to ensure that only authorized and authenticated devices can perform specific remote operations, employing techniques like shared key generation and public/private key pairs for secure encryption and validation of remote commands.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional user authentication and authorization methods are used for remote operations of IoT devices, then ease of operation is improved, but security against unauthorized access and accidental commands deteriorates

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the authentication process into multiple distinct stages: initial device pairing with cryptographic key exchange, separate user authentication, and specific operation authorization. This multi-layered segmentation ensures that each aspect (device trust, user identity, operation permission) is independently verified, resolving the contradiction by maintaining ease of use through automated processes while significantly improving security through comprehensive verification at each stage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary pairing and cryptographic key exchange between devices before any remote operations can occur. This preliminary action establishes a secure cryptographic foundation in advance, so that subsequent operations can be securely authenticated without adding complexity to the actual operation process. The pairing resource is generated and stored beforehand, enabling both ease of operation and high security.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If cryptographic pairing resources are generated and stored on devices, then security against unauthorized access is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a server as an intermediary that manages the generation, distribution, and storage of cryptographic pairing resources. Rather than requiring each device to independently manage complex cryptographic key pairs, the server acts as a trusted mediator that handles the cryptographic infrastructure. This reduces device complexity while maintaining or improving security, as the server centralizes the management of pairing resources and can implement security policies across the entire system.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates cryptographic pairing resources as digital copies that can be securely stored and transmitted. Instead of requiring complex hardware security modules or physical security tokens, the system uses software-based cryptographic copies of keys and pairing information. These digital copies can be securely stored in device memory and used for authentication, significantly reducing hardware complexity while maintaining cryptographic security.

Inventive Principle:
Principle #26Copying

3Measurement precision

If device identifiers are collected and verified through a server, then authorization accuracy is improved, but loss of time increases

Engineering Contradiction:
Improveauthorization accuracyVSAvoidloss of time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent performs device identifier collection, verification, and pairing resource generation as preliminary actions during an initial setup phase. Once the pairing is established and cryptographic resources are exchanged, subsequent remote operations can proceed with faster authentication using the pre-established cryptographic keys. This preliminary verification ensures high authorization accuracy for the initial pairing while minimizing time loss for actual operational commands.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses cryptographic copies of device identifiers and authentication tokens that can be quickly verified without requiring real-time server intervention for each operation. The server verifies device identifiers once during pairing and creates cryptographic tokens that prove authorization. These tokens can be validated locally or with minimal server communication, maintaining high authorization accuracy while significantly reducing the time required for subsequent operations compared to repeated full verification cycles.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS10959092B2Method and system for pairing wireless mobile device with IoT device
Publication Date: 2021.03.23 AERIS COMM INC
  • US10959092B2 patent drawing
  • US10959092B2 patent drawing
  • US10959092B2 patent drawing

AI summary

A computer-implemented method and system for pairing one or more source devices with at least one target device are disclosed. The computer implemented method for pairing one or more source devices with at least one target device, the method includes receiving device identifiers for the one or more source devices and the at least one target device; generating pairing resource for at least one of the one or more source devices and the at least one target device; and using the pairing resource to allow authenticated and authorized users to perform a remote operation on the at least one target device from the at least one of the one or more source devices.