Abstract: A context adaptive zero-trust security system for an Internet of Things (IOT) network, comprises of multiple IoT devices, a security management framework implemented at least in part on multiple IoT devices and the at least one edge gateway, the security management framework comprising, a behavior monitoring module to measure real-time operational parameters of the IoT device and generate and store a device-specific behavior fingerprint, a trust scoring module to continuously compute and update a dynamic trust score based on a comparison between observed behavior and the device-specific behavior fingerprint, a context-aware zero-trust access controller to evaluate each communication request associated with an IoT device to generate a per-request access decision, a federated learning engine to train an anomaly detection model using locally available behavior data and to transmit model updates without transmitting raw device data, an autonomous mitigation module to initiate a mitigation action.
Description:FIELD OF THE INVENTION
[0001] The present invention relates to a context adaptive zero-trust security system for an Internet of Things (IoT) network that provides continuous and real-time security protection by evaluating device behavior and contextual conditions before allowing any communication or access and ensures that no device is trusted by default and every request is verified dynamically to prevent unauthorized access and cyber threats.
BACKGROUND OF THE INVENTION
[0002] Due to increasing deployment of Internet of Things (IoT) networks across industrial, healthcare, smart infrastructure, and consumer environments, security risks associated with unauthorized access, anomalous device behavior, and dynamically evolving cyber threats have significantly increased. Context Adaptive Zero-Trust Security provides continuous evaluation of device trustworthiness and communication activities based on contextual conditions, operational behavior, identity verification, and network activity within distributed IoT environments.
[0003] US20220021665A1 discloses a networking device at an edge of a network enrolls with a controller that supervises operation of the networking device. The networking device sends a publication request to a cloud-based messaging service. The networking device provides, to the cloud-based messaging service, identification information that indicates the controller that supervises operation of the networking device. The networking device receives, from the cloud-based messaging service, authorization to publish messages to the cloud-based messaging service. The cloud-based messaging service uses the identification information to confirm an identity of the networking device with the controller that supervises operation of the networking device. The networking device sends, after receiving authorization to publish messages to the cloud-based messaging service, a message for publication to the cloud-based messaging service. The message comprises data sourced from an endpoint in the network.
[0004] US20220210173A1 discloses a systems and methods for enabling context-aware zero-trust network access (ZTNA) using security posture insights received from an endpoint agent are provided. According to an embodiment, of a Zero Trust Network Access (ZTNA) service module receives from an endpoint device an access request to a protected object. An identity of a user of the endpoint device is verified via an identity management system. When the identify verification is affirmative: (i) receiving from an endpoint agent running on the endpoint device, security posture information associated with one or more of the endpoint device, the user, and the protected object; (ii) determining based on a set of ZTNA policies and the security posture information whether to allow the access request; and (iii) when the determination is affirmative, granting access to the protected object by the user via the endpoint device.
[0005] Conventionally, many devices are disclosed in prior art but they lack in providing continuous adaptive security evaluation, real-time behavioral analysis, context-driven access regulation, privacy-preserving distributed learning, and autonomous low-latency threat response within Internet of Things (IoT) environments, thereby reducing effectiveness against dynamically evolving cyber threats and unauthorized network activities.
[0006] In order to overcome the aforementioned drawbacks, there exists a need in the art to develop a system capable of continuously evaluating device behavior, dynamically regulating communication access, detecting anomalous activities in real time, and executing low-latency security responses within Internet of Things (IoT) environments. The system should further support privacy-preserving distributed learning, adaptive trust-based decision-making, and localized security enforcement independent of continuous cloud connectivity.
OBJECTS OF THE INVENTION
[0007] The principal object of the present invention is to overcome the disadvantages of the prior art.
[0008] An object of the present invention is to develop a system that is capable to provide security and ensure continuous, adaptive evaluation of device behavior and contextual conditions to enable real-time access control and prevention of unauthorized activities in network environments.
[0009] Another object of the present invention is to develop a system that is capable of preserving data privacy by ensuring that raw operational data is not transmitted, and instead only processed updates derived from local learning are shared for collective model improvement across distributed environments.
[0010] Another object of the present invention is to develop a system that is capable to enable decentralized and adaptive security enforcement at network edge through continuous trust evaluation, context-based access control, anomaly detection, and automated mitigation for real-time threat response without centralized dependency.
