LPWA Security Domain Segmentation for Resource-Constrained IoT

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Narrowband IoT communication devices face security challenges due to limited hardware resources, making existing security mechanisms from smartphones unsuitable, and there is a need for improved security systems in wireless communication networks based on Low-Power Wide-Area technology.

Innovation Solution

The implementation of communication devices with a processor, memory, and radio modules configured to operate multiple logically separated security domains, using filter rules to monitor and control data transmission and reception, and incorporating a security system that can prohibit unauthorized data transmission or processing based on blacklists or whitelists, with the ability to adjust filter rules and verify digital signatures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security mechanisms from smartphones are used in LPWA communication devices, then security level is improved, but device complexity increases due to insufficient hardware resources

Engineering Contradiction:
Improvesecurity levelVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security system into multiple logically separated security domains (first security domain, second security domain, etc.), each with its own filter rules and processing functions. This segmentation allows the security system to operate with limited hardware resources by dividing complex security tasks into manageable, isolated domains that can be processed sequentially or in parallel without requiring full smartphone-level security infrastructure.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If multiple security domains are implemented to enhance security control, then security functionality is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity control capabilityVSAvoiddevice complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal security domain framework where each security domain can perform multiple functions including filtering, monitoring, controlling, and prohibiting data transmission based on filter rules. This multi-functional design allows the security system to provide comprehensive security control without requiring separate dedicated components for each security function, thereby managing complexity while enhancing adaptability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If filter rules are applied to monitor and control data transmission, then data security is improved, but processing time increases

Engineering Contradiction:
Improvedata securityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies filter rules in advance before data transmission occurs, allowing the security system to pre-establish criteria for acceptable data communication. By performing security checks beforehand rather than in real-time during transmission, the system reduces processing delays while maintaining comprehensive data security monitoring and control capabilities.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3432535B1Applying filter rules in LPWA communication networks
Publication Date: 2021.09.01 DEUTSCHE TELEKOM AG
  • EP3432535B1 patent drawingFigure 1
  • EP3432535B1 patent drawingFigure 2
  • EP3432535B1 patent drawingFigure 3

AI summary

The invention relates to a communication device (110) for communicating data over a low power wide area, LPWA, communication network, wherein the communication device (110) comprises: a processor (111) configured to process data; a memory (113, 115) configured to store data; a radio (117) configured to transmit and/or receive data over the LPWA communication network (100); and a security system. The security system is configured to operate one or more logically separated sets of security domains (111a-c, 113a-c, 115a-c), including a first set of security domains (111a, 113a, 115a), on the processor (111) and the memory (113, 115), wherein each set of security domains comprises a processor security domain (111a-c) and a memory security domain (113a-c, 115a-c), wherein the processor security domain (111a) of the first set of security domains (111a, 113a, 115a) is configured to monitor and/or control data to be transmitted by the radio (117) and/or data received by the radio (117) on the basis of a set of filter rules.