Digital Twin-Based IoT Device Security Inspection System for Cyberattack Response

KR103024683B1Active Publication Date: 2026-09-29SECUREPONIT CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
KR1020250154680
Authority / Receiving Office
KR · KR
Patent Type
Patents
Current Assignee / Owner
Filing Date
2025-10-23
Publication Date
2026-09-29
Estimated Expiration
2045-10-23

Smart Images

  • Figure 112025118413122-PAT00002_ABST
    Figure 112025118413122-PAT00002_ABST
Patent Text Reader

Abstract

The present invention relates to a digital twin-based IoT equipment security inspection system for cyber attack response that supports the operation of IoT equipment in a safer security environment by constructing a digital twin-based test bed for security inspection of IoT equipment and simulating a response to a virtual cyber attack.
Need to check novelty before this filing date? Find Prior Art

Description

Technology Field

[0001] The present invention relates to an IoT equipment security inspection system, and more specifically, to a digital twin-based IoT equipment security inspection system for cyber attack response that supports the operation of IoT equipment in a safer security environment by constructing a digital twin-based test bed for security inspection of IoT equipment and simulating a response to a virtual cyber attack. Background Technology

[0002] The recent advancement of the Internet of Things (IoT) is providing innovative services through intelligent interconnections between people and objects, and between objects themselves.

[0003] However, behind this convenience lies a serious security threat. Specifically, IoT technology adopts wireless communication as its primary means to facilitate connectivity between devices, creating an open environment for easy access to the network. This results in the IoT environment being critically exposed to various forms of cyber attacks that threaten key elements of information security, such as confidentiality, integrity, and availability.

[0004] Traditional security solutions to date, such as firewalls, intrusion detection systems, and IDS, are primarily designed to focus on the moment an 'intrusion' occurs. As a result, once an attacker has breached the security system, the likelihood of detecting the threat decreases. Particularly in the case of APT (Advanced Persistent Threat) attacks, it often takes a relatively long time from the intrusion until the threat is actually discovered, allowing attackers time to remain hidden for an extended period to steal information or paralyze the system.

[0005] As an alternative to these passive methods, active cyber defense techniques such as Intelligence Cyber ​​Threat Hunting have emerged. This proactively and iteratively searches for threats that are already latent within the network but cannot be detected by existing solutions.

[0006] However, most currently commercialized threat hunting platforms are focused on general enterprise environments, making them difficult to apply directly to complex IoT or industrial control system environments. Furthermore, while it is necessary to master advanced cyber technologies through preliminary analysis before conducting threat hunting, achieving technical proficiency is challenging due to the lack of actual attack experience and secure analysis environments.

[0007] In addition, while general corporate environments face difficulties in analysis due to reasons such as red team operations and security issues, the IoT environment presents significant challenges in defending against such threats due to its unique environmental characteristics. Furthermore, it is realistically difficult to operate specialized industrial IoT attack teams, and the pool of domestic offensive security experts is limited.

[0008] For threat analysis to be effective, it must be performed in an environment similar to the target system; however, due to the diversity and complexity of IoT environments, it is currently difficult to establish a secure cyber threat analysis environment that mimics the actual environment. Therefore, there is an urgent need to develop a new level of proactive security inspection system that reflects the characteristics of the IoT environment and can fundamentally resolve the aforementioned problems. Prior art literature

[0009] Republic of Korea Published Patent No. 10-2023-0076593 (May 31, 2023) The problem to be solved

[0010] The present invention was created in response to the aforementioned needs, and the objective of the present invention is to provide a digital twin-based IoT equipment security inspection system for cyber attack response that supports the safe operation of IoT equipment by establishing a digital twin-based IoT security testbed to ensure the security of various equipment used in IoT environments and devising cyber attack and response measures.

