TLS Node Identity Generation Using Computational Difficulty

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current communication networks face challenges in ensuring unique and secure node identification, particularly in massive Machine Type Communications (mMTC) environments, where traditional identities like IMEI, MAC addresses, and IP addresses can be duplicated or spoofed, and existing authentication methods are costly and not scalable.

Innovation Solution

A TLS-based method that generates a unique persistent node identity using a difficulty controller to impose computational difficulty, allowing nodes to autonomously authenticate without relying on central authorities, and restricts identity usage to specific time periods, zones, or node types, using pseudo-random functions and Diffie-Hellman key exchanges.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If traditional public identities (IMEI, MAC addresses, IP addresses) are used for node identification, then identification can be easily generated and assigned, but uniqueness cannot be guaranteed as these identities can be duplicated or spoofed

Engineering Contradiction:
Improveease of identity generationVSAvoiduniqueness of identity
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent changes the parameters of identity generation by introducing a difficulty condition that requires computational effort (energy parameter) and limits the number of valid identities through a scarcity mechanism. This transforms the identity space from easily replicable public identities to computationally constrained unique identities that satisfy both ease of generation and uniqueness requirements.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces temporary, expiring identities that are valid only for specific time periods, zones, or purposes. These short-lived identities can be freely generated within their validity constraints, providing uniqueness during their active period while allowing easy rotation and revocation, thus resolving the uniqueness problem without requiring permanent centralized assignment.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

2Reliability

If pre-provisioned shared secrets are used for authentication, then secure authentication can be established, but the processes to distribute, renew and revoke secrets are tedious, costly and not scalable to massive Machine Type Communications

Engineering Contradiction:
Improvesecurity of authenticationVSAvoidscalability of authentication
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent enables nodes to autonomously generate their own identities and authentication credentials without requiring centralized distribution of secrets. The difficulty controller provides public parameters, and nodes independently compute their identities through cryptographic puzzles, eliminating the need for centralized secret management infrastructure and enabling massive scalability.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent performs authentication preparation in advance by having nodes pre-compute identities that satisfy the difficulty condition before network access is needed. These pre-computed identities can be stored and rapidly presented for authentication, eliminating real-time computational overhead during the authentication process itself and enabling fast access for massive numbers of devices.

Inventive Principle:
Principle #10Preliminary action

3Extent of automation

If Public Key Infrastructure (PKI) is used for authentication, then nodes can autonomously authenticate without real-time central authority contact, but the endpoint's public key certificate must be submitted and signed by the Certificate Authority in advance

Engineering Contradiction:
Improveautonomous authenticationVSAvoidtime for certificate issuance
Core Design Contradiction:
Extent of automationVSLoss of time

Solution Approach 1:

The patent replaces permanent, centrally-signed certificates with temporary, self-generated identities that expire after use or after a predetermined time period. These short-lived identities eliminate the need for lengthy certificate issuance processes while maintaining autonomous authentication, as nodes can independently generate valid identities without centralized signing infrastructure.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

4Quantity of substance

If random identities are generated without computational difficulty constraints, then a large number of unique identities can be created, but the network cannot resist Denial of Service attacks from exaggerated number of identities

Engineering Contradiction:
Improvenumber of unique identitiesVSAvoidvulnerability to DoS attacks
Core Design Contradiction:
Quantity of substanceVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a difficulty parameter that constrains the entropy and search space of valid identities. By requiring identities to satisfy a computational difficulty condition (e.g., cryptographic puzzles with specific solution characteristics), the system allows many identities to exist but makes it computationally infeasible to generate them in bulk, thus preventing DoS attacks while maintaining identity abundance.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3340530B1Transport layer security (TLS) based method to generate and use a unique persistent node identity, and corresponding client and server
Publication Date: 2021.04.28 ALCATEL LUCENT SA
  • EP3340530B1 patent drawingFigure 1
  • EP3340530B1 patent drawingFigure 2
  • EP3340530B1 patent drawingFigure 3

AI summary

A Transport Layer Security, abbreviated TLS, based method to generate and use a unique persistent node identity for identifying and authenticating a client (1) in a telecommunication network (2) comprises establishing a secure TLS connection between the client (1) and a server (3) and generating at the client (1) and the server (3) a shared secret key value K through a computational algorithm with a difficulty condition D obtained from a difficulty controller (7) and limiting the number of valid node identities.