OPTIMIZING THE SECURITY OF INTERNET OF THINGS DEVICES
By dynamically adjusting the security level of IoT devices based on content sensitivity, the method optimizes security processing and reduces power consumption, addressing the overload issues in existing encryption methods.
Patent Information
- Application Number
- DE112023003296
- Authority / Receiving Office
- DE · DE
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2022-08-01
- Filing Date
- 2023-07-31
- Publication Date
- 2025-06-26
AI Technical Summary
The existing methods for securing data in IoT devices through encryption and decryption can overload these devices, particularly due to the exponential increase in IoT devices and the comprehensive data flow in IoT networks, leading to higher power consumption and reduced data processing capacity.
A method that dynamically adjusts the security level of IoT devices based on the sensitivity of the content being transferred, reducing the security processing overhead for non-critical data and maintaining high security levels for critical data.
This approach reduces the additional cost for security processing by tailoring the security level to the actual content being processed, thereby optimizing the security and performance of IoT devices.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
BACKGROUND
[0001] The present disclosure relates generally to the field of Internet of Things (IoT) security and, more particularly, to automatic optimization of the security of IoT devices.
[0002] With the development of cloud infrastructure as a universal platform for running systems in central locations, the number of end devices around the world has increased exponentially. There are now more IoT devices than people in the world, and this is made possible because all devices are connected in one way or another via the IoT network. Given such a massive amount of data flowing through the IoT network, security understandably takes on paramount importance. The general approach to solving such security problems is to use encryption and decryption of stored and flowing data. However, the use of encryption and decryption algorithms in IoT devices to secure the data can overload the IoT devices. SUMMARY
[0003] Embodiments of the present disclosure include a method, computer program product, and system for optimal security of IoT devices. A processor may determine that content is being generated for data transmission between IoT devices. The processor may identify a source device and a destination device of the IoT devices. The processor may analyze the content. The processor may determine a sensitivity of the content. The processor may assign a security level to either the source device or the destination device based on the determination.
[0004] The above summary is not intended to describe every illustrated embodiment or every implementation of the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS
[0005] The drawings included in this disclosure are incorporated in and constitute a part of the specification. They illustrate embodiments of the present disclosure and, in addition to the description, serve to explain the principles of the disclosure. The drawings are merely illustrative of certain embodiments and are not limitative of the disclosure. Fig. 1 illustrates a block diagram of an example system for optimal security of IoT devices according to aspects of the present disclosure. Fig. 2 illustrates a flowchart of an example method for optimal security of IoT devices according to aspects of the present disclosure. Fig. 3A illustrates a cloud computing environment according to aspects of the present disclosure. Fig. 3B illustrates abstraction model layers according to aspects of the present disclosure. Fig. 4 illustrates a high-level block diagram of an example computer system that may be used to implement one or more of the methods, tools, and modules described herein, as well as any related functionality described herein, in accordance with aspects of the present disclosure.
[0006] While the embodiments described herein are susceptible to various modifications and alternative forms, specifics thereof have been shown by way of example in the drawings and will be described in detail. It is to be understood, however, that the specific embodiments described are not to be considered in a limiting sense. Rather, the intention is to cover all modifications, equivalents, and alternatives falling within the spirit and scope of the disclosure. DETAILED DESCRIPTION
[0007] Aspects of the present disclosure generally relate to the field of Internet of Things (IoT) security, and more particularly to automatic optimization of the security of IoT devices. While the present disclosure is not necessarily limited to such applications, various aspects of the disclosure can be better appreciated when discussing the various examples in this context.
[0008] With the development of cloud infrastructure as a universal platform for running systems in central locations, the number of end devices worldwide has increased exponentially. There are now more IoT devices than people in the world, and this is made possible because all devices are connected in one way or another via the IoT network. Given such a massive amount of data flowing through the IoT network, security understandably takes on paramount importance. The general approach to solving such security problems is to use encryption and decryption of stored and flowing data. However, the use of encryption and decryption algorithms in IoT devices to secure the data can overload the IoT devices.For example, a variety of security techniques have currently been applied to gain users' trust in storing (networked) data at a remote location, ultimately causing an overload of security / encryption processing for each bit of data in a data processing system (e.g., a source device and / or destination device).
