Containerized IoT Gateway Architecture for Secure Device Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current IoT management systems lack efficient containerized architectures to securely manage and provide network connectivity to Internet-connected devices, leading to challenges in resource isolation, access control, and secure data processing.

Innovation Solution

Implementing a containerized architecture using Linux Containers (LXC) on an IoT gateway, which includes an edge agent for provisioning, securing, and managing IoT devices, along with a security proxy for policy-based access to backend services, ensuring secure and controlled access to sensors through a consistent API.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional IoT management systems are used, then device connectivity and basic management are achieved, but resource isolation and security control are insufficient

Engineering Contradiction:
Improvesecurity controlVSAvoidmanagement architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies segmentation by dividing the IoT management system into isolated container environments. Each IoT device or application runs in a separate container with defined resource limits and security boundaries. This segmentation provides strong resource isolation and security control while maintaining manageable system complexity through modular architecture.

Inventive Principle:
Principle #1Segmentation

2Reliability

If containerized architecture is implemented, then resource isolation and security are improved, but system complexity increases

Engineering Contradiction:
Improveresource isolationVSAvoidcontainer management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary component (container management system/orchestration layer) that handles the complexity of containerized architecture. This intermediary manages container provisioning, resource allocation, security policies, and lifecycle operations, thereby providing strong resource isolation while shielding users from the underlying complexity of container management.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If centralized management is used, then ease of operation is maintained, but network communication and storage resource consumption increase

Engineering Contradiction:
Improvedevice managementVSAvoidnetwork resource consumption
Core Design Contradiction:
Ease of operationVSLoss of energy

Solution Approach 1:

The patent applies local quality by enabling containers to process and manage data locally at the edge device rather than requiring all operations to communicate with centralized cloud services. This local processing reduces network communication and storage resource consumption while maintaining ease of operation through automated local container management for provisioning, monitoring, and updates.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10374869B2Containerized architecture to manage internet-connected devices
Publication Date: 2019.08.06 IVANTI INC
  • US10374869B2 patent drawing
  • US10374869B2 patent drawing
  • US10374869B2 patent drawing

AI summary

A containerized architecture to secure and manage Internet-connected devices, such as “Internet of Things” devices, is disclosed. In various embodiments, one or more containerized applications are run, e.g., on an Internet of Things gateway, subject to management by the management server. At least one of the containerized applications is a management agent configured to participate, subject to control of the management server, in management of one or more other of said containerized applications.