Machine-To-Machine Gateway Architecture

US2018014192A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2018014192-A1
Application numberUS-201715699843-A
CountryUS
Kind codeA1
Filing dateSep 8, 2017
Priority dateDec 28, 2009
Publication dateJan 11, 2018
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Systems, methods, and instrumentalities are disclosed that provide for a gateway outside of a network domain to provide services to a plurality of devices. For example, the gateway may act as a management entity or as a proxy for the network domain. As a management entity, the gateway may perform a security function relating to each of the plurality of devices. The gateway may perform the security function without the network domain participating or having knowledge of the particular devices. As a proxy for the network, the gateway may receive a command from the network domain to perform a security function relating to each of a plurality of devices. The network may know the identity of each of the plurality of devices. The gateway may perform the security function for each of the plurality of devices and aggregate related information before sending the information to the network domain.

First claim

Opening claim text (preview).

1 . In a system comprising a network domain that is capable of providing one or more service capabilities to a plurality of devices in communication with the network domain, a method of offloading certain functionality of the network domain to an entity outside of the network domain, the method comprising, by the entity: establishing trust with the network domain; establishing a connection with each of the plurality of devices; performing a security function for each of the plurality of devices; and reporting information to the network domain relating to each of the plurality of devices. 2 . The method of claim 1 , wherein the information is aggregated from each of the plurality of devices. 3 . The method of claim 1 , wherein aggregated security functions are parsed and performed for each of the plurality of devices. 4 . The method of claim 1 , wherein the reporting is in response to a request from the network domain. 5 . The method of claim 4 , wherein the network domain is unaware of an identity of each of the plurality of devices. 6 . The method of claim 1 , wherein the reporting is performed periodically. 7 . The method of claim 1 , wherein the security function comprises registering and authenticating each of the plurality of devices with the network domain. 8 . The method of claim 7 , wherein the registering and authenticating includes using a bootstrapped credential. 9 . The method of claim 1 , wherein the security function comprises provisioning and migration of credentials to each of the plurality of devices. 10 . The method of claim 1 , wherein the security function comprises provisioning of security policies to each of the plurality of devices. 11 . The method of claim 1 , wherein the security function comprises establishing a trustworthy functionality in each of the plurality of devices, wherein an integrity validation for each of the plurality of devices is performed. 12 . The method of claim 1 , wherein the security function comprises providing device management for each of the plurality of devices. 13 . The method of claim 12 , wherein a critical failure alarm associated with at least one of the plurality of devices is sent to the network domain. 14 . The method of claim 1 , wherein the security function comprises establishing, for at least one of the plurality of devices, at least one of: a security association, a communication channel, or a communication link. 15 . The method of claim 1 , further comprising: determining an integrity breach or failure associated with one or more of the plurality of devices; and quarantining the one or more of the plurality of devices. 16 . The method of claim 1 , wherein the security function is performed on behalf of the network domain without network domain participation. 17 . In a system comprising a network domain that is capable of providing one or more service capabilities to a plurality of devices in communication with the network domain, a method of offloading certain functionality of the network domain to an entity outside of the network domain, the method comprising, by the entity: establishing trust with the network domain; receiving a command from the network domain to perform a security function relating to each of the plurality of devices; performing the security function for each of the plurality of devices; aggregating information from each of the plurality of devices relating to the performed security function; and sending the aggregated information to the network domain. 18 . The method of claim 17 , wherein the security function comprises registering and authenticating each of the plurality of devices with the network domain. 19 . The method of claim 18 , wherein the registering and authenticating includes using a bootstrapped credential. 20 . The method of claim 17 , wherein the security function comprises provisioning and migration of credentials to each of the plurality of devices. 21 .- 26 . (canceled)

Assignees

Inventors

Classifications

  • Services specially adapted for wireless communication networks; Facilities therefor · CPC title

  • H04W12/06Primary

    Authentication · CPC title

  • Access security · CPC title

  • Services for machine-to-machine communication [M2M] or machine type communication [MTC] · CPC title

  • Integrity · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2018014192A1 cover?
Systems, methods, and instrumentalities are disclosed that provide for a gateway outside of a network domain to provide services to a plurality of devices. For example, the gateway may act as a management entity or as a proxy for the network domain. As a management entity, the gateway may perform a security function relating to each of the plurality of devices. The gateway may perform the secur…
Who is the assignee on this patent?
Interdigital Patent Holdings Inc
What technology area does this patent fall under?
Primary CPC classification H04W12/06. Mapped technology areas include Electricity.
When was this patent published?
Publication date Thu Jan 11 2018 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).