[0009] As devices become smaller, data processing capacity and energy consumption will become critical in the future. For example, each smartphone consumes a significant amount of energy simply to encrypt and decrypt each bit of data. These smartphones are generally much smaller than the devices that send data on a network. As explained in this disclosure, there is therefore much data that actually does not require as much security processing or additional security overhead.
[0010] Because there is no dynamic nature of accessing any level of security for any content, general or universal security application rules impose additional overhead on any processing required to secure a system. For example, if a smartphone accesses a publicly available website, such as one with news or weather information, the smartphone does not need to encrypt or decrypt every bit associated with the news or weather website during loading, even though the smartphone must be secured.
[0011] In the context of this example, it should be noted that smartphones and IoT devices generally have the following inherited limitations: less available computing / CPU and less available power / energy. This, in turn, leads to higher energy consumption and CPU utilization during encryption / decryption, further reducing the overall computing capacity of IoT devices.
[0012] In a group of IoT devices at work or at home, there can be a large amount of complex, meshed data transfer between devices and numerous data transmissions. This makes it extremely important to determine which of the data transfers between IoT devices must be secure.
[0013] Therefore, a solution is disclosed herein that reduces the overhead for security processing based on the actual content to be processed by an IoT device. When content is critical, the security level must be maintained, but when this is not required, the system reduces the security level while dynamically processing the content / data. Instead of a consistently high security level throughout an entire system for each bit of data for transmission or storage, a solution is thus disclosed for a system (or systems) that can adapt the security level based on the content to be processed within or beyond a network.
[0014] This solution includes, but is not limited to: dynamically detecting the security level of the content for IoT devices, where the content consists of data that needs to be sent / received and where the content flows through a data transmission channel; applying the security level based on a detection of the content sensitivity (e.g., the sensitivity of the content) (e.g., medical information has a higher sensitivity and thus a higher security level than a general text message, etc.); and automatically detecting the security level of data, where the security is based on organized / identified parameters (e.g., calibrated data / a calibrated database). If a parameter has an expected value, device algorithm, etc., the solution assumes, in some embodiments, that sensitive data is being transmitted.Whenever the solution detects a sensitive data flow, it triggers the flow to improve security.
[0015] Simply put, the solution discussed herein is a method, system, and / or computer program product that provides dynamic security levels to IoT devices based on the sensitive nature of the data generated in, captured in, or transmitted to or from the IoT devices. In some embodiments, the dynamic security levels of the IoT device may be based on: the geographic location (e.g., a public cafe, a processing plant, etc.), the source of the data / content (e.g., IoT devices identified as sensitive by the device manufacturer, etc.), the destination of the data (e.g., the IoT device to which data was sent was identified as sensitive by the device manufacturer, etc.), and / or the type of IoT device (e.g., a video surveillance device would be considered more sensitive by nature than a temperature measurement device, etc.).
[0016] As a more detailed example of the solution disclosed herein, we shall now assume: Unit 1 (D1) → is an IoT unit in a network, Unit 2 (D2) → is another loT unit in a network, Unit N (Dn) → represents the nth loT unit in the network, Data transfer link (Li) → represents the data transfer between two IoT units, and Dn - 1 ← Li → Dn = represents the link between the nth loT unit and the (n - 1)th loT unit.
[0017] The solution can thus: analyze the data generated in the unit Dn and determine the security level of the generated PII / SPI data (personally identifiable data / sensitive personal data) (w1), determine / identify the ability of an IoT unit to control or operate other IoT units (w2), determine / identify the ability of an IoT unit to influence the overall system (w3) (e.g. temperature control of IoT units in a power plant or gas control unit in a chemical plant, etc.) and Based on the detection / identification, calculate the security level (SL) for the entity Dn. The security level can be a value between 1 and 5, where 1 represents the least sensitive data generation and 5 represents the most sensitive. The security level can be defined as SL = f(w1, w2, w3).
[0018] In some embodiments, the solution may further: calculate the SL for each device in the network, rank the IoT devices based on the calculated SL, and calculate the SLs for the data link (Li) between all devices.
