Split Secret Cryptography for IoT Payment Credential Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
IoT devices are susceptible to security threats due to the need to store payment credential data, which exposes it to misappropriation risks, while lacking access to this data renders them unable to perform electronic transactions.
Innovation Solution
Implementing split secret cryptography-based security by splitting payment credential data into credential elements stored on a client device and a router, allowing secure reconstruction for transactions without permanent storage, thereby reducing exposure to security risks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If payment credential data is stored within the memory of the IoT device, then the device can perform electronic payment transactions, but the data becomes vulnerable to security threats and misappropriation
Solution Approach 1:
The payment credential data is segmented into multiple credential elements that are distributed across different devices (client device, router, and IoT device). Each device holds only a portion of the credential data, making it impossible for any single device to access the complete payment information. This segmentation resolves the contradiction by enabling transaction capability while eliminating the security vulnerability of storing complete credentials in one location.
Solution Approach 2:
A router is introduced as an intermediary device that facilitates secure credential reconstruction during transactions. The router receives credential elements from both the client device and the IoT device, temporarily reconstructs the payment credential data, and uses it for transaction processing. After the transaction, the router deletes the reconstructed data. This intermediary approach allows the IoT device to perform transactions without permanently storing sensitive credential data.
2Object-affected harmful factors
If payment credential data is not stored in the IoT device, then security risks are reduced, but the device becomes unable to implement electronic payment transactions
Solution Approach 1:
The system performs preliminary actions by pre-distributing credential elements to the IoT device, router, and client device before any transaction occurs. The IoT device receives and stores a first credential element in advance, while the router receives a second credential element. When a transaction is needed, these pre-positioned elements are quickly combined without requiring the IoT device to store complete credential data, thus maintaining both security and transaction capability.
Solution Approach 2:
The system transitions from a static storage model (where credentials are permanently stored in one location) to a dynamic reconstruction model. The complete payment credential data exists only temporarily during transaction processing, dynamically assembled from distributed elements. This dynamic approach allows the IoT device to have transaction capability without permanent storage vulnerability, resolving the contradiction between security and operational ability.
Data Source
AI summary
The invention provides methods, systems and computer program products for securely provisioning an internet-of-things (IoT) device for implementing an electronic payment transaction. The invention comprises (i) retrieving a first credential element from the client device, and a second credential element from a router, (ii) generating payment credential data by applying split secret cryptography based reconstruction to the first credential element and the second credential element, (iii) retrieving a unique identifier associated with the IoT device, (iv) generating a combined data element comprising the payment credential data and the unique identifier associated with the loT device, (v) applying split secret cryptography based splitting to the combined data element to generate a first verifiable secure element and a second verifiable secure element, (vi) storing the first verifiable secure element and the retrieved unique identifier within the router, and (vii) storing the second verifiable secure element within the IoT device.


