Optimizing Security for Internet of Things Devices

The system dynamically adjusts IoT device security levels based on data sensitivity, reducing computational and power consumption by applying encryption only when necessary, addressing the inefficiency of uniform high security processing.

JP2025525748APending Publication Date: 2025-08-07INTERNATIONAL BUSINESS MACHINE CORPORATION
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2025503119
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-08-01
Filing Date
2023-07-31
Publication Date
2025-08-07

AI Technical Summary

Technical Problem

Existing IoT devices face computational overload due to uniform high security processing for all data, which is inefficient and consumes excessive power and CPU resources, especially for less sensitive data transfers.

Method used

A system that dynamically adjusts security levels based on the sensitivity of data being processed, applying encryption only when necessary, using a processor to analyze content, determine sensitivity, and assign appropriate security levels to IoT devices.

Benefits of technology

Reduces security processing overhead and power consumption by optimizing security levels based on data sensitivity, ensuring secure communication without overburdening IoT devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025525748000001_ABST
    Figure 2025525748000001_ABST
Patent Text Reader

Abstract

Identifying that content has been generated for communication between IoT devices, identifying source and target IoT devices, analyzing the content, determining the sensitivity of the content, and assigning a security level to either the source or target device based on the determination.
Need to check novelty before this filing date? Find Prior Art

Description

[Background technology]

[0001] The present disclosure relates generally to the field of internet-of-things (IoT) security, and more particularly to automated security optimization for IoT devices.

[0002] With the emergence of cloud infrastructure as a universal platform for running systems from a central location, the number of end devices has increased exponentially around the world. Currently, the number of IoT devices exceeds the world's population, and this is possible because all devices are somehow connected together through IoT networks. As can be understood, with so much data flowing over IoT networks, security becomes of utmost importance. A common way to solve such security issues is to use encryption and decryption of data at rest and in transit. However, using encryption and decryption algorithms in IoT devices to protect data can overload IoT devices. Summary of the Invention

[0003] Embodiments of the present disclosure include methods, computer program products, and systems for optimal IoT device security. The processor may identify that content has been generated for communication between IoT devices. The processor may identify a source device and a target device of the IoT devices. The processor may analyze the content. The processor may determine the sensitivity of the content. The processor may assign a security level to either the source device or the target device based on the determination.

[0004] The above summary is not intended to describe each illustrated embodiment or every implementation of the present disclosure. [Brief explanation of the drawings]

[0005] The drawings included in this disclosure are incorporated in and form a part of this specification. They illustrate embodiments of the present disclosure and, together with the description, serve to explain the principles of the present disclosure. The drawings are merely illustrative of particular embodiments and are not intended to limit the disclosure.

[0006] [Figure 1] FIG. 1 illustrates a block diagram of an example system for optimal IoT device security according to aspects of the present disclosure.

[0007] [Figure 2] FIG. 1 illustrates a flowchart of an example method for optimal IoT device security according to aspects of the present disclosure.

[0008] [Figure 3A] 1 illustrates a cloud computing environment according to an aspect of the present disclosure.

[0009] [Figure 3B] 1 illustrates an abstraction model layer according to an aspect of the present disclosure.

[0010] [Figure 4] 1 depicts a high-level block diagram of an exemplary computer system that may be used in implementing one or more of the methods, tools, and modules described herein, and any associated functionality, in accordance with aspects of the present disclosure.

[0011] While the embodiments described herein are amenable to various modifications and alternative forms, specific features thereof have been shown by way of example in the drawings and will be described in detail. It is to be understood, however, that the particular embodiments described are not to be construed in a limiting sense. On the contrary, it is intended to cover all modifications, equivalents, and alternatives falling within the scope of the present disclosure. DETAILED DESCRIPTION OF THE INVENTION

[0012] Aspects of the present disclosure relate generally to the field of internet-of-things (IoT) security, and more specifically to automated security optimization for IoT devices. While the present disclosure is not necessarily limited to such applications, various aspects of the present disclosure may be understood through a discussion of various examples using this context.

