Hierarchical Security System for IoT Network Edge

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing number of Internet-of-Things (IoT) devices with limited bandwidth and processing power poses challenges in securing data networks, as classical firewall technologies require pre-emptive knowledge of devices and cannot be updated easily, making them vulnerable to attacks like Denial of Service (DoS) and physical relocation, which classical firewalls cannot prevent without risking the devices.

Innovation Solution

A hierarchical security system is implemented within the data network, comprising network edge nodes, first and second-level analysis nodes, and a centralized entity that generate and evaluate traffic profiles using machine learning algorithms to apply dynamic firewall rules, allowing for real-time adaptation and protection without relying on device-specific updates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If classical firewall technology is used to secure IoT devices, then device-specific protection rules can be implemented, but the system cannot adapt to device changes (e.g., physical relocation) and requires continuous manual updates

Engineering Contradiction:
Improvesecurity protectionVSAvoidadaptation to device changes
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system enables self-service by having devices automatically report their status (location, operational state) to the network edge node, which then automatically updates firewall rules without manual intervention. This resolves the contradiction by making the system both reliable (continuous protection) and adaptable (automatic response to changes).

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements feedback loops where device status changes are detected, communicated to the network edge node, and trigger automatic rule updates. This feedback mechanism ensures the firewall remains both reliable (consistent protection) and adaptable (responsive to changes).

Inventive Principle:
Principle #23Feedback

2Reliability

If firewall rules are updated manually for each device change, then security rules can be maintained, but the operational effort becomes unsustainable with large numbers of devices

Engineering Contradiction:
Improvesecurity rule accuracyVSAvoidoperational efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The automated system performs the work of monitoring and updating firewall rules without human intervention, dramatically improving productivity while maintaining reliability through continuous automatic adaptation to device changes.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system replaces manual mechanical processes (human operators updating rules) with automated electronic monitoring and rule generation at the network edge, enabling scalable management of large device populations while maintaining security accuracy.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If security control is implemented at the device level, then device-specific threats can be addressed, but devices with limited processing power cannot run firewalling

Engineering Contradiction:
Improvedevice-level securityVSAvoidprocessing requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The firewall functionality is extracted from the resource-constrained IoT devices and relocated to the network edge node, which has sufficient processing power. This allows devices to remain simple while still benefiting from robust security control.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The network edge node acts as an intermediary between the devices and the core network, providing firewall services to devices that lack the capability to run their own firewalling, thus maintaining security without increasing device complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If comprehensive traffic monitoring is implemented to detect all attack vectors, then security coverage is improved, but bandwidth consumption increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidbandwidth consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The system applies different levels of monitoring intensity to different devices and traffic patterns based on their risk profiles and behavior characteristics, optimizing security coverage while minimizing unnecessary bandwidth consumption from uniform high-intensity monitoring of all devices.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP3503494B1Security system and security method for a data network and for terminal devices connected to the data network
Publication Date: 2021.03.24 DEUTSCHE TELEKOM AG
  • EP3503494B1 patent drawingFigure 1

AI summary

The present invention refers to a security system for a data network and for terminal devices coupled to the data network, the network comprising a network topology of a plurality of network nodes which are interconnected with each other, the security system being built-up hierarchically and implemented in the data network and comprising at least: - at least one network edge node (110) of the data network which is configured to extract and/or to generate traffic profiles from data traffic within the data network; - at least one first level analysis node (120) being connected to the at least one network edge node (110) and configured to receive the traffic profiles of the data traffic, to apply a learning algorithm to the traffic profiles, to store the learned traffic profiles locally and to forward at least some of the learned profiles which have become firmly established, to at least one second level analysis node (130), - the at least one second level analysis node (130) being connected to the at least one first level analysis node (120) and to at least one first logically centralized entity (140) and configured to receive the learned profiles from the at least one first level analysis node (120); - the at least one first logically centralized entity (140) which is configured to store rules which assign certain traffic profiles to respective actions, respectively, and to distribute, when the at least one second level analysis node (130) receives with a preconfigured frequency one of the certain traffic profiles from the at least one first level analysis node, the respective rules to the at least one second level analysis node (130) which forwards the respective rules to the at least one first level analysis node (120) for triggering execution of at least one action assigned to the received one of the certain traffic profiles.