IoT Hub Subnet-Based Device Allocation with Geofenced Attestation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing IoT systems face challenges in efficiently managing and securing IoT devices across various subnets, leading to increased setup times and management overhead, as well as security vulnerabilities due to the lack of automated and geographically validated connections.

Innovation Solution

An IoT hub is configured to automatically assign IoT devices to specific solutions based on subnet connectivity and geofenced attestation, utilizing prediction algorithms and machine learning techniques to streamline device setup, reduce errors, and enhance security by validating device locations before allowing connections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual device setup and configuration is used, then device security can be controlled, but setup time increases and management overhead increases

Engineering Contradiction:
Improvedevice securityVSAvoidsetup time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-configuring subnet-to-IoT-solution mappings and pre-establishing geofences before devices arrive. When devices connect, the hub automatically retrieves pre-defined configurations based on subnet and location, eliminating manual setup time while maintaining security through pre-validating rules.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

IoT devices perform self-service by automatically detecting their own subnet information and geographic location, then autonomously requesting and receiving appropriate IoT solution assignments without human intervention. The system uses device-provided metadata (subnet, location) to trigger automated configuration, reducing setup time while maintaining security through automated validation.

Inventive Principle:
Principle #25Self-service

2Loss of time

If automated device assignment is implemented, then setup time is reduced, but security validation may be compromised

Engineering Contradiction:
Improvesetup timeVSAvoidsecurity validation
Core Design Contradiction:
Loss of timeVSReliability

Solution Approach 1:

The system implements feedback mechanisms where devices provide metadata about their subnet and geographic location, which the hub uses to validate eligibility against pre-defined rules. This feedback loop ensures that automated assignment is based on verified device characteristics, maintaining security while reducing setup time through rapid automated decision-making.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

Security validation rules and geofence definitions are established in advance before devices connect. The hub retrieves and applies these pre-validating rules automatically based on device-subnet and location information, ensuring security is maintained during automated assignment without requiring manual security review for each device.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If geofenced attestation is added to validate device locations, then network security is enhanced, but system complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary layer in the form of geofence definitions and location validation services that mediate between device location data and security decisions. This intermediary component handles the complexity of geographic validation centrally, allowing devices to simply provide location information while the hub manages the sophisticated geofence matching and security enforcement.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Ease of operation

If subnet-based automated assignment is implemented, then management overhead is reduced, but device control flexibility may be limited

Engineering Contradiction:
Improvemanagement overheadVSAvoiddevice control flexibility
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The system implements dynamic configuration where subnet-to-IoT-solution mappings and geofence definitions can be updated in real-time without affecting existing device connections. New devices are automatically assigned based on current configurations, while existing devices maintain their assignments unless explicitly reassigned, providing both automated management and flexible control when needed.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP3878191B1Subnet-based device allocation with geofenced attestation
Publication Date: 2024.03.13 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP3878191B1 patent drawingFigure 1
  • EP3878191B1 patent drawingFigure 2
  • EP3878191B1 patent drawingFigure 3~4

AI summary

An IoT hub comprising one or more servers and databases is configured to automatically assign Internet of Things (IoT) enabled devices to IoT solutions based on a subnet to which the IoT devices are connected. A user interface is configured to enable a user to define subnets within the customer's network environment and assign each subnet to an IoT solution. Upon the user setting up an IoT device's network connection to a network device, such as a router, the IoT device transmits its network information to the IoT hub. The IoT hub can then automatically assign the IoT device to a specific IoT solution without further user input or predict which IoT solution to utilize for that IoT device based on known parameters.