PSK Distribution for Certificate-Free IoT Supply Chain Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cybersecurity methods for IoT, IIoT, and OT environments face challenges in managing symmetric pre-shared keys (PSKs) due to complex workflows, scalability issues, and resource constraints, particularly in the absence of digital certificates and asymmetric keypairs, leading to service disruptions and high operational costs.

Innovation Solution

A system and method for symmetric pre-shared key distribution using a key distribution service (KDS) that automates key generation, distribution, and management without PKI-based digital certificates, leveraging DNS and DHCP services for device authentication and secure communications over various protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If PKI-based digital certificates and asymmetric keypairs are used for device authentication, then security is improved, but device complexity and operational costs increase

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the complex PKI certificate management system and replaces it with a simplified pre-shared key (PSK) authentication mechanism. Devices are provisioned with PSKs during manufacturing or onboarding, eliminating the need for digital certificates, asymmetric keypairs, and certificate authority infrastructure on resource-constrained IoT/IIoT/OT devices while maintaining authentication security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent uses computationally lightweight symmetric encryption algorithms (e.g., AES) with pre-shared keys instead of computationally intensive asymmetric cryptography. This allows resource-constrained devices to perform cryptographic operations with minimal processing power, memory, and energy consumption, effectively replacing expensive long-lived certificate infrastructure with cheap short-lived PSK sessions.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

2Ease of operation

If manual PSK management methods are used, then implementation simplicity is improved, but scalability and security deteriorate

Engineering Contradiction:
Improveimplementation simplicityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a key distribution service (KDS) as an intermediary that automates PSK provisioning, distribution, and management. The KDS receives authentication requests from devices, validates them against stored PSKs, and manages key lifecycles including rotation and revocation. This mediator eliminates manual PSK management while maintaining simplicity for end users and provides scalable security infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables devices to autonomously authenticate themselves using pre-configured PSKs without requiring manual intervention during operation. Devices can independently establish secure connections by presenting their PSKs to the KDS or peer devices, and the KDS automatically handles key renewal and rotation processes without human involvement.

Inventive Principle:
Principle #25Self-service

3Reliability

If PSKs are distributed to devices, then secure communications are enabled, but key management workflows become complex

Engineering Contradiction:
Improvesecure communicationsVSAvoidkey management workflows
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal key management architecture where a single PSK can serve multiple functions and applications on the same device. Instead of requiring separate PSKs for each application or communication channel, the system allows one PSK to be used across multiple services and protocols, simplifying key management workflows while maintaining secure communications.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent performs preliminary PSK provisioning during device manufacturing or initial onboarding in controlled environments. PSKs are pre-configured in device secure storage before deployment, eliminating the need for complex runtime key distribution workflows. The KDS then manages subsequent key operations including rotation and renewal without requiring complex manual procedures.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If certificate chain verification is performed, then authentication reliability is improved, but computational overhead and bandwidth consumption increase

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidcomputational overhead
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent replaces computationally expensive certificate chain verification with lightweight symmetric key authentication using pre-shared keys and AES encryption. The authentication process involves simple cryptographic operations that can be performed efficiently on resource-constrained devices without requiring complex public key infrastructure validation, significantly reducing computational overhead and energy consumption.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS12463802B2System and method for pre-shared key (PSK) based supply chain tamper resistance
Publication Date: 2025.11.04 SYMMERA INC
  • US12463802B2 patent drawing
  • US12463802B2 patent drawing
  • US12463802B2 patent drawing

AI summary

The method provides an automated and scalable system for the generation, distribution, management of symmetric pre-shared keys (PSKs) to applications executing on headless and mobile devices. It helps achieve device protection, application security, and data protection with data authenticity and confidentiality in intra-device, inter-device, device-to-edge, and device-to-cloud communications. It helps Transport Layer Security (TLS) enabled applications dynamically acquire and renew PSKs and use identity hints for PSK based authentication ceremony during a TLS handshake. It helps broker-consumer applications dynamically acquire and renew PSKs using keyed-hash message authentication code (HMAC) for data integrity and authenticity, content signing, and data encryption for confidentiality. It helps manage and distribute API shared secrets and API access tokens required for authenticated API requests and API security. It helps applications (producers, brokers, and consumers of content) with PSKs for supply chain tamper resistance. It helps real-time low-latency applications with selective encryption of partial messages.