[0011] The foregoing and other objects, features, and advantages of the present invention will become readily apparent upon further review of the following detailed description of the preferred embodiment as illustrated in the accompanying drawings.
SUMMARY OF THE INVENTION
[0012] The present invention relates to a context adaptive zero-trust security system for an Internet of Things (IoT) network that provides continuous and real-time security protection by analyzing device behavior and contextual conditions prior to permitting any communication or access that ensures that no device is inherently trusted and that each request is dynamically verified to prevent unauthorized access and mitigate cyber threats.
[0013] According to an aspect of the present invention, a context adaptive zero-trust security system for an Internet of Things (IoT) network, comprises a plurality of IoT (Internet of Things) devices, at least one edge gateway communicatively coupled to the plurality of IoT devices, a security management framework implemented at least in part on the plurality of IoT devices and the at least one edge gateway, the security management framework comprising where the security management framework is configured for resource-constrained IoT devices by performing lightweight feature extraction and trust score computation on the IoT devices while offloading model training and federated learning aggregation operations to the at least one edge gateway, for each IoT device, a behavior monitoring module configured to measure real-time operational parameters of the IoT device and generate and store a device-specific behavior fingerprint, for each IoT device, a trust scoring module configured to continuously compute and update a dynamic trust score based on a comparison between observed behavior and the device-specific behavior fingerprint, the trust scoring module is configured to update the dynamic trust score by increasing the score when observed behavior conforms to the device-specific behavior fingerprint within an expected range and decreasing the score when the observed behavior deviates from the device-specific behavior fingerprint beyond a threshold, for the at least one edge gateway.
[0014] According to another aspect of the present invention, a context-aware zero-trust access controller configured to evaluate each communication request associated with an IoT device using at least the dynamic trust score and one or more contextual parameters, and to generate a per-request access decision comprising allow, restrict, or deny, the context-aware zero-trust access controller is configured to enforce graduated access control by applying at least two trust thresholds that map to at least two different access decisions including restricted access and denied access, the one or more contextual parameters comprise at least one of time of operation, geographic location, network state, device role, firmware state, communication peer identity, or requested operation type, for the at least one edge gateway, a federated learning engine configured to train or update an anomaly detection model using locally available behavior data and to transmit model updates without transmitting raw device data, for the at least one edge gateway, an autonomous mitigation module configured to initiate a mitigation action in response to the dynamic trust score satisfying a mitigation criterion and/or the anomaly detection model indicating anomalous behavior.
[0015] While the invention has been described and shown with particular reference to the preferred embodiment, it will be apparent that variations might be possible that would fall within the scope of the present invention.
BRIEF DESCRIPTION OF THE DRAWINGS
[0016] These and other features, aspects, and advantages of the present invention will become better understood with regard to the following description, appended claims, and accompanying drawings where:
Figure 1 illustrates a flowchart depicting work flow of a context adaptive zero-trust security system for an Internet of Things (IoT) network.
DETAILED DESCRIPTION OF THE INVENTION
[0017] The following description includes the preferred best mode of one embodiment of the present invention. It will be clear from this description of the invention that the invention is not limited to these illustrated embodiments but that the invention also includes a variety of modifications and embodiments thereto. Therefore, the present description should be seen as illustrative and not limiting. While the invention is susceptible to various modifications and alternative constructions, it should be understood, that there is no intention to limit the invention to the specific form disclosed, but, on the contrary, the invention is to cover all modifications, alternative constructions, and equivalents falling within the spirit and scope of the invention as defined in the claims.
[0018] In any embodiment described herein, the open-ended terms "comprising," "comprises,” and the like (which are synonymous with "including," "having” and "characterized by") may be replaced by the respective partially closed phrases "consisting essentially of," consists essentially of," and the like or the respective closed phrases "consisting of," "consists of, the like.
[0019] As used herein, the singular forms “a,” “an,” and “the” designate both the singular and the plural, unless expressly stated to designate the singular only.
[0020] The present invention relates to a context adaptive zero-trust security system for an Internet of Things (IoT) network that provides continuous and real-time security protection by analyzing device behavior and contextual conditions prior to permitting any communication or access that ensures that no device is inherently trusted and that each request is dynamically verified to prevent unauthorized access and mitigate cyber threats.
