Distributed Network Security Engine for IoT Firewall
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing firewall technologies require significant computing power and memory resources, making them unsuitable for constrained devices like IoT clients, and are not scalable to handle large networks with millions or billions of endpoints.
Innovation Solution
A network security engine that operates on the transport and session layers of the OSI model, using keys and identifiers to monitor and protect physical ports and processor cores, allowing each device to function as a firewall with minimal resource usage, forming a distributed firewall system that scales with the size of the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional firewall methods are used to defend security attacks, then security protection is improved, but computing power and memory resources are significantly consumed
Solution Approach 1:
The firewall functionality is segmented and distributed to individual networked devices rather than centralized. Each device independently implements firewall rules locally, eliminating the need for a single powerful firewall system and reducing resource consumption at any single point while maintaining comprehensive security coverage across the network.
Solution Approach 2:
Each networked device performs its own security validation and filtering operations autonomously using locally stored firewall rules. Devices self-manage their security without requiring external firewall management, reducing the computational burden on centralized systems and enabling resource-constrained devices to participate in security enforcement.
2Reliability
If traditional firewalls are deployed to protect network endpoints, then security is improved, but scalability to large networks with millions or billions of endpoints deteriorates
Solution Approach 1:
The firewall system is divided into independent, identical units deployed at each networked device. This segmentation allows the system to scale linearly with network size, as each device independently enforces security rules without requiring coordination or management overhead that would limit scalability to millions or billions of endpoints.
Solution Approach 2:
The same firewall rule set and security logic are universally applied across all networked devices regardless of network size. This universal approach allows the system to handle everything from small networks to massive IoT deployments using identical mechanisms, achieving both consistency and scalability.
3Measurement precision
If third generation firewalls with extensive databases are used to detect application layer attacks, then detection capability is improved, but device complexity and resource requirements increase
Solution Approach 1:
The firewall rules are extracted from complex, centralized databases and transformed into simplified, structured rule sets that can be stored and processed efficiently in resource-constrained environments. This extraction maintains attack detection capability while dramatically reducing the complexity and resource requirements compared to traditional extensive databases.
4Reliability
If comprehensive firewall rules are enforced at every networked device, then security coverage is improved, but processing overhead and latency increase
Solution Approach 1:
Firewall rules are pre-processed and structured into efficient formats before deployment to networked devices. This preliminary action optimizes the rule representation and organization, enabling rapid matching and decision-making during packet processing, thereby maintaining comprehensive security coverage while minimizing processing overhead and latency.
Data Source
AI summary
A device is provided to perform secure operations in a network that includes multiple devices. The device comprises multiple processor cores; multiple physical ports to receive packets; a system interconnect and a network security engine. The network security engine is operative to: extract a key from a packet received from a physical port among the physical ports; in response to a first determination that the key does not match a stored key in the device, block the packet from entering the system interconnect through the physical port; and in response to the first determination that the key matches the stored key and in response to a second determination that one or more identifiers extracted from the packet do not match stored information in the device, block the packet from entering an identified processor core among the processor cores that is to be accessed by the packet.


