Network Socket Proxying for Secure IoT Communication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current IoT device security management is inefficient due to the need for direct interaction and frequent updates, leading to increased costs and vulnerability to attacks, as security protocols are integrated into firmware and applications, making it difficult to maintain security without affecting the entire system.

Innovation Solution

A communication method and system that delegate security functionalities to independent software modules, using proxies and security contexts to restrict access, allowing for updates without affecting other software, enabling secure communication and simplifying maintenance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security protocols are integrated into firmware and applications, then cryptographic protection is provided, but updates require modification of the entire application and firmware

Engineering Contradiction:
Improvesecurity protectionVSAvoidsoftware update complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments security functionality into independent proxy components that operate separately from the main application and firmware. The proxy acts as an intermediary layer that handles security protocols independently, allowing security updates without modifying the core application or firmware, thus resolving the contradiction between maintaining security protection and reducing update complexity

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a proxy as an intermediary component between the application and the network. This proxy handles all security-related operations (TLS/SSL encryption, authentication) independently, allowing the main application to remain unchanged during security updates. The intermediary proxy absorbs the complexity of security maintenance while preserving the simplicity of the core application

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If direct interaction between devices and network operator is used, then security management is simplified, but scalability is limited

Engineering Contradiction:
Improvesecurity managementVSAvoidscalability
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent introduces automated proxy components as intermediaries between devices and the network operator. These proxies handle security management tasks automatically without requiring direct human intervention, maintaining ease of operation while enabling scalable deployment across large numbers of devices. The intermediary layer abstracts security management complexity while supporting system growth

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If security protocols are embedded in applications, then communication security is ensured, but maintenance costs increase over time

Engineering Contradiction:
Improvecommunication securityVSAvoidmaintenance cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent segments security functionality into independent proxy components that can be updated and maintained separately from the main application. This segmentation allows security protocols to be refreshed without requiring application rewrites or firmware updates, significantly reducing long-term maintenance costs while preserving communication security

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The proxy components are designed to self-manage security configurations and automatically update security protocols without requiring application modifications. This self-service capability reduces maintenance burden and costs over time while maintaining robust security protection

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3800564B1Secure communication method and system using network socket proxying
Publication Date: 2023.06.21 DE HOZ DIEGO JORGE DAVID
  • EP3800564B1 patent drawingFigure 1
  • EP3800564B1 patent drawingFigure 2
  • EP3800564B1 patent drawingFigure 3

AI summary

The present invention relates to the telecommunications sector and, in particular, to the field of telematics. More specifically, the invention describes a method and system for defining an improved network technology that can be used for communication and to operate secure communications between processes, based on the secure proxying of local area network sockets that may be between different devices. In particular, the system and method describe how socket proxies are established and managed between devices and how the security of said socket proxies in the local area thereof is enhanced and operated using security contexts. These contexts are configured based on privilege separation and local packet marking and filtering, and they allow applications to delegate all aspects relating to the security of the communications in the present invention.