Wireless Mobile Device Encryption Key Distribution for IoT Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing contactless payment systems for IoT devices rely on dedicated communication infrastructure for encryption key distribution, limiting deployment and increasing costs due to the need for custom or private communication networks.

Innovation Solution

A method using a wireless mobile device, such as a smartphone, to request and transmit encryption keys from a key management system to IoT systems, eliminating the need for dedicated infrastructure by utilizing cellular networks and near-field communication, and ensuring secure key distribution based on geographic location and service type.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If dedicated communication infrastructure is used for encryption key distribution, then security and reliability are improved, but device complexity and infrastructure costs increase

Engineering Contradiction:
Improveencryption key distribution securityVSAvoidcommunication infrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a key distribution server as an intermediary component that manages encryption key distribution centrally. This server acts as a mediator between the IoT system and mobile devices, handling key generation, storage, and distribution without requiring complex point-to-point communication infrastructure between all system components. The server consolidates the security infrastructure into a single manageable entity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent makes mobile devices serve multiple functions: they act as both the communication endpoint for IoT services and the secure storage container for encryption keys. The mobile device's existing security infrastructure (secure element, trusted execution environment) is leveraged to store and manage IoT-specific encryption keys, eliminating the need for separate dedicated key storage hardware at each IoT node.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If dedicated communication infrastructure is deployed, then key distribution reliability is improved, but ease of manufacture and deployment are worsened

Engineering Contradiction:
Improvekey distribution reliabilityVSAvoidsystem deployment ease
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent enables mobile devices to automatically obtain encryption keys through standard communication channels without requiring manual configuration or dedicated infrastructure setup. The key distribution server automatically detects mobile devices, authenticates them, and distributes appropriate encryption keys using existing communication protocols, making the system self-configuring and easy to deploy.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent pre-provisions mobile devices with security credentials and establishes trust relationships before IoT deployment. The key management system prepares encryption keys and security configurations in advance, storing them securely in the mobile device's secure element prior to actual IoT operation, eliminating the need for complex post-deployment infrastructure setup.

Inventive Principle:
Principle #10Preliminary action

3Ease of manufacture

If encryption keys are stored in mobile devices, then infrastructure costs are reduced, but measurement precision of key security is worsened

Engineering Contradiction:
Improveinfrastructure costVSAvoidkey security verification
Core Design Contradiction:
Ease of manufactureVSMeasurement precision

Solution Approach 1:

The key distribution server acts as a trusted intermediary that verifies and manages encryption keys stored in mobile devices. It maintains the master key hierarchy, performs cryptographic verification, and validates key usage, providing centralized security measurement and verification without requiring additional physical infrastructure at each deployment location.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces physical security infrastructure (dedicated key management hardware, secure communication channels) with cryptographic software-based solutions running on mobile devices. Security is enforced through software-based cryptographic verification, digital signatures, and protocol-level authentication, substituting mechanical/physical security systems with computational security mechanisms.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This approach expands the capacity and speed of updating information in IoT systems, reduces infrastructure costs, and enables secure key distribution without relying on custom communication networks, enhancing the deployment and efficiency of contactless payment systems.

Implementation Method 1

requesting IoT systems keys from a key management system with a first radio transceiver

Methodology Applied
Scientific EffectElectromagnetic radiation: Electromagnetic Induction

Implementation Method 2

The IoT system keys are transmitted from the wireless mobile device to the recipient IoT system with the second radio transceiver

Methodology Applied
Scientific EffectElectromagnetic radiation: Electromagnetic Induction

Data Source

PatentUS12137159B2Encryption key distribution via wireless mobile devices to internet of things (IoT) systems
Publication Date: 2024.11.05 CENT DE PESQUISAS AVANCADES WERNHER VON BRAUN
  • US12137159B2 patent drawing
  • US12137159B2 patent drawing
  • US12137159B2 patent drawing

AI summary

A wireless mobile device, and a computer-implemented method of distributing encryption keys to Internet of Things (IoT) systems begins with the wireless mobile device requesting IoT systems keys from a key management system with a first radio transceiver. Next, the requested IoT systems keys are received. Each of the IoT systems keys is i) encrypted with a public key from a recipient IoT system, and ii) signed by the key management system. In response to the wireless mobile device being located in proximity to the recipient IoT system, identifiers of the IoT system are received by the wireless mobile device with a second radio transceiver. The wireless mobile device selects at least one of the IoT systems keys that corresponds to the identifiers. The IoT system keys are transmitted from the wireless mobile device to the recipient IoT system with the second radio transceiver.