IoT Data Security via Distributed Subsets and Location Files

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

IoT networks face significant security challenges due to the lack of enterprise-level firewall protection, vulnerability to malicious attacks, and the difficulty in managing and securing distributed data across various devices, especially in loosely connected systems with limited computing power and geographical dispersion.

Innovation Solution

The implementation of a method that involves storing device identifiers, maintaining a data location file with encryption keys, authorization information, and hash functions to track and secure data distribution, allowing secure access and communication between devices, and using a configurable policy for access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If data is distributed among various devices in an IoT network, then data storage capacity and network scalability are improved, but data security and tracking become more difficult

Engineering Contradiction:
Improvedata storage capacityVSAvoiddata security
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The patent segments data into multiple data subsets and distributes them across different devices in the IoT network. Each data subset is associated with specific parameters including encryption keys, authorization information, and hash functions. This segmentation allows the network to scale while maintaining security through distributed storage and cryptographic protection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a data location file as an intermediary mechanism that tracks the distribution of data subsets across the network. This file contains parameters such as device identifiers, encryption keys, and hash functions, enabling centralized tracking and security management without requiring data to be centralized, thus resolving the contradiction between distributed storage and security tracking.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of manufacture

If simple low-cost computing devices are used in IoT networks, then device cost and power consumption are reduced, but capability to handle sophisticated communication protocols and security measures is worsened

Engineering Contradiction:
Improvedevice costVSAvoidsecurity implementation capability
Core Design Contradiction:
Ease of manufactureVSDevice complexity

Solution Approach 1:

The patent enables simple IoT devices to participate in secure communication by assigning them data subsets with embedded encryption keys and authorization information. The devices themselves can perform basic cryptographic operations on their stored data without requiring sophisticated processing capabilities, as the security burden is distributed through the data location file and host entities.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces host entities and data location files as intermediaries that handle complex security management tasks. Simple IoT devices can store and process data with embedded security parameters without needing to implement complex security protocols themselves, as the host entities manage the overall security architecture and protocol complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If no centralized tracking mechanism is used for distributed data, then network decentralization and device autonomy are improved, but ability to monitor and secure data distribution is worsened

Engineering Contradiction:
Improvedevice autonomyVSAvoiddata distribution visibility
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The patent introduces a data location file as a lightweight tracking mechanism that maintains visibility into data distribution without centralizing data storage or compromising device autonomy. The file contains parameters such as device identifiers, data subset locations, and cryptographic information, enabling monitoring and security management while preserving the decentralized nature of the IoT network.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10423802B2Establishing data security over an internet of things (IoT) network
Publication Date: 2019.09.24 YU KENNETH KEUNG YUM
  • US10423802B2 patent drawing
  • US10423802B2 patent drawing
  • US10423802B2 patent drawing

AI summary

Embodiments of the present disclosure provide a technique for establishing data security over an Internet of Things (IoT) network. According to an embodiment, a method includes performing by at least one host entity implemented in a network, tracking distribution of data in the network by maintaining a data location file that includes plurality of parameters of each of plurality of data subsets. The data subsets are distributed in plurality of devices of the network such as key servers, host entities and client entities. The data subsets include any or a combination of an encryption key, a key identifier, a header, an authorization information, a decryption key, a control message, a computer program, a config file, data generated by any client entity of the one or more client entities, and data processed by any host entity of the one or more host entities.