Dynamic Reputation Scoring for Secure IoT Access Connections

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In IoT network environments, existing mechanisms fail to continuously secure connectivity between electronic devices, making them susceptible to fake or rogue devices that can disconnect verified devices and compromise security, with no mechanism to detect intrusions or provide user feedback.

Innovation Solution

A method and system that dynamically determine a local reputation score for access points based on various parameters and pre-defined weights, updating a global reputation score to establish a secure connection only if it meets a pre-defined threshold, thereby continuously monitoring and securing the connection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic security mechanisms are used during pairing, then confidentiality and integrity are improved, but the connection remains susceptible to fake devices that can disconnect verified devices

Engineering Contradiction:
Improveconnection securityVSAvoidrogue device intrusion
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by establishing cryptographic security during pairing and pre-storing connection information before the actual connection is needed. This prepares the foundation for secure communication, though additional measures are needed to prevent rogue device intrusions that occur after pairing.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system introduces feedback mechanisms by continuously monitoring connection status and detecting disconnection events. When a disconnection is detected, the system can identify potential rogue devices and alert users, creating a closed-loop security system that responds to threats in real-time.

Inventive Principle:
Principle #23Feedback

2Ease of operation

If connection information is stored and referenced for automatic reconnection, then ease of operation is improved, but the system cannot detect intrusions from fake devices

Engineering Contradiction:
Improveautomatic reconnectionVSAvoidintrusion detection
Core Design Contradiction:
Ease of operationVSDifficulty of detecting and measuring

Solution Approach 1:

The system enhances automatic reconnection with feedback mechanisms that monitor connection events. By tracking disconnection and reconnection patterns, the system can detect anomalies that indicate rogue device interference, maintaining ease of operation while adding security monitoring capabilities.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system introduces an intermediary monitoring layer that sits between the automatic reconnection mechanism and the network connection. This intermediary component analyzes connection events and can identify when reconnections are caused by rogue devices rather than legitimate network conditions.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Device complexity

If no continuous monitoring mechanism is implemented, then device complexity is reduced, but security is compromised leading to data loss

Engineering Contradiction:
Improvemonitoring mechanismVSAvoidsensitive data loss
Core Design Contradiction:
Device complexityVSLoss of information

Solution Approach 1:

The system implements a lightweight feedback mechanism that continuously monitors connection status without adding significant complexity. By listening for disconnection events and analyzing reconnection patterns, the system can detect security threats and alert users, preventing data loss while maintaining relatively simple device architecture.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system employs self-service security monitoring where devices automatically detect and report potential rogue device intrusions without requiring complex external monitoring infrastructure. Each device monitors its own connection status and can alert users to security issues, reducing overall system complexity while maintaining security.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10686783B2Method and system for establishing a secure access connection with electronic devices
Publication Date: 2020.06.16 WIPRO LTD
  • US10686783B2 patent drawing
  • US10686783B2 patent drawing
  • US10686783B2 patent drawing

AI summary

A technique is provided for establishing a secure access connection with electronic devices. The technique includes receiving a request for establishing the secure access connection, from an electronic device, via an access point associated with the electronic device. The technique further includes dynamically determining at least a local reputation score associated the access point, based on at least a plurality of parameters and pre-defined weights assigned to each of the plurality of parameters. The technique further includes establishing the secure access connection between the host device and the electronic device, via the access point, based on a comparison of an updated global reputation score with a pre-defined threshold. The global reputation score is updated based on the dynamically determined local reputation score.