LPWAN Communication Interface With Trusted Execution for Secure Key Updates
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security architectures for Low Power Wide Area Networks (LPWAN) in IoT devices are vulnerable to physical attacks, and the use of Secure Elements (SEs) is costly, energy-intensive, and limits upgradability, making them unsuitable for the resource-constrained IoT environment.
Innovation Solution
A communication interface with a trusted execution part and an untrusted execution part, integrated into a single semiconductor chip, that securely manages cryptographic operations and key updates over LPWAN protocols, eliminating the need for separate SEs by using a reprogrammable memory section for encrypted keys and code, enabling secure and efficient key management and upgrades.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If Secure Elements (SEs) are used for physical protection of cryptographic keys, then security against physical attacks is improved, but hardware cost, energy consumption, and device complexity increase
Solution Approach 1:
The patent merges the Secure Element functionality directly into the microcontroller unit, creating an integrated security architecture. The cryptographic keys are stored in protected memory regions within the MCU itself, eliminating the need for separate SE hardware components. This integration maintains security while reducing hardware complexity and cost.
Solution Approach 2:
The microcontroller unit is designed to perform multiple functions including both application processing and secure cryptographic operations. The MCU's processor executes cryptographic algorithms while its protected memory stores keys, making the device self-sufficient without requiring dedicated SE hardware for basic security operations.
2Reliability
If Secure Elements (SEs) are used for key protection, then security is improved, but energy consumption increases
Solution Approach 1:
By combining security functions into the MCU, the patent eliminates the need for separate SE power management circuits and reduces overall system energy consumption. The integrated architecture allows the processor to handle cryptographic operations using the same power supply as application code, reducing redundant power management overhead.
3Reliability
If Secure Elements (SEs) are used for key storage, then security is improved, but upgradability and adaptability are limited
Solution Approach 1:
The patent implements dynamic key management where cryptographic keys can be generated, updated, and rotated through software processes. The protected memory and processor work together to allow key refresh operations and algorithm updates without requiring hardware changes, enabling the system to adapt to new security requirements over time.
4Reliability
If separate Secure Elements are used, then security is improved, but hardware cost increases
Solution Approach 1:
The patent consolidates security functionality into the existing MCU architecture, eliminating the need for separate SE components. This integration reduces bill of materials costs and simplifies manufacturing processes while maintaining adequate security through protected memory regions and secure boot mechanisms.
Data Source
AI summary
The present invention relates to a communication interface (200) for supporting communication between a wireless device (101, 102, 103) and a server (121) over a low power wide area network, LPWAN, comprising: an untrusted execution part (201) configured to operate in accordance with an LPWAN communication protocol stack (203) including at least one secured LPWAN protocol using cryptographic primitives; a memory (205) for storing computer code (206) and at least one cryptographic key (207, 208, 209) in an encrypted form; a trusted execution part (202) incorporating a root secret (210) for decrypting the at least one cryptographic key (207, 208, 209) from the memory (205), wherein the trusted execution part (202) is configured to execute the cryptographic primitives of the at least one secured LPWAN protocol using the decrypted cryptographic key and computer code (206) from the memory (205).


