Geo-location Based Community of Interest System for IoT Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing number of Internet of Things (IoT) devices poses security risks as information from connected devices can be harvested outside their intended geographical zone, compromising privacy and security.

Innovation Solution

A geo-location based community of interest (COI) system that configures Network Connect Devices (NCDs) to identify and restrict data packets to predefined IP address ranges, ensuring that only packets destined for within the specified zone are allowed to reach their destination, using a zone-based authentication mechanism (ZAM) to manage access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If internet connected devices transmit data freely across the network, then device connectivity and data exchange are improved, but security risks increase as information can be harvested outside the intended geographical zone

Engineering Contradiction:
Improvedevice connectivityVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements geo-location based access control that restricts device connectivity to specific geographical zones. Each device is assigned a geographical boundary (latitude/longitude coordinates), and the system evaluates whether connecting devices are within acceptable distance thresholds. This creates local quality control where connectivity permissions vary by geographical location, allowing free communication within zones while blocking external access attempts.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent introduces a server as an intermediary between devices attempting to connect. The server receives connection requests, evaluates the geographical locations of both source and destination devices using their IP addresses, and decides whether to permit or block the connection. This intermediary layer enables security evaluation without preventing legitimate local connectivity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If geo-location restrictions are implemented to prevent unauthorized data access, then security is improved, but device complexity increases due to location tracking and packet evaluation mechanisms

Engineering Contradiction:
Improveunauthorized data accessVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent implements a self-service mechanism where devices automatically report their IP addresses to the server, and the server automatically evaluates connection requests based on pre-configured geographical boundaries. The system maintains lists of authorized devices and their locations, automatically updating connection permissions without manual intervention. This automation reduces the operational complexity of managing geo-location security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent performs preliminary actions by pre-configuring geographical boundaries and authorized device lists before connectivity issues arise. The server maintains pre-evaluated location data and authorization status for all devices, allowing rapid connection decisions without complex real-time calculations. This preliminary preparation simplifies the runtime complexity of security evaluation.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9716703B2Systems and methods of geo-location based community of interest
Publication Date: 2017.07.25 UNISYS CORP
  • US9716703B2 patent drawing
  • US9716703B2 patent drawing
  • US9716703B2 patent drawing

AI summary

The embodiments described herein recite a geo-location based community of interest (COI) system and method that add the capability to configure Network Connect Devices (NCD) to identify the location of the source and destination IP addresses. The NCDS may drop any packets that are destined to an IP address outside of its predefined radius. For any sent/received packets, the geo-location position of the remote IP-address on the wide area network (WAN) may be determined. The distance between two points on the earth given their latitudes and longitudes of the devices may be determined. If the distance is greater than the predefined range, the data packets may be denied. If the distance falls within the pre-determined range, the data packets are allowed to reach their destination.