[0019] In some embodiments, calculating the security level for the data transmission link(s) may include the solution receiving / retrieving the security levels for both or all entities involved in the data transmission (e.g., SLn, SLn + 1). The solution may further determine / identify the average of both security levels and assign the average security level to the data transmission link (e.g., Li SL = average of [Unit 1 SL, Unit 2 SL]). In some embodiments, the solution may calculate the security levels for all data transmission links in the network. It is noted that the proposed solution may include an opt-in feature to which a user may consent to allow the solution to analyze the content / data, the entities, and / or the data transmission link(s).
[0020] In some embodiments, the proposed solution may include a ranking function used to determine the security level for a content based on the content sensitivity, where the ranking function is: R(Li)=∑i=1nV(p)∗W(p)n where Li is the loT unit for which the risk rank is calculated; p is the parameter for calculating the rank; V is the value of the parameter; W is the weighting that determines which parameters are important for calculating the risk rank; and n is the total number of parameters.
[0021] In some embodiments, parameters that determine what is sensitive about the data collected by IoT devices are: privacy data, personal data, manufacturer labels (as discussed above), health data, location data, etc.
[0022] In some embodiments, the proposed solution may include a threshold function used to determine whether a security level should be dynamically increased, where the threshold function is: TI=∑i=1nR(Li)n where R(Li) is the security risk rank for the IoT unit D(i); and n is the total number of IoT units.
[0023] If the IoT device generates the PII / SPI data, the proposed solution assigns a higher weight to the device. Additionally, the proposed solution assigns a higher weight to the data transmission link (Li) if the data transmission device accepts any type of PII / SPI data.
[0024] With reference to Fig. 1, a block diagram of an example system 100 for optimal security of IoT devices according to aspects of the present disclosure is illustrated.
[0025] As shown, the system 100 includes a data transmission channel 102, a content 104, a dynamic security adjuster 106, a source device analyzer 108, a destination device analyzer 110, a content analyzer 112, a decision engine 114, a security level identifier 116, an encryption applicator 118, and a calibrated database 120.
[0026] In some embodiments, content 104 is received by system 100 over communications channel 102, and content 104 is identified from a data transmission (not shown) in communications channel 102. System 100 then uses dynamic security adaptor 106 to analyze content 104. Dynamic security adaptor 106 processes content 104 (or data transmission) through source device analyzer 108, destination device analyzer 110, and content analyzer 112, respectively, which assign a rank or weight to the sensitive nature of content 104.
[0027] The rank or weight of the sensitive nature of the content 104 is then sent from the source entity analyzer 108, the destination entity analyzer 110, and the content analyzer 112 to the decision engine 114, which may compare the rank or weight to calibrated data in the calibrated database 120, where the calibrated data includes a predefined list of sensitivity / security levels associated with a specific piece of content.
[0028] In some embodiments, the decision engine 114 provides a decision regarding the sensitivity of the content 104 to the security level identifier 116, which may provide a security level associated with the sensitivity. The security level identifier 116 then provides the security level to the encryption practitioner 118, which then applies an encryption algorithm (e.g., SHA-256, etc.) or scheme (push notifications, etc.) to a source device and / or a destination device (not shown).
[0029] With reference to Fig. 2, a flowchart of an example method 200 for optimal security of IoT devices according to aspects of the present disclosure is illustrated. In some embodiments, the method 200 may be performed by a processor (e.g., of the system 100 of Fig. 1 etc.) can be carried out.
[0030] In some embodiments, method 200 begins with an operation 202 in which the processor may determine that content is being generated for a data transfer between IoT devices. Note that a data transfer may be a message between devices, and content may be the sentiment or context of the data transfer.
[0031] In some embodiments, the method 200 may continue with an operation 204, in which the processor may identify a source device and a destination device of the IoT devices. In some embodiments, the method 200 may continue with an operation 206, in which the processor may analyze the content.
[0032] In some embodiments, the method 200 may continue with an operation 208, in which the processor may determine a sensitivity of the content. In some embodiments, the method 200 may continue with an operation 210, in which the processor may assign a security level to either the source device or the destination device based on the determination. In some embodiments, the method 200 may end after operation 210.
