Secure Data Exchange Platform for IoT Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Low Power and Lossy Networks (LLNs), such as IoT networks, face challenges due to environmental changes, low bandwidth, and resource constraints, making secure and efficient data exchange difficult, especially in sharing sensitive data across multiple entities while maintaining anonymity and controlling access to data attributes.
Innovation Solution
A secure data exchange platform is introduced, utilizing a cloud-based intermediary and exchange connectors that select processing modes and encrypt sensor data using a first encryption mechanism, allowing selective sharing of data attributes with authorized entities, optimizing cryptographic operations and reducing computational overhead on IoT devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If sensor data is encrypted using a first encryption mechanism that controls access to attributes, then data security and access control are improved, but computational overhead and processing time increase
Solution Approach 1:
The patent introduces a cloud-based intermediary service that handles the computationally intensive encryption and attribute access control operations. The IoT device offloads these cryptographic operations to the cloud intermediary, which manages the encryption mechanisms and attribute access policies. This resolves the contradiction by moving the security processing from the resource-constrained IoT device to a more powerful intermediary system, maintaining strong security while reducing local processing time and energy consumption.
2Reliability
If cryptographic operations are performed on IoT devices, then data security is improved, but device complexity and energy consumption increase
Solution Approach 1:
The cloud-based intermediary acts as a mediator that performs cryptographic operations on behalf of IoT devices. The intermediary manages key storage, encryption/decryption operations, and attribute-based access control, allowing IoT devices to maintain security without bearing the computational burden. This energy-intensive security processing is shifted from battery-powered IoT devices to the cloud infrastructure, significantly reducing device energy consumption while maintaining strong security guarantees.
3Adaptability or versatility
If selective sharing of data attributes is implemented, then data control and security are improved, but device complexity increases
Solution Approach 1:
The patent implements attribute-based access control where the cloud intermediary manages complex data attribute policies and selective sharing rules. The intermediary service handles the complexity of defining, storing, and evaluating access policies for different data attributes, while IoT devices simply interact with the simplified interface. This allows fine-grained control over which data attributes are shared with which entities without burdening the IoT device with complex policy management logic.
4Reliability
If cloud-based intermediary is used for data exchange, then data security and controlled sharing are improved, but network dependency and latency increase
Solution Approach 1:
The system performs preliminary actions by pre-establishing security credentials, encryption keys, and access policies in the cloud intermediary before actual data exchange occurs. The intermediary pre-configures the security framework and attribute access controls, so that during runtime, data exchange can proceed more efficiently with minimal cryptographic overhead. This preliminary setup reduces latency during actual data transactions while maintaining strong security guarantees.
Data Source
AI summary
In one embodiment, a device in a network receives sensor data from one or more nodes in the network. The device selects a processing mode from among a plurality of processing modes based on a plurality of attributes of the sensor data. The plurality of processing modes comprises a fast data path mode and a slow data path mode. The device encrypts the sensor data using a first encryption mechanism that controls access to the plurality of attributes of the sensor data. The device sends the encrypted sensor data to a cloud-based intermediary based on the selected processing mode for sharing with one or more other devices in one or more other networks.


