IoT Compromise Detection Using Ambient Stimulus Response

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Detecting compromised Internet of Things (IoT) devices is challenging due to natural fluctuations in their traffic patterns and the difficulty in distinguishing between legitimate and unauthorized changes, especially when the guarding software remains unaltered.

Innovation Solution

A method involving determining IoT devices with ambience sensing capabilities and those capable of causing ambient stimulation, monitoring data transmissions, and issuing ambient stimulation to detect significant changes, which can indicate compromised devices without interfering with normal operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traffic monitoring methods are used to detect compromised IoT devices, then detection capability is improved, but false positives increase due to natural traffic fluctuations

Engineering Contradiction:
Improvedetection capabilityVSAvoidfalse positive rate
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent introduces an intermediary ambient stimulus (audio or light signal) that acts as a mediator between the detector and the IoT device. This stimulus causes a measurable reaction in compromised devices without being part of their normal operation, thereby distinguishing malicious activity from natural traffic fluctuations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary action by sending an ambient stimulus (audio or light signal) to the target device before attempting to detect compromise. This proactive approach elicits a response that can be measured and analyzed, allowing detection before traditional traffic monitoring would indicate a problem.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If guarding software is used to detect unauthorized changes, then security monitoring is improved, but detection fails when guarding software is altered

Engineering Contradiction:
Improvesecurity monitoringVSAvoiddetection accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent implements self-service by enabling IoT devices to perform self-detection through their response to ambient stimuli. The device's own reaction to the stimulus (unauthorized activation of sensors or actuators) reveals compromise without requiring external guarding software, making the detection mechanism independent of potentially compromised security software.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the mechanical/software-based guarding system with a physics-based detection method using ambient acoustic or light stimuli. This substitution transitions from software monitoring (which can be altered) to physical stimulus-response measurement (which cannot be easily spoofed or modified).

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Measurement precision

If ambient stimulation is issued to detect compromised devices, then detection effectiveness is improved, but interference with normal device operation increases

Engineering Contradiction:
Improvedetection effectivenessVSAvoidoperation interference
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent applies periodic action by issuing ambient stimuli at specific intervals rather than continuously. This allows normal device operation to proceed between stimulus events, minimizing interference while still enabling effective detection when the stimulus is applied.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The patent applies local quality by targeting specific IoT devices with ambient stimuli based on their location and characteristics. Rather than broadcasting to all devices uniformly, the system tailors the stimulus to specific targets, reducing overall interference while maintaining detection effectiveness for suspected devices.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11503049B2Method and apparatus for compromised IoT device detection
Publication Date: 2022.11.15 NOKIA TECHNOLOGIES OY
  • US11503049B2 patent drawing
  • US11503049B2 patent drawing
  • US11503049B2 patent drawing

AI summary

A method and apparatus for determining one or more first devices that are Internet devices meeting all of the following conditions: residing at a given location; equipped with one or more ambience sensing capable sensors; and operation mode being such that their ambience sensing capable sensors should not cause transmission of data. One or more second devices are determined that are Internet devices at the given location and equipped with one or more elements capable of causing an ambient stimulation detectable by the sensors of one or more first devices. Data transmissions of the first devices are monitored. Issuing of the ambient stimulation is caused by a subset of the one or more second devices. It is determined whether the issuing of the ambient stimulation caused a significant change in the monitored data transmissions of the first devices.