Digital Twin Intrusion Detection for Embedded Nodes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing intrusion detection systems for embedded devices, particularly in vehicular networks, face challenges in resource-constrained environments and require complex analyses that increase operational costs and data transmission, making it difficult to detect sophisticated cyber intrusion attempts effectively.

Innovation Solution

A method utilizing a digital twin model where a second computing node monitors and compares characteristics of a first computing node, allowing for complex analyses without significant data transmission, using a digital model that mimics the first node's state and behavior to detect discrepancies indicative of cyber intrusions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If intrusion detection is performed using complex analysis methods, then detection accuracy improves, but computational resource consumption and data transmission increase

Engineering Contradiction:
Improveintrusion detection accuracyVSAvoidcomputational resource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent creates a digital twin (copy) of the target computing node that replicates its software stack and execution behavior. This copy runs in a virtualized environment, allowing the system to analyze the node's behavior without directly consuming the node's limited computational resources. The digital twin receives the same input instructions and produces corresponding output characteristics for comparison, enabling sophisticated intrusion detection while preserving the original node's resources for its primary functions.

Inventive Principle:
Principle #26Copying

2Measurement precision

If more monitoring characteristics are analyzed, then intrusion detection capability improves, but communication overhead increases

Engineering Contradiction:
Improveintrusion detection capabilityVSAvoidcommunication overhead
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent extracts only the essential output characteristics from the digital twin that are necessary for intrusion detection, rather than transmitting or analyzing all possible monitoring data. By identifying and extracting the most relevant behavioral indicators (such as timing characteristics, power consumption patterns, or performance metrics), the system achieves effective intrusion detection while minimizing communication overhead between the monitored node and the analysis system.

Inventive Principle:
Principle #2Taking out (Extraction)

3Measurement precision

If a digital twin model is used for intrusion detection, then detection accuracy improves, but device complexity increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent introduces a digital twin as an intermediary between the target computing node and the intrusion detection analysis. This intermediary replicates the node's software stack and execution environment, allowing comprehensive behavioral analysis without directly modifying or complicating the target node's architecture. The digital twin serves as a safe sandbox for experimentation and analysis, isolating the complexity from the resource-constrained embedded system while enabling sophisticated detection capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20230367870A1Intrusion detection in computer systems
Publication Date: 2023.11.16 ROBERT BOSCH GMBH
  • US20230367870A1 patent drawing
  • US20230367870A1 patent drawing
  • US20230367870A1 patent drawing

AI summary

A computer implemented method for intrusion detection performed at a first computing node. The method includes: obtaining, at the first computing node, at least one monitored characteristic of the first computing node during an operation of the first computing node associated with a state iteration of the first computing node, wherein the first monitored characteristic is indicative of an intrusion; and communicating, from the first computing node to a second computing node, the at least one monitored characteristic of the first computing node.