Protocol-Agnostic IoT Security via Out-of-Band Health Checks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security infrastructure for IoT devices is inadequate due to limited processing power, memory, and network connectivity, and existing security measures are protocol-dependent and ineffective against unknown attacks, lacking robustness against unauthorized access and malware.

Innovation Solution

A distributed system utilizing a security broker to generate digital fingerprints of IoT devices and store them in a distributed ledger database for out-of-band validity checks, allowing continuous integrity health checks and restoration of devices to a secure state without relying on specific protocols or known malware signatures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If protocol-dependent security measures are implemented, then security effectiveness against known threats is improved, but device complexity and processing burden increase

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidprocessing burden
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments security functionality into two parts: a lightweight agent on the IoT device that only performs local health checks and data collection, and a centralized security management system that handles fingerprint generation, storage, and analysis. This segmentation reduces the processing burden on resource-constrained IoT devices while maintaining comprehensive security effectiveness.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a security agent as an intermediary component that runs on the IoT device. This agent acts as a mediator between the device's limited resources and the comprehensive security requirements, performing only lightweight local checks while delegating complex security operations to the centralized system, thereby reducing device complexity and processing burden.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of manufacture

If protocol-dependent security measures are used, then security implementation is simplified for specific protocols, but adaptability to different communication protocols decreases

Engineering Contradiction:
Improvesecurity implementation simplicityVSAvoidprotocol compatibility
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent implements a universal security architecture where the centralized security management system can generate and manage fingerprints for multiple different communication protocols (HTTP, MQTT, CoAP, etc.). The system adapts to different protocols without requiring protocol-specific security implementations on each device, achieving both ease of implementation and broad protocol compatibility through a single multi-functional platform.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If traditional security systems with centralized control are used, then security management is simplified, but network bandwidth consumption and processing delays increase

Engineering Contradiction:
Improvesecurity management simplicityVSAvoidprocessing delays
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-generating security fingerprints and storing them in a distributed ledger before security incidents occur. The health check mechanism continuously verifies device states against these pre-established fingerprints, enabling rapid detection and response without requiring real-time centralized analysis, thereby reducing processing delays while maintaining simplified security management.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent transitions from traditional centralized security management to a distributed architecture using a distributed ledger. This dimensional change from centralized to distributed storage and verification enables parallel processing of health checks across multiple nodes, reducing network bandwidth consumption and processing delays while maintaining ease of security management through the ledger's inherent structure.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

4Reliability

If comprehensive security monitoring is implemented, then security breach detection capability is improved, but processing power requirements and energy consumption increase

Engineering Contradiction:
Improvesecurity breach detection capabilityVSAvoidenergy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent implements partial action by having the IoT device's security agent perform only essential local health checks and data collection, rather than comprehensive security analysis. The agent collects sufficient data to maintain accurate fingerprints and report anomalies, delegating the computationally intensive analysis to the centralized security management system, thereby achieving effective breach detection with reduced energy consumption on resource-constrained devices.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10630702B1Protocol agnostic security by using out-of-band health checks
Publication Date: 2020.04.21 XAGE SECURITY INC
  • US10630702B1 patent drawing
  • US10630702B1 patent drawing
  • US10630702B1 patent drawing

AI summary

A computer-implemented method provides an improvement in security breach detection and comprises using a broker computing device, sending an initial digital fingerprint of a computing device out-of-band for storing in a distributed data repository, wherein the initial digital fingerprint is based on initial security service data of the computing device; using a gateway computing device, remotely calculating a current digital fingerprint of the computing device based on current security service data of the computing device; using the gateway computing device, conducting a real-time out-of-band health check of the computing device based, at least in part, on the initial digital fingerprint stored in the distributed data repository; and using the gateway computing device, in response to conducting the real-time out-of-band health check, determining whether to restore the computing device with configurations consistent with the initial digital fingerprint stored in the distributed data repository.