Embedded Device Cybersecurity via Component Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Embedded devices, such as IoT devices and vehicles, lack effective cybersecurity measures due to limited processing power and difficulty in applying comprehensive IT infrastructure cybersecurity approaches, leading to vulnerability to cyber attacks.

Innovation Solution

A data-driven technique that uses system performance parameters to identify critical components affecting device operation, assess performance risk, and implement targeted cybersecurity measures to ensure mission success, prioritizing components based on impact and implementing countermeasures to mitigate vulnerabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If comprehensive IT infrastructure cybersecurity approaches are applied to embedded devices, then security coverage is improved, but device complexity and processing requirements increase beyond what embedded devices can handle

Engineering Contradiction:
Improvecybersecurity protectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the embedded device into multiple security domains (e.g., critical control functions vs. non-critical functions) and applies different security measures to each domain. This allows comprehensive security coverage without requiring the entire system to meet high security standards, thereby reducing overall complexity while maintaining essential security protection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by applying security measures selectively to specific components or functions based on their criticality. Critical functions receive enhanced security monitoring and validation, while non-critical functions use standard or reduced security measures, optimizing the balance between security and complexity.

Inventive Principle:
Principle #3Local quality

2Reliability

If comprehensive IT infrastructure cybersecurity approaches are applied to embedded devices, then security coverage is improved, but processing power requirements exceed embedded device capabilities

Engineering Contradiction:
Improvecybersecurity protectionVSAvoidprocessing power
Core Design Contradiction:
ReliabilityVSPower

Solution Approach 1:

The patent applies partial action by implementing security measures only where necessary based on risk assessment. Instead of applying comprehensive security to all functions, the system identifies critical security requirements and applies appropriate security controls only to those areas, reducing processing power consumption while maintaining essential security protection.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent changes security parameters dynamically based on operational context and risk levels. Security monitoring intensity, validation frequency, and control strictness are adjusted according to the criticality of operations and threat levels, allowing the system to maintain security protection while adapting processing power consumption to actual needs.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If cybersecurity measures are implemented on embedded devices, then vulnerability to cyber attacks is reduced, but cost and implementation complexity increase

Engineering Contradiction:
Improveresilience against cyber threatsVSAvoidimplementation ease
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent incorporates security measures during the design and development phases rather than adding them later. Security requirements are defined early, security domains are established during system architecture design, and security controls are integrated into the development process, reducing implementation complexity and cost while improving overall security effectiveness.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent employs universal security mechanisms that can be applied across multiple functions and components. By creating reusable security frameworks, validation routines, and domain definitions that work across different parts of the system, the patent reduces overall implementation complexity and cost while providing comprehensive security coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10698753B2Mitigating device vulnerabilities in software
Publication Date: 2020.06.30 RAYTHEON CO
  • US10698753B2 patent drawing
  • US10698753B2 patent drawing
  • US10698753B2 patent drawing

AI summary

A method can include simulating, by at least one hardware processor, operation of an embedded device under a variety of conditions including a variety of electromagnetic interference (EMI) conditions and a variety of weather conditions, determining proper operation characteristics of the components based on the simulating, the proper operation characteristics of the components determined based on simulations that result in the embedded device operating properly, determining which components of the embedded device impact proper operation of the embedded device by a threshold amount, and programming the at least one hardware processor to implement a safeguard that ensures proper operation of a component of the components.