Secure IoT WLAN Provisioning via Cellular Non-IP Data Delivery
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing internet-of-things (IoT) devices face security vulnerabilities during provisioning due to the use of non-cellular data connections, which lack the robustness and security of cellular connections, and current methods like certificate-based authentication introduce significant overhead.
Innovation Solution
Utilizing cellular connections for IoT devices with non-IP data delivery to provision cryptographic elements over-the-air, eliminating the need for IP-based data transmission and reducing security risks by leveraging cellular encryption.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If certificate-based authentication is used for IoT device provisioning, then security is improved, but device complexity and overhead increase significantly
Solution Approach 1:
The patent extracts the cryptographic element delivery from the IP-based provisioning process and places it within the cellular network's secure domain. By using Non-IP Data Delivery (NIDD), the provisioning data is delivered through cellular signaling channels rather than IP packets, eliminating the need for complex certificate-based authentication while maintaining security through cellular network encryption and authentication mechanisms.
Solution Approach 2:
The cellular network acts as an intermediary between the provisioning server and the IoT device. Instead of direct IP-based communication requiring certificate validation, the cellular network infrastructure mediates the secure delivery of cryptographic elements through its established secure channels, simplifying the authentication process while maintaining security.
2Adaptability or versatility
If IP-based data transmission is used for provisioning cryptographic elements, then adaptability is improved, but security deteriorates due to exposed attack vectors
Solution Approach 1:
The cellular network serves as a secure intermediary that shields the provisioning process from external attacks. By routing cryptographic element delivery through cellular signaling channels rather than exposed IP networks, the system maintains provisioning flexibility while eliminating the security vulnerabilities inherent in IP-based transmission.
Solution Approach 2:
The patent creates a secure, isolated environment for provisioning by using cellular network channels that are inherently protected from external access. This 'inert' provisioning channel prevents attackers from intercepting or manipulating cryptographic elements during delivery, while still allowing flexible provisioning of various IoT devices.
3Reliability
If cellular connections with Non-IP Data Delivery are used for provisioning, then security is improved, but ease of operation deteriorates due to connection management complexity
Solution Approach 1:
The cellular network infrastructure automatically handles the complexity of secure connection management for NIDD. The network itself performs the secure channel establishment, authentication, and data delivery without requiring the IoT device or provisioning system to manually manage cryptographic keys or secure connections, thus maintaining ease of operation while achieving high security.
Data Source
AI summary
Cellular connections can be used to provision non-cellular devices such as internet-of-things (IOT) devices. For example, IoT devices can comprise Bluetooth, Wi-Fi, and cellular capabilities. However, the cellular capability can be used to provision the IoT devices using non-internet protocol data delivery to prevent security vulnerabilities. Data can be transmitted to the IoT device using core elements without using an IP stack. Thus, IoT device configurations and the keys can be provisioned over-the-air without the use of internet protocol data.


