Connected Object Security via Distributed Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Connected objects in IoT networks face security vulnerabilities due to insecure internet communications, making it difficult to identify and restore modified or hacked devices, as conventional solutions rely on centralized servers that can be compromised.

Innovation Solution

A method and system allowing connected objects to perform self-evaluations and group verifications, reducing the need for a central server, using periodic exchanges of information and warning signals to detect abnormalities and facilitate firmware updates securely, with symmetric or asymmetric cryptography for protection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If centralized server-based security verification is used, then security management is centralized, but the server can be compromised and individual object verification is insufficient

Engineering Contradiction:
Improvesecurity verification reliabilityVSAvoidcentralized server dependency
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the security verification system into distributed segments where each connected object performs verification independently with neighboring objects. Instead of relying on a single centralized server, the verification function is segmented across multiple objects in the network, eliminating the single point of failure and reducing overall system complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Connected objects perform self-verification and mutual verification with neighboring objects without requiring external server intervention. Each object autonomously checks the integrity of its neighbors by comparing operational states and detecting anomalies, enabling the system to self-monitor and self-protect against compromises.

Inventive Principle:
Principle #25Self-service

2Reliability

If individual cryptographic verification is performed on each connected object, then security is maintained, but detection of compromised objects becomes difficult when they stop responding

Engineering Contradiction:
Improvesecurity verificationVSAvoidcompromised object detection
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements continuous feedback loops where connected objects periodically exchange operational state information with neighboring objects. This creates multiple monitoring pathways so that if one object becomes compromised and stops responding, neighboring objects detect the absence of feedback and can identify the compromised object through anomaly detection algorithms.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The verification system dynamically adapts by continuously monitoring operational states and adjusting detection thresholds based on observed patterns. When objects are added or removed from the network, the verification relationships are dynamically reconfigured, ensuring that detection capabilities remain effective as the network topology changes over time.

Inventive Principle:
Principle #15Dynamics

3Reliability

If periodic self-evaluations and group verifications are implemented among connected objects, then security against malicious software is enhanced, but communication overhead and system complexity increase

Engineering Contradiction:
Improvesecurity against malicious softwareVSAvoidverification system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple verification functions into unified exchange messages that simultaneously perform identity verification, operational state monitoring, and anomaly detection. By merging these functions into single communication packets exchanged between neighboring objects, the system achieves comprehensive security verification without proportionally increasing communication overhead or processing complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The verification messages exchanged between connected objects serve multiple purposes: they verify cryptographic identities, monitor operational states, detect anomalies, and maintain network topology information. This multi-functionality allows the system to achieve enhanced security against malicious software while minimizing the increase in communication and processing requirements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If dynamic group topology is implemented where objects can be associated or dissociated, then unpredictability and security are enhanced, but system complexity and management difficulty increase

Engineering Contradiction:
Improvegroup securityVSAvoiddynamic topology management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent establishes predetermined verification protocols and cryptographic relationships that are configured in advance before objects join or leave the network. When dynamic topology changes occur, the pre-configured verification frameworks automatically adapt without requiring complex real-time reconfiguration, simplifying management of the dynamic group structure while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11303677B2Method and system for managing the operation of a group of several connected objects
Publication Date: 2022.04.12 STMICROELECTRONICS (GRAND OUEST) SAS
  • US11303677B2 patent drawing
  • US11303677B2 patent drawing
  • US11303677B2 patent drawing

AI summary

A method for managing the operation of a group of a plurality of connected objects includes exchanging information between two of the connected objects of the group. The information relates to a state of each connected object participating in the exchanging of information. The method also includes triggering an action on a connected object participating in the exchanging of information. The triggering is based on the information received by this object.