IoT Device Security via Network Hub Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security solutions for IoT devices are inadequate due to their limited computing capabilities, resource constraints, and the rapid evolution of malware, making them vulnerable to attacks that can compromise data integrity, availability, and confidentiality, particularly in the context of the Industrial Internet of Things (IIoT) where such breaches can have catastrophic consequences.

Innovation Solution

A method and system for controlling IoT devices from a network hub by analyzing their characteristics, adjusting settings based on security and functionality assessments, and managing access rights to enhance information security, utilizing a secure operating system and machine learning models to predict device behavior and identify vulnerabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security solutions are deployed on IoT devices, then security protection is provided, but the limited computing capabilities and resource constraints of IoT devices make these solutions ineffective and redundant

Engineering Contradiction:
Improvesecurity protectionVSAvoidcomputing platform requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a network hub as an intermediary device that performs security analysis and control functions. The hub analyzes IoT device characteristics, generates security policies, and manages access rights centrally, rather than requiring each IoT device to have full security capabilities. This mediator approach allows security functions to be executed on more powerful infrastructure while protecting resource-constrained IoT devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security policies and anti-virus applications are implemented on IoT devices, then malware protection is attempted, but the limited functionality operating systems with few resources make these measures redundant

Engineering Contradiction:
Improvemalware protectionVSAvoidoperating system functionality
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent extracts security analysis and policy enforcement functions from the IoT devices themselves and relocates them to the network hub. The hub performs characteristic analysis, generates security policies, and manages access control centrally. This extraction allows IoT devices to operate with simple, resource-constrained operating systems while still receiving comprehensive security protection from the centralized system.

Inventive Principle:
Principle #2Taking out (Extraction)

3Adaptability or versatility

If the number of IoT devices is increased to expand network coverage and functionality, then network capability is improved, but the large volume of traffic enables botnet exploitation for malicious activity

Engineering Contradiction:
Improvenetwork coverageVSAvoidbotnet exploitation risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements continuous feedback mechanisms where the network hub monitors IoT device characteristics, network traffic patterns, and security status in real-time. Based on this feedback, the hub dynamically adjusts security policies, generates access control rules, and responds to potential threats. This feedback loop enables the system to maintain security as the network scales, detecting and responding to botnet activity even as device numbers increase.

Inventive Principle:
Principle #23Feedback

4Productivity

If information is transferred from IoT devices to improve service quality, then service functionality is enhanced, but malicious users may obtain sensitive personal information

Engineering Contradiction:
Improveservice qualityVSAvoidpersonal information security
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The patent changes the parameters of information transfer by implementing characteristic-based analysis and policy-driven control. The network hub analyzes device characteristics, determines appropriate information sharing parameters, and enforces access control policies that regulate what information can be transferred. This parameter control allows useful data exchange for service improvement while preventing unauthorized access to sensitive personal information through dynamically adjusted security settings.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP4057570A1System and method for controlling an IoT device from a node in a network infrastructure
Publication Date: 2022.09.14 AO KASPERSKY LAB
  • EP4057570A1 patent drawingFigure 1
  • EP4057570A1 patent drawingFigure 2
  • EP4057570A1 patent drawingFigure 3

AI summary

Disclosed herein are systems and methods for controlling an IoT device from a node (hub) in a network infrastructure. In one example, an exemplary method comprises, analyzing the IoT device based on at least one of: characteristics of functionalitites of the IoT device, characteristics of information security of the IoT device, and characteristics of an impact on human life by the IoT device and/or by the security of the IoT device, adjusting the IoT device based on results of the analysis, determining whether the characteristics for which the analysis was performed changed during an operation of the device, and when the characteristics for which the analysis was performed changed, changing one or more settings associated with the IoT device based on the changes determined during the operation of the device.