[0033] In some embodiments discussed below, one or more operations of method 200 discussed in this disclosure are not shown for brevity. Accordingly, in some embodiments, determining the sensitivity of the content may include the processor analyzing a calibrated database, where the calibrated database may include pre-populated data indicating sensitivity based on the content type (e.g., personal information, location data, etc.).
[0034] In some embodiments, the calibrated database may further include an indication of the security level associated with the sensitivity (e.g., personal data = high security level, entity name = lower security level, etc.).
[0035] In some embodiments, assigning the security level to either the source device or the destination device may include the processor identifying a predefined security level for the source device. The processor may further identify a predefined security level for the destination device and generate a medium security level for the assignment. In some embodiments, the medium security level may be a combination of the predefined security levels for the source device and the destination device (or all devices within a data transmission link, or all devices within all data transmission links of a network).
[0036] In some embodiments, the processor may apply data transmission encryption based on the assigned security level. In some embodiments, applying data transmission encryption may include the processor identifying which type of device the source device and the destination device are, respectively, and enhancing the data transmission encryption based on the type (e.g., by dynamically changing the security level or encryption based on a manufacturer's recommendation, etc.).
[0037] In some embodiments, the processor may further continuously analyze the content for changes in sensitivity and automatically update the security level.
[0038] It should be understood that, although this disclosure contains a detailed description of cloud computing, implementation of the teachings herein is not limited to a cloud computing environment. Rather, embodiments of the present disclosure may be implemented in conjunction with any type of computing environment now known or later developed.
[0039] Cloud computing is a service delivery model for enabling seamless, on-demand network access to a shared pool of configurable computing resources (e.g., networks, network bandwidth, servers, processing, memory, storage, applications, virtual machines, and services) that can be rapidly provisioned and released with minimal management effort or interaction with a service provider. This cloud model can include at least five characteristics, at least three service models, and at least four deployment models.
[0040] The properties are as follows: On-Demand Self-Service: A cloud user can unilaterally and automatically provision computing capabilities such as server time and network storage as needed, without requiring human interaction with the service provider. Broad Network Access: Capabilities are available over a network and accessed through standard mechanisms that support use by heterogeneous thin or thick client platforms (e.g., mobile phones, laptops, and PDAs). Resource Pooling: The provider's computing resources are pooled to serve multiple users using a multi-tenant model, with various physical and virtual resources dynamically allocated and reassigned as needed. There is a perceived partial independence, as the user generally has no control or knowledge over the exact portion of the resources provided, but may be able to specify a portion at a higher level of abstraction (e.g., country, state, or data center). Rapid Elasticity: Capabilities can be provisioned quickly and elastically for rapid horizontal scaling out, in some cases automatically, and released quickly for rapid scaling in. To the user, the capabilities available for provisioning often appear unlimited, and they can be purchased in any quantity at any time. Measured Service: Cloud systems automatically control and optimize resource usage by leveraging measurement capabilities at a certain level of abstraction appropriate to the type of service (e.g., storage, processing, bandwidth, and active user accounts). Resource consumption can be monitored, controlled, and reported, providing transparency for both the provider and the user of the service.
[0041] The service models are as follows: Software as a Service (SaaS): The ability provided to the user is to use the provider's applications running on a cloud infrastructure. The applications are accessible from various client devices via a thin client interface such as a web browser (e.g., web-based email). The user does not manage or control the underlying cloud infrastructure, including the network, servers, operating systems, storage, or even individual application capabilities, with the possible exception of limited user-specific application configuration settings. Platform as a Service (PaaS): The ability provided to the user is to deploy applications created or obtained by the user, using programming languages and tools supported by the provider, on the cloud infrastructure. The user does not manage or control the underlying cloud infrastructure, including networks, servers, operating systems, or storage, but has control over the deployed applications and possibly configurations for the application hosting environment. Infrastructure as a Service (IaaS): The capability provided to the user consists of providing processing, storage, networking, and other basic computing resources, allowing the user to deploy and run any software, including operating systems and applications. The user does not manage or control the underlying cloud infrastructure, but has control over operating systems, storage, deployed applications, and possibly limited control over selected network components (e.g., host firewalls).
