Adaptive Security for Resource-Constrained IoT Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Computing resource-constrained devices, such as IoT devices, face challenges in effectively protecting against cyberattacks due to limited resources, which existing security systems struggle to manage efficiently, leading to high power consumption and resource demands.

Innovation Solution

A method and system that collect threat intelligence data in the form of indicators of compromise (IoC) to determine the relevance and resource consumption of security measures, enabling selective enabling and disabling of security measures to optimize resource usage and prioritize effective protection against cyberattack chains.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If comprehensive security measures are deployed to protect against cyberattacks, then protection level is improved, but resource consumption increases

Engineering Contradiction:
Improveprotection levelVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The security system dynamically adjusts the activation state of security measures based on real-time threat assessments and resource availability. The system transitions between different security postures, enabling comprehensive protection when threats are detected and reducing resource consumption when threats are low, thereby resolving the contradiction between maintaining high protection levels and managing resource usage on constrained devices.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes operational parameters of security measures based on contextual factors such as threat level, device state, and resource availability. By adjusting parameters like detection sensitivity, response intensity, and measurement frequency, the system optimizes the balance between protection effectiveness and resource consumption, allowing comprehensive security when needed while conserving resources during normal operation.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If multiple security measures are activated simultaneously, then detection capability is improved, but device complexity increases

Engineering Contradiction:
Improvedetection capabilityVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The security system segments detection capabilities into modular security measures that can be independently activated. Each security measure focuses on specific threat vectors or device components, allowing the system to achieve comprehensive detection capability by selectively combining simple, specialized modules rather than deploying a single complex security system. This segmentation reduces overall system complexity while maintaining high detection precision.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system activates only the necessary subset of security measures required to address current threats and device contexts, rather than enabling all security features simultaneously. By applying partial action principles, the system achieves sufficient detection capability for specific scenarios without the overhead of maintaining all possible security measures active, thereby managing device complexity while preserving essential detection precision.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11539737B2Adaptive security for resource constraint devices
Publication Date: 2022.12.27 KYNDRYL INC
  • US11539737B2 patent drawing
  • US11539737B2 patent drawing
  • US11539737B2 patent drawing

AI summary

A method for providing protection of a computing resource constrained device against cyberattacks may include collecting threat intelligence data in form of indicators of compromise (IoC). The indicators may include cyberattack chain related data. The method may also include determining a relevance of the cyberattack chain for the device, measuring a utilization of security measures in terms of their detection of the respective IoCs and their respective responses to the IoCs, measuring a resource consumption of the security measures, and determining a benefit value for at least one the security measure expressed by its utilization and a relevance value of the IoCs detected with it.