IoT Data Exchange via Centralized Label Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The Internet of Things (IoT) faces challenges in securely sharing data between smart devices and authorized entities, as existing solutions lack efficient mechanisms for controlling access and ensuring data is transferred only to authorized devices and in an authorized manner.

Innovation Solution

Implementing an IoT label system where smart devices can selectively send data to a central control device based on access levels, and the central control device compiles data into realms, using realm hash values to securely share information with peer devices, ensuring only authorized access and secure data transfer.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If data sharing mechanisms are implemented in IoT, then data accessibility and connectivity are improved, but security and authorization control deteriorate

Engineering Contradiction:
Improvedata sharing capabilityVSAvoidsecurity and authorization
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a central control device as an intermediary between smart devices and peer devices. This mediator manages authentication, authorization, and data routing, ensuring that data is shared securely only with authorized entities. The central control device verifies credentials and access levels before allowing data transfer, thus resolving the contradiction between enabling data sharing and maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If access control mechanisms are implemented, then data security is improved, but device complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the complex access control and authentication logic from individual smart devices and concentrates it in a separate central control device. Each smart device only needs to store its unique identifier and basic credentials, while the central control device handles credential verification, access level management, and authorization decisions. This extraction simplifies the smart devices while maintaining strong security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The central control device serves multiple functions: it acts as an authentication server, an authorization manager, a data router, and a communication coordinator. By consolidating these diverse functions into a single multi-functional component, the patent reduces the overall system complexity that would otherwise require multiple specialized devices for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If selective data sharing is implemented, then data privacy is improved, but data exchange efficiency deteriorates

Engineering Contradiction:
Improvedata privacyVSAvoiddata exchange efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements preliminary action by establishing access levels and authorized peer device lists before actual data exchange occurs. The central control device pre-authenticates peer devices and assigns appropriate access levels to each smart device. When data exchange is needed, the system only needs to verify pre-established credentials and routing information, enabling rapid selective data sharing without repeated authentication overhead.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9674161B2Data exchange in the internet of things
Publication Date: 2017.06.06 VERIZON DEUTLAND
  • US9674161B2 patent drawing
  • US9674161B2 patent drawing
  • US9674161B2 patent drawing

AI summary

A device is configured to store a hash value and an encrypted hash value. The device may broadcast a boot label including the encrypted hash value. The device may receive an administrator label from an administrative device based on the boot label. The administrator label may include a decrypted hash value. The device may determine the decrypted hash value matches the hash value. The device may receive access information from the administrative device based on the decrypted hash value matching the hash value. The access information may associate authorization information and an access level. The access level may be associated with particular data that is permitted to be read from the device. The device may selectively provide the particular data to a control device based on the access information.