Security Controller for IoT Access Control via Gateway

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing number of Internet of Things (IoT) devices with limited security capabilities makes them vulnerable to malicious attacks, as they often have inadequate authorization, authentication, and encryption, leading to potential unauthorized access and control.

Innovation Solution

A security controller establishes an authenticated communication channel with home gateway devices to manage access to IoT devices by installing access control directives, such as access control lists, based on manufacturer usage descriptions, ensuring only authorized IoT device controllers can access and manage these devices, even when their network addresses are dynamic or unknown.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If special purpose network connected devices are deployed to expand IoT functionality, then device versatility and network coverage are improved, but security vulnerability and susceptibility to malicious attacks increase due to limited security capabilities

Engineering Contradiction:
Improvedevice versatilityVSAvoidsecurity capability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a gateway device as an intermediary between the external network and special purpose IoT devices. The gateway performs authentication, authorization, and security functions that the resource-constrained IoT devices cannot handle independently. This mediator approach allows versatile IoT deployment while centralizing security capabilities in the gateway, resolving the contradiction between device versatility and security reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If access control directives are implemented to secure IoT devices, then security protection is improved, but system complexity increases due to authentication and authorization mechanisms

Engineering Contradiction:
Improvesecurity protectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The gateway acts as a security intermediary that handles complex authentication and authorization protocols, preventing these complexity-inducing mechanisms from being implemented in the simple IoT devices themselves. The gateway manages access control directives and security policies centrally, providing robust security protection while keeping individual IoT devices simple and easy to deploy.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If comprehensive access control is implemented to prevent unauthorized access, then security protection is improved, but ease of operation deteriorates due to restricted device accessibility

Engineering Contradiction:
Improvesecurity protectionVSAvoiddevice accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system implements feedback mechanisms where the gateway continuously monitors access requests, device states, and security policies. Based on this feedback, the gateway dynamically adjusts access control decisions, allowing legitimate operations to proceed smoothly while blocking unauthorized access. This feedback-driven approach maintains security protection while ensuring ease of operation for authorized users through automated access management.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10778775B2Control of network connected devices
Publication Date: 2020.09.15 CISCO TECHNOLOGY INC
  • US10778775B2 patent drawing
  • US10778775B2 patent drawing
  • US10778775B2 patent drawing

AI summary

Presented herein are techniques in which one or more network devices can use information provided by a special purpose network connected device to retrieve a usage profile (i.e., configuration file) associated with the special purpose network connected device. The retrieved usage profile, which includes/describes preselected (predetermined) usage descriptions associated with the special purpose network connected device, can then be used to configure one or more network devices. For example, the predetermined usage descriptions associated with the special purpose network connected device can be instantiated and enforced at a network device or the predetermined usage descriptions can be used for auditing the special purpose network connected device (e.g., monitoring of traffic within the network).