Gateway Apparatus for IoT Device Authentication and Cloud Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Devices within the Internet of Things (IoT) face challenges in accessing networks due to verification issues, leading to difficulties in uploading data to cloud services, which detracts from the user experience.

Innovation Solution

A method and apparatus for controlling communications between a data processing device in one network and a target service in another network via a gateway apparatus, involving credential verification, authentication, and traffic policy management to establish and maintain secure communication paths.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If devices attempt to access network enabled devices to upload data to cloud services, then data transmission capability is improved, but verification problems cause access reliability to deteriorate

Engineering Contradiction:
Improvedata transmission capabilityVSAvoidaccess reliability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces a gateway apparatus as an intermediary between IoT devices and cloud services. The gateway performs credential verification and authentication, mediating the connection between devices attempting to upload data and the cloud services they need to access. This resolves the verification problems by centralizing authentication functions in the gateway, allowing devices to reliably access cloud services through the gateway's verified communication paths.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If credential verification and authentication processes are implemented, then communication security is improved, but communication establishment time increases

Engineering Contradiction:
Improvecommunication securityVSAvoidcommunication establishment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary credential verification and authentication processes during device registration and gateway setup phases. Device credentials are verified in advance, and authentication states are established before actual data transmission occurs. This preliminary action ensures communication security is already in place when data upload is needed, reducing the time penalty during actual communication operations.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If gateway apparatus controls communication paths between devices and target services, then network access control is improved, but system complexity increases

Engineering Contradiction:
Improvenetwork access controlVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The gateway apparatus serves as a centralized intermediary that consolidates communication control functions. Instead of each device independently managing complex authentication and communication path establishment, the gateway handles credential verification, authentication state management, and communication path control. This centralization improves network access control reliability while managing system complexity by concentrating control logic in a single intermediary component.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11050733B2Communication mechanism for data processing devices
Publication Date: 2021.06.29 ARM IP
  • US11050733B2 patent drawing
  • US11050733B2 patent drawing
  • US11050733B2 patent drawing

AI summary

A method for controlling communications between a data processing device in a first network and a target service in a second network via a gateway apparatus, the method comprising: transmitting a request to communicate with the target service from the data processing device to the gateway apparatus; transmitting device credentials from the data processing device to the gateway apparatus, wherein the credentials comprise information relating to the target service; verifying at the gateway apparatus an authentication status of the data processing device based on the device credentials; establishing a communication path between the data processing device and the target service if the authentication status is verified.