Wireless Sensor Mutual Authentication via TPM Private Key

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wireless sensors deployed in networks are susceptible to Man-in-the-Middle (MITM) attacks, which compromise encryption keys and allow attackers to decrypt or alter traffic, highlighting a need for resilient authentication technologies.

Innovation Solution

Implementing a method where a wireless sensor connects to a wireless access point using a private key stored in a Trusted Platform Module (TPM), performing mutual authentication with an authentication server via Transport Layer Security (TLS) protocol, deriving an encryption key from the mutual authentication, and using this key for secure communications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If wireless sensors use traditional authentication methods to connect to wireless networks, then ease of operation is improved, but security against MITM attacks deteriorates

Engineering Contradiction:
Improveease of connectionVSAvoidsecurity against MITM attacks
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies preliminary action by pre-provisioning each wireless sensor with a unique certificate and private key during manufacturing. This authentication credentials are embedded in the sensor's secure storage before deployment, enabling the sensor to perform mutual authentication with the authentication server before establishing any data connection, thereby preventing MITM attacks from the outset

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an authentication server as an intermediary between the wireless sensor and the wireless network. This server acts as a trusted mediator that verifies the sensor's identity using pre-shared certificates and private keys, and establishes secure encrypted connections. The intermediary prevents direct unauthenticated access to the network, blocking MITM attack vectors

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If wireless sensors store private keys securely in TPM to prevent MITM attacks, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent leverages the Trusted Platform Module (TPM) as a universal security component that serves multiple functions: secure key generation, private key storage, cryptographic operations, and authentication verification. By utilizing this multi-functional hardware security module, the patent achieves robust security without adding separate dedicated components for each security function, thereby limiting the increase in device complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If mutual authentication with certificate verification is implemented, then security against MITM attacks is improved, but processing time increases

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-configuring both the wireless sensor and the authentication server with certificates and public keys during manufacturing and initial setup. This pre-provisioning eliminates the need for complex real-time key exchange and certificate issuance during authentication, significantly reducing the time required for mutual authentication while maintaining security

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses digital certificates as verified copies of identity credentials that can be rapidly exchanged and validated. Instead of performing complex cryptographic key generation and exchange during authentication, the system uses pre-issued certificate copies that can be quickly verified using public key infrastructure, reducing authentication processing time while maintaining strong security

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11902781B2Methods and systems of wireless sensor authentication
Publication Date: 2024.02.13 NILE GLOBAL INC
  • US11902781B2 patent drawing
  • US11902781B2 patent drawing
  • US11902781B2 patent drawing

AI summary

Embodiments of a device and method are disclosed. In an embodiment, a method of communications involves from a wireless sensor deployed at a customer site, connecting to a wireless access point (AP) deployed at the customer site and based on a private key stored in the wireless sensor, performing mutual authentication between the wireless sensor and an authentication server connected to the wireless AP.