[0021] Referring to Figure 1, a context adaptive zero-trust security system for an Internet of Things (IoT) network is illustrated comprising a plurality of IoT devices are operatively connected to at least one edge gateway, a behavior monitoring module is functionally coupled with the plurality of IoT devices, a trust scoring module is communicatively connected to the behavior monitoring module, a context-aware zero-trust access controller is interfaced with the trust scoring module and the communication interface of the IoT devices, a federated learning engine is deployed at the at least one edge gateway, an anomaly detection module is coupled with the federated learning engine and trust scoring module to identify deviations in behavior, an autonomous mitigation module is connected to the trust scoring module and anomaly detection module.
[0022] The device disclosed herein comprises of a plurality of Internet of Things (IoT) devices communicatively connected within a network environment, each IoT device being configured to perform at least one sensing, monitoring, control, communication, or actuation operation and to exchange operational data with at least one edge gateway through one or more wired and/or wireless communication protocols The plurality of IoT devices comprise heterogeneous endpoint devices including, but not limited to, smart cameras, environmental sensors, industrial controllers, wearable devices, smart appliances, medical monitoring systems, autonomous robotic systems, and vehicular communication modules.
[0023] At least one edge gateway is communicatively connected to the plurality of IoT devices through one or more wired and/or wireless communication networks. The edge gateway is configured to facilitate data exchange, coordinate communication between connected IoT devices and external networks, and support localized processing and operational management associated with the plurality of IoT devices within the IoT network environment.
[0024] A security management framework implemented at least in part on the plurality of IoT devices and the at least one edge gateway, the security management framework being configured to facilitate monitoring, security evaluation, communication control, and adaptive protection operations associated with the plurality of IoT devices within the IoT network environment.
[0025] A behavior monitoring module associated with each IoT device, configured to measure real-time operational parameters of the respective IoT device and generate and store a device-specific behavior fingerprint representative of normal operational behavior of the IoT device over time. The behavior fingerprint comprises a set of extracted operational features of an IoT device, including one or more of packet inter-arrival timing, network traffic periodicity, sensor sampling rate, power consumption characteristics, sequences of executed commands, API invocation patterns, and actuator usage behavior, wherein the features collectively represent the normal operating profile of the device.
[0026] The behavior monitoring module operates by continuously receiving real-time operational parameters of an IoT device and processing the data using statistical feature analysis and time-series pattern recognition principle. The module applies machine learning protocols including clustering-based anomaly detection such as K-means clustering and sequence modeling protocol such as Hidden Markov Models to identify normal operational behavior patterns of the device. Based on the learned behavioral model, the module generates a device-specific behavior fingerprint representing a baseline profile of expected device activity. The fingerprint is stored and periodically updated using incremental learning to incorporate new operational patterns, thereby enabling adaptive representation of evolving device behavior within the system environment.
[0027] A trust scoring module configured to generate and continuously update a dynamic trust score for each IoT device by evaluating real-time operational behavior of the IoT device against a device-specific behavior fingerprint, wherein the trust scoring module is further configured to increment the trust score when the observed behavior remains within an expected behavioral range defined by the behavior fingerprint, and to decrement the trust score when the observed behavior deviates beyond a predetermined threshold relative to the behavior fingerprint, thereby enabling continuous adaptive assessment of device trustworthiness.
[0028] The trust scoring module is configured to operate by receiving real-time behavioral parameters associated with an IoT device and continuously evaluating the observed behavior against a device-specific behavior fingerprint. The module applies statistical deviation analysis and time-series comparison to quantify behavioral similarity. In addition, it utilizes machine learning-based classification, including clustering protocols such as K-means for baseline behavior grouping and probabilistic models such as Hidden Markov Models for sequential behavior evaluation, to determine conformity or anomaly levels. Based on this multi-factor analysis, the module computes a dynamic trust score using a weighted scoring function that increases the score when behavioral similarity exceeds a defined threshold and decreases the score when deviations are detected beyond acceptable limits. The computed trust score is continuously updated and maintained as a real-time indicator of device trustworthiness within the network environment.
