LPWAN Communication Interface With Trusted Execution for Secure Key Updates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security architectures for Low Power Wide Area Networks (LPWAN) in IoT devices are vulnerable to physical attacks, and the use of Secure Elements (SEs) is costly, energy-intensive, and limits upgradability, making them unsuitable for the resource-constrained IoT environment.

Innovation Solution

A communication interface with a trusted execution part and an untrusted execution part, integrated into a single semiconductor chip, that securely manages cryptographic operations and key updates over LPWAN protocols, eliminating the need for separate SEs by using a reprogrammable memory section for encrypted keys and code, enabling secure and efficient key management and upgrades.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If Secure Elements (SEs) are used for physical protection of cryptographic keys, then security against physical attacks is improved, but hardware cost, energy consumption, and device complexity increase

Engineering Contradiction:
ImprovesecurityVSAvoidhardware complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the Secure Element functionality directly into the microcontroller unit, creating an integrated security architecture. The cryptographic keys are stored in protected memory regions within the MCU itself, eliminating the need for separate SE hardware components. This integration maintains security while reducing hardware complexity and cost.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The microcontroller unit is designed to perform multiple functions including both application processing and secure cryptographic operations. The MCU's processor executes cryptographic algorithms while its protected memory stores keys, making the device self-sufficient without requiring dedicated SE hardware for basic security operations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If Secure Elements (SEs) are used for key protection, then security is improved, but energy consumption increases

Engineering Contradiction:
ImprovesecurityVSAvoidenergy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

By combining security functions into the MCU, the patent eliminates the need for separate SE power management circuits and reduces overall system energy consumption. The integrated architecture allows the processor to handle cryptographic operations using the same power supply as application code, reducing redundant power management overhead.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If Secure Elements (SEs) are used for key storage, then security is improved, but upgradability and adaptability are limited

Engineering Contradiction:
ImprovesecurityVSAvoidupgradability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic key management where cryptographic keys can be generated, updated, and rotated through software processes. The protected memory and processor work together to allow key refresh operations and algorithm updates without requiring hardware changes, enabling the system to adapt to new security requirements over time.

Inventive Principle:
Principle #15Dynamics

4Reliability

If separate Secure Elements are used, then security is improved, but hardware cost increases

Engineering Contradiction:
ImprovesecurityVSAvoidhardware cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent consolidates security functionality into the existing MCU architecture, eliminating the need for separate SE components. This integration reduces bill of materials costs and simplifies manufacturing processes while maintaining adequate security through protected memory regions and secure boot mechanisms.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11233771B2Communication interface for a low power wide area network, wireless device and server using such communication interface
Publication Date: 2022.01.25 ACTILITY
  • US11233771B2 patent drawing
  • US11233771B2 patent drawing
  • US11233771B2 patent drawing

AI summary

The present invention relates to a communication interface (200) for supporting communication between a wireless device (101, 102, 103) and a server (121) over a low power wide area network, LPWAN, comprising: an untrusted execution part (201) configured to operate in accordance with an LPWAN communication protocol stack (203) including at least one secured LPWAN protocol using cryptographic primitives; a memory (205) for storing computer code (206) and at least one cryptographic key (207, 208, 209) in an encrypted form; a trusted execution part (202) incorporating a root secret (210) for decrypting the at least one cryptographic key (207, 208, 209) from the memory (205), wherein the trusted execution part (202) is configured to execute the cryptographic primitives of the at least one secured LPWAN protocol using the decrypted cryptographic key and computer code (206) from the memory (205).