Smart Hub Forging Traffic to Block IoT Device Fingerprinting

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cybersecurity solutions are inadequate in protecting Internet-of-Things (IoT) devices and other communication devices from privacy leakage and identification, as they are vulnerable to fingerprinting and passive analysis techniques, despite encryption being used.

Innovation Solution

A method and system that generates and transmits forged data traffic with an entropy factor, using a machine learning model to analyze and synthesize data traffic, and routing it through virtual private networks (VPNs) to obscure the identity and activities of communication devices, thereby preventing fingerprinting and privacy leakage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption is used to protect data traffic, then data security is improved, but fingerprinting and privacy leakage still occur due to metadata analysis

Engineering Contradiction:
Improvedata securityVSAvoidfingerprinting and privacy leakage
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a smart hub as an intermediary device between the communication device and the network. This hub generates forged data traffic that mimics the actual traffic patterns, creating a decoy that prevents passive analysis from identifying the real communication device. The intermediary absorbs the harmful analysis attempts while the real device maintains its normal operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates a copy of the actual data traffic in the form of forged traffic. This forged traffic replicates the operational characteristics, destination addresses, and communication patterns of the real device, making it indistinguishable from actual traffic to passive analyzers. The copy serves as a distraction that protects the original from identification.

Inventive Principle:
Principle #26Copying

2Reliability

If existing cybersecurity solutions are implemented, then basic security is provided, but protection against passive analysis and identification remains insufficient

Engineering Contradiction:
Improvebasic securityVSAvoidpassive analysis resistance
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The system dynamically generates forged data traffic based on the actual operational characteristics of the communication device. The smart hub continuously monitors real traffic patterns and adapts the forged traffic to match these patterns, making the deception effective against evolving analysis techniques. This dynamic adaptation ensures that passive analysis remains ineffective.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent modifies key parameters of data traffic including destination addresses, source addresses, and operational characteristics. By changing these parameters in the forged traffic to match the real device's behavior patterns, the system makes the device unrecognizable to passive analyzers while maintaining the appearance of normal network activity.

Inventive Principle:
Principle #35Parameter changes

3Object-affected harmful factors

If data traffic is routed through a smart hub with forged traffic generation, then identification and fingerprinting are prevented, but device complexity increases

Engineering Contradiction:
Improveidentification and fingerprinting preventionVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The smart hub performs multiple functions within a single device: it monitors actual data traffic, analyzes operational characteristics, generates forged traffic, and routes traffic through VPNs. By consolidating these functions into one universal device, the patent reduces the overall system complexity compared to having separate components for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The smart hub acts as a centralized intermediary that handles all complexity of traffic manipulation. Rather than requiring complex modifications to multiple devices, the hub absorbs the complexity in one location, simplifying the overall system architecture while maintaining effective protection against identification.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11477221B2System and method for protecting a communication device against identification outside a computer network by routing traffic through a smart hub
Publication Date: 2022.10.18 SAUDI ARABIAN OIL CO
  • US11477221B2 patent drawing
  • US11477221B2 patent drawing
  • US11477221B2 patent drawing

AI summary

A system, a method, and a computer program for protecting data traffic from a communication device against fingerprinting or privacy leakage. The method can include receiving data traffic from a communication device connected to a network, analyzing the received data traffic to determine network activity or operational characteristics of the communication device, generating forged data traffic for the network based on the determined network activity or operational characteristic of the communication device, and transmitting the forged data traffic to an external communication device that is located outside the network. The forged data traffic can add an entropy factor to the data traffic from said communication device connected to the network.