Agent-Based Secure Tunnels for IoT Endpoint Cloud Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current SD-WAN technologies fail to provide secure connectivity from IoT endpoints to remote operation centers, especially across private and public networks, raising health and safety concerns in industries like mining and automotive, where equipment data needs to be monitored autonomously without complete exposure.

Innovation Solution

An agent-based system establishes a secure tunnel from endpoints to cloud servers using unique keys generated by agents installed on endpoints, enabling secure connection, monitoring, and anomaly detection with AI/ML-driven self-healing capabilities, eliminating the need for MPLS/SD-WAN investments and supporting Zero Trust Networking.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional VPN and SD-WAN branch edges are used for connectivity, then network connectivity is established, but security is compromised as machines data is exposed on IT network across IoT network boundary

Engineering Contradiction:
ImprovesecurityVSAvoidnetwork architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

An agent is introduced as an intermediary component installed on each endpoint device. This agent establishes direct secure tunnels to cloud servers, acting as a mediator that eliminates the need for traditional VPN/SD-WAN infrastructure while maintaining security. The agent handles authentication, encryption, and data transmission, thereby resolving the contradiction between security and infrastructure complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The network architecture is segmented into independent endpoint-to-cloud tunnels rather than a centralized VPN infrastructure. Each endpoint operates independently with its own secure connection, eliminating the single point of failure and security exposure inherent in traditional SD-WAN architectures while reducing overall system complexity.

Inventive Principle:
Principle #1Segmentation

2Reliability

If complete private network connectivity is implemented from trucks to remote operation center, then security is improved, but adaptability deteriorates as connectivity cannot cross public networks

Engineering Contradiction:
ImprovesecurityVSAvoidnetwork connectivity flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system dynamically changes security parameters based on network conditions. When connected to private networks, it uses enhanced security protocols; when transitioning to public networks, it adjusts encryption and authentication parameters accordingly. This allows the system to maintain security while adapting to different network environments, resolving the contradiction between security and adaptability.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If centralized monitoring and control is implemented, then operational control is improved, but device complexity increases due to infrastructure requirements

Engineering Contradiction:
Improvecentralized controlVSAvoidinfrastructure complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The agent on each endpoint performs self-registration, self-authentication, and self-configuration with cloud servers. This eliminates the need for complex centralized infrastructure for device provisioning and management. The endpoint devices serve themselves by automatically establishing secure connections and reporting status, thereby achieving centralized control with minimal infrastructure complexity.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12537804B2Agent-based establishment of secure connection between endpoints and cloud servers
Publication Date: 2026.01.27 INFOSYS LTD
  • US12537804B2 patent drawing
  • US12537804B2 patent drawing
  • US12537804B2 patent drawing

AI summary

A method and/or system for agent-based establishment of secure connection between endpoints and cloud servers is disclosed wherein a deployment information is received at an agent controller comprising information of endpoint and a cloud server for establishing secure connection and monitoring. The endpoint is registered by the agent controller by generating a unique key and authenticating the endpoint using the installed agent causing establishment of dedicated secure channel between the endpoint and the cloud server over a computer network. The connected endpoint may be monitored by the agent controller to collect data and any anomaly may be detected based on the collected data and the detected anomaly may be resolved by the agent controller.