IoT Device Secure Zone Driver for Malicious Attack Response
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
IoT devices with low computing power are vulnerable to malicious attacks and lack effective response mechanisms, as they cannot accurately determine normal or abnormal operating states, leading to inadequate security measures.
Innovation Solution
An IoT device with a first memory in a normal zone and a second driver in a secure zone, where the first driver monitors data changes and transmits information to the second driver, which then communicates with an IoT device management system to control the device's operating state, leveraging high computing power to respond to malicious attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If IoT devices use low specification processors to reduce cost, then manufacturing cost is reduced, but security response capability deteriorates
Solution Approach 1:
The patent introduces a trusted execution environment (TEE) as an intermediary layer between the normal application and the processor. This TEE provides secure cryptographic operations and security management functions, enabling the low-cost processor to achieve enhanced security capabilities without requiring a high-performance processor. The TEE acts as a mediator that compensates for the security response capability limitations of low-specification processors.
2Device complexity
If IoT devices lack accurate determination of operating states, then device complexity is reduced, but security protection deteriorates
Solution Approach 1:
The patent implements a feedback mechanism where the first driver continuously monitors the operating state of the IoT device and provides this information to the second driver in the trusted execution environment. The second driver analyzes the operating state information and provides feedback control by adjusting security parameters or triggering security responses. This feedback loop enables accurate determination of operating states without significantly increasing device complexity.
3Device complexity
If IoT devices cannot recognize malicious attacks, then device complexity is reduced, but reliability deteriorates
Solution Approach 1:
The patent introduces the trusted execution environment as an intermediary security module that specifically handles attack recognition and response functions. The second driver within the TEE is responsible for receiving operating state information, determining whether malicious attacks are occurring, and generating appropriate security instructions. This separation of security functions into an intermediary TEE layer enables attack recognition capability without burdening the main processor or significantly increasing overall device complexity.
Data Source
AI summary
An Internet of Things (IoT) device includes a first memory disposed in a normal zone; a first driver disposed in the normal zone; and a second driver disposed in a secure zone. The first driver is configured to perform: (a) monitoring the first memory to generate data change information of the first memory, the data change information being information on changes of data in the first memory; (b) transmitting the data change information to the second driver; and (c) controlling an operating state of the IoT device based on an instruction for the operating state received from the second driver. The second driver is configured to perform: (d) transmitting the data change information to a specified IoT device management system; and (e) receiving the instruction for the operating state from the IoT device management system and transmitting the instruction for the operating state to the first driver.


