Secure Pairing via Bootstrapping Server for IoT Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for establishing secure connections between master and slave devices, such as wireless speakers and mobile phones, often require significant user interaction, compromising usability and flexibility, and typically involve additional interfaces or complex cryptographic exchanges.
Innovation Solution
A bootstrapping mechanism using a pre-shared secret key, where the slave device generates a proof-of-possession and transmits it to the master device, which then forwards it to a bootstrapping server for verification, allowing secure key establishment without additional interfaces and enhancing security through location-limited communication channels.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If additional interfaces such as NFC are added to the slave device for establishing secure connections, then security is improved, but device complexity and manufacturing cost increase
Solution Approach 1:
The patent introduces a bootstrapping server as an intermediary that facilitates secure key establishment between the master and slave devices. The server receives proofs of possession from both devices, verifies them, and generates a shared secret key, eliminating the need for additional secure interfaces on the slave device while maintaining connection security
Solution Approach 2:
The patent replaces physical interface mechanisms (such as NFC hardware) with a cryptographic protocol-based solution. Instead of requiring additional physical interfaces for secure pairing, the system uses digital proof-of-possession verification and cryptographic key generation over existing communication channels
2Reliability
If user interaction such as button pressing or confirmation messages is required for device pairing, then security is improved, but usability and flexibility deteriorate
Solution Approach 1:
The patent enables devices to perform self-service pairing through automated cryptographic protocols. The master and slave devices automatically generate proofs of possession, exchange them through the bootstrapping server, and establish shared secrets without requiring user intervention, making the process both secure and convenient
Solution Approach 2:
The system performs preliminary cryptographic setup during device manufacturing, where each slave device is pre-configured with unique identifiers and cryptographic credentials. This preliminary action enables automatic secure pairing later without requiring users to manually configure security settings or exchange physical tokens
3Device complexity
If cryptographic information is exchanged directly between master and slave devices through audio/video channels, then additional interfaces are avoided, but the requirement for microphones and speakers increases device complexity
Solution Approach 1:
The bootstrapping server acts as an intermediary that receives cryptographic proofs from both devices and performs the key generation centrally. This eliminates the need for direct cryptographic exchange between master and slave devices, removing the requirement for audio/video interfaces while maintaining the ability to use such channels if desired for alternative pairing methods
Data Source
AI summary
A method (200) of establishing a secure connection (213) between a master device (101) and a slave device (102), sharing at least a first communication channel, is provided. The method comprises transmitting (201) an identifier IDM of the master device over the first communication channel, generating (202) a proof-of-possession Xs of a key Ks, using Ks, IDM, and a first identifier I DSi of the slave device, generating (202) a key MKS using IDM, I DSi, and Ks, storing (204) MKS, and transmitting (203) I DSi and Xs to the master device. The method further comprises transmitting (205) IDSi, Xs, and IDM, to a bootstrapping server, acquiring (206) Ks using IDSi, and generating (207) a proof-of-possession XB of Ks using Ks, IDM, and IDsi. The method further comprises, if XB and Xs are identical (208), generating (210) a key MKB using IDM, I DSi, and Ks, and transmitting (211) MKB to the master device where it is stored (212). Optionally, I DSi and Xs may be transmitted (203) to the master device over a second, preferably location-limited, communication channel, such as audio or video.


