Decentralized IoT Security Broker for Identity Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security infrastructure for IoT devices is inadequate, with limited processing power, memory, and network connectivity making them difficult to integrate into existing client-server security systems, and there is a need for enhanced data security to prevent malicious attacks and unauthorized access.
Innovation Solution
A decentralized data security system using a distributed architecture with a security broker, blockchain database, and security gateway to encrypt, distribute, and manage identity and access management (IAM) services, reducing reliance on enterprise servers and enhancing resistance to malicious attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional client-server security systems are used, then identity and access management services can be provided, but the system becomes vulnerable to security breaches and requires centralized trust
Solution Approach 1:
The patent segments the centralized security system into distributed security nodes. Each node maintains local security context and can independently perform authentication and access control decisions, eliminating the single point of failure at the central server while reducing overall system vulnerability to breaches.
Solution Approach 2:
The patent introduces security proxies or intermediaries between clients and servers that operate autonomously to make security decisions. These intermediaries cache security context, perform local authentication, and mediate communication, reducing reliance on centralized authority while maintaining security functions.
2Productivity
If centralized security services are deployed, then access control can be managed, but network traffic and processing resources are concentrated at the server
Solution Approach 1:
The patent performs security context establishment, authentication, and access control decisions in advance at distributed nodes before actual data transmission occurs. By pre-establishing security contexts and caching authentication information at edge nodes, the system reduces real-time network traffic for security operations while maintaining efficient access control.
Solution Approach 2:
The patent implements local security processing at distributed nodes rather than centralizing all security operations. Each node performs security functions locally using cached context and pre-shared keys, reducing network bandwidth consumption for security traffic while improving overall processing efficiency through parallel security operations.
3Adaptability or versatility
If IoT devices have limited processing power and memory, then device constraints are satisfied, but integration into existing security systems becomes difficult
Solution Approach 1:
The patent creates lightweight copies of security contexts, credentials, and access control policies at distributed nodes and IoT devices. Instead of requiring full security system replication, devices store and process only the necessary security context information locally, enabling integration with limited processing power while maintaining security functionality.
Solution Approach 2:
The patent implements partial security processing at IoT devices, where devices perform only the minimal necessary security operations locally (such as presenting credentials or receiving authorization decisions) while more complex security functions are handled by distributed security nodes. This partial action approach enables device integration without requiring excessive processing power at the device level.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method comprises: at a first computing device, receiving security service data from a first digital data repository (DDR), generating hidden security service data by generating a plurality of shares of the security service data, encrypting each share of the plurality of shares to generate a plurality of encrypted shares; electronically storing the plurality of encrypted shares as data in a second DDR; using a subset of the plurality of second computing devices, in response to receiving an authentication request from a third computing device to access one or more fourth computing devices, decrypting a subset of the plurality of encrypted shares; forming and storing a readable copy of the hidden security service data using the plurality of decrypted shares; using the readable copy of the hidden security service data, performing authentication services for the third computing device to grant/deny access to the one or more fourth computing devices.