[0042] The deployment models are as follows: Private Cloud: The cloud infrastructure is operated solely for an organization. It can be managed by the organization or a third party and can be located on its own premises or on third-party premises. Community Cloud: The cloud infrastructure is shared by multiple organizations and supports a specific user community with common objectives (e.g., objectives, security requirements, policies, and compliance considerations). It can be managed by the organizations or a third party and can be located on-premises or on shared premises. Public Cloud: The cloud infrastructure is made available to the general public or a large industry group and is owned by an organization that sells cloud services. Hybrid Cloud: The cloud infrastructure is a composition of two or more clouds (private, community or public) that remain separate entities but are connected by a standardized or proprietary technology that enables data and application portability (e.g. cloud target distribution for load balancing between clouds). A cloud computing environment is service-oriented with a focus on statelessness, low coupling, modularity, and semantic interoperability. At the heart of cloud computing is an infrastructure that contains a network of interconnected nodes.
[0043] In Fig. 3A illustrates a cloud computing environment 310. As shown, the cloud computing environment 310 includes one or more cloud computing nodes 300 with which local computing devices used by cloud users, such as a personal digital assistant (PDA) or mobile phone 300A, a desktop computer 300B, a laptop computer 300C, and / or an automotive computer system 300N, can communicate. The nodes 300 can communicate with each other. They can be physically or virtually grouped together in one or more networks such as private, community, public, or hybrid clouds (not shown), as described above, or in a combination thereof.
[0044] This allows the cloud computing environment 310 to offer infrastructure, platforms, and / or software as services for which a cloud user does not need to maintain resources on a local computing device. It should be noted that the types of Fig. 3A are intended to be merely illustrative and that the computing nodes 300 and the cloud computing environment 310 may communicate with any type of computer-based device via any type of network and / or via any type of network-accessible connection (e.g., using a web browser).
[0045] In Fig. 3B illustrates a set of functional abstraction layers provided by the cloud computing environment 310 ( Fig. 3A). It should be clear from the outset that the Fig. 3B are intended to be illustrative only, and embodiments of the disclosure are not limited thereto. As further illustrated below, the following layers and corresponding functions are provided.
[0046] A hardware and software layer 315 includes hardware and software components. Examples of hardware components include: mainframe computers 302; Reduced Instruction Set Computer (RISC)-based servers 304; servers 306; blade servers 308; storage devices 311; and networks and network components 312. In some embodiments, software components include network application server software 314 and database software 316.
[0047] A virtualization layer 320 provides an abstraction layer from which the following examples of virtual entities may be provided: virtual servers 322, virtual storage 324, virtual networks 326, including virtual private networks; virtual applications and operating systems 328; and virtual clients 330.
[0048] In one example, a management layer 340 may provide the functions described below. Resource provisioning 342 provides for the dynamic procurement of computing resources and other resources used to perform tasks within the cloud computing environment. Metering and pricing 344 provides cost tracking for using resources within the cloud computing environment, as well as billing or invoicing for the consumption of those resources. In one example, these resources may include application software licenses. Security provides identity verification for cloud users and tasks, as well as protection for data and other resources. A user portal 346 provides users and system administrators with access to the cloud computing environment.Service level management 348 provides for the allocation and management of cloud computing resources so that required service objectives are met. Service level agreement (SLA) planning and fulfillment 350 provides for the pre-ordering and procurement of cloud computing resources for which future demand is anticipated, in accordance with an SLA.
[0049] A workload layer 360 provides examples of the functionality for which the cloud computing environment can be used. Examples of workloads and functions that can be provided by this layer include: mapping and navigation 362; software development and lifecycle management 364; virtual training delivery 366; data analytics processing 368; transaction processing 370; and IoT device security optimization 372.
[0050] In Fig. 4 illustrates a high-level block diagram of an example computer system 401 that may be used to implement one or more of the methods, tools, and modules described herein, as well as any related functionality (e.g., using one or more processor circuits or computer processors of the computer), in accordance with embodiments of the present disclosure. In some embodiments, computer system 401 may include one or more CPUs 402, a memory subsystem 404, a terminal interface 412, a storage interface 416, an I / O (input / output) device interface 414, and a network interface 418, all of which may be directly or indirectly interconnected for intercomponent data transfer via a memory bus 403, an I / O bus 408, and an I / O bus interface device 410.
