LPWA Device Routing by Security Credibility
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Low-Power Wide-Area (LPWA) wireless communication networks, particularly Narrowband IoT (NB IoT), face challenges in security due to limited hardware resources, making existing security mechanisms from smartphones infeasible for these devices.
Innovation Solution
A communication device with a secure proxy or relay functionality that extends communication between neighboring devices and a base station, considering the security credibility of neighboring devices, using a multi-hop routing scheme and implementing a security system with hardware and/or software-based virtualization, and multiple security domains for authentication and access control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If smartphone security mechanisms are used in LPWA devices, then security reliability is improved, but device complexity and energy consumption increase beyond what limited hardware resources can support
Solution Approach 1:
The patent segments security functionality into separate security domains (first security domain for authentication, second security domain for encryption) that can operate independently. This allows essential security functions to be implemented with minimal hardware resources while maintaining security reliability, avoiding the need for comprehensive smartphone-level security mechanisms.
Solution Approach 2:
The patent extracts and implements only the critical security functions needed for LPWA devices (authentication and encryption) rather than implementing complete smartphone security mechanisms. This extraction approach reduces device complexity and energy consumption while maintaining adequate security reliability for the specific LPWA application context.
2Reliability
If comprehensive security mechanisms are implemented in LPWA devices, then security credibility is improved, but use of energy increases beyond battery capacity
Solution Approach 1:
Security functions are segmented into distinct domains with specific responsibilities. The first security domain handles authentication with the base station, while the second security domain handles data encryption. This segmentation allows the device to perform only essential security operations, reducing energy consumption while maintaining security credibility.
Solution Approach 2:
The patent implements partial security functionality tailored to LPWA requirements rather than comprehensive security mechanisms. By implementing only authentication and encryption functions needed for LPWA devices, the system achieves adequate security credibility with significantly reduced energy consumption compared to full smartphone security implementations.
3Reliability
If security domains are separated into distinct modules, then security functionality is improved, but device complexity increases
Solution Approach 1:
The patent segments security functionality into two distinct security domains: a first security domain for authentication and a second security domain for encryption. Each domain is implemented as a separate functional module with dedicated hardware resources, improving security functionality through functional separation while keeping each individual domain simple and resource-efficient.
Solution Approach 2:
Each security domain is designed to perform multiple related functions within its scope. The first security domain handles various authentication operations, while the second security domain handles different encryption operations. This multi-functionality approach improves overall security functionality without requiring separate dedicated hardware for each individual operation, thereby controlling device complexity.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The invention relates to a communication device (110a) for communicating data over a low power wide area, LPWA, communication network (100), wherein the communication device (110a) comprises: a processor configured to process data; a memory configured to store data; and a radio configured to receive data from and transmit data to neighbouring communication devices (110b-e) and/or a base station (130); wherein the processor is configured to route the data received from neighbouring communication devices (110b-e) to other neighbouring communication devices (110b-e) and/or the base station (130) of the LPWA communication network (100) on the basis of a routing scheme stored in the memory and wherein the routing scheme is based on information about a respective security credibility of the respective neighbouring communication devices (110b-e).