IoT Auto-Discovery via Cloud Mediator and Secure Stream

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

IoT devices are difficult to discover and manage, especially when they do not connect directly to the internet, and they lack secure data streaming capabilities to unified dashboards, requiring manual provisioning and lacking plug-and-play discoverability and secure data aggregation.

Innovation Solution

A method and device for auto-discovery of IoT devices using a proprietary protocol that includes receiving a discovery packet, identifying a registration, determining a destination for data streaming, and establishing a secure stream using a Diffie-Hellman key exchange, enabling secure and automatic data streaming to a cloud platform with globally unique identifiers and token-secured routing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If IoT devices connect only to manufacturer servers or do not connect directly to the Internet, then device security and manufacturer control are improved, but device discoverability and automatic provisioning are worsened

Engineering Contradiction:
Improvedevice securityVSAvoiddevice discoverability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a cloud platform as an intermediary that enables indirect discovery and communication between IoT devices and users. Devices maintain secure connections to manufacturer servers while the cloud platform facilitates discovery through alternative means (device identifiers, network scanning, manual input) without requiring direct Internet accessibility. This mediator approach resolves the contradiction by enabling discoverability through the manufacturer's infrastructure while preserving device security architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the discovery and communication process into multiple independent channels: device registration with manufacturer servers, cloud platform registration with device identifiers, and data streaming establishment. This segmentation allows each component to function independently - devices remain secure on manufacturer networks while the cloud platform handles discovery and routing, resolving the discoverability-security contradiction.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If manual provisioning is used for IoT devices, then device management control is improved, but provisioning time and complexity are worsened

Engineering Contradiction:
Improvemanagement controlVSAvoidprovisioning time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-registering devices with the cloud platform using device identifiers obtained during manufacturing or initial setup. This preliminary registration establishes device profiles, data stream configurations, and routing information in advance, enabling automatic provisioning when devices are deployed. This eliminates time-consuming manual configuration while maintaining management control through the cloud platform's registration system.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements self-service provisioning where devices automatically register with the cloud platform using their own identifiers, and the system automatically establishes data streams and routing configurations. This automated self-service process eliminates manual provisioning steps while maintaining control through validation and registration protocols, significantly reducing provisioning time without sacrificing management capability.

Inventive Principle:
Principle #25Self-service

3Reliability

If secure data streaming is implemented using key establishment procedures, then data security is improved, but computational overhead and setup complexity are worsened

Engineering Contradiction:
Improvedata securityVSAvoidsetup complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs key establishment and security configuration as preliminary actions during the device registration phase. The cloud platform pre-establishes secure communication channels, generates encryption keys, and configures data stream security parameters before actual data transmission begins. This preliminary security setup consolidates complexity into an initial one-time process rather than requiring ongoing complex configuration, maintaining data security while reducing operational complexity.

Inventive Principle:
Principle #10Preliminary action

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

Enables plug-and-play discoverability and secure data streaming of IoT devices to a cloud platform, allowing for automatic registration, provisioning, and routing of data streams, ensuring data security and ease of management without manual configuration.

Implementation Method 1

establishing a secure stream using a Diffie-Hellman key exchange

Methodology Applied
Scientific EffectDiffie-Hellman key exchange:

Data Source

PatentUS11356826B2Medical internet of things device discovery
Publication Date: 2022.06.07 GUARDIAN HEALTH INC
  • US11356826B2 patent drawing
  • US11356826B2 patent drawing
  • US11356826B2 patent drawing

AI summary

Devices and methods for internet of things (IOT) discovery/auto discovery are described. A discovery packet is received from a device. The discovery packet includes a first stream identifier and a request to establish a second stream. A stream acceptance packet is sent to the device. The stream acceptance packet includes the first stream identifier and an input for generating a second stream identifier. A first association is added to the registration based on the request to establish the second stream. The first association is between the second stream identifier and a determined destination. A first data packet is received from the device, where the first data packet includes/utilizes the second stream identifier. The first data packet is sent to the destination based on the first association in the registration.