IoT Communication with Selective Authentication for Secure Data Exchange

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In IoT systems, mutual authentication is often required even for low confidentiality information transmission, leading to excessive suppression of communication freedom and reduced convenience.

Innovation Solution

Implement a system where communication devices and IoT devices store lists indicating first information exchangeable without mutual authentication and second information exchangeable with mutual authentication, allowing selective information exchange based on these lists.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If mutual authentication is performed in all situations, then security is improved, but communication freedom is suppressed

Engineering Contradiction:
ImprovesecurityVSAvoidcommunication freedom
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments information into two categories: first information that can be exchanged without mutual authentication, and second information that requires mutual authentication. This segmentation allows the system to apply authentication selectively rather than universally, thereby maintaining security for sensitive data while enabling free communication for non-sensitive data.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces dynamic decision-making based on information type. The communication device determines whether to perform mutual authentication dynamically according to the category of information being exchanged, rather than following a static authentication policy for all communications.

Inventive Principle:
Principle #15Dynamics

2Reliability

If mutual authentication is performed in all situations, then security is improved, but convenience is reduced

Engineering Contradiction:
ImprovesecurityVSAvoidconvenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

By dividing information into first information (low confidentiality) and second information (high confidentiality), the system eliminates the need for authentication overhead when exchanging first information, thereby improving convenience without compromising security for second information.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies authentication partially rather than excessively. Instead of performing mutual authentication for all information exchanges, the system performs authentication only when necessary (for second information), reducing the burden on users while maintaining adequate security.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP4589880A1IoT system and program
Publication Date: 2025.07.23 KK TOSHIBA
  • EP4589880A1 patent drawingFigure 1
  • EP4589880A1 patent drawingFigure 2
  • EP4589880A1 patent drawingFigure 3

AI summary

A communication device is capable of identifying a user via a security device. An IoT device includes a secure element that performs an encryption process for establishing a secure channel with the communication device. The communication device and the IoT device each store a list indicating first information and second information. The first information is information that is exchangeable when no mutual authentication is performed between the communication device and the IoT device. The second information is information that is exchangeable when the mutual authentication is performed. The communication device acquires the list from the IoT device, and, based on the acquired list, transmits the first information to the IoT device when the mutual authentication is not performed and transmits the second information to the IoT device when the mutual authentication is performed. The IoT device acquires the list from the communication device, and, based on the acquired list, transmits the first information to the communication device when the mutual authentication is not performed and transmits the second information to the communication device when the mutual authentication is performed.