IoT Security Management via Unique Device Signatures

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

IoT-based devices in industrial IoT environments often pose cybersecurity risks due to non-compliance with pre-defined security standards, threatening the security of connected devices and the IoT-cloud platform.

Innovation Solution

A method and system that determine violations of pre-defined security requirements in IoT-based devices, generate unique signatures, and take corrective actions to ensure compliance, including terminating communication with vulnerable devices, performing security updates, and storing signatures in a vulnerable-device repository to prevent security risks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If IoT-based devices with different security capabilities are connected to the IoT-cloud platform, then device connectivity and functionality are improved, but security risks and vulnerability propagation increase

Engineering Contradiction:
Improvedevice connectivityVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary security mechanism between IoT devices and the cloud platform. The system acts as a mediator that intercepts, analyzes, and validates security tokens from devices before allowing communication. This intermediary layer enables diverse devices with varying security capabilities to connect while preventing vulnerable devices from compromising the overall system security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the security validation process into distinct components: device identification, security token generation, token validation, and selective communication blocking. By dividing the security management into separate functional modules, the system can independently assess and control security risks for each device without affecting others, thus maintaining both connectivity and security.

Inventive Principle:
Principle #1Segmentation

2Reliability

If security validation is performed on all IoT-based devices, then security compliance is improved, but system complexity and processing overhead increase

Engineering Contradiction:
Improvesecurity complianceVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements partial validation by focusing security checks on critical authentication tokens rather than examining all device functions and configurations. The system performs selective security validation - generating and validating specific security tokens for communication control - rather than进行全面 comprehensive security auditing of each device, thus maintaining security compliance while reducing system complexity.

Inventive Principle:
Principle #16Partial or excessive action

3Object-affected harmful factors

If communication is terminated with vulnerable IoT-based devices, then security risk propagation is reduced, but device functionality and data flow are disrupted

Engineering Contradiction:
Improvesecurity risk propagationVSAvoiddata flow
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

The patent implements dynamic communication control where the system can adaptively adjust device connectivity based on real-time security assessments. Devices that fail security validation have their communication dynamically restricted or terminated, while compliant devices maintain normal data flow. This dynamic approach ensures security risk propagation is minimized while preserving productivity for authorized devices.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11394729B2Method and system for managing IoT-based devices in an internet-of-things environment
Publication Date: 2022.07.19 SIEMENS AG
  • US11394729B2 patent drawing
  • US11394729B2 patent drawing
  • US11394729B2 patent drawing

AI summary

A method and system for managing IoT-based devices in an Internet-of-Things (IoT) environment is disclosed. The method includes determining violation of at least one pre-defined security requirement by at least one IoT-based device. Then, the method includes generating a unique signature of the IoT-based device based on information associated with the IoT-based device. The method includes terminating communication between the IoT-based device and an IoT-cloud platform. Also, the method includes sending a first notification indicating that the IoT-based device violates the at least one pre-defined security requirement to the IoT-based devices connected to the IoT-cloud platform. The first notification includes the unique signature of the IoT-based device.