IoT Data Security Management via Sensitivity-Based Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The exponential growth of IoT devices generates massive amounts of data that require secure management and processing, leading to increased financial and computing costs due to the need for extensive data encryption and decryption for read-intensive applications, with existing cloud systems employing all-or-nothing encryption approaches that lack fine-grained security and cost efficiency.
Innovation Solution
Implementing a security management system that classifies IoT data based on sensitivity levels, applying appropriate encryption and masking techniques, and utilizing tiered storage and analytics to minimize unnecessary computing power and costs, allowing for secure data storage and processing while optimizing performance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If all-or-nothing encryption is applied to all IoT data in cloud systems, then data security is improved, but computing and financial costs increase due to extensive encryption and decryption operations
Solution Approach 1:
The patent applies different encryption strengths and types to different data based on their sensitivity levels. High-sensitivity data receives strong encryption while low-sensitivity data receives minimal or no encryption, eliminating the need for uniform encryption across all data and reducing computational overhead.
Solution Approach 2:
The patent segments data into different sensitivity levels (e.g., public, internal, confidential, restricted) and applies differentiated encryption policies to each segment. This allows the system to encrypt only the portions of data that require protection, reducing overall encryption/decryption operations.
2Reliability
If all-or-nothing encryption is applied to all IoT data, then data protection is improved, but financial costs increase due to unnecessary encryption operations
Solution Approach 1:
The system applies encryption quality matched to data sensitivity levels, avoiding over-encryption of data that does not require protection and reducing financial costs associated with encryption operations.
Solution Approach 2:
The patent applies partial encryption only to the extent necessary for data protection, rather than applying encryption universally to all data. This eliminates excessive encryption operations on low-sensitivity data.
3Reliability
If data is encrypted at high levels for all data types, then security is improved, but read-intensive application performance deteriorates due to unnecessary decryption
Solution Approach 1:
The patent implements differentiated encryption levels based on data sensitivity, allowing read-intensive applications to access low-sensitivity data without decryption overhead while maintaining strong security for high-sensitivity data.
Solution Approach 2:
The system applies encryption only to the extent necessary for security requirements, avoiding excessive encryption on data that can be read without decryption, thus improving application performance.
4Reliability
If uniform encryption policies are applied to all data, then security consistency is improved, but cost efficiency deteriorates
Solution Approach 1:
The patent implements differentiated encryption policies tailored to each data sensitivity level, achieving cost efficiency by applying appropriate security measures only where needed while maintaining overall security consistency through a structured classification framework.
Data Source
AI summary
Techniques are provided for secure data management in a network computing environment. A security management system receives data from a device which operates in a device network that is managed by the security management system. The security management system performs a data classification process to determine a data sensitivity level of the received data. The security management system determines a type of encryption to apply to the received data based on the determined data sensitivity level. The type of encryption is determined from a plurality of different types of encryption that are supported by a cloud system. The security management system sends the received data to the cloud system to at least one of store the data and perform secured data analytic processing of the data, in a format according to the determined type of encryption.


