Unified Security Object for M2M IoT Connections

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current machine-to-machine (M2M) communication techniques in IoT devices lack efficiency in establishing secure communication sessions, leading to increased data storage and transmission burdens due to the need for individual security object instances for each connection option, which is resource-intensive and inefficient.

Innovation Solution

A single security object is implemented on client devices, allowing them to generate a Server Security URI by selecting from server connection data, reducing the need for multiple security object instances and minimizing credential data duplication, thereby enabling secure communication across multiple connection options using a unified security object.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If individual security object instances are created for each connection option, then secure communication can be established for each protocol, but storage requirements and data transmission burdens increase

Engineering Contradiction:
Improvesecure communication establishmentVSAvoidstorage requirements
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent merges multiple security object instances into a single unified security object that contains security credentials applicable to multiple connection options. Instead of maintaining separate security objects for each protocol (CoAP, HTTPS, MQTT), the system consolidates them into one object that can be reused across different connection types, thereby reducing storage requirements while maintaining secure communication capabilities.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The unified security object is designed to be universal and multi-functional, serving multiple connection options simultaneously. The security credentials stored in this single object can be used across different protocols and connection types, making the security object applicable to various communication scenarios without requiring protocol-specific duplications.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If individual security object instances are created for each connection option, then protocol-specific security can be ensured, but communication overhead increases

Engineering Contradiction:
Improveprotocol-specific securityVSAvoidcommunication overhead
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent reduces communication overhead by merging security credential management into a single object. Instead of transmitting or managing multiple separate security objects for different protocols, the system communicates with a single unified security object, thereby reducing the volume of data transmitted and the complexity of security management operations.

Inventive Principle:
Principle #5Merging (Combining)

3Adaptability or versatility

If multiple security object instances are maintained, then connection flexibility is provided, but device complexity increases

Engineering Contradiction:
Improveconnection flexibilityVSAvoidsecurity object management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The unified security object provides connection flexibility by supporting multiple connection options (CoAP, HTTPS, MQTT) within a single object. This universal approach allows the device to adapt to different protocols and connection types without requiring separate security object instances, thereby maintaining versatility while reducing the complexity of managing multiple security objects.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11949664B2Machine to machine communications
Publication Date: 2024.04.02 ARM LTD
  • US11949664B2 patent drawing
  • US11949664B2 patent drawing
  • US11949664B2 patent drawing

AI summary

Broadly speaking, the present techniques relate to a computer implemented method for establishing a secure communication session between a client device and a server, the method performed at the client device comprising: obtaining a security object comprising at least one security credential and server connection data for multiple connection options to a first server, wherein the security credential is to be used for each of the multiple connection options; generating, a first server security universal resource identifier (URI), the first Server Security URI comprising server contact information for the first server and a first security binding selected from the server connection data; communicating with the first server using the first Server Security URI and the at least one security credential to establish a secure communication session between the client device and the first server.