[0011] Another objective of the present invention is to provide a digital twin-based IoT equipment security inspection system that can proactively prevent privacy infringement of users or the surrounding environment by actively driving a protection module installed in the IoT equipment according to detected threats or predicted attack patterns, and can safely simulate and verify the risk of privacy exposure due to hacking or environmental tampering in a digital twin virtual space without affecting the operation of the actual equipment. means of solving the problem

[0012] For the above purposes, the present invention relates to an IoT equipment security inspection system applicable to an IoT equipment capable of acquiring images of a designated area including a camera capable of controlling the shooting direction, comprising: an information collection module that receives area information where the IoT equipment is installed and device information of the installed IoT equipment, and collects information collected from the IoT equipment in real time; a first simulation module having a modeling unit that creates a virtual space reproduced as a digital twin based on the area information and device information, and a matching unit that matches information collected through the information collection module to the virtual space; a second simulation module having a storage unit in which an attack tool for a cyber attack is set and stored, and a virtual attack unit that selects the attack tool against the virtual space and performs a cyber attack; a threat detection module that detects an abnormal state by analyzing data generated in the virtual space; and a response derivation module that outputs response information according to the abnormal state and the corresponding attack tool in the form of a report.

[0013] At this time, a third simulation module comprising a modulation information generation unit that generates modulation information based on the zone information and a virtually input object, and a test unit that applies the modulation information to the virtual space; and a tracking module that tracks changes in virtual space data in response to the operation of the test unit; wherein the corresponding solution derivation module may include the data of the tracking module in a report.

[0014] Additionally, it may further include a protection module comprising a blocking means that blocks the shooting of the camera, and a driving unit that moves the blocking means by an applied driving signal and allows normal shooting of the camera.

[0015] Additionally, the above-mentioned interference means includes a diffuser that diffuses light to lower image clarity, a prism that distorts the image through a regular grid pattern, a gobo mask that causes a set object to be superimposed on the captured image, and a light-blocking plate that blocks light, and the driving unit may be configured such that the diffuser, the prism, the gobo mask, and the light-blocking plate are selectively positioned in front of the camera lens.

[0016] In addition, the protection module may further include a monitoring unit that recognizes objects within a designated area and monitors the presence or absence of objects over time, and a setting unit that analyzes the monitoring results of the monitoring unit and generates a driving signal reflecting a time period specified by the user and applies it to the driving unit.

[0017] Additionally, the learning module may further include a temporary storage unit that classifies and stores abnormal conditions detected by the threat detection module and monitoring results of the monitoring unit; a pattern analysis unit that analyzes the stored data of the temporary storage unit to generate and store pattern information according to the data type; a pattern prediction unit that analyzes real-time data of the IoT equipment, compares and analyzes it with the pattern information, and outputs an expected pattern according to the degree of match; and a signal update unit that generates a driving signal according to the expected pattern and applies it to the driving unit. Effects of the invention

[0018] Through the present invention, physical systems and digital systems can be linked in real time to monitor, analyze, and respond to security threats. In particular, through a digital twin that reflects actual system data in real time, the system status can be continuously monitored to rapidly detect and respond to potential security threats.

[0019] Furthermore, by performing simulated attack and environment tampering tests in a digital twin-based virtual space rather than on actual IoT equipment, security vulnerabilities can be safely checked and threats predicted without the risk of system damage. This significantly reduces the difficulties and costs associated with establishing a test environment and maximizes the safety and efficiency of security inspections.

[0020] In addition, based on hacking threat information detected or predicted in a virtual space, the protection module of the actual IoT device physically obstructs camera recording, thereby physically blocking user privacy infringements such as video leakage or illegal filming resulting from hacking attempts in advance.

[0021] In addition, by integrating and analyzing threat patterns and actual monitoring results (presence of objects, time zones, etc.), the protection module is activated only at the optimal time when privacy protection is needed, minimizing unnecessary interference with recording while enabling accurate response in situations with a high risk of security threats and privacy exposure. Brief explanation of the drawing

[0022] FIG. 1 is a conceptual diagram of the present invention, FIG. 2 is a block diagram showing the system configuration and connection relationships according to an embodiment of the present invention. FIGS. 3 to 5 are conceptual diagrams of a protection module according to an embodiment of the present invention. Specific details for implementing the invention

[0023] The digital twin-based IoT equipment security inspection system for responding to cyber attacks according to the present invention will be described in detail below with reference to the attached drawings.

[0024] FIG. 1 is a concept of the present invention, and the present invention is an IoT equipment security inspection system applied to IoT equipment capable of acquiring images of a designated area including a camera capable of controlling the shooting direction, wherein the IoT equipment in the present invention is an image-based IoT equipment including a camera (lens, image sensor), a control unit, a communication unit, etc.

[0025] This includes various devices that acquire images of an area and transmit information through a network, such as surveillance cameras (CCTV) and network cameras (IP Camera). Since it transmits and receives data based on the Internet Protocol (IP) through the communication unit (220) and operates by receiving external control commands, it serves as the basis for interaction between devices and intelligent services.

