Proxy-Mediated Key Provisioning for Low-Power IoT Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Low order IoT devices, with limited processing, power, and bandwidth resources, are incompatible with complex key exchange mechanisms, leading to potential security breaches and excessive resource consumption when attempting to communicate securely with high order devices using protocols like TLS or HTTPS.
Innovation Solution
A proxy entity is introduced to negotiate and provision keys for low order devices, implementing both lightweight and Internet-compatible cryptographic protocols, allowing secure communication sessions without overburdening the low order devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If TLS or HTTPS protocols are used for secure key exchange, then security reliability is improved, but device complexity and resource consumption increase
Solution Approach 1:
A proxy entity is introduced as an intermediary between low order IoT devices and high order devices. The proxy entity handles complex TLS/HTTPS key exchange protocols with high order devices, while providing simplified authentication mechanisms to low order devices. This mediator approach allows low order devices to benefit from secure communication without directly implementing complex cryptographic protocols, thus resolving the contradiction between security reliability and device complexity.
2Reliability
If complex key exchange mechanisms are implemented, then authentication security is improved, but power consumption increases
Solution Approach 1:
The proxy entity acts as an energy-saving intermediary by performing computationally intensive cryptographic operations on its own powerful hardware rather than on resource-constrained low order devices. The proxy entity establishes secure connections with high order devices using complex protocols, then provides simplified access to low order devices, thereby maintaining authentication security while significantly reducing power consumption on battery-operated IoT devices.
Solution Approach 2:
The authentication function is segmented into two parts: complex cryptographic operations are performed by the proxy entity (high order device), while simple authentication mechanisms are used by low order devices. This segmentation allows the system to achieve high security without burdening energy-constrained devices with computationally intensive tasks, thus resolving the contradiction between authentication security and power consumption.
3Reliability
If TLS protocol is used for secure communication, then communication security is improved, but processing power requirements increase
Solution Approach 1:
The proxy entity serves as a processing-power intermediary that handles all computationally intensive TLS protocol operations. Low order devices only need to implement simple authentication mechanisms, while the proxy entity performs complex cryptographic computations to establish secure communication channels with high order devices. This approach maintains communication security without requiring low order devices to possess substantial processing power.
4Reliability
If standard authentication protocols are implemented, then security is improved, but bandwidth consumption increases
Solution Approach 1:
The proxy entity optimizes bandwidth usage by establishing secure connections with high order devices once, then caching authentication credentials and session information. This allows multiple low order devices to access the network without repeating complex authentication exchanges, thereby reducing overall bandwidth consumption while maintaining security. The intermediary handles the bandwidth-intensive cryptographic operations centrally rather than distributed across all devices.
Data Source
AI summary
The present disclosure proposes method and systems for establishing secure communication session(s) between a first device and a second device, where the first device operates in a user network and implements a first key exchange protocol for secure communication. The second device is capable of communicating with the first device over a wireless communication network. The second device implements a second key exchange protocol that is different to the first key exchange protocol for secure communication. A proxy entity configured for implementing the first and the second key exchange protocols for secure communication is provided. The proxy entity is configured for generating and/or provisioning one or more session keys for the first and the second devices using the key exchange protocols specific to each device for establishing secure communication between the first and second device based on the generated session key(s).


