Secure Device Coupling via Short-Range Key Exchange

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless device coupling mechanisms are vulnerable to man-in-the-middle attacks, which can lead to unauthorized access and security breaches in network attached devices, posing financial and safety risks.

Innovation Solution

Implementing a secure device coupling method using short-range communication to exchange domain device secrets and public keys, along with the DICE-RIOT protocol for mutual authentication, ensuring secure communication between network management devices and network attached devices without adding new components or increasing complexity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If wireless communication is used for device coupling, then ease of operation is improved, but security is worsened due to vulnerability to man-in-the-middle attacks

Engineering Contradiction:
Improvedevice couplingVSAvoidcommunication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent performs preliminary authentication actions before establishing wireless communication. The network management device and network attached device exchange and verify digital certificates and cryptographic keys during an initial pairing phase, ensuring that subsequent communications are secured with pre-established trust relationships that prevent man-in-the-middle attacks.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces cryptographic intermediaries (digital certificates, public key infrastructure, and authentication protocols) that mediate between the network management device and network attached device. These intermediaries verify identities and establish secure communication channels, allowing wireless convenience while maintaining security through layered cryptographic verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security measures are added to prevent attacks, then reliability is improved, but device complexity increases

Engineering Contradiction:
Improvecommunication securityVSAvoidcoupling mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal cryptographic framework that handles multiple security functions (authentication, encryption, key exchange) through standardized protocols. This multi-functional approach consolidates security operations into unified processes that can be applied across different device types and communication scenarios, reducing overall system complexity while maintaining comprehensive security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent enables devices to perform self-authentication and self-verification using embedded cryptographic credentials. Each network attached device independently verifies the network management device's certificate and establishes its own secure connection, eliminating the need for complex centralized authentication management and reducing operational complexity.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11985114B2Secure device coupling
Publication Date: 2024.05.14 MICRON TECHNOLOGY INC
  • US11985114B2 patent drawing
  • US11985114B2 patent drawing
  • US11985114B2 patent drawing

AI summary

The present disclosure includes secure device coupling. An embodiment includes a processing resource, memory, and a network management device communication component configured to, identifying a network attached device within a first domain. Generating a domain device secret corresponding to the first domain. Each network attached device within the first domain can share the same domain device secret. Coupling iterations may be performed for each device within the first domain can include: generating a network management device private key and public key. Providing, via short-range communication, the network management device public key and the domain device secret to a network attached device communication component included in each network attached device of the first domain. A network attached device public key and data from the network attached device communication component in response to providing the network management device public key to the network attached device communication component is received from each device in the first domain.