LPWA Security Domain Segmentation for Resource-Constrained IoT
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Low-Power Wide-Area (LPWA) wireless communication networks, particularly Narrowband IoT (NB IoT), face security challenges due to limited hardware resources, making existing security mechanisms from smartphones unsuitable for these devices.
Innovation Solution
The implementation of a communication device with multiple security domains, including processor and memory security domains, that use cryptographic authentication and virtualization techniques to secure communication, allowing for secure proxy or relay communication and extended network coverage while restricting access based on access control rules.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If smartphone security mechanisms are used for LPWA devices, then security level is improved, but device complexity and resource consumption increase beyond what LPWA devices can support
Solution Approach 1:
The patent divides the security system into separate security domains (first security domain for routing functions, second security domain for authentication) that operate independently on the same processor. This segmentation allows security functions to be isolated without requiring separate hardware processors, thus maintaining high security while reducing device complexity and resource consumption suitable for LPWA devices.
2Reliability
If multiple security domains are implemented on the same processor, then security isolation is improved, but device complexity increases
Solution Approach 1:
The patent introduces a new dimension of security domain separation through virtualization on the same processor, rather than using physical separation. By creating logically isolated security domains that can be implemented through software partitioning and access control mechanisms, the system achieves security isolation without adding physical hardware complexity, making it suitable for resource-constrained LPWA devices.
3Area of stationary object
If secure proxy communication is enabled, then network coverage is extended, but authentication overhead and processing time increase
Solution Approach 1:
The patent implements preliminary authentication where the second security domain authenticates neighboring communication devices before routing operations. By performing authentication in advance and caching authentication results within the security domains, the system enables secure proxy communication that extends network coverage while minimizing authentication overhead during actual data transmission, reducing processing time for subsequent communications.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The invention relates to a communication device (110a) for communicating data over a low power wide area, LPWA, communication network. The communication device (110a) comprises: a processor (111) configured to process data; a memory (113, 115) configured to store data; a radio (117) configured to receive data from and transmit data to neighbouring communication devices and/or a base station; and a security system configured to operate one or more sets of logically separated security domains (111a-c, 113a-c, 115a-c), including a first set of security domains (111a, 113a, 115a), on the processor (111) and the memory (113, 115), wherein each set of security domains comprises a processor security domain (111a-c) and a memory security domain (113a-c, 115a-c), which are configured to interact with each other to provide at least one respective security function, wherein the processor security domain (111a) and the memory security domain (113a, 115a) of the first set of security domains (111a, 113a, 115a) are configured to interact with each other to route the data received from neighbouring communication devices (110b-e) to other neighbouring communication devices and/or the base station of the LPWA communication network on the basis of a routing scheme stored in the memory security domain (113a, 115a) of the first set of security domains (111a, 113a, 115a).