Quantum-Resistant IoT Device Onboarding With KEM Channels

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current IoT device onboarding processes are vulnerable to quantum computer attacks due to the use of asymmetric cryptography, necessitating a more secure and efficient method.

Innovation Solution

Implementing a Key Encapsulation Mechanism (KEM) method involving three authenticated and encrypted communication channels between a manufacturer's first server, a customer's second server, and the IoT device, using KEMTLS for secure communication and eliminating the need for signature generation methods.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If asymmetric cryptography is used for authentication in IoT device onboarding, then device authenticity can be verified, but the system becomes vulnerable to quantum computer attacks

Engineering Contradiction:
Improvedevice authentication securityVSAvoidquantum computer attack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent changes the cryptographic parameter from asymmetric cryptography to symmetric cryptography (KEM). This fundamental parameter change eliminates quantum vulnerability while maintaining authentication security, as symmetric cryptographic methods are not vulnerable to quantum attacks in the same way asymmetric methods are.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent substitutes the asymmetric cryptographic mechanism with a symmetric key encapsulation mechanism. This replacement eliminates the mathematical problems (integer factorization, discrete logarithm) that make asymmetric cryptography vulnerable to quantum attacks, while preserving the authentication function through a different cryptographic approach.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Ease of manufacture

If asymmetric cryptography with signature generation is used, then device certificates can be issued, but key management complexity increases

Engineering Contradiction:
Improvedevice certificate issuanceVSAvoidsignature key management
Core Design Contradiction:
Ease of manufactureVSDevice complexity

Solution Approach 1:

The patent extracts and eliminates the signature generation component from the cryptographic system. By using KEM instead of digital signatures, the system removes the need for private key management and signature verification, significantly simplifying key management while maintaining certificate issuance capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent uses ephemeral keys generated during the key encapsulation process instead of long-term private keys. These temporary keys are discarded after use, eliminating the need for secure long-term key storage and management infrastructure, thereby reducing system complexity.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS12438706B2Method and system for onboarding an IoT device
Publication Date: 2025.10.07 SIEMENS AG
  • US12438706B2 patent drawing
  • US12438706B2 patent drawing

AI summary

Various embodiments of the teachings herein include a method for onboarding an IoT device (3) of a manufacturer, in a manner secure against quantum computer attacks, in an infrastructure of a customer by means of a first server (1) of a manufacturer domain of the manufacturer and a second server (2) of a customer domain of the customer. In some embodiments, three authenticated and encrypted communication channels and a key encapsulation method are used to provide a device certificate of the customer domain for the IoT device on the IoT device.