LPWA Device Security via Parallel Processor Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Low-Power Wide-Area (LPWA) communication devices, particularly those using Narrowband IoT technology, face challenges in implementing effective security mechanisms due to limited hardware resources, making them vulnerable to side channel attacks and unable to utilize security mechanisms from smartphones.

Innovation Solution

The implementation of a communication device with a processor configured to operate in a real-time execution environment and a security system that includes logically separated security domains, allowing parallel execution of applications to detect and respond to potential security breaches, such as terminating operations or transmitting error messages, using hardware and/or software-based security systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security mechanisms from smartphones are used in LPWA communication devices, then security protection capability is improved, but device complexity and hardware resource requirements increase beyond what LPWA devices can support

Engineering Contradiction:
Improvesecurity protection capabilityVSAvoidhardware resource requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the processor into multiple calculating units (first calculating unit, second calculating unit) that can operate independently in parallel. This segmentation allows security-critical operations to be performed in dedicated security modes while maintaining basic communication functions, providing smartphone-level security protection through architectural division rather than full hardware replication.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a temporal dimension to security processing by implementing multiple operation modes (security mode, normal mode) that switch between different processing configurations. The calculating units can selectively operate in security mode where they process data in parallel with identical instructions, adding a time-based layer of security verification without permanently increasing hardware complexity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If parallel processing of the same data by multiple calculating units is implemented, then security against side channel attacks is improved, but processing time and operational overhead increase

Engineering Contradiction:
Improvesecurity against side channel attacksVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements periodic switching between security mode and normal mode operation. The control unit selectively activates parallel security processing only when security-critical operations are detected, rather than continuously maintaining parallel processing. This periodic activation provides protection against side channel attacks during vulnerable operations while minimizing time loss during routine communication tasks.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The patent changes the operational parameters of the calculating units dynamically based on security requirements. In normal mode, units operate sequentially for efficiency; in security mode, they switch to parallel operation with identical instructions. This parameter change allows the system to adapt processing time investment to the actual security risk level of each operation.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3432625B1Secure devices and methods for LPWA communication networks
Publication Date: 2019.10.02 DEUTSCHE TELEKOM AG
  • EP3432625B1 patent drawingFigure 1
  • EP3432625B1 patent drawingFigure 2
  • EP3432625B1 patent drawingFigure 3

AI summary

The invention relates to a communication device (110) for communicating data over a low power wide area, LPWA, communication network, wherein the communication device (110) comprises: a processor (111) configured to implement a real-time execution environment (112) based on a real-time operating system, wherein the real-time execution environment (112) is configured to execute a first instance of an application; a memory (113, 115) configured to store data; a radio (117) configured to transmit and/or receive data over the LPWA communication network; and a security system configured to operate one or more logically separated sets of security domains (111 a-c, 113a-c, 115a-c), including a first set of security domains (111 a, 113a, 115a), on the processor (111) and the memory (113, 115), wherein each set of security domains comprises a processor security domain (111 a-c) and a memory security domain (113a-c, 115a-c). The security system is configured to operate the respective processor security domains (111 a-c) of the one or more sets of security domains (111a-c, 113a-c, 115a-c) in parallel to the real-time execution environment (112), wherein the processor security domain (111 a) of the first set of security domains (111 a, 113a, 115a) is configured to execute a second instance of the application in response to the execution of the first instance of the application by the real-time execution environment (112).