SD-SCAN Overlay Network for Industrial IoT Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Internet architectures are inadequate for securing and managing the increasing connectivity of IoT devices, particularly in industrial settings, as they lack the necessary security measures and resource management to prevent hacking and ensure reliable operation.

Innovation Solution

A Software Defined Secure Content/Context Aware Network (SD-SCAN) is proposed, featuring a cloaked network, digital twins, a communications mesh, and a resource provisioning matrix. This network uses dynamic connections, strong encryption, and intelligent agents to mirror and control physical devices, while the resource provisioning matrix adjusts resources based on service level demands.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional Internet architecture is used for IoT device connectivity, then device connectivity is achieved, but security vulnerabilities and hacking risks increase

Engineering Contradiction:
ImprovesecurityVSAvoidhacking risks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the network architecture into multiple isolated layers including device layer, edge layer, cloud layer, and data layer. Each layer operates with its own security protocols and access controls, preventing lateral movement of attacks. The digital twin technology creates virtual representations that isolate physical devices from direct network exposure, thereby segmenting the attack surface and enhancing overall security posture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces digital twins as intermediary entities between physical IoT devices and the network infrastructure. These digital twins act as secure proxies that handle authentication, authorization, and data exchange, eliminating the need for physical devices to maintain direct network connections. This intermediary layer blocks direct hacking attempts while maintaining full device functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If more IoT devices are connected to the Internet, then connectivity and functionality increase, but security management complexity increases

Engineering Contradiction:
Improvedevice connectivityVSAvoidsecurity management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal security management platform that handles authentication, authorization, monitoring, and provisioning for all IoT devices across the network. This centralized system provides multi-functional capabilities including device registration, credential management, policy enforcement, and threat detection, eliminating the need for separate security implementations for each device and simplifying management of large-scale IoT deployments.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent utilizes service level agreements (SLAs) with adjustable parameters to dynamically configure security policies based on device criticality, data sensitivity, and operational requirements. Security parameters such as authentication strength, encryption levels, and monitoring intensity can be modified without changing the underlying architecture, allowing flexible adaptation to different device types and threat scenarios.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If default passwords are used on IoT devices, then device setup is simplified, but security is compromised

Engineering Contradiction:
Improvedevice setupVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements preliminary security actions during device manufacturing and onboarding, where unique cryptographic credentials and security certificates are pre-provisioned to devices before deployment. The security management platform automatically generates and distributes device identities, authentication keys, and encryption credentials, ensuring that no default passwords exist while maintaining streamlined setup procedures through automated credential injection.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent enables devices to self-provision security credentials automatically upon network connection. Devices autonomously register with the security management platform, receive their unique authentication credentials, and configure their security settings without manual intervention. This self-service mechanism eliminates default passwords while maintaining ease of deployment through automated security configuration.

Inventive Principle:
Principle #25Self-service

4Reliability

If static resource allocation is used for digital twins, then system simplicity is maintained, but service level demands cannot be satisfied

Engineering Contradiction:
Improveservice level complianceVSAvoidresource management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic resource allocation for digital twins based on real-time service level agreement (SLA) requirements. The resource provisioning matrix continuously monitors digital twin performance metrics and automatically adjusts computational resources, memory allocation, and network bandwidth to meet changing service demands. This dynamic adaptation ensures SLA compliance while maintaining system simplicity through automated resource orchestration that responds to actual operational needs rather than static configurations.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11516068B2Software-defined network resource provisioning architecture
Publication Date: 2022.11.29 SHERR DAVID M
  • US11516068B2 patent drawing
  • US11516068B2 patent drawing
  • US11516068B2 patent drawing

AI summary

Embodiments are directed to an overlay network for an industrial Internet of Things. The overlay network has multiple main components: (1) a security component, such as a cloaked network, (2) a digital twin component that operates as digital simulations of the physical devices, (3) a communications mesh, and (4) a resource provisioning matrix for adjusting the resources used by the digital twin. The overlay network is a virtual network that is Software Defined—it sits on top of the existing Internet physical hardware of servers, routers, etc. The overlay network is sometimes referred to herein as a Software Defined Secure Content/Context Aware Network (SD-SCAN).