IoT Gateway Authorization for Secure Local Network Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The proliferation of Internet of Things (IoT) devices connected to local networks increases security risks due to rogue devices exploiting vulnerabilities, leading to unauthorized data access, malware distribution, and denial-of-service attacks, making it challenging for individual vendors to control security effectively.
Innovation Solution
A system that includes a first computer and a second computer connected to an external network, where the first computer evaluates authorization for the second computer to initiate direct inbound connections to a third computer, providing necessary network identifiers if authorized, or redirecting traffic through a fourth computer if not authorized, using techniques such as VPN tunnels and interactive connectivity establishment over UDP or HTTP protocols.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If IoT devices are allowed to communicate freely on local networks, then device functionality and usability are improved, but security risks increase due to rogue devices exploiting vulnerabilities
Solution Approach 1:
The patent introduces a gateway device as an intermediary between IoT devices and external networks. The gateway evaluates authorization requests, determines whether devices should establish direct connections or use relay connections through the gateway, and enforces security policies. This mediator approach allows free communication while preventing rogue devices from directly accessing vulnerable devices on the network.
Solution Approach 2:
The system dynamically adjusts connection paths based on real-time authorization evaluations. When a device is authorized, direct connections are permitted for optimal functionality. When unauthorized or suspicious, the system dynamically switches to relay connections through the gateway, maintaining usability while enhancing security. This dynamic adaptation resolves the contradiction between free communication and security.
2Productivity
If direct inbound connections are allowed between devices, then communication efficiency is improved, but vulnerability to attacks increases
Solution Approach 1:
The gateway acts as a mediator that sits between devices wanting to establish direct connections and the actual communication path. It evaluates authorization requests and can redirect traffic through relay connections when direct connections pose security risks. This allows the system to maintain communication efficiency through direct connections when safe, while preventing attacks by interposing the gateway when vulnerabilities exist.
Solution Approach 2:
The system performs preliminary authorization evaluation before allowing direct inbound connections to be established. The gateway assesses whether the initiating device has proper authorization credentials and whether the target device should accept direct connections. This preliminary security check prevents vulnerable devices from being attacked while allowing efficient direct connections when authorization is confirmed.
3Object-affected harmful factors
If security controls are implemented to prevent unauthorized access, then security is improved, but device complexity increases
Solution Approach 1:
The patent merges security control functions into a centralized gateway device that handles authorization evaluation, connection path determination, and relay communication. Instead of implementing complex security controls in each individual IoT device, the gateway consolidates these functions, reducing overall system complexity while maintaining strong security controls against unauthorized access.
4Object-affected harmful factors
If relay connections through gateway are used for all devices, then security is improved, but communication overhead increases
Solution Approach 1:
The system dynamically selects connection paths based on real-time authorization evaluations. When devices are authorized and direct connections are deemed safe, the system uses direct connections for efficient communication. When authorization fails or security risks are detected, the system dynamically switches to relay connections through the gateway. This dynamic approach minimizes communication overhead while maintaining security protection.
Data Source
AI summary
A network device allows inbound connections from external addresses to a computer on a local network while forbidding output connections from the computer to that external address unless preceded by an inbound connection therefrom. In some embodiments, the computer is allowed to accept inbound connections from external addresses but is not permitted to initiate outbound connections to other computers in the local network unless preceded by an inbound connection. In some embodiments, a request from an external address is processed by the network device by transmitting network information for the computer to the external address and temporarily changes network rules to allow connections from the external address. In some embodiments, if the computer attempts a disallowed connection, the connection attempt is routed through a proxy server by providing network data for the proxy server to the computer.


