Bridge Device Control in IoT Networks via Publish-Subscribe Messaging

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The proliferation of network-enabled devices in IoT environments poses challenges in securing interactions and communications within local networks, including determining authorized users and devices, ensuring secure communication, and managing the addition of new devices without compromising security.

Innovation Solution

A system that includes a bridge device and a server implementing power-on provisioning, third-party messaging, and load balancing through an encrypted publish-subscribe model, using device-specific encryption keys and a message broker for secure channel management and communication routing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If network-enabled devices are added to IoT environments, then device connectivity and functionality are improved, but security risks and complexity of managing authorized interactions increase

Engineering Contradiction:
Improvedevice connectivityVSAvoidsecurity management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a bridge device as an intermediary component that mediates all communications between IoT devices and external networks. This bridge device implements security policies, manages authentication, and controls authorized interactions, thereby reducing the security management burden on individual devices and simplifying overall system security while maintaining device connectivity

Inventive Principle:
Principle #24Intermediary (Mediator)

2Quantity of substance

If new devices are added to the network, then network functionality and device volume increase, but determining authorized users and securing communications becomes more difficult

Engineering Contradiction:
Improvedevice volumeVSAvoidauthorization management
Core Design Contradiction:
Quantity of substanceVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements preliminary provisioning and authentication mechanisms where devices and users are pre-configured with credentials and authorization policies before joining the network. The bridge device maintains provisioning information and authorization data in advance, enabling seamless integration of new devices without compromising security or requiring complex real-time authorization decisions

Inventive Principle:
Principle #10Preliminary action

3Reliability

If secure communication channels are established between devices, then communication security is improved, but system complexity and provisioning requirements increase

Engineering Contradiction:
Improvecommunication securityVSAvoidprovisioning system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges security functions including encryption, authentication, and channel management into a centralized bridge device. This consolidation reduces the complexity burden on individual IoT devices while maintaining strong security, as the bridge device handles cryptographic operations and provisioning centrally, simplifying the overall system architecture

Inventive Principle:
Principle #5Merging (Combining)

4Reliability

If a centralized security system is implemented to manage device interactions, then security control and authorization management are improved, but system complexity and processing requirements increase

Engineering Contradiction:
Improvesecurity controlVSAvoidprocessing requirements
Core Design Contradiction:
ReliabilityVSPower

Solution Approach 1:

The patent extracts complex security processing requirements from resource-constrained IoT devices and relocates them to the more powerful bridge device. This extraction allows simple, low-power sensor and actuator devices to maintain basic functionality while the bridge device handles computationally intensive tasks such as cryptographic operations, authorization decisions, and security policy enforcement

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11520897B2Bridge computing device control in local networks of interconnected devices
Publication Date: 2022.12.06 DELPHIAN SYSTEMS LLC
  • US11520897B2 patent drawing
  • US11520897B2 patent drawing
  • US11520897B2 patent drawing

AI summary

Systems, methods, and apparatus for using a message broker that implements a publish-subscribe messaging protocol to exchange messages between a remote server and a bridge computing device of a local network of interconnected devices are disclosed. In one example, a bridge computing devices transmits to a remote server, a provisioning request in response to achieving a power-on state. The server generates and transmits, to the bridge computing device, a provisioning response that includes information indicating a channel to which the remote server will publish messages and a channel to which the bridge computing device should publish messages. The bridge computing device subscribes to the channel the server will publish to, and the server subscribes to the channel the bridge computing device will publish to. Third-party computing devices may also subscribe and publish to the channels in order to receive and provide messages to the bridge computing device.