Peer-to-Peer Group Vigilance for IoT Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security solutions rely on infrastructure elements, leading to latency, scalability issues, and single points of failure, particularly in large hierarchical networks like the Internet of Things, as they require additional devices for detection, decision-making, and security responses.
Innovation Solution
Implementing peer-to-peer group vigilance using trusted network devices with a Trusted Execution Environment (TEE) that determines trust scores based on local and remote data, allowing devices to restrict problematic activities without external infrastructure, through a peer behavior analysis engine, self-assessment logic engine, and enforcement engine.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If infrastructure elements (servers, appliances, firewalls) are used to detect and block misbehaving devices, then network security detection capability is improved, but latency increases and real-time response is lost
Solution Approach 1:
The patent divides the centralized security infrastructure into distributed security functions across multiple peer devices. Each device performs local detection and decision-making, segmenting the monolithic security system into autonomous units that operate independently, thereby eliminating latency associated with centralized processing.
Solution Approach 2:
Devices are empowered to perform self-detection and self-enforcement of security policies. The peer device under scrutiny conducts its own behavior analysis and can autonomously restrict its own activities when problematic behavior is detected, eliminating the time delay of external infrastructure intervention.
2Reliability
If centralized infrastructure is used for security detection and response, then security decision-making capability is improved, but scalability to large hierarchical networks deteriorates
Solution Approach 1:
The centralized security authority is segmented into distributed decision-making capabilities across peer devices. Each device maintains local security logic and can independently make security decisions, allowing the system to scale to large hierarchical networks without requiring centralized coordination for each decision.
Solution Approach 2:
The patent transitions from a vertical hierarchical security model (centralized infrastructure) to a horizontal peer-to-peer model. This dimensional shift allows security functions to operate at the network edge rather than requiring traversal through centralized infrastructure, enabling scalability to large distributed networks.
3Reliability
If additional network devices are deployed for security detection and response, then network security capability is improved, but device complexity and single point of failure risks increase
Solution Approach 1:
The patent makes each peer device universally capable of performing security detection, analysis, and enforcement functions. Rather than deploying specialized security infrastructure, ordinary peer devices are equipped with the capability to perform all security functions, reducing overall system complexity while maintaining security capability.
Solution Approach 2:
Devices perform their own security assessment and enforcement without requiring external security infrastructure. This self-service approach eliminates the need for additional dedicated security devices, reducing device complexity while maintaining comprehensive security coverage across the network.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Providing peer-to-peer network security includes collecting, by a local trusted network device, local trust data related to behavior of the local trusted network device, receiving, by one or more remote trusted network devices, additional trust data for the local trusted network device, calculating a combined trust score for the local trusted network device based on the local trust data and additional trust data, and modifying activity of the local trusted network device based on the combined trust score.