Communication Control Apparatus for Secure IoT Network Interconnection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication systems face challenges in securely connecting devices operating on closed networks to open networks, particularly in IoT environments, where unauthorized access can occur through open networks.

Innovation Solution

A communication system is implemented with a first communication control apparatus connected between a network connection apparatus and a first client apparatus, a second communication control apparatus connected between the network connection apparatus and a second client apparatus, and a communication control management apparatus that manages communication by encrypting data using SSL/TLS protocols and utilizing IC cards for authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a system protected by a unique network is connected to an open network to enable data collection and utilization, then the system can access and share data across networks, but the system becomes vulnerable to unauthorized access via the open network

Engineering Contradiction:
Improvenetwork connectivityVSAvoidunauthorized access
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

A communication control apparatus is introduced as an intermediary between the closed network system and the open network. This apparatus selectively controls packet transmission, allowing legitimate data collection while blocking unauthorized access attempts. The intermediary maintains the isolation benefits while enabling necessary connectivity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The network communication is segmented into controlled and uncontrolled portions. The communication control apparatus divides packet flow into authorized data collection traffic and potential unauthorized access traffic, applying different handling rules to each segment to maintain security while enabling connectivity.

Inventive Principle:
Principle #1Segmentation

2Object-affected harmful factors

If communication control apparatuses are introduced to manage network security, then unauthorized access is prevented, but the device complexity increases

Engineering Contradiction:
Improveunauthorized access preventionVSAvoidcommunication control apparatus
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The communication control apparatus automatically monitors incoming packets, identifies unauthorized access attempts, and blocks them without requiring constant human intervention. The system serves itself by maintaining security policies and making real-time decisions, reducing operational complexity despite increased device complexity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Security rules and authorization criteria are pre-configured in the communication control apparatus before deployment. This preliminary setup allows the device to automatically handle security decisions without complex real-time analysis, simplifying operation while maintaining robust security controls.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12218774B2Communication system and computer-readable storage medium
Publication Date: 2025.02.04 KK TOSHIBA
  • US12218774B2 patent drawing
  • US12218774B2 patent drawing
  • US12218774B2 patent drawing

AI summary

According to an embodiment, a communication system includes a first communication control apparatus connected between a network connection apparatus and a first client apparatus, a second communication control apparatus connected between the network connection apparatus and a second client apparatus, and a communication control management apparatus that is connected to the network connection apparatus and manages communication by the first communication control apparatus and second communication control apparatus. The communication control management apparatus monitors communication based on management information defining regular communication between the first client apparatus and the second client apparatus as communication by the first packet including the first virtual tag, and defining regular communication between the communication control management apparatus and the first communication control apparatus or second communication control apparatus as communication by the second packet including the second virtual tag.