Root-Key MAC Authentication for Low-Power AIoT Network Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Zero-power ambient Internet of Things (AIoT) devices face challenges in accessing networks with low-complexity computing methods while ensuring security, as existing authentication processes are complex and resource-intensive.

Innovation Solution

A method involving the use of a root key shared between devices for authentication, where a first device transmits a message with a MAC and authentication parameter to a second device, allowing the second device to calculate a verification MAC and authenticate with the core network side, along with key generation methods using integrity and encryption keys based on random numbers and anonymous keys.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication processes are used for AIoT devices, then security is ensured, but computational complexity and resource consumption increase significantly

Engineering Contradiction:
Improveauthentication securityVSAvoidcomputational complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication process is segmented into two distinct paths: a first authentication process for traditional devices using existing complex algorithms, and a second authentication process for AIoT devices using simplified algorithms. This segmentation allows each device type to use appropriately complex authentication methods without forcing low-power devices to handle unnecessary computational burden.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the authentication parameters and algorithms based on device type. For AIoT devices, it uses simplified authentication parameters and less computationally intensive algorithms compared to traditional devices. This parameter adaptation enables AIoT devices to perform authentication with reduced computational complexity while maintaining security requirements.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If traditional authentication processes are used for AIoT devices, then security is ensured, but energy consumption increases

Engineering Contradiction:
Improveauthentication securityVSAvoidenergy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The authentication process is segmented into two distinct paths: a first authentication process for traditional devices using existing complex algorithms, and a second authentication process for AIoT devices using simplified algorithms. This segmentation allows each device type to use appropriately complex authentication methods without forcing low-power devices to handle unnecessary computational burden.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the authentication parameters and algorithms based on device type. For AIoT devices, it uses simplified authentication parameters and less computationally intensive algorithms compared to traditional devices. This parameter adaptation enables AIoT devices to perform authentication with reduced computational complexity while maintaining security requirements.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20260058820A1Authentication methods
Publication Date: 2026.02.26 GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTD
  • US20260058820A1 patent drawing
  • US20260058820A1 patent drawing
  • US20260058820A1 patent drawing

AI summary

An authentication method includes: receiving, by a second device, a second message from a first device, the second message carrying a MAC and an authentication parameter; calculating, by the second device, a verification MAC based on the authentication parameter and a root key, the root key being a key shared between the second device and a core network side device; completing, by the second device, authentication of the core network side device in a case where the verification MAC is the same as the MAC.