IP Library › Granted Patent US 11,799,634
Granted Patent B2
US 11,799,634 · App. 17/490,511 · Granted Oct 24, 2023

Mesh network for resource-constrained devices

Inventors: Ridha Hamila (Doha, QA); Omar Ellabban (Doha, QA); Adel Gastli (Doha, QA); Ula Hijawi (Doha, QA); Devrim Unal (Doha, QA)
Assignees: QATAR FOUNDATION FOR EDUCATION, SCIENCE AND COMMUNITY DEVELOPMENT; IBERDROLA QSTP LLC; QATAR UNIVERSITY
H04L9/0825H04L9/083H04L9/0866
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,799,634
App. No.
17/490,511
Granted
Oct 24, 2023
Kind
B2
Abstract

IoT frameworks require flexible and scalable communication and security schemes that can be deployed on devices of low computational capabilities and memory (e.g., resource-constrained devices). A system is provided including a mesh network of resource-constrained devices creating a self-organizing and collaborative communication topology between the devices, and an attribute-based encryption security scheme integrated with the mesh network that enables the resource-constrained devices to communicate securely in unsecured channels by defining an access policy that can only be satisfied by the authorized resource-constrained devices. In order to integrate the attribute-based encryption scheme with the mesh network of resource-constrained devices, a serializer and deserializer are provided that prepare all communications to go through the attribute-based encryption scheme by converting all data and metadata into a suitable format for transmission over the network.

Claims (30)

1. A system for secure internet-of-things communications, the system comprising:

a management system;

a trusted third party system in communication with the management system;

a mesh network of a plurality of resource-constrained devices, wherein the plurality of resource-constrained devices include a root node in communication with the trusted third party system via a network, wherein each of the plurality of resource-constrained devices is directly or indirectly in communication with the root node, and wherein the root node is one of the plurality of resource-constrained devices; and

a key generator in communication with the trusted third party system and each of the plurality of resource-constrained devices, the key generator configured to generate a public key, a private key, and a decryption key, wherein the private key is stored within a memory of the key generator, wherein the public key is shared with the trusted third party system and each resource-constrained device capable of encrypting data, and wherein the decryption key is shared with the trusted third party system and one of the plurality of resource-constrained devices which is capable of decrypting data,

wherein data is encrypted and decrypted between the trusted third party system and the plurality of resource-constrained devices in the mesh network via an attribute-based encryption scheme integrated with the mesh network.

2. The system of claim 1 , wherein the attribute-based encryption scheme is a key policy attribute-based encryption scheme.

3. The system of claim 1 , wherein the root node is automatically selected from the plurality of resource-constrained devices.

4. The system of claim 3 , wherein the root node is automatically selected based on a signal strength of each of the plurality of resource-constrained devices with respect to an access point.

5. The system of claim 4 , wherein the resource-constrained device with the greatest signal strength is selected as the root node.

6. The system of claim 1 , wherein the root node is manually selected by a user of the system.

7. The system of claim 1 , wherein a resource-constrained device indirectly in communication with the root node communicates with the root node via another resource-constrained device of the plurality of resource-constrained devices.

8. The system of claim 1 , wherein the root node is in communication with the management system via the network through an access point.

9. The system of claim 8 , wherein the access point is a router.

10. The system of claim 8 , wherein the access point is the trusted third party.

11. The system of claim 1 , wherein each of the plurality of resource-constrained devices includes a sensor or an actuator.

12. The system of claim 1 , wherein at least one of the plurality of resource-constrained devices is a mobile device.

13. The system of claim 1 , wherein each of the plurality of resource-constrained devices includes an internal power source.

14. The system of claim 1 , wherein at least one of the plurality of resource-constrained devices includes a serializer having a multi-stage binarizer configured to break down each component of an object of the attribute-based encryption scheme into its low-level counterparts, the components of the object of the attribute-based encryption scheme including a ciphered message, the decryption key, encryption parameters, and the private key.

15. The system of claim 1 , wherein at least one of the plurality of resource-constrained devices includes a deserializer comprising a disaggregator configured to disaggregate a character vector of a received serialized object into character vectors corresponding to each component of an object of the attribute-based encryption scheme, the components of the object of attribute-based encryption scheme including a ciphered message, the decryption key, encryption parameters, and the private key.

16. The system of claim 15 , wherein the deserializer further comprises a multi-stage debinarizer configured to deserialize the character vectors corresponding to each component of the object of the attribute-based encryption scheme into original complex objects.

17. A system for secure internet-of-things communications, the system comprising:

a management system;

a trusted third party system in communication with the management system;

a mesh network including a plurality of resource-constrained devices, each of the plurality of resource-constrained devices being a sensor, an actuator, or a sensor/actuator, wherein the plurality of resource-constrained devices include a root node in communication with the trusted third party via a network, wherein each of the plurality of resource-constrained devices is directly or indirectly in communication with the root node, and wherein the root node is one of the plurality of resource-constrained devices; and

a key generator in communication with the trusted third party system and each of the plurality of resource-constrained devices, the key generator configured to generate a public key, a private key, and a decryption key, wherein the private key is stored within a memory of the key generator, wherein the public key is shared with the trusted third party system and each sensor and sensor/actuator of the resource-constrained devices, and wherein the decryption key is shared with the trusted third party system and each actuator and sensor/actuator of the resource-constrained devices,

wherein data is encrypted and decrypted between the trusted third party system and the plurality of resource-constrained devices in the mesh network via a key policy attribute-based encryption scheme integrated with the mesh network.

18. The system of claim 17 , wherein the key policy attribute-based encryption scheme is programmed in a respective memory of each of the plurality of resource constrained devices.

19. The system of claim 17 , wherein each of the plurality of resource-constrained devices is in wireless communication with one another.

20. The system of claim 17 , wherein the management system is configured to receive data from one or more of the plurality of resource-constrained devices via the trusted third party and to transmit a command to one or more of the plurality of resource-constrained devices via the trusted third party based on the received data.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 11, 2022
From: HIJAWI, ULA; UNAL, DEVRIM; HAMILA, RIDHA; GASTLI, ADEL; ELLABBAN, OMAR
To: QATAR FOUNDATION FOR EDUCATION, SCIENCE AND COMMUNITY DEVELOPMENT; IBERDROLA QSTP LLC; QATAR UNIVERSITY
Reel/Frame 058620/0647 →
Continuity (2)
Provisional Application 63085276 · Sep 30, 2020
Related Publication 20220103353A1 · Mar 31, 2022