Bus Security Intermediary for Data Risk Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Prior bus network topologies are vulnerable to security breaches as rogue devices can intercept and store sensitive data intended for other clients, posing a risk of unauthorized access and data theft.

Innovation Solution

A method and apparatus for enhancing security by transparently receiving data, storing it, and analyzing it for security risks, with the option to perform a security process if a risk is identified, including encryption, data modification, or communication termination, to prevent unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If data is transmitted transparently over a bus network, then communication efficiency is improved, but security is worsened as rogue devices can intercept and store sensitive data

Engineering Contradiction:
Improvecommunication efficiencyVSAvoiddata interception risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary security device that connects between the host computing device and peripheral devices on the bus network. This intermediary monitors and controls data flow, preventing rogue devices from intercepting sensitive information while maintaining transparent communication for authorized devices. The intermediary acts as a gatekeeper that selectively allows or blocks data transmission based on security policies.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary security analysis on data before it is transmitted across the bus network. By analyzing data packets in advance and identifying potential security risks, the system can prevent unauthorized interception before it occurs. This proactive approach allows the system to block suspicious data flows while allowing legitimate communication to proceed uninterrupted.

Inventive Principle:
Principle #9Preliminary anti-action

2Reliability

If security analysis is performed on transmitted data, then security is improved, but communication speed is worsened due to additional processing time

Engineering Contradiction:
ImprovesecurityVSAvoidcommunication speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The security analysis is performed in advance on data packets before they are transmitted across the bus network. By pre-analyzing data for security risks and categorizing them accordingly, the system establishes security policies that can be automatically applied during transmission. This eliminates the need for real-time analysis during data flow, maintaining communication speed while ensuring security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system applies security analysis selectively rather than to all data uniformly. It identifies and analyzes only the portions of data that pose security risks, while allowing routine or low-risk communications to pass through with minimal or no analysis. This partial action approach maintains security for critical data while preserving communication speed for non-critical data.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If security processes are implemented to prevent data theft, then security is improved, but device complexity is worsened

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security system operates autonomously without requiring constant user intervention or complex manual configuration. It automatically monitors data flows, identifies security risks, applies predefined security policies, and adjusts to new threats using machine learning algorithms. This self-service capability simplifies the user interface and reduces the operational complexity of managing security processes.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system dynamically adjusts security parameters and policies based on the specific data being transmitted and the identified risk level. Rather than using a fixed complex security framework for all data, it modifies security measures in real-time according to the characteristics of each data packet and the trustworthiness of communicating devices, thereby reducing overall system complexity.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10678913B2Apparatus and method for enhancing security of data on a host computing device and a peripheral device
Publication Date: 2020.06.09 NETSCOUT SYSTEMS INC
  • US10678913B2 patent drawing
  • US10678913B2 patent drawing
  • US10678913B2 patent drawing

AI summary

A method of enhancing security of at least one of a host computing device and a peripheral device coupled to the host computing device through a communication interface. Data is transparently received from the peripheral device or the host computing device, and the received data is stored. The stored data is analyzed to detect a circumstance associated with a security risk. If such a circumstance is not detected, then the data is transparently forwarded to the other of the peripheral device or the host. However, if a circumstance associated with a security risk is detected, then a security process, defined by a rule, is performed. Related apparatus are provided, as well as other methods and apparatus.