Device Security Configuration via Unauthorized Component Detection and Encrypted Tunneling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security measures for computers and networks are inadequate in detecting and preventing unauthorized components and ensuring optimized performance, particularly in remote access scenarios, where hardware and software security can be compromised by hackers and viruses.

Innovation Solution

A method and system that perform checks for unauthorized components, establish an encrypted VPN tunnel between devices, and optimize hardware operations for specific tasks by comparing parameters and components against predetermined lists, ensuring secure and efficient operation through remote configuration and monitoring.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple security checks are performed to detect unauthorized components, then device security is improved, but device complexity and processing time increase

Engineering Contradiction:
Improvedevice securityVSAvoidsecurity check complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent performs security checks at multiple predetermined stages (before OS installation, before application deployment, and during operation) to detect unauthorized components. By conducting checks preliminarily at each stage, the system prevents security issues before they can compromise the device, resolving the contradiction between enhanced security and increased complexity through structured phased verification.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a remote second device as an intermediary that performs verification of device parameters and communicates security status. This intermediary handles complex verification tasks remotely, allowing local device security to be enhanced without proportionally increasing local device complexity, as the intermediary assumes part of the verification burden.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If an encrypted VPN tunnel is established for remote access, then security is improved, but network configuration complexity increases

Engineering Contradiction:
Improveremote access securityVSAvoidnetwork configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements automatic VPN tunnel establishment where the first device autonomously initiates encrypted tunnel connections to the second device using pre-configured parameters. The system self-manages the tunnel lifecycle including establishment, maintenance, and termination without requiring manual intervention, thereby enhancing remote access security while minimizing the operational complexity burden on users.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The VPN tunnel system is designed to handle multiple functions including secure data transmission, remote device management, and coordinated security checks. By making the tunnel infrastructure multi-functional, the patent reduces overall system complexity as a single encrypted channel serves multiple security and operational purposes rather than requiring separate mechanisms for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If hardware components are optimized for specific tasks, then performance is improved, but device adaptability decreases

Engineering Contradiction:
Improvetask performance efficiencyVSAvoidhardware configuration flexibility
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic hardware optimization where the system continuously monitors task requirements and adjusts hardware operations accordingly. The hardware components are configured to perform predefined tasks with optimized parameters, but can dynamically adapt their operation based on real-time task demands. This dynamic approach allows the system to maintain high performance for specific tasks while retaining the flexibility to handle different task types through runtime configuration adjustments.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent optimizes hardware components by adjusting operational parameters (such as CPU frequency, memory allocation, I/O configurations) based on predefined task requirements. By changing hardware operational parameters rather than physical configuration, the system achieves task-specific optimization while maintaining adaptability to switch between different parameter sets for different tasks, avoiding the need for physical hardware modifications.

Inventive Principle:
Principle #35Parameter changes

4Reliability

If device parameters are verified against predetermined lists, then security is improved, but processing time increases

Engineering Contradiction:
Improveparameter verification accuracyVSAvoidverification processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs parameter verification against predetermined authorized lists at predetermined stages before critical operations (such as before OS installation and before application deployment). By conducting verifications preliminarily, the system identifies and blocks unauthorized parameters early in the process, preventing security issues from progressing to later stages where remediation would be more time-consuming and complex.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts and verifies only critical device parameters (such as hardware identifiers, network configuration, and system architecture) against predetermined authorized lists, rather than verifying all possible parameters. This selective extraction of essential verification targets reduces processing time while maintaining security effectiveness by focusing verification efforts on the most critical security-relevant parameters.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS9473462B2Method and system for configuring and securing a device or apparatus, a device or apparatus, and a computer program product
Publication Date: 2016.10.18 QIP SOLUTIONS LTD
  • US9473462B2 patent drawing
  • US9473462B2 patent drawing
  • US9473462B2 patent drawing

AI summary

A computer-implemented method for configuring and securing a first device, the method including performing a first check of the first device to determine the presence of unauthorized components or modules in a memory of the first device, performing a second check of the device to compare hardware components of the first device against a predetermined list of authorized components, initiating an encrypted virtual private network (VPN) tunnel between the first device and a second device that is remote from the first device by transmitting a request from the first device to the second device including data representing multiple parameters associated with the first device.