M2M Privacy Brokered Transactions via Intermediary Server

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current machine-to-machine (M2M) communication systems face challenges in maintaining privacy and security, as devices often need to reveal their addressing information to connect, making them vulnerable to attacks and unsolicited messages, and existing solutions rely on pre-distributed secrets and certificates that can be fraudulently generated.

Innovation Solution

A secure M2M messaging system that uses an intermediary server with access to a database linking addressing information with machine characteristic information, allowing secure communication without revealing addressing details, and utilizing security rules to authenticate and authorize message transmissions based on ownership, location, and other criteria.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If machines use pre-distributed secrets and certificates for authentication, then connection security is improved, but vulnerability to fraudulent generation and attacks increases

Engineering Contradiction:
Improveconnection securityVSAvoidfraudulent generation and attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a broker as an intermediary that performs mutual authentication between machines. Instead of relying on pre-distributed secrets that can be compromised, the broker verifies credentials and establishes secure connections. This intermediary approach resolves the contradiction by providing reliable authentication while preventing fraudulent access through centralized verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If machines reveal their addressing information to connect, then communication capability is improved, but privacy and security are worsened

Engineering Contradiction:
Improvecommunication capabilityVSAvoidprivacy and security
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The broker acts as an intermediary that manages addressing information centrally. Machines can communicate through the broker without exposing their actual addressing details to each other. The broker translates and routes communications while maintaining privacy, thus improving communication capability without sacrificing security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system uses virtual addressing or proxy identifiers that copy the function of real addresses without revealing the actual machine identities. These virtual addresses can be changed or revoked by the broker without affecting the underlying machine, providing both communication capability and privacy protection.

Inventive Principle:
Principle #26Copying

3Productivity

If machines store and manage physical addresses across all connecting devices, then direct communication is improved, but system complexity and workload increase

Engineering Contradiction:
Improvedirect communication efficiencyVSAvoidaddress management workload
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The broker centralizes address management, eliminating the need for each machine to store and manage addresses of all other devices. The broker maintains the addressing information and performs lookups, reducing system complexity while maintaining direct communication efficiency through centralized coordination.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2907275B1System and method for machine-to-machine privacy and security brokered transactions
Publication Date: 2018.06.27 MOBILE SEARCH SECURITY LLC
  • EP2907275B1 patent drawingFigure 1
  • EP2907275B1 patent drawingFigure 2
  • EP2907275B1 patent drawingFigure 3

AI summary

A machine-to-machine secure messaging system permits a first machine to send a message to a second machine, despite not knowing the addressing information (e.g., telephone number, IP address or other identifier) associated with the second machine. The system comprises an intermediary server with access to a database with information linking addressing information with other information related to the device, e.g., owner name, operator name and job title, etc., and facilitates a secure communication without the need for either party to the communication to know the other party's addressing information.