IoT Secure Communication Without Local Time

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

IoT devices without a real-time clock (RTC) or unable to synchronize time information face challenges in verifying the validity of digital certificates, which is essential for establishing secure communication with remote servers.

Innovation Solution

A method where a client device sends a query to a server device for proof of identity, which involves prompting a trusted third party, such as a Certification Authority, to provide a proof of identity response. This response is then verified by the client device without relying on absolute time references.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If digital certificates are used for secure communication, then security is improved, but time synchronization becomes necessary which increases device complexity

Engineering Contradiction:
ImprovesecurityVSAvoidtime synchronization capability
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a trusted third party (TTP) as an intermediary that issues time-independent proofs of identity. Instead of directly verifying certificate timestamps, the client device obtains a proof from the TTP that attests to the server's identity without requiring time synchronization. This mediator resolves the contradiction by decoupling security verification from time-dependent operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent transforms the verification parameter from time-based (certificate expiration dates) to identity-based (cryptographic proofs issued by TTP). By changing the fundamental parameter used for verification, the system maintains security while eliminating the requirement for time synchronization, thus resolving the contradiction between security and device complexity.

Inventive Principle:
Principle #35Parameter changes

2Device complexity

If time-independent identity verification is implemented, then device complexity is reduced, but establishing initial trust becomes more difficult

Engineering Contradiction:
Improvetime synchronization requirementVSAvoidinitial trust establishment
Core Design Contradiction:
Device complexityVSEase of operation

Solution Approach 1:

The trusted third party performs preliminary actions by pre-issuing time-independent proofs of identity to server devices before actual communication occurs. These proofs are generated in advance and can be verified by client devices without requiring time synchronization. This preliminary establishment of trust eliminates the need for complex time-dependent verification during actual communication.

Inventive Principle:
Principle #10Preliminary action

3Device complexity

If IoT devices without RTC are used, then device resource constraints are addressed, but certificate validation becomes impossible

Engineering Contradiction:
ImproveRTC hardware requirementVSAvoidcertificate validation capability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The trusted third party acts as a mediator that provides time-independent proofs, allowing IoT devices without RTC to validate server identities. The TTP issues proofs that do not require time-based verification, enabling resource-constrained devices to perform certificate validation without needing hardware clocks or time synchronization capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical time-keeping system (RTC hardware) with a cryptographic verification system based on time-independent proofs. Instead of using physical time-based mechanisms, the system uses mathematical proofs issued by a trusted third party, allowing IoT devices to validate certificates without any time-keeping hardware.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentEP3954083B1Establishing secure communication without local time information
Publication Date: 2025.03.05 SIEMENS AG
  • EP3954083B1 patent drawingFigure 1
  • EP3954083B1 patent drawingFigure 2

AI summary

Methods (100; 300) and devices (10; 30) are provided for establishing secure communication between the devices (10; 30) without relying on local time information. According to the methods (100; 300), a client device (10) which is going to establish the secure communication to a server device (30), is provided by the server device (30) with a proof of its integrity. The proof of integrity of the server device (30) is issued by a trusted third party, TTP, to which both devices (10; 30) have a trust relation.