IoT Device Pairing via Proof of Possession Tokens

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing IoT network security solutions lack sufficient security, confidentiality, and authorization constraints, particularly in complex IoT fog and network settings, where conventional authentication services like OAuth2 are inadequate for ensuring secure interactions between devices.

Innovation Solution

The integration of proof of possession tokens and access control mechanisms, leveraging authentication services like OpenID-Connect and OAuth2, to establish trusted pairing relationships between IoT devices, enabling secure data exchange and authentication even without direct sessions, using decentralized systems and intermediary devices for enhanced security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional authentication services like OAuth2 are used in IoT networks, then ease of operation is improved, but security and authorization constraints deteriorate

Engineering Contradiction:
Improveauthentication processVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an authentication service as an intermediary between IoT devices, utilizing established protocols like OAuth2 and OpenID-Connect. This intermediary handles the complex authentication logic, providing both ease of operation for devices while maintaining strong security through standardized protocols that include proper token management and authorization frameworks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent transforms authentication parameters by converting device identities into standardized token formats (access tokens, refresh tokens) that carry specific claims and permissions. This parameter transformation enables secure authentication state representation while maintaining operational simplicity through uniform token handling across diverse IoT devices.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If decentralized authentication systems are implemented in IoT fog networks, then adaptability is improved, but device complexity increases

Engineering Contradiction:
Improvenetwork configuration flexibilityVSAvoidauthentication mechanism
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal authentication service that can operate in multiple IoT network configurations including fog computing, edge computing, and cloud-based architectures. The same authentication mechanisms (OAuth2, OpenID-Connect) serve diverse deployment scenarios, providing adaptability without requiring device-specific complex implementations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

IoT devices are equipped with self-service authentication capabilities through standardized libraries that automatically handle token acquisition, validation, and refresh processes. This self-service approach reduces the operational complexity for device manufacturers while maintaining high adaptability across different network configurations.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11509644B2Establishing connections between IOT devices using authentication tokens
Publication Date: 2022.11.22 INTEL CORP
  • US11509644B2 patent drawing
  • US11509644B2 patent drawing
  • US11509644B2 patent drawing

AI summary

Various systems and methods of establishing a trusted pairing relationship between IoT devices, through the exchange of authentication service proof of possession tokens, are described herein. In an example, a trusted pairing relationship is established between IoT devices, through access control and credential resources based on communication via intermediary devices and services. The IoT devices may request or receive access to or information from a resource based on the trusted relationship.