LPWA Device Routing by Security Credibility

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Low-Power Wide-Area (LPWA) wireless communication networks, particularly Narrowband IoT (NB IoT), face challenges in security due to limited hardware resources, making existing security mechanisms from smartphones infeasible for these devices.

Innovation Solution

A communication device with a secure proxy or relay functionality that extends communication between neighboring devices and a base station, considering the security credibility of neighboring devices, using a multi-hop routing scheme and implementing a security system with hardware and/or software-based virtualization, and multiple security domains for authentication and access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If smartphone security mechanisms are used in LPWA devices, then security reliability is improved, but device complexity and energy consumption increase beyond what limited hardware resources can support

Engineering Contradiction:
Improvesecurity reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments security functionality into separate security domains (first security domain for authentication, second security domain for encryption) that can operate independently. This allows essential security functions to be implemented with minimal hardware resources while maintaining security reliability, avoiding the need for comprehensive smartphone-level security mechanisms.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts and implements only the critical security functions needed for LPWA devices (authentication and encryption) rather than implementing complete smartphone security mechanisms. This extraction approach reduces device complexity and energy consumption while maintaining adequate security reliability for the specific LPWA application context.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If comprehensive security mechanisms are implemented in LPWA devices, then security credibility is improved, but use of energy increases beyond battery capacity

Engineering Contradiction:
Improvesecurity credibilityVSAvoiduse of energy
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

Security functions are segmented into distinct domains with specific responsibilities. The first security domain handles authentication with the base station, while the second security domain handles data encryption. This segmentation allows the device to perform only essential security operations, reducing energy consumption while maintaining security credibility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements partial security functionality tailored to LPWA requirements rather than comprehensive security mechanisms. By implementing only authentication and encryption functions needed for LPWA devices, the system achieves adequate security credibility with significantly reduced energy consumption compared to full smartphone security implementations.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If security domains are separated into distinct modules, then security functionality is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity functionalityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments security functionality into two distinct security domains: a first security domain for authentication and a second security domain for encryption. Each domain is implemented as a separate functional module with dedicated hardware resources, improving security functionality through functional separation while keeping each individual domain simple and resource-efficient.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Each security domain is designed to perform multiple related functions within its scope. The first security domain handles various authentication operations, while the second security domain handles different encryption operations. This multi-functionality approach improves overall security functionality without requiring separate dedicated hardware for each individual operation, thereby controlling device complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3432622B1Secure devices and methods for LPWA communication networks
Publication Date: 2020.03.25 DEUTSCHE TELEKOM AG
  • EP3432622B1 patent drawingFigure 1
  • EP3432622B1 patent drawingFigure 2
  • EP3432622B1 patent drawingFigure 3

AI summary

The invention relates to a communication device (110a) for communicating data over a low power wide area, LPWA, communication network (100), wherein the communication device (110a) comprises: a processor configured to process data; a memory configured to store data; and a radio configured to receive data from and transmit data to neighbouring communication devices (110b-e) and/or a base station (130); wherein the processor is configured to route the data received from neighbouring communication devices (110b-e) to other neighbouring communication devices (110b-e) and/or the base station (130) of the LPWA communication network (100) on the basis of a routing scheme stored in the memory and wherein the routing scheme is based on information about a respective security credibility of the respective neighbouring communication devices (110b-e).