Smart Device Network Security Gatekeeper for Data Arbitration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Smart home devices connected to the internet pose security concerns due to multiple data connections, which can lead to the disclosure of personal information to unauthorized parties.
Innovation Solution
A system that acts as a conduit or gatekeeper for data transfer between smart home devices and external networks, implementing a security paradigm with two layers: hiding internal device identifiers and controlling network connections through markers and user plane functions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If smart appliances are connected to the network with multiple data connections, then network functionality and service capability are improved, but security risk and information disclosure risk increase
Solution Approach 1:
The patent introduces a security device as an intermediary component between smart appliances and the network. This security device monitors and controls data connections, acting as a gatekeeper that allows legitimate network functionality while blocking malicious access. The security device implements the marker mechanism and user plane function allocation to enforce security policies without preventing normal network operations.
Solution Approach 2:
The patent segments the network architecture by introducing distinct security layers and functions. The system divides network operations into controlled segments: marker-based identification layers, user plane function allocation layers, and security policy enforcement layers. This segmentation allows the system to maintain multiple data connections for functionality while applying security controls at each segment to mitigate risks.
2Object-affected harmful factors
If internal device identifiers are hidden, then security against malicious actors is improved, but device identification and network management become more difficult
Solution Approach 1:
The security device serves as an intermediary that manages device identification. It maintains internal device identifiers securely while providing external identification through markers. The security device translates between internal hidden identifiers and external marker-based identification, allowing network management without exposing sensitive device identities to potential attackers.
Solution Approach 2:
The patent uses markers as copies or representations of internal device identifiers. Instead of exposing the actual device identifiers, the system creates marker copies that serve external identification and management purposes. These markers are visible to the network but do not reveal the true device identity, thus maintaining security while enabling network management.
3Loss of information
If network connections are controlled through markers and user plane functions, then data disclosure is prevented, but network connection establishment becomes more complex
Solution Approach 1:
The security device implements self-service mechanisms by automatically allocating user plane functions and managing marker-based connections based on pre-configured security policies. The system does not require manual intervention for each connection decision; instead, it autonomously evaluates connection requests against security policies and enforces appropriate controls, reducing the perceived complexity for users while maintaining strong security.
Solution Approach 2:
The patent implements preliminary action by pre-configuring security policies and marker associations before network operations begin. The system establishes security frameworks, marker schemas, and user plane function allocation rules in advance. This preliminary setup allows the complex connection control to operate automatically without requiring complex real-time decisions, simplifying the operational complexity while maintaining security.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Aspects of the disclosure provide for a method implemented by a smart device executing an artificial intelligence electronic assistant application. In at least some examples, the method includes receiving a request from an appliance in a same local network as the smart device, the request to transfer first data from the appliance to a first device located outside the local network. The method also includes facilitating the transfer of the first data from the appliance to the first device based at least in part on security policies of the smart device and content of the first data.