[0013] As cloud infrastructure has emerged as a universal platform for running systems from a central location, the number of end devices has increased exponentially worldwide. Currently, the number of IoT devices exceeds the world's population, and this is possible because all devices are connected together in some way through IoT networks. Understandably, with so much data flowing over IoT networks, security becomes paramount. A common approach to solving such security issues is to use encryption and decryption of stored and flowing data. However, using encryption and decryption algorithms in IoT devices to protect data can overload the IoT devices. For example, currently, various security methods are applied to gain the trust of users who store remote (networked) data, but ultimately result in overloading the computing system (e.g., source device and / or target device) with security / encryption processing for every bit of data.

[0014] As devices get smaller in the future, computing power and power consumption will become more important. For example, every smartphone consumes a lot of power just to encrypt and decrypt one bit of data. These smartphones are generally much smaller devices than the devices that transmit data over a network. Therefore, as will be explained throughout this disclosure, there is a lot of data that does not truly require much security processing or overhead.

[0015] There is no dynamism in accessing the security level of any content, so general or generic universal security enforcement rules impose a processing overhead on any system that needs to be secured. For example, if a smartphone accesses a publicly available web page such as a news or weather forecast, even if the smartphone needs to be secured, there is no need to encrypt or decrypt every bit associated with the site when loading the news web page or weather forecast page.

[0016] Following this example, it should be noted that smartphones and IoT devices in general have inherent limitations of less available compute / CPU and less available wattage / power, which results in higher power and CPU usage during encryption / decryption, further reducing the overall computational capabilities of the IoT device.

[0017] Accordingly, given a cluster of IoT devices in the workplace, or even at home, there may be many complex mesh communications and many data transfers between them, so it becomes very important to determine whether all IoT device communications need to be secure.

[0018] Therefore, disclosed herein is a solution that reduces security processing overload based on the actual content processed by IoT devices. Then, if the content is important, the security level should be maintained, but if it is not, the system should lower the security level while dynamically processing the content / data. In other words, instead of setting a uniform high security level across the entire system for every bit of data for transmission or storage, disclosed herein is a solution for a system (or systems) that can adjust the security level based on the content being processed on or off the network.

[0019] The solution includes, but is not limited to, dynamically detecting the security level of content in an IoT device, where content that is data that needs to be sent / received is traveling through a communication channel; applying a security level based on the detection of content sensitivity (e.g., content confidentiality) (e.g., medical information is more sensitive than a typical text message, etc., and therefore has a higher security level); and automatically detecting the security level of data, where security is based on organized / specified parameters (e.g., calibrated data / databanks). In some embodiments, the solution assumes that sensitive data is flowing if the parameters have expected values, device algorithms, etc. Furthermore, whenever the solution detects sensitive data flow, it will trigger a flow to enhance security.

[0020] Briefly, the solutions described herein are methods, systems, and / or computer program products that provide dynamic security levels to IoT devices based on the sensitive nature of data generated, captured, or transmitted at or from the IoT device. In some embodiments, the dynamic security level for an IoT device may be based on geographic location (e.g., a public cafe, a processing plant, etc.), the source of the data / content (e.g., an IoT device tagged as sensitive by the device manufacturer, etc.), the target of the data (e.g., the IoT device to which the data is sent is marked as sensitive by the device manufacturer, etc.), and / or the type of IoT device (e.g., a CCTV is considered more sensitive in nature compared to, for example, a temperature measurement device).

[0021] Currently, as a detailed example of the solution disclosed herein, assume the following.

[0022] Device 1 (D1) → is an IoT device in the network.

[0023] Device 2 (D2) → is another IoT device in the network.

[0024] Device N (Dn) → represents the nth IoT device in the network.

[0025] A communication link (Li) → represents communication between two IoT devices.

[0026] And Dn-1←Li→Dn= represents the link between the nth IoT device and the (n-1)th IoT device.

[0027] Thus, the solution may: analyze the data generated by device Dn and determine the level of PII / SPI (Personally Identifiable Information / Sensitive Personal Information) data generated (w1);

[0028] It may determine / identify the ability of an IoT device to control or function other IoT devices (w2).

[0029] Determine / identify the ability of IoT devices to affect the entire system (w3) (e.g., temperature control IoT devices in a power plant or gas control devices in a chemical plant), and

[0030] Based on the determination / identification, a security level (SL) of the device Dn may be calculated. The security level may be a value between 1 and 5, with 1 being the lowest and 5 being the most sensitive data generation. The security level may be defined as SL=f(w1, w2, w3).

