IoT Update Policy Enforcement via Forwarder Intermediary

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

IoT devices, especially those not traditionally part of a network, face configuration challenges and security threats when integrated, due to complications in access management and update policies.

Innovation Solution

An apparatus and method that utilize combined data including policy data and update metadata to configure access for IoT devices, enforcing update-specific policies through a forwarder to ensure appropriate and secure updates, using a system comprising an IoT device, a forwarder, an update repository, and a combined data manager.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If IoT devices are integrated into the network, then network functionality and connectivity are improved, but configuration challenges and security threats increase

Engineering Contradiction:
Improvenetwork connectivityVSAvoidsecurity threats
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a forwarder as an intermediary component between IoT devices and the network. The forwarder receives policy data from a combined data manager and applies it to control device access and update processes. This intermediary structure isolates IoT devices from direct network exposure, reducing security threats while maintaining connectivity functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If general access policies are applied to IoT devices, then device operation is simplified, but update-specific security requirements are not met

Engineering Contradiction:
Improvedevice operationVSAvoidupdate security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments access control policies into two distinct types: general access policies for device operation and update-specific policies for firmware updates. The combined data manager stores separate policy data structures, and the forwarder applies the appropriate policy type based on the request nature. This segmentation allows simplified general operation while enforcing strict security for updates.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically selects and applies different policy types based on the operation being performed. The forwarder determines whether a request requires general access policy or update-specific policy, and switches between policy application modes accordingly. This dynamic approach maintains ease of operation for routine tasks while ensuring security for critical update operations.

Inventive Principle:
Principle #15Dynamics

3Reliability

If update-specific policies are enforced, then security and reliability of updates are improved, but device complexity and configuration difficulty increase

Engineering Contradiction:
Improveupdate securityVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The combined data manager automatically retrieves, combines, and manages policy data without requiring manual configuration. The system self-configures by obtaining device information, fetching appropriate policy data from remote servers, and storing combined policies locally. This self-service approach reduces configuration complexity while maintaining comprehensive update-specific security policies.

Inventive Principle:
Principle #25Self-service

4Measurement precision

If manual configuration of access policies is performed, then policy accuracy is improved, but time consumption and operational efficiency decrease

Engineering Contradiction:
Improvepolicy accuracyVSAvoidconfiguration time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary actions by automatically obtaining device information and retrieving pre-defined policy data from remote servers before local deployment. The combined data manager pre-processes and combines policy data structures, so that when updates are needed, the accurate policies are already prepared and stored locally. This preliminary automation maintains policy accuracy while eliminating manual configuration time.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10581690B2Update specific policies for internet of things devices
Publication Date: 2020.03.03 CISCO TECHNOLOGY INC
  • US10581690B2 patent drawing
  • US10581690B2 patent drawing
  • US10581690B2 patent drawing

AI summary

In one embodiment, an apparatus comprising at least one memory, and processing circuitry, the processing circuitry adapted to obtain combined data, the combined data including policy data, or a pointer to the policy data, the policy data relating to general access for an Internet of Things (IoT) device, and update metadata, or a pointer to the update metadata, the update metadata relating to at least one update that is relevant to the IoT device in accordance with at least one criterion, and cause access of the IoT device to the at least one update to be in accordance with an update specific policy that is based on the combined data.