Wireless Re-Pairing Security Using Reachability-Based Key Switching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Low-voltage protection apparatuses face challenges in secure re-pairing with communication nodes, particularly when reconnecting, as existing security models like Zigbee's centralized model restrict flexibility and are vulnerable to 'man-in-the-middle' attacks, while the distributed model compromises security.

Innovation Solution

An apparatus and method that utilize an integrated transmitting and receiving module for wireless communication with a communication node, employing an installation key for initial pairing and a connection key for secure data transfer, with re-pairing triggered by checking reachability criteria to switch between keys, enhancing security and reducing malicious attack risks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the centralized security model (Zigbee) is used for pairing, then security is improved, but re-pairing flexibility and ease of operation deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoidre-pairing flexibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The pairing process is segmented into two distinct phases: initial pairing using an installation key, and re-pairing using a connection key. This segmentation allows different security mechanisms to be applied at different stages, resolving the contradiction between security and re-pairing flexibility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically switches between using the installation key and connection key based on the pairing context. During initial pairing, the installation key is used; during re-pairing, the connection key is used. This dynamic adaptation resolves the contradiction by providing the appropriate key type for each scenario.

Inventive Principle:
Principle #15Dynamics

2Ease of operation

If the distributed security model is used for pairing, then re-pairing flexibility is improved, but security deteriorates due to vulnerability to man-in-the-middle attacks

Engineering Contradiction:
Improvere-pairing flexibilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The connection key is preliminarily established during the initial pairing phase through secure key derivation. This preliminary action ensures that when re-pairing is needed, a secure key is already available, eliminating the need for insecure key transmission during re-pairing operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The connection key acts as an intermediary that enables secure re-pairing without requiring direct exposure of the installation key. It mediates between the need for re-pairing flexibility and the requirement for security, allowing devices to re-pair securely without vulnerable key exchange processes.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If the installation key is reused for re-pairing, then ease of operation is improved, but security deteriorates due to potential key exposure and unauthorized access

Engineering Contradiction:
Improvere-pairing simplicityVSAvoidunauthorized access risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The connection key is extracted from the installation key through a secure key derivation process during initial pairing. This extraction creates a separate, purpose-specific key for re-pairing operations, eliminating the security risks associated with reusing the installation key while maintaining operational simplicity.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11751270B2Apparatus and method for achieving higher security on re-pairing
Publication Date: 2023.09.05 SIEMENS AG
  • US11751270B2 patent drawing
  • US11751270B2 patent drawing
  • US11751270B2 patent drawing

AI summary

For providing data of an apparatus for applications, routing of the data via a communication node is provided. In this case, the apparatus communicates the data wirelessly to the communication node. This necessitates pairing the apparatus with the communication node beforehand, which is carried out with the aid of an installation key. The data transfer itself is then secured with a connection key defined during the pairing. If replacing or reconnecting the communication node necessitates carrying out re-pairing, at least one criterion relating to the reachability of the communication node is checked and the lack of reachability as per the criterion is made into the prerequisite for using the installation key instead of the connection key for re-pairing. At least one embodiment of the invention increases protection against interferers wanting to access the apparatus in an unauthorized manner.