IoT Security Gateway for Interoperability Path Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

IoT networks face challenges in achieving consistent security capabilities across heterogeneous devices due to varying security parameters and limited resources in constrained environments, leading to interoperability gaps, including security interoperability issues.

Innovation Solution

Implementing a Software Defined Network Security Interoperability (SDNSI) solution with a Security Resource Introspection Manager (SRIM) that analyzes security attributes of IoT devices, constructs connectivity graphs, and provides recommendations or isolates devices to ensure secure communication paths, using mechanisms like directory services, inference engines, and dynamic provisioning to align security settings.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security capabilities are enhanced across IoT devices, then network security is improved, but device complexity and resource requirements increase

Engineering Contradiction:
Improvenetwork securityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a Security Gateway as an intermediary component that centralizes security management functions. The gateway analyzes security attributes, constructs connectivity graphs, and determines interoperability paths, thereby enhancing network security without requiring complex security implementations in individual constrained IoT devices. The gateway acts as a mediator that handles the computational burden of security analysis externally.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The Security Gateway performs multiple functions including security attribute analysis, connectivity graph construction, interoperability path determination, and device provisioning. By consolidating these diverse security management tasks into a single multi-functional gateway, the system improves overall network security while avoiding the need to implement all these complex functions in each individual IoT device.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If security interoperability is ensured across heterogeneous devices, then communication reliability is improved, but system complexity increases

Engineering Contradiction:
Improvecommunication reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The Security Gateway serves as a central intermediary that manages security interoperability across heterogeneous IoT devices. It analyzes security attributes from different devices, constructs a connectivity graph representing security relationships, and determines appropriate interoperability paths. This centralized mediation approach ensures reliable communication between diverse devices without requiring each device to independently handle complex interoperability logic.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system dynamically determines security parameters and interoperability configurations based on the analyzed security attributes of participating devices. The Security Gateway adjusts security settings, protocol selections, and communication paths by changing parameters in response to the specific capabilities and requirements of each device pair, thereby ensuring reliable communication while adapting to heterogeneity.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If security analysis is performed on all devices, then interoperability issues are identified, but processing time and computational resources increase

Engineering Contradiction:
Improveinteroperability analysis accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The Security Gateway performs security attribute analysis and connectivity graph construction in advance, before actual device communication is needed. By pre-analyzing security attributes and pre-determining interoperability paths, the system identifies potential interoperability issues ahead of time without causing delays during actual device operations. This preliminary analysis approach ensures accurate interoperability detection while minimizing processing time during runtime.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10389756B2System, apparatus and method for security interoperability path analysis in an internet of things (IOT) network
Publication Date: 2019.08.20 INTEL CORP
  • US10389756B2 patent drawing
  • US10389756B2 patent drawing
  • US10389756B2 patent drawing

AI summary

In one embodiment, an apparatus comprises a first logic to receive security attribute information from a plurality of devices, generate a connectivity graph of the plurality of devices based at least in part on the security attribute information and identify an interoperability issue between a first device and a second device based on the connectivity graph. The apparatus may further include a second logic to generate a recommendation to resolve the interoperability issue and a third logic to provide provisioning information to at least one of the first device and the second device based on the recommendation. Other embodiments are described and claimed.