Constrained IoT Device Firewall PCP Configuration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Constrained devices in IoT deployments are vulnerable to attacks, such as Denial of Service (DoS), due to their limited processing power and energy supply, which conventional firewall security rules are not designed to prevent, leaving them potentially vulnerable even when deployed behind a firewall.
Innovation Solution
A method for operating a constrained device within a network that involves receiving configuration information for an Attack Vector data Object and a Port Control Protocol (PCP) configuration data Object from a manager, and sending a PCP Request to the firewall to configure a policy that can identify and mitigate attacks based on defined attack methods and thresholds.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional firewall security rules are used to protect constrained devices, then network security against conventional threats is improved, but vulnerability to attacks targeting constrained device limitations (processing power, energy supply) worsens
Solution Approach 1:
The security system is segmented into two parts: conventional firewall rules for standard threats and a specialized DoS protection mechanism for attacks targeting constrained devices. The PCP (Port Control Protocol) segments network traffic control, allowing the constrained device to request specific port blocking actions from the firewall without implementing complex protection logic locally.
Solution Approach 2:
The firewall acts as an intermediary between the constrained device and external network threats. Instead of requiring the constrained device to handle complex security decisions, the firewall intercepts and filters malicious traffic based on PCP policies, mediating between external threats and the vulnerable constrained device.
2Reliability
If constrained devices implement comprehensive security measures locally, then attack mitigation capability is improved, but device complexity and resource consumption worsen
Solution Approach 1:
Complex security functionality is extracted from the constrained device and implemented externally in the firewall. The constrained device only needs to send simple PCP requests to block ports, while the firewall handles the complex task of monitoring traffic patterns, detecting DoS attacks, and enforcing security policies.
Solution Approach 2:
The constrained device maintains simplicity by implementing a self-service mechanism where it can autonomously request port blocking through PCP when it detects attack conditions, without requiring complex local security processing or external management intervention.
3Ease of operation
If constrained devices process and respond to excessive information requests during attacks, then responsiveness to legitimate requests is maintained, but device stability and crash resistance worsen
Solution Approach 1:
The system performs preliminary action by pre-configuring PCP rules and thresholds for detecting DoS attacks. When attack conditions are met (excessive requests on specific ports), the constrained device automatically triggers port blocking before the attack can overwhelm the device, preventing crashes while maintaining responsiveness to legitimate traffic.
Data Source
AI summary
A method (200) is disclosed for operating a constrained device within a network, the network comprising a firewall deployed between the constrained device and a manager. The method comprises receiving from the manager configuration information for an Attack Vector data Object and a Port Control Protocol (PCP) configuration data Object on the constrained device (210). The configuration information comprises a value for a Resource in the Attack Vector data Object (210a) and a value for a Resource in the PCP configuration data Object (210b). The method further comprises sending a PCP Request to the firewall in accordance with the PCP configuration data Object, the PCP Request including the Resource value for the Attack Vector data Object received in the configuration information (220). Also disclosed are methods (400, 500) and apparatus for managing a constrained device.


