Security Gateway for IoT Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security infrastructure for IoT devices is inadequate, as they often lack processing power, memory, and user interface elements, making them difficult to integrate into existing client-server security systems, and there is a need for a single authentication portal that can accommodate multiple devices and applications efficiently.

Innovation Solution

A security gateway system that provides local identity and access management services, authenticating devices and applications on behalf of enterprise servers, using blockchain technology for secure data storage and validation, and rotating credentials to enhance security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional client-server security systems are used with IoT devices, then security validation can occur, but the limited processing power and memory of IoT devices make them difficult to integrate

Engineering Contradiction:
Improvesecurity validationVSAvoidintegration capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a server as an intermediary between IoT devices and the authentication system. The server handles all authentication and validation operations, while IoT devices only need to communicate basic device identifiers. This mediator approach allows security validation without requiring processing power or memory on the IoT devices themselves, resolving the contradiction between maintaining security and accommodating limited device capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If multiple IoT devices with different applications are accessed from a single client device, then access management is simplified, but the client device requires excessive storage space for multiple applications

Engineering Contradiction:
Improveaccess managementVSAvoidstorage space
Core Design Contradiction:
Ease of operationVSQuantity of substance

Solution Approach 1:

The patent extracts the authentication functionality from individual device applications and consolidates it into a single unified application on the client device. This single application can authenticate to multiple different IoT devices without requiring separate applications for each device. The extraction of authentication logic from device-specific applications eliminates the need for multiple applications, thereby reducing storage space while maintaining ease of access management.

Inventive Principle:
Principle #2Taking out (Extraction)

3Adaptability or versatility

If authentication is handled by downloaded applications on the client device, then device-specific access can be controlled, but processing resources of the client device are heavily strained

Engineering Contradiction:
Improvedevice-specific access controlVSAvoidprocessing resources
Core Design Contradiction:
Adaptability or versatilityVSPower

Solution Approach 1:

The patent introduces a server as an intermediary that handles all authentication processing. Instead of the client device's downloaded applications performing authentication locally (which strains processing resources), the server performs all authentication operations. The client device simply communicates authentication requests and receives responses, transferring the computational burden to the server while maintaining device-specific access control capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If uninterrupted internet access is required for authentication, then security validation can occur, but network connectivity becomes a critical dependency

Engineering Contradiction:
Improveauthentication validationVSAvoidnetwork dependency
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary authentication where the server validates IoT devices and establishes authentication tokens or credentials in advance. These pre-established credentials allow the system to maintain security validation capability even when network connectivity is interrupted. The preliminary authentication action stores necessary validation information that can be used offline, reducing critical network dependency while maintaining authentication reliability.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10404696B2Enabling multitenant data access on a single industrial network
Publication Date: 2019.09.03 XAGE SECURITY INC
  • US10404696B2 patent drawing
  • US10404696B2 patent drawing
  • US10404696B2 patent drawing

AI summary

In an embodiment, a computer-implemented method comprises: in response to receiving a first authentication request from one or more first computing devices, authenticating the first computing devices on behalf of a first client device using a first set of identity information; in response to authenticating the first computing devices, generating and queuing a first set of one or more transactions corresponding to at least one of the one or more first computing devices; in response to receiving a second authentication request from the first client device configured to access the first set of one or more transactions, authenticating the first client device on behalf of a second computing device using a second set of identity information that is associated with the first client device; in response to performing the second authentication service, encrypting and sending the first set of one or more transactions to the first client device.