Gateway Access Checkpoint for IoT Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Home network security is compromised due to the lack of technical expertise among users to configure and secure IoT devices, which often come with default or weak login credentials, making them vulnerable to attacks, and existing access control solutions require technical knowledge and are not effective in mitigating risks from outside the local network.

Innovation Solution

A home gateway router with an access proxy engine that intercepts incoming requests, provides a tiered authentication checkpoint, and configures access rules based on session, context, and severity, ensuring secure access to IoT devices by managing access policies and automatically detecting and securing potentially weak devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users manually configure and secure IoT devices, then security control is achieved, but technical expertise is required which most users lack

Engineering Contradiction:
Improvesecurity controlVSAvoiduser operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The gateway acts as an intermediary between external networks and IoT devices, implementing automatic security policies without requiring user intervention. The gateway intercepts access requests, performs authentication, and enforces security rules automatically, bridging the gap between security requirements and user capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements self-service security by automatically detecting weak credentials, generating security policies, and enforcing access controls without user input. The gateway autonomously manages security configurations, performs risk assessments, and applies protective measures based on predefined policies.

Inventive Principle:
Principle #25Self-service

2Ease of manufacture

If default or weak login credentials are used in IoT devices, then device deployment is simplified, but vulnerability to attacks increases

Engineering Contradiction:
Improvedevice deploymentVSAvoidattack vulnerability
Core Design Contradiction:
Ease of manufactureVSObject-affected harmful factors

Solution Approach 1:

The gateway performs preliminary security actions by detecting weak credentials before attackers can exploit them. It proactively identifies devices with default credentials, assesses security risks, and implements protective policies in advance, preventing vulnerabilities from being exploited.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system applies preliminary anti-action by blocking access requests to devices with weak credentials before legitimate users or attackers can compromise them. The gateway intercepts and denies access attempts targeting vulnerable devices, neutralizing the threat before it can cause harm.

Inventive Principle:
Principle #9Preliminary anti-action

3Reliability

If access control solutions require technical knowledge, then security policies can be customized, but user accessibility is reduced

Engineering Contradiction:
Improvesecurity policy customizationVSAvoiduser accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The gateway implements self-service security policy management by automatically generating and enforcing security rules based on device characteristics and threat assessments. Users don't need to manually configure security policies; the system autonomously adapts security measures to each device and access scenario.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system dynamically adjusts security parameters based on contextual factors such as device type, credential strength, and access patterns. Security policies are automatically modified in response to changing conditions, providing customized protection without requiring user technical knowledge.

Inventive Principle:
Principle #35Parameter changes

4Reliability

If existing access control solutions are used, then some security protection is provided, but risks from outside the local network are not mitigated

Engineering Contradiction:
Improvesecurity protectionVSAvoidexternal network risks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The gateway segments network traffic into internal and external flows, applying different security policies to each. It specifically targets and blocks external access attempts to IoT devices, creating a layered defense that protects against outside threats while maintaining internal network functionality.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP3759886B1Gateway with access checkpoint
Publication Date: 2024.01.10 MCAFEE LLC
  • EP3759886B1 patent drawingFigure 1
  • EP3759886B1 patent drawingFigure 2
  • EP3759886B1 patent drawingFigure 3

AI summary

There is disclosed in one example a gateway apparatus to operate on an intranet, including: a hardware platform; and an access proxy engine to operate on the hardware platform and configured to: intercept an incoming packet; determine that the incoming packet is an access request directed to an access interface of a resource of the intranet; present an access checkpoint interface; receive an authentication input response; validate the authentication input response; and provide a redirection to the access interface of the device.