IoT Gateway Security for Resource-Constrained Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

IoT devices face significant security vulnerabilities due to lack of robust security policies, limited computing power, and small operating systems, making them susceptible to malware, botnets, privacy breaches, and potential exploitation leading to critical infrastructure failures.

Innovation Solution

A gateway-based security system intercepts and analyzes traffic between IoT devices, servers, and services, using databases and security services to detect threats and perform mitigation actions such as rebooting, updating firmware, and blocking malicious connections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security policies and antivirus applications are implemented on IoT devices, then security protection is improved, but device complexity and resource consumption increase beyond what IoT devices can handle

Engineering Contradiction:
Improvesecurity protectionVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a gateway as an intermediary component that provides security services to IoT devices. The gateway intercepts network traffic, performs security analysis, and executes mitigation actions centrally, allowing IoT devices to benefit from security protection without having to run complex security software themselves. This resolves the contradiction by moving the security functionality from the resource-constrained IoT devices to the more capable gateway infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If comprehensive security monitoring is implemented across all IoT devices, then threat detection capability is improved, but system complexity and processing requirements increase

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent merges security monitoring functions into a centralized gateway that handles multiple IoT devices. Instead of each device running independent security monitoring, the gateway consolidates traffic interception, threat analysis, and response capabilities into a single system. This reduces overall system complexity while maintaining comprehensive threat detection across all connected devices.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If security services are deployed on each IoT device, then individual device security is improved, but resource consumption exceeds the limited computing power of IoT devices

Engineering Contradiction:
Improveindividual device securityVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The gateway acts as an intermediary that provides security services to IoT devices without requiring the devices to consume resources for running security software. The gateway handles traffic interception, analysis, and mitigation actions externally, allowing IoT devices with limited computing power and energy resources to maintain security protection without exceeding their resource constraints.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12438844B2System and method for securing IoT devices through a gateway
Publication Date: 2025.10.07 AO KASPERSKY LAB
  • US12438844B2 patent drawing
  • US12438844B2 patent drawing
  • US12438844B2 patent drawing

AI summary

A method for securing a plurality of IoT devices using a gateway includes intercepting, by a gateway, information about interactions between a first IoT device and at least one of: a second IoT device, a computer server, and a computer service. One or more cyber security threats are detected by the gateway based on the intercepted information and based on information stored in at least one of a first database and a second database. The first database is configured to store information about IoT devices and the second database is configured to store information about cyber security threats. One or more cyber security threat mitigation actions are identified by the gateway to address the detected one or more cyber security threats. The identified one or more cyber security threat mitigation actions are performed by the gateway.