IoT Data Security via Intermediary and Blockchain

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

IoT networks face significant challenges with data privacy and security due to vulnerabilities such as default passwords and 'backdoors' that can be exploited, leading to cyberattacks and data abuse, with IoT devices often having access to sensitive information like credit card numbers and personal data.

Innovation Solution

Implementing a system that segregates data by context using blockchain technologies to securely audit and manage access, with a federated or private blockchain for inter-category transactions, and machine-learning models to identify and prevent suspicious data usage patterns, classifying requests as normal, block, or request approval, and sending alerts to users for feedback.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If IoT devices are deployed with default passwords and basic security configurations, then device complexity and ease of operation are improved, but security reliability deteriorates due to vulnerabilities and backdoors

Engineering Contradiction:
Improveease of operationVSAvoidsecurity reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an intermediary security system that sits between IoT devices and data systems. This intermediary monitors data access requests, validates device credentials, and enforces security policies without requiring complex security configurations on individual IoT devices. The intermediary handles authentication and authorization, allowing simple device operation while maintaining high security reliability through centralized control.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If data access is freely permitted to all IoT devices, then productivity and ease of operation are improved, but harmful factors increase due to unauthorized access and data abuse

Engineering Contradiction:
ImproveproductivityVSAvoidharmful factors
Core Design Contradiction:
ProductivityVSObject-generated harmful factors

Solution Approach 1:

The patent implements a feedback mechanism where the security system continuously monitors data access patterns from IoT devices. When suspicious or unauthorized access attempts are detected, the system provides feedback by blocking the request and potentially alerting administrators. This feedback loop enables productive data access for legitimate operations while automatically preventing harmful access patterns, thus maintaining both productivity and security.

Inventive Principle:
Principle #23Feedback

3Reliability

If comprehensive security monitoring is implemented for all data access, then security reliability is improved, but device complexity and processing overhead increase

Engineering Contradiction:
Improvesecurity reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the complex security monitoring functionality from individual IoT devices and concentrates it in a centralized security system. The IoT devices themselves remain simple, generating only basic access requests. The complex tasks of authentication, authorization, and pattern analysis are performed by the external security system, thereby maintaining high security reliability without increasing device complexity at the IoT endpoint.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11457032B2Managing data and data usage in IoT network
Publication Date: 2022.09.27 KYNDRYL INC
  • US11457032B2 patent drawing
  • US11457032B2 patent drawing
  • US11457032B2 patent drawing

AI summary

In an approach, a processor receives from a network device a request. A processor obtains from a database a device profile for the network device. A processor determines whether the device profile of the network device has a data usage pattern related to data identified by a data identifier. In response to determining the device profile has a related data usage pattern, a processor receives the related data usage pattern from the database. In response to determining the device profile does not have a related data usage pattern, a processor obtains a device type profile from the database. A processor classifies the data usage request based on at least one of the device profile and the device type profile. A processor executes a security action based on the classification of the data usage request. A processor stores the data usage request and executed security action to the database.