IoT Component Trust Assessment via Group Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing number of network-enabled components in IoT systems poses a risk of data breaches and malicious activities, as existing technologies lack effective methods to assess and ensure the trustworthiness of these components in real-time, potentially leading to unauthorized access and malfunction.

Innovation Solution

A method that involves receiving performance data from components, determining aggregate data for groups of similar components, comparing individual component data to group characteristics, and identifying anomalies to determine trust levels, using telemetry data and statistical significance tests to establish baseline behavior patterns and detect deviations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the number of network-enabled components in IoT systems increases, then system functionality and automation capability improve, but security risk and vulnerability to malicious activities increase

Engineering Contradiction:
Improvesystem functionalityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by establishing baseline behavior patterns for components before evaluating their trustworthiness. Performance data is collected and aggregated to create expected behavior models, allowing the system to proactively identify deviations and potential security threats before they cause harm.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary trust assessment mechanism that mediates between components and the network. By comparing individual component performance against aggregated group characteristics, the system acts as a security intermediary that can identify and isolate malicious components without disrupting legitimate operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If real-time trust assessment of components is implemented, then security and reliability improve, but system complexity and computational requirements increase

Engineering Contradiction:
Improvetrustworthiness assessmentVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the trust assessment process into manageable parts: collecting performance data from individual components, aggregating data by component groups, establishing baseline patterns, and comparing individual behavior against group characteristics. This segmentation reduces computational complexity by processing data in organized batches rather than analyzing all components simultaneously.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent merges individual component performance data with aggregated group characteristics to establish trust assessments. By combining individual monitoring with collective behavior analysis, the system achieves comprehensive security monitoring while leveraging the statistical power of group data to simplify individual component evaluation.

Inventive Principle:
Principle #5Merging (Combining)

3Measurement precision

If individual component performance data is continuously monitored and compared to group characteristics, then anomaly detection accuracy improves, but data processing time and computational resources increase

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoiddata processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary aggregation of performance data by component groups before conducting individual component analysis. Baseline behavior patterns are established in advance using aggregated group data, so when individual component evaluation is needed, the comparison can be made quickly against pre-computed characteristics rather than analyzing raw data from scratch.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies partial action by focusing anomaly detection efforts on components that deviate from group characteristics rather than continuously analyzing every component in detail. By using aggregated group data as a filter, the system efficiently identifies suspicious components for further investigation without expending excessive computational resources on normal components.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10587639B2Assessing trust of components in systems
Publication Date: 2020.03.10 CA TECH INC
  • US10587639B2 patent drawing
  • US10587639B2 patent drawing
  • US10587639B2 patent drawing

AI summary

Systems and methods may include receiving performance data of components in a system. The performance data may include data for parameters for each of the components. The systems and methods may include determining aggregate data for each group of similar components of the components. The aggregate data for each group of similar components may include a group characteristic for each of the parameters. The systems and methods may include, for each group of similar components, determining whether the data for each of the parameters for each component is consistent with the group characteristic for the respective parameter. The systems and methods may include, for each component of the respective group determining that the component is anomalous in response to determining that the data for a parameter for the component is not consistent with the group characteristic for the parameter.