IoT Gateway Mediating Secure End-to-End Tunnel Between Non-IP and IP Subnetworks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current IoT systems face security risks due to the inability to establish secure end-to-end communication between Non-IP and IP subnetworks, particularly because existing solutions rely on proprietary and non-standardized security protocols, making it difficult to ensure the trustworthiness of gateways and leading to interoperability issues.
Innovation Solution
A computer network architecture where the gateway mediates handshaking to establish a secure end-to-end tunnel between Non-IP and IP subnetworks, with the session key generated by the frontend and backend devices without the gateway possessing it, using a combination of IP and Non-IP communication to exchange handshaking parameters, ensuring the gateway cannot eavesdrop or alter the communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a gateway is used as a bridge between Non-IP and IP subnetworks, then connectivity between heterogeneous devices is improved, but security trustworthiness deteriorates because the gateway becomes a potential attack point and cannot be trusted to protect end-to-end communication
Solution Approach 1:
The patent extracts the session key generation and management functions from the gateway, allowing frontend and backend devices to generate and manage their own session keys independently. The gateway only mediates handshaking parameter exchange without possessing the actual session keys, thereby removing the security vulnerability associated with gateway key management while preserving its connectivity function
Solution Approach 2:
The gateway acts as a communication intermediary that facilitates handshaking between frontend and backend devices by exchanging parameters, but deliberately does not obtain or store the session keys. This mediator role allows the gateway to enable connectivity between Non-IP and IP subnetworks while avoiding becoming a security attack point
2Reliability
If proprietary security protocols are applied in Non-IP subnetworks, then hop-by-hop authentication is improved, but end-to-end security deteriorates and interoperability worsens due to vendor-specific implementations
Solution Approach 1:
The patent implements a universal handshaking mechanism that works across different vendors and Non-IP communication protocols. The frontend device and gateway exchange standardized handshaking parameters that enable the frontend device to generate session keys regardless of the specific Non-IP protocol being used, achieving both security and interoperability
Solution Approach 2:
The security mechanism is segmented into two independent parts: hop-by-hop authentication between frontend and gateway using Non-IP protocols, and end-to-end authentication between frontend and backend using IP security protocols. This segmentation allows each layer to operate independently with its own authentication mechanism, enabling both proprietary protocol support and universal end-to-end security
3Productivity
If TLS/DTLS session resumption is implemented, then session establishment efficiency is improved, but security deteriorates because the gateway can potentially reconstruct session keys from resumption requests
Solution Approach 1:
The patent extracts the session key generation function from the gateway and assigns it to the frontend device. The gateway only handles parameter exchange during handshaking and does not possess or reconstruct session keys, even during session resumption. This extraction eliminates the security vulnerability while maintaining efficient session establishment
Data Source
AI summary
A computer network may include a Non-IP subnetwork for communication between the gateway and the frontend device, an IP subnetwork for communication between the gateway and at least one backend device, and a gateway connecting the Non-IP subnetwork with the IP subnetwork and translating communication therebetween. The IP communication is based on an IP security protocol, providing means for authentication and/or encryption. The gateway mediates handshaking for establishing a secure tunnel for secure end-to-end communication between the backend device and the frontend device. The secure tunnel is set to apply a session key. The gateway and the backend device exchange datagrams with handshaking parameters. The Non-IP messages are exchanged with a subset of the handshaking parameters. The backend device and the frontend device generate the session keys and to authenticate the handshaking incorporating the handshaking parameters and subset of handshaking parameters, respectively.


