Multicast Security Grouping for IoT Memory Constraints

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing multicast transmission techniques face challenges in secure communication and efficient management of cryptographic keying materials in constrained environments, such as those in IoT applications, particularly in lighting systems, where memory resources are limited and secure encryption is required.

Innovation Solution

A method that associates different network nodes with distinct cryptographic keying materials and multicast IP addresses, allowing secure encrypted multicast transmission while enabling flexible IP address assignment and reducing memory requirements by grouping nodes into the same multicast group with different security groups.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple groups of receiving network nodes are defined in IOT applications, then secure communication is improved, but memory resources are consumed

Engineering Contradiction:
Improvesecure communicationVSAvoidmemory resources
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent segments network nodes into multiple security groups, each with its own cryptographic keying material. This allows secure communication to be maintained for multiple groups while using a single multicast IP address, thereby reducing the memory resources that would otherwise be needed to track multiple separate multicast groups.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent makes the multicast IP address universal by allowing it to be shared across multiple security groups. Instead of requiring a dedicated multicast IP address for each security group, the same IP address serves multiple groups, reducing the total number of routing entries needed in constrained environments.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If cryptographic keying material is maintained for several security sessions, then secure communication is improved, but device complexity is increased

Engineering Contradiction:
Improvesecure communicationVSAvoidrouting information management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple security sessions under a single multicast IP address. By combining the routing information for multiple security groups into one multicast routing entry, the complexity of maintaining separate routing information for each security session is reduced, while still allowing secure communication through distinct cryptographic keying materials.

Inventive Principle:
Principle #5Merging (Combining)

3Quantity of substance

If a single multicast IP address is used for multiple security groups, then memory resources are reduced, but security is compromised

Engineering Contradiction:
Improvememory resourcesVSAvoidsecurity
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The patent applies local quality by assigning different cryptographic keying materials to different security groups while sharing a common multicast IP address. Each security group maintains its own security properties through unique keying material, while the shared IP address provides the memory efficiency benefit. This resolves the contradiction by making security properties local to each group while the routing infrastructure is shared.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11019045B2Secure group communication
Publication Date: 2021.05.25 ARM LTD
  • US11019045B2 patent drawing
  • US11019045B2 patent drawing
  • US11019045B2 patent drawing

AI summary

A first plurality (201) of network nodes (120-123, 130-133) of a network (100) is associated with a first cryptographic keying material and the multicast IP address. A second plurality (202) of network nodes (120-123, 130-133) of the network (100) is associated with a second cryptographic keying material and the multicast IP address. The first cryptographic keying material has a different secret than the second cryptographic keying material.