Gateway Packet Validation for Securing Legacy Ethernet Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing legacy computing infrastructure is largely unsecured, making it difficult to retrofit protected, trusted Ethernet-based communications networks, necessitating a solution to secure communications between secured and unsecured networks.
Innovation Solution
Implementing methods and systems that validate and manage network packets between secured and unsecured networks using data models, identification codes, and secure communication pathways, including encryption and authentication, to ensure only authorized communications occur.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If protected, trusted Ethernet-based communications are implemented, then network security is improved, but capital expenditure and reengineering requirements increase
Solution Approach 1:
The patent introduces a gateway device as an intermediary between unsecured legacy networks and secured Ethernet-based networks. This gateway performs protocol translation, packet validation, and security policy enforcement, allowing legacy devices to communicate securely without requiring full reengineering of the existing infrastructure. The gateway acts as a mediator that bridges the security domain gap.
Solution Approach 2:
The network is segmented into unsecured and secured zones, with the gateway device creating a boundary between them. This segmentation allows the legacy unsecured network to continue operating as-is while the secured network implements protected communications. The gateway enforces security policies at the boundary, validating packets and controlling data flow between zones without requiring changes to devices within each zone.
2Reliability
If all legacy devices are converted to protected communications, then network security is improved, but cost increases significantly
Solution Approach 1:
The gateway serves as a cost-effective intermediary that provides security services to legacy devices without requiring device replacement. Instead of converting each legacy device individually (which would be expensive), the gateway centralizes security functions such as authentication, encryption, and packet validation, making security affordable for the entire network.
Solution Approach 2:
The gateway device performs multiple functions including protocol translation, security policy enforcement, packet validation, and authentication. This multi-functionality consolidates what would otherwise require multiple separate systems, reducing overall cost. The gateway can serve multiple legacy devices simultaneously, providing economy of scale.
3Reliability
If data validation against pre-established data models is performed, then network security is improved, but processing time increases
Solution Approach 1:
Data models and validation rules are pre-established and configured in advance before runtime packet validation. This preliminary action allows the gateway to perform rapid validation by comparing packets against pre-compiled schemas rather than creating validation logic dynamically. Security policies, authentication credentials, and data models are loaded during system initialization, reducing runtime overhead.
Data Source
AI summary
The present disclosure relates to network security software cooperatively configured on plural nodes to authenticate and authorize devices, applications, users, and data protocol in network communications by exchanging nonpublic identification codes, application identifiers, and data type identifiers via pre-established communication pathways and comparing against pre-established values to provide authorized communication and prevent compromised nodes from spreading malware to other nodes.


