Multi-Client Messaging Access With Double-Broker Commissioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current publish-subscribe network protocols are cumbersome and prone to security breaches, particularly when managing access to private networks connected to public networks, due to their task-centric approach and reliance on manual client discovery, which can lead to labor-intensive, expensive, and error-prone processes.

Innovation Solution

Implementing a double broker system with a commissioning broker and a building broker that uses short-lived access certificates from a local Certificate Authority for local messaging, along with a client-centric publish-subscribe network protocol that provides unique IDs for clients, enhancing security and simplifying device commissioning by reducing manual processes and increasing bandwidth efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If manual client discovery is used in publish-subscribe network protocols, then device commissioning can be completed, but the process becomes labor-intensive, expensive, and error-prone

Engineering Contradiction:
Improvedevice commissioning processVSAvoidcommissioning time
Core Design Contradiction:
Ease of manufactureVSLoss of time

Solution Approach 1:

The system enables self-service through automatic client discovery mechanisms where devices automatically register and discover each other on the network without manual intervention. The publish-subscribe protocol automatically handles client registration, topic subscription, and message routing, eliminating the need for manual commissioning processes.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary action by pre-configuring devices with unique identifiers and authentication credentials before deployment. The broker is pre-configured with discovery protocols and client registration mechanisms, so that when devices connect, the commissioning process is already prepared to handle automatic registration and integration.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If long-lived access certificates are used for network security, then authentication is simplified, but unauthorized parties can monitor traffic for extended periods and break encryption

Engineering Contradiction:
Improveauthentication processVSAvoidsecurity against unauthorized access
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system implements periodic action through short-lived access certificates that are automatically renewed at regular intervals. Instead of using long-lived certificates, the system issues certificates with limited validity periods, requiring periodic re-authentication. This limits the window of opportunity for unauthorized parties to capture and break encryption, while the automated renewal process maintains ease of operation.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The system applies parameter changes by dynamically adjusting certificate validity periods based on security requirements and operational context. The broker can modify certificate lifetime parameters, renewal frequencies, and authentication thresholds to balance security needs with operational convenience, transforming static authentication into a dynamic, adaptive process.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If task-centric publish-subscribe protocols are used, then message routing can be organized by function, but the system becomes cumbersome as the number of devices and task types increases

Engineering Contradiction:
Improvemessage routing efficiencyVSAvoidprotocol complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system implements universality by designing a unified publish-subscribe protocol that handles multiple task types and device categories through a common messaging framework. Instead of creating separate protocols for different tasks, the system uses universal topic patterns, wildcard subscriptions, and hierarchical topic structures that can accommodate diverse device types and functions within a single protocol implementation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system applies another dimension by organizing message routing not just by task type but by multiple hierarchical dimensions including device type, location, function, and priority levels. This multi-dimensional topic hierarchy allows efficient routing across diverse devices without increasing protocol complexity, as the same protocol handles routing along multiple organizational dimensions simultaneously.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS11750594B2Access and messaging in a multi client network
Publication Date: 2023.09.05 VIEW OPERATING CORP
  • US11750594B2 patent drawing
  • US11750594B2 patent drawing
  • US11750594B2 patent drawing

AI summary

A messaging system for exchanging messages between nodes in a network via a broker that uses a publish-subscribe message protocol, which nodes have object identifications (IDs). Messages between the nodes are routed using the object IDs of the nodes. Secure communication is provided using authentication according to digital certificates being used as first and second tiers by a commissioning broker and a data broker, respectively, in which the second tier certificate used by the data broker has a shorter lived expiration time.