Formal Model for IoT Security via Behavioral Schema

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large-scale IoT infrastructure in smart buildings lacks a common data model, leading to limited interoperability and holistic analysis, making them vulnerable to cyberattacks due to ad-hoc security evaluation methods and inadequate access control enforcement.

Innovation Solution

A method that translates descriptions of physical environments and device behavior profiles into a formal model, generating network flow rules to enhance security by enforcing expected network behavior and detecting anomalous patterns using machine learning techniques.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a formal model combining device behavioral models and building schema is implemented, then security evaluation and attack surface detection capability is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity evaluation capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security evaluation system into distinct components: device behavioral models, building schema, and a formal model combining both. This segmentation allows each component to be developed, validated, and maintained independently while working together to provide comprehensive security evaluation capabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The formal model acts as an intermediary layer that translates and integrates device behavioral models with building schema into a unified representation. This intermediary structure enables systematic security evaluation without requiring direct complex interactions between all system components.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If heterogeneous IoT devices from multiple vendors are integrated, then system functionality and interoperability are improved, but security vulnerability and attack surface increase

Engineering Contradiction:
ImproveinteroperabilityVSAvoidattack surface
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent creates a universal formal model that can represent diverse IoT devices from multiple vendors using standardized building schema. This universal representation enables consistent security evaluation across heterogeneous devices while maintaining their specific functionality and interoperability capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of manufacture

If ad-hoc security evaluation methods are used, then implementation simplicity is maintained, but security posture assessment accuracy deteriorates

Engineering Contradiction:
Improveimplementation simplicityVSAvoidsecurity posture assessment accuracy
Core Design Contradiction:
Ease of manufactureVSMeasurement precision

Solution Approach 1:

The patent performs preliminary actions by pre-defining device behavioral models and building schema before security evaluation is needed. These pre-established models enable systematic and accurate security posture assessment without requiring complex ad-hoc analysis during implementation.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20240380768A1Combining device behavioral models and building schema for cyber-security of large-scale IoT infrastructure
Publication Date: 2024.11.14 NEWSOUTH INNOVATIONS PTY LTD
  • US20240380768A1 patent drawing
  • US20240380768A1 patent drawing
  • US20240380768A1 patent drawing

AI summary

Embodiments of the present disclosure may include a method for enforcing network flow rules of a heterogeneous network of devices including receiving a description of a physical environment. Embodiments may also include receiving a device behavior profile of a plurality of network devices. Embodiments may also include receiving at least one network configuration input. Embodiments may also include translating the received description of the physical environment, the received device behavior profile, and the at least one network configuration input into a formal model. Embodiments may also include determining network flow rules based at least in part on the formal model. Embodiments may also include enforcing the network flow rules. In some embodiments, the network flow rules enhance the security of a heterogeneous network of devices.