Protocol-Agnostic IoT Gateway Authorization Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authorization and audit techniques are inadequate for legacy IoT systems such as Modbus serial, SNMPv1/2, and DNP3, and there is a lack of standardized authorization mechanisms across multiple IoT protocols, posing risks for intellectual property protection in multi-vendor, multi-technology Operational Technology environments.

Innovation Solution

Implementing a protocol-independent authorization and audit control layer at a gateway device that translates native protocol request packets into an authorization protocol mapping, such as SNMP, allowing for uniform authorization and audit control across legacy and newer IoT systems without requiring changes to the OT protocols or device managers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If protocol-specific authorization techniques are implemented for each IoT protocol, then authorization control can be achieved for that specific protocol, but device complexity and the need for multiple customized solutions increase

Engineering Contradiction:
Improveauthorization controlVSAvoidmultiple protocol-specific implementations
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The gateway device is designed with a universal authorization mechanism that can handle multiple IoT protocols (Modbus, DNP3, Profinet, SNMP) through a single unified interface. The system translates various protocol-specific requests into a common authorization protocol, allowing one gateway to provide authorization control across diverse protocols without requiring separate specialized systems for each protocol.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The invention introduces an intermediary authorization layer between the requesting devices and serving devices. This intermediary translates native protocol requests into authorization protocol mappings, mediating between protocol-specific requirements and unified authorization control. The gateway acts as a mediator that converts diverse protocol requests into a standardized authorization format without requiring changes to the underlying protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If legacy IoT systems (Modbus serial, SNMPv1/2, DNP3) are integrated into the authorization framework, then comprehensive coverage is achieved, but these legacy systems lack built-in authorization techniques

Engineering Contradiction:
Improvelegacy system compatibilityVSAvoidauthorization implementation for legacy protocols
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system creates virtual representations (mappings) of legacy protocol requests in terms of the authorization protocol. Instead of modifying legacy protocols to include authorization capabilities, the gateway creates translated copies of the authorization logic that operate on the standardized protocol, allowing legacy systems to benefit from modern authorization mechanisms without changing their original protocol implementations.

Inventive Principle:
Principle #26Copying

3Ease of operation

If remote maintenance is enabled for multi-vendor, multi-technology solutions, then operational flexibility improves, but the risk of attacks and intellectual property loss increases

Engineering Contradiction:
Improveremote maintenance capabilityVSAvoidsecurity risks and IP loss
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The authorization mechanism performs preliminary authorization checks before allowing remote access to serving devices. By evaluating authorization protocol mappings in advance and establishing access permissions before remote maintenance operations begin, the system prevents unauthorized access and potential security breaches while still enabling legitimate remote maintenance activities.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12041033B2Authorization and audit control in a multi-protocol IoT domain
Publication Date: 2024.07.16 CISCO TECHNOLOGY INC
  • US12041033B2 patent drawing
  • US12041033B2 patent drawing
  • US12041033B2 patent drawing

AI summary

In one embodiment, an authorizing device (e.g., a gateway) receives a native protocol request packet from a requesting device destined to a serving device, and translates the native protocol request packet into an authorization protocol mapping. The authorizing device may then apply authorization protocol based authorization (e.g., OT protocol independent) to the native protocol request packet based on the authorization protocol mapping, and transmits the native protocol request packet toward the serving device in response to the authorization protocol mapping being authorized. In one embodiment, the techniques herein may also perform an audit in this manner.