Distributed Network Security Engine for IoT Firewall

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing firewall technologies require significant computing power and memory resources, making them unsuitable for constrained devices like IoT clients, and are not scalable to handle large networks with millions or billions of endpoints.

Innovation Solution

A network security engine that operates on the transport and session layers of the OSI model, using keys and identifiers to monitor and protect physical ports and processor cores, allowing each device to function as a firewall with minimal resource usage, forming a distributed firewall system that scales with the size of the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional firewall methods are used to defend security attacks, then security protection is improved, but computing power and memory resources are significantly consumed

Engineering Contradiction:
Improvesecurity protectionVSAvoidcomputing power and memory resources
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The firewall functionality is segmented and distributed to individual networked devices rather than centralized. Each device independently implements firewall rules locally, eliminating the need for a single powerful firewall system and reducing resource consumption at any single point while maintaining comprehensive security coverage across the network.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Each networked device performs its own security validation and filtering operations autonomously using locally stored firewall rules. Devices self-manage their security without requiring external firewall management, reducing the computational burden on centralized systems and enabling resource-constrained devices to participate in security enforcement.

Inventive Principle:
Principle #25Self-service

2Reliability

If traditional firewalls are deployed to protect network endpoints, then security is improved, but scalability to large networks with millions or billions of endpoints deteriorates

Engineering Contradiction:
Improvesecurity protectionVSAvoidscalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The firewall system is divided into independent, identical units deployed at each networked device. This segmentation allows the system to scale linearly with network size, as each device independently enforces security rules without requiring coordination or management overhead that would limit scalability to millions or billions of endpoints.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The same firewall rule set and security logic are universally applied across all networked devices regardless of network size. This universal approach allows the system to handle everything from small networks to massive IoT deployments using identical mechanisms, achieving both consistency and scalability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If third generation firewalls with extensive databases are used to detect application layer attacks, then detection capability is improved, but device complexity and resource requirements increase

Engineering Contradiction:
Improveattack detection capabilityVSAvoiddatabase size and structure
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The firewall rules are extracted from complex, centralized databases and transformed into simplified, structured rule sets that can be stored and processed efficiently in resource-constrained environments. This extraction maintains attack detection capability while dramatically reducing the complexity and resource requirements compared to traditional extensive databases.

Inventive Principle:
Principle #2Taking out (Extraction)

4Reliability

If comprehensive firewall rules are enforced at every networked device, then security coverage is improved, but processing overhead and latency increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidpacket processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Firewall rules are pre-processed and structured into efficient formats before deployment to networked devices. This preliminary action optimizes the rule representation and organization, enabling rapid matching and decision-making during packet processing, thereby maintaining comprehensive security coverage while minimizing processing overhead and latency.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10122686B2Method of building a firewall for networked devices
Publication Date: 2018.11.06 MEDIATEK INC
  • US10122686B2 patent drawing
  • US10122686B2 patent drawing
  • US10122686B2 patent drawing

AI summary

A device is provided to perform secure operations in a network that includes multiple devices. The device comprises multiple processor cores; multiple physical ports to receive packets; a system interconnect and a network security engine. The network security engine is operative to: extract a key from a packet received from a physical port among the physical ports; in response to a first determination that the key does not match a stored key in the device, block the packet from entering the system interconnect through the physical port; and in response to the first determination that the key matches the stored key and in response to a second determination that one or more identifiers extracted from the packet do not match stored information in the device, block the packet from entering an identified processor core among the processor cores that is to be accessed by the packet.