IoT Security Descriptor Generation for Low-Complexity Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The deployment of IoT devices requires complex and costly processes for authentication, especially when multiple devices are involved, as manufacturers need to input device-specific information, leading to deployment delays and increased costs.

Innovation Solution

An end device is equipped with a memory device injected with a unique device-specific secret, and a firmware security descriptor (FSD) generator uses publicly-available data such as time, location, and other information to create a security descriptor for authentication, eliminating the need for direct user input and simplifying the authentication process for multiple devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If device-specific information is manually input for each IoT device during authentication, then authentication security is maintained, but deployment complexity and costs increase

Engineering Contradiction:
Improveauthentication securityVSAvoiddeployment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables self-service authentication by having each IoT device automatically generate its own device alias key using its unique device secret and the FSD. The device independently computes authentication credentials without requiring manual configuration or user input, thus maintaining security while eliminating deployment complexity

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The device secret is pre-injected into each IoT device during manufacturing, and the FSD is generated in advance based on publicly available information. These preliminary actions prepare the authentication credentials before deployment, eliminating the need for manual device-specific information input during authentication

Inventive Principle:
Principle #10Preliminary action

2Reliability

If device-specific information is manually input for each IoT device during authentication, then device identity verification is ensured, but deployment time increases

Engineering Contradiction:
Improvedevice identity verificationVSAvoiddeployment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The device secret is pre-injected during manufacturing and the FSD is generated in advance using publicly available information such as device identifiers and timestamps. This preliminary preparation of authentication credentials eliminates time-consuming manual information input during deployment

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Each IoT device autonomously generates its device alias key and authentication credentials using its pre-injected secret and the FSD, without requiring manual configuration. This self-service mechanism ensures device identity verification while dramatically reducing deployment time

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If user-provided device-specific information is required for authentication, then customization flexibility is maintained, but costs increase

Engineering Contradiction:
Improvecustomization flexibilityVSAvoiddeployment cost
Core Design Contradiction:
Adaptability or versatilityVSEase of manufacture

Solution Approach 1:

The system eliminates the need for user-provided device-specific information by having each device automatically generate its authentication credentials using its pre-injected device secret and the FSD. This self-service approach removes customization overhead while maintaining security, thereby reducing deployment costs

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The FSD generator creates a universal authentication mechanism that works across all IoT devices using publicly available information and pre-injected secrets. This universal approach eliminates the need for custom device-specific information collection, reducing deployment costs while maintaining adaptability through the cryptographic key generation process

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11418353B2Security descriptor generation
Publication Date: 2022.08.16 MICRON TECHNOLOGY INC
  • US11418353B2 patent drawing
  • US11418353B2 patent drawing
  • US11418353B2 patent drawing

AI summary

Methods, systems, and devices for security descriptor generation are described. An end device may be authenticated based on a certificate and a device key based on a security descriptor. The security descriptor may be generated based on publicly-available information such as time of day information, geographical information, or a default set of information. The security descriptor may be used for generation of a certificate accessible by a server used for authenticating the device and also may be used by an end device to generate a device key for verification by the server authenticating the device.