Security Device Message Verification for IoT Malicious Takeover

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Communicating devices, especially those using long-range networks, are vulnerable to security flaws that allow malicious takeovers, leading to data theft and denial-of-service attacks, as they lack robust security measures.

Innovation Solution

A method and security device that verify and block messages from potentially malicious communicating devices by identifying and neutralizing them, using a security device positioned in the communication network to prevent further malicious transmissions from similar devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If communicating devices are connected to wide area networks with remote access capabilities, then connectivity and usability are improved, but security vulnerability to malicious takeovers increases

Engineering Contradiction:
ImproveconnectivityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a network operator device as an intermediary between communicating devices and the network. This mediator verifies messages, detects malicious takeovers, and blocks harmful communications, thereby protecting devices without requiring complex security implementations on the devices themselves.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary verification of messages before they are processed by the network. By checking messages in advance for signs of malicious takeover (such as unusual message patterns or frequencies), the system prevents compromised devices from causing harm while maintaining normal operation for legitimate devices.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If security verification is performed on every message from communicating devices, then security is improved, but processing time and network overhead increase

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies partial verification by focusing security checks on specific message types or patterns that are more likely to indicate malicious activity. Rather than verifying every single message in detail, the system performs targeted verification on suspicious messages while allowing normal messages to pass through with minimal checking.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system replaces complex cryptographic verification mechanisms with simpler pattern recognition and behavioral analysis. By monitoring message frequency, content patterns, and transmission characteristics, the system achieves effective security verification with lower processing overhead than traditional cryptographic methods.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If a receiving device blocks messages from a compromised communicating device, then protection against that device is improved, but messages from other legitimate devices may be incorrectly blocked

Engineering Contradiction:
ImproveprotectionVSAvoidmessage blocking accuracy
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies local quality by tailoring the blocking criteria to each specific communicating device and message type. Rather than implementing a universal blocking rule, the system analyzes the specific characteristics of each device and message, applying blocking only when the specific pattern matches known malicious behavior for that device type.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system implements feedback mechanisms where the network operator device continuously monitors message patterns and adjusts blocking decisions based on observed behavior. When legitimate messages are incorrectly blocked, the system learns from this feedback and refines its verification criteria to reduce false positives while maintaining protection against malicious devices.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3718280B1Technique for processing messages sent by a communicating device
Publication Date: 2023.02.22 ORANGE SA
  • EP3718280B1 patent drawingFigure 1~3
  • EP3718280B1 patent drawingFigure 2

AI summary

The invention relates to a processing technique implemented by a security device. The security device (50) verifies that a message sent by a communicating device (11, 21, 31, 12, 22) to a receiving device (60) is a message to be sent. When the verification is positive, the message is sent to the receiving device. The security device then receives a notification emitted by the receiving device indicating that the sent message is to be blocked. Subsequent messages of the same type as the message for which the notification was received, emitted by communicating devices provided by the same manufacturer and with the same product identifier as those of the communicating device that emitted said message are thus blocked by the security device during this verification.