Relay Device Secure Session Management for IoT Credential Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

IoT and M2M devices often lack a user interface, making it impractical to input or update credentials for secure sessions with application devices, especially in scenarios where periodic updates are needed, leading to insecure data communication over LTE networks.

Innovation Solution

A relay device establishes a secure session between the LTE network and the application device without requiring the IoT/M2M device to store credentials, reducing processor and storage usage by using a relay device to detect association and manage secure data upload/download services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If credentials are stored locally in IoT/M2M devices for secure sessions, then security is improved, but device complexity and storage requirements increase

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the credential storage and management function from the IoT/M2M device and relocates it to a remote server. The device only retains a minimal identifier, while the server stores the actual credentials and handles authentication, thereby reducing device complexity while maintaining security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a remote server as an intermediary between the IoT/M2M device and the application device. This server mediates the authentication process by verifying credentials and establishing secure sessions, allowing devices to remain simple while security requirements are met through the intermediary's capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If credentials are updated periodically in IoT/M2M devices, then security is improved, but ease of operation deteriorates due to lack of user interface

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service authentication where the remote server automatically manages credential updates and reissuance without requiring user intervention. The server can programmatically update credentials for devices based on security policies, eliminating the need for user interfaces while maintaining security through automated credential rotation.

Inventive Principle:
Principle #25Self-service

3Reliability

If secure sessions are established between IoT/M2M devices and application devices, then security is improved, but processor usage increases

Engineering Contradiction:
ImprovesecurityVSAvoidprocessor usage
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts the computationally intensive session management and credential verification processes from the IoT/M2M device and relocates them to a remote server. The device only performs lightweight operations like presenting its identifier, while the server handles the heavy processing of authentication and session establishment, thereby reducing processor usage in resource-constrained devices.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10103879B2Secure data upload/download service
Publication Date: 2018.10.16 VERIZON PATENT & LICENSING INC
  • US10103879B2 patent drawing
  • US10103879B2 patent drawing
  • US10103879B2 patent drawing

AI summary

A first device may receive data, to be provided to a second device, and an application identifier. The data and application identifier may be received from a third device. The first device may be associated with a first network, and the second device may be associated with a second network. The first network may be a different network than the second network. The application identifier may be associated with the second device. The first device may determine that the data is destined to the second device based on the application identifier. The first device may cause a secure session to be established with the second device. The secure session may allow the data to be securely transmitted from the third device to the second device. The first device may provide the data to the second device via the secure session.