Quantum-Resistant IoT Device Onboarding With KEM Channels
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current IoT device onboarding processes are vulnerable to quantum computer attacks due to the use of asymmetric cryptography, necessitating a more secure and efficient method.
Innovation Solution
Implementing a Key Encapsulation Mechanism (KEM) method involving three authenticated and encrypted communication channels between a manufacturer's first server, a customer's second server, and the IoT device, using KEMTLS for secure communication and eliminating the need for signature generation methods.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If asymmetric cryptography is used for authentication in IoT device onboarding, then device authenticity can be verified, but the system becomes vulnerable to quantum computer attacks
Solution Approach 1:
The patent changes the cryptographic parameter from asymmetric cryptography to symmetric cryptography (KEM). This fundamental parameter change eliminates quantum vulnerability while maintaining authentication security, as symmetric cryptographic methods are not vulnerable to quantum attacks in the same way asymmetric methods are.
Solution Approach 2:
The patent substitutes the asymmetric cryptographic mechanism with a symmetric key encapsulation mechanism. This replacement eliminates the mathematical problems (integer factorization, discrete logarithm) that make asymmetric cryptography vulnerable to quantum attacks, while preserving the authentication function through a different cryptographic approach.
2Ease of manufacture
If asymmetric cryptography with signature generation is used, then device certificates can be issued, but key management complexity increases
Solution Approach 1:
The patent extracts and eliminates the signature generation component from the cryptographic system. By using KEM instead of digital signatures, the system removes the need for private key management and signature verification, significantly simplifying key management while maintaining certificate issuance capability.
Solution Approach 2:
The patent uses ephemeral keys generated during the key encapsulation process instead of long-term private keys. These temporary keys are discarded after use, eliminating the need for secure long-term key storage and management infrastructure, thereby reducing system complexity.
Data Source
AI summary
Various embodiments of the teachings herein include a method for onboarding an IoT device (3) of a manufacturer, in a manner secure against quantum computer attacks, in an infrastructure of a customer by means of a first server (1) of a manufacturer domain of the manufacturer and a second server (2) of a customer domain of the customer. In some embodiments, three authenticated and encrypted communication channels and a key encapsulation method are used to provide a device certificate of the customer domain for the IoT device on the IoT device.

