Hardware Firewall Segmentation for Secure BIOS Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional firewalls, positioned externally, are inadequate in defending computers from Internet-based malware attacks due to their inability to effectively block constantly changing and vast amounts of network traffic, leading to inherent vulnerabilities in modern computer architectures.

Innovation Solution

Implementing inner hardware-based access barriers or firewalls, which are internally positioned and can strictly limit access to only authenticated sources, using simple one-way buses and switches to create secure, private units disconnected from the public Internet, thereby preventing unauthorized access and malware infiltration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional external firewalls are used to block network traffic, then some security protection is provided, but they are inadequate against constantly changing malware and vast amounts of network traffic

Engineering Contradiction:
Improvesecurity protectionVSAvoidability to block changing malware
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The computer system is divided into multiple security zones including a public unit connected to the Internet and a private unit disconnected from the Internet, separated by hardware-based access barriers. This segmentation isolates critical components in the private unit from external threats while allowing controlled communication through unidirectional gates, thereby providing reliable security protection that adapts to changing malware threats.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Hardware-based access barriers with unidirectional communication gates serve as intermediaries between the public unit and private unit. These barriers act as intelligent mediators that selectively allow or block data flow based on security rules, providing both reliable security protection and adaptability to new malware by enforcing strict communication protocols at the hardware level.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If external firewalls are positioned outside the computer, then they can filter network traffic, but they cannot effectively block all malware attacks due to architectural limitations

Engineering Contradiction:
Improvenetwork traffic filteringVSAvoidmalware blocking effectiveness
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

Instead of positioning the firewall externally as conventional systems do, this invention inverts the architecture by placing hardware-based access barriers internally within the computer system, between the public unit and private unit. This internal positioning allows the barriers to effectively control and filter traffic at the source, dramatically improving malware blocking effectiveness while maintaining ease of operation through automated hardware enforcement.

Inventive Principle:
Principle #13The other way round (Inversion)

3Adaptability or versatility

If the computer is fully connected to the Internet for functionality, then network access is maximized, but vulnerability to malware attacks increases

Engineering Contradiction:
Improvenetwork access capabilityVSAvoidmalware attack vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system segments network connectivity into a public unit that interfaces with the Internet and a private unit that remains disconnected, allowing the computer to maintain full Internet access capability through the public unit while protecting vulnerable components in the private unit from malware attacks through hardware-based isolation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Critical and vulnerable components are extracted from the public Internet-connected unit and placed into a private unit that is physically isolated from the Internet. This extraction removes the vulnerability to malware attacks from the system while preserving network access functionality in the public unit, thereby maintaining adaptability without increasing harmful factor exposure.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11683288B2Computer or microchip with a secure system bios having a separate private network connection to a separate private network
Publication Date: 2023.06.20 ELLIS
  • US11683288B2 patent drawing
  • US11683288B2 patent drawing
  • US11683288B2 patent drawing

AI summary

A method for a computer or microchip with one or more inner hardware-based access barriers or firewalls that establish one or more private units disconnected from a public unit or units having connection to the public Internet and one or more of the private units have a connection to one or more non-Internet-connected private networks for private network control of the configuration of the computer or microchip using active hardware configuration, including field programmable gate arrays (FPGA). The hardware-based access barriers include a single out-only bus and/or another in-only bus with a single on/off switch.