LPWA Device Security via Parallel Processor Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Low-Power Wide-Area (LPWA) communication devices, particularly those using Narrowband IoT technology, face challenges in implementing effective security mechanisms due to limited hardware resources, making them vulnerable to side channel attacks and unable to utilize security mechanisms from smartphones.
Innovation Solution
The implementation of a communication device with a processor configured to operate in a real-time execution environment and a security system that includes logically separated security domains, allowing parallel execution of applications to detect and respond to potential security breaches, such as terminating operations or transmitting error messages, using hardware and/or software-based security systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security mechanisms from smartphones are used in LPWA communication devices, then security protection capability is improved, but device complexity and hardware resource requirements increase beyond what LPWA devices can support
Solution Approach 1:
The patent segments the processor into multiple calculating units (first calculating unit, second calculating unit) that can operate independently in parallel. This segmentation allows security-critical operations to be performed in dedicated security modes while maintaining basic communication functions, providing smartphone-level security protection through architectural division rather than full hardware replication.
Solution Approach 2:
The patent introduces a temporal dimension to security processing by implementing multiple operation modes (security mode, normal mode) that switch between different processing configurations. The calculating units can selectively operate in security mode where they process data in parallel with identical instructions, adding a time-based layer of security verification without permanently increasing hardware complexity.
2Reliability
If parallel processing of the same data by multiple calculating units is implemented, then security against side channel attacks is improved, but processing time and operational overhead increase
Solution Approach 1:
The patent implements periodic switching between security mode and normal mode operation. The control unit selectively activates parallel security processing only when security-critical operations are detected, rather than continuously maintaining parallel processing. This periodic activation provides protection against side channel attacks during vulnerable operations while minimizing time loss during routine communication tasks.
Solution Approach 2:
The patent changes the operational parameters of the calculating units dynamically based on security requirements. In normal mode, units operate sequentially for efficiency; in security mode, they switch to parallel operation with identical instructions. This parameter change allows the system to adapt processing time investment to the actual security risk level of each operation.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The invention relates to a communication device (110) for communicating data over a low power wide area, LPWA, communication network, wherein the communication device (110) comprises: a processor (111) configured to implement a real-time execution environment (112) based on a real-time operating system, wherein the real-time execution environment (112) is configured to execute a first instance of an application; a memory (113, 115) configured to store data; a radio (117) configured to transmit and/or receive data over the LPWA communication network; and a security system configured to operate one or more logically separated sets of security domains (111 a-c, 113a-c, 115a-c), including a first set of security domains (111 a, 113a, 115a), on the processor (111) and the memory (113, 115), wherein each set of security domains comprises a processor security domain (111 a-c) and a memory security domain (113a-c, 115a-c). The security system is configured to operate the respective processor security domains (111 a-c) of the one or more sets of security domains (111a-c, 113a-c, 115a-c) in parallel to the real-time execution environment (112), wherein the processor security domain (111 a) of the first set of security domains (111 a, 113a, 115a) is configured to execute a second instance of the application in response to the execution of the first instance of the application by the real-time execution environment (112).