Constrained IoT Device Firewall PCP Configuration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Constrained devices in IoT deployments are vulnerable to attacks, such as Denial of Service (DoS), due to their limited processing power and energy supply, which conventional firewall security rules are not designed to prevent, leaving them potentially vulnerable even when deployed behind a firewall.

Innovation Solution

A method for operating a constrained device within a network that involves receiving configuration information for an Attack Vector data Object and a Port Control Protocol (PCP) configuration data Object from a manager, and sending a PCP Request to the firewall to configure a policy that can identify and mitigate attacks based on defined attack methods and thresholds.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional firewall security rules are used to protect constrained devices, then network security against conventional threats is improved, but vulnerability to attacks targeting constrained device limitations (processing power, energy supply) worsens

Engineering Contradiction:
Improvesecurity protectionVSAvoidvulnerability to attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The security system is segmented into two parts: conventional firewall rules for standard threats and a specialized DoS protection mechanism for attacks targeting constrained devices. The PCP (Port Control Protocol) segments network traffic control, allowing the constrained device to request specific port blocking actions from the firewall without implementing complex protection logic locally.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The firewall acts as an intermediary between the constrained device and external network threats. Instead of requiring the constrained device to handle complex security decisions, the firewall intercepts and filters malicious traffic based on PCP policies, mediating between external threats and the vulnerable constrained device.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If constrained devices implement comprehensive security measures locally, then attack mitigation capability is improved, but device complexity and resource consumption worsen

Engineering Contradiction:
Improveattack mitigation capabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Complex security functionality is extracted from the constrained device and implemented externally in the firewall. The constrained device only needs to send simple PCP requests to block ports, while the firewall handles the complex task of monitoring traffic patterns, detecting DoS attacks, and enforcing security policies.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The constrained device maintains simplicity by implementing a self-service mechanism where it can autonomously request port blocking through PCP when it detects attack conditions, without requiring complex local security processing or external management intervention.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If constrained devices process and respond to excessive information requests during attacks, then responsiveness to legitimate requests is maintained, but device stability and crash resistance worsen

Engineering Contradiction:
ImproveresponsivenessVSAvoiddevice stability
Core Design Contradiction:
Ease of operationVSStability of the object's composition

Solution Approach 1:

The system performs preliminary action by pre-configuring PCP rules and thresholds for detecting DoS attacks. When attack conditions are met (excessive requests on specific ports), the constrained device automatically triggers port blocking before the attack can overwhelm the device, preventing crashes while maintaining responsiveness to legitimate traffic.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12316607B2Methods and apparatus for operating and managing a constrained device within a network
Publication Date: 2025.05.27 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US12316607B2 patent drawing
  • US12316607B2 patent drawing
  • US12316607B2 patent drawing

AI summary

A method (200) is disclosed for operating a constrained device within a network, the network comprising a firewall deployed between the constrained device and a manager. The method comprises receiving from the manager configuration information for an Attack Vector data Object and a Port Control Protocol (PCP) configuration data Object on the constrained device (210). The configuration information comprises a value for a Resource in the Attack Vector data Object (210a) and a value for a Resource in the PCP configuration data Object (210b). The method further comprises sending a PCP Request to the firewall in accordance with the PCP configuration data Object, the PCP Request including the Resource value for the Attack Vector data Object received in the configuration information (220). Also disclosed are methods (400, 500) and apparatus for managing a constrained device.