IoT Security Ecosystem with Digital Certificate Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing and securing Internet of Things (IoT) devices is challenging due to issues with unauthorized access, data control, and firmware updates, particularly in devices like automobiles where remote hacking can occur, necessitating robust identity management and secure communication protocols.

Innovation Solution

A security ecosystem using a central server with an attribute authority, public key infrastructure, and cryptographic keys to provision unique identities and certificates to IoT devices, establishing secure communication lines and preventing unauthorized access, while enabling secure firmware updates and data protection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional communication protocols are used for IoT devices, then device connectivity and ease of operation are improved, but security vulnerabilities and unauthorized access risks increase

Engineering Contradiction:
Improvedevice connectivityVSAvoidunauthorized access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary authentication and certificate issuance before establishing communication. IoT devices are provisioned with digital certificates and cryptographic keys in advance, and the system validates device identities before allowing network access, preventing unauthorized devices from connecting in the first place

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system introduces a certificate authority and authentication server as intermediary components between IoT devices and the network. These intermediaries verify device identities, manage digital certificates, and control access permissions, creating a security layer that maintains connectivity while blocking unauthorized access

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If open firmware update mechanisms are used, then ease of updating and adaptability are improved, but device security and reliability deteriorate due to unauthorized firmware installation

Engineering Contradiction:
Improvefirmware update capabilityVSAvoiddevice security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary verification of firmware authenticity before installation. Digital signatures are validated and cryptographic verification is performed in advance of the actual firmware update process, ensuring that only authorized and verified firmware can be installed on devices

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms where the authentication server verifies firmware signatures with devices, and the system monitors and tracks firmware update processes. This feedback loop ensures that unauthorized firmware attempts are detected and rejected, maintaining security while allowing legitimate updates

Inventive Principle:
Principle #23Feedback

3Reliability

If centralized security management is implemented, then security control and reliability are improved, but system complexity and difficulty of operation increase

Engineering Contradiction:
Improvesecurity controlVSAvoidsystem management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements universal authentication protocols and standardized certificate management that can be applied across diverse IoT devices and platforms. The centralized security management uses common cryptographic standards and unified policies that work across different device types, reducing the need for device-specific security configurations and simplifying overall system management

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3433791B1System and method for internet of things (IOT) security and management
Publication Date: 2022.01.12 T CENT
  • EP3433791B1 patent drawingFigure 1
  • EP3433791B1 patent drawingFigure 2
  • EP3433791B1 patent drawingFigure 3

AI summary

System and method for establishing a secure communication between a plurality of Internet of Things (IoT) devices, includes issuing a first digital certificate to the second IoT device, inviting the second IoT device by the first IoT device to establish a communication line with the first IoT device by receiving a digital token from the second IoT device, authenticating the second IoT device using the unique identification and cryptographic key of the second IoT device; establishing a secure communication line between the first IoT device and the second IoT device by authenticating the established communication line and issuing a second digital certificate to the communication line between the first IoT device and the second IoT device; and preventing a third IoT device for which a secure communication line to the first or second IoT device has not been established from communicating with the first or second IoT device.