Obscuring IoT Device Locations via Data Partitioning and VNF Routing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
IoT devices deployed in sensitive areas are vulnerable to malicious attacks, which can compromise data security and safety due to their network connectivity, as attackers can determine device locations and exploit this information for physical harm or crime.
Innovation Solution
Implementing a device network mapping obscuration method using sender devices that partition data into multiple virtual network functions (VNFs) and network randomizer engines, encrypting data, and routing it through participant devices to obscure device locations and create random data traffic characteristics, thereby protecting against malicious scanning and attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If IoT devices are deployed with network interfaces to enable connectivity, then network communication capability is improved, but vulnerability to malicious attacks and location tracking increases
Solution Approach 1:
The patent introduces network randomizer engines and virtual network functions as intermediary components between IoT devices and the network. These intermediaries obscure the true device locations by generating random traffic patterns and routing data through multiple participant devices, thereby maintaining network connectivity while protecting against malicious attacks and location tracking
Solution Approach 2:
The patent segments data into multiple data partitions that are routed through different virtual network functions and participant devices. This segmentation prevents attackers from obtaining complete information about device locations and network topology, as each participant only handles a portion of the total data traffic
2Reliability
If data is routed through multiple virtual network functions to obscure device locations, then security is improved, but system complexity increases
Solution Approach 1:
The patent designs virtual network functions and network randomizer engines that perform multiple functions simultaneously: data encryption, traffic pattern randomization, location obscuration, and secure routing. This multi-functionality reduces the number of separate components needed, thereby managing system complexity while maintaining high security standards
3Difficulty of detecting and measuring
If network randomizer engines are implemented to create random traffic characteristics, then detection difficulty is improved, but processing overhead increases
Solution Approach 1:
The network randomizer engines implement periodic traffic patterns that mimic normal device behavior while obscuring true device locations. By using periodic rather than continuously random patterns, the system reduces processing overhead while maintaining detection difficulty for attackers
Data Source
AI summary
A sender device can determine that data associated with an application is to be sent to a service via a network. The sender device can generate resource queries directed to at least two participant devices and receive responses indicating whether each of the participant devices has a resource available to host a virtual network function (“VNF”). The sender device can generate commands directed to security interface applications executed by the participant devices. The commands can instruct the participant devices to instantiate the VNFs. The sender device can partition the data into data partitions directed to the participant devices. The sender device can send the data partitions to the VNFs of the participant devices. The VNFs can forward the data partitions to a network access device that can combine the data partitions and send the data to the service via the network.


