Mediation Server and IC Card for Secure IoT Communication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication systems between communicating devices and services platforms are vulnerable to malicious attacks, particularly due to the lack of encryption and decryption capabilities in these devices, making secure exchanges inconvenient and costly to implement on an industrial scale.

Innovation Solution

A security system that employs a mediation server and an integrated circuit (IC) card to encrypt and decrypt messages between a services platform and a communicating device, leveraging existing key distribution methods used by telecommunications operators, thus simplifying and cost-effectively securing communications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption and decryption means are incorporated in each communicating thing with a personalized encryption key, then security of exchanges is improved, but device complexity and manufacturing cost increase significantly

Engineering Contradiction:
Improvesecurity of exchangesVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a mediation server as an intermediary component that centralizes the encryption and decryption operations. Instead of embedding encryption capabilities directly in each communicating thing, the mediation server acts as a mediator between the services platform and communicating things, handling all cryptographic operations remotely. This resolves the contradiction by maintaining security while eliminating the need for complex encryption hardware in each device.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the encryption and decryption functions from the communicating things and relocates them to the mediation server. The personalized encryption keys are stored in the mediation server rather than being embedded in each device. This extraction eliminates the complexity of incorporating encryption means in each communicating thing while maintaining security through centralized key management.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If encryption and decryption means are incorporated in each communicating thing with a personalized encryption key, then security of exchanges is improved, but manufacturing cost increases significantly

Engineering Contradiction:
Improvesecurity of exchangesVSAvoidmanufacturing cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The mediation server serves as an intermediary that centralizes cryptographic operations, eliminating the need for expensive encryption hardware in each communicating thing. This reduces manufacturing costs significantly, especially for simple communicating things with rudimentary operations, while maintaining security through centralized key management in the mediation server.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The encryption and decryption capabilities are extracted from each communicating thing and consolidated in the mediation server. This extraction eliminates the need to equip each device with expensive cryptographic hardware, thereby significantly reducing manufacturing costs while maintaining security through centralized key storage and management.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If a secure channel with shared encryption key is used between communicating thing and services platform, then security of exchanges is improved, but ease of operation deteriorates due to key distribution complexity

Engineering Contradiction:
Improvesecurity of exchangesVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The mediation server acts as an intermediary that manages key distribution automatically. The services platform does not need to directly distribute encryption keys to each communicating thing; instead, keys are managed centrally in the mediation server which automatically provides encrypted communication to all communicating things. This simplifies operation while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service through automatic key management. The mediation server automatically handles key distribution, storage, and retrieval for all communicating things without requiring manual intervention from the services platform. This automation improves ease of operation while maintaining strong security through centralized key management.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10805277B2System for securing exchanges between a communicating thing and a services platform
Publication Date: 2020.10.13 ORANGE SA
  • US10805277B2 patent drawing
  • US10805277B2 patent drawing
  • US10805277B2 patent drawing

AI summary

A security system makes secure exchanges between a services platform and a communicating thing, which includes a control device. The system further includes a server, referred to as a “mediation” server, which receives a message, referred to as a “first” message, from the services platform, encrypts the first message, and sends the encrypted first message to the communicating thing. The communicating thing is also fitted with an IC card that is distinct from the control device and that decrypts the encrypted first message and sends the decrypted first message to the control device. The encryption and decryption operations are performed by at least one secret key shared between the mediation server and the IC card.