On-Chip Security Routing for Trusted Mobile Network Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile devices lack the robust network security provided by enterprise networks when operating outside the trusted environment, increasing vulnerability to malicious code and potential contamination of the enterprise network upon reconnection.

Innovation Solution

A mobile security system that connects to mobile devices, acting as a gateway and implementing security policies and engines to filter out malicious content, including antivirus, antispyware, and firewall capabilities, with remote management and update capabilities to maintain enterprise-level security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If mobile devices connect to the internet outside the enterprise network, then mobility and access to information are improved, but vulnerability to malicious code and security attacks increases

Engineering Contradiction:
ImprovemobilityVSAvoidvulnerability to malicious code
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a mobile security system that acts as an intermediary between the mobile device and the internet. This security system includes security engines, policy enforcement mechanisms, and filtering capabilities that intercept and analyze network traffic before it reaches the mobile device, thereby protecting the device while maintaining internet access mobility.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The mobile security system is designed to be integrated within or coupled to the mobile device, creating a nested security architecture. The security system includes multiple layers of protection (firewall, antivirus, content filtering) that are embedded within the overall system, providing comprehensive security without adding significant external complexity.

Inventive Principle:
Principle #7Nested doll (Nesting)

2Reliability

If network security systems are implemented on individual mobile devices, then security protection is improved, but device complexity and resource consumption increase

Engineering Contradiction:
Improvesecurity protectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the security system into separate functional modules including security engines, policy enforcement components, and traffic filtering mechanisms. These segmented components can be independently managed, updated, and configured, reducing the complexity burden on the mobile device while maintaining comprehensive security protection.

Inventive Principle:
Principle #1Segmentation

3Object-affected harmful factors

If comprehensive security filtering and content analysis are performed, then protection against malicious code is improved, but processing time and energy consumption increase

Engineering Contradiction:
Improveprotection against malicious codeVSAvoidenergy consumption
Core Design Contradiction:
Object-affected harmful factorsVSUse of energy by moving object

Solution Approach 1:

The security system implements selective filtering and analysis based on security policies and threat levels. Not all traffic undergoes the same level of inspection - the system performs partial analysis on low-risk traffic and more comprehensive analysis on suspicious traffic, thereby reducing overall energy consumption while maintaining effective protection.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20250392567A1System and method for implementing content and network security inside a chip
Publication Date: 2025.12.25 CUPP COMPUTING
  • US20250392567A1 patent drawing
  • US20250392567A1 patent drawing
  • US20250392567A1 patent drawing

AI summary

Systems and methods for implementing content, streaming, and network security inside a chip or inside a computing device are disclosed. In exemplary embodiments, a system comprises a communication chip and a second processor. The communication chip comprises a router and security instructions. The router is configured to intercept untrusted data between a network, and a first router. The second processor is configured to receive the untrusted data from the router, process the untrusted data with the security instructions to produce trusted data, and provide the trusted data to the router.