External Terminal Protection Device for Data Flow Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security measures are inadequate in protecting internal hosts from unauthorized access and data flow anomalies, with 70% of computer crimes originating from internal sources due to lack of security awareness, and special devices often lacking compatible network flow control and security software, leading to compatibility issues and performance impacts.

Innovation Solution

An external terminal protection device with an interface control module and system control module that monitors and controls data interfaces, performs security authentication, and filters data flows without installing security software on the protected host, using USB, serial, and network interfaces to prevent unauthorized access and ensure protocol compliance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network security software is installed on the protected host, then security protection capability is improved, but system compatibility deteriorates and performance is impacted

Engineering Contradiction:
Improvesecurity protection capabilityVSAvoidsystem compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces an external terminal protection device as an intermediary between the protected host and external devices. This device includes an interface control module that connects to multiple data interfaces of the protected host and performs security control functions externally, thereby providing security protection without installing software on the host itself. The interface control module acts as a mediator that filters and controls data flows between external devices and the protected host, resolving the contradiction between security protection and system compatibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If flow control software is installed on special devices, then data flow control capability is improved, but system compatibility deteriorates

Engineering Contradiction:
Improvedata flow control capabilityVSAvoidsystem compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The external terminal protection device serves as an intermediary that provides data flow control functionality without requiring installation on special devices. The interface control module externally monitors and controls data interfaces, enabling flow control for specialized equipment while avoiding compatibility issues that would arise from installing control software directly on the protected host.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If security software is installed on the protected host, then security protection is improved, but system performance deteriorates

Engineering Contradiction:
Improvesecurity protectionVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

By moving security protection functions to an external terminal protection device, the patent eliminates the performance overhead that would be imposed on the protected host by security software. The interface control module handles security control, authentication, and data flow monitoring externally, allowing the protected host to maintain optimal performance while still receiving comprehensive security protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If internal personnel are monitored for security compliance, then security risks from internal sources are reduced, but operational flexibility deteriorates

Engineering Contradiction:
Improvesecurity risk controlVSAvoidoperational flexibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system control module implements feedback mechanisms by monitoring data transmission states in real-time and controlling data flows based on security policies. The interface control module provides feedback on interface usage and data flow patterns, enabling the system to detect and respond to security violations while maintaining normal operational flexibility through automated control rather than restrictive manual procedures.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11170133B2External terminal protection device and protection system for data flow control
Publication Date: 2021.11.09 BEIJING BEYONDINFO TECH CO LTD
  • US11170133B2 patent drawing
  • US11170133B2 patent drawing
  • US11170133B2 patent drawing

AI summary

The present invention discloses an external terminal protection device for data flow control and a corresponding protection system. The external terminal protection device includes: an interface control module, used for providing a plurality of data interfaces respectively connected to a protected host and one or more external devices; and a system control module, used for monitoring in real time a data transmission state of each data interface in the interface control module, and controlling the data flow of each data interface. The present invention realizes the functions of performing protocol filtering and auditing on various types of data flow without installing flow monitoring and security protection software on the protected host, and achieves the effects of low-latency network auditing and high-reliability protocol filtering, thereby comprehensively eliminating potential security hazards such as Trojan Horse virus implantation and flow anomaly that may be generated by the interfaces.