IoT Secure Signal Processing via Segmented Security Zones
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems for handling IoT device signals face data security risks and resource consumption issues, failing to enable effective analytics that could improve processes.
Innovation Solution
A security system that generates secure signals by using domain distribution service domains to create security zones, providing point-to-point mutual authentication, and encrypting data in transit and storage, following the IEC-62443 cybersecurity standard, allowing for near real-time control and data collection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If IoT device signals are handled by external systems for analytics, then data analytics capability is improved, but data security risk increases
Solution Approach 1:
The system segments the data handling architecture into multiple security zones (Zone 1 for device signals, Zone 2 for processing, Zone 3 for analytics, Zone 4 for storage) with secure data layers between them. This segmentation allows analytics to proceed while maintaining security boundaries, resolving the contradiction between analytics capability and data security.
Solution Approach 2:
Secure data layers act as intermediaries between security zones, providing controlled data transmission with encryption and authentication. These intermediaries enable analytics processing while preventing direct unauthorized access to sensitive IoT device signals, thus maintaining both analytics capability and security.
2Reliability
If security measures are implemented for IoT device signals, then data security is improved, but resource consumption increases
Solution Approach 1:
Security measures are segmented and applied only where necessary between zones rather than uniformly across the entire system. This targeted approach provides strong security at critical boundaries while minimizing resource consumption in data processing zones, resolving the contradiction between security and resource usage.
Solution Approach 2:
Different security measures are applied locally to different zones based on their specific requirements. Zone 1 focuses on device authentication, secure data layers focus on encrypted transmission, and Zone 4 focuses on secure storage. This localized quality approach optimizes resource consumption by applying appropriate security measures only where needed.
Data Source
AI summary
A device may receive a secure signal message from an IoT device provided in a first security zone, and may provide the secure signal message from the first security zone to a second security zone, via a first secure data layer. The device may generate two processed secure signal messages from the secure signal message, and may provide the two processed secure signal messages from the second security zone to a third security zone, via a second secure data layer. The device may calculate a secure analytics message, that includes a graph, based on the two processed secure signal messages, and may provide the secure analytics message from the third security zone to a fourth security zone, via a third secure data layer. The device may store the secure analytics message in a data structure associated with the fourth security zone.


