Cloud Device Security via Concierge Profile Matching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for connecting devices to the cloud lack adequate security measures, exposing them to risks of data breaches and unauthorized access, particularly in IIoT applications, where clients with varying security profiles are not differentiated, leading to potential vulnerabilities.

Innovation Solution

A concierge service is used to determine a suitable security profile for each client based on its security functions and connect it to a corresponding communication channel, allowing for differentiated treatment of clients with different security features, enabling secure communication channels that support various encryption levels and microservices activation based on the profile.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If all clients are connected to the cloud using the same communication channel without differentiation, then the system is simple to operate and manage, but security is compromised because clients with varying security profiles cannot be protected appropriately

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the cloud communication infrastructure into multiple communication channels, each tailored to specific security profiles. The concierge service divides clients into different groups based on their security capabilities and assigns them to appropriate channels, thereby providing differentiated security protection without requiring complete system redesign.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by customizing the security characteristics of individual communication channels according to the specific needs and capabilities of client groups. Each channel is optimized with appropriate encryption and security measures matching the security profile of assigned clients, rather than applying uniform security across all channels.

Inventive Principle:
Principle #3Local quality

2Reliability

If security checks and concierge services are implemented to differentiate clients based on security profiles, then security is improved, but the connection process becomes more complex and time-consuming

Engineering Contradiction:
ImprovesecurityVSAvoidconnection time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The concierge service performs security profile assessment and communication channel assignment in advance, before actual data transmission begins. By pre-evaluating client security capabilities and pre-assigning appropriate channels, the system avoids time-consuming security checks during active communication, thereby reducing overall connection time while maintaining security.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If multiple communication channels with different security profiles are implemented, then security is enhanced through differentiated protection, but the device complexity and management overhead increase

Engineering Contradiction:
ImprovesecurityVSAvoidease of management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The concierge service acts as an intermediary between clients and the cloud infrastructure, automatically managing the complexity of multiple communication channels. It handles security profile assessment, channel selection, and assignment without requiring manual intervention from clients or cloud administrators, thereby maintaining ease of operation despite the underlying system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Adaptability or versatility

If clients with weaker security profiles are allowed to connect to the cloud, then adaptability and client compatibility are improved, but security risks increase due to potential data manipulation and unauthorized access

Engineering Contradiction:
Improveclient compatibilityVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent converts the security limitations of clients with weaker security profiles into a benefit by assigning them to communication channels with appropriate security measures. Instead of rejecting these clients or forcing them to use insecure channels, the system adapts the channel security to match the client capabilities, thereby enabling their participation while still providing protection against security risks.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Data Source

PatentEP3529967B1Method for connecting devices to the so-called cloud, computer program with an implementation of the method and processing unit for executing the method
Publication Date: 2023.10.11 SIEMENS AG
  • EP3529967B1 patent drawingFigure 1~2
  • EP3529967B1 patent drawingFigure 3
  • EP3529967B1 patent drawingFigure 4

AI summary

The invention makes it possible to securely connect devices (12-16) to the cloud (10) by virtue of the particular device (12-16) first of all being connected to a concierge service (24) of the cloud (10) and transmitting information relating to the security functions offered by the device (12-16) to said service, whereupon the concierge service (24) determines, on the basis of the information which is transmitted by the requesting device (12-16) and relates to the security functions of the latter, a security profile which is appropriate for the device (12-16) and connects the requesting device (12-16) to a communication channel (26-30) appropriate for the determined security profile.