IoT Chain Link Authorization Header for Secure Node Communication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

IoT networks are vulnerable to malicious devices due to unstructured communication between IoT nodes, which can lead to security breaches.

Innovation Solution

A structured communication method between IoT nodes and a base IoT hub, where each node generates and verifies encrypted ID authentication tokens within an authorization header, ensuring only authorized nodes can communicate, forming a secure circuit that strengthens network security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If unstructured communication is allowed between IoT nodes, then network flexibility and ease of operation are improved, but network security and reliability deteriorate due to vulnerability to malicious devices

Engineering Contradiction:
Improvecommunication flexibilityVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an authorization header as an intermediary element that mediates communication between IoT nodes. This header contains encrypted authentication tokens from each node in the communication chain, allowing the base IoT hub to verify the legitimacy of communications without restricting the flexibility of node-to-node interactions. The intermediary mechanism enables secure verification while maintaining communication freedom.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary authentication by requiring nodes to generate and attach encrypted authentication tokens to the authorization header before communications occur. This preliminary action of pre-authenticating nodes ensures that security verification is performed in advance, allowing flexible communication to proceed only from authorized nodes, thus preventing malicious device infiltration.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If structured communication with authentication is implemented, then network security and reliability are improved, but device complexity and difficulty of operation increase due to authentication requirements

Engineering Contradiction:
Improvenetwork securityVSAvoidauthentication structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authorization header serves multiple functions simultaneously: it carries encrypted authentication tokens from each node, provides a structured format for verification, and enables the base IoT hub to identify and reject unauthorized communications. This multi-functional design consolidates security mechanisms into a single universal structure, reducing overall system complexity despite the enhanced security requirements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent uses encrypted copies of authentication tokens that are generated once and then attached to communications. These token copies verify node identity without requiring complex real-time authentication protocols, simplifying the authentication structure while maintaining security. The copied tokens enable efficient verification at the base IoT hub without increasing device complexity at the node level.

Inventive Principle:
Principle #26Copying

3Reliability

If all communications are validated at the base IoT hub, then network security is improved by preventing unauthorized access, but processing time and loss of time increase due to verification requirements

Engineering Contradiction:
Improveauthorization validationVSAvoidcommunication delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Authentication tokens are generated and attached to the authorization header in advance, before communications reach the base IoT hub. This preliminary authentication action allows the hub to perform rapid verification of the pre-computed tokens, significantly reducing processing time compared to performing full authentication protocols in real-time, thus minimizing communication delays while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces complex real-time authentication mechanics with a simpler verification process. Instead of performing multi-step authentication protocols at the base IoT hub, the system uses pre-generated encrypted tokens that can be verified through simpler cryptographic checks, substituting mechanical authentication processes with more efficient digital verification methods that reduce processing time.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS10574651B2Internet of things (“IoT”) chain link
Publication Date: 2020.02.25 BANK OF AMERICA CORP
  • US10574651B2 patent drawing
  • US10574651B2 patent drawing
  • US10574651B2 patent drawing

AI summary

Systems and methods for securing the communication in a structured IoT system between a first, second, and third node and a base IoT hub is provided. The base IoT hub may be in direct connection with the internet. The system may include the first IoT node in electronic communication with the second IoT node. The second node may be in electronic communication with the third IoT node. The third node may be in electronic communication with the hub. The hub may be in electronic communication with the first node. The system may be configured to generate a data packet including an authorization header. The header may include a first segment corresponding to a first node, a second segment corresponding to the second node, and a third segment corresponding to the third node. The header may be configured to store an encrypted ID authentication token generated by the corresponding node.