Gateway Device Aggregating IoT Authentication Credentials

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current IoT systems face challenges in establishing trust for new devices, particularly in multi-manufacturer environments, due to lack of standardized communication protocols and limited user interfaces, leading to security concerns and increased costs for individual device certification.

Innovation Solution

A gateway device aggregates local IoT devices, acting as a network proxy and authenticator, using a method that establishes secure connections between devices and servers, ensuring trust through attestation protocols and preventing misconfiguration of malicious devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple user accounts are created for different IoT devices from different manufacturers, then device compatibility and functionality are improved, but system complexity and security risk increase

Engineering Contradiction:
Improvedevice compatibilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent combines multiple device-specific authentication credentials into a single gateway device credential. The gateway device aggregates authentication for multiple IoT devices from different manufacturers, allowing users to manage all devices through one account rather than creating separate accounts for each device, thereby reducing system complexity while maintaining multi-manufacturer compatibility

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The gateway device serves as a universal authentication intermediary that works with IoT devices from multiple manufacturers. It provides a single credential system that can authenticate various types of devices regardless of manufacturer, making the authentication system universal across different device ecosystems

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple user accounts with different passwords are created for different IoT devices, then device-specific authentication is improved, but security vulnerability increases

Engineering Contradiction:
Improveauthentication securityVSAvoidpassword compromise risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent merges multiple device-specific credentials into a single gateway credential, reducing the number of passwords users must manage from multiple device-specific passwords to one gateway password, thereby reducing the attack surface and risk of password compromise while maintaining secure authentication

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The gateway device acts as an intermediary authentication layer between users and IoT devices. Instead of users directly authenticating with each device using device-specific credentials, the gateway mediates authentication, reducing direct exposure of sensitive credentials and minimizing the impact of potential compromises

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If security certificates are issued to each IoT device during manufacturing, then device trustworthiness is improved, but manufacturing cost increases

Engineering Contradiction:
Improvedevice trustworthinessVSAvoidmanufacturing cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent consolidates the security certificate issuance process from individual device level to gateway device level. Instead of embedding certificates in each IoT device during manufacturing, the gateway device holds the security credentials and provides authentication for all connected devices, significantly reducing per-device manufacturing costs while maintaining trustworthiness

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The gateway device performs the security credential management function that would otherwise require individual device certification. The gateway itself serves as the security anchor, eliminating the need for expensive individual device certificates while maintaining a trusted authentication mechanism for the entire device ecosystem

Inventive Principle:
Principle #25Self-service

4Reliability

If individual device certification is required for each IoT device, then network security is improved, but deployment time and complexity increase

Engineering Contradiction:
Improvenetwork securityVSAvoiddeployment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent merges the certification process into a single gateway device certification rather than requiring individual certification for each IoT device. This allows rapid deployment of multiple devices simultaneously through the gateway's pre-established security credentials, dramatically reducing deployment time while maintaining network security through the gateway's authentication mechanism

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11678183B2Devices, systems and methods for connecting and authenticating local devices to common gateway device
Publication Date: 2023.06.13 INFINEON TECHNOLOGIES AMERICAS CORP
  • US11678183B2 patent drawing
  • US11678183B2 patent drawing
  • US11678183B2 patent drawing

AI summary

Devices, systems and methods use a first communication interface to connect with a local device via a first protocol and use a second communication interface to connect with a server via a second protocol. Embodiments relay secure communications between the local device and the server for authentication of the at least one local device by the server and responsive to authentication of the local device by the server, transmit information for storage in a secure memory of the authenticated local device.