IoT Security Profile Management via CPE

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security solutions for IoT devices are costly, require extensive expertise and time to implement, and often necessitate multiple expensive appliances or managed services, lacking in ease of configuration and comprehensive protection for newly added devices.

Innovation Solution

A method and system that involve receiving and storing security profiles for IoT devices, using a communication device to transmit these profiles to Customer Premises Equipment (CPE) for controlling communication with external networks, ensuring secure operation by defining normal and abnormal behavior based on communication analysis, and updating profiles dynamically based on user input and machine learning.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple security appliances are deployed to protect connected locations, then security coverage is improved, but cost and device complexity increase significantly

Engineering Contradiction:
Improvesecurity coverageVSAvoidnumber of security appliances
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple security functions (firewall, intrusion detection, antivirus, URL filtering) into a single integrated CPE device. This consolidation provides comprehensive security coverage while reducing the number of separate appliances needed, directly resolving the contradiction between security coverage and device complexity

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The CPE device is designed to perform multiple security functions simultaneously - acting as a firewall, intrusion detection system, antivirus scanner, and URL filter all in one device. This multi-functionality allows a single appliance to provide the security coverage previously requiring multiple specialized devices

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If multiple security appliances are configured manually, then security customization is improved, but implementation time and expertise requirements increase

Engineering Contradiction:
Improvesecurity customizationVSAvoidimplementation time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system automatically discovers IOT devices on the network, retrieves their identifiers, and configures appropriate security profiles without requiring manual intervention. This self-service capability maintains security customization while eliminating the time-consuming manual configuration process

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Security profiles are pre-configured in the system database based on device identifiers. When a new IOT device is detected, the matching security profile is automatically applied, eliminating the need for real-time manual configuration and reducing implementation time while maintaining customization

Inventive Principle:
Principle #10Preliminary action

3Reliability

If manual configuration is performed for each new device, then device-specific security is improved, but scalability and ease of operation deteriorate

Engineering Contradiction:
Improvedevice-specific securityVSAvoidease of configuration
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The CPE automatically performs device discovery, identifier retrieval, and security profile configuration for each new IOT device without requiring user intervention. This automated self-service process maintains device-specific security customization while dramatically improving ease of operation and scalability

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system continuously monitors the network for new IOT devices, automatically detects them, and configures appropriate security profiles based on their identifiers. This feedback loop ensures each device receives customized security configuration automatically, improving both ease of operation and scalability while maintaining device-specific security

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10911494B2Methods and systems for providing security to iot devices operating in an environment
Publication Date: 2021.02.02 GIOKAS IOANNIS
  • US10911494B2 patent drawing
  • US10911494B2 patent drawing
  • US10911494B2 patent drawing

AI summary

A method of providing security to IOT devices operating in an environment is disclosed. The method may include receiving, using a communication device, a plurality of security profiles associated with a plurality of IOT devices from at least one security database. Further, the method may include storing, using a storage device, the plurality of security profiles. Further, the method may include receiving, using the communication device, a plurality of identifiers associated with the plurality of IOT devices from a customer premises equipment. Further, the method may include retrieving, using the storage device, the plurality of security profiles associated with the plurality of IOT devices based on the plurality of identifiers. Further, the method may include and transmitting, using the communication device, the plurality of security profiles to the CPE.