Proxy-Mediated Key Provisioning for Low-Power IoT Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Low order IoT devices, with limited processing, power, and bandwidth resources, are incompatible with complex key exchange mechanisms, leading to potential security breaches and excessive resource consumption when attempting to communicate securely with high order devices using protocols like TLS or HTTPS.

Innovation Solution

A proxy entity is introduced to negotiate and provision keys for low order devices, implementing both lightweight and Internet-compatible cryptographic protocols, allowing secure communication sessions without overburdening the low order devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If TLS or HTTPS protocols are used for secure key exchange, then security reliability is improved, but device complexity and resource consumption increase

Engineering Contradiction:
Improvesecurity reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A proxy entity is introduced as an intermediary between low order IoT devices and high order devices. The proxy entity handles complex TLS/HTTPS key exchange protocols with high order devices, while providing simplified authentication mechanisms to low order devices. This mediator approach allows low order devices to benefit from secure communication without directly implementing complex cryptographic protocols, thus resolving the contradiction between security reliability and device complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If complex key exchange mechanisms are implemented, then authentication security is improved, but power consumption increases

Engineering Contradiction:
Improveauthentication securityVSAvoidpower consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The proxy entity acts as an energy-saving intermediary by performing computationally intensive cryptographic operations on its own powerful hardware rather than on resource-constrained low order devices. The proxy entity establishes secure connections with high order devices using complex protocols, then provides simplified access to low order devices, thereby maintaining authentication security while significantly reducing power consumption on battery-operated IoT devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication function is segmented into two parts: complex cryptographic operations are performed by the proxy entity (high order device), while simple authentication mechanisms are used by low order devices. This segmentation allows the system to achieve high security without burdening energy-constrained devices with computationally intensive tasks, thus resolving the contradiction between authentication security and power consumption.

Inventive Principle:
Principle #1Segmentation

3Reliability

If TLS protocol is used for secure communication, then communication security is improved, but processing power requirements increase

Engineering Contradiction:
Improvecommunication securityVSAvoidprocessing power
Core Design Contradiction:
ReliabilityVSPower

Solution Approach 1:

The proxy entity serves as a processing-power intermediary that handles all computationally intensive TLS protocol operations. Low order devices only need to implement simple authentication mechanisms, while the proxy entity performs complex cryptographic computations to establish secure communication channels with high order devices. This approach maintains communication security without requiring low order devices to possess substantial processing power.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If standard authentication protocols are implemented, then security is improved, but bandwidth consumption increases

Engineering Contradiction:
ImprovesecurityVSAvoidbandwidth consumption
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The proxy entity optimizes bandwidth usage by establishing secure connections with high order devices once, then caching authentication credentials and session information. This allows multiple low order devices to access the network without repeating complex authentication exchanges, thereby reducing overall bandwidth consumption while maintaining security. The intermediary handles the bandwidth-intensive cryptographic operations centrally rather than distributed across all devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12432551B2Key negotiation and provisioning for devices in a network
Publication Date: 2025.09.30 NAGRAVISION SA
  • US12432551B2 patent drawing
  • US12432551B2 patent drawing
  • US12432551B2 patent drawing

AI summary

The present disclosure proposes method and systems for establishing secure communication session(s) between a first device and a second device, where the first device operates in a user network and implements a first key exchange protocol for secure communication. The second device is capable of communicating with the first device over a wireless communication network. The second device implements a second key exchange protocol that is different to the first key exchange protocol for secure communication. A proxy entity configured for implementing the first and the second key exchange protocols for secure communication is provided. The proxy entity is configured for generating and/or provisioning one or more session keys for the first and the second devices using the key exchange protocols specific to each device for establishing secure communication between the first and second device based on the generated session key(s).