IoT P2P Communication via Digital Certificate Token Association

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional client-server communications in IoT networks face challenges in supporting high volumes of IoT devices due to bandwidth requirements and security concerns, especially with periodic endpoint availability changes and context shifts, which exacerbate communication, data, and privacy issues as the network scales.

Innovation Solution

Implementing a combination of digital certificates and associated tokens for endpoint association, using endpoint fingerprinting and context information to create secure connections for asynchronous peer-to-peer communications, allowing secure data exchange and management in isolated containers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If traditional client-server communications are used in IoT networks, then centralized data management is achieved, but bandwidth requirements increase and security concerns worsen as the network scales

Engineering Contradiction:
Improvecentralized data managementVSAvoidbandwidth requirements
Core Design Contradiction:
Device complexityVSLoss of energy

Solution Approach 1:

The patent segments the centralized client-server architecture into distributed peer-to-peer communication channels. Each IoT device establishes independent communication paths with other devices, eliminating the need for all traffic to traverse central servers. This segmentation reduces overall bandwidth consumption while maintaining data management capabilities through distributed trust relationships established via digital certificates and tokens.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces digital certificates and tokens as intermediary mechanisms that enable secure direct peer-to-peer communication without requiring continuous server mediation. These cryptographic intermediaries establish trust relationships that allow devices to communicate securely autonomously, reducing bandwidth requirements while maintaining security and data management functions.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of energy

If peer-to-peer communication is implemented to reduce bandwidth usage, then communication efficiency improves, but security and data privacy issues worsen due to periodic endpoint availability changes and context shifts

Engineering Contradiction:
Improvebandwidth efficiencyVSAvoidcommunication security
Core Design Contradiction:
Loss of energyVSReliability

Solution Approach 1:

The patent applies preliminary action by establishing digital certificates and tokens before peer-to-peer communication occurs. These cryptographic credentials are pre-configured and validated, creating secure trust relationships in advance. This preliminary setup ensures that even when endpoints experience availability changes or context shifts, the pre-established security framework maintains communication reliability and data privacy without requiring continuous server verification.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If digital certificates and tokens are used for endpoint association, then security and trust relationships improve, but device complexity increases

Engineering Contradiction:
Improvetrust relationship establishmentVSAvoidcertificate and token management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service by enabling IoT devices to autonomously manage their own digital certificates and tokens without requiring complex centralized management infrastructure. Each device independently validates certificates and generates tokens as needed for peer-to-peer communication. This self-service approach reduces the operational complexity of certificate management while maintaining strong security and trust relationships across the distributed network.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9838204B2IoT communication utilizing secure asynchronous P2P communication and data exchange
Publication Date: 2017.12.05 VERIZON PATENT & LICENSING INC
  • US9838204B2 patent drawing
  • US9838204B2 patent drawing
  • US9838204B2 patent drawing

AI summary

A device may receive a connection request including a digital certificate from an endpoint for establishing a secure connection for a communication, the digital certificate including a digital certificate chain identifying one or more certificate authorities associated with the digital certificate. The device may determine whether the digital certificate is valid based on the digital certificate chain identifying one or more certificate authorities trusted by the device. The device may determine whether the connection request includes a valid token. The device may generate a token based on the digital certificate being valid and an absence of a valid token included in the connection request. The device may associate the token with the digital certificate. The device may distribute the token to the endpoint. The device may establish the secure connection with the endpoint using the token associated with the digital certificate.