LPWA Security Domain Segmentation for Resource-Constrained IoT
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Narrowband IoT (NB IoT) communication devices face security challenges due to limited hardware resources, making existing security mechanisms from smartphones infeasible, and there is a need for improved security systems and methods within wireless communication networks based on Low-Power Wide-Area (LPWA) technology.
Innovation Solution
The implementation of a communication device with a processor and radio modules configured to operate within multiple security domains, utilizing virtualization techniques and a system-on-a-chip architecture, which includes a security system capable of monitoring and controlling operations, adjusting parameters based on power status, and verifying digital signatures to ensure secure data transmission and anomaly detection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If smartphone security mechanisms are used in NB IoT devices, then security protection is improved, but device complexity and power consumption increase beyond what limited hardware resources can support
Solution Approach 1:
The patent segments the device into multiple security domains (first security domain for critical functions, second security domain for less critical functions) with different protection levels. This allows smartphone-level security mechanisms to be applied selectively to critical components without requiring full smartphone-level security across the entire device, thus reducing overall hardware resource requirements while maintaining essential security protection.
Solution Approach 2:
The patent implements local quality by providing different security protection levels to different parts of the device. The first security domain receives enhanced security mechanisms (similar to smartphone level) while the second security domain uses standard protection. This localized approach ensures critical security functions get adequate protection without requiring all device components to have high resource requirements.
2Reliability
If multiple security domains are implemented with virtualization techniques, then security isolation and control are improved, but device complexity increases
Solution Approach 1:
The patent introduces a security domain controller as an intermediary component that manages the multiple security domains. This controller handles the complex tasks of domain isolation, access control, and security policy enforcement, thereby achieving strong security isolation without requiring the application layer to directly manage complex security mechanisms. The intermediary absorbs the complexity while providing simplified interfaces to other components.
3Reliability
If security mechanisms are enhanced for LPWA devices, then security reliability is improved, but power consumption increases reducing battery life
Solution Approach 1:
The patent segments security functions into different domains with different power consumption characteristics. Critical security functions in the first domain use enhanced protection mechanisms only when needed, while less critical functions in the second domain use standard, lower-power mechanisms. This segmentation allows the device to maintain high security reliability for critical operations while keeping overall power consumption within battery constraints.
Solution Approach 2:
The patent dynamically adjusts security parameters (such as encryption strength, verification frequency, and domain access policies) based on operational context and power availability. This allows the system to enhance security reliability when power is充足 and reduce power consumption when battery levels are low, achieving a dynamic balance between security and power usage.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The invention relates to a communication device (110) for communicating data over a low power wide area, LPWA, communication network, wherein the communication device (110) comprises: a processor (111) configured to process data; a memory (113, 115) configured to store data; a radio (117) configured to transmit and/or receive data over the LPWA communication network (100); and a security system. The security system is configured to operate one or more logically separated sets of security domains (111a-c, 113a-c, 115a-c), including a first set of security domains (111 a, 113a, 115a), on the processor (111) and the memory (113, 115), wherein each set of security domains comprises a processor security domain (111a-c) and a memory security domain (113a-c, 115a-c), wherein the processor security domain (111 a) of the first set of security domains (111 a, 113a, 115a) is configured to implement a monitoring and/or control function and wherein the processor security domain (111 a) of the first set of security domains (111 a, 113a, 115a) is configured to monitor and/or control the operation of the communication device (110) on the basis of the monitoring and/or control function.