[0051] Computer system 401 may include one or more general-purpose central processing units (CPUs) 402A, 402B, 402C, and 402D, referred to herein generically as CPU 402. In some embodiments, computer system 401 may include multiple processors, typical of a relatively large system; however, in other embodiments, computer system 401 may alternatively be a single-CPU system. Each CPU 402 may execute instructions stored in memory subsystem 404 and may include one or more levels of integrated cache.
[0052] System memory 404 may include a computer system-readable medium in the form of volatile memory, such as random access memory (RAM) 422 or cache memory 424. Computer system 401 may further include other removable / non-removable, volatile / non-volatile computer system storage media. By way of example only, a storage system 426 may be provided for reading from and writing to a non-removable, non-volatile magnetic medium, such as a "hard disk." Although not shown herein, a magnetic disk drive may be provided for reading from and writing to a removable, non-volatile magnetic disk (e.g., a "floppy disk"), and an optical disk drive may be provided for reading from or writing to a removable, non-volatile optical disk, such as a CD-ROM, DVD-ROM, or other optical medium.Additionally, memory 404 may include flash memory, such as a flash memory stick or a flash drive. Memory devices may be connected to memory bus 403 through one or more data media interfaces. Memory 404 may include at least one program product having a set of (e.g., at least one) program modules configured to perform the functions of various embodiments.
[0053] One or more programs / utilities 428, each having at least one set of program modules 430, may be stored in memory 404. The programs / utilities 428 may include a hypervisor (also referred to as a VM monitor), one or more operating systems, one or more application programs, other program modules, and program data. Each of the operating systems, the one or more application programs, the other program modules, and the program data, or a combination thereof, may each include an implementation of a network environment. The programs 428 and / or program modules 430 generally perform the functions or procedures of various embodiments.
[0054] Although the memory bus 403 in Fig. 4 as a single bus structure providing a direct data transmission path between the CPUs 402, the memory subsystem 404, and the I / O bus interface 410, in some embodiments, the memory bus 403 may include multiple different buses and data transmission paths that may be arranged in any manner, e.g., as point-to-point links in hierarchical, star, or network configurations, as multiple hierarchical buses, parallel and redundant paths, or any other suitable type of configuration. Furthermore, although the I / O bus interface 410 and the I / O bus 408 are each shown as individual units, in some embodiments, the computer system 401 may include multiple I / O bus interface units 410, multiple I / O buses 408, or both.Furthermore, although multiple I / O interface units are shown separating the I / O bus 408 from various data transmission paths to the various I / O units, in other embodiments, some or all of the I / O units may be directly connected to one or more system I / O buses.
[0055] In some embodiments, computer system 401 may be a multi-user mainframe computer system, a single-user system, or a server computer or a similar device that has little or no direct user interface but receives requests from other computer systems (clients). Furthermore, in some embodiments, computer system 401 may be implemented as a desktop computer, portable computer, laptop or notebook computer, tablet computer, handheld computer, telephone, smartphone, network switches or routers, or any other suitable type of electronic device.
[0056] It is pointed out that Fig. 4 is intended to illustrate the representative major components of an exemplary computer system 401. However, in some embodiments, individual components may have greater or lesser complexity than in Fig. 4 have shown that other or additional components than those in Fig. 4 may be present, and the number, type, and configuration of such components may vary.
[0057] As discussed in more detail herein, it is contemplated that some or all of the operations of some of the embodiments of methods described herein may be performed in alternative orders or not performed at all; furthermore, multiple operations may occur concurrently or as an inherent part of a larger process.
[0058] The present disclosure may be a system, method, and / or computer program product with any possible degree of technical integration. The computer program product may include a computer-readable storage medium (or media) with computer-readable program instructions for causing a processor to perform aspects of the present disclosure.
[0059] The computer-readable storage medium may be a tangible device capable of retaining and storing instructions for use by an instruction execution unit. The computer-readable storage medium may be, for example, but not limited to, an electronic storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination thereof. A non-exhaustive list of more specific examples of the computer-readable storage medium includes the following: a portable computer diskette, a hard disk, RAM, ROM, erasable programmable read-only memory (EPROM).Flash memory), a static random access memory (SRAM), a portable CD-ROM, a DVD (Digital Versatile Disc), a memory stick, a floppy disk, a mechanically encoded device such as punched cards or raised structures in a groove on which instructions are stored, and any suitable combination thereof. A computer-readable storage medium, as used herein, shall not be construed as containing transitory signals per se, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through a waveguide or other transmission medium (e.g., pulses of light traveling through fiber optic cables), or electrical signals transmitted through a wire.