[0031] In some embodiments, the solution may further calculate the SL for each device in the network, rank the IoT devices based on the calculated SL, and calculate the SL of the communication links (Li) between all devices.

[0032] In some embodiments, calculating the security level of a communication link may include the solution receiving / obtaining the security levels of both or all devices involved in the communication (e.g., SLn, SLn+1). The solution may further find / identify the median of both security levels and assign the median security level to the communication link (e.g., Li SL = Median [Device 1 SL, Device 2 SL]). In some embodiments, the solution may calculate the security level of all communication links in the network. Note that the proposed solution may include an opt-in feature to which the user may agree to allow the solution to analyze content / data, devices, and / or communication links.

[0033] In some embodiments, the proposed solution may include a rank function that is used to determine a security level for content based on the sensitivity of the content, where the rank function is as follows:

[0034]

number

[0035] where:

[0036] Li is the IoT device whose risk rank is calculated;

[0037] p is a parameter for calculating the rank;

[0038] V is the value of the parameter;

[0039] W is the weight that defines which parameters are important for calculating the risk rank;

[0040] n is the total number of parameters.

[0041] In some embodiments, parameters that determine what data captured by an IoT device is sensitive include privacy data, personal data, tags from the manufacturer (as described above), health data, location data, etc.

[0042] In some embodiments, the proposed solution may include a threshold function that is used to determine whether the security level should be dynamically increased, the threshold function being:

[0043]

number

[0044] where:

[0045] R(Li) is the security risk rank for IoT device D(i); and

[0046] n is the total number of IoT devices.

[0047] If an IoT device is generating PII / SPI data, the proposed solution assigns more weight to the device. Additionally, if the communication device accepts any PII / SPI data, the proposed solution assigns more weight to the communication link (Li).

[0048] Referring now to FIG. 1, a block diagram of an example system 100 for optimal IoT device security is illustrated, according to an aspect of the present disclosure.

[0049] As shown, the system 100 includes a communication channel 102, content 104, a dynamic security adjuster 106, a source device analyzer 108, a target device analyzer 110, a content analyzer 112, a decision engine 114, a security level identifier 116, an encryption applicator 118, and a calibrated data bank 120.

[0050] In some embodiments, content 104 is received by system 100 through communication channel 102, and the content 104 is identified from a communication (not shown) within communication channel 102. System 100 then analyzes the content 104 utilizing dynamic security adjuster 106. Dynamic security adjuster 106 processes each piece of content 104 (or communication) through a source device analyzer 108, a target device analyzer 110, and a content analyzer 112, respectively, which rank or provide weights to the sensitive nature of the content 104.

[0051] The ranks or weights of the sensitive nature of the content 104 are then sent from the source device analyzer 108, the target device analyzer 110, and the content analyzer 112 to the decision engine 114, which may compare the ranks or weights to calibrated data in the calibrated data bank 120, where the calibrated data includes a predefined list of sensitivity / security levels associated with the particular content.

[0052] In some embodiments, the decision engine 114 provides the decision regarding the confidentiality of the content 104 to a security level identifier 116, which can provide a security level associated with the confidentiality. The security level identifier 116 then provides the security level to an encryption applicator 118, which applies an encryption algorithm (e.g., SHA-256, etc.) or scheme (e.g., push notification, etc.) to the source device and / or target device (not shown).

[0053] 2, a flowchart of an example method 200 for optimal IoT device security is illustrated in accordance with aspects of the present disclosure. In some embodiments, method 200 may be performed by a processor (such as, for example, system 100 of FIG. 1).

[0054] In some embodiments, method 200 begins at operation 202, where a processor may identify that content is to be generated for communication between IoT devices. Note that the communication may be a message between the devices, and the content may be the sentiment or context of the communication.

[0055] In some embodiments, method 200 may proceed to operation 204 where processing may identify the source device and the target device of the IoT device. In some embodiments, method 200 may proceed to operation 206 where a processor may analyze the content.

