Hardware Firewall for Protocol Data Unit Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data processing systems lack efficient hardware-based security checks for protocol data units, making them vulnerable to software-based attacks and ineffective in detecting malicious data units.

Innovation Solution

A hardware-based firewall device is integrated into the data processing apparatus to perform security checks on protocol data units using specifiable rules, capable of selectively testing units based on control information and discarding malicious ones, while being resistant to software-based attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If software-based security checks are used, then the system is flexible and can be updated, but the system becomes vulnerable to software-based attacks and less reliable

Engineering Contradiction:
Improvesecurity check reliabilityVSAvoidvulnerability to software-based attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent replaces software-based security checking with a hardware-based checking device that operates independently of the operating system. This hardware firewall checks protocol data units at the hardware level, making it immune to software-based attacks while maintaining security functionality. The hardware circuit performs packet filtering and security checks without being susceptible to OS vulnerabilities or software exploits.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If hardware-based security checks are implemented, then resistance to software-based attacks improves, but device complexity increases

Engineering Contradiction:
Improveresistance to software-based attacksVSAvoidhardware circuit complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the data processing system into distinct functional components: a hardware-based checking device for security checks, and software components for higher-level processing. The checking device is further segmented into specific functional units for different checking operations, allowing each component to be optimized independently while reducing overall system complexity through clear separation of concerns.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The hardware checking device acts as an intermediary between the network interface and the operating system. It performs security checks on incoming protocol data units before they reach the software layer, providing a buffer that protects the software from malicious inputs while maintaining a clear interface for legitimate communication.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If selective testing based on control information is implemented, then processing efficiency improves, but measurement precision of security checks decreases

Engineering Contradiction:
Improvedata processing efficiencyVSAvoidsecurity check coverage
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent implements dynamic security checking where the checking device can selectively apply different checking strategies based on control information in the protocol data units. For example, it can perform full security checks on suspicious packets while using faster filtering for trusted traffic, adapting the checking intensity to the specific situation to balance security and performance.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20240338448A1Apparatus and method for processing data units
Publication Date: 2024.10.10 ROBERT BOSCH GMBH
  • US20240338448A1 patent drawing
  • US20240338448A1 patent drawing
  • US20240338448A1 patent drawing

AI summary

An apparatus for processing data units, e.g., protocol data units. The apparatus includes a first number of input interfaces for receiving protocol data units and, optionally, a second number of output interfaces for outputting protocol data units, and a checking device, e.g., a firewall device, which is designed to check at least one received protocol data unit, e.g., to subject it to a security check.