Methods and apparatus for operating a constrained device
A method ( 600 ) for operating a constrained device is disclosed, the constrained device being operable to communicate with an entity over a network. The method, performed by the constrained device, comprises generating a message for transmission to the entity ( 602 ), encrypting the generated message by applying a Pseudo Random Binary Sequence (PRBS) to the generated message ( 604 ), and transmitting the encrypted message to the entity ( 606 ). Also disclosed is a method ( 700 ) for operating an entity comprising receiving an encrypted message from a constrained device ( 702 ) and decrypting the encrypted message by applying a PRBS to the encrypted message. In some examples of the present disclosure, a constrained device and entity may dynamically renew the PRBS used for encryption and decryption of exchanged messages.
1 . A method performed by a constrained device that is operable to communicate with an entity over a network, the method comprising:
generating a message for transmission to the entity;
encrypting the generated message by applying a Pseudo Random Binary Sequence (PRBS) to the generated message, wherein the PRBS is based on a first characteristic polynomial and a Linear Feedback Shift Register (LFSR) of the constrained device is configured according to the first characteristic polynomial; and
transmitting the encrypted message to the entity, wherein the encrypted message excludes and is not transmitted with any identification of the first characteristic polynomial.
2 . The method of claim 1 , wherein applying the PRBS to the generated message comprises one or more of the following:
adding the PRBS to the generated message using modulo-2 addition, and
inputting the generated message to the LFSR configured according to the first characteristic polynomial.
3 . The method of claim 1 , wherein the first characteristic polynomial is one of the following: a Primitive Binary Polynomial or a default polynomial.
4 . The method of claim, 3 , further comprising, upon expiry of an encryption renewal trigger, configuring the LFSR in accordance with a second characteristic polynomial different from the first characteristic polynomial.
5 . The method of claim 4 , wherein the encryption renewal trigger comprises at least one of sending or receiving a periodic message for the purpose of maintaining a connection with the entity.
6 . The method of claim 4 , further comprising obtaining the second characteristic polynomial based on one of the following:
selecting a next candidate polynomial, from a set of candidate polynomials, based on an ordered cyclical progression through the set of candidate polynomials;
calculating a function of a previous message and selecting from the set of candidate polynomials a polynomial that is determined by the calculated result of the function; or
calculating a function of a previous message and selecting from the set of candidate polynomials a polynomial that is a number of polynomials after the currently programmed characteristic polynomial, the number comprising the calculated result of the function.
7 . The method of claim 6 , further comprising sending to the entity a further message indicating one or more of the following:
the previous message on which the selection of the second characteristic polynomial is based; and
the second characteristic polynomial.
8 . The method of claim 1 , further comprising:
receiving a second encrypted message from the entity; and
decrypting the second encrypted message by applying the PRBS to the second encrypted message, thereby generating a second message.
9 . The method of claim 8 , further comprising:
applying the PRBS to the second message to generate a check message;
generating an error signal representing a comparison between the check message and the second encrypted message; and
when the error signal exceeds a threshold, sending an encryption reset message to the entity and configuring the LFSR in accordance with a default characteristic polynomial.
10 . A method performed by an entity operable to communicate with a constrained device over a network, the method comprising:
receiving an encrypted message from the constrained device; and
decrypting the encrypted message by applying a Pseudo Random Binary Sequence (PRBS) to the encrypted message, wherein:
the PRBS is based on a first characteristic polynomial,
a Linear Feedback Shift Register (LFSR) of the entity is configured according to the first characteristic polynomial, and
the encrypted message excludes and is not transmitted with any identification of the first characteristic polynomial.
11 . The method of claim 10 , wherein applying the PRBS to the encrypted message comprises one or more of the following:
adding the PRBS to the encrypted message using modulo-2 addition; and
inputting the encrypted message to the LFSR configured according to the first characteristic polynomial.
12 . The method of claim 10 , wherein the first characteristic polynomial is one of the following: a Primitive Binary Polynomial or a default polynomial.
13 . The method of claim 12 , further comprising, upon expiry of an encryption renewal trigger, configuring the LFSR in accordance with a second characteristic polynomial different from the first characteristic polynomial.
14 . The method of claim 13 , wherein the encryption renewal trigger comprises at least one of sending or receiving a periodic message for the purpose of maintaining a connection with the constrained device.
15 . The method of claim 13 , further comprising obtaining the second characteristic polynomial based on one of the following:
selecting a next candidate polynomial, from a set of candidate polynomials, based on an ordered cyclical progression through the set of candidate polynomials;
calculating a function of a previous message and selecting from the set of candidate polynomials a polynomial that is determined by the calculated result of the function; or
calculating a function of a previous message and selecting from the set of candidate polynomials a polynomial that is a number of polynomials after the currently programmed characteristic polynomial, the number comprising the calculated result of the function.
16 . The method of claim 15 , wherein obtaining the second characteristic polynomial is further based on receiving from the constrained device a further message indicating one or more of the following: the second characteristic polynomial, and the previous message on which the selection of the second characteristic polynomial is to be based.
17 . The method of claim 10 , further comprising:
applying the PRBS to the decrypted message to generate a check message;
generating an error signal representing a comparison between the check message and the received encrypted message; and
when the error signal exceeds a threshold, sending an encryption reset message to the constrained device and configuring the LFSR in accordance with a default characteristic polynomial.
18 . The method of claim 10 , further comprising:
generating a second message for transmission to the constrained device;
encrypting the second message by applying the PRBS to the second message; and
transmitting the encrypted second message to the constrained device.
19 . A constrained device operable to communicate with an entity over a network, the constrained device comprising:
a processor; and
a memory storing instructions executable by the processor, whereby execution of the instructions configures the constrained device to:
generate a message for transmission to the entity;
encrypt the generated message by applying a Pseudo Random Binary Sequence (PRBS) to the generated message, wherein the PRBS is based on a first characteristic polynomial and a Linear Feedback Shift Register (LFSR) of the constrained device is configured according to the first characteristic polynomial; and
transmit the encrypted message to the entity, wherein the encrypted message excludes and is not transmitted with any identification of the first characteristic polynomial.
20 . An entity operable to communicate with a constrained device over a network, the entity comprising:
a processor; and
a memory storing instructions executable by the processor, whereby execution of the instructions configures the entity to:
receive an encrypted message from the constrained device; and
decrypt the encrypted message by applying a Pseudo Random Binary Sequence (PRBS) to the encrypted message, wherein:
the PRBS is based on a first characteristic polynomial,
a Linear Feedback Shift Register (LFSR) of the entity is configured according to the first characteristic polynomial, and
the encrypted message excludes and is not transmitted with any identification of the first characteristic polynomial.