[0056] In some embodiments, method 200 may proceed to operation 208, where the processor may determine the sensitivity of the content. In some embodiments, method 200 may proceed to operation 210, where the processor may assign a security level to either the source device or the target device based on the determination. In some embodiments, after operation 210, method 200 may end.

[0057] In some embodiments described below, for the sake of brevity, there are one or more operations of method 200 described throughout this disclosure that are not shown. Accordingly, in some embodiments, determining the sensitivity of the content may include a processor analyzing a calibrated database, where the calibrated database may include prefilled data indicating sensitivity based on content type (e.g., personal data, location data, etc.).

[0058] In some embodiments, the calibrated data bank may further include an indication of security levels associated with confidentiality (e.g., personal data = high security level, device name = lower security level, etc.).

[0059] In some embodiments, assigning a security level to either the source device or the target device may include the processor identifying a predefined security level for the source device. The processor may further identify a predefined security level for the target device and generate a median security level for assignment. In some embodiments, the median security level may be a combination of the predefined security levels for the source device and the target device (or all devices in a communication link, or all devices in all communication links of a network).

[0060] In some embodiments, the processor may apply encryption of the communications based on the assigned security level. In some embodiments, applying encryption of the communications may include the processor determining what type of device each of the source device and target device is and increasing encryption of the communications based on the type (e.g., dynamically changing the security level or encryption based on manufacturer recommendations, etc.).

[0061] In some embodiments, the processor may further continuously analyze the content for changes in sensitivity and automatically update the security level.

[0062] Although this disclosure includes detailed descriptions of cloud computing, it should be understood that implementation of the teachings cited herein is not limited to cloud computing environments. Rather, embodiments of the present disclosure can be implemented in conjunction with any other type of computing environment now known or later developed.

[0063] Cloud computing is a service delivery model for enabling convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, network bandwidth, servers, processing, memory, storage, applications, virtual machines, and services) that can be rapidly provisioned and released with minimal administrative effort or interaction with the service provider. This cloud model can include at least five characteristics, at least three service models, and at least four deployment models.

[0064] The characteristics are as follows:

[0065] On-Demand Self-Service: Cloud consumers can unilaterally provision computing capacity, such as server time and network storage, automatically as needed, without requiring human interaction with the service provider.

[0066] Wide network access: Capabilities are available over the network and accessed through standard mechanisms that facilitate use by heterogeneous thin or thick client platforms (e.g., cell phones, laptops, and PDAs).

[0067] Resource Pooling: A provider's computing resources are pooled to serve multiple consumers using a multi-tenant model, with various physical and virtual resources dynamically allocated and reallocated according to demand. Consumers generally do not control or know the exact portion of the resources provided, but there is a sense of portion independence in that they may be able to specify portions at a higher level of abstraction (e.g., country, state, or data center).

[0068] Rapid Elasticity: Capacity is provisioned quickly and elastically, sometimes automatically, and can be quickly scaled out or quickly released and quickly scaled in. In many cases, the capacity available for provisioning appears unlimited to the consumer, and can be purchased in any quantity at any point in time.

[0069] Metering Services: Cloud systems automatically control and optimize resource usage by leveraging metering capabilities appropriate to the type of service (e.g., storage, processing, bandwidth, and active user accounts) at a certain level of abstraction. Resource utilization can be monitored, controlled, and reported, providing transparency to both providers and consumers of the services used.

[0070] The service model is as follows:

[0071] Software as a Service (SaaS): The consumer is offered the ability to use a provider's applications running on a cloud infrastructure. The applications are accessible from a variety of client devices through a thin-client interface such as a web browser (e.g., web-based email). The consumer does not manage or control the underlying cloud infrastructure, including the network, servers, operating systems, storage, or even individual application capabilities, with the possible exception of limited user-specific application configuration settings.

[0072] Platform as a Service (PaaS): The ability offered to consumers is to deploy applications they create or acquire, written using programming languages and tools supported by the provider, onto a cloud infrastructure. The consumer does not manage or control the underlying cloud infrastructure, including networks, servers, operating systems, or storage, but does control the deployed applications and, in some cases, the configuration of the application hosting environment.

