IoT Security via Blockchain and Rendezvous Servers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The rapid proliferation of Internet of Things (IoT) devices is hindered by the lack of effective security measures, making them vulnerable to malicious attacks, as seen in the 2016 Dyn attack where unsecured IoT devices were used to launch a Distributed Denial of Service (DDoS) attack, and it is expected that two-thirds of enterprises will experience an IoT security breach by 2018.

Innovation Solution

A management system for IoT devices that utilizes blockchain technology and Diffie-Hellman encryption to secure communications, with a NeuroNode managing device nodes, rendezvous servers, and a NeuroCloud, implementing security protocols such as whitelisting IP addresses, malware signature detection, and packet sniffing to protect against breaches.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security measures are implemented on IoT devices, then security protection is improved, but device complexity and resource consumption increase

Engineering Contradiction:
Improvesecurity protectionVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a blockchain-based intermediary system that acts as a trusted mediator between IoT devices and external entities. The blockchain network provides security functions (identity verification, access control, transaction logging) without requiring these functions to be implemented directly within resource-constrained IoT devices, thus improving security while maintaining device simplicity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables IoT devices to autonomously interact with the blockchain network using standardized protocols. Devices can independently perform security-critical operations such as generating cryptographic key pairs, verifying blockchain transactions, and enforcing access policies without requiring centralized management intervention, thereby achieving self-service security that reduces overall system complexity.

Inventive Principle:
Principle #25Self-service

2Reliability

If security updates are applied to IoT devices, then security protection is improved, but device operation is interrupted requiring devices to be taken offline

Engineering Contradiction:
Improvesecurity protectionVSAvoiddevice operation continuity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs security updates in advance by leveraging the immutable nature of blockchain. Security policies, access control rules, and cryptographic credentials are predetermined and stored on the blockchain before being needed. When updates are required, devices simply retrieve new policies from the blockchain without requiring complex update mechanisms or taking offline, thus maintaining continuous operation while improving security.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If comprehensive security protocols are implemented, then security protection is improved, but communication overhead and processing time increase

Engineering Contradiction:
Improvesecurity protectionVSAvoidcommunication overhead
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system dynamically adjusts security protocol parameters based on context. For example, it uses asymmetric cryptography (public-key infrastructure) for initial authentication and key exchange, then switches to symmetric cryptography for subsequent data transmission. This parameter change optimizes the balance between security strength and communication efficiency, reducing time loss while maintaining robust security protection.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10652016B2Methods, apparatus, and systems for controlling internet-connected devices having embedded systems with dedicated functions
Publication Date: 2020.05.12 CIRCLE INTERNET GRP INC
  • US10652016B2 patent drawing
  • US10652016B2 patent drawing
  • US10652016B2 patent drawing

AI summary

Systems, apparatus, and methods are disclosed for controlling internet-connected devices having embedded systems with dedicated functions. A lightweight software that protects the internet-connected devices from security breaches and security threat is installed on the internet-connected devices. The lightweight software sends network traffic data to a management server via one or more rendezvous servers. The management server analyzes the network traffic data and generates a security update. The security update is posted on a blockchain. The lightweight software obtains the security update in the form of a blockchain transaction.