Centralized Smart Security System for IoT Network Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The exponential increase in network-connected devices in IoT applications poses significant challenges for network security, particularly in RFID and wireless networks, where existing security mechanisms are inadequate to prevent anomalous behavior and ensure trusted communications.

Innovation Solution

A centralized smart security system is implemented to manage security operations within a network, utilizing a computing node to detect and prevent anomalous behavior, validate device identities, and automatically install patches, thereby establishing secured and trusted communications between network devices and the computing system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a centralized security system is implemented to manage security operations and validate device identities, then network security and reliability are improved, but device complexity and system overhead increase

Engineering Contradiction:
Improvenetwork securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security system is segmented into a centralized security server that handles complex security operations (certificate validation, anomaly detection, patch distribution) and lightweight security agents deployed on individual network devices. This segmentation allows the complex security functionality to be centralized while keeping individual device complexity low.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A centralized security server acts as an intermediary between network devices and the computing system, mediating security operations such as certificate validation, anomaly detection, and patch distribution. This intermediary handles the complexity of security management centrally, reducing the burden on individual devices while maintaining high security standards.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security operations are centralized to prevent anomalous behavior and validate identities, then security reliability is improved, but processing time and operational delays increase

Engineering Contradiction:
Improvesecurity validationVSAvoidoperation delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Security credentials such as certificates and security policies are pre-configured and distributed to network devices before they need to perform operations. The centralized security server validates these credentials in advance and maintains updated security databases, so that during actual operations, validation can be performed quickly using pre-prepared security information.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces traditional manual security validation mechanisms with automated electronic verification systems. The centralized security server automatically validates device identities, detects anomalies, and distributes patches through electronic communication, eliminating the need for manual security checks and significantly reducing validation time while maintaining reliability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If automated patch installation is implemented to secure network devices, then security maintenance is improved, but device autonomy and manual control are reduced

Engineering Contradiction:
Improvesecurity maintenanceVSAvoidmanual control
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The centralized security server automatically performs security maintenance tasks including detecting vulnerable devices, downloading appropriate security patches, and installing them on network devices without requiring manual intervention. The security agents on individual devices cooperate with this automated process by receiving and applying patches, enabling self-service security maintenance that improves reliability while minimizing the need for manual operational control.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11109229B2Security for network computing environment using centralized security system
Publication Date: 2021.08.31 EMC IP HLDG CO LLC
  • US11109229B2 patent drawing
  • US11109229B2 patent drawing
  • US11109229B2 patent drawing

AI summary

Systems, methods, and articles of manufacture comprising processor-readable storage media are provided for implementing security for a network environment using a centralized smart security system. For example, a method includes implementing a network comprising a plurality of network devices which collectively generate data that is utilized by a computing system to execute an application, and implementing a centralized security system as a computing node within the network to manage security operations within the network and to establish secured and trusted communications between the network devices and the computing system. The network devices may comprise wireless sensor devices operating in a wireless sensor network, wherein the computing system executes an IoT (Internet of Things) application which processes the data that is generated by the wireless sensor devices.