Firewall Resource Reservation for Secure IoT Updates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Communication networks, particularly those involving IoT devices, face challenges in ensuring secure updating procedures due to resource constraints, making them vulnerable to attacks that can cause significant losses and damages.

Innovation Solution

A method where a firewall apparatus transmits a request to a security service provider with load data characteristics, receives an updated firewall strategy, and adjusts its operation to reserve resources for updates, ensuring valid updates are forwarded while invalid ones are dropped, thereby enhancing security and resource management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If frequent updating is performed to maintain security, then security level is improved, but resource consumption increases and device stability deteriorates

Engineering Contradiction:
Improvesecurity levelVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The firewall strategy is updated in advance with predetermined update intervals and resource reservation parameters. The security service provider configures update policies before deployment, including time intervals and resource allocation, so that devices can execute updates efficiently without real-time negotiation, reducing resource consumption during actual update operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The firewall strategy includes dynamic resource reservation that adapts to device conditions. The update mechanism adjusts resource allocation based on device state, allowing flexible resource management that balances security update needs with device stability and resource constraints.

Inventive Principle:
Principle #15Dynamics

2Reliability

If resource reservation is increased to ensure update stability, then update reliability is improved, but available resources for normal operations decrease

Engineering Contradiction:
Improveupdate stabilityVSAvoidnormal operation capacity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system reserves resources partially for update operations rather than fully. The firewall strategy specifies resource reservation parameters that allocate only the necessary portion of resources for security updates, maintaining sufficient resources for normal device operations while ensuring update stability when needed.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If firewall strategy is updated frequently to prevent attacks, then attack prevention capability is improved, but device complexity and processing overhead increase

Engineering Contradiction:
Improveattack prevention capabilityVSAvoidprocessing overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Firewall strategies are configured in advance with predetermined update intervals and validation rules. The security service provider prepares update policies beforehand, including time intervals and resource parameters, reducing the complexity of real-time strategy generation and lowering processing overhead during execution.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The update mechanism includes validation based on device characteristics and current state feedback. The firewall apparatus validates incoming strategies against device capabilities and operational conditions, ensuring attack prevention effectiveness while managing complexity through intelligent filtering and adaptation.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12095821B2Enhancements for secure updating in communication networks
Publication Date: 2024.09.17 NOKIA TECHNOLOGIES OY
  • US12095821B2 patent drawing
  • US12095821B2 patent drawing
  • US12095821B2 patent drawing

AI summary

According to an example aspect of the present invention, there is provided a method comprising transmitting to a security service provider, by a firewall apparatus, a request to update firewall strategy of the firewall apparatus for a location center, wherein the request comprises at least one characteristic of the firewall apparatus, the at least one characteristic of the firewall apparatus further comprising load data of the firewall apparatus, receiving from the security service provider, by the firewall apparatus, an updated firewall strategy for the location center, wherein the updated firewall strategy comprises load data required by the updated firewall strategy and adjusting the operation of the firewall apparatus based on the updated firewall strategy by reserving resources at the firewall apparatus for updates according to the required load data.