[0026] The camera (210) included in the IoT equipment can remotely control the shooting direction or focus, such as with a PTZ (Pan-Tilt-Zoom) function, and the communication unit (220) mainly uses wireless communication such as Wi-Fi, LTE, and 5G and is exposed to an open environment, and since sensitive video information is continuously acquired through the camera (210), there is a very high risk of privacy infringement, such as video theft or illegal filming due to hacking.

[0027] The present invention supports the safe operation of IoT equipment by establishing a digital twin-based IoT security testbed to ensure the security of such IoT equipment (200) and by providing measures against cyber attacks and countermeasures.

[0028] FIG. 2 is a block diagram showing the system configuration and connection relationship according to an embodiment of the present invention. The present invention includes, as a main configuration, an IoT device (200), an information collection module (110), a first simulation module (120), a second simulation module (130), a third simulation module (140), a tracking module (150), a threat detection module (160), a tracking module (150), and a response derivation module (170).

[0029] The above information collection module (110) receives area information where IoT equipment is installed and device information of the installed IoT equipment, and collects information collected from the above IoT equipment (200) in real time.

[0030] That is, information for virtual space modeling and physical system modeling according to digital twin construction is collected for a space that can be captured through the camera of the IoT equipment. This includes receiving area information such as the location, size, and purpose of the space where the IoT equipment is installed, as well as device information of the installed IoT equipment (200). Furthermore, connection settings and real-time data linkage with the sensor and the IoT equipment (200) are established so that data generated from the IoT equipment can be reflected in the digital twin in real time.

[0031] The first simulation module (120) is a digital twin construction module configured to create a virtual space that is a digital twin by integrating data in conjunction with the information collection module (110) and collecting data from IoT equipment (200) in real time and reflecting it in the digital twin. It is equipped with a modeling unit (121) that creates a virtual space reproduced as a digital twin based on the zone information and device information, and a matching unit (122) that matches the information collected through the information collection module (110) to the virtual space.

[0032] The purpose of the digital twin according to the present invention is set to be for responding to security threats, and it reproduces all physical components of the space where the IoT equipment (200) is installed in a digital environment. Hardware modeling that maps the accurate functions and operations of the IoT equipment, and environment modeling that digitizes information such as the internal layout of the space and various fixed objects existing in the space are performed, thereby creating a virtual space that perfectly reproduces the physical environment and the logical / physical state of the IoT equipment (200) as a digital twin based on zone information and device information.

[0033] To this end, the modeling unit (121) creates a virtual space that perfectly reproduces the logical / physical state of the physical environment and IoT equipment (200) as a digital twin based on zone information and device information, and the matching unit (122) matches, i.e., synchronizes, the operational information of the actual IoT equipment collected through the information collection module (110) with the digital twin model of the virtual space in real time, so that the virtual space accurately reflects the current state of the actual system.

[0034] To collect data from IoT devices, data can be transmitted and received using protocols such as REST API, MQTT, and WebSocket; furthermore, large amounts of data can be processed in real time using Kafka or MQTT, enabling real-time data streaming.

[0035] In addition, to build a digital twin platform capable of integrating and analyzing data, commercial platforms such as Siemens MindSphere, GE Predix, and Microsoft Azure Digital Twins can be used, or customized platforms that build a Python-based simulation and data analysis environment can be used, and data models are created and applied to digitally reproduce data from physical systems.

[0036] The second simulation module (130) is equipped with a simulation engine capable of testing threats and countermeasures by virtually reproducing a real environment to test security threats and countermeasures, and is composed of a storage unit (131) in which various cyber attack scenarios and necessary attack tools are pre-set and stored, and a virtual attack unit (132) that tests potential vulnerabilities without damaging actual equipment by selecting an attack tool from the storage unit (131) and performing a cyber attack on the digital twin virtual space.

[0037] This is a closed testbed where various cyber attacks can be executed without affecting the actual operating environment, and the attack tool is a tool for checking security vulnerabilities of IoT equipment (200), and can use attack tools pre-written to match attack scenarios such as malware that damages the system or steals information using malicious software, DDoS attacks that cause an overload on the server or network and disrupt services, and authentication and authorization failures.

