Geocast Wormhole for Secure IoT Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

IoT devices face challenges in secure access due to non-routable IP addresses and lack of identifiable host names, making it difficult for devices behind NATs and firewalls to initiate connections and be designated for network requests.

Innovation Solution

The implementation of Geocast Wormholes, which use Geocast messaging to securely convey information and set up connections through a rendezvous server, allowing devices to access IoT resources despite non-routable addresses and firewall constraints.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If IoT devices use non-routable IP addresses behind NATs and firewalls, then device security and network protection are improved, but the ability to initiate connections and be designated for network requests deteriorates

Engineering Contradiction:
Improvedevice securityVSAvoidconnection initiation capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a rendezvous server as an intermediary that facilitates connections between IoT devices behind NATs/firewalls and external clients. The server receives connection requests, determines target devices using geocast messages with location information, and establishes relay connections without requiring devices to have routable addresses or initiate outbound connections themselves.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent adds geographic location as a new dimension for device identification and connection routing. Instead of relying solely on traditional network addressing (IP addresses), the system uses geographic coordinates in geocast messages to locate and connect to devices, enabling access despite network address limitations.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If IoT devices lack host names and identifiable identifiers, then device anonymity and security are improved, but the ability to be designated for specific network requests deteriorates

Engineering Contradiction:
Improvedevice anonymityVSAvoiddevice identification capability
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent applies different identification mechanisms to different contexts: devices maintain anonymity using non-routable addresses and lack of host names in their local network environment, while enabling specific identification through geographic location data in geocast messages when external access is needed. This allows devices to have different identification properties in different operational contexts.

Inventive Principle:
Principle #3Local quality

3Adaptability or versatility

If traditional TCP-based services are used for IoT devices, then standard network communication protocols are maintained, but scalability and security for mobile devices without routable addresses deteriorate

Engineering Contradiction:
Improveprotocol compatibilityVSAvoidsystem scalability
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The rendezvous server provides multiple functions within a single system: it acts as a connection initiator, a message relay, a location-based device finder, and a security intermediary. This universal approach enables the system to handle diverse IoT devices with different network capabilities (routable or non-routable addresses, mobile or stationary) through a unified architecture, greatly improving scalability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12267309B2System and method providing secure access to internet of things devices
Publication Date: 2025.04.01 AT&T INTELLECTUAL PROPERTY I L P
  • US12267309B2 patent drawing
  • US12267309B2 patent drawing
  • US12267309B2 patent drawing

AI summary

Aspects of the subject disclosure may include, for example, a device, including: a processing system including a processor; and a memory that stores executable instructions that, when executed by the processing system, facilitate performance of operations of allocating a port for receiving a request to access a resource of a second device, wherein the second device has a non-routable network address, wherein the device is on a first network, wherein the second device is on a third network, and wherein the first network and the third network are communicatively coupled by the second network; opening a second connection to a network element on the second network responsive to receiving a first connection; sending a first message to the network element to create a meeting with the resource; and sending a Geocast message requesting that the second device create a third connection that enables access to the resource, wherein the Geocast message identifies a geographic area in which the second device is physically located. Other embodiments are disclosed.