IoT Security via Blockchain and Rendezvous Servers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The rapid proliferation of Internet of Things (IoT) devices is hindered by the lack of effective security measures, making them vulnerable to malicious attacks, as seen in the 2016 Dyn attack where unsecured IoT devices were used to launch a Distributed Denial of Service (DDoS) attack, and it is expected that two-thirds of enterprises will experience an IoT security breach by 2018.
Innovation Solution
A management system for IoT devices that utilizes blockchain technology and Diffie-Hellman encryption to secure communications, with a NeuroNode managing device nodes, rendezvous servers, and a NeuroCloud, implementing security protocols such as whitelisting IP addresses, malware signature detection, and packet sniffing to protect against breaches.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional security measures are implemented on IoT devices, then security protection is improved, but device complexity and resource consumption increase
Solution Approach 1:
The patent introduces a blockchain-based intermediary system that acts as a trusted mediator between IoT devices and external entities. The blockchain network provides security functions (identity verification, access control, transaction logging) without requiring these functions to be implemented directly within resource-constrained IoT devices, thus improving security while maintaining device simplicity.
Solution Approach 2:
The system enables IoT devices to autonomously interact with the blockchain network using standardized protocols. Devices can independently perform security-critical operations such as generating cryptographic key pairs, verifying blockchain transactions, and enforcing access policies without requiring centralized management intervention, thereby achieving self-service security that reduces overall system complexity.
2Reliability
If security updates are applied to IoT devices, then security protection is improved, but device operation is interrupted requiring devices to be taken offline
Solution Approach 1:
The system performs security updates in advance by leveraging the immutable nature of blockchain. Security policies, access control rules, and cryptographic credentials are predetermined and stored on the blockchain before being needed. When updates are required, devices simply retrieve new policies from the blockchain without requiring complex update mechanisms or taking offline, thus maintaining continuous operation while improving security.
3Reliability
If comprehensive security protocols are implemented, then security protection is improved, but communication overhead and processing time increase
Solution Approach 1:
The system dynamically adjusts security protocol parameters based on context. For example, it uses asymmetric cryptography (public-key infrastructure) for initial authentication and key exchange, then switches to symmetric cryptography for subsequent data transmission. This parameter change optimizes the balance between security strength and communication efficiency, reducing time loss while maintaining robust security protection.
Data Source
AI summary
Systems, apparatus, and methods are disclosed for controlling internet-connected devices having embedded systems with dedicated functions. A lightweight software that protects the internet-connected devices from security breaches and security threat is installed on the internet-connected devices. The lightweight software sends network traffic data to a management server via one or more rendezvous servers. The management server analyzes the network traffic data and generates a security update. The security update is posted on a blockchain. The lightweight software obtains the security update in the form of a blockchain transaction.