[0038] This second simulation module (130) performs tests to evaluate and strengthen the security of the IoT equipment environment, thereby discovering security vulnerabilities of the organization, improving response capabilities, and minimizing damage in the event of an actual attack.

[0039] The third simulation module (140) is configured to simulate non-cyber threat scenarios, such as external environmental changes or physical modifications, in a virtual space implemented as a digital twin to check the security and potential for malfunction of the IoT equipment (200). It is equipped with a modification information generation unit (141) that generates environmental / physical modification information, such as environmental changes or object movements, based on the zone information and virtual objects, and a test unit (142) that applies the modification information to the virtual space to test the potential for malfunction and security vulnerabilities of the IoT equipment due to environmental changes.

[0040] The above modulation information generation unit (141) generates various types of modulation information for simulation, which can be broadly divided into the following two categories. First, based on actual area information, there is environmental modulation that generates natural / artificial environmental changes that may affect the sensor or camera recognition of the IoT equipment (200), such as changes in illumination such as sudden loss of light source or excessive flash, or weather changes such as fog, rain, snow, or dust in the case of an external area. Next, there is virtual object-based modulation that generates scenarios that cause malfunction of the IoT equipment by abnormally manipulating the attributes or movements of objects entered into the virtual space, such as a person, such as camera view obstruction, such as an act of a virtual object or hand covering the camera lens, inducing misrecognition that causes object recognition errors by inserting a specific pattern, or abnormal movement of a virtual object.

[0041] The test unit (142) performs the role of applying modulation information generated by the modulation information generation unit (141) to the digital twin virtual space to perform actual tests, and injects generated environmental variables or abnormal behavior of virtual objects into the virtual space. For example, it can simulate actions such as suddenly setting the illumination of a virtual object in front of the camera lens of an IoT device in the virtual space to 0 or inserting a virtual light shield, and when modulation information is applied, it induces the IoT device (200) implemented as a digital twin model to react to this and output data. This reaction data is subsequently analyzed through the tracking module (150).

[0042] The tracking module (150) is configured to track changes in virtual space data in response to the operation of the test unit (142). In response to whether the test unit (142) is tampering, the tracking module tracks in real time how virtual space data changes, such as changes in image quality, sensor values, and the processing speed of the equipment. This information is then transmitted to the response derivation module (170), which will be described later, and included in the report. Through this, the master can clearly identify not only simple cyber attack response but also the vulnerability and resilience of the IoT equipment against physical environmental threats.

[0043] The threat detection module (160) is configured to detect security threats, which are abnormal signals, by analyzing data in the virtual space during the operation of the second simulation module (130) and the third simulation module (140). It records data generated during a cyber attack through the second simulation module (130) and analyzes it to derive vulnerabilities and security improvement points. That is, it detects as abnormal signals cases where the cyber attack on the virtual space through the second simulation module (130) deviates from the normal signal range set during the IoT equipment system design. Through this, security weaknesses in networks, systems, applications, etc., can be discovered, the effectiveness of reapplied security policies and defense systems can be evaluated, threat detection and response capabilities can be verified, and the expected impact in the event of an actual attack can be measured.

[0044] The above response derivation module (170) derives optimal response information based on the detected abnormal state and the corresponding attack tool or tampering information, and outputs this in the form of a report, while including data from the above tracking module (150) in the report. That is, it identifies and reports security vulnerabilities regarding attack tools through abnormal signals and abnormal changes in data generated by the threat detection module (160) and the tracking module (150), and outputs response information in the form of a report by searching for and recommending response measures against the used attack tool and data tampering in a pre-stored cyber attack response information DB.

[0045] For example, measures can be presented such as recommending security solutions to respond to cyber attacks, strengthening network design and architecture, filtering abnormal IPs or traffic patterns at routers or firewalls, blocking abnormal requests by limiting specific IPs or request counts, and managing network traffic to prevent server overload by limiting the number of concurrent requests. Furthermore, response information for responding to and preventing data tampering includes data integrity assurance technologies such as encryption to make unauthorized modification difficult, digital signatures to verify the original state of data, and hash functions to confirm that data has not been altered; network security enhancements such as TLS / SSL to prevent tampering through encryption during data transmission and VPNs to provide secure network paths; application security enhancement technologies such as input validation to prevent SQL injection and tampering by thoroughly verifying user input values, and static and dynamic code analysis to eliminate potential vulnerabilities in code; and monitoring technologies such as log monitoring to rapidly detect traces of tampering and the use of IDS / IPS equipped with intrusion detection and prevention systems.

