Classification-Based Data Security Management for IoT

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional universal data encryption policies fail to manage different types of data encryption and decryption effectively, unable to identify and utilize data attributes to customize security policies for various devices and data segments, leading to inefficient resource utilization and security operations in IoT and network devices.

Innovation Solution

Classification-based data security management that identifies attributes such as device resource availability, access trust score, data confidentiality score, geo-coordinates, and date/time value to customize encryption modes like full-encryption, minimal-encryption, and hybrid-encryption for secure data transmission, allowing for optimized resource allocation and efficient operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional universal data encryption policy is implemented, then data confidentiality is protected, but resource consumption increases and security operations become inefficient

Engineering Contradiction:
Improvedata confidentialityVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent applies local quality by classifying data into different types (e.g., critical data, non-critical data) and applying different encryption policies to each type. Instead of using a single universal encryption policy for all data, the system tailors encryption strength and resources based on the specific characteristics and sensitivity of each data type, thereby reducing unnecessary resource consumption while maintaining confidentiality where needed.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically adjusts encryption policies based on real-time factors such as device trust scores, data classification, and network conditions. The encryption mode (full-encryption, minimal-encryption, or no encryption) is dynamically selected and changed according to the current security context, allowing the system to optimize resource usage by applying strong encryption only when and where necessary.

Inventive Principle:
Principle #15Dynamics

2Reliability

If traditional universal data encryption policy is implemented, then data security is maintained, but ability to customize security policies for different devices and data segments is lost

Engineering Contradiction:
Improvedata securityVSAvoidcustomization capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements local quality by creating distinct security policies for different data types and device categories. The system identifies data attributes (such as data type, sensitivity level) and applies appropriate encryption policies locally to each segment, enabling customization without compromising overall security.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system segments the data and devices into different categories based on their characteristics and security requirements. By dividing the homogeneous universal policy into heterogeneous segment-specific policies, the system achieves both security and adaptability, allowing different encryption modes for different segments while maintaining unified security management.

Inventive Principle:
Principle #1Segmentation

3Use of energy by moving object

If classification-based data security management is implemented, then resource consumption is optimized, but system complexity increases

Engineering Contradiction:
Improveresource consumptionVSAvoidsystem complexity
Core Design Contradiction:
Use of energy by moving objectVSDevice complexity

Solution Approach 1:

The patent applies universality by implementing a unified security management system that handles multiple data types and device categories through a single framework. The system uses common classification mechanisms, trust score calculations, and policy enforcement processes across all segments, reducing the actual complexity increase by sharing common functionality rather than requiring separate complex systems for each data type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system incorporates feedback mechanisms where devices provide trust scores and data attributes are continuously monitored to adjust encryption policies. This automated feedback loop simplifies management by using algorithmic decision-making rather than manual configuration complexity, allowing the system to adapt dynamically without requiring complex user intervention or manual policy setup for each scenario.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12137125B2Classification-based data privacy and security management
Publication Date: 2024.11.05 CISCO TECHNOLOGY INC
  • US12137125B2 patent drawing
  • US12137125B2 patent drawing
  • US12137125B2 patent drawing

AI summary

Techniques are described for classification-based data security management. The classification-based data security management can include utilizing device and/or data attributes to identify security modes for communication of data stored in a source device. The security modes can be identified based on a hybrid-encryption negotiation. The attributes can include a device resource availability value, an access trust score, a data confidentiality score, a geo-coordinates value, and/or a date/time value. The security modes can include a hybrid-encryption mode. The source device can utilize the hybrid-encryption mode to transmit the data, via one or more network nodes, such as an edge node, to one or more service nodes.