IoT Router Traffic Interception and Cloud Authorization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing router firewall policies for IoT devices are complex and difficult for non-technical users to understand, and many IoT device manufacturers forward ports to the Internet without user awareness, making IoT devices susceptible to infections.

Innovation Solution

Mechanisms are provided to intercept inbound traffic to IoT devices, block traffic unless authorized by the user, and allow traffic for a specified period after user authorization, thereby making users aware of and in control of inbound traffic without needing to deal with complex router firewall rules.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If router firewall policies are used to control inbound traffic to IoT devices, then security control is provided, but the system complexity and difficulty of operation increase significantly

Engineering Contradiction:
Improvesecurity controlVSAvoiddifficulty of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a cloud-based security service as an intermediary between the user's router and IoT devices. This mediator handles the complex firewall policy management and traffic control remotely, eliminating the need for users to directly configure complex router settings while maintaining security control.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical/manual configuration of local router firewall rules with an automated cloud-based system. Users interact with simplified web interfaces to define security policies, which are then automatically translated and applied by the cloud service, substituting complex local configuration with remote service automation.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Adaptability or versatility

If port forwarding is configured manually by users, then specific traffic control is achieved, but user awareness and control of all device connections is reduced

Engineering Contradiction:
Improvetraffic control capabilityVSAvoiduser awareness of connections
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The patent implements comprehensive feedback mechanisms where the cloud-based security service continuously monitors all inbound traffic to IoT devices and provides real-time notifications to users. This feedback loop ensures users are always aware of connection attempts, allowing them to make informed decisions about traffic control.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The cloud-based security service provides universal monitoring and control capabilities for all types of traffic to any IoT device, regardless of the specific port or protocol. This multi-functional approach consolidates what would otherwise require multiple separate configurations into a single unified system.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If IoT device manufacturers forward ports automatically, then device functionality is improved, but security vulnerability increases due to lack of user awareness

Engineering Contradiction:
Improvedevice functionalityVSAvoidsecurity vulnerability
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by blocking all inbound traffic to IoT devices by default before any potential malicious connections can occur. The system proactively prevents unauthorized access attempts rather than reacting to security breaches after they occur, thereby countering the security vulnerabilities introduced by automatic port forwarding.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentEP3939234B1Systems, methods, and media for securing connections to internet of things devices
Publication Date: 2025.05.28 MCAFEE LLC
  • EP3939234B1 patent drawingFigure 1

AI summary

Mechanisms (which can include systems, methods, and media) for securing connections to IoT devices are provided. In some embodiments, systems for securing connections to Internet of Things (IoT) devices are provided, the systems comprising: a memory; and a hardware processor coupled to the memory and configured to: receive first inbound traffic at a router from a wide area network (WAN), wherein the first inbound traffic is destined for a first IoT device; block the first inbound traffic at the router; notify a server on the WAN that the first inbound traffic has been blocked; receive instructions from the server indicating to unblock the first inbound traffic; and unblock the first inbound traffic.