IoT Gateway Mediator for Secure Local Network Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The proliferation of Internet of Things (IoT) devices connected to local networks increases security risks due to vulnerabilities that can lead to unauthorized data access, malware distribution, and denial-of-service attacks, making it difficult for individual vendors to control security effectively.
Innovation Solution
A system that includes a first computer and a second computer connected to an external network, where the first computer evaluates authorization for the second computer to initiate direct inbound connections to a third computer, providing necessary network identifiers if authorized, or redirecting traffic through a fourth computer if not authorized, using techniques such as VPN tunnels and DNS resolution.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If IoT devices are allowed to communicate freely on local networks, then device functionality and connectivity are improved, but security risks increase due to unauthorized access and malicious activities
Solution Approach 1:
The patent introduces a gateway device as an intermediary between IoT devices and external networks. The gateway evaluates inbound connection requests, determines authorization status, and controls whether devices can establish direct connections or must use reverse connections through the gateway. This intermediary structure maintains device functionality while preventing unauthorized access by filtering and managing all network traffic.
Solution Approach 2:
The patent implements dynamic connection management where the gateway can switch between allowing direct inbound connections and requiring reverse connections based on authorization evaluation. The system adapts its security posture in real-time by evaluating each connection request and adjusting the connection path accordingly, rather than using static security rules.
2Object-affected harmful factors
If direct inbound connections are blocked for security, then security risks are reduced, but device functionality and data exchange capability are degraded
Solution Approach 1:
The gateway acts as a mediator that enables authorized data exchange without requiring direct inbound connections to IoT devices. By evaluating authorization and managing reverse connections, the gateway maintains full data exchange capability for authorized devices while blocking unauthorized access attempts, thus resolving the contradiction between security and functionality.
Solution Approach 2:
The patent segments network traffic into authorized and unauthorized categories through gateway evaluation. Authorized traffic is routed through managed reverse connections that maintain functionality, while unauthorized traffic is blocked. This segmentation allows the system to preserve necessary data exchange capabilities while eliminating security risks.
3Adaptability or versatility
If individual vendors control security measures, then device-specific security needs are met, but overall network security is compromised due to multiple vulnerability points
Solution Approach 1:
The patent merges security control functions into a single gateway device that consolidates authorization evaluation for all IoT devices on the network. Instead of each device implementing its own security measures, the gateway provides centralized security management, reducing the number of vulnerability points while maintaining vendor-specific device requirements through coordinated authorization policies.
Data Source
AI summary
A network device allows inbound connections from external addresses to a computer on a local network while forbidding output connections from the computer to that external address unless preceded by an inbound connection therefrom. In some embodiments, the computer is allowed to accept inbound connections from external addresses but is not permitted to initiate outbound connections to other computers in the local network unless preceded by an inbound connection. In some embodiments, a request from an external address is processed by the network device by transmitting network information for the computer to the external address and temporarily changes network rules to allow connections from the external address. In some embodiments, if the computer attempts a disallowed connection, the connection attempt is routed through a proxy server by providing network data for the proxy server to the computer.


