Secure IoT Data Exchange via Centralized Gateway and PUF

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Connected objects with constrained resources face security risks throughout their life cycle, particularly due to their deployment in various physical locations and association with sensitive elements, which increases the complexity of ensuring security across different phases handled by different third parties.

Innovation Solution

A data exchange architecture that includes a gateway, supervision system, and secure communication protocols, utilizing Physical Unclonable Function (PUF) technology, True Random Number Generator (TRNG), and Trust Zone security features to provide a secure identity, encryption, and fine-grained access control for connected objects, ensuring security throughout their life cycle.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If connected objects are deployed in various physical locations and associated with sensitive elements, then the functionality and utility of the system is improved, but the security risks and complexity of ensuring security across different phases increase

Engineering Contradiction:
Improvedeployment flexibilityVSAvoidsecurity integrity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies preliminary action by establishing security measures during the manufacturing phase, including pre-programming security algorithms, generating unique identification keys, and configuring secure communication protocols before deployment. This ensures that security infrastructure is already in place when objects are deployed to various locations, eliminating the need for complex security setup at each deployment site.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a security gateway as an intermediary between connected objects and the central system. This gateway centralizes security management functions, including authentication, authorization, and encryption key distribution. By using this intermediary, the system can maintain security integrity across diverse deployment locations without requiring each location to implement its own security complex.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security measures are implemented throughout the entire lifecycle of connected objects, then security integrity is improved, but the device complexity and resource consumption increase

Engineering Contradiction:
Improvesecurity integrityVSAvoidsecurity system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts complex security management functions from the connected objects themselves and places them in a centralized security gateway. The objects only retain minimal security-related components such as unique identification keys and simple encryption modules. This extraction significantly reduces the complexity and resource consumption of individual objects while maintaining comprehensive security throughout their lifecycle.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements a universal security gateway that handles multiple security functions including authentication, authorization, encryption, and key management. This single multi-functional component replaces what would otherwise require multiple separate security systems distributed across different phases and locations, thereby reducing overall system complexity while maintaining comprehensive security coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If different third parties handle different phases of the connected object lifecycle, then operational flexibility and specialization are improved, but the security risks increase due to multiple handovers and trust boundaries

Engineering Contradiction:
Improveoperational flexibilityVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The security gateway serves as a trusted intermediary that all third parties must interact with during phase transitions. Whether manufacturing, deployment, or dismantling phases are handled by different third parties, all security-critical operations go through the gateway, which validates credentials, encrypts data, and maintains audit trails. This intermediary approach allows operational flexibility among different providers while containing security risks within a controlled environment.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements feedback mechanisms where the security gateway continuously monitors and logs security events across all lifecycle phases. This feedback loop enables real-time detection of anomalies, automatic adjustment of security protocols, and post-event analysis. By having continuous feedback about security conditions, the system can adapt to different third-party operations while maintaining consistent security standards and quickly responding to potential threats.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3828737B1Data exchange architecture comprising a plurality of connected objects with limited resources
Publication Date: 2023.09.06 THALES SA
  • EP3828737B1 patent drawingFigure 1
  • EP3828737B1 patent drawingFigure 2

AI summary

The present invention relates to a data exchange architecture (10) of interest comprising a plurality of connected objects (12-1,...,12-3) with constrained resources and a security system (40). Each connected object (12-1,...,12-3) comprises an access control microcontroller, a memory, a processor and a communication module. The security system (40) is capable of verifying the access control microcontroller and the memory integrity of each object (12-1,...,12-3) during a manufacturing phase of that object (12-1,..., 12-3), of discovering, identifying and registering each new object (12-1,...,12-3), of updating software resources of each connected object during an operating phase of that object, and of activating means of disabling each connected object (12-1,...,12-3) to disable its operation during a dismantling phase of that object (12-1,...,12-3).