[0046] FIGS. 3 to 5 are conceptual diagrams of a protection module according to an embodiment of the present invention. In an embodiment of the present invention, a protection module (180) is installed on the front of an IoT device (200) to perform physical defense against cyber threats.

[0047] The above protection module (180) is configured based on a closed circuit not connected to an external network or an independent microcontroller unit (MCU) for the purpose of protecting privacy by interfering with the normal shooting of the camera (210) in situations where there is a cyber attack on the IoT equipment (200) or a possibility thereof. This independent configuration enables the protection module (180) to reliably perform its unique privacy protection function without being affected by direct hacking attempts from the outside, even if the main processor of the IoT equipment (200) is hacked or becomes uncontrollable due to a cyber attack.

[0048] Specifically, the protection module (180) is provided with a blocking means (181) that physically blocks the shooting of the camera (210) of the IoT equipment (200), and a driving unit (186) that moves the blocking means (181) by an applied driving signal to position it in front of the camera lens or remove it to allow normal shooting.

[0049] In the present invention, the obstruction means (181) includes a diffuser (182) that diffuses light to lower the clarity of the image, a prism (183) that distorts the image through a regular grid pattern, a gobo mask (184) that causes a set object to be superimposed on the image being captured, and a light-blocking plate (185) that blocks light, and the driving unit (186) is configured such that the diffuser (182), the prism (183), the gobo mask (184), and the light-blocking plate (185) are selectively positioned in front of the camera (210) lens.

[0050] The above diffuser (182) is a filter that diffuses light to lower the clarity of the image, thereby lowering the risk of privacy infringement by making it impossible to identify the subject or details while the image itself is acquired. It is useful when a hacking risk is detected but monitoring of personnel entering the site or the operating status (On / Off) of equipment must be maintained at a minimum level.

[0051] The above prism (183) distorts the image obtained using a regular grid pattern or a specific optical pattern, maintaining data integrity but causing it to lose its value as actual image information, thereby hindering malicious image analysis. It is useful when security of a specific area is important but widespread disabling of camera functions must be avoided.

[0052] The above-mentioned gobo mask (184) has specific objects set to intentionally alter the image, such as a ‘privacy protection in progress’, ‘no recording’ watermark, and a black block pattern, and these are superimposed on the video being filmed. It is useful when essential information is obscured, when it is clear that the video is illegally leaked, when an intentionally altered video is provided, when hacking is already in progress, or when a physical stamp needs to be left on the video itself.

[0053] The light-blocking plate (185) is an opaque plate that completely blocks light and completely covers the camera (210) lens so that no image information can be obtained. It is useful when the risk of hacking is very high or when absolute privacy protection is required during a user-specified time period.

[0054] The above driving unit (186) is a device that physically drives the four obstruction means. In an embodiment of the present invention, the four mentioned are stacked in the form of slide filters and are configured to be positioned in front of the camera (210) lens through selective positional movement while adjacent to the camera (210) lens. To this end, the slide filters are stacked and stored with through holes formed in different directions at the center of rotation, and the driving unit (186) can be configured to rotate only the selected obstruction means through a lead screw position adjustment mechanism for the forward and backward position of a precision control motor having a rotation axis with a protrusion corresponding to the groove.

[0055] At this time, the driving unit (186) selectively places one of a diffuser (182), a prism (183), a gobo mask (184), and a light-blocking plate (185) in front of the camera lens according to a driving signal applied from the monitoring unit (187) or setting unit (188) or an external command described later, and when there is no driving signal, all obstructing means (181) are removed from the front of the camera (210) lens so that the camera can perform normal shooting.

[0056] The monitoring unit (187) recognizes objects within a designated area and monitors the presence or absence of objects over time to measure the risk of privacy exposure. Monitoring is performed independently of external signals, ensuring safety from hacking. To this end, the monitoring unit (187) protects privacy by including object detection sensors, such as PIR (Passive Infrared) sensors, ultrasonic sensors, or low-resolution / non-image-based thermal imaging sensors, which detect only the presence or absence of 'people' within the designated area and output the information as binary data or simple distance / motion signals. It continuously tracks changes in the presence or absence of objects over time by analyzing the data collected from these sensors. For example, it can record 'the time a person enters the area,' 'the time a person leaves the area,' and 'the time spent within the area.' Based on the data regarding the presence or absence of objects and the time spent, it determines whether there is a subject requiring privacy protection in the current area.

