LPWA Security Domain Segmentation for Resource-Constrained IoT

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Low-Power Wide-Area (LPWA) wireless communication networks, particularly Narrowband IoT (NB IoT), face security challenges due to limited hardware resources, making existing security mechanisms from smartphones unsuitable for these devices.

Innovation Solution

The implementation of a communication device with multiple security domains, including processor and memory security domains, that use cryptographic authentication and virtualization techniques to secure communication, allowing for secure proxy or relay communication and extended network coverage while restricting access based on access control rules.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If smartphone security mechanisms are used for LPWA devices, then security level is improved, but device complexity and resource consumption increase beyond what LPWA devices can support

Engineering Contradiction:
Improvesecurity levelVSAvoidhardware resource requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the security system into separate security domains (first security domain for routing functions, second security domain for authentication) that operate independently on the same processor. This segmentation allows security functions to be isolated without requiring separate hardware processors, thus maintaining high security while reducing device complexity and resource consumption suitable for LPWA devices.

Inventive Principle:
Principle #1Segmentation

2Reliability

If multiple security domains are implemented on the same processor, then security isolation is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity isolationVSAvoidsoftware architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a new dimension of security domain separation through virtualization on the same processor, rather than using physical separation. By creating logically isolated security domains that can be implemented through software partitioning and access control mechanisms, the system achieves security isolation without adding physical hardware complexity, making it suitable for resource-constrained LPWA devices.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Area of stationary object

If secure proxy communication is enabled, then network coverage is extended, but authentication overhead and processing time increase

Engineering Contradiction:
Improvenetwork coverageVSAvoidauthentication processing time
Core Design Contradiction:
Area of stationary objectVSLoss of time

Solution Approach 1:

The patent implements preliminary authentication where the second security domain authenticates neighboring communication devices before routing operations. By performing authentication in advance and caching authentication results within the security domains, the system enables secure proxy communication that extends network coverage while minimizing authentication overhead during actual data transmission, reducing processing time for subsequent communications.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3432623B1Secure devices and methods for LPWA communication networks
Publication Date: 2020.03.25 DEUTSCHE TELEKOM AG
  • EP3432623B1 patent drawingFigure 1
  • EP3432623B1 patent drawingFigure 2
  • EP3432623B1 patent drawingFigure 3

AI summary

The invention relates to a communication device (110a) for communicating data over a low power wide area, LPWA, communication network. The communication device (110a) comprises: a processor (111) configured to process data; a memory (113, 115) configured to store data; a radio (117) configured to receive data from and transmit data to neighbouring communication devices and/or a base station; and a security system configured to operate one or more sets of logically separated security domains (111a-c, 113a-c, 115a-c), including a first set of security domains (111a, 113a, 115a), on the processor (111) and the memory (113, 115), wherein each set of security domains comprises a processor security domain (111a-c) and a memory security domain (113a-c, 115a-c), which are configured to interact with each other to provide at least one respective security function, wherein the processor security domain (111a) and the memory security domain (113a, 115a) of the first set of security domains (111a, 113a, 115a) are configured to interact with each other to route the data received from neighbouring communication devices (110b-e) to other neighbouring communication devices and/or the base station of the LPWA communication network on the basis of a routing scheme stored in the memory security domain (113a, 115a) of the first set of security domains (111a, 113a, 115a).