IoT Network Anomaly Detection via Group Attestation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In a distributed Internet of Things (IoT) infrastructure, existing solutions for preventing physical and wireless channel errors, as well as malicious attacks, face challenges due to resource constraints, heterogeneity in hardware, and the risk of single points of failure in root of trust solutions, making it difficult to deploy and maintain security across IoT devices.

Innovation Solution

The approach employs group attestation using a public ledger system, such as Blockchain, to collect and cross-validate data from IoT endpoints, detecting anomalies by comparing readings across sensors and reporting inconsistencies, thus addressing the limitations of existing solutions without requiring physical modifications to IoT devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hardware-based root of trust solutions (e.g., TrustZone, TPM) are deployed on every IoT device, then security against physical and wireless attacks is improved, but device cost and complexity increase

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a network-based attestation service as an intermediary between IoT devices and the verification system. Instead of requiring complex hardware roots of trust in each device, the service mediates security verification through software-based attestation protocols that leverage existing device capabilities, thereby improving security without significantly increasing device complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces hardware-based root of trust mechanisms with software-based attestation services. By substituting the mechanical/hardware approach with a software service running on existing device infrastructure, the system achieves comparable security guarantees without requiring additional hardware components in each IoT device

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If hardware-based root of trust solutions are deployed on every IoT device, then security is improved, but deployment feasibility decreases due to resource constraints and heterogeneity

Engineering Contradiction:
ImprovesecurityVSAvoiddeployment feasibility
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent creates a universal attestation service that can operate across heterogeneous IoT devices with varying hardware capabilities. The service is designed to work with existing device resources and can be deployed across different device types without requiring uniform hardware roots of trust, thereby improving deployment feasibility while maintaining security

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent replaces expensive, permanent hardware security modules with lighter-weight software-based attestation mechanisms. The software service can be updated, replaced, or revoked without physical hardware changes, making the system more adaptable and easier to deploy across diverse device populations with constrained resources

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Device complexity

If a single root of trust is used in each IoT device, then security verification is simplified, but the system becomes vulnerable to single points of failure

Engineering Contradiction:
Improvesecurity verification complexityVSAvoidvulnerability to compromise
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the security verification function into distributed attestation services that operate across multiple independent nodes in the network. Instead of relying on a single root of trust per device, the system uses multiple attestation service instances that can independently verify device states, thereby eliminating single points of failure while keeping verification complexity manageable through standardized protocols

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11520880B2Identifying internet of things network anomalies using group attestation
Publication Date: 2022.12.06 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11520880B2 patent drawing
  • US11520880B2 patent drawing
  • US11520880B2 patent drawing

AI summary

An approach is provided that identifies Internet of Things (IoT) network anomalies. The approach receives IoT endpoint device data at an attestation entity included in the network. The data is logged to a secured ledger and analyzed. Conditions pertaining to the IoT endpoint devices are analyzed with the analysis being based on a set of network policy data. Based on the analysis, the approach detects network anomalies that correspond to the IoT endpoint devices. These network anomalies and their corresponding IoT endpoint devices are then reported.