[0029] A context-aware zero-trust access controller configured to evaluate each communication request associated with an IoT device using at least a dynamic trust score of the IoT device and one or more contextual parameters associated with the communication request, and to generate a per-request access decision comprising allow, restrict, or deny. The context-aware zero-trust access controller is further configured to enforce graduated access control by applying at least two or more predefined trust thresholds, each threshold being mapped to a respective access decision including at least restricted access and denied access, and wherein the one or more contextual parameters comprise at least one of time of operation, geographic location, network state, device role, firmware state, communication peer identity, or type of requested operation, thereby enabling context-aware and adaptive access control within the IoT network environment.
[0030] The context-aware zero-trust access controller is configured to operate by receiving communication requests from IoT devices over secure application-layer protocols such as Message Queuing Telemetry Transport and Constrained Application Protocol, and evaluating each request in real time using a dynamic trust score and associated contextual parameters. The controller processes request metadata and correlates the trust score with contextual information including time of operation, network state, device role, firmware status, communication peer identity, and requested operation type. Based on this evaluation, the controller applies predefined trust thresholds to classify requests into allow, restrict, or deny categories. Upon computing the dynamic trust score, the controller is further configured to enforce graduated access control by mapping different threshold levels to corresponding access decisions, thereby enabling adaptive enforcement of zero-trust security policies. The controller is additionally configured to generate and transmit control signals corresponding to the determined access decision. The generated access decision and associated control signals are applied on a per-request basis to regulate communication flow within the IoT network environment through the underlying network stack and protocol gateways, ensuring context-aware and real-time access governance.
[0031] A federated learning engine configured at the at least one edge gateway to train or update an anomaly detection model using locally available behavior data of IoT devices, and to generate model updates based on the locally trained model without transmitting raw device data outside the edge environment, wherein the federated learning engine is further configured to transmit encrypted or privacy-protected model updates for secure aggregation while preserving data locality and preventing exposure of raw device telemetry beyond a local network segment, and to periodically synchronize model parameters with one or more additional edge gateways and/or a centralized model aggregator to improve collective anomaly detection performance across distributed IoT deployments, wherein upon detection of anomalous behavior through the updated anomaly detection model, the federated learning engine is further configured to generate and transmit control signals for initiating one or more mitigation actions including restricting device communication, isolating the IoT device from the network, or flagging the IoT device for reduced trust evaluation within the system environment.
[0032] The federated learning engine is configured to operate at the at least one edge gateway by training or updating an anomaly detection model using locally available behavior data of Internet of Things (IoT) devices, and performing local model optimization without transmitting raw device data outside the edge environment. The engine computes and exchanges model updates as encrypted or privacy-preserving parameters using secure communication protocols such as Hypertext Transfer Protocol Secure (HTTPS) and Transport Layer Security (TLS)-secured Message Queuing Telemetry Transport (MQTT) for aggregation. The engine further synchronizes model parameters with one or more additional edge gateways and/or a centralized model aggregator to improve distributed anomaly detection performance.
[0033] Upon detection of anomalous behavior by the updated anomaly detection model, the federated learning engine is configured to generate and transmit control signals to execute mitigation actions including restricting device communication, isolating the Internet of Things (IoT) device from the network, and reducing the trust level assigned to the IoT device, thereby enabling coordinated and privacy-preserving distributed intelligence across the IoT network environment.
[0034] The anomaly detection module is configured to operate by receiving behavioral data and model parameters from a federated learning engine and evaluating operational behavior of IoT devices using a trained anomaly detection model. The module performs pattern matching between observed behavior and learned normal behavior profiles to identify deviations. The module computes an anomaly score representing a degree of deviation from expected behavior and classifies device activity as normal or anomalous based on predefined thresholds. The module generates an anomaly detection output signal upon identifying anomalous behavior and communicates the output to an access control system for further decision-making and enforcement actions within the IoT network environment.
