Secure Tunnel Proxy for IoT Data Integrity and Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Navigating the vast and complex world of data management from Internet of Things (IoT) devices is daunting due to challenges in ensuring data security and integrity, particularly in large network environments where unauthorized access and data breaches can compromise confidentiality and integrity.

Innovation Solution

Implementing a secure tunnel proxy with a software-defined perimeter for network data transfer, which includes configuring a secure tunnel between IoT sensors and edge computing devices using cryptographic keys and dynamic port assignments to ensure encryption, authentication, and integrity checks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data is transmitted directly between IoT devices and edge computing devices without a secure tunnel proxy, then network communication efficiency is maintained, but data security and integrity are compromised due to unauthorized access risks

Engineering Contradiction:
Improvedata securityVSAvoidnetwork architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A secure tunnel proxy is introduced as an intermediary component between IoT devices and edge computing devices. The proxy establishes encrypted tunnel connections, manages authentication, and filters traffic, thereby providing security without requiring complex changes to the underlying IoT device architecture. The proxy acts as a dedicated security layer that handles cryptographic operations and access control policies.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The network architecture is segmented into distinct functional layers: IoT device layer, secure tunnel proxy layer, and edge computing device layer. This segmentation isolates security-critical functions in the proxy layer, allowing IoT devices to maintain simple communication protocols while the proxy handles encryption, authentication, and security policy enforcement separately.

Inventive Principle:
Principle #1Segmentation

2Reliability

If traditional data transmission methods are used between IoT sensors and edge computing devices, then implementation simplicity is maintained, but data integrity and confidentiality are compromised in large network environments

Engineering Contradiction:
Improvedata integrityVSAvoidsystem implementation ease
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

Security measures are implemented preliminarily through the tunnel proxy before data reaches the edge computing devices. The proxy pre-establishes encrypted channels, performs authentication, and validates data integrity using cryptographic signatures. This preliminary security processing prevents the need for complex security implementations at each IoT device and edge device endpoint.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The secure tunnel proxy serves as a dedicated intermediary that implements security protocols, thereby simplifying the overall system implementation. Instead of requiring each IoT device and edge device to implement full security stacks, the centralized proxy handles encryption, decryption, authentication, and integrity verification, reducing implementation complexity at the endpoints.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If secure encryption protocols are implemented for all data transmissions, then data confidentiality is improved, but computing resource consumption increases

Engineering Contradiction:
Improvedata confidentialityVSAvoidcomputing resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The secure tunnel proxy acts as a dedicated intermediary that performs all computationally intensive cryptographic operations. The proxy handles key management, encryption, decryption, and authentication, thereby offloading these resource-intensive tasks from battery-constrained IoT devices and edge computing devices. This concentration of cryptographic processing in the proxy minimizes energy consumption across the distributed system.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The tunnel proxy implements self-service security mechanisms including automatic key generation, certificate management, and session establishment. By automating these security functions at the proxy level, the system reduces the computational burden on IoT devices and edge devices, allowing them to focus on their primary functions with minimal security-related resource consumption.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12598162B2Secure tunnel proxy with software-defined perimeter for network data transfer
Publication Date: 2026.04.07 BANK OF AMERICA CORP
  • US12598162B2 patent drawing
  • US12598162B2 patent drawing
  • US12598162B2 patent drawing

AI summary

Systems, computer program products, and methods are described herein for a secure tunnel proxy with software-defined perimeter for network data transfer. The present disclosure is configured to receive sensor configuration information associated with an Internet of Things (IoT) sensor; receive information associated with an edge computing device configured to receive sensor data from the IoT sensor; configure a secure tunnel proxy between the IoT sensor and the edge computing device based on at least the sensor configuration information and the information associated with the edge computing device; and deploy the secure tunnel proxy between the IoT sensor and the edge computing device.