Ethernet Security Unit for Bandwidth Integrity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In Ethernet networks, compromised communications nodes can spam or tamper with data, compromising bandwidth integrity, particularly in shared media environments like in-vehicle networks, where existing security measures are inadequate.

Innovation Solution

An Ethernet communications device equipped with a security unit that manipulates data streams by extracting and comparing frame information with pre-defined policies, interrupting or modifying the data stream when it violates these policies, thereby preventing misuse and ensuring bandwidth integrity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a shared media Ethernet network is used to enable multiple nodes to connect, then network connectivity and bandwidth sharing are improved, but security risks and vulnerability to compromised nodes increase

Engineering Contradiction:
Improvenetwork connectivityVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a security unit as an intermediary component between the PHY unit and MAC unit. This security unit acts as a mediator that monitors and controls data streams passing through the Ethernet communications device, preventing compromised nodes from affecting network security while maintaining connectivity. The security unit extracts frame information, compares it with pre-defined policies, and manipulates data streams accordingly without disrupting normal network operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security unit performs self-service by autonomously monitoring data streams, extracting frame information, comparing against policies, and taking corrective actions without external intervention. The system enables each Ethernet communications device to protect itself by implementing security functions locally at the device level, allowing individual nodes to independently identify and block malicious traffic while maintaining network-wide security.

Inventive Principle:
Principle #25Self-service

2Reliability

If security functions are added to prevent compromised node attacks, then network security is improved, but device complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the security unit with existing Ethernet device components (PHY unit, MAC unit, or MII) to implement security functions without adding separate standalone security hardware. By integrating security capabilities into the existing data path infrastructure, the system enhances network security while minimizing increases in overall device complexity. The security unit leverages existing frame processing mechanisms already present in Ethernet devices.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system performs preliminary action by pre-defining security policies before data streams are processed. These pre-defined policies establish security criteria in advance, allowing the security unit to quickly compare incoming frame information against established rules without requiring complex real-time analysis. This approach simplifies the security enforcement process while maintaining high reliability.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If frame information is extracted and compared with pre-defined policies in real-time, then security detection capability is improved, but processing time and operational complexity increase

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The security unit extracts only the necessary frame information (such as source address, destination address, port information, and frame priority information) from passing data streams rather than analyzing entire frames. This selective extraction approach enables precise security detection by focusing on critical identification fields while minimizing processing overhead and maintaining operational efficiency.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11671455B2Ethernet communications device and method for operating an ethernet communications device
Publication Date: 2023.06.06 NXP BV
  • US11671455B2 patent drawing
  • US11671455B2 patent drawing
  • US11671455B2 patent drawing

AI summary

Embodiments of a device and method are disclosed. In an embodiment, an Ethernet communications device includes a physical layer (PHY) unit or a media access control (MAC) unit configured to perform media access control for the Ethernet communications device. The Ethernet communications device includes a security unit configured to manipulate a data stream in a data path within the Ethernet communications device when the data stream violates or conforms to a pre-defined policy.