IoT Device Configuration Data Security via Domain Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing interconnectedness of devices in the Internet of Things (IoT) makes them vulnerable to untrustworthy configuration data, which can persist even after device restarts, posing risks to system security and integrity.

Innovation Solution

Implementing a machine-implemented method and device architecture with at least two security domains to receive, store, and validate configuration data items, providing security indications, and invalidating untrustworthy data effects, while analyzing metadata to transmit security information across the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If configuration data is stored in device storage to enable extended capabilities, then device functionality is improved, but vulnerability to untrustworthy code and data increases

Engineering Contradiction:
Improvedevice functionalityVSAvoidvulnerability to untrustworthy code
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The device storage is divided into multiple security domains with different trust levels. Configuration data is stored in specific security domains based on its trustworthiness, creating segmented storage areas that isolate untrustworthy data from critical system operations. This allows the device to maintain extended capabilities while protecting against malicious code through spatial separation of trusted and untrusted data.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A security domain acts as an intermediary layer between configuration data and system operations. This intermediary validates and manages access to configuration data, preventing direct execution of untrustworthy code while allowing legitimate configuration changes. The security domain mediates between the need for device adaptability and the risk of harmful factors.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If configuration data is allowed to persist in storage, then device configuration flexibility is improved, but persistence of malicious code after restart increases

Engineering Contradiction:
Improveconfiguration flexibilityVSAvoidpersistence of malicious code
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary validation of configuration data before storing it in persistent storage. Security indicators are assigned to configuration data items during the storage process, establishing a trust baseline before the data is written. This preliminary action ensures that only validated configuration data persists across restarts, preventing malicious code from establishing persistent presence while maintaining configuration flexibility.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system continuously monitors configuration data for security violations and provides feedback by invalidating configuration effects when untrustworthiness is detected. This feedback mechanism allows the system to maintain flexible configuration while automatically responding to and neutralizing persistent malicious code threats, ensuring reliability despite configuration persistence.

Inventive Principle:
Principle #23Feedback

3Reliability

If security validation is performed on configuration data, then data integrity is improved, but system complexity increases

Engineering Contradiction:
Improvedata integrityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Security validation is implemented through segmented security domains rather than a monolithic validation system. Each security domain has specific validation rules and trust levels, simplifying the validation logic within each domain while providing comprehensive security across the system. This segmentation reduces overall system complexity by breaking down complex validation requirements into manageable domain-specific rules.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The security domain structure enables self-service validation where configuration data carries its own security indicators that automatically guide validation decisions. The system validates data integrity through inherent security metadata attached to configuration items, reducing the need for complex external validation mechanisms while maintaining high data integrity standards.

Inventive Principle:
Principle #25Self-service

4Reliability

If multiple security domains are implemented, then security control is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity controlVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security domain structure implements multi-functionality where each security domain can serve multiple purposes: storing configuration data, validating trust indicators, isolating malicious code, and controlling system access. This universal approach allows comprehensive security control through a unified multi-domain architecture rather than requiring separate specialized systems for each security function, thereby managing complexity while enhancing security control.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11366904B2Secure configuration data storage
Publication Date: 2022.06.21 ARM IP
  • US11366904B2 patent drawing
  • US11366904B2 patent drawing
  • US11366904B2 patent drawing

AI summary

A machine-implemented method for controlling a configuration data item in a storage-equipped device having at least two security domains, comprising receiving, by one of the security domains, a configuration data item; storing the configuration data item; providing a security indication for the configuration data item; and when an event indicates untrustworthiness of the data item, invalidating a configuration effect of the stored configuration data item. Further provided is a machine-implemented method for controlling a storage-equipped device as a node in a network of devices, comprising receiving information that a data source or type of a configuration data item is untrusted; analysing metadata for the data source and the configuration data item; populating a knowledge base with analysed metadata; and responsive to the analysed metadata, transmitting security information to the network of devices. A corresponding device and computer program product are also described.