LPWAN Message Security via Dynamic Key Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In LPWAN communications, the low bandwidth makes it challenging to implement secure key exchanges between mobile electronic devices and servers, as existing fixed key solutions are vulnerable to unauthorized access.

Innovation Solution

A process that generates a dynamic and transient key using an indicator element within the message, allowing for secure decryption of encrypted data while minimizing bandwidth usage by incorporating a counter for message exchanges.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If fixed keys are stored on the server and mobile device for security, then communication security is improved, but vulnerability to unauthorized key retrieval increases

Engineering Contradiction:
Improvecommunication securityVSAvoidunauthorized key retrieval
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent transforms static fixed keys into dynamic transient keys that change with each message exchange. The complete indicator (counter value) evolves over time, and keys are derived from this changing indicator rather than from predetermined fixed values, making the system dynamic and adaptive to each communication session.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameter of key stability by introducing time-varying counter values. Instead of using constant keys, the system uses keys that are periodically updated based on the counter increment, transforming the key parameter from static to dynamic, thereby reducing the window of opportunity for unauthorized retrieval.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If multiple information exchanges are performed for key establishment, then security is improved, but bandwidth consumption increases beyond LPWAN capacity

Engineering Contradiction:
ImprovesecurityVSAvoidbandwidth usage
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent merges the utility message content and security information into a single integrated message structure. The indicator element is embedded within the same message frame as the encrypted payload, eliminating the need for separate key exchange messages and reducing overall bandwidth consumption while maintaining security functionality.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The message structure is designed to serve multiple functions simultaneously: it carries the encrypted utility information, includes the indicator element for key derivation, and provides frame structure for protocol compliance. This multi-functionality eliminates the need for separate dedicated key exchange messages.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Quantity of substance

If only useful information is sent in messages, then bandwidth efficiency is improved, but communication security deteriorates

Engineering Contradiction:
Improvebandwidth efficiencyVSAvoidcommunication security
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The patent combines useful information and security information in the same message transmission. The indicator element that enables key derivation is embedded within the message frame alongside the encrypted payload, allowing security functionality to be achieved without requiring separate dedicated security messages.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11974119B2Device and process for processing a message and sending a LPWAN message
Publication Date: 2024.04.30 IDEMIA FRANCE SAS
  • US11974119B2 patent drawing
  • US11974119B2 patent drawing
  • US11974119B2 patent drawing

AI summary

A process for processing a received message, where the message includes encrypted data and at least one indicator element, is disclosed. The process includes generating a complete indicator from data stored in the electronic device and from the received indicator element, generating a key from the complete indicator, and decrypting the encrypted data using said key. The disclosure also relates to a corresponding sending process.