Network Modeling for Device and Certificate Population Anomalies

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing edge computing architectures struggle to efficiently detect anomalies in device population and certificate management, particularly in large-scale IoT environments, leading to security risks and computational inefficiencies due to exponential growth and lack of reliable one-to-one correlation between devices and certificates.

Innovation Solution

A method is developed to establish a network model that analyzes the relationship between devices and certificates, using historical data to predict expected growth rates and detect anomalies through iterative evaluation and hypothesis-based insights, enabling automated detection and response actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional centralized anomaly detection methods are used in edge computing environments, then security monitoring coverage is achieved, but latency increases and computational efficiency decreases

Engineering Contradiction:
Improvesecurity monitoringVSAvoiddetection latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the centralized anomaly detection system into distributed edge-based detectors. Each edge device independently performs anomaly detection on local device population and certificate data, eliminating the need to transmit all data to a central server for analysis. This segmentation reduces detection latency while maintaining security monitoring coverage across the edge computing environment.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If comprehensive device and certificate monitoring is implemented in large-scale IoT networks, then detection accuracy improves, but computational overhead increases exponentially

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidcomputational overhead
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent applies local quality by having each edge device perform anomaly detection only on its local device population and certificate data rather than processing global network data. This localized approach maintains detection accuracy for local anomalies while dramatically reducing computational overhead by avoiding exponential scaling with network size. The system processes data at the edge where it originates rather than centralizing all processing.

Inventive Principle:
Principle #3Local quality

3Reliability

If real-time device population analysis is performed across the entire network, then anomaly detection reliability improves, but data transmission requirements and network load increase

Engineering Contradiction:
Improveanomaly detectionVSAvoiddata transmission volume
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts anomaly detection functionality from the centralized cloud environment and places it directly at the edge devices. This extraction eliminates the need to transmit large volumes of raw device population and certificate data to the cloud for analysis. Only localized anomaly results and alerts need to be communicated, dramatically reducing data transmission requirements while maintaining reliable anomaly detection through local analysis.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS20250294041A1Device population anomaly detection
Publication Date: 2025.09.18 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US20250294041A1 patent drawing
  • US20250294041A1 patent drawing
  • US20250294041A1 patent drawing

AI summary

An embodiment establishes a network model based at least in part on network data received from a network, wherein the network data comprises device data and certificate data. The embodiment samples the network to receive a network data sample. The embodiment compares the network data sample to the network model to determine whether an anomalous amount of devices is present in the network. The embodiment compares the network data sample to the network model to determine whether an anomalous amount of certificates is present in the network. The embodiment identifies a device population anomaly upon a determination that an anomalous amount of devices and/or an anomalous amount of certificates is present in the network.