ZigBee Security Domain Node Compromise Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure wireless networks, such as ZigBee networks, face challenges in detecting compromised nodes, especially in large-scale telecom applications where scalability and unattended system deployment make it difficult to identify and address node compromises.

Innovation Solution

A method and system for identifying compromised nodes in a network divided into security domains, where a general trust center distributes keying material shares based on location information and node identifiers, allowing for comparison across domains to detect common compromised nodes, and incorporating a variable identifier component to reduce comparison scope and enhance security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If α-secure schemes are used in large-scale telecom networks with millions of nodes, then key agreement and information verification can be performed efficiently, but the system security is compromised when α nodes are captured and detection becomes difficult

Engineering Contradiction:
Improvekey agreement efficiencyVSAvoidsystem security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent divides the network into multiple security domains (first security domain and second security domain), each with its own set of nodes. By segmenting the large-scale network into smaller domains, the system can track and compare node distributions across domains to identify compromised nodes, thus maintaining security while supporting large-scale deployment.

Inventive Principle:
Principle #1Segmentation

2Reliability

If the network is divided into multiple security domains with location-based keying material distribution, then compromised nodes can be identified by comparing node sets across domains, but the system complexity and computational overhead increase

Engineering Contradiction:
Improvecompromised node detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a feedback mechanism where the trust center continuously monitors node locations, tracks which nodes have received keying material for each security domain, and compares these sets to identify compromised nodes. This automated feedback loop enables detection without requiring complex manual intervention.

Inventive Principle:
Principle #23Feedback

3Reliability

If location information is used to distribute keying material shares to nodes entering security domains, then security can be enhanced by controlling access based on location, but the need to track and compare node locations across domains increases processing requirements

Engineering Contradiction:
Improvesecurity domain protectionVSAvoidprocessing time for comparison
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by maintaining continuous tracking of node locations and keying material distribution before security incidents occur. The trust center proactively builds and updates sets of nodes for each security domain, so when comparison is needed to identify compromised nodes, the data is already prepared and readily available.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2438705B1Method and system for identifying compromised nodes
Publication Date: 2015.03.25 KONINKLIJKE PHILIPS NV
  • EP2438705B1 patent drawingFigure 1~2

AI summary

The invention relates to a method for identifying compromised nodes in a ZigBee network comprising a general trust center, divided in at least two security domains, each security domain corresponding to a spatial or temporal area, and being associated with a different root keying material, and each node being identified by an identifier, the method comprising: upon detection of a node (Ul) entering into a security domain (SD), the general trust center (TC) distributing to the node at least one keying material share corresponding to the entered security domain, and upon detecting corruption of at least two security domains, determining, for each security domain, based on information registered by the base station (BTS), a respective set of nodes having received keying material corresponding to said security domain, - comparing the respective sets of nodes and identifying the common nodes as being compromised.