Multi-Level Security Identification for Network Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current ID generation and management systems for network-connected devices, such as semiconductor chips, are inadequate for the security requirements of IoT operations, as they often rely on conventional methods like barcodes that fail to provide the necessary multi-level security and compatibility across different environments and protocols.
Innovation Solution
A method and apparatus for generating and managing multiple IDs with different security levels in network-connected devices, utilizing a set of inter-related keys including a main identity and aliases, and performing select-and-mask operations on bit patterns to derive sub-patterns for secure communication, enabling devices to interact with various network entities across different security levels.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional ID methods like barcodes are used for network-connected devices, then ease of manufacture and simplicity are maintained, but security requirements for IoT operations are inadequate
Solution Approach 1:
The patent segments the identification system into multiple hierarchical levels: device ID, group ID, and service ID. Each level serves specific security and functional requirements, allowing the system to achieve high security through layered identification while managing complexity through structured organization of ID types and their corresponding access rights.
2Reliability
If multiple IDs with different security levels are implemented, then security requirements are met, but device complexity increases
Solution Approach 1:
The patent creates a universal ID management framework where a single device can operate with multiple IDs (device ID, group ID, service ID) that serve different functions and security levels. The system universally handles key generation, storage, and authentication across all ID types through integrated hardware modules, reducing the operational complexity despite the multiplicity of identifiers.
Solution Approach 2:
The identification system employs a nested structure where service IDs are contained within group IDs, which are in turn contained within device IDs. This hierarchical nesting allows the system to manage multiple security levels by organizing keys and identifiers in nested containers, making complex key management more systematic and tractable.
3Reliability
If inter-related keys with aliases are used for high security communication, then authentication security is enhanced, but memory allocation and data structure management become more complex
Solution Approach 1:
The patent performs preliminary actions by pre-generating and storing multiple keys and their corresponding aliases in the device's secure memory before deployment. The system pre-establishes the relationships between device IDs, group IDs, and service IDs, along with their cryptographic keys, allowing for rapid authentication without complex real-time key generation, thus enhancing security while managing data structure complexity through advance preparation.
4Adaptability or versatility
If select-and-mask operations are performed on bit patterns to derive sub-patterns, then key generation flexibility and security are improved, but processing time and computational complexity increase
Solution Approach 1:
The system performs select-and-mask operations on bit patterns during the initial key generation and provisioning phase, storing the resulting sub-patterns and derived keys in secure memory. By pre-computing these cryptographic transformations before deployment, the system achieves key generation flexibility and security without incurring processing time penalties during actual authentication operations, as the complex bit manipulation has already been performed in advance.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A network-connected device is identified by multiple keys for multiple security levels in a network. From the network, the device detects a request directed at the device. The device identifies, from the request, a source entity that sent the request and a security level specified by the request. Among the plurality keys that identify the device for different levels of security, the device determines one or more of the keys to identify the device according to at least the security level. In response to the security level being a high security level, the device establishes a network session with the high security level to communicate with the source entity using a set of inter-related keys among the plurality of keys.