IoT Data Security via Decryption Identifier Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing volume of IoT data transmission poses privacy concerns, as it can reveal user activities, making IoT devices vulnerable to cyber-attacks, and existing security measures struggle to identify malicious actors and mitigate attacks effectively.
Innovation Solution
A method involving a processor-controlled device that decrypts and encrypts data, embedding identifiers to track interactions, using one-way cryptographic functions to generate and process identifiers, and storing them for tracking malicious behavior, thereby enhancing data security and identifying malicious entities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data encryption is used to protect privacy, then data security is improved, but the ability to identify and track malicious actors is worsened
Solution Approach 1:
The patent segments the data into two distinct parts: the encrypted data portion that maintains privacy protection, and the identifier portion that enables tracking and identification. This segmentation allows the system to simultaneously achieve data security through encryption while preserving the ability to identify malicious actors through the separate identifier mechanism.
Solution Approach 2:
The identifier acts as an intermediary element between the encrypted data and the need for identification. It is derived from the encrypted data through a one-way cryptographic function, serving as a mediator that enables tracking and identification without requiring decryption of the sensitive data itself, thus resolving the contradiction between security and identifiability.
2Ease of operation
If encryption keys are stored to enable decryption, then data accessibility is improved, but the risk of key compromise and malicious behavior is worsened
Solution Approach 1:
The system implements feedback mechanisms by tracking which devices have accessed or decrypted the data through the identifier. This feedback information can be used to detect suspicious patterns, identify malicious behavior, and respond appropriately, thereby reducing the risk of key compromise while maintaining data accessibility for authorized devices.
Solution Approach 2:
The patent performs preliminary actions by embedding the identifier in the encrypted data before it is transmitted or stored. This preliminary embedding ensures that tracking capability is established in advance, allowing the system to monitor and detect malicious behavior related to key compromise without requiring additional real-time intervention.
3Adaptability or versatility
If IoT devices transmit data to enable functionality, then device functionality is improved, but privacy vulnerability to cyber-attacks is worsened
Solution Approach 1:
The patent applies segmentation by separating the functional data transmission from the identification tracking. The encrypted data portion enables device functionality and privacy protection, while the identifier portion enables security monitoring. This segmentation allows IoT devices to transmit data for functionality while the identifier tracks access patterns to detect and prevent cyber-attacks.
Solution Approach 2:
The identifier serves as an intermediary that enables security monitoring without interfering with the functional data transmission. It is derived from the encrypted data through a one-way cryptographic function, allowing the system to track device interactions and detect malicious behavior while maintaining the integrity and functionality of the transmitted data.
Data Source
AI summary
A method comprising, at a processor-controlled device, obtaining encrypted data comprising an encrypted data portion, obtaining an identifier indicative of a characteristic associated with the processor-controlled device, and performing a decryption process. The decryption process comprises decrypting the encrypted data portion to generate a decrypted data portion, and generating decrypted data comprising the decrypted data portion and an identifying portion based on the identifier.


