IoT Device Grouping via Cloud Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network access systems face challenges in efficiently connecting new network devices while ensuring secure and seamless authentication, particularly in environments with multiple gateways and devices, leading to complexities in remote access and management.

Innovation Solution

A method and system for grouping network devices based on common capabilities, using a cloud network server to generate security keys and network IDs, allowing accountless authentication and remote access through an access device, which communicates with network devices using unique keys for secure access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional network access systems are used to connect new network devices, then network security can be maintained through authentication, but the complexity of remote access and management increases, especially in environments with multiple gateways and devices

Engineering Contradiction:
Improvenetwork securityVSAvoidcomplexity of remote access and management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments network devices into groups based on their capabilities and characteristics. Each group is assigned a group identifier, allowing devices to be managed collectively rather than individually. This segmentation reduces the complexity of remote access and management while maintaining security through group-based authentication policies.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a network device group as an intermediary layer between the authentication system and individual devices. Instead of authenticating each device separately, the system authenticates groups, which then manage individual device access. This intermediary approach simplifies remote management while preserving security controls.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If individual device authentication is implemented for each network device, then secure access can be ensured, but the time and complexity required for device connection and management increases

Engineering Contradiction:
Improvesecure accessVSAvoidtime required for device connection and management
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary grouping of network devices based on their capabilities before authentication is required. By pre-organizing devices into groups with defined characteristics and assigning group identifiers in advance, the system eliminates the need for time-consuming individual device authentication during connection events. Security is maintained through group-based policies while connection time is reduced.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If network devices are managed individually without grouping, then precise control over each device is possible, but the efficiency of network management and access control decreases

Engineering Contradiction:
Improveefficiency of network managementVSAvoidcomplexity of device management operations
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent merges multiple individual network devices into unified groups based on shared capabilities. Each group is represented by a group identifier that encapsulates the collective characteristics of its member devices. This merging approach improves management efficiency by allowing operations to be performed on groups rather than individual devices, while the underlying device-level control is preserved through the group structure.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11856395B2Grouping of network devices
Publication Date: 2023.12.26 ZEBRA TECHNOLOGIES CORP
  • US11856395B2 patent drawing
  • US11856395B2 patent drawing
  • US11856395B2 patent drawing

AI summary

The present disclosure relates to setup of IoT network devices, and specifically to setup of multiple similar IoT devices at substantially the same time using joint authentication. Embodiments include, for example, receiving, at an existing network device on a network, one or more communications, wherein the one or more communications include an indication that multiple new network devices are associated with the network; receiving an indication that the multiple new network devices have generated a setup access point; establishing a connection with the access point of each of the multiple new network devices; receiving identification information, wherein the identification information includes information identifying each of the multiple new network devices; and transmitting the identification information identifying each of the multiple new network devices, wherein when the identification information is received, the identification information facilitates generating an authentication query to authenticate one or more of the multiple new network devices.