IoT Device Attack Protection via Hardware-Level Communication Curtailment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

IoT devices are vulnerable to attacks such as BOT attacks and DDoS, with existing defenses being mostly reactive and ineffective, especially when the software is compromised, and there is a growing concern as more devices are connected to networks.

Innovation Solution

An IoT device with a communications module, processor, and activity module that can detect abnormal system parameters, such as excessive power consumption, and throttle or halt communications to prevent attacks, operating independently of compromised software to ensure effective detection and mitigation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If reactive defense mechanisms are used to mitigate IoT attacks, then damage control is possible, but the attacks cannot be stopped at the source and effectiveness diminishes as more devices are compromised

Engineering Contradiction:
Improveattack protection effectivenessVSAvoidattack volume
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary action by establishing baseline communication patterns and system parameter profiles before attacks occur. The system continuously monitors and learns normal device behavior, enabling it to detect and respond to attacks proactively rather than reactively. This baseline establishment allows the system to identify deviations indicating attacks and take preventive measures before significant damage occurs.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies self-service by enabling IoT devices to autonomously detect, analyze, and respond to attacks without external intervention. The device independently monitors its own system parameters, compares them against baselines, and automatically curtails communications when attacks are detected. This self-contained approach ensures protection even when devices are compromised, as the monitoring occurs at the hardware/firmware level rather than relying on vulnerable higher-level software.

Inventive Principle:
Principle #25Self-service

2Adaptability or versatility

If IoT devices are connected to networks for Internet access and remote control, then functionality and usability are improved, but vulnerability to attacks increases

Engineering Contradiction:
Improvedevice functionalityVSAvoidattack susceptibility
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies segmentation by separating the attack detection and response functions from the main application software layer. The system divides protection into independent monitoring of system parameters (CPU usage, memory, power consumption, communications) that operates at a lower level than application software. This segmentation ensures that even if application software is compromised, the core protection mechanisms remain intact and functional.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary layer between the compromised application software and the hardware resources. This intermediary continuously monitors system parameters and acts as a mediator that can block or curtail communications and resource access when attacks are detected. The intermediary operates independently of application software, providing a protective buffer that prevents compromised software from fully exploiting device resources for attacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If software-based security measures are implemented, then protection mechanisms can be deployed, but they become ineffective when the software is compromised

Engineering Contradiction:
Improvesecurity measure effectivenessVSAvoidsoftware dependency
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces software-based security mechanisms with hardware and firmware-level monitoring. Instead of relying on application software to detect and respond to attacks, the system uses direct monitoring of physical system parameters (CPU cycles, memory access patterns, power consumption, communications) at the hardware/firmware level. This substitution ensures that protection mechanisms remain effective even when application software is compromised, as the monitoring occurs at a more fundamental level that is harder to subvert.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Productivity

If communication volume is increased for normal device operation, then device functionality is improved, but it becomes harder to distinguish from attack traffic

Engineering Contradiction:
Improvedevice communication activityVSAvoidattack detection accuracy
Core Design Contradiction:
ProductivityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent applies parameter changes by monitoring multiple system parameters simultaneously (CPU usage, memory consumption, power draw, communications volume, timing patterns) rather than relying on a single metric. The system establishes baseline profiles for normal operation across all these parameters and detects attacks based on deviations from the baseline pattern. This multi-parameter approach enables the system to distinguish between increased communication for legitimate purposes versus attack traffic, as attacks typically affect multiple parameters in characteristic ways that differ from normal operational variations.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11711392B2System for attack protection in IoT devices
Publication Date: 2023.07.25 IOXT LLC
  • US11711392B2 patent drawing
  • US11711392B2 patent drawing
  • US11711392B2 patent drawing

AI summary

An Internet of Things device is herein disclosed. The Internet of Things device comprises a communications module having circuitry to communicatively connect to a computer network, a memory operable to store data, a processor coupled to the memory and the communications module and operable to execute instructions stored in the memory, and an activity module, including at least one of a sensor and a control device. The activity module operates under control of the processor to perform a designated activity with at least one of the sensor and the control device. The activity module further communicates on the computer network via the communications module. The processor curtails a volume of communication of the communications module on the computer network if a measured value of a system parameter exceeds a threshold value.