Embedded Security Bridge for M2M Cyber Attack Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Machine to machine (M2M) communication systems are vulnerable to cyber-attacks, and existing security solutions are inadequate for detecting and preventing attacks without human intervention, especially in distributed networks where energy efficiency and robust security mechanisms are crucial.
Innovation Solution
An embedded security bridge (ESB) is introduced, operatively connected to proximal machines and M2M modules, equipped with inspection units for analyzing communication for malicious activity and decision units for taking action, enabling detection and prevention of cyber-attacks such as unauthorized use, hijacking, and information attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If conventional centralized IT security network model with firewall is used, then security enforcement is centralized and manageable, but it is not practically feasible for highly distributed M2M networks
Solution Approach 1:
The patent divides the security system into distributed security agents deployed on individual M2M devices and a centralized security server. Each device independently performs local security checks while the server provides global coordination, making the system adaptable to distributed networks without requiring complete centralization of security functions.
Solution Approach 2:
The patent introduces security agents as intermediary components that bridge the gap between centralized security management and distributed M2M devices. These agents reside on individual devices, performing local security enforcement while communicating with the centralized server, thus adapting firewall-like security to distributed architectures.
2Reliability
If robust security mechanisms such as authentication and tamperproof design are implemented, then security is improved, but power consumption increases which is problematic for energy-constrained M2M devices
Solution Approach 1:
The patent implements selective security verification where the security agent performs authentication and security checks only when necessary - such as when detecting suspicious traffic patterns or policy violations - rather than continuously verifying all communications. This reduces power consumption while maintaining security reliability through targeted enforcement actions.
Solution Approach 2:
The security agent on each M2M device performs local security functions including authentication verification and policy checking independently, without requiring continuous interaction with the centralized server. This self-service capability reduces communication overhead and power consumption while maintaining security through distributed enforcement.
3Measurement precision
If inspection units analyze communication for malicious activity, then detection accuracy is improved, but processing time and computational resources increase
Solution Approach 1:
The patent implements preliminary security policy configuration where security rules and authentication credentials are pre-loaded onto M2M devices during manufacturing or deployment. This allows the security agent to perform rapid local verification against pre-configured policies without requiring real-time analysis or communication with the server, thus improving detection speed while maintaining accuracy.
Solution Approach 2:
The patent implements differentiated inspection strategies where the security agent performs basic authentication and policy checking locally with simple comparison operations, and only escalates to more complex analysis or server verification when anomalies are detected. This local quality approach maintains high detection accuracy for common cases while minimizing processing time through simplified local checks.
Data Source
Figure 1~2
Figure 3
Figure 4
AI summary
Apparatus, system and method useful for machine to machine (M2M) communication cyber-attack detection and prevention, are provided. An embedded security bridge (ESB), operatively connected to at least one proximal machine and at least one M2M module. The M2M module is in communication with at least one remote machine, and configured to enable communication between at least one remote machine and at least one proximal machine through the ESB. The ESB includes: one or more inspection units, configured for communication analysis for identifying communication and/or content suspicious as malicious, and, one or more decision units operatively connected to the inspection unit. The decision unit is configured to perform at least one action based on analysis of at least one inspection unit. The ESB is configured to detect by means of the inspection unit and prevent by means of the decision unit cyber-attacks on the proximal machine, the remote machine, or both.