IP Library › Granted Patent US 11,822,648
Granted Patent B2
US 11,822,648 · App. 17/238,478 · Granted Nov 21, 2023

Systems and methods for remote anomaly data scanner for cyber-physical systems

Inventors: Ly Vessels (Chandler, AZ); Asongu Tambo (Easgan, NM)
Assignee: HONEYWELL INTERNATIONAL INC.
G06F21/552H04L9/0825H04L9/0897H04L63/0428G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,822,648
App. No.
17/238,478
Granted
Nov 21, 2023
Kind
B2
Abstract

Disclosed are methods, systems, and non-transitory computer-readable medium for detecting data anomalies on a device. For instance, the method may include: receiving an initial data measurement transmitted by the device, wherein the initial data measurement includes a measurement of data stored in the device using a unique key associated with the device; transmitting a request for a subsequent data measurement of data stored in the device; receiving the subsequent data measurement transmitted by the device; comparing the subsequent data measurement to the initial data measurement; and determining whether an anomaly exists in the data stored in the device based on the comparison.

Claims (51)

1. A computer-implemented method for detecting data anomalies on a device, comprising:

receiving, by one or more processors, an initial data measurement transmitted by the device, wherein the initial data measurement includes a measurement of data stored in the device using a unique key associated with the device;

transmitting, by the one or more processors, a request for a subsequent data measurement of data stored in the device based on a schedule, wherein the schedule identifies a plurality of devices to transmit the request and a frequency at which to transmit the request;

receiving, by the one or more processors, the subsequent data measurement transmitted by the device;

comparing, by the one or more processors, the subsequent data measurement to the initial data measurement; and

determining, by the one or more processors, whether an anomaly exists in the data stored in the device based on the comparison.

2. The computer-implemented method of claim 1 , further comprising:

storing the received initial data measurement in a trusted platform module.

3. The computer-implemented method of claim 1 , wherein determining whether an anomaly exists in the data stored in the device based on the comparison further comprises:

determining a deviation in the subsequent data measurement compared to the initial data measurement; and

determining the anomaly in the data stored in the device based on determined deviation.

4. The computer-implemented method of claim 1 , wherein determining whether an anomaly exists in the data stored in the device based on the comparison further comprises:

determining that the subsequent data measurement matches the initial data measurement; and

determining that the anomaly does not exist in the data stored in the device as a result of determining that the subsequent data measurement matches the initial data measurement.

5. The computer-implemented method of claim 1 , wherein the device is a remote cyber-physical system (CPS) device.

6. The computer-implemented method of claim 1 , further comprising:

establishing secure communication with the device prior to receiving the initial data measurement.

7. The computer-implemented method of claim 6 , further comprising:

establishing secure communication with the device by exchanging a public key with the device, and obtaining one or more public key and private key pairs from a certificate authority.

8. A computer-implemented method for detecting data anomalies on a device, comprising:

determining, by one or more processors, a unique key associated with the device;

determining, by the one or more processors, an initial measurement of data stored in the device using the unique key;

transmitting, by the one or more processors, the initial measurement of data stored in the device;

receiving, by the one or more processors, a request for a subsequent data measurement of data stored in the device based on a schedule, wherein the schedule identifies a plurality of devices to transmit the request and a frequency at which to transmit the request;

determining, by the one or more processors, a subsequent measurement of data stored in the device using the unique key; and

transmitting, by the one or more processor, the subsequent measurement of data stored in the device.

9. The computer-implemented method of claim 8 , further comprising:

storing the determined unique key in a trusted platform module of the device.

10. The computer-implemented method of claim 8 , wherein the device is a remote cyber-physical system (CPS) device.

11. The computer-implemented method of claim 8 , further comprising:

transmitting, by the one or more processors, the initial measurement of data stored in the device to a server; and

establishing secure communication with the server prior to transmitting the initial data measurement.

12. A non-transitory computer-readable medium storing instructions that, when executed by a processor, cause the processor to perform a method for detecting data anomalies on a device, the method comprising:

receiving an initial data measurement transmitted by the device, wherein the initial data measurement includes a measurement of data stored in the device using a unique key associated with the device;

transmitting a request for a subsequent data measurement of data stored in the device based on a schedule, wherein the schedule identifies a plurality of devices to transmit the request and a frequency at which to transmit the request;

receiving the subsequent data measurement transmitted by the device;

comparing the subsequent data measurement to the initial data measurement; and

determining whether an anomaly exists in the data stored in the device based on the comparison.

13. The non-transitory computer-readable medium of claim 12 , the method further comprising:

storing the received initial data measurement in a trusted platform module.

14. The non-transitory computer-readable medium of claim 12 , wherein determining whether an anomaly exists in the data stored in the device based on the comparison further comprises:

determining a deviation in the subsequent data measurement compared to the initial data measurement; and

determining the anomaly in the data stored in the device based on determined deviation.

15. The non-transitory computer-readable medium of claim 12 , wherein determining whether an anomaly exists in the data stored in the device based on the comparison further comprises:

determining that the subsequent data measurement matches the initial data measurement; and

determining that the anomaly does not exist in the data stored in the device as a result of determining that the subsequent data measurement matches the initial data measurement.

16. The non-transitory computer-readable medium of claim 12 , wherein the device is a remote cyber-physical system (CPS) device.

17. The non-transitory computer-readable medium of claim 12 , the method further comprising:

establishing secure communication with the device prior to receiving the initial data measurement.

18. The non-transitory computer-readable medium of claim 17 , the method further comprising:

establishing secure communication with the device by exchanging a public key with the device, and obtaining one or more public key and private key pairs from a certificate authority.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 8, 2021
From: VESSELS, LY; TAMBO, ASONGU
To: HONEYWELL INTERNATIONAL INC.
Reel/Frame 056789/0531 →
Continuity (2)
Provisional Application 63014791 · Apr 24, 2020
Related Publication 20210334365A1 · Oct 28, 2021