Secure Element Authentication for IoT Control Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authorization solutions for remote and automatic control in IoT devices are vulnerable to hacks due to potential software flaws, compromising both user devices and IoT devices, necessitating secure communication methods that are resistant to such threats.

Innovation Solution

The implementation of secure elements in both user devices and IoT devices, optionally assisted by a trusted third party, for secure pairing and authentication, where the secure elements verify the authenticity of commands and authorize actions based on their source, ensuring only authorized commands are executed.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If software-based authorization solutions are used for remote control in IoT devices, then ease of operation and implementation are improved, but security reliability deteriorates due to vulnerability to hacks and software flaws

Engineering Contradiction:
Improveease of implementationVSAvoidsecurity reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

A secure element acts as an intermediary component between the software application and the IoT device. This hardware-based secure element stores cryptographic keys and performs authentication operations, mediating the authorization process to prevent software vulnerabilities from compromising security. The secure element is a separate hardware module that interfaces with both the controlling device and the controlled IoT device, enabling secure communication without exposing the system to software-based attacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces software-based authorization mechanisms with hardware-based secure elements. Instead of relying on software cryptographic implementations that are vulnerable to hacking, the system uses dedicated hardware security modules that perform authentication and key management operations in a physically protected environment, making them resistant to software attacks and exploitation.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If hardware-protected secure elements are implemented in both user devices and IoT devices, then security reliability is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security-critical functions are extracted into a separate, dedicated secure element component. This allows the main device architecture to remain relatively simple while the complex security operations are handled by the specialized secure element module. The secure element can be integrated into existing devices as a separate component, minimizing disruption to the overall device design and reducing the complexity burden on the main system architecture.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The secure element is designed as a universal component that can be integrated into various IoT devices and controlling devices with different form factors and functions. It provides standardized security services (authentication, key management, encrypted communication) that work across multiple device types, reducing the need for device-specific security implementations and thereby lowering overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3469852B1Authorized control of an embedded system using end-to-end secure element communication
Publication Date: 2023.10.25 SAMSUNG ELECTRONICS CO LTD
  • EP3469852B1 patent drawingFigure 1~2
  • EP3469852B1 patent drawingFigure 3
  • EP3469852B1 patent drawingFigure 4

AI summary

A first device includes an application processor, a secure processor, and a control processor. The application processor is configured to receive a control command from a second device. The secure processor is connected between the application processor and a control processor and is configured to authenticate the control command. The control processor is configured to receive the control command when the control command is authenticated by the secure processor, execute the control command to activate at least one function of the first device, and transmit a response to the second device.