Local Coordinator for IoT Device Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In environments where network connectivity is limited or unavailable, traditional network-based authentication and authorization management for IoT devices becomes deficient, leading to security risks and communication latency issues, especially in industrial settings where external network access is disabled for compliance reasons.

Innovation Solution

A coordinator system is introduced that enables local remote management of IoT devices within a coordinated environment, allowing for secure and rapid execution of tasks without external communication, using on-demand code execution and portable code segments to process authentication and authorization requests, thereby reducing security risks and communication latency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If remote management is implemented for embedded devices, then device management capability is improved, but communication latency increases and security risks arise

Engineering Contradiction:
Improvedevice management capabilityVSAvoidcommunication latency
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The system segments the management architecture into local embedded devices and a local coordinator, separating them from remote management systems. This segmentation enables local processing of management tasks, reducing communication latency while maintaining management capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The local coordinator acts as an intermediary between embedded devices and remote management systems. It handles authentication and authorization requests locally, reducing the need for direct communication with remote systems and thereby reducing latency and security risks.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If remote management is implemented for embedded devices, then device management capability is improved, but security risks increase due to private information disclosure

Engineering Contradiction:
Improvedevice management capabilityVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system segments sensitive authentication and authorization information locally at the coordinator, preventing it from being transmitted over public networks. This segmentation maintains security while enabling remote management capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The local coordinator serves as a secure intermediary that processes authentication and authorization requests without exposing private information to remote systems or public networks, thereby reducing security risks while maintaining management functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Extent of automation

If network-based authentication and authorization management is used, then centralized control is maintained, but system reliability decreases when network connectivity is limited or unavailable

Engineering Contradiction:
Improvecentralized controlVSAvoidsystem reliability
Core Design Contradiction:
Extent of automationVSReliability

Solution Approach 1:

The system segments authentication and authorization functionality from centralized remote systems and places it locally at the coordinator. This segmentation enables the system to maintain reliability during network outages while preserving centralized control when networks are available.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The local coordinator preliminarily processes authentication and authorization requests using locally stored information, enabling the system to function reliably without network connectivity. Centralized control is re-established when network connectivity is restored.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10872142B1Localized identity management in limited communication networks
Publication Date: 2020.12.22 AMAZON TECH INC
  • US10872142B1 patent drawing
  • US10872142B1 patent drawing
  • US10872142B1 patent drawing

AI summary

Systems and methods are described for management of data transmitted between computing devices in a communication network. An administrative component can configure one or more devices in the communication path of messages to be exchanged by devices to interpret codes embedded in the communication messages. A receiving device can review incoming messages for one or more processing codes or instructions that are embedded in the portion of the communication typically utilized solely to identify the subject matter of the communication, generally referred to as the topic portion of the communication. The receiving devices can then process the embedded codes to determine how the communication message will be routed or otherwise processed.