IoT Security via Edge-Cloud Segmentation and Lightweight ML

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

IoT devices lack effective features to prevent, mitigate, or recover from cyberattacks, due to limited memory and compute resources.

Innovation Solution

A system and method utilizing machine learning and a set of rules to enhance device security, which acquires log data from IoT devices, prepares a feature set, and applies incident detection rules and ML models to detect and mitigate security incidents.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If machine learning models and incident detection rules are deployed on IoT devices, then security detection and mitigation capability is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments security functions by deploying lightweight ML models and detection rules specifically on edge devices, while centralizing heavy data processing and analysis in cloud servers. This segmentation allows edge devices to perform basic security detection without requiring full security operation center capabilities, thus improving security capability while managing complexity through functional division.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a cloud-based security operation center as an intermediary between edge devices and the broader security ecosystem. This intermediary receives log data from edge devices, performs comprehensive analysis using advanced ML models, and provides guidance for incident response. This mediator approach allows edge devices to maintain simplicity while gaining access to advanced security capabilities through the cloud.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If comprehensive security features are installed on IoT devices, then security against cyberattacks is improved, but memory and compute resources are consumed

Engineering Contradiction:
Improvesecurity protectionVSAvoidcompute resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system applies partial action by implementing only the essential security functions on edge devices - lightweight ML models for anomaly detection and incident response rules - rather than deploying comprehensive security suites. This partial implementation provides sufficient security protection for most IoT devices while consuming minimal compute resources, reserving heavy processing for cloud-based systems when needed.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent employs simplified, lightweight ML models that can be easily deployed and updated on edge devices without requiring substantial computational power. These models are designed to be computationally efficient, similar to using simpler, less expensive objects that achieve the necessary function without excessive resource consumption, allowing security features to be added without proportionally increasing hardware requirements.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Loss of time

If incident detection rules and ML models are applied locally on devices, then response time is improved, but device complexity and resource requirements increase

Engineering Contradiction:
Improveincident response timeVSAvoidprocessing complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The system segments processing tasks by performing quick local evaluations using simplified detection rules and lightweight ML models on edge devices for immediate response, while reserving complex analysis and decision-making for cloud-based security operation centers. This segmentation enables fast local response to common incidents while maintaining complexity management through hierarchical processing.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary action by pre-deploying simplified detection rules and trained lightweight ML models on edge devices before incidents occur. These pre-configured systems can immediately detect and respond to known attack patterns without requiring complex real-time analysis, thus reducing response time while keeping processing complexity low. Complex analysis is performed preliminarily in the cloud and results are cached for future use.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12273379B2Enhancement of device security using machine learning and set of rules
Publication Date: 2025.04.08 SONY GROUP CORP
  • US12273379B2 patent drawing
  • US12273379B2 patent drawing
  • US12273379B2 patent drawing

AI summary

A system and method for enhancement of device security using machine learning and a set of rules is provided. The system acquires log data from an electronic device configured to communicate data via a network. The system prepares a feature set based on the log data. The feature set corresponds to one or more parameters associated with a cybersecurity of the electronic device. The system determines security incidents associated with the electronic device based on at least one of an application of one or more incident detection rules and/or one or more ML models on the feature set. The system collects information associated with the determined security incidents and determines a set of measures to be implemented on the electronic device to mitigate or prevent issues associated with the security incidents. Thereafter, the system controls execution of the determined set of measures on the electronic device.