IoT Multifactor Authentication via Gateway Intermediary

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

IoT devices face complexities in deploying and using multifactor authentication due to the need for specialized security solutions, which can be expensive, difficult to deploy, and increase time to market, especially when multiple authentication methods are required.

Innovation Solution

A system and method for IoT devices that assigns an IP address and uses a security management platform to obtain and validate certificates via an over-the-air channel, allowing for standardized multifactor authentication without the need for customized applications, thereby improving security and efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If specialized security solutions are implemented for each IoT device, then authentication security is improved, but device complexity and deployment difficulty increase

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a gateway device as an intermediary that centralizes authentication management for multiple IoT devices. The gateway maintains security policies, protocols, and credentials, acting as a mediator between IoT devices and third-party platforms. This eliminates the need for each device to have dedicated security solutions, reducing device complexity while maintaining authentication security through centralized management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The gateway device provides universal authentication services to multiple different IoT devices, enabling them to access various third-party platforms using standardized security mechanisms. The gateway can handle multiple authentication methods and approaches for different devices, making the security system versatile and adaptable to diverse IoT device requirements without requiring device-specific customization.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple authentication methods are enabled for IoT devices, then authentication security is improved, but deployment time and time to market increase

Engineering Contradiction:
Improveauthentication securityVSAvoiddeployment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The gateway device performs preliminary configuration of security policies, protocols, and authentication methods before IoT devices need to access third-party platforms. During device activation or startup, the gateway already has the necessary security credentials and policies prepared, enabling rapid authentication without requiring time-consuming on-device configuration or programming of multiple authentication steps.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables automated authentication processes where the gateway and IoT devices can independently perform authentication operations without requiring manual programming or user intervention. The gateway automatically manages security credentials, protocols, and multiple authentication methods, allowing devices to be deployed quickly while maintaining robust multi-factor authentication security.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If customized authentication applications are deployed on IoT devices, then authentication functionality is improved, but resource usage increases

Engineering Contradiction:
Improveauthentication functionalityVSAvoiddevice resource usage
Core Design Contradiction:
Adaptability or versatilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts authentication functionality from individual IoT devices and relocates it to the gateway device. Instead of embedding customized authentication applications on resource-constrained IoT devices, the authentication logic, security policies, and credential management are extracted and centralized at the gateway, which has sufficient computational resources. This allows IoT devices to maintain versatility in authentication support while consuming minimal local resources.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Multiple authentication functions and security mechanisms are merged into the gateway device, which consolidates security policies, protocols, and credential management for all connected IoT devices. This combining of authentication capabilities at the gateway level provides comprehensive authentication functionality without requiring each individual IoT device to have its own customized authentication application, thereby reducing overall resource usage across the IoT device fleet.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11153309B2Multifactor authentication for internet-of-things devices
Publication Date: 2021.10.19 AT&T INTELLECTUAL PROPERTY II LP
  • US11153309B2 patent drawing
  • US11153309B2 patent drawing
  • US11153309B2 patent drawing

AI summary

Concepts and technologies are disclosed herein for multifactor authentication for Internet-of-things devices. An access request can be received from an Internet-of-things device. The access request can include identifying information associated with the Internet-of-things device and a certificate. The certificate can be validated and a stored version of the identifying information can be obtained. If the stored version of the identifying information is determined to match the identifying information included with the access request, access to a resource can be allowed.