Local Analytics Device Provisioning for IoT Asset Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In the context of IoT-enabled remote asset monitoring, existing technologies face challenges in authorizing and authenticating IoT devices to interact with remote systems, particularly in recognizing and securely managing assets, which leads to issues with data routing and privacy concerns.

Innovation Solution

A local analytics device is provisioned with credentials to interact with an asset data platform, involving a multi-phase authorization process, where a provisioning device exchanges credentials with the asset data platform to enable the local analytics device to operate on behalf of the asset, ensuring secure data management and authorization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a local analytics device is integrated into an existing asset, then the device can collect and process asset data locally, but challenges arise in recognizing the existing device, obtaining authorizations, and routing data to proper recipients

Engineering Contradiction:
ImproveAbility of local analytics device to integrate with existing assetsVSAvoidComplexity of authorization and authentication processes
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by establishing credential exchange and authorization protocols before the local analytics device begins operating. The system pre-configures authentication credentials, establishes trust relationships, and sets up data routing rules in advance, so that when the device is deployed on an existing asset, the authorization framework is already in place to facilitate seamless integration without ad-hoc configuration complexity

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent employs an intermediary approach by introducing a provisioning system that mediates between the local analytics device, the remote asset monitoring system, and the asset itself. This intermediary provisioning infrastructure manages credential distribution, authorization verification, and data routing configuration, thereby reducing the direct complexity burden on the local analytics device while enabling versatile integration with existing assets

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple credentials are exchanged during provisioning, then secure authorization is achieved, but the provisioning process becomes more complex and time-consuming

Engineering Contradiction:
ImproveSecurity of authorization processVSAvoidTime required for credential exchange
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-establishing trust anchors and root credentials before the actual provisioning occurs. The system prepares authorization templates, pre-configures credential hierarchies, and sets up encryption key pairs in advance, so that during the actual credential exchange process, only signature verification and token distribution are needed rather than full cryptographic key establishment, thereby maintaining security while reducing provisioning time

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments the credential exchange process into distinct phases: initial trust establishment, credential issuance, authorization verification, and data routing configuration. By dividing the provisioning process into modular segments, the system can parallelize certain operations, cache verification results, and reuse authentication contexts across multiple devices, reducing the overall time required while maintaining comprehensive security through staged validation

Inventive Principle:
Principle #1Segmentation

3Productivity

If the local analytics device operates autonomously on behalf of the asset, then real-time data processing is enabled, but authorization management and data routing become more challenging

Engineering Contradiction:
ImproveReal-time data processing capabilityVSAvoidEase of authorization management
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The patent implements self-service by enabling the local analytics device to autonomously manage its own authorization context once initially provisioned. The device can locally verify credentials against stored trust anchors, self-validate data routing rules based on pre-configured policies, and autonomously establish secure communication channels with remote systems. This self-service capability allows real-time data processing without continuous external authorization intervention, while the initial provisioning phase establishes the autonomous operation framework

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent applies preliminary action by pre-configuring authorization policies, data routing rules, and communication protocols before the local analytics device begins autonomous operation. The system establishes trust relationships, pre-loads credential verification algorithms, and configures data flow pathways in advance, enabling the device to process data in real-time while relying on pre-established authorization frameworks rather than requiring continuous external authorization management

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10333775B2Facilitating the provisioning of a local analytics device
Publication Date: 2019.06.25 UPTAKE TECHNOLOGIES INC
  • US10333775B2 patent drawing
  • US10333775B2 patent drawing
  • US10333775B2 patent drawing

AI summary

Disclosed herein are systems, devices, and methods for provisioning a local analytics device to interact with a remote computing system on behalf of an asset that is coupled to the local analytics device and that is associated with a particular customer account hosted by the remote computing system.