IoT Device DNS Mapping and Authentication at Scale

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Legacy networking systems face challenges in securely and cost-effectively scaling Internet-connected devices due to limitations in Domain Name System (DNS) capability and Secure Sockets Layer (SSL) certificate deployment, particularly with wildcard handling, and lack efficient methods for device identification and authentication, leading to difficulties in managing and communicating with a large number of connected devices.

Innovation Solution

The implementation of advanced techniques for deploying and maintaining Internet-connected networked devices, including a multi-server fractional subdomain DNS protocol, direct map proxy systems, and secure device identification methods using partially-encrypted provisioning files, enables efficient and secure management of multiple devices by allowing flexible domain name mapping and secure authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If legacy DNS and SSL certificate management systems are used, then device deployment is straightforward, but scalability and security are limited due to wildcard and subdomain handling constraints

Engineering Contradiction:
ImprovescalabilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the domain name space into fractional subdomains that can be independently mapped to different devices. Each device receives a unique fractional subdomain (e.g., device1.example.com, device2.example.com) rather than relying on wildcard certificates. This segmentation enables scalable device deployment while maintaining simple DNS and SSL certificate management, as each fractional subdomain can be independently configured and secured.

Inventive Principle:
Principle #1Segmentation

2Reliability

If wildcard SSL certificates are used for multiple devices, then deployment is simplified, but security is compromised due to inability to provide unique device identification

Engineering Contradiction:
ImprovesecurityVSAvoiddeployment ease
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent applies local quality by providing unique SSL certificates tailored to each device's specific fractional subdomain. Instead of using a single wildcard certificate that compromises security, each device (e.g., device1.example.com, device2.example.com) receives its own certificate. This ensures that each device has unique cryptographic identity while the systematic approach to fractional subdomain assignment maintains deployment simplicity.

Inventive Principle:
Principle #3Local quality

3Adaptability or versatility

If traditional DNS wildcard records are used, then device management is simplified, but domain name mapping flexibility is reduced for large-scale device networks

Engineering Contradiction:
Improvedomain name mapping flexibilityVSAvoiddevice management ease
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent introduces a new dimension to domain name organization by implementing fractional subdomains that extend the traditional hierarchical DNS structure. Instead of relying solely on wildcard records that match patterns, the system creates a structured fractional subdomain space (e.g., device1.fractional.example.com) that provides fine-grained control over domain name mapping. This dimensional extension enables flexible mapping for large-scale device networks while maintaining manageable complexity through systematic naming conventions.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS12149406B2Managing network connected devices
Publication Date: 2024.11.19 REMOT3 IT INC
  • US12149406B2 patent drawing
  • US12149406B2 patent drawing
  • US12149406B2 patent drawing

AI summary

Methods, systems, and computer program products for managing Internet of Things (IoT) network-connected devices.