Connected Objects Mutual Entropy Sharing for IoT Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Connected objects in IoT networks face security vulnerabilities due to insecure internet communications, making it difficult to identify and restore modified or hacked devices without a server, which can be compromised by hackers.

Innovation Solution

A method and system that enables self-evaluation and grouped verification among connected objects, allowing them to perform periodic checks and restorations without relying on a central server, using symmetric or asymmetric cryptography for secure communication and firmware updates, and mutual entropy sharing for enhanced security and randomness.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a conventional cryptographic mechanism is used for each connected object individually, then security verification can be performed, but the system complexity increases and the ability to identify and restore hacked objects deteriorates when they disconnect from the server

Engineering Contradiction:
Improvesecurity verificationVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple connected objects into a group where they collectively perform security verification. Instead of each object operating independently with individual cryptographic mechanisms, the group acts as a unified entity that can verify and restore objects even when disconnected from external servers. This reduces system complexity while maintaining reliability.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The group of connected objects performs self-verification and self-restoration without requiring external server intervention. When an object is suspected of being hacked, the other objects in the group collectively verify its status and can restore it using their combined cryptographic resources, making the system self-sufficient and reducing overall complexity.

Inventive Principle:
Principle #25Self-service

2Ease of operation

If a central server is used to manage security for connected objects, then centralized control is achieved, but the server becomes a vulnerable target for hackers and a single point of failure

Engineering Contradiction:
Improvecentralized controlVSAvoidvulnerability to hacking
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments the centralized security management function into distributed components across multiple connected objects in a group. Instead of relying on a single central server that becomes a vulnerable target, the security verification and restoration capabilities are distributed among group members, eliminating the single point of failure while maintaining ease of operation through coordinated group action.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The group of connected objects acts as an intermediary between individual objects and external security management. Rather than objects directly relying on a vulnerable central server, the group collectively mediates security verification and restoration, distributing the trust model and reducing vulnerability to targeted attacks on centralized infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Difficulty of detecting and measuring

If periodic self-evaluations are implemented among connected objects, then the ability to identify compromised objects improves, but communication power consumption increases

Engineering Contradiction:
Improvedetection of compromised objectsVSAvoidcommunication power consumption
Core Design Contradiction:
Difficulty of detecting and measuringVSUse of energy by moving object

Solution Approach 1:

The patent implements periodic self-evaluations among connected objects in the group, where objects exchange security status information at regular intervals rather than continuously. This allows the system to maintain good detection capability for compromised objects while significantly reducing communication power consumption compared to continuous monitoring, as objects can enter low-power states between evaluation periods.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS20220147319A1Method and system for managing the operation of a group of several connected objects
Publication Date: 2022.05.12 STMICROELECTRONICS (GRAND OUEST) SAS
  • US20220147319A1 patent drawing
  • US20220147319A1 patent drawing
  • US20220147319A1 patent drawing

AI summary

In an embodiment a method for generating a random number includes selecting, by a first object, first symbols from an entropy pool of the first object, wherein the first object is an object of a group of mutually connected objects which are substantially identical, and wherein the entropy pool is fed with second symbols by objects of the group of mutually connected objects, applying, by the first object, a hash function to the first symbols to generate a random seed and generating, by the first object, the random number from the random seed.