[0060] Computer-readable program instructions described herein may be downloaded from a computer-readable storage medium to respective computing / processing units or to an external computer or external storage unit over a network such as the Internet, a local area network (LAN), a wide area network (WAN), and / or a wireless network. The network may include copper transmission cables, fiber optic transmission lines, wireless transmission, routers, firewalls, switching units, gateway computers, and / or edge servers. A network adapter card or network interface in each computing / processing unit receives computer-readable program instructions from the network and forwards the computer-readable program instructions for storage in a computer-readable storage medium within the respective computing / processing unit.
[0061] Computer-readable program instructions for performing operations of the present disclosure may be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state-setting data, integrated circuit configuration data, or both source code and object code written in any combination of one or more programming languages, including object-oriented programming languages such as Smalltalk, C++, or the like, as well as traditional procedural programming languages such as the "C" programming language or similar programming languages.The computer-readable program instructions may execute entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on the remote computer or server. In the latter case, the remote computer may be connected to the user's computer through any type of network, for example, a local area network (LAN) or a wide area network (WAN), or the connection may be made to an external computer (for example, over the Internet using an Internet service provider).In some embodiments, an electronic circuit such as a programmable logic circuit, field programmable gate arrays (FPGAs), or programmable logic arrays (PLAs) may execute the computer-readable program instructions by using state data of the computer-readable program instructions to personalize the electronic circuit and perform aspects of the present disclosure.
[0062] Aspects of the present disclosure are described herein with reference to flowchart and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the disclosure. It should be understood that each block of the flowchart illustrations and / or block diagrams, as well as combinations of blocks in the flowchart illustrations and / or block diagrams, may be implemented by computer-readable program instructions.
[0063] These computer-readable program instructions may be provided to a processor of a computer or other programmable data processing apparatus to produce a machine, such that instructions executing via the processor of the computer or other programmable data processing apparatus produce a means for implementing the functions / steps specified in the flowchart and / or block diagram block or blocks. These computer-readable program instructions may also be stored on a computer-readable storage medium capable of directing a computer, programmable data processing apparatus, and / or other devices to function in a particular manner, such that the computer-readable storage medium on which instructions are stored comprises an article of manufacture, including instructions implementing aspects of the function or steps specified in the flowchart and / or block diagram block or blocks.implement the function / step specified in the blocks of the flow charts and / or block diagrams.
[0064] The computer-readable program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of process steps to be performed on the computer, other programmable apparatus, or other device to produce a computer-implemented process such that the instructions executing on the computer, other programmable apparatus, or other device implement the functions / steps specified in the block(s) of flowcharts and / or block diagrams.
[0065] The flowchart and block diagrams in the figures illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flowcharts or block diagrams may represent a module, segment, or portion of instructions comprising one or more executable instructions for performing the particular logical function or functions. In some alternative implementations, the functions specified in the block may occur in a different order than shown in the figures.For example, two blocks shown in sequence may actually occur as one step, execute substantially simultaneously, partially or completely overlap in time, or the blocks may sometimes execute in reverse order depending on the functionality involved. It should also be noted that each block of the block diagrams and / or flowcharts, as well as combinations of blocks in the block diagrams and / or flowcharts, may be implemented by special purpose hardware-based systems that perform the specified functions or steps, or by combinations of special purpose hardware and computer instructions.
[0066] The descriptions of the various embodiments of the present disclosure have been presented for illustrative purposes and are not intended to be exhaustive or limited to the disclosed embodiments. Those skilled in the art will appreciate that numerous modifications and variations are possible without departing from the spirit and scope of the described embodiments. The terminology used herein has been chosen to best explain the principles of the embodiments, practical application, or technical improvement over commercially available technology, or to enable others skilled in the art to understand the embodiments disclosed herein.
