Device Certificate Access Zone for IoT Infrastructure
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The challenge in connecting devices to IoT infrastructure lies in creating a secure and user-friendly communications protocol that allows authorized devices to access functions within the network, while existing methods are laborious and inefficient, especially with the distribution of private keys for multiple devices.
Innovation Solution
A method involving the creation of a device certificate for each end device, which is used to register and identify the device within a linkable computer infrastructure's access zone, enabling secure and convenient access to the infrastructure's functions, utilizing a demilitarized zone with controlled access and protocols like OPC UA PubSub for secure communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If prior registration of devices in cloud backend is used for connection, then security is improved, but connection effort and time increase significantly with increasing number of devices
Solution Approach 1:
The patent introduces an access zone as an intermediary component between end devices and the cloud backend. This access zone handles device registration and authentication, eliminating the need for direct device-by-device registration in the cloud backend. The access zone acts as a mediator that manages multiple devices collectively, thereby maintaining security while significantly reducing connection effort and time.
Solution Approach 2:
The system is segmented into distinct functional zones: the access zone for device registration and authentication, and the cloud backend for core services. This segmentation allows the access zone to handle authentication tasks independently, preventing the scaling overhead from propagating to the cloud backend and enabling efficient handling of multiple devices.
2Reliability
If device certificates are created and distributed to multiple devices, then authentication security is improved, but distribution effort and complexity increase
Solution Approach 1:
The access zone serves as an intermediary that centralizes certificate management. Instead of distributing certificates directly to multiple devices from the cloud backend, the access zone receives a single certificate from the cloud backend and then distributes it to multiple end devices. This intermediary approach maintains authentication security while dramatically simplifying distribution logistics.
Solution Approach 2:
The patent employs certificate copying as a strategy. A single device certificate is obtained from the cloud backend and then copied and distributed to multiple end devices through the access zone. This copying approach maintains security (as the certificate is properly managed through the intermediary) while eliminating the complexity of individual certificate generation and distribution for each device.
3Ease of operation
If direct connection between end devices and cloud backend is established, then connection simplicity is improved, but security control and access management become difficult
Solution Approach 1:
The access zone is positioned as a necessary intermediary between end devices and the cloud backend. While this adds a layer to the connection architecture, it provides essential security control and access management functions. The access zone can authenticate devices, manage permissions, and control access to cloud services, thereby maintaining both security and operational simplicity.
4Reliability
If multiple authentication methods are implemented for device verification, then authentication security is improved, but connection process complexity increases
Solution Approach 1:
The patent merges multiple authentication functions into a single integrated access zone. Instead of implementing separate authentication mechanisms at different levels (device-to-cloud, device-to-service, etc.), all authentication and authorization functions are combined in the access zone. This consolidation maintains comprehensive security while simplifying the connection process for end devices.
Data Source
AI summary
A method for connecting an end device to a linkable computer infrastructure is provided. A device certificate is created and supplied to a user of the end device. The device certificate is input into the end device. A data link from the end device to an access zone connected upstream of functions of the linkable computer infrastructure is produced. The access zone may be selectively separated from the functions of the linkable computer infrastructure by this link. The end device is registered in the access zone using the device certificate. By access of a function from the linkable computer infrastructure to the end device registered in the access zone, this end device is identified for the linkable computer infrastructure. With successful identification of the end device, use of the linkable computer infrastructure is enabled for the end device.
