Embedded Security Bridge for M2M Cyber Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Machine to machine (M2M) communication systems are vulnerable to cyber-attacks, and existing security solutions are inadequate for detecting and preventing attacks without human intervention, especially in distributed networks where energy efficiency and robust security mechanisms are crucial.

Innovation Solution

An embedded security bridge (ESB) is introduced, operatively connected to proximal machines and M2M modules, equipped with inspection units for analyzing communication for malicious activity and decision units for taking action, enabling detection and prevention of cyber-attacks such as unauthorized use, hijacking, and information attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If conventional centralized IT security network model with firewall is used, then security enforcement is centralized and manageable, but it is not practically feasible for highly distributed M2M networks

Engineering Contradiction:
Improveadaptability to distributed networksVSAvoidsecurity system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent divides the security system into distributed security agents deployed on individual M2M devices and a centralized security server. Each device independently performs local security checks while the server provides global coordination, making the system adaptable to distributed networks without requiring complete centralization of security functions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces security agents as intermediary components that bridge the gap between centralized security management and distributed M2M devices. These agents reside on individual devices, performing local security enforcement while communicating with the centralized server, thus adapting firewall-like security to distributed architectures.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If robust security mechanisms such as authentication and tamperproof design are implemented, then security is improved, but power consumption increases which is problematic for energy-constrained M2M devices

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidpower consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent implements selective security verification where the security agent performs authentication and security checks only when necessary - such as when detecting suspicious traffic patterns or policy violations - rather than continuously verifying all communications. This reduces power consumption while maintaining security reliability through targeted enforcement actions.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The security agent on each M2M device performs local security functions including authentication verification and policy checking independently, without requiring continuous interaction with the centralized server. This self-service capability reduces communication overhead and power consumption while maintaining security through distributed enforcement.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If inspection units analyze communication for malicious activity, then detection accuracy is improved, but processing time and computational resources increase

Engineering Contradiction:
Improvemalicious activity detection accuracyVSAvoidcommunication processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements preliminary security policy configuration where security rules and authentication credentials are pre-loaded onto M2M devices during manufacturing or deployment. This allows the security agent to perform rapid local verification against pre-configured policies without requiring real-time analysis or communication with the server, thus improving detection speed while maintaining accuracy.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements differentiated inspection strategies where the security agent performs basic authentication and policy checking locally with simple comparison operations, and only escalates to more complex analysis or server verification when anomalies are detected. This local quality approach maintains high detection accuracy for common cases while minimizing processing time through simplified local checks.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP3254223B1Security system for machine to machine cyber attack detection and prevention
Publication Date: 2020.07.29 TOWER SEC
  • EP3254223B1 patent drawingFigure 1~2
  • EP3254223B1 patent drawingFigure 3
  • EP3254223B1 patent drawingFigure 4

AI summary

Apparatus, system and method useful for machine to machine (M2M) communication cyber-attack detection and prevention, are provided. An embedded security bridge (ESB), operatively connected to at least one proximal machine and at least one M2M module. The M2M module is in communication with at least one remote machine, and configured to enable communication between at least one remote machine and at least one proximal machine through the ESB. The ESB includes: one or more inspection units, configured for communication analysis for identifying communication and/or content suspicious as malicious, and, one or more decision units operatively connected to the inspection unit. The decision unit is configured to perform at least one action based on analysis of at least one inspection unit. The ESB is configured to detect by means of the inspection unit and prevent by means of the decision unit cyber-attacks on the proximal machine, the remote machine, or both.