Security Gateway for IoT Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security infrastructure for IoT devices is inadequate, as they often lack processing power, memory, and user interface elements, making them difficult to integrate into existing client-server security systems, and there is a need for a single authentication portal that can accommodate multiple devices and applications efficiently.
Innovation Solution
A security gateway system that provides local identity and access management services, authenticating devices and applications on behalf of enterprise servers, using blockchain technology for secure data storage and validation, and rotating credentials to enhance security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional client-server security systems are used with IoT devices, then security validation can occur, but the limited processing power and memory of IoT devices make them difficult to integrate
Solution Approach 1:
The patent introduces a server as an intermediary between IoT devices and the authentication system. The server handles all authentication and validation operations, while IoT devices only need to communicate basic device identifiers. This mediator approach allows security validation without requiring processing power or memory on the IoT devices themselves, resolving the contradiction between maintaining security and accommodating limited device capabilities.
2Ease of operation
If multiple IoT devices with different applications are accessed from a single client device, then access management is simplified, but the client device requires excessive storage space for multiple applications
Solution Approach 1:
The patent extracts the authentication functionality from individual device applications and consolidates it into a single unified application on the client device. This single application can authenticate to multiple different IoT devices without requiring separate applications for each device. The extraction of authentication logic from device-specific applications eliminates the need for multiple applications, thereby reducing storage space while maintaining ease of access management.
3Adaptability or versatility
If authentication is handled by downloaded applications on the client device, then device-specific access can be controlled, but processing resources of the client device are heavily strained
Solution Approach 1:
The patent introduces a server as an intermediary that handles all authentication processing. Instead of the client device's downloaded applications performing authentication locally (which strains processing resources), the server performs all authentication operations. The client device simply communicates authentication requests and receives responses, transferring the computational burden to the server while maintaining device-specific access control capabilities.
4Reliability
If uninterrupted internet access is required for authentication, then security validation can occur, but network connectivity becomes a critical dependency
Solution Approach 1:
The patent implements preliminary authentication where the server validates IoT devices and establishes authentication tokens or credentials in advance. These pre-established credentials allow the system to maintain security validation capability even when network connectivity is interrupted. The preliminary authentication action stores necessary validation information that can be used offline, reducing critical network dependency while maintaining authentication reliability.
Data Source
AI summary
In an embodiment, a computer-implemented method comprises: in response to receiving a first authentication request from one or more first computing devices, authenticating the first computing devices on behalf of a first client device using a first set of identity information; in response to authenticating the first computing devices, generating and queuing a first set of one or more transactions corresponding to at least one of the one or more first computing devices; in response to receiving a second authentication request from the first client device configured to access the first set of one or more transactions, authenticating the first client device on behalf of a second computing device using a second set of identity information that is associated with the first client device; in response to performing the second authentication service, encrypting and sending the first set of one or more transactions to the first client device.