[0067] Although the present disclosure has been described with reference to specific embodiments, it is understood that changes and modifications thereto will be apparent to those skilled in the art. Therefore, the following claims are intended to be interpreted to encompass all such changes and modifications that fall within the true scope of the disclosure.
Claims
[1] System for optimal security of Internet of Things devices, Internet of Things, loT, the system comprising: a RAM; and a processor in communication with the memory, the processor configured to perform operations comprising: Determine that content is generated for data transmission between IoT units; Identifying a source unit and a destination unit of the IoT units; Analyzing the content; Determining the sensitivity of the content; and based on determining assigning a security level to either the source unit or the target unit. [2] The system of claim 1, wherein determining the sensitivity of the content comprises: Analyzing a calibrated database, where the calibrated database has pre-populated data indicating sensitivity based on content type. [3] The system of claim 2, wherein the calibrated database further comprises an indication of the security level associated with the sensitivity. [4] The system of claim 1, wherein assigning the security level to either the source unit or the destination unit comprises: Identifying a predefined security level for the source unit; Identifying a predefined security level for the target unit; and Generating a medium security level for the assignment, where the medium security level is a combination of the predefined security levels for the source unit and the target unit. [5] The system of claim 1, wherein the processor is further configured to perform operations comprising: Apply data transmission encryption based on the assigned security level. [6] The system of claim 5, wherein applying the data transmission encryption comprises: Identify what type of entity the source entity and the target entity are, respectively; and Extend data transfer encryption based on type. [7] The system of claim 1, wherein the processor is further configured to perform operations comprising: continuously analyzing the content for changes in sensitivity; and Automatically update the security level. [8] Computer-implemented method for optimal security of Internet of Things (IoT) devices, the method comprising: Determining by a processor that content is being generated for data transmission between IoT devices; Identifying a source unit and a destination unit of the IoT units; Analyzing the content; Determining the sensitivity of the content; and based on determining assigning a security level to either the source unit or the target unit. [9] The computer-implemented method of claim 8, wherein determining the sensitivity of the content comprises: Analyzing a calibrated database, where the calibrated database has pre-populated data indicating sensitivity based on content type. [10] The computer-implemented method of claim 9, wherein the calibrated database further comprises an indication of the security level associated with the sensitivity. [11] The computer-implemented method of claim 8, wherein assigning the security level to either the source entity or the destination entity comprises: Identifying a predefined security level for the source unit; Identifying a predefined security level for the target unit; and Generating a medium security level for the assignment, where the medium security level is a combination of the predefined security levels for the source unit and the target unit. [12] A computer-implemented method according to claim 8, further comprising: Apply data transmission encryption based on the assigned security level. [13] The computer-implemented method of claim 12, wherein applying the data transmission encryption comprises: Identify what type of entity the source entity and the target entity are, respectively; and Extend data transfer encryption based on type. [14] A computer-implemented method according to claim 8, further comprising: continuously analyzing the content for changes in sensitivity; and Automatically update the security level. [15] A computer program product for optimal security of Internet of Things (IoT) devices, comprising a computer-readable storage medium having program instructions embodied thereon, the program instructions being executable by a processor to cause the processor to perform operations, the operations comprising: Determine that content is generated for data transmission between IoT units; Identifying a source unit and a destination unit of the IoT units; Analyzing the content; Determining the sensitivity of the content; and based on determining assigning a security level to either the source unit or the target unit. [16] The computer program product of claim 15, wherein determining the sensitivity of the content comprises: Analyzing a calibrated database, where the calibrated database has pre-populated data indicating sensitivity based on content type. [17] The computer program product of claim 16, wherein the calibrated database further comprises an indication of the security level associated with the sensitivity. [18] The computer program product of claim 15, wherein assigning the security level to either the source entity or the target entity comprises: Identifying a predefined security level for the source unit; Identifying a predefined security level for the target unit; Generating a medium security level for the assignment, where the medium security level is a combination of the predefined security levels for the source unit and the target unit. [19] The computer program product of claim 15, wherein the processor is further configured to perform operations comprising: Apply data transmission encryption based on the assigned security level. [20] The computer program product of claim 19, wherein applying the data transmission encryption comprises: Identify what type of entity the source entity and the target entity are, respectively; and Extend data transfer encryption based on type.