Mobile Device Authentication via Mutable Code Key Derivation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Constrained mobile devices, lacking tamper-resistant hardware, face challenges in authenticating to mobile communications networks, as they do not support the same level of cryptographic security as conventional devices, especially in non-cellular access networks like IEEE802.11 based WLANs.
Innovation Solution
A method and apparatus for generating authentication credentials using a first key derived from the measurement of mutable code and a unique device secret, which is then used to create a symmetric second key for authenticating the device to a mobile communications network, eliminating the need for pre-provisioned security hardware and allowing secure authentication even in constrained devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If constrained mobile devices without tamper-resistant hardware are used, then device complexity and cost are reduced, but cryptographic security and authentication reliability deteriorate
Solution Approach 1:
The patent introduces a mediator entity (authentication server or network function) that performs cryptographic operations on behalf of constrained devices. The mediator has access to the device's mutable code measurements and unique device secrets, generates authentication credentials, and manages key derivation. This allows constrained devices without tamper-resistant hardware to achieve authentication reliability comparable to devices with secure elements, as the cryptographic security functions are offloaded to the trusted mediator.
Solution Approach 2:
The patent replaces the mechanical/physical security mechanism (tamper-resistant hardware, secure elements, or trusted platform modules) with a software-based cryptographic approach. Instead of relying on hardware security modules to protect private keys, the system uses software-based key derivation from mutable code measurements and unique device secrets, managed by a trusted authentication server. This substitution enables constrained devices to achieve cryptographic security without requiring complex hardware security infrastructure.
2Reliability
If traditional security hardware is required for authentication, then cryptographic security is improved, but device cost and complexity increase
Solution Approach 1:
The patent extracts the cryptographic security functions from the constrained device itself and places them in a separate authentication server or network function. The device only needs to provide measurements of its mutable code and its unique device secret, while the authentication server performs the complex cryptographic operations for generating authentication credentials and deriving session keys. This extraction eliminates the need for constrained devices to have embedded tamper-resistant hardware, reducing device complexity and cost while maintaining cryptographic security through the trusted server infrastructure.
Solution Approach 2:
The authentication server provides universal cryptographic security services to multiple constrained devices without requiring each device to have its own dedicated security hardware. The server can authenticate numerous devices using the same infrastructure, deriving unique authentication credentials for each device based on their individual mutable code measurements and device secrets. This multi-functional approach allows cryptographic security to be provided universally across the network, eliminating the need for expensive security hardware in each individual constrained device.
3Adaptability or versatility
If dynamic key generation based on mutable code is implemented, then authentication flexibility and adaptability are improved, but computational requirements and processing time increase
Solution Approach 1:
The patent performs preliminary actions by pre-generating and storing measurements of mutable code in the constrained device during manufacturing or initial setup. These pre-computed measurements are ready for immediate use during authentication operations. When authentication is required, the device simply provides these pre-prepared measurements along with its unique device secret, and the authentication server performs the key derivation. This preliminary preparation reduces the computational burden during actual authentication, minimizing processing time while maintaining the flexibility of dynamic key generation based on mutable code.
Data Source
AI summary
According to an example aspect of the present invention, there is provided method, comprising: generating a first key based on a first input specific to a mobile device, wherein the first input comprises measurement of mutable code of the mobile device and a unique device secret, generating a symmetric second key on the basis of the first key and a second input specific to the mobile device, and generating authentication credentials on the basis of the second key for authenticating the mobile device to a mobile communications network.


