Secure D2D Communication via Cellular Intermediary

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current device-to-device communication methods over public Internet face security vulnerabilities and challenges in network topology, firewall restrictions, and device mobility, especially for IoT devices, which can lead to breaches and impact multiple connected devices.

Innovation Solution

A system and method for secure device-to-device data communication using a Device Management Server and Security Enforcement Server on distributed cloud servers, establishing secure tunnels without public Internet connection, with anomaly detection and alert mechanisms, utilizing blockchain digital ledger for ownership and security policies, and employing IPSec, SSL, or TLS VPN for encryption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If device-to-device communication is established over public Internet, then remote access and direct communication are enabled, but security vulnerabilities and firewall restrictions increase

Engineering Contradiction:
Improveremote access capabilityVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a cellular network as an intermediary communication path between devices. Instead of direct Internet connectivity, devices establish connections through cellular network infrastructure, which acts as a trusted mediator providing inherent security and bypassing public Internet firewall restrictions while enabling remote access

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If IoT devices connect via home Wi-Fi network, then local device communication is simplified, but security breach impact spreads to multiple devices

Engineering Contradiction:
Improvelocal network connectivityVSAvoiddevice security isolation
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the communication architecture by assigning each device its own cellular network connection independent of local Wi-Fi networks. This segmentation isolates devices from each other at the network level, so that a security breach on one device cannot propagate to other devices through the same local network

Inventive Principle:
Principle #1Segmentation

3Object-affected harmful factors

If secure tunnels are established through cellular network, then security and firewall restrictions are mitigated, but device complexity and infrastructure requirements increase

Engineering Contradiction:
Improvefirewall restrictionsVSAvoidcommunication infrastructure
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent leverages the cellular network's inherent capabilities and existing infrastructure to provide secure communication. The cellular network itself provides the tunneling and security functions without requiring complex additional infrastructure at the device level, as the network operator's infrastructure handles the complexity

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11178542B1Method and system for secure device-to-device data communications
Publication Date: 2021.11.16 SYNIVERSE TECHNOLOGIES LLC
  • US11178542B1 patent drawing
  • US11178542B1 patent drawing
  • US11178542B1 patent drawing

AI summary

This invention relates generally to the field of security and remote data communications, specifically to data communications between applications running on different devices residing in different service provider networks. The invention includes methods and systems to resolve the application host based on user defined naming schema, automate the secure tunnel creation among the communication entities via Security Enforcement Servers, start up the applications via secure out of band control channel, perform packet inspection and anomaly detection based on injected user rules and historical traffic pattern, generate alert or notifications via email, text, etc. to specific users. The invention further tears down the secure connection based on application demand or inactivity timeout, generates event and statistic data records for troubleshooting and future auditing.