Edge Server Encryption Policy for IoT Data Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In edge computing systems, especially in IoT environments, changes in device functions lead to mismatches in encryption schemes, resulting in potential security level mismatches during data transmission between edge servers and central servers, as the encryption scheme is uniformly decided based on device type rather than specific device and data combinations.

Innovation Solution

A data collecting system with a central server and edge servers that bi-directionally communicate, where data encryption is performed according to an encryption policy defining schemes for different combinations of device types and data types, ensuring appropriate security levels for various IoT devices and data types.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If encryption scheme is decided on according to device type, then ease of operation is improved, but security level reliability deteriorates due to mismatch when device functions change

Engineering Contradiction:
Improveease of operationVSAvoidreliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent changes the parameters used to determine encryption schemes from only device type to a combination of device type and data type. This allows the system to adapt encryption parameters dynamically based on the specific data being transmitted, resolving the contradiction by maintaining ease of operation through automated policy selection while improving reliability by matching encryption schemes to actual data requirements.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces dynamic encryption policy selection based on real-time device and data type identification. Instead of static encryption rules based solely on device type, the system dynamically determines appropriate encryption schemes by querying policies that consider both device characteristics and data characteristics, ensuring reliable security matching even when device functions change.

Inventive Principle:
Principle #15Dynamics

2Device complexity

If encryption scheme is decided on according to device type, then device complexity is reduced, but adaptability deteriorates when new device functions are added

Engineering Contradiction:
Improvedevice complexityVSAvoidadaptability
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent segments the encryption determination process into distinct components: device type identification, data type identification, and policy-based scheme selection. This segmentation allows the system to maintain simple device implementations while achieving high adaptability through the policy framework that handles complex decision-making centrally, resolving the contradiction between low device complexity and high adaptability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an encryption policy as an intermediary layer between devices and encryption implementation. The policy framework acts as a mediator that translates device and data type information into appropriate encryption schemes, allowing devices to remain simple while the system as a whole achieves high adaptability to new device functions and data types.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11516009B2Data collecting system, data collecting apparatus, and non-transitory computer readable medium
Publication Date: 2022.11.29 FUJIFILM BUSINESS INNOVATION CORP
  • US11516009B2 patent drawing
  • US11516009B2 patent drawing
  • US11516009B2 patent drawing

AI summary

A data collecting system includes a central server and at least one edge server capable of bi-directionally communicating with the central server. The edge server includes a collecting unit that collects data generated by a group of devices, and an output processing unit that encrypts the collected data and transmits the encrypted data to the central server. The encryption of the collected data is performed in accordance with an encryption policy that defines encryption schemes for different combinations of a device type and a data type.