Obscuring IoT Device Locations via Data Partitioning and VNF Routing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

IoT devices deployed in sensitive areas are vulnerable to malicious attacks, which can compromise data security and safety due to their network connectivity, as attackers can determine device locations and exploit this information for physical harm or crime.

Innovation Solution

Implementing a device network mapping obscuration method using sender devices that partition data into multiple virtual network functions (VNFs) and network randomizer engines, encrypting data, and routing it through participant devices to obscure device locations and create random data traffic characteristics, thereby protecting against malicious scanning and attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If IoT devices are deployed with network interfaces to enable connectivity, then network communication capability is improved, but vulnerability to malicious attacks and location tracking increases

Engineering Contradiction:
Improvenetwork communication capabilityVSAvoidvulnerability to malicious attacks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces network randomizer engines and virtual network functions as intermediary components between IoT devices and the network. These intermediaries obscure the true device locations by generating random traffic patterns and routing data through multiple participant devices, thereby maintaining network connectivity while protecting against malicious attacks and location tracking

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments data into multiple data partitions that are routed through different virtual network functions and participant devices. This segmentation prevents attackers from obtaining complete information about device locations and network topology, as each participant only handles a portion of the total data traffic

Inventive Principle:
Principle #1Segmentation

2Reliability

If data is routed through multiple virtual network functions to obscure device locations, then security is improved, but system complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent designs virtual network functions and network randomizer engines that perform multiple functions simultaneously: data encryption, traffic pattern randomization, location obscuration, and secure routing. This multi-functionality reduces the number of separate components needed, thereby managing system complexity while maintaining high security standards

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Difficulty of detecting and measuring

If network randomizer engines are implemented to create random traffic characteristics, then detection difficulty is improved, but processing overhead increases

Engineering Contradiction:
Improvedetection difficultyVSAvoidprocessing overhead
Core Design Contradiction:
Difficulty of detecting and measuringVSUse of energy by moving object

Solution Approach 1:

The network randomizer engines implement periodic traffic patterns that mimic normal device behavior while obscuring true device locations. By using periodic rather than continuously random patterns, the system reduces processing overhead while maintaining detection difficulty for attackers

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS11502997B1Device network mapping obscuration
Publication Date: 2022.11.15 AT&T INTELLECTUAL PROPERTY I L P
  • US11502997B1 patent drawing
  • US11502997B1 patent drawing
  • US11502997B1 patent drawing

AI summary

A sender device can determine that data associated with an application is to be sent to a service via a network. The sender device can generate resource queries directed to at least two participant devices and receive responses indicating whether each of the participant devices has a resource available to host a virtual network function (“VNF”). The sender device can generate commands directed to security interface applications executed by the participant devices. The commands can instruct the participant devices to instantiate the VNFs. The sender device can partition the data into data partitions directed to the participant devices. The sender device can send the data partitions to the VNFs of the participant devices. The VNFs can forward the data partitions to a network access device that can combine the data partitions and send the data to the service via the network.