Shared-Key Authentication Relay for Low-Power IoT Communication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Ambient power-enabled Internet of Things (A-IoT) devices face challenges in accessing networks due to high computational complexity in authentication and key agreement processes, necessitating a solution to reduce complexity while enabling authentication and communication.
Innovation Solution
A communication method involving a core network sending a message authentication code based on a shared key to a second device, allowing the second device to authenticate the network side and obtain a key for communication, thereby reducing computational complexity by leveraging shared keys for authentication and data transmission.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication processes are used for A-IoT devices, then security authentication can be achieved, but computational complexity becomes too high for zero-power devices
Solution Approach 1:
The patent introduces a core network side device as an intermediary that performs the complex authentication and key agreement operations. The A-IoT device only needs to participate in a simplified authentication process where it receives a first information containing authentication result, rather than performing complex computational functions itself. This mediator approach allows security authentication to be achieved while keeping the A-IoT device computational complexity low.
Solution Approach 2:
The authentication process is segmented into different functional parts: the core network side device handles the complex key agreement and authentication computation, while the A-IoT device handles only the reception and verification of authentication results. This segmentation allows each component to perform only the computational tasks appropriate to its capabilities, resolving the contradiction between security requirements and device complexity constraints.
2Reliability
If complex key architectures are used for network authentication, then security can be ensured, but energy consumption increases for A-IoT devices
Solution Approach 1:
The core network side device acts as an intermediary that performs the energy-intensive key agreement and authentication operations centrally, rather than requiring the A-IoT device to perform these computations locally. The A-IoT device only needs to receive and process the first information containing authentication results, dramatically reducing its energy consumption while maintaining security through the robust key architecture implemented by the core network.
3Reliability
If A-IoT devices perform full authentication protocols, then network security is maintained, but device capability requirements become too high
Solution Approach 1:
The core network side device serves as an intermediary that performs the complex authentication protocols and key agreement procedures, eliminating the need for A-IoT devices to have high computational capabilities. The A-IoT device simply receives the first information containing authentication results from the core network, allowing devices with minimal capabilities to participate in secure network authentication.
Solution Approach 2:
The authentication functionality is segmented such that the core network side device performs the complex cryptographic operations and key management, while the A-IoT device performs only the simple reception and verification of authentication results. This segmentation enables network security to be maintained through robust authentication protocols executed by capable network infrastructure, while A-IoT devices can participate despite having limited computational capabilities.
Data Source
Figure 1~2
Figure 3~5
Figure 6
AI summary
The present application relates to communication methods, devices, a computer-readable storage medium, a computer program product and a computer program. A method comprises: a first device sends to a second device first information from a core network side device, the first information comprising a first message authentication code, the first message authentication code being related to a first shared key, the first shared key being shared between the second device and the core network side device and/or a target service device, and the first message authentication code being used for the second device to authenticate the core network side device; and the first device receives a first key from the core network side device, the first key being used for communication between the first device and the second device, and the first device being used for transmitting data between the second device and the target service device.