PKI Security Ecosystem for IoT Device Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security technologies for IoT devices are inadequate in providing robust access control and identity management, especially in collaborative models where multiple devices interact, leading to increased risks of unauthorized access and security breaches.

Innovation Solution

The implementation of a Public Key Infrastructure (PKI) based security ecosystem that includes unique ID creation, digital certificate issuance, secure communication line establishment, and PKI-Enforced Whitelisting to ensure only authorized devices communicate, using Inviter-Invitee Protocol and Attribute Authorities for enhanced security and authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security technologies are used for IoT devices, then device simplicity and ease of operation are maintained, but security reliability and access control robustness are inadequate

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidsecurity system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a Public Key Infrastructure (PKI) system as an intermediary layer between IoT devices and the network. This PKI system includes certificate authorities, registration authorities, and security modules that mediate authentication and encryption processes. By placing this intermediary security layer, the patent achieves robust access control and identity management without requiring complex security implementations within each individual IoT device, thus resolving the contradiction between security reliability and device complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If PKI-based security ecosystem is implemented, then access control and identity management are improved, but computational overhead and energy consumption increase

Engineering Contradiction:
Improveaccess control robustnessVSAvoidenergy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent implements preliminary action by pre-provisioning IoT devices with security modules, unique identifiers, and cryptographic key pairs during the manufacturing process. The PKI infrastructure pre-establishes certificate authorities and registration authorities before devices are deployed. This preliminary setup eliminates the need for complex runtime security computations on resource-constrained devices, reducing their energy consumption while maintaining robust access control through pre-computed cryptographic credentials.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If multiple devices interact in collaborative models, then system functionality and versatility are enhanced, but security risks and unauthorized access possibilities increase

Engineering Contradiction:
Improvecollaborative functionalityVSAvoidsecurity breaches
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements a feedback mechanism through the PKI system where each device in the collaborative network continuously authenticates others using digital certificates and cryptographic verification. The registration authority provides feedback by issuing and revoking certificates based on device trustworthiness. This continuous cryptographic feedback loop enables multiple devices to interact collaboratively while maintaining security, as each device can verify the identity and authorization of others before engaging in collaborative operations, thus preventing unauthorized access despite enhanced system versatility.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10652031B2Using PKI for security and authentication of control devices and their data
Publication Date: 2020.05.12 T CENT
  • US10652031B2 patent drawing
  • US10652031B2 patent drawing
  • US10652031B2 patent drawing

AI summary

Method for authenticating a first and a second electronic devices associated through a communication line includes: creating a unique ID, by a third electronic device; transmitting the unique ID to the first electronic device; signing the transmitted unique ID by the first electronic device; transmitting the signed unique ID to the second electronic device, by the first electronic device; signing the transmitted signed unique ID by the second electronic device; transmitting the unique ID signed by the first and second electronic devices to the third electronic device; verifying and accepting the unique ID signed by the first device and the second device, by the third device; issuing a certificate for a secure communication line between the first electronic device and the second electronic device; and transmitting the certificate to the first electronic device and the second electronic device.