Trusted Ephemeral Identifier for IoT Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

IoT devices with globally unique identifiers (GUIDs) face security risks due to ease of replay, storage, and reuse, leading to potential data mining and malicious access, especially in environments with numerous devices where security is relatively low, allowing collusions and increased vulnerabilities.

Innovation Solution

The implementation of a trusted ephemeral identifier (TEID) system, where a verifier device communicates with a prover device to establish a secure connection using Sigma protocol and key exchange, generating a TEID unique to each device for group participation, preventing identity and capability compromise, and ensuring privacy and security through ephemeral identifiers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If GUIDs are used to identify IoT devices, then device identification is achieved, but security risks increase due to ease of replay, storage, and reuse

Engineering Contradiction:
ImprovesecurityVSAvoiddata mining and malicious access
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies dynamics by replacing static GUIDs with dynamic TEIDs that change based on context. Each TEID is generated uniquely for a specific service context and time period, making it impossible for attackers to replay or store identifiers effectively. The TEID evolves with each service interaction, transforming the identification mechanism from static to dynamic, thereby resolving the security vulnerability.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent segments the identification system into multiple components: device identifier, service identifier, and time component. The TEID is constructed as a composite structure that combines these elements, ensuring that no single identifier can be reused across different services or time periods. This segmentation prevents cross-service attacks and data mining while maintaining unique device identification within each context.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If GUIDs are used in large IoT environments, then device identification is achieved, but collusions and vulnerabilities increase

Engineering Contradiction:
Improvedevice identificationVSAvoidcollusions and vulnerabilities
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

In large IoT environments, the dynamic nature of TEIDs prevents collusions between devices. Each device receives a unique TEID for each service context, and these identifiers change over time. This dynamic assignment makes it impossible for devices to coordinate attacks or share identification information across services, effectively countering collusion attempts in large-scale deployments.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces a trusted third party (the service provider or authorization server) as an intermediary that manages TEID assignment. This intermediary controls the generation and distribution of TEIDs, ensuring that each device receives a unique identifier appropriate for its specific service context. The intermediary acts as a mediator that prevents direct device-to-device identification leaks, thereby reducing vulnerabilities in large IoT environments.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If GUIDs are used to identify devices, then device recognition is achieved, but privacy is compromised due to correlation of transactions

Engineering Contradiction:
Improvedevice recognitionVSAvoidprivate information
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent segments the identification information into separate components: device identifier, service identifier, and temporal context. By separating these elements, the system can recognize devices for authentication purposes while preventing correlation of transactions across different services and time periods. Each TEID is scoped to a specific service context, ensuring that transaction data remains isolated and private.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent employs disposable TEIDs that are valid only for a specific service context and time period. After use, the TEID is discarded and a new one is generated for the next interaction. This short-lived identifier approach maintains ease of device recognition during active use while ensuring that private information cannot be correlated across time or services, as each TEID is single-use and context-specific.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS9635021B2Trusted ephemeral identifier to create a group for a service and/or to provide the service
Publication Date: 2017.04.25 INTEL CORP
  • US9635021B2 patent drawing
  • US9635021B2 patent drawing
  • US9635021B2 patent drawing

AI summary

Devices and methods may provide for generating and/or using a trusted ephemeral identifier (TEID) to create a group for a service, and/or to provide the service. A verifier device may assign a value to a group that is to be created to provide the service, wherein the value may identify the group and may be issued to the prover device for use to generate the TEID value that is unique to the prover device and to participation of the prover device in the group. In addition, a prover device may generate the TEID value, wherein the TEID may be derived from a combination of a unique value that may be generated in a trusted execution environment (TEE) of the prover device and the value that may identify the group.