[0073] Infrastructure as a Service (IaaS): The ability provided to consumers is to provision processing, storage, network, and other basic computing resources onto which they can deploy and run any software, which may include operating systems and applications. The consumer does not manage or control the underlying cloud infrastructure, but rather controls the operating system, storage, deployed applications, and in some cases has limited control over selected networking components (e.g., host firewalls).

[0074] The deployment model is as follows:

[0075] Private Cloud: Cloud infrastructure is operated exclusively for an organization. It may be managed by the organization or a third party and may reside on-premise or off-premise.

[0076] Community Cloud: Cloud infrastructure is shared by multiple organizations to support a specific community with shared concerns (e.g., mission, security requirements, policies, and regulatory compliance considerations). Community clouds may be managed by those organizations or by a third party and may exist on-premises or off-premises.

[0077] Public Cloud: Cloud infrastructure is made available to the general public or large industry organizations and is owned by organizations that sell cloud services.

[0078] Hybrid Cloud: This cloud infrastructure is a composite of two or more clouds (private, community, or public) that remain unique entities but are bound together by standardized or proprietary technologies that allow for data and application portability (e.g., cloud bursting for load balancing between clouds).

[0079] Cloud computing environments are service-oriented with an emphasis on statelessness, low coupling, modularity, and semantic interoperability. At the core of cloud computing is an infrastructure that includes a network of interconnected nodes.

[0080] 3A illustrates a cloud computing environment 310. As shown, the cloud computing environment 310 includes one or more cloud computing nodes 300 with which local computing devices used by cloud consumers, such as a personal digital assistant (PDA) or cellular phone 300A, a desktop computer 300B, a laptop computer 300C, or an automobile computer system 300N, or combinations thereof, can communicate. The nodes 300 may communicate with each other. They may be physically or virtually grouped (not shown) into one or more networks, such as a private cloud, a community cloud, a public cloud, or a hybrid cloud, or combinations thereof, as described hereinabove.

[0081] This enables the cloud computing environment 310 to provide infrastructure, platform, or software, or a combination thereof, as a service without requiring cloud consumers to maintain resources on their local computing devices. It will be understood that the types of computing devices 300A-N shown in Figure 3A are intended to be exemplary only, and that the computing nodes 300 and cloud computing environment 310 can communicate with any type of computerized device over any type of network or network-addressable connection, or both (e.g., using a web browser).

[0082] 3B illustrates a set of functional abstraction layers provided by the cloud computing environment 310 (FIG. 3A). It should be understood in advance that the components, layers, and functions illustrated in FIG. 3B are intended to be examples only, and that embodiments of the present disclosure are not limited thereto. As shown below, the following layers and corresponding functions are provided:

[0083] Hardware and software layer 315 includes hardware and software components. Examples of hardware components include mainframe 302, RISC (reduced instruction set computer) architecture-based server 304, server 306, blade server 308, storage device 311, and network and networking components 312. In some embodiments, software components include network application server software 314 and database software 316.

[0084] The virtualization layer 320 provides an abstraction layer from which the following examples of virtual entities may be provided: virtual servers 322, virtual storage 324, virtual networks including virtual private networks 326, virtual applications and operating systems 328, and virtual clients 330.

[0085] In one example, management layer 340 may provide the functions described below. Resource provisioning 342 provides dynamic procurement of computing and other resources utilized to execute tasks within the cloud computing environment. Metering and pricing 344 provides cost tracking as resources are utilized within the cloud computing environment and bills or invoices for the consumption of these resources. In one example, these resources may include application software licenses. Security provides identity verification for cloud consumers and tasks, as well as protection of data and other resources. User portal 346 provides consumers and system administrators with access to the cloud computing environment. Service level management 348 provides allocation and management of cloud computing resources to ensure required service levels are met. Service level agreement (SLA) planning and fulfillment 350 provides pre-configuration and procurement of cloud computing resources to anticipate future requirements according to SLAs.

[0086] Workload tier 360 provides examples of functions for which cloud computing environments can be utilized. Examples of workloads and functions that can be provided from this tier include mapping and navigation 362, software development and lifecycle management 364, virtual classroom instruction delivery 366, data analytics processing 368, transaction processing 370, and IoT device security optimization 372.

