IoT Secure Signal Processing via Segmented Security Zones

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for handling IoT device signals face data security risks and resource consumption issues, failing to enable effective analytics that could improve processes.

Innovation Solution

A security system that generates secure signals by using domain distribution service domains to create security zones, providing point-to-point mutual authentication, and encrypting data in transit and storage, following the IEC-62443 cybersecurity standard, allowing for near real-time control and data collection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If IoT device signals are handled by external systems for analytics, then data analytics capability is improved, but data security risk increases

Engineering Contradiction:
Improvedata analytics capabilityVSAvoiddata security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system segments the data handling architecture into multiple security zones (Zone 1 for device signals, Zone 2 for processing, Zone 3 for analytics, Zone 4 for storage) with secure data layers between them. This segmentation allows analytics to proceed while maintaining security boundaries, resolving the contradiction between analytics capability and data security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Secure data layers act as intermediaries between security zones, providing controlled data transmission with encryption and authentication. These intermediaries enable analytics processing while preventing direct unauthorized access to sensitive IoT device signals, thus maintaining both analytics capability and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security measures are implemented for IoT device signals, then data security is improved, but resource consumption increases

Engineering Contradiction:
Improvedata securityVSAvoidcomputing resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

Security measures are segmented and applied only where necessary between zones rather than uniformly across the entire system. This targeted approach provides strong security at critical boundaries while minimizing resource consumption in data processing zones, resolving the contradiction between security and resource usage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different security measures are applied locally to different zones based on their specific requirements. Zone 1 focuses on device authentication, secure data layers focus on encrypted transmission, and Zone 4 focuses on secure storage. This localized quality approach optimizes resource consumption by applying appropriate security measures only where needed.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11700242B2Systems and methods for generating secure signals based on internet of things device signals
Publication Date: 2023.07.11 VERIZON PATENT & LICENSING INC
  • US11700242B2 patent drawing
  • US11700242B2 patent drawing
  • US11700242B2 patent drawing

AI summary

A device may receive a secure signal message from an IoT device provided in a first security zone, and may provide the secure signal message from the first security zone to a second security zone, via a first secure data layer. The device may generate two processed secure signal messages from the secure signal message, and may provide the two processed secure signal messages from the second security zone to a third security zone, via a second secure data layer. The device may calculate a secure analytics message, that includes a graph, based on the two processed secure signal messages, and may provide the secure analytics message from the third security zone to a fourth security zone, via a third secure data layer. The device may store the secure analytics message in a data structure associated with the fourth security zone.