IoT Edge Device Credential Translation via Network Manager

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Remote management of IoT networks with local security credentials is challenging due to difficulties in securely managing access control and communication, leading to communication failures and inadequate security management.

Innovation Solution

Implementing a system where a device management service uses service credentials for secure communication with a network manager, which translates messages using local credentials assigned to each edge device, enabling end-to-end device security and access control while maintaining local credentials inaccessible outside the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If local security credentials are used in self-managed IoT networks, then security management autonomy is improved, but remote manageability deteriorates

Engineering Contradiction:
Improvesecurity management autonomyVSAvoidremote manageability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a cloud service as an intermediary that uses service credentials to communicate with the network manager. This mediator translates between remote management requests and local device credentials, enabling remote management without directly exposing or duplicating local security credentials. The cloud service acts as a bridge that maintains security autonomy while enabling remote accessibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments credential management into two distinct layers: service credentials for cloud-to-network-manager communication and local credentials for network-internal device communication. This segmentation allows independent management of each credential type, enabling remote management through service credentials without compromising local security autonomy maintained by local credentials.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If device repository information is duplicated for remote management, then remote access capability is improved, but data consistency and security deteriorate

Engineering Contradiction:
Improveremote access capabilityVSAvoiddata consistency
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The cloud service acts as a mediator that accesses the device repository through authenticated service credentials rather than duplicating repository data. This intermediary approach enables remote management operations while maintaining a single source of truth in the local device repository, preventing data consistency issues and security vulnerabilities associated with duplication.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If service credentials are used for cloud communication and local credentials for device communication, then end-to-end security is improved, but system complexity increases

Engineering Contradiction:
Improveend-to-end securityVSAvoidcredential management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments credential usage into distinct domains: service credentials for cloud service communication and local credentials for device communication. This segmentation, while introducing multiple credential types, organizes complexity into manageable, non-overlapping domains with clear boundaries and purposes, making the system more understandable and maintainable than a unified credential system would be.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The network manager acts as an intermediary that handles the complexity of credential translation and message format conversion between service credentials and local credentials. This intermediary absorbs the complexity of dual-credential management, presenting a simplified interface to both cloud services and local devices while maintaining end-to-end security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11582027B1Secure communication with individual edge devices of remote networks that use local security credentials
Publication Date: 2023.02.14 AMAZON TECH INC
  • US11582027B1 patent drawing
  • US11582027B1 patent drawing
  • US11582027B1 patent drawing

AI summary

A device management service of a provider network maintain a device repository that is accessible to a remote managed network. The device management service assigns different service credentials for different edge devices indicated by the device repository. For a particular edge device, the device management service provides, based on the service credentials assigned for the edge device, secure transmission of a message between the device management service and a network manager of the managed network. The network manager of the managed network provides secure transmission of the message between the network manager and the edge device based on local credentials assigned for the edge device.