IoT Network Security Gateway with Dynamic Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security solutions, particularly for IoT devices, fail to actively manage device access to the Internet based on usage, leading to increased exposure to attacks and unauthorized access, as they are often configured to remain continuously connected, even when not in use.

Innovation Solution

A network-based security system that regulates IoT device access to cloud servers by requiring user authorization, implementing conditional access and two-factor authentication, and allowing users to configure access rules through a user-friendly interface, eliminating the need for complex VPN infrastructure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If IoT devices remain continuously connected to the Internet, then users can access devices remotely and receive real-time data, but network exposure to attacks and unauthorized access increases

Engineering Contradiction:
Improveremote device accessibilityVSAvoidnetwork security exposure
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic internet access control for IoT devices based on real-time usage conditions. The gateway device monitors device status and automatically grants or restricts internet access depending on whether devices are actively being used, transforming the static continuous connection model into a dynamic conditional access model that adapts to current operational needs

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces a gateway device as an intermediary between IoT devices and the internet. This gateway acts as a security mediator that authenticates devices, monitors their usage patterns, and controls their internet access permissions. The gateway serves as a buffer that maintains security while enabling legitimate remote access when needed

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If conventional firewalls and VPNs are used to secure networks, then unauthorized access is blocked, but user-friendly device access management and active communication control are lost

Engineering Contradiction:
Improvenetwork securityVSAvoiddevice access management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service authentication and access control mechanisms where IoT devices automatically present credentials to the gateway, and the gateway autonomously authenticates devices and manages their access permissions without requiring manual firewall configuration or VPN setup by users. The system automatically monitors device status and adjusts access rights based on usage conditions

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The gateway device performs multiple functions including authentication, authorization, monitoring, and access control in a single integrated system. It combines security functions with device management capabilities, eliminating the need for separate firewall and VPN infrastructure while providing both security and user-friendly access management

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If device manufacturers implement basic communication schemes, then device connectivity is achieved, but comprehensive security protection and active access control are insufficient

Engineering Contradiction:
Improvedevice connectivityVSAvoiddevice security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements preliminary authentication and registration actions that occur before IoT devices gain internet access. Devices must be registered with the gateway and authenticated using credentials established during setup. The gateway pre-establishes access policies and monitors device behavior, preventing unauthorized access before it can occur rather than reacting to security threats after they happen

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3466136B1Method and system for improving network security
Publication Date: 2020.10.28 AVAST SOFTWARE
  • EP3466136B1 patent drawingFigure 1
  • EP3466136B1 patent drawingFigure 2
  • EP3466136B1 patent drawingFigure 3

AI summary

Methods and systems for securing a network including IoT devices arc provided. A networking device system can regulate the ability of IoT devices to communicate with their corresponding cloud servers over the Internet, for example, by allowing a device to connect to its associated cloud servers when a user (e.g., an authorized user) requests to use the device. The system can communicate (e.g., directly) with users outside of the network through an app and/or a software development kit installed on user client device(s), where communications received from the app or kit (e.g., to access one or more IoT devices on the network) can be presumed to originate from authorized users.