IoT Communication Control Apparatus for Unauthorized Device Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional communication control for IoT devices relies on pre-defined signatures and blacklists, which are often unavailable or outdated, leading to inefficiencies in identifying unauthorized communication, security concerns, and high costs due to the need for extensive information processing and external dependencies.

Innovation Solution

A communication control apparatus comprising a collection unit, analysis unit, and coordination unit that autonomously collects and analyzes device communication data to specify device identification information, control conditions, and shares this information within a decentralized network, enabling real-time matching of communication states without relying on external information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If signature matching and blacklist methods are used for communication control, then unauthorized communication can be detected, but the system requires extensive external information and pre-defined data which are often unavailable or outdated

Engineering Contradiction:
Improvedetection accuracyVSAvoidexternal information dependency
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The communication control apparatus performs self-learning by automatically collecting communication data, analyzing it to extract device identification information, and generating control conditions without requiring external signature databases or blacklists. The system serves itself by using its own collected data to create detection capabilities.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary data collection and analysis during a learning period before actual communication control begins. By pre-collecting communication data and extracting device characteristics in advance, the system prepares control conditions that will be used for subsequent unauthorized communication detection.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If conventional blacklist-based control is implemented, then communication control can be performed, but the system becomes complex and costly due to extensive information processing requirements

Engineering Contradiction:
Improvecontrol efficiencyVSAvoidinformation processing complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system extracts only the essential device identification information and control conditions from the collected communication data, rather than processing and storing entire communication logs. This extraction process simplifies the data structure while maintaining detection effectiveness.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The communication control apparatus is divided into distinct functional modules: a collection unit for gathering data, an analysis unit for processing and extracting features, and a coordination unit for executing control decisions. This segmentation reduces overall system complexity by making each module independent and manageable.

Inventive Principle:
Principle #1Segmentation

3Reliability

If external signature databases and blacklists are used, then communication control can be achieved, but the system has high costs and relies on external information that may be outdated

Engineering Contradiction:
Improvesecurity controlVSAvoidsystem implementation cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The communication control apparatus generates its own detection capabilities by collecting and analyzing actual communication data from connected devices. This self-service approach eliminates the need for expensive external signature databases and blacklists, reducing implementation costs while maintaining security control.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system continuously collects communication data, analyzes it to update device identification information, and adjusts control conditions accordingly. This feedback loop enables the system to adapt to changing communication patterns and emerging threats without requiring manual updates from external sources.

Inventive Principle:
Principle #23Feedback

4Adaptability or versatility

If the system collects and analyzes communication data for each device, then device-specific control can be achieved, but processing time and computational resources increase

Engineering Contradiction:
Improvedevice-specific controlVSAvoiddata processing time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system performs preliminary analysis of communication data during a learning period to extract device identification information and establish control conditions before actual security control begins. This preliminary action consolidates processing work upfront, reducing real-time computational requirements.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system analyzes only the necessary portions of communication data to extract essential device characteristics, rather than processing every detail of all communication traffic. This selective analysis approach achieves device-specific control while minimizing processing time and computational resources.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11489832B2Communication control apparatus, communication control method, and communication control program
Publication Date: 2022.11.01 NIPPON TELEGRAPH & TELEPHONE CORP
  • US11489832B2 patent drawing
  • US11489832B2 patent drawing
  • US11489832B2 patent drawing

AI summary

A communication control apparatus includes a collection control unit, an analysis unit, and a coordination unit. The collection control unit collects communication performed with a device connected to a subordinate network, and controls communication performed by the device based on a first control condition; The analysis unit analyzes the communication collected by the collection control unit to extract device identification information indicating characteristics of the communication performed by the device. The analysis unit specifies a device name of the device and the first control condition corresponding to a normal communication range extracted from the device identification information, based on the device identification information. The coordination unit transmits at least part of first shared information in which the device name and the first control condition specified by the analysis unit and the device identification information are associated with each other, to an outside of the subordinate network.