IoT Registry Apparatus Offloading Authentication Complexity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In the Internet of Things (IoT) environment, establishing trusted communication between agent devices and application providing apparatuses is challenging due to the limited processing capabilities of many agent devices, leading to increased costs and complexity in resource allocation and deployment.

Innovation Solution

A registry apparatus maintains a device registry with authentication information for agent devices, facilitating authentication and key management to enable trusted communication between agent devices and application providing apparatuses, allowing for the use of off-the-shelf devices with various application providers without the need for complex resources on the agent devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If authentication resources are provided in the agent device to establish trusted relationship with the application providing apparatus, then security and trust are improved, but device cost and complexity increase significantly

Engineering Contradiction:
Improvetrusted relationshipVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the authentication and key management functions from the agent device and relocates them to a external key management server. The agent device retains only minimal authentication credentials, while the server handles complex cryptographic operations, certificate management, and key distribution. This extraction resolves the contradiction by maintaining security (through centralized authentication) while dramatically reducing device complexity and cost.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a key management server as an intermediary between the agent device and the application providing apparatus. This mediator handles all authentication requests, verifies device identities, manages cryptographic keys, and establishes trusted relationships. The intermediary absorbs the computational complexity and resource requirements, allowing agent devices to remain simple while maintaining secure communication through the mediation of the authentication server.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If complex authentication resources are embedded in agent devices, then authentication security is improved, but manufacturing cost increases

Engineering Contradiction:
Improveauthentication securityVSAvoidmanufacturing cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent extracts complex authentication resources from the agent device manufacturing process and consolidates them in a centralized key management server. Agent devices are manufactured with only basic identification credentials, while the server is provisioned with comprehensive cryptographic infrastructure, certificate authorities, and key management capabilities. This separation dramatically reduces manufacturing costs for agent devices while maintaining strong authentication security through the centralized server.

Inventive Principle:
Principle #2Taking out (Extraction)

3Device complexity

If agent devices have limited processing capability, then device cost is reduced, but ability to establish trusted communication deteriorates

Engineering Contradiction:
Improveprocessing capabilityVSAvoidtrusted communication
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent introduces a key management server as a computational intermediary that performs all heavy cryptographic operations, authentication verification, and key management tasks. Agent devices with limited processing capability simply present their identification credentials to the server, which then handles the complex authentication protocols and establishes secure communication channels. This intermediary approach allows simple, low-cost agent devices to participate in trusted communication without requiring sophisticated local processing capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts computationally intensive authentication and encryption functions from the agent device and relocates them to the key management server. The agent device retains only minimal cryptographic capabilities for signing and verifying authentication tokens, while the server performs all complex operations including key generation, certificate management, and secure session establishment. This extraction enables trusted communication with devices that have very limited processing power.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11240222B2Registry apparatus, agent device, application providing apparatus and corresponding methods
Publication Date: 2022.02.01 ARM IP
  • US11240222B2 patent drawing
  • US11240222B2 patent drawing
  • US11240222B2 patent drawing

AI summary

A registry apparatus is provided for maintaining a device registry of agent devices for communicating with application providing apparatus. The registry comprises authentication information for uniquely authenticating at least one trusted agent device. In response to an authentication request from an agent device, the authentication information for that device is obtained from the registry, and authentication of the agent device is performed. If the authentication is successful, then application key information is transmitted to at least one of the agent device and the application providing apparatus.