IoT Device Configuration Data Security via Domain Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing interconnectedness of devices in the Internet of Things (IoT) makes them vulnerable to untrustworthy configuration data, which can persist even after device restarts, posing risks to system security and integrity.
Innovation Solution
Implementing a machine-implemented method and device architecture with at least two security domains to receive, store, and validate configuration data items, providing security indications, and invalidating untrustworthy data effects, while analyzing metadata to transmit security information across the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If configuration data is stored in device storage to enable extended capabilities, then device functionality is improved, but vulnerability to untrustworthy code and data increases
Solution Approach 1:
The device storage is divided into multiple security domains with different trust levels. Configuration data is stored in specific security domains based on its trustworthiness, creating segmented storage areas that isolate untrustworthy data from critical system operations. This allows the device to maintain extended capabilities while protecting against malicious code through spatial separation of trusted and untrusted data.
Solution Approach 2:
A security domain acts as an intermediary layer between configuration data and system operations. This intermediary validates and manages access to configuration data, preventing direct execution of untrustworthy code while allowing legitimate configuration changes. The security domain mediates between the need for device adaptability and the risk of harmful factors.
2Adaptability or versatility
If configuration data is allowed to persist in storage, then device configuration flexibility is improved, but persistence of malicious code after restart increases
Solution Approach 1:
The system performs preliminary validation of configuration data before storing it in persistent storage. Security indicators are assigned to configuration data items during the storage process, establishing a trust baseline before the data is written. This preliminary action ensures that only validated configuration data persists across restarts, preventing malicious code from establishing persistent presence while maintaining configuration flexibility.
Solution Approach 2:
The system continuously monitors configuration data for security violations and provides feedback by invalidating configuration effects when untrustworthiness is detected. This feedback mechanism allows the system to maintain flexible configuration while automatically responding to and neutralizing persistent malicious code threats, ensuring reliability despite configuration persistence.
3Reliability
If security validation is performed on configuration data, then data integrity is improved, but system complexity increases
Solution Approach 1:
Security validation is implemented through segmented security domains rather than a monolithic validation system. Each security domain has specific validation rules and trust levels, simplifying the validation logic within each domain while providing comprehensive security across the system. This segmentation reduces overall system complexity by breaking down complex validation requirements into manageable domain-specific rules.
Solution Approach 2:
The security domain structure enables self-service validation where configuration data carries its own security indicators that automatically guide validation decisions. The system validates data integrity through inherent security metadata attached to configuration items, reducing the need for complex external validation mechanisms while maintaining high data integrity standards.
4Reliability
If multiple security domains are implemented, then security control is improved, but device complexity increases
Solution Approach 1:
The security domain structure implements multi-functionality where each security domain can serve multiple purposes: storing configuration data, validating trust indicators, isolating malicious code, and controlling system access. This universal approach allows comprehensive security control through a unified multi-domain architecture rather than requiring separate specialized systems for each security function, thereby managing complexity while enhancing security control.
Data Source
AI summary
A machine-implemented method for controlling a configuration data item in a storage-equipped device having at least two security domains, comprising receiving, by one of the security domains, a configuration data item; storing the configuration data item; providing a security indication for the configuration data item; and when an event indicates untrustworthiness of the data item, invalidating a configuration effect of the stored configuration data item. Further provided is a machine-implemented method for controlling a storage-equipped device as a node in a network of devices, comprising receiving information that a data source or type of a configuration data item is untrusted; analysing metadata for the data source and the configuration data item; populating a knowledge base with analysed metadata; and responsive to the analysed metadata, transmitting security information to the network of devices. A corresponding device and computer program product are also described.


