Peer-to-Peer Group Vigilance for IoT Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security solutions rely on infrastructure elements, leading to latency, scalability issues, and single points of failure, particularly in large hierarchical networks like the Internet of Things, as they require additional devices for detection, decision-making, and security responses.

Innovation Solution

Implementing peer-to-peer group vigilance using trusted network devices with a Trusted Execution Environment (TEE) that determines trust scores based on local and remote data, allowing devices to restrict problematic activities without external infrastructure, through a peer behavior analysis engine, self-assessment logic engine, and enforcement engine.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If infrastructure elements (servers, appliances, firewalls) are used to detect and block misbehaving devices, then network security detection capability is improved, but latency increases and real-time response is lost

Engineering Contradiction:
Improvenetwork security detection capabilityVSAvoidlatency between problematic device and infrastructure
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent divides the centralized security infrastructure into distributed security functions across multiple peer devices. Each device performs local detection and decision-making, segmenting the monolithic security system into autonomous units that operate independently, thereby eliminating latency associated with centralized processing.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Devices are empowered to perform self-detection and self-enforcement of security policies. The peer device under scrutiny conducts its own behavior analysis and can autonomously restrict its own activities when problematic behavior is detected, eliminating the time delay of external infrastructure intervention.

Inventive Principle:
Principle #25Self-service

2Reliability

If centralized infrastructure is used for security detection and response, then security decision-making capability is improved, but scalability to large hierarchical networks deteriorates

Engineering Contradiction:
Improvesecurity decision-making capabilityVSAvoidscalability to large hierarchical networks
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The centralized security authority is segmented into distributed decision-making capabilities across peer devices. Each device maintains local security logic and can independently make security decisions, allowing the system to scale to large hierarchical networks without requiring centralized coordination for each decision.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transitions from a vertical hierarchical security model (centralized infrastructure) to a horizontal peer-to-peer model. This dimensional shift allows security functions to operate at the network edge rather than requiring traversal through centralized infrastructure, enabling scalability to large distributed networks.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If additional network devices are deployed for security detection and response, then network security capability is improved, but device complexity and single point of failure risks increase

Engineering Contradiction:
Improvenetwork security capabilityVSAvoidinfrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes each peer device universally capable of performing security detection, analysis, and enforcement functions. Rather than deploying specialized security infrastructure, ordinary peer devices are equipped with the capability to perform all security functions, reducing overall system complexity while maintaining security capability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

Devices perform their own security assessment and enforcement without requiring external security infrastructure. This self-service approach eliminates the need for additional dedicated security devices, reducing device complexity while maintaining comprehensive security coverage across the network.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3314852B1Peer-to-peer group vigilance
Publication Date: 2021.10.27 MCAFEE LLC
  • EP3314852B1 patent drawingFigure 1
  • EP3314852B1 patent drawingFigure 2
  • EP3314852B1 patent drawingFigure 3

AI summary

Providing peer-to-peer network security includes collecting, by a local trusted network device, local trust data related to behavior of the local trusted network device, receiving, by one or more remote trusted network devices, additional trust data for the local trusted network device, calculating a combined trust score for the local trusted network device based on the local trust data and additional trust data, and modifying activity of the local trusted network device based on the combined trust score.