Privacy Protected Autonomous Attestation for 5G IoT Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current privacy protection approaches in edge computing and IoT networks, such as Intel's EPID, IBM's IDEMIX, and Microsoft's U-Prove, are insufficient to support the latency and device density requirements of 5G networks, particularly in scenarios requiring high-performance, privacy-protecting authentication mechanisms for millions of devices.

Innovation Solution

The implementation of bilinear maps over elliptic curve groups for cryptographic anonymous attestation operations, combined with DICE hardware root-of-trust and EPID key management, enables efficient and privacy-preserving device authentication, allowing devices to remain anonymous or partially anonymous while supporting 5G device latency and density.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If current privacy protection approaches (EPID, IDEMIX, U-Prove) are used in edge computing and IoT networks, then device authentication privacy is protected, but the system cannot support 5G network latency and device density requirements

Engineering Contradiction:
Improveprivacy protectionVSAvoidauthentication performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the authentication process into distinct cryptographic operations (key generation, signature creation, verification) that can be independently optimized and parallelized. The use of bilinear maps divides the computational workload into manageable mathematical operations that reduce overall processing time while maintaining privacy protections.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the cryptographic parameter space by implementing bilinear maps over elliptic curve groups, which provides different computational characteristics compared to traditional approaches. This parameter change enables faster authentication operations while maintaining the same level of privacy protection, thus supporting 5G network requirements.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If traditional authentication mechanisms are used, then device identity can be verified, but device anonymity and privacy are compromised

Engineering Contradiction:
Improveauthentication accuracyVSAvoidprivacy information
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent introduces cryptographic intermediaries (bilinear maps, elliptic curve groups, and anonymous attestation protocols) that mediate between the need for accurate authentication and the need for privacy preservation. These mathematical structures act as intermediaries that verify device legitimacy without exposing identifying information, thus resolving the contradiction between authentication accuracy and privacy protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If privacy-protecting authentication is implemented, then device anonymity is maintained, but verifier complexity increases

Engineering Contradiction:
Improveprivacy protectionVSAvoidverifier complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces complex mechanical or procedural verification methods with elegant mathematical substitutions using bilinear maps and elliptic curve cryptography. This substitution reduces verifier complexity by leveraging well-understood mathematical properties rather than requiring complex trust models or multiple verification steps, thus maintaining privacy while simplifying the verification process.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS20240333532A1Privacy protected autonomous attestation
Publication Date: 2024.10.03 INTEL PRODUCTS IP LLC
  • US20240333532A1 patent drawing
  • US20240333532A1 patent drawing
  • US20240333532A1 patent drawing

AI summary

An apparatus operating as a certificate authority (CA) is described. The apparatus can perform operations including receiving, from a plurality of requesting devices, a request to join a group. The request can include identification information for the group and attestation evidence for the plurality of requesting devices. Responsive to receiving the request, the apparatus can provide a group certificate for the group to the plurality of requesting devices.