Asymmetric Network Architecture for IoT Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current IT communication networks based on TCP/IP standards exhibit functional symmetry, leading to high complexity and security weaknesses, especially for end users, making them vulnerable to cyber threats and costly incidents, particularly in environments like Industry 4.0 and IoT where devices have limited processing capabilities and lack human control.

Innovation Solution

An asymmetric system and network architecture that relocates functions from end user devices to protected central nodes, limiting endpoint functionality and hardcoding secure applications, using read-only memories to prevent remote alterations, and employing redundant communication paths and encryption for enhanced security and reliability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If symmetric protocol stacks are used between participating systems, then communication compatibility is achieved, but system complexity and security vulnerabilities increase

Engineering Contradiction:
Improvecommunication compatibilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements functional asymmetry by designating specific systems as security hosts with enhanced security functions while other systems operate as clients with basic functionality. This asymmetric architecture resolves the contradiction by concentrating complexity in controlled host systems while keeping client systems simple, thereby maintaining communication compatibility through standardized interfaces while reducing overall system vulnerability and complexity distribution.

Inventive Principle:
Principle #4Asymmetry

2Reliability

If security functions are distributed across all end user devices, then security coverage is improved, but device complexity and vulnerability increase

Engineering Contradiction:
Improvesecurity coverageVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments security functions by distinguishing between security hosts that implement comprehensive security measures and client systems that perform basic operations. This segmentation allows security coverage to be concentrated in host systems where it is most needed, while client systems remain simple and less vulnerable. The segmented architecture maintains broad security coverage through coordinated host-client interactions without distributing complex security functions across all devices.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If software-based security measures are implemented, then adaptability is improved, but vulnerability to malware and manipulation increases

Engineering Contradiction:
Improvesecurity adaptabilityVSAvoidmalware vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent replaces software-based security mechanisms with hardware-based security functions embedded in security hosts. By implementing security-critical operations in hardware rather than software, the system achieves inherent resistance to malware and manipulation while maintaining adaptability through configurable hardware security features. This substitution eliminates the vulnerability of software to malicious code while preserving the ability to adapt security parameters through controlled hardware interfaces.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Ease of operation

If end user devices have full functionality, then operational flexibility is improved, but security risks and attack surface increase

Engineering Contradiction:
Improveoperational flexibilityVSAvoidattack surface
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces security hosts as intermediary systems that handle security-critical functions between client devices and external threats. Clients maintain operational flexibility for user-facing tasks while delegating security-sensitive operations to host intermediaries. This intermediary architecture allows end user devices to retain full operational flexibility for legitimate tasks while significantly reducing their attack surface by removing or minimizing security-critical software components.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11373010B2Asymmetrical system and network architecture
Publication Date: 2022.06.28 SCHWARTZ GERHARD
  • US11373010B2 patent drawing
  • US11373010B2 patent drawing
  • US11373010B2 patent drawing

AI summary

A novel system and network architecture unburdens the end users as a result of reduced complexity of the infrastructure used by said users. As a result of the omission of processors, operating systems and conventional software on the user side, the use of the IT is simplified and the infiltration of malware into the devices belonging to the end users is prevented. In addition, the new architecture makes it possible to set up secure and more efficient networks even with respect to IoT and Industry 4.0 as well as new business models and supports both the coexistence and the migration of the conventional technology to the new architecture.