System and method for formal modelling of trusted edge IoT security gateways

Inventors

Vasudevan, AmitMcCORMACK, MatthewSekar, Vyas

Interested in licensing this patent?

MTEC can help explore whether this patent might be available for licensing for your application.

Assignees

Member
Carnegie Mellon University
Carnegie Mellon University

Carnegie Mellon University is a global research institution based in Pittsburgh, Pennsylvania, recognized for interdisciplinary education, research, and innovation in science, engineering, arts, technology, and social sciences. The university leads advancements in artificial intelligence, robotics, digital health, and performing arts. Located in a technology-driven and culturally rich city, CMU powers real-world impact through research centers, industry engagement, workforce training, and initiatives that shape regional and global communities.

Publication Number

US-12639420-B2

Patent

Publication Date

2026-05-26

Expiration Date


Abstract

Disclosed herein is a method for defining a model of a trusted IoT security gateway architecture based on a microhypervisor, wherein evaluation of the model provides a guarantee that the correct security protections are applied to each IoT device's network traffic at all times, including when under attack. The models defined in accordance with the method disclosed herein are used to verify security gateway architectures that provide robust trust properties to a broad range of legacy hardware platforms utilizing existing software with a reasonable performance overhead.

Core Innovation

The invention describes a method for verifying a trusted gateway for IoT devices by creating a model of the trusted gateway and evaluating security properties using a mathematical logic solver. A controller defining a control plane is defined in a modelling language, where the controller executes software that is either protected by or attested by a controller microhypervisor, and a security gateway defining a data plane is also defined in the modelling language, where the data plane is attested by a security gateway microhypervisor.

The method compiles the model into a mathematical logic problem and evaluates the model using a mathematical logic solver. The model includes a function specifying how data packets sent to and received from an IoT device are processed at the security gateway, including sending a packet to a vSwitch for routing to a specific middlebox that determines if the packet is benign or malicious.

The model further includes a predicate with constraints that must be satisfied to establish the trusted gateway, including preventing an attacker from tampering with policies of the controller, ensuring a secure control channel immune to an attacker injecting malicious messages, requiring correct software to be running on the controller, vSwitch and each middlebox, and requiring that each packet follow a path specified by the controller and enforced by the vSwitch and each middlebox. The model includes an assert interface comprising one or more statements that must evaluate as true and providing counterexamples if any statement does not evaluate as true.

Evaluating the model using the logic solver therefore verifies that the trusted gateway satisfies the asserted trust properties, and counterexamples can be produced when the overarching trust property is not satisfied under the constraints. The disclosed approach is applied to the formal modelling and verification of a controller-plus-gateway architecture for trusted edge IoT security gateways built on a microhypervisor.

Claims Coverage

Independent claim clm-00001 covers the end-to-end method with 5 inventive features: modelling a controller and a security gateway, compiling to a mathematical logic problem, evaluating with a mathematical logic solver, using an assert interface, and applying trust constraints with packet-processing and path enforcement.

Modeling a trusted controller and security gateway for an IoT trusted gateway

Defining, in a modelling language, a controller defining a control plane for the IoT device, where the controller executing software is either protected by or attested by a controller microhypervisor; and defining, in a modelling language, a security gateway defining a data plane attested by a security gateway microhypervisor.

Compiling and evaluating the model with a mathematical logic solver

Compiling the model into a mathematical logic problem; and evaluating the model using a mathematical logic solver.

Packet processing via vSwitch routing to middleboxes that determine benign or malicious

Including a function specifying how data packets sent to and received from an IoT device are processed, where a packet received by the security gateway is sent to a vSwitch for routing to a specific middlebox which determines if the packet is benign or malicious.

Trust-establishing constraints for controller policy, secure control channel, correct software, and enforced packet paths

Including a predicate comprising one or more constraints that must be satisfied to establish the trusted gateway, including at least one of preventing an attacker from tampering with policies of the controller; a constraint specifying that a control channel between the controller and the gateway must be secure such as to be immune to an attacker injecting malicious messages; a constraint specifying that correct software must be running on the controller, vSwitch and each middlebox; and a constraint specifying that each packet must follow a path specified by the controller and enforced by the vSwitch and each middlebox.

Assert interface with true evaluation requirement and counterexample reporting

Including an assert interface comprising one or more statements that must evaluate as true and providing counterexamples if any statement does not evaluate as true.

The independent claim centers on formal modelling of a controller microhypervisor-protected or attested control plane and a security gateway microhypervisor-attested data plane, compilation to a mathematical logic problem, and solver-based evaluation using an assert interface. The claim further requires controller policy protection, a secure control channel, correct software on controller, vSwitch and middleboxes, and controller-specified packet paths enforced by the vSwitch and middleboxes, with counterexamples produced when assertions fail.

Stated Advantages

Provides a method for verifying that a trusted gateway satisfies stated trust properties through model evaluation.

Provides counterexamples when one or more assert-interface statements do not evaluate as true.

Documented Applications

Verification of trusted edge IoT security gateways built on a microhypervisor using formal Alloy-based modelling and logic solver evaluation [procedural detail omitted for safety].

JOIN OUR MAILING LIST

Stay Connected with MTEC

Keep up with active and upcoming solicitations, MTEC news and other valuable information.