Security Gateway for IoT Device Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Secure access, management, and control of computing devices with constrained processing hardware, such as those in the Internet of Things, are challenging due to limited resources and the need for robust security measures, often overlooked by developers focused on device functionality rather than security.

Innovation Solution

A software-as-a-service (SaaS) framework provides pre-built secure computing tools and services, allowing developers to outsource security implementation through a policy-based control system that registers, manages, and operates secure services on network-connected devices, simplifying secure software development and operation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security measures are implemented on constrained computing devices, then security reliability is improved, but device complexity and resource consumption increase

Engineering Contradiction:
Improvesecurity reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a security gateway as an intermediary component that mediates between the constrained computing device and the external network. The gateway handles complex security functions including authentication, authorization, and encryption/decryption operations, allowing the device itself to remain simple while still achieving robust security. The gateway acts as a buffer that protects the device from direct exposure to network threats.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts security-critical functions from the constrained computing device and relocates them to a dedicated security gateway. Functions such as public key infrastructure (PKI) management, certificate validation, and secure key storage are removed from the device and implemented in the gateway, reducing the device's complexity and resource requirements while maintaining security effectiveness.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If comprehensive security implementation is done by developers, then security reliability is improved, but development time and expertise requirements increase

Engineering Contradiction:
Improvesecurity reliabilityVSAvoiddevelopment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements a security framework where the system automatically handles security configurations and operations without requiring developer intervention. The security gateway automatically manages certificate issuance, key pair generation, and security policy enforcement. Developers simply need to register their devices and services, and the system autonomously provisions security credentials and configurations, eliminating the need for developers to manually implement complex security measures.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent creates a universal security gateway that serves multiple functions across different devices and applications. The gateway provides a standardized interface for authentication, authorization, encryption, and device management that works across diverse IoT devices, eliminating the need for developers to implement device-specific security solutions. This multi-functional approach consolidates security operations into a single reusable infrastructure.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11425168B2System and methods for facilitating secure computing device control and operation
Publication Date: 2022.08.23 SEQUITUR LABS INC
  • US11425168B2 patent drawing
  • US11425168B2 patent drawing
  • US11425168B2 patent drawing

AI summary

A system and methods for facilitating secure computing device control and operation. The invention discloses a framework to supply security and policy-based control to computing applications as a software service. Clients running the framework make requests for services whereby they identify the service needed and its required parameters, encrypt and sign them, and send them to the service handler. The service handler decrypts, checks for policy allowance, and then, if allowed, executes the functions. The handler then encrypts and returns the response to the client. The framework allows for an aggregator that collects service requests for any number of clients and manages the distribution to service handlers and communications back to the clients.