Embedded Security Bridge for M2M Cyber Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Machine to machine (M2M) communication systems are vulnerable to cyber-attacks, and existing security solutions lack embedded detection and prevention mechanisms, making them susceptible to unauthorized access, hijacking, and other malicious activities without human intervention.

Innovation Solution

An embedded security bridge (ESB) is introduced, connected to proximal machines and M2M modules, equipped with inspection units to analyze communication for malicious activity and decision units to perform actions such as blocking or altering communications, thereby detecting and preventing cyber-attacks on both proximal and remote machines.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional centralized IT security network model is used, then security protection is provided, but it is not feasible for highly distributed M2M networks

Engineering Contradiction:
Improvesecurity protectionVSAvoidadaptability to distributed networks
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the centralized security model into distributed security bridges deployed at multiple network nodes. Each security bridge independently performs inspection and decision-making locally, transforming the monolithic centralized security architecture into a scalable distributed system that can handle M2M network requirements.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces security bridges as intermediary components between M2M devices and the network. These bridges act as mediators that inspect communications, make security decisions, and enforce policies without requiring direct centralized control, enabling security in distributed architectures.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Extent of automation

If M2M devices operate unattended for long periods, then automation is improved, but security risks increase

Engineering Contradiction:
Improveunattended operationVSAvoidsecurity security
Core Design Contradiction:
Extent of automationVSReliability

Solution Approach 1:

The patent implements self-service security through autonomous security bridges that automatically inspect communications, detect threats, and enforce security policies without human intervention. The system performs self-diagnosis, self-protection, and automatic response to security incidents, enabling secure unattended operation.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent incorporates feedback mechanisms where security bridges continuously monitor communications, analyze security events, and automatically adjust security responses. The system uses real-time feedback from inspection units to inform decision units, creating a closed-loop security system that adapts to threats during unattended operation.

Inventive Principle:
Principle #23Feedback

3Use of energy by moving object

If M2M devices are limited in power consumption, then energy efficiency is improved, but security mechanism complexity must be reduced

Engineering Contradiction:
Improvepower consumptionVSAvoidsecurity mechanism
Core Design Contradiction:
Use of energy by moving objectVSReliability

Solution Approach 1:

The patent segments security functions into lightweight inspection units and decision units that can operate with minimal processing power. By dividing security tasks into modular components, the system achieves robust security mechanisms while maintaining low power consumption suitable for resource-constrained M2M devices.

Inventive Principle:
Principle #1Segmentation

4Difficulty of detecting and measuring

If embedded security bridge inspects communication, then detection capability is improved, but processing time increases

Engineering Contradiction:
Improvedetection capabilityVSAvoidprocessing time
Core Design Contradiction:
Difficulty of detecting and measuringVSLoss of time

Solution Approach 1:

The patent implements preliminary action by having security bridges pre-configured with security policies, threat signatures, and inspection rules before deployment. The inspection units use pre-compiled detection patterns and the decision units have pre-established response protocols, enabling fast detection and response without extensive real-time processing.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces complex mechanical inspection processes with efficient electronic and software-based detection mechanisms. The inspection units use digital signal processing, pattern matching algorithms, and automated analysis techniques that provide high detection capability with minimal processing time, substituting traditional manual or hardware-intensive security inspection methods.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS10944765B2Security system for machine to machine cyber attack detection and prevention
Publication Date: 2021.03.09 RED BEND LTD
  • US10944765B2 patent drawing
  • US10944765B2 patent drawing
  • US10944765B2 patent drawing

AI summary

Apparatus, system and method useful for machine to machine (M2M) communication cyber-attack detection and prevention, are provided. An embedded security bridge (ESB), operatively connected to at least one proximal machine and at least one M2M module. The M2M module is in communication with at least one remote machine, and configured to enable communication between at least one remote machine and at least one proximal machine through the ESB. The ESB includes: one or more inspection units, configured for communication analysis for identifying communication and/or content suspicious as malicious, and, one or more decision units operatively connected to the inspection unit. The decision unit is configured to perform at least one action based on analysis of at least one inspection unit. The ESB is configured to detect by means of the inspection unit and prevent by means of the decision unit cyber-attacks on the proximal machine, the remote machine, or both.