IoT Security Management System with Digital Identity Tokens

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing and securing Internet of Things (IoT) devices is challenging due to issues with unauthorized access, data control, and firmware updates, particularly in manufactured products like automobiles, where third-party devices are integrated, posing risks and liability concerns.

Innovation Solution

A method and system for establishing secure communication between IoT devices using unique identification, digital identity tokens, cryptographic keys, and digital certificates, with an attribute authority mediating secure communication lines and preventing unauthorized access, while enabling secure firmware updates and strong identity management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If IoT devices are integrated into manufactured products by third-parties, then device functionality and versatility are improved, but security control and access management become more difficult

Engineering Contradiction:
Improvedevice functionalityVSAvoidsecurity control
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a security management system as an intermediary between manufacturers, third-party IoT devices, and end users. This system provides centralized device provisioning, digital certificate management, and access control policies that simplify security control while maintaining device functionality. The intermediary handles the complexity of securing third-party devices, allowing manufacturers to benefit from versatile IoT integration without directly managing the security complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If strong identity management and access control are implemented for IoT devices, then security is improved, but device provisioning and configuration become more complex

Engineering Contradiction:
ImprovesecurityVSAvoidprovisioning and configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by pre-provisioning IoT devices with unique identifiers, cryptographic keys, and digital certificates during manufacturing or device initialization. The security management system pre-configures access control policies and device identities before deployment, eliminating the need for complex manual configuration after deployment. This preliminary setup ensures strong identity management while simplifying the actual device provisioning process for end users.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If centralized security management is implemented for IoT devices, then access control and data protection are improved, but system complexity and infrastructure requirements increase

Engineering Contradiction:
Improveaccess controlVSAvoidsystem infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal security management system that serves multiple functions: device provisioning, identity management, access control policy enforcement, and firmware update management. By consolidating these security functions into a single multi-functional platform, the system provides centralized access control and data protection without proportionally increasing infrastructure complexity. The universal system can manage diverse IoT devices from different manufacturers through standardized protocols and interfaces.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9832026B2System and method from Internet of Things (IoT) security and management
Publication Date: 2017.11.28 T CENT
  • US9832026B2 patent drawing
  • US9832026B2 patent drawing
  • US9832026B2 patent drawing

AI summary

System and method for establishing a secure communication between a plurality of Internet of Things (IoT) devices, includes provisioning a first and a second IoT devices by providing a unique identification, a digital identity token and a cryptographic key to each of the first and second IoT devices; authenticating the second IoT device by the first IoT device; inviting the second IoT device by the first IoT device to establish a communication line with the first IoT device; establishing a secure communication line between the first IoT device and the second IoT device by authenticating the communication line between the first IoT device and the second IoT device and issuing a digital certificate to the communication line between the first IoT device and the second IoT device; establishing secure communication lines between the first IoT device, the second IoT device and a plurality of more devices; and grouping the first IoT device, the second IoT device and the plurality of more devices into different groups based on a predetermined criteria.