[0087] 4 illustrates a high-level block diagram of an exemplary computer system 401 that may be used to implement (e.g., using one or more processor circuits of a computer or computer processor) one or more of the methods, tools, and modules, and any associated functionality described herein, according to embodiments of the present disclosure. In some embodiments, major components of computer system 401 may include one or more CPUs 402, a memory subsystem 404, a terminal interface 412, a storage interface 416, an I / O (input / output) device interface 414, and a network interface 418, all of which may be communicatively coupled, directly or indirectly, for inter-component communication via a memory bus 403, an I / O bus 408, and an I / O bus interface unit 410.

[0088] Computer system 401 may include one or more general-purpose programmable central processing units (CPUs) 402A, 402B, 402C, and 402D, collectively referred to herein as CPUs 402. In some embodiments, computer system 401 may include multiple processors, as is typical for relatively large systems. However, in other embodiments, computer system 401 may alternatively be a single-CPU system. Each CPU 402 may execute instructions stored in memory subsystem 404 and may include one or more levels of on-board cache.

[0089] The system memory 404 may include computer system-readable media in the form of volatile memory, such as random access memory (RAM) 422 or cache memory 424. The computer system 401 may further include other removable / non-removable volatile / non-volatile computer system storage media. By way of example only, the storage system 426 may be provided to read from and write to a non-removable, non-volatile magnetic medium, such as a “hard drive.” Although not shown, a magnetic disk drive may be provided to read from or write to a removable, non-volatile magnetic disk (e.g., a “floppy disk”), or an optical disk drive may be provided to read from and write to a removable, non-volatile optical disk, such as a CD-ROM, DVD-ROM, or other optical medium. Additionally, the memory 404 may include flash memory, such as a flash memory stick drive or flash drive. Memory devices may be connected to the memory bus 403 by one or more data medium interfaces. The memory 404 may include at least one program product having a set (e.g., at least one) of program modules configured to perform the functions of various embodiments.

[0090] One or more programs / utilities 428, each having at least one set of program modules 430, may be stored in memory 404. The programs / utilities 428 may include a hypervisor (also called a virtual machine monitor), one or more operating systems, one or more application programs, other program modules, and program data. Each of these operating systems, one or more application programs, other program modules, and program data, or any combination thereof, may comprise an implementation of a networking environment. The programs 428 and / or program modules 430 generally perform the functions or methodologies of the various embodiments.

[0091] 4 as a single bus structure providing a direct communication path between CPU 402, memory subsystem 404, and I / O bus interface 410, memory bus 403, in some embodiments, may include multiple different buses or communication paths that may be configured in any of a variety of forms, such as point-to-point links in a hierarchical, star, or web configuration, multiple hierarchical buses, parallel and redundant paths, or any other suitable type of configuration. Additionally, while I / O bus interface 410 and I / O bus 408 are shown as single respective units, computer system 401, in some embodiments, may include multiple I / O bus interface units 410, multiple I / O buses 408, or both. Additionally, while multiple I / O interface units are shown isolating I / O bus 408 from the various communication paths extending to the various I / O devices, in other embodiments, some or all of the I / O devices may be directly connected to one or more system I / O buses.

[0092] In some embodiments, computer system 401 may be a multi-user mainframe computer system, a single-user system, or a server computer or similar device that has little or no direct user interface but receives requests from other computer systems (clients). Further, in some embodiments, computer system 401 may be implemented as a desktop computer, a portable computer, a laptop or notebook computer, a tablet computer, a pocket computer, a telephone, a smartphone, a network switch or router, or any other suitable type of electronic device.

[0093] It should be noted that Figure 4 is intended to illustrate representative major components of an exemplary computer system 401. However, in some embodiments, individual components may be of greater or less complexity than depicted in Figure 4, components other than or in addition to those depicted in Figure 4 may be present, and the number, type, and configuration of such components may vary.

[0094] As discussed in more detail herein, it is contemplated that some or all of the operations of the method embodiments described herein may be performed in an alternative order, or not at all, and further, multiple operations may occur simultaneously or as part of a larger process.

[0095] The present disclosure may be a system, method, or computer program product, or combination thereof, at any possible level of integration of technical details. The computer program product may include a computer-readable storage medium having computer-readable program instructions for causing a processor to perform aspects of the present disclosure.

