Autonomous Non-Secure Port Closure for Secure Communications

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Communication devices, such as smart meters, remain vulnerable to hacking during the initial configuration and setup phase due to non-secure ports, which can be exploited to send rogue commands or modify data, even after they are capable of secure communications, as existing solutions require manual intervention to close these ports, leaving them open for extended periods.

Innovation Solution

The device autonomously closes its non-secure port once it has established secure communications, using a microprocessor to monitor messages and verify credentials, ensuring all further communications are secure, thereby reducing the vulnerability window.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the non-secure port remains open to enable initial configuration and setup, then the device can receive necessary configuration information, but the device remains vulnerable to hacking and unauthorized access

Engineering Contradiction:
Improveconfiguration capabilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The device performs preliminary actions by detecting successful secure communication establishment before automatically closing the non-secure port. This ensures configuration is completed while the port is open, then secures the device by closing the port immediately after secure communication is confirmed

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The device autonomously monitors for secure communication establishment and automatically closes its own non-secure port without requiring manual intervention. The system self-manages the security transition from open to closed state based on detected communication conditions

Inventive Principle:
Principle #25Self-service

2Object-affected harmful factors

If manual intervention is required to close the non-secure port, then security can be enhanced, but the vulnerability window is extended due to delayed port closure

Engineering Contradiction:
ImprovesecurityVSAvoidvulnerability window
Core Design Contradiction:
Object-affected harmful factorsVSLoss of time

Solution Approach 1:

The device continuously monitors for feedback signals indicating successful secure communication establishment. Upon detecting this feedback, it immediately triggers the port closure action, creating a responsive system that reduces vulnerability window by acting on real-time communication status

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The device autonomously manages the port closure process by detecting secure communication establishment and automatically closing the non-secure port without waiting for manual intervention, thereby minimizing the vulnerability window through immediate autonomous action

Inventive Principle:
Principle #25Self-service

3Object-affected harmful factors

If the non-secure port is closed immediately, then security is improved, but the device cannot receive configuration information needed for initial setup

Engineering Contradiction:
ImprovesecurityVSAvoidconfiguration capability
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The device maintains the non-secure port in an open state during the preliminary configuration phase, then performs the security-enhancing action of closing the port only after successful secure communication is established, ensuring both configuration capability and security are satisfied at appropriate stages

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The device dynamically adjusts the state of the non-secure port based on communication conditions - keeping it open during configuration and closing it after secure communication is established. This dynamic state transition allows the system to adapt between configuration mode and secure operation mode

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10853522B2Automatic closing of non-secure ports in a remote network communications device
Publication Date: 2020.12.01 ITRON NETWORKED SOLUTIONS INC
  • US10853522B2 patent drawing
  • US10853522B2 patent drawing

AI summary

A communications device has a first communications port via which secure messages are received, and a second communications port via which non-secure messages are received. In response to detecting that a secure message has been received, the device determines whether the second communications port is in a state that enables non-secure messages to be received. If the second communications port is in the enabled state, the device autonomously disables the second communications port to preclude non-secure messages received at that port from being processed.