IoT Patch Propagation via Opportunistic Peer-to-Peer Networking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Propagating patches to diverse IoT devices is challenging due to their periodic inaccessibility and lack of reliable Internet connections, leading to prolonged exposure to security vulnerabilities.

Innovation Solution

Implementing an opportunistic peer-to-peer networking schema that allows devices to share patch blocks locally, even when offline, using nearby devices of the same or different kinds to accelerate patch propagation without relying on centralized servers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Use of energy by moving object

If devices are kept offline to save power and reduce security risks, then energy consumption and vulnerability exposure are reduced, but patch propagation becomes impossible

Engineering Contradiction:
Improveenergy consumptionVSAvoidpatch propagation capability
Core Design Contradiction:
Use of energy by moving objectVSReliability

Solution Approach 1:

Devices perform patch propagation actions during brief connectivity windows before going offline. The system prepares and exchanges patch data during these intermittent connections, allowing devices to remain offline most of the time while still receiving updates. This resolves the contradiction by enabling patch propagation without requiring continuous online presence.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces intermediary devices that act as relay points for patch propagation. When a device is offline, other devices in proximity can share patches through peer-to-peer communication. This intermediary mechanism allows patch propagation to occur without direct Internet connectivity, resolving the contradiction between offline operation and update capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Speed

If devices connect to Internet continuously to receive patches, then patch propagation speed is improved, but energy consumption increases

Engineering Contradiction:
Improvepatch propagation speedVSAvoidenergy consumption
Core Design Contradiction:
SpeedVSUse of energy by moving object

Solution Approach 1:

Instead of continuous Internet connectivity, the system uses periodic brief connection windows for patch propagation. Devices connect intermittently to exchange patch data, then go offline to conserve energy. This periodic action maintains patch propagation capability while dramatically reducing energy consumption compared to continuous connectivity.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

Devices autonomously manage their own connectivity patterns, connecting only when necessary for patch propagation and remaining offline otherwise. The system self-regulates energy consumption by allowing devices to operate independently without requiring sustained Internet connection, resolving the contradiction between speed and energy use.

Inventive Principle:
Principle #25Self-service

3Device complexity

If centralized servers are used for patch distribution, then patch management is simplified, but resource consumption and propagation time increase

Engineering Contradiction:
Improvepatch management complexityVSAvoidpropagation time
Core Design Contradiction:
Device complexityVSLoss of time

Solution Approach 1:

The patent segments the centralized patch distribution model into distributed peer-to-peer exchanges. Instead of all devices communicating with a central server, devices share patches directly with each other in a distributed manner. This segmentation reduces the burden on centralized infrastructure and enables parallel propagation across multiple device pairs, reducing overall propagation time.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system merges the functions of centralized server distribution with decentralized peer-to-peer sharing. Devices can obtain patches from either centralized servers or neighboring devices, combining both approaches to achieve efficient propagation. This merging maintains simplified management while reducing propagation time through multiple distribution pathways.

Inventive Principle:
Principle #5Merging (Combining)

4Reliability

If devices are patched quickly to reduce vulnerability exposure, then security is improved, but resource consumption increases

Engineering Contradiction:
Improvesecurity vulnerability protectionVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The system performs preliminary patch preparation and exchange during brief connectivity windows, allowing devices to be patched quickly when they do connect. By preparing patch data in advance during intermittent connections, the actual patching operation can proceed rapidly without prolonged resource consumption, resolving the contradiction between security speed and energy use.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10223098B2Method and system to accelerate IoT patch propagation and reduce security vulnerabilities exposure time
Publication Date: 2019.03.05 INTEL CORP
  • US10223098B2 patent drawing
  • US10223098B2 patent drawing
  • US10223098B2 patent drawing

AI summary

Techniques for allowing devices to obtain software updates are described. In one scenario, a device broadcasts request for updates to nearby devices of the same type, at least one of which responds indicating an available update. The device requesting the update broadcasts a request for the available update to nearby devices, at least one of which provides at least a portion of the update. In another scenario, a device broadcasts requests for update to nearby devices manufactured by the same manufacturer. At least one device may provide the update, responsive to a determination that the update is available. Alternately, responsive to a determination that the update is not available, the device receiving the broadcast may respond saying the update is not available, then attempt to update the update from an update server. Upon receiving a later broadcast, the device having the update may provide the update to the requesting device.