[0057] The setting unit (188) generates a driving signal by reflecting the analysis results of the monitoring unit (187) and a time period designated by the user, such as the time required for privacy protection, and applies this to the driving unit (186). That is, it analyzes the record of the presence or absence of objects in the monitoring unit (187), combines it with a privacy protection time period designated in advance by the user, such as private time or confidential work time, and when there is a complex situation such as when a person is present as a result of the analysis and it is within the designated protection time period, or when an abnormal state is detected by the threat detection module (160), it can apply a driving signal to the driving unit (186) to activate the interference means.

[0058] In addition, the protection module (180) receives a response plan derived from the virtual space simulation and analysis unit (120-170) manually, or generates a driving signal based on the independent privacy monitoring result of the setting unit (188), so that when a hacking risk occurs or privacy protection is needed, it immediately activates a means of interference to physically interfere with the shooting.

[0059] Through this configuration, the present invention establishes a dual defense system that provides the effect of predicting safe and realistic security vulnerabilities and deriving countermeasures through a digital twin, as well as a stable physical privacy protection function that is not affected even in the event of a hacking threat through a protection module (180) composed of an independent closed circuit. This can contribute to significantly improving the reliability of IoT equipment security.

[0060] The above learning module (190) is an intelligent module that integrates the system's threat detection results and actual environment monitoring results to generate an optimal predicted pattern for the security and privacy protection of the IoT equipment (200) and to update the driving signal. In particular, the system is equipped with a temporary storage unit (191), a pattern analysis unit (192), a pattern prediction unit (193), and a signal update unit (194) to predict and respond to the risk of privacy infringement that occurs when a hacking attempt targeting fixed vulnerabilities, such as failure to change the initial password, is combined with a resident's specific lifestyle pattern.

[0061] The above temporary storage unit (191) is configured to store abnormal state information detected by the threat detection module (160) and monitoring results of the monitoring unit (187), thereby enabling the identification of cyber threat patterns associated with voyeurism, such as repeated login attempts exploiting the weak initial password or default password of the IoT device, and continuous port scanning in a specific IP address range. For example, it accurately records data on the resident's lifestyle patterns, such as specific time periods when no one is present, such as 10:00 AM to 5:00 PM on weekdays, or specific behavioral patterns such as the absence of an object for a long period, thereby providing basic data for analyzing the temporal / situational correlation between the time of cyber threat occurrence and the actual resident's lifestyle patterns.

[0062] The above pattern analysis unit (192) is configured to analyze integrated data stored in the temporary storage unit (191) to generate and store pattern information according to the data type, thereby deriving a combined pattern between cyber attack types and resident lifestyle patterns. For example, a pattern can be generated and stored as pattern information in which hacking attempts are minimal during times when no one is present, but login attempts exploiting the initial password are concentrated during times when someone is present. This can serve as a basis for proving the hypothesis with data that an attacker uses the resident's pattern (time of presence) to maximize the effect of peeping, and for building a customized defense logic to respond to this.

[0063] The pattern prediction unit (193) is configured to predict future threat or privacy risk situations by analyzing the current state of the IoT equipment (200). It compares real-time data of the current IoT equipment with stored pattern information to predict whether the current time is the time when hackers are expected to be most active. As an example of the prediction process, the current time and data on the presence or absence of current objects from the monitoring unit (187) are input, and this data is compared with pattern information to calculate the degree of agreement, which indicates the extent to which the current time matches a high-risk time period in terms of pattern, i.e., a time period of concentrated voyeurism. The higher the degree of agreement, the higher the risk of privacy infringement due to hacking threats, and the predicted pattern provides intelligent threat prediction information based on lifestyle patterns that goes beyond simple threat detection.

[0064] When a high-risk predicted pattern is output from the pattern prediction unit (193), the signal update unit (194) updates the driving signal to immediately select the most powerful privacy intrusion means and applies it to the driving unit (186). By doing so, the system predicts the most vulnerable and dangerous moment when a hacker attempts to peek with peace of mind while a resident is absent, and even if no one is present, it activates the protection module to physically interfere with filming, thereby blocking privacy infringement at the source.

