Decentralized IoT Device Administration via Distributed Record-Keeping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enforcing appropriate security policies for Internet of Things (IoT) devices across large numbers of distributed devices is a challenging task due to the complexity of firmware and software updates from various sources, requiring a scalable and low-overhead solution.

Innovation Solution

A decentralized consensus-based approach using a distributed record-keeping network (RKN) to manage administration rights of IoT devices, allowing nodes to store and validate transaction records of administrative changes without centralized authority, ensuring secure and transparent administration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a centralized authority is used to manage device administration rights, then security policy enforcement is simplified, but scalability and single point of failure risks deteriorate

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoidscalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent divides the centralized administration authority into multiple distributed nodes in a record-keeping network. Each node maintains a copy of the transaction records and can independently validate administrative changes, eliminating the single point of failure while maintaining security policy enforcement across the IoT device fleet.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a decentralized record-keeping network as an intermediary layer between IoT devices and administrators. This network of nodes collectively maintains administration rights records, providing a distributed mediation mechanism that preserves security enforcement without requiring a single centralized authority.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If centralized record-keeping is used for tracking administration changes, then security transparency is improved, but resource overhead and scalability worsen

Engineering Contradiction:
Improveadministration change transparencyVSAvoidresource overhead
Core Design Contradiction:
Loss of informationVSUse of energy by moving object

Solution Approach 1:

The patent merges the record-keeping functions across multiple nodes in a distributed network. Instead of one centralized server bearing all the resource overhead, each node shares the burden of storing and validating transaction records, reducing individual node resource requirements while maintaining complete transparency of administration changes through the distributed ledger.

Inventive Principle:
Principle #5Merging (Combining)

3Adaptability or versatility

If multiple centralized authorities are used to manage different device types, then specialized security policies are improved, but system complexity and coordination overhead worsen

Engineering Contradiction:
Improvespecialized security policiesVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates a universal record-keeping network that can handle multiple types of IoT devices and administration scenarios through a single decentralized system. The same network of nodes and transaction record structure serves diverse device types, eliminating the need for multiple specialized centralized authorities while maintaining the ability to enforce device-specific security policies through the unified framework.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11469884B1Decentralized techniques for managing device administration rights
Publication Date: 2022.10.11 AMAZON TECH INC
  • US11469884B1 patent drawing
  • US11469884B1 patent drawing
  • US11469884B1 patent drawing

AI summary

At a computing device, contents of one or more transaction records are obtained from a record-keeping network at which a decentralized consensus-based protocol is used to store transaction records of administrator changes of various devices. Using the contents of the obtained records, an administrator of the computing device is identified, as well as a network endpoint of the administrator. A set of instructions is obtained from the endpoint and executed.