[0035] An autonomous mitigation module configured at the at least one edge gateway to initiate one or more mitigation actions upon the dynamic trust score satisfying a predefined mitigation criterion and/or the anomaly detection model indicating anomalous behavior of an IoT device, wherein the autonomous mitigation module is further configured to perform low-latency security enforcement locally at the at least one edge gateway independent of continuous cloud connectivity, and to execute the mitigation actions without requiring human intervention and without requiring any cloud-based authorization decision, wherein the mitigation actions comprise one or more of isolating the IoT device from a network, throttling communications associated with the IoT device, revoking or rotating device credentials, enforcing a reduced-permission access policy, triggering additional authentication or verification processes, or generating an alert indicative of a security event within the IoT network environment.
[0036] The autonomous mitigation module is configured to operate at the at least one edge gateway by continuously receiving and processing outputs from a trust scoring module and an anomaly detection module, and evaluating in real time whether a dynamic trust score satisfies a predefined mitigation criterion and/or whether anomalous behavior has been identified for an IoT device. The module performs decision-level processing to generate a mitigation control response based on a severity assessment of the detected condition, wherein the mitigation control response is mapped to one or more predefined security policies for the IoT network environment.
[0037] The autonomous mitigation module is further configured to execute mitigation actions locally at the edge gateway without human intervention and without requiring cloud-based authorization, thereby enabling low-latency enforcement. The mitigation actions include isolating the IoT device from network communication paths, throttling or rate-limiting device communications, revoking or rotating authentication credentials, enforcing a reduced-permission access policy, triggering secondary verification workflows, and generating security event alerts. Communication of mitigation commands and status updates is performed using secure Transport Layer Security (TLS)-enabled Hypertext Transfer Protocol Secure (HTTPS) and Message Queuing Telemetry Transport (MQTT) protocols, ensuring encrypted and real-time autonomous security enforcement within the IoT network environment.
[0038] The invention comprises a plurality of IoT devices to generate and exchange operational data within an IoT network. At least one edge gateway configured to perform local processing and security enforcement. The security management framework to provide distributed security operations across the IoT devices and the edge gateway. The behavior monitoring module to generate a device-specific behavior fingerprint by observing real-time operational parameters of IoT devices. The trust scoring module to compute and continuously update a dynamic trust score based on comparison of observed behavior with the behavior fingerprint. The context-aware zero-trust access controller is configured to evaluate communication requests using the trust score and contextual parameters to generate access decisions. The federated learning engine is configured to train and update an anomaly detection model using local data and exchange encrypted model updates. The anomaly detection module is configured to detect deviations from normal behavior and generate anomaly outputs. The autonomous mitigation module is configured to execute mitigation actions such as isolation, throttling, credential control, and access restriction. The system flow comprises monitoring, fingerprint generation, trust evaluation, access control, anomaly detection, model update, and mitigation at the edge gateway.
[0039] The invention works in the following manner where the plurality of IoT devices operate within the network and generate operational data that is continuously observed by the behavior monitoring module to form device-specific behavior profiles. The trust scoring module evaluates observed behavior against the profiles to compute dynamic trust levels. The context-aware zero-trust access controller processes each communication request using trust values and contextual conditions to determine access permissions. The federated learning engine located at an edge gateway trains and updates models using locally derived data while sharing only encrypted updates for aggregation. The anomaly detection module identifies deviations from normal behavioral patterns and generates alert signals. The autonomous mitigation module receives trust and anomaly inputs and enforces security actions such as restricting communication, isolating devices, or adjusting access privileges. The edge gateway coordinates local processing and decision enforcement, ensuring low-latency response without reliance on continuous cloud connectivity ensuring adaptive and distributed security across IoT environments.
[0040] Although the field of the invention has been described herein with limited reference to specific embodiments, this description is not meant to be construed in a limiting sense. Various modifications of the disclosed embodiments, as well as alternate embodiments of the invention, will become apparent to persons skilled in the art upon reference to the description of the invention. , Claims:1) A context adaptive zero-trust security system for an Internet of Things (IoT) network, comprising:
i) a plurality of IoT (Internet of Things) devices;
ii) at least one edge gateway communicatively coupled to the plurality of IoT devices; and
iii) a security management framework implemented at least in part on the plurality of IoT devices and the at least one edge gateway, the security management framework comprising;
a) for each IoT device, a behavior monitoring module configured to measure real-time operational parameters of the IoT device and generate and store a device-specific behavior fingerprint;
b) for each IoT device, a trust scoring module configured to continuously compute and update a dynamic trust score based on a comparison between observed behavior and the device-specific behavior fingerprint;
c) for the at least one edge gateway, a context-aware zero-trust access controller configured to evaluate each communication request associated with an IoT device using at least the dynamic trust score and one or more contextual parameters, and to generate a per-request access decision comprising allow, restrict, or deny;
d) for the at least one edge gateway, a federated learning engine configured to train or update an anomaly detection model using locally available behavior data and to transmit model updates without transmitting raw device data; and
e) for the at least one edge gateway, an autonomous mitigation module configured to initiate a mitigation action in response to the dynamic trust score satisfying a mitigation criterion and/or the anomaly detection model indicating anomalous behavior,
wherein the system is configured to perform low-latency security enforcement at the at least one edge gateway independent of continuous cloud connectivity.
