Cloud-to-Device Mediator Service for Secure IoT Onboarding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current IoT device management and network configurations face challenges in securely onboarding new devices and establishing trust relationships with cloud services, particularly in heterogeneous networks, where existing methods often require complex isolation and limited access until full onboarding, hindering efficient integration and interaction among devices from different domains.

Innovation Solution

The implementation of a cloud-to-device mediator service that dynamically configures and operates within an IoT framework, enabling secure onboarding and interaction by creating sandbox domains for untrusted devices, allowing limited access and facilitating interactions between untrusted devices and cloud services without prior in-band trust negotiations, and the use of a proxy access service to enable roaming IoT devices to access local networks while preserving security and access control policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If complex isolation and limited access are implemented for untrusted devices during onboarding, then security is improved, but device complexity and integration difficulty increase

Engineering Contradiction:
ImprovesecurityVSAvoidonboarding complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a mediator service as an intermediary component that manages the onboarding process between untrusted devices and the trusted domain. The mediator service handles device introduction, credential distribution, and access control, isolating the complexity from both the devices and the core system. This allows untrusted devices to be onboarded without requiring them to directly implement complex security protocols, while maintaining strong security through the mediator's controlled access management.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If in-band trust negotiations are required before device interaction, then security is improved, but onboarding time and operational efficiency deteriorate

Engineering Contradiction:
Improvetrust relationship securityVSAvoidonboarding time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary trust establishment through out-of-band provisioning mechanisms. Device credentials and trust relationships are established before the devices need to interact, using separate provisioning channels. The mediator service pre-configures access policies and distributes credentials in advance, so that when devices join the network, they can immediately communicate securely without performing time-consuming in-band trust negotiations.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If sandbox domains are created for untrusted devices, then security isolation is improved, but network complexity and resource consumption increase

Engineering Contradiction:
Improvesecurity isolationVSAvoidnetwork configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements network segmentation by creating isolated sandbox domains for untrusted devices. Each sandbox domain acts as a separate network segment that restricts communication to only authorized devices and services. The mediator service dynamically manages these segments, allocating resources and configuring access controls automatically. This segmentation provides strong security isolation while the automation of segment management reduces the operational complexity of maintaining multiple network segments.

Inventive Principle:
Principle #1Segmentation

4Adaptability or versatility

If mediator service dynamically configures access control, then adaptability is improved, but system complexity increases

Engineering Contradiction:
Improvedynamic access control adaptabilityVSAvoidmediator service complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic access control through the mediator service, which can adaptively configure permissions and policies based on device identity, purpose, and current network conditions. Access control rules are not static but can be modified in real-time as devices are onboarded, move between domains, or change their operational state. The mediator service maintains a dynamic view of the network and automatically adjusts access controls to maintain security while enabling appropriate device interactions.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11770383B2Cloud-to-device mediator service from services definition
Publication Date: 2023.09.26 INTEL CORP
  • US11770383B2 patent drawing
  • US11770383B2 patent drawing
  • US11770383B2 patent drawing

AI summary

Various systems and methods of establishing and utilizing device management (DM) services in Internet of Things (IoT) networks and similar distributed network architectures, are described herein. In an example, a Cloud-To-OCF Device mediator service may be established from OCF services definition; this mediator service may be used to establish connectivity between a cloud-capable device and a cloud-based service. Further systems and methods to provide a proxy access service (PAS) hosted on a cloud service provider, that enable a PAS to coordinate and preserve device-to-device interactions from end-to-end, are also disclosed.