ZigBee Security Domain Node Compromise Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing secure wireless networks, such as ZigBee networks, face challenges in detecting compromised nodes, especially in large-scale telecom applications where scalability and unattended system deployment make it difficult to identify and address node compromises.
Innovation Solution
A method and system for identifying compromised nodes in a network divided into security domains, where a general trust center distributes keying material shares based on location information and node identifiers, allowing for comparison across domains to detect common compromised nodes, and incorporating a variable identifier component to reduce comparison scope and enhance security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If α-secure schemes are used in large-scale telecom networks with millions of nodes, then key agreement and information verification can be performed efficiently, but the system security is compromised when α nodes are captured and detection becomes difficult
Solution Approach 1:
The patent divides the network into multiple security domains (first security domain and second security domain), each with its own set of nodes. By segmenting the large-scale network into smaller domains, the system can track and compare node distributions across domains to identify compromised nodes, thus maintaining security while supporting large-scale deployment.
2Reliability
If the network is divided into multiple security domains with location-based keying material distribution, then compromised nodes can be identified by comparing node sets across domains, but the system complexity and computational overhead increase
Solution Approach 1:
The patent implements a feedback mechanism where the trust center continuously monitors node locations, tracks which nodes have received keying material for each security domain, and compares these sets to identify compromised nodes. This automated feedback loop enables detection without requiring complex manual intervention.
3Reliability
If location information is used to distribute keying material shares to nodes entering security domains, then security can be enhanced by controlling access based on location, but the need to track and compare node locations across domains increases processing requirements
Solution Approach 1:
The patent performs preliminary actions by maintaining continuous tracking of node locations and keying material distribution before security incidents occur. The trust center proactively builds and updates sets of nodes for each security domain, so when comparison is needed to identify compromised nodes, the data is already prepared and readily available.
Data Source
Figure 1~2
AI summary
The invention relates to a method for identifying compromised nodes in a ZigBee network comprising a general trust center, divided in at least two security domains, each security domain corresponding to a spatial or temporal area, and being associated with a different root keying material, and each node being identified by an identifier, the method comprising: upon detection of a node (Ul) entering into a security domain (SD), the general trust center (TC) distributing to the node at least one keying material share corresponding to the entered security domain, and upon detecting corruption of at least two security domains, determining, for each security domain, based on information registered by the base station (BTS), a respective set of nodes having received keying material corresponding to said security domain, - comparing the respective sets of nodes and identifying the common nodes as being compromised.