Secure Session Resumption for Resource-Constrained IoT Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Resource-constrained devices in IoT face challenges in establishing secure sessions efficiently due to computational intensity of standard authentication protocols, which drains resources and shortens device lifetime.

Innovation Solution

A method where a resource-constrained device registers with a management terminal, receives a credential from a server, and initiates a service approval request, allowing the management terminal to perform computationally intensive operations for secure session establishment, enabling the device to resume the session using a security context without intensive computations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If standardized certificate-based authentication protocols are used for secure session establishment, then security is improved, but computational resource consumption increases and device lifetime decreases

Engineering Contradiction:
ImprovesecurityVSAvoidcomputational resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The authentication system is segmented into two parts: a lightweight authentication mechanism for resource-constrained devices and a full certificate verification system for management terminals. The device performs simplified authentication while the terminal handles computationally intensive certificate validation, resolving the contradiction between security and energy consumption.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The management terminal acts as an intermediary that performs computationally intensive certificate verification on behalf of resource-constrained devices. This mediator approach allows devices to achieve secure authentication without directly performing heavy computations, thus maintaining security while reducing energy consumption.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If full certificate verification is performed by the resource-constrained device, then authentication security is improved, but processing power and battery life deteriorate

Engineering Contradiction:
Improveauthentication securityVSAvoidprocessing power requirement
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication workload is segmented between the resource-constrained device and the management terminal. The device performs lightweight authentication operations while the terminal handles complex certificate verification, reducing device complexity while maintaining authentication security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The management terminal serves as an intermediary that offloads computationally intensive certificate verification from resource-constrained devices. This allows devices with limited processing power to achieve secure authentication by delegating heavy computational tasks to the terminal.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Use of energy by moving object

If lightweight authentication methods are used, then resource consumption is reduced, but authentication robustness deteriorates

Engineering Contradiction:
Improveresource consumptionVSAvoidauthentication robustness
Core Design Contradiction:
Use of energy by moving objectVSReliability

Solution Approach 1:

The management terminal acts as a mediator that performs robust certificate verification while the resource-constrained device uses lightweight authentication methods. This intermediary approach maintains authentication robustness by ensuring that full certificate validation is performed by capable systems rather than constrained devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10693879B2Methods, devices and management terminals for establishing a secure session with a service
Publication Date: 2020.06.23 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US10693879B2 patent drawing
  • US10693879B2 patent drawing
  • US10693879B2 patent drawing

AI summary

This disclosure provides a method, performed in a resource-constrained device 60, for establishing a secure session with a service 800 delivered by a server terminal 80 using a security protocol over a communication network. The resource-constrained device 60 is registered at a management terminal 70. The method comprises receiving, from the server terminal 80, a credential associated with the service 800. The method comprises sending, to the management terminal 70, a service approval request 803. The service approval request 803 comprises an identifier of the service 800 and/or the credential. The method comprises receiving, from the management terminal 70, a response 804. The response 804 comprises an indication that the service 800 is approved, and a security context for a resumption of the secure session. The secure session has been established by the management terminal 70. The method comprises initiating the resumption of the secure session with the service 800 using the security context.