Device Certificate Access Zone for IoT Infrastructure

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The challenge in connecting devices to IoT infrastructure lies in creating a secure and user-friendly communications protocol that allows authorized devices to access functions within the network, while existing methods are laborious and inefficient, especially with the distribution of private keys for multiple devices.

Innovation Solution

A method involving the creation of a device certificate for each end device, which is used to register and identify the device within a linkable computer infrastructure's access zone, enabling secure and convenient access to the infrastructure's functions, utilizing a demilitarized zone with controlled access and protocols like OPC UA PubSub for secure communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If prior registration of devices in cloud backend is used for connection, then security is improved, but connection effort and time increase significantly with increasing number of devices

Engineering Contradiction:
Improveconnection securityVSAvoidconnection effort
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent introduces an access zone as an intermediary component between end devices and the cloud backend. This access zone handles device registration and authentication, eliminating the need for direct device-by-device registration in the cloud backend. The access zone acts as a mediator that manages multiple devices collectively, thereby maintaining security while significantly reducing connection effort and time.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system is segmented into distinct functional zones: the access zone for device registration and authentication, and the cloud backend for core services. This segmentation allows the access zone to handle authentication tasks independently, preventing the scaling overhead from propagating to the cloud backend and enabling efficient handling of multiple devices.

Inventive Principle:
Principle #1Segmentation

2Reliability

If device certificates are created and distributed to multiple devices, then authentication security is improved, but distribution effort and complexity increase

Engineering Contradiction:
Improveauthentication securityVSAvoidkey distribution complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The access zone serves as an intermediary that centralizes certificate management. Instead of distributing certificates directly to multiple devices from the cloud backend, the access zone receives a single certificate from the cloud backend and then distributes it to multiple end devices. This intermediary approach maintains authentication security while dramatically simplifying distribution logistics.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent employs certificate copying as a strategy. A single device certificate is obtained from the cloud backend and then copied and distributed to multiple end devices through the access zone. This copying approach maintains security (as the certificate is properly managed through the intermediary) while eliminating the complexity of individual certificate generation and distribution for each device.

Inventive Principle:
Principle #26Copying

3Ease of operation

If direct connection between end devices and cloud backend is established, then connection simplicity is improved, but security control and access management become difficult

Engineering Contradiction:
Improveconnection simplicityVSAvoidaccess control security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The access zone is positioned as a necessary intermediary between end devices and the cloud backend. While this adds a layer to the connection architecture, it provides essential security control and access management functions. The access zone can authenticate devices, manage permissions, and control access to cloud services, thereby maintaining both security and operational simplicity.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If multiple authentication methods are implemented for device verification, then authentication security is improved, but connection process complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidconnection process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple authentication functions into a single integrated access zone. Instead of implementing separate authentication mechanisms at different levels (device-to-cloud, device-to-service, etc.), all authentication and authorization functions are combined in the access zone. This consolidation maintains comprehensive security while simplifying the connection process for end devices.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11722487B2Connecting an end device to a linkable computer infrastructure
Publication Date: 2023.08.08 SIEMENS AG
  • US11722487B2 patent drawing

AI summary

A method for connecting an end device to a linkable computer infrastructure is provided. A device certificate is created and supplied to a user of the end device. The device certificate is input into the end device. A data link from the end device to an access zone connected upstream of functions of the linkable computer infrastructure is produced. The access zone may be selectively separated from the functions of the linkable computer infrastructure by this link. The end device is registered in the access zone using the device certificate. By access of a function from the linkable computer infrastructure to the end device registered in the access zone, this end device is identified for the linkable computer infrastructure. With successful identification of the end device, use of the linkable computer infrastructure is enabled for the end device.