Network Data Transfer Using Transit Time for Secure Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Devices with limited resources, such as those in IoT and automation systems, face challenges with asymmetric authentication due to high energy and memory requirements, leading to increased management efforts for symmetric authentication protocols and keys as the number of devices increases.

Innovation Solution

A method where communication devices determine a transit time property to derive a common secret, which is then used to protect messages, allowing for secure communication without prior protected relationships or shared secrets, and reducing user input and technical effort.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If asymmetric authentication is used for resource-constrained devices, then security is improved, but energy consumption and CPU performance requirements increase significantly

Engineering Contradiction:
Improveauthentication securityVSAvoidenergy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system enables resource-constrained devices to autonomously generate cryptographic key material using their own idle computational resources during normal operation. The device serves itself by utilizing unused CPU cycles to perform cryptographic computations, eliminating the need for external authentication servers and reducing energy consumption while maintaining security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent changes the operational parameters of the device by utilizing idle CPU cycles and available memory resources that would otherwise remain unused. By transforming waste computational resources into useful cryptographic key generation capacity, the system achieves secure authentication without additional energy expenditure or hardware requirements.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If asymmetric authentication is used, then security is improved, but device complexity and management effort increase

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables resource-constrained devices to autonomously generate cryptographic key material using their own idle computational resources during normal operation. The device serves itself by utilizing unused CPU cycles to perform cryptographic computations, eliminating the need for external authentication servers and reducing energy consumption while maintaining security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent extracts the authentication server functionality from the external infrastructure and embeds it within the resource-constrained device itself. By moving the key generation and authentication logic into the edge device, the system eliminates complex centralized management while maintaining security, directly addressing the device complexity contradiction.

Inventive Principle:
Principle #2Taking out (Extraction)

3Use of energy by moving object

If symmetric authentication protocols are used for resource-constrained devices, then energy consumption is reduced, but security decreases and key management becomes more complex

Engineering Contradiction:
Improveenergy consumptionVSAvoidauthentication security
Core Design Contradiction:
Use of energy by moving objectVSReliability

Solution Approach 1:

The patent applies asymmetry by having each device generate its own unique asymmetric key pairs locally, rather than using shared symmetric keys. This asymmetric approach maintains security while reducing key management complexity, as each device independently manages its own credentials without requiring centralized symmetric key distribution and rotation.

Inventive Principle:
Principle #4Asymmetry

4Reliability

If asymmetric authentication is implemented, then security is improved, but processing time increases making it infeasible for acceptable periods

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs cryptographic key generation and authentication computations during idle periods and intervals when the device is not actively transmitting data. By utilizing off-peak computational windows and pre-generating key material during low-activity periods, the system avoids authentication delays during critical communication moments while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3900297B1Method and system for transfer of data in a network
Publication Date: 2022.12.21 SIEMENS AG
  • EP3900297B1 patent drawingFigure 1
  • EP3900297B1 patent drawingFigure 2
  • EP3900297B1 patent drawingFigure 3

AI summary

The proposal relates to a method for transmitting data in a network (NW) comprising a plurality M of communication apparatuses, with M ≥ 2, wherein the plurality M comprises a first communication apparatus (20) and a second communication apparatus (30), which are connected via a network connection section (NVA) for the purpose of transmitting data, having the steps of: a) ascertaining a time-of-flight property of data transmitted between the first communication apparatus (20) and the second communication apparatus (30) via the network connection section (NVA) by means of the first communication apparatus (20) and the second communication apparatus (30) in each case, b) deriving a secret by means of the first communication apparatus (20) and the second communication apparatus (30) in each case, by using the respective ascertained time-of-flight property, and c) transmitting a message protected by means of the derived secret between the first and second communication apparatuses (20, 30). This method allows transmission of protected messages between two communication apparatuses.