[0096] A computer-readable storage medium may be a tangible device that can hold and store instructions for use by an instruction execution device. The computer-readable storage medium may be, for example, but is not limited to, an electronic storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination thereof. A non-exhaustive list of more specific examples of computer-readable storage media includes the following: portable computer diskettes, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), static random access memory (SRAM), portable compact disc read-only memory (CD-ROM), digital versatile disk (DVD), memory sticks, floppy disks, mechanically encoded devices such as punch cards or ridge structures in grooves on which instructions are recorded, and any suitable combination of the foregoing. Computer-readable storage medium, as used herein, should not be construed as a transitory signal per se, such as an electric wave or other freely propagating electromagnetic wave, an electromagnetic wave propagating through a waveguide or other transmission medium (e.g., a light pulse passing through a fiber optic cable), or an electrical signal transmitted through a wire.

[0097] The computer-readable program instructions described herein may be downloaded from a computer-readable storage medium to each computing / processing device or to an external computer or external storage device via a network, such as the Internet, a local area network, a wide area network, and / or a wireless network. The network may include copper transmission cables, optical fiber transmissions, wireless transmissions, routers, firewalls, switches, gateway computers, and / or edge servers. A network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards the computer-readable program instructions for storage in a computer-readable storage medium in the respective computing / processing device.

[0098] The computer-readable program instructions for carrying out the operations of the present disclosure may be either assembler instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state setting data, configuration data for an integrated circuit, or source or object code written in any combination of one or more programming languages, including object-oriented programming languages such as Smalltalk®, C++, and procedural programming languages such as the “C” programming language or similar programming languages. The computer-readable program instructions may run entirely on the user's computer, as a standalone software package, partially on the user's computer, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the latter scenario, the remote computer may be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection may be to an external computer (e.g., via the Internet using an Internet Service Provider). In some embodiments, electronic circuitry including, for example, a programmable logic circuit, a field programmable gate array (FPGA), or a programmable logic array (PLA) may execute computer-readable program instructions by utilizing state information of the computer-readable program instructions to personalize the electronic circuitry to perform aspects of the present disclosure.

[0099] Aspects of the present disclosure are described herein with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the present disclosure. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer-readable program instructions.

[0100] These computer-readable program instructions may be provided to a processor of a computer or other programmable data processing apparatus to produce a machine, such that the instructions, executed by the processor of the computer or other programmable data processing apparatus, create means for implementing the functions / acts specified in one or more blocks of the flowcharts and / or block diagrams. These computer-readable program instructions may also be stored on a computer-readable storage medium that can instruct a computer, programmable data processing apparatus and / or other device to function in a particular manner, such that the computer-readable storage medium having instructions stored therein has an article of manufacture including instructions that implement aspects of the functions / acts specified in one or more blocks of the flowcharts and / or block diagrams.

[0101] The computer-readable program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable apparatus, or other device to create a computer-implemented process, such that the instructions executing on the computer, other programmable apparatus, or other device implement the functions / acts specified in one or more blocks of the flowcharts and / or block diagrams.

[0102] The flowcharts and block diagrams in the figures illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of instructions, including one or more executable instructions for implementing a specified logical function. In some alternative implementations, the functions noted in the blocks may occur out of the order noted in the figures. For example, two blocks shown in succession may actually be realized as a single step, executed concurrently, substantially concurrently, partially, or fully in an overlapping manner, or the blocks may possibly be executed in reverse order depending on the functionality involved. It should also be noted that each block in the block diagrams and / or flowchart diagrams, and combinations of blocks in the block diagrams and / or flowchart diagrams, may be implemented by a dedicated hardware-based system that performs the specified functions or operations, or executes a combination of dedicated hardware and computer instructions.

[0103] The description of various embodiments of the present disclosure has been presented for purposes of illustration and is not intended to be exhaustive or limited to the disclosed embodiments. Many modifications and variations will be apparent to those skilled in the art without departing from the scope of the described embodiments. The terminology used herein has been selected to best explain the principles, practical applications, or technical improvements of the embodiments over art found in the market, or to enable others skilled in the art to understand the embodiments disclosed herein.

