PKI Authentication for IoT Device Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional security methods for IoT devices are inadequate, as they often rely on perimeter defense, which is insufficient for collaborative intelligent systems, leading to increased risks of unauthorized access, hacking, and data breaches, especially in environments with weak or non-existent network protection.

Innovation Solution

The implementation of a Public Key Infrastructure (PKI) for robust access control and secure communication between IoT devices, using digitally signed requests and acceptance to establish secure communication lines, along with attribute certificates and a trusted third-party authority to manage identities and authenticate endpoints.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional perimeter defense security methods are used for IoT devices, then device deployment is simple and cost-effective, but security against unauthorized access and data breaches is insufficient

Engineering Contradiction:
ImprovesecurityVSAvoidsecurity infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by establishing security credentials and digital certificates for IoT devices during the manufacturing and provisioning phase, before the devices are deployed to the network. This includes embedding unique device identifiers, generating key pairs, and issuing digital certificates so that devices are pre-configured with security credentials needed for mutual authentication and secure communication from the moment they go online, eliminating the need for complex post-deployment security configuration.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a certificate authority (CA) as an intermediary that issues digital certificates to IoT devices and validates their identities. This intermediary enables trusted third-party verification, allowing devices to authenticate each other through certificate validation rather than relying on traditional perimeter-based security controls. The CA acts as a trusted mediator that establishes confidence in device identities across the network.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If PKI-based mutual authentication is implemented between IoT devices, then security against man-in-the-middle attacks and endpoint spoofing is enhanced, but the complexity of identity management and certificate verification increases

Engineering Contradiction:
Improveauthentication securityVSAvoididentity management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies copying by using digital certificates as verifiable copies of device identity information. Instead of devices directly sharing sensitive private keys or complex authentication credentials, each device possesses a certificate that is a verified copy of its identity attributes signed by a trusted certificate authority. This allows devices to prove their identity through certificate presentation without exposing sensitive security materials, simplifying the authentication process while maintaining strong security.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent replaces traditional mechanical or administrative security controls (such as physical security, manual access controls, and perimeter defenses) with cryptographic mechanisms based on public key infrastructure. Device authentication is achieved through mathematical cryptography rather than physical barriers or manual verification processes. This substitution enables automated, scalable identity management where devices can independently verify each other's identities through certificate validation without human intervention.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If digitally signed requests and acceptance protocols are used to establish secure communication lines, then data transmission security is improved, but the overhead of digital signing and verification processes increases communication latency

Engineering Contradiction:
Improvedata transmission securityVSAvoidcommunication latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by performing the computationally intensive key pair generation and certificate issuance processes during device provisioning and manufacturing, before actual data communication begins. Security credentials are pre-established so that during operational communication, devices only need to perform relatively lightweight certificate validation and message signing operations rather than generating cryptographic materials in real-time, thereby reducing communication latency.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements partial action by applying digital signatures selectively to critical authentication and authorization messages rather than encrypting or signing all data transmissions. The full PKI authentication protocol is executed during the connection establishment phase to verify device identities, after which secure communication channels can be maintained with reduced cryptographic overhead for subsequent data exchanges, balancing security requirements with communication efficiency.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12028466B2Using PKI for security and authentication of control devices and their data
Publication Date: 2024.07.02 T CENT
  • US12028466B2 patent drawing
  • US12028466B2 patent drawing
  • US12028466B2 patent drawing

AI summary

Method for utilizing a communication line certificate corresponding to a first device and a second device for a communication line, each of the first and second devices including a hardware processor and associated memory includes: creating a unique ID, by a third electronic device; transmitting the unique ID to the first generating a digitally signed request by the first device, wherein the digitally signed request comprises a first proof of an association of the first device to the communication line; transmitting the digitally signed request to the second device; verifying the first proof by the second device to produce a first verification of the association of the first device to the communication line; and generating a digitally signed acceptance by the second device, wherein the digitally signed acceptance comprises a second proof of an association of the second device to the communication line.