2) The device as claimed in claim 1, wherein the device specific behavior fingerprint comprises features including at least one of packet inter-arrival timing, network traffic periodicity, sensor sampling frequency, power consumption patterns, command execution sequences, API call sequences, or actuator usage patterns.
3) The device as claimed in claim 1, wherein the trust scoring module is configured to update the dynamic trust score by increasing the score when observed behavior conforms to the device-specific behavior fingerprint within an expected range and decreasing the score when the observed behavior deviates from the device-specific behavior fingerprint beyond a threshold.
4) The device as claimed in claim 1, wherein the one or more contextual parameters comprise at least one of time of operation, geographic location, network state, device role, firmware state, communication peer identity, or requested operation type.
5) The device as claimed in claim 1, wherein the context-aware zero-trust access controller is configured to enforce graduated access control by applying at least two trust thresholds that map to at least two different access decisions including restricted access and denied access.
6) The device as claimed in claim 1, wherein the federated learning engine is configured to perform federated learning by generating model updates at the at least one edge gateway and transmitting encrypted or privacy-protected model updates for aggregation while preventing transmission of raw device telemetry outside a local network segment.
7) The device as claimed in claim 1, wherein the federated learning engine is configured to synchronize model parameters with one or more additional edge gateways and/or a centralized model aggregator at periodic intervals to improve collective anomaly detection across distributed IoT deployments.
8) The device as claimed in claim 1, wherein the autonomous mitigation module is configured to perform one or more mitigation actions comprising isolating a device from a network, throttling device communications, revoking or rotating a credential, enforcing a reduced-permission policy, triggering additional verification, or generating an alert.
9) The device as claimed in claim 1, wherein the autonomous mitigation module is configured to execute the mitigation action locally at the at least one edge gateway without requiring human intervention and without requiring a cloud-based authorization decision.
10) The device as claimed in claim 1, wherein the security management framework is configured for resource-constrained IoT devices by performing lightweight feature extraction and trust score computation on the IoT devices while offloading model training and federated learning aggregation operations to the at least one edge gateway.
| # | Name | Date |
|---|---|---|
| 1 | 202641062089-STATEMENT OF UNDERTAKING (FORM 3) [15-05-2026(online)].pdf | 2026-05-15 |
| 2 | 202641062089-PROOF OF RIGHT [15-05-2026(online)].pdf | 2026-05-15 |
| 3 | 202641062089-POWER OF AUTHORITY [15-05-2026(online)].pdf | 2026-05-15 |
| 4 | 202641062089-FORM-9 [15-05-2026(online)].pdf | 2026-05-15 |
| 8 | 202641062089-EVIDENCE FOR REGISTRATION UNDER SSI(FORM-28) [15-05-2026(online)].pdf | 2026-05-15 |
| 9 | 202641062089-EVIDENCE FOR REGISTRATION UNDER SSI [15-05-2026(online)].pdf | 2026-05-15 |
| 10 | 202641062089-EDUCATIONAL INSTITUTION(S) [15-05-2026(online)].pdf | 2026-05-15 |
| 11 | 202641062089-DRAWINGS [15-05-2026(online)].pdf | 2026-05-15 |
| 12 | 202641062089-DECLARATION OF INVENTORSHIP (FORM 5) [15-05-2026(online)].pdf | 2026-05-15 |
| 13 | 202641062089-COMPLETE SPECIFICATION [15-05-2026(online)].pdf | 2026-05-15 |