IoT Hub Intermediary for Device Authentication and Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

As the IoT platform grows, it faces increased security threats due to various communications with the internet, making it essential to ensure authenticity and prevent unauthorized devices or communications from attacking the system.

Innovation Solution

A system with a base IoT hub that includes a data repository, data analysis engine, and processor is established to link IoT devices, analyze communications, and verify their authenticity before allowing them to connect to the internet, masking identities and terminating unauthorized communications to enhance security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If IoT devices are connected directly to the internet to enable communication, then communication capability is improved, but security vulnerability increases

Engineering Contradiction:
Improvecommunication capabilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a hub device as an intermediary between IoT devices and the internet. The hub performs authentication, authorization, and communication routing, preventing direct exposure of devices to internet threats while maintaining communication capability. This mediator architecture allows devices to communicate effectively without being directly vulnerable to internet-based attacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If multiple IoT devices are linked to enable platform growth, then system functionality is improved, but attack surface increases

Engineering Contradiction:
Improvesystem functionalityVSAvoidattack surface
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the IoT system into isolated device groups, each linked to a specific hub. This segmentation prevents lateral movement of attacks across the entire network. Each hub manages its own authenticated devices independently, so if one device is compromised, the attack cannot easily propagate to other device-hub combinations, thus reducing the effective attack surface while maintaining overall system functionality.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary authentication and authorization actions before devices can communicate. The hub verifies device identities and establishes trust relationships in advance, creating a security barrier that prevents unauthorized devices from joining the network. This preliminary security check ensures that only authenticated devices can participate in platform communications, reducing vulnerability as the platform grows.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If device identities are exposed for communication verification, then authentication is improved, but susceptibility to attacks increases

Engineering Contradiction:
ImproveauthenticationVSAvoidsusceptibility to attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The hub acts as an intermediary that handles authentication without requiring devices to expose their identities to the internet or external systems. The hub verifies device credentials locally and manages authentication processes, providing reliable verification while keeping device identity information protected within the trusted hub environment, thus reducing susceptibility to identity-based attacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11122037B2Internet of things (“IoT”) protection retro-system
Publication Date: 2021.09.14 BANK OF AMERICA CORP
  • US11122037B2 patent drawing
  • US11122037B2 patent drawing
  • US11122037B2 patent drawing

AI summary

Methods for securing communication in a network of IoT devices is provided. Methods include selecting a base IoT hub for operating as an intermediary layer for IoT devices. Methods include selecting from the plurality of IoT devices a selected plurality of IoT devices. Each of the selected IoT devices is configured to send and receive electronic communications. Methods include linking each of the selected plurality of IoT devices to the base IoT hub. Methods include storing, in a data repository within the hub, identification data associated with each of the IoT devices. The communication-types typically associated with each of the selected plurality of IoT devices are stored in the data repository. When an IoT device is activated to send a communication, methods include comparing and analyzing the communication and identification data of the activated device to stored identification data and communication-types of the selected IoT devices.