IoT Device Update Service with Mobile Relay Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current IoT systems face challenges in efficiently managing and updating IoT devices, particularly in ensuring secure communication and data transmission across long ranges without formal pairing, and in effectively handling multiple IoT hubs connecting to a single device, which leads to unnecessary wireless traffic and potential security vulnerabilities.
Innovation Solution
The implementation of a system that uses secure key exchange protocols, such as public/private key pairs and symmetric key encryption, for encrypted communication between IoT devices and hubs, along with an intermediary mobile device for data transmission when within range, and a mechanism to manage advertising intervals and flow control to reduce unnecessary wireless traffic.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple IoT hubs connect to a single IoT device, then communication flexibility and redundancy are improved, but wireless traffic increases and security vulnerabilities increase
Solution Approach 1:
The patent introduces an intermediary mobile device that acts as a relay between the IoT device and multiple hubs. The mobile device receives data from the IoT device when in range and forwards it to the appropriate hub, eliminating the need for the IoT device to maintain simultaneous connections with multiple hubs and reducing wireless traffic from the IoT device.
2Reliability
If formal pairing is required between IoT devices and hubs, then security is improved, but ease of operation deteriorates
Solution Approach 1:
The patent implements preliminary security measures by establishing encrypted communication channels and exchanging cryptographic keys during the initial connection phase. The mobile device pre-establishes secure connections with hubs and caches authentication credentials, so that subsequent communications do not require repeated formal pairing while maintaining security.
Solution Approach 2:
The mobile device serves as a security intermediary that handles complex authentication and key exchange protocols between the IoT device and hubs. This shields the IoT device from complex pairing procedures while maintaining secure communication through the mobile device's mediation.
3Use of energy by moving object
If advertising intervals are increased to reduce wireless traffic, then energy consumption is reduced, but data transmission responsiveness deteriorates
Solution Approach 1:
The patent implements dynamic advertising intervals where the mobile device adjusts the frequency of data requests and advertisements based on current conditions. When the mobile device is in range of the IoT device, it increases communication frequency for rapid data transfer. When out of range, it reduces advertising intervals to minimize energy consumption while maintaining the ability to quickly resume communication when reconnecting.
Data Source
AI summary
A system and method are described for performing service-initiated updates to IoT devices. For example, one embodiment of a system comprises: a plurality of IoT devices, each IoT device comprising: a storage device to store attributes and/or program code; a processor to execute the program code using the attributes to perform one or more specified functions of the IoT device, and attribute/code management circuitry and/or logic to manage a current state of the attributes and/or program code; an Internet of Things (IoT) cloud service to be communicatively coupled to IoT devices over the Internet, the IoT cloud service including an update service to initiate updates of the attributes and/or program code stored on the plurality of IoT devices, an IoT device to transmit a notification to the update service upon reaching a particular initialization state, the notification including an indication of a current attribute and/or program code state; the update service to responsively determine whether an update to the current attribute and/or program code state is available and, if so, to use a first key to generate a signature over a binary which includes the update to the attribute and/or program code state to generate a signed binary; the update service to further store the signed binary in a designated network location and to generate or retrieve a Uniform Resource Locator (URL) identifying the network location, the update service to transmit an update command to the IoT device containing the URL; the attribute/code management circuitry and/or logic of the IoT device to interpret the URL to retrieve the signed binary, to use a second key to verify the signature, and to responsively update the attribute and/or program code in accordance with the binary.