[0104] While the present disclosure has been described with reference to specific embodiments, it is anticipated that variations and modifications thereof will become apparent to those skilled in the art. It is therefore intended that the following claims be interpreted to cover all such variations and modifications as fall within the true scope of the present disclosure.

Claims

1. memory; and Identifying that content is generated for communication between Internet of Things (IoT) devices; Identifying a source device and a target device of the IoT device; analyzing said content; determining the sensitivity of said content; and assigning a security level to either the source device or the target device based on said determining step; a processor in communication with the memory configured to perform operations including: A system for optimal IoT device security, comprising:

2. 10. The system of claim 1, wherein determining the sensitivity of the content comprises analyzing a calibrated database, wherein the calibrated database includes prefilled data indicating the sensitivity based on content type.

3. The system of claim 2 , wherein the calibrated data bank further includes an indication of a security level associated with the sensitivity.

4. The step of assigning the security level to either the source device or the target device comprises: identifying a predefined security level for the source device; identifying a predefined security level for the target device; and generating a median security level for the allocating step, the median security level being a combination of the predefined security levels for the source device and the target device; The system of claim 1 , comprising:

5. The processor further comprises: applying encryption to communications based on the assigned security level; The system of claim 1 configured to perform operations including:

6. The step of applying encryption to the communication comprises: Identifying what type of device each of the source device and the target device is; and increasing encryption of said communication based on said type. The system of claim 5 , comprising:

7. The processor further comprises: Procedures for continually analyzing said content for changes in sensitivity; and Steps for automatically updating the security level The system of claim 1 configured to perform operations including:

8. identifying, by a processor, that content is to be generated for communication between Internet of Things (IoT) devices; identifying a source device and a target device of the IoT device; Analyzing the content; determining the sensitivity of the content; and assigning a security level to either the source device or the target device based on the determining procedure; 1. A computer-implemented method for optimal IoT device security, comprising:

9. 10. The computer-implemented method of claim 8, wherein determining the sensitivity of the content includes analyzing a calibrated database, wherein the calibrated database includes prefilled data indicating the sensitivity based on content type.

10. The computer-implemented method of claim 9 , wherein the calibrated databank further includes an indication of a security level associated with the sensitivity.

11. The step of assigning the security level to either the source device or the target device comprises: identifying a predefined security level for the source device; identifying a predefined security level for the target device; and generating a median security level for the allocating step, the median security level being a combination of the predefined security levels for the source device and the target device. The computer-implemented method of claim 8 , comprising:

12. applying encryption of communications based on the assigned security level. The computer-implemented method of claim 8 further comprising:

13. applying encryption to the communication, Identifying what type of device each of the source device and the target device is; and Increasing encryption of said communication based on said type. The computer-implemented method of claim 12, comprising:

14. continuously analyzing said content for changes in sensitivity; and automatically updating the security level The computer-implemented method of claim 8 further comprising:

15. The processor Identifying that content is generated for communication between Internet of Things (IoT) devices; Identifying a source device and a target device of the IoT device; analyzing said content; determining the sensitivity of said content; and assigning a security level to either the source device or the target device based on said determining step; 1. A computer program product for optimal IoT device security, comprising: a computer-readable storage medium having embodied thereon program instructions executable by the processor to cause the processor to perform operations including:

16. 16. The computer program product of claim 15, wherein determining the sensitivity of the content includes analyzing a calibrated database, wherein the calibrated database includes prefilled data indicating the sensitivity based on content type.

17. 17. The computer program product of claim 16, wherein the calibrated databank further comprises an indication of a security level associated with the sensitivity.

18. The step of assigning the security level to either the source device or the target device comprises: identifying a predefined security level for the source device; identifying a predefined security level for the target device; and generating a median security level for the allocating step, the median security level being a combination of the predefined security levels for the source device and the target device; 16. The computer program product of claim 15, comprising:

19. The processor further comprises: applying encryption to communications based on the assigned security level; 16. The computer program product of claim 15 configured to perform operations including:

20. The step of applying encryption to the communication comprises: Identifying what type of device each of the source device and the target device is; and increasing encryption of said communication based on said type.

20. The computer program product of claim 19, comprising: