Virtual IoT UID Registry for Cross-Domain Device Trust
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing IoT device management systems are susceptible to attacks and do not provide secure, trusted transfers across administrative boundaries, lacking the ability to authenticate and manage device identities effectively.
Innovation Solution
A registry system for IoT devices, managed by a central trusted authority, uses IoT Universal Identifiers (UIDs) for device authentication and trust management, allowing devices to verify each other's capabilities and risk levels, and track device histories and trust indicators.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional IoT device management systems are used, then device connectivity and basic operation are maintained, but security is compromised and trusted transfers across administrative boundaries cannot be achieved
Solution Approach 1:
A centralized registry system acts as an intermediary between IoT devices, providing a trusted authority that issues and manages unique device identifiers. This mediator enables secure authentication and trust verification without requiring complex peer-to-peer security implementations, thus improving security while managing complexity through a single point of coordination.
Solution Approach 2:
The patent extracts the trust management function from individual domain controllers and consolidates it into a centralized registry. By separating the trust authority from local systems, the solution achieves cross-administrative trust without requiring each device to maintain complex trust relationships with multiple authorities, thereby improving security while simplifying the overall architecture.
2Ease of operation
If domain controller servers are used to manage security groups, then device authentication is achieved, but system complexity and management overhead increase
Solution Approach 1:
The patent removes the domain controller server component from the authentication architecture and replaces it with a registry-based system. Devices obtain authentication credentials from the registry once and can then authenticate with multiple services without requiring domain controller involvement, significantly simplifying operation while eliminating complex server management.
Solution Approach 2:
Devices perform self-authentication by presenting their unique identifiers to services that query the registry. This eliminates the need for centralized authentication servers and allows devices to independently verify their identities, reducing operational complexity while maintaining secure authentication.
3Reliability
If approved lists are maintained by devices or administrators to trust other devices, then security is improved, but real-time trust verification capability is reduced
Solution Approach 1:
The registry provides real-time feedback on device trust status by maintaining current information about device identifiers and their associated trust attributes. When a service needs to verify a device, it queries the registry which immediately returns the current trust status, enabling real-time verification without requiring devices to maintain and update their own approved lists.
Solution Approach 2:
The system performs preliminary trust evaluation by pre-establishing device identifiers and their trust attributes in the registry before devices need to interact. This allows for rapid verification at the time of interaction without requiring real-time trust building or complex verification processes, thus reducing verification time while maintaining reliability.
Data Source
AI summary
A method for registering one or more Greenfield devices via a virtual Internet of Things Universal Identifier (IoT UID) is provided. The method includes identifying one or more Brownfield devices, generating device property data based at least in part on the one or more Brownfield devices, and transmitting, to an IoT device registrar server, a registration request that includes the device property data. The method further includes interpreting one or more IoT UIDs generated in response to the transmitting of the registration request.


