IoT Security via Unspoofable Tags and Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Internet of Things (IoT) devices within enterprise IT infrastructures pose significant security risks due to weak access mechanisms, lack of granular user access permissions, exposure to multiple networks, and vulnerability to software and firmware overwriting, making them infiltration points for the infrastructure.

Innovation Solution

A security system utilizing Transport Layer Security (TLS) mechanisms, including a controller, policy enforcement points (PEPs), and a certification server, to manage and enforce security policies across IoT devices and services, segregating them from other infrastructure elements and ensuring secure communication through unspoofable tags and whitelisting.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If IoT devices are deployed across multiple networks without segmentation, then network coverage and accessibility are improved, but security vulnerabilities and exposure to attacks increase

Engineering Contradiction:
Improvenetwork coverageVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements network segmentation by creating a dedicated IoT subnet that separates IoT devices from the main corporate network. This segmentation allows IoT devices to communicate across multiple networks and locations while isolating them in a controlled environment, thus maintaining network coverage benefits while reducing security vulnerabilities through architectural separation.

Inventive Principle:
Principle #1Segmentation

2Reliability

If traditional data center security features are applied to IoT devices, then security protection is improved, but device complexity and deployment difficulty increase

Engineering Contradiction:
Improvesecurity protectionVSAvoiddeployment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a gateway device as an intermediary between IoT devices and the corporate network. The gateway implements security policies, authentication, and encryption centrally, allowing simple IoT devices to benefit from enterprise-grade security without requiring complex security features embedded in each device. This mediator approach provides strong security protection while keeping individual device complexity low.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If IoT devices allow easy software and firmware updates, then device functionality and adaptability are improved, but security risks from unauthorized overwriting increase

Engineering Contradiction:
Improvesoftware update capabilityVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements a secure boot process with cryptographic verification that provides feedback on the integrity of firmware before execution. The system checks digital signatures and hash values of firmware updates, allowing legitimate updates to proceed while blocking unauthorized modifications. This feedback mechanism maintains software adaptability through easy updates while preventing security risks from malicious overwriting.

Inventive Principle:
Principle #23Feedback

4Ease of operation

If IoT devices use weak access mechanisms, then ease of operation and setup are improved, but password security and encryption vulnerabilities increase

Engineering Contradiction:
Improvesetup simplicityVSAvoidaccess security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements preliminary action by pre-configuring strong cryptographic credentials, certificates, and security policies in IoT devices during manufacturing. This preliminary setup provides strong access security from the outset while maintaining ease of operation, as devices are already secured and ready for deployment without requiring complex security configuration by end users. The security is built-in before the device reaches the user.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10389753B2Security system and method for internet of things infrastructure elements
Publication Date: 2019.08.20 NTT RESEARCH INC
  • US10389753B2 patent drawing
  • US10389753B2 patent drawing
  • US10389753B2 patent drawing

AI summary

A security system and method are provided that manage the security of a plurality of internet of things (IoT) devices that are part of an enterprise infrastructure. The security system and method may use unspoofable tags wherein each unspoofable tag may be assigned to a category of IoT devices and each unspoofable tag may have a security policy rule assigned to the unspoofable tag (and thus the category of IoT devices) so that IoT devices that are part of the enterprise infrastructure are secured by the security policy rule.