[0065] The rights of the invention are not limited to the embodiments described above but are defined by what is stated in the claims, and it is obvious that a person skilled in the art may make various modifications and adaptations within the scope of the rights stated in the claims. Explanation of the symbols

[0066] 110: Information Collection Module 120: 1st Simulation Module 121: Modeling Section 122: Matching Section 130: 2nd Simulation Module 131: Storage Unit 132: Virtual Attack Unit 140: 3rd Simulation Module 141: Modification Information Generation Unit 142: Test Unit 150: Trace Module 160: Threat Detection Module 170: Response Derivation Module 180: Protection Module 181: Disruption means 182: Diffuser 183: Prism 184: Gobo Mask 185: Sunshade 186: Drive unit 187: Monitoring Section 188: Configuration Section 190: Learning Module 191: Temporary Storage 192: Pattern Analysis Department 193: Pattern Prediction Department 194: Signal Updater 200: IoT Equipment 210: Camera 220: Communications Unit

Claims

Claim 1 An IoT equipment security inspection system applied to an IoT equipment (200) capable of acquiring images of a designated area, including a camera (210) capable of controlling the shooting direction, comprising: an information collection module (110) that receives information about the area where the IoT equipment (200) is installed and device information of the installed IoT equipment (200), and collects information collected from the IoT equipment (200) in real time; a first simulation module (120) having a modeling unit (121) that creates a virtual space reproduced as a digital twin based on the area information and device information, and a matching unit (122) that matches information collected through the information collection module (110) to the virtual space; a second simulation module (130) having a storage unit (131) in which an attack tool for a cyber attack is set and stored, and a virtual attack unit (132) that selects the attack tool and performs a cyber attack targeting the virtual space; and an environmental / physical modulation information generated based on the area information and a virtual input object. A third simulation module (140) comprising a modulation information generation unit (141) and a test unit (142) that applies the modulation information to the virtual space to test the possibility of malfunction and security vulnerability of the IoT equipment; a tracking module (150) that tracks changes in virtual space data in response to the operation of the test unit (142); a threat detection module (160) that detects abnormal conditions by analyzing data generated in the virtual space; and a response plan derivation module (170) that outputs a report including response information according to the abnormal condition and the corresponding attack tool and data from the tracking module (150).The device is equipped with a protection module (180) installed on the front of the camera (210), which is configured as a closed circuit based on an independent microcontroller unit that is not connected to an external network and operates independently even when the main processor of the IoT device is hacked. The protection module (180) includes a interference means (181) comprising a diffuser (182) that diffuses light to lower image clarity, a prism (183) that distorts the image through a grid pattern, a gobo mask (184) that causes a set object to appear superimposed on the image, and a light-blocking plate (185) that completely blocks light; a driving unit (186) that moves the interference means (181); a monitoring unit (187) that recognizes objects within a designated area and monitors the presence or absence of objects over time; and a setting unit (188) that analyzes the monitoring results of the monitoring unit (187), generates a driving signal reflecting a time period specified by the user, and applies it to the driving unit (186). The driving unit (186) is configured to selectively rotate and position one of the diffuser, prism, gobo mask, and light shield plate in front of the camera lens through a lead screw position adjustment mechanism that adjusts the front and rear position of a motor having a rotation axis with a protrusion formed corresponding to the groove, while obstruction means in the form of a slide filter having a through hole with a groove formed in a different direction at the center of rotation are overlapped; and the learning module (190) comprises a temporary storage unit (191) that classifies and stores abnormal conditions detected by the threat detection module (160) and monitoring results of the monitoring unit (187), a pattern analysis unit (192) that analyzes the stored data of the temporary storage unit (191) to generate and store pattern information according to the data type, a pattern prediction unit (193) that analyzes real-time data of the IoT equipment, compares and analyzes it with the pattern information, and outputs an expected pattern according to the degree of match, and a signal update unit (194) that generates a driving signal according to the expected pattern and applies it to the driving unit (186). A digital twin-based IoT equipment security inspection system characterized by further including Claim 2 delete Claim 3 delete Claim 4 delete Claim 5 delete Claim 6 delete

Citation Information

Patent Citations

  • Surveillance camera having lens blocking function

    KR1020200133645A

  • Unmanned camera for defending light attack and controlling method thereof

    KR102088956B1

  • Digital twin-based security assessment system for responding to security threats

    KR102864006B1