Hardware Firewall Segmentation for Secure Microchip Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional firewalls, positioned externally, are inadequate in defending computers from Internet-based malware attacks due to their inability to effectively block the vast and constantly changing network traffic, leaving systems vulnerable to security threats.

Innovation Solution

Implementing inner hardware or firmware-based access barriers or firewalls that disconnect private units from public Internet connections, allowing only authenticated and approved traffic, thereby simplifying the security mechanism and enhancing protection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional external firewalls are used to block malware, then network security is improved, but the firewall cannot effectively block the vast and constantly changing network traffic, leaving systems vulnerable

Engineering Contradiction:
Improvesecurity protectionVSAvoidability to block changing traffic
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The computer system is divided into multiple security zones (public unit, private unit, secure unit) with different access levels. Each zone has its own microprocessors and memory, separated by hardware firewalls. This segmentation allows the system to handle public network traffic in the public unit while protecting sensitive operations in private and secure units, resolving the contradiction by providing both broad network connectivity and targeted security for specific traffic types.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Hardware firewalls act as intermediaries between different security zones. The first hardware firewall mediates between the public unit and private unit, while the second hardware firewall mediates between the private unit and secure unit. These intermediary devices filter and control traffic flow, enabling the system to adapt to changing traffic patterns while maintaining security through multiple layers of mediation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If hardware-based access barriers are implemented to strictly limit access, then security protection is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity protectionVSAvoidfirewall architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Multiple security functions are merged into integrated hardware firewall devices. Each hardware firewall combines network traffic filtering, access control, and zone isolation capabilities into single physical devices positioned between security zones. This merging reduces the overall system complexity compared to having separate devices for each function, while maintaining strong security protection through the combined capabilities.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The security architecture uses a nested structure where the private unit is nested within the public unit, and the secure unit is nested within the private unit. Hardware firewalls are positioned at each nesting level to control access. This nested arrangement provides comprehensive security through multiple layers while organizing the complexity in a hierarchical manner that simplifies management and understanding of the overall system architecture.

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentUS8869260B2Computer or microchip with a master controller connected by a secure control bus to networked microprocessors or cores
Publication Date: 2014.10.21 ELLIS
  • US8869260B2 patent drawing
  • US8869260B2 patent drawing
  • US8869260B2 patent drawing

AI summary

A computer or microchip securely controlled through a private network including a connection to a network of computers including the Internet; a separate connection to at least a private network of computers located in a hardware protected area of said computer or microchip, a first microprocessor, core or processing unit configured to connect to the connection to the network of computers including the Internet; a master controlling device for the computer or microchip located in the hardware protected area; and a secure control bus configured to connect at least said master controlling device with said microprocessor, core or processing unit, and isolated from input from the network and components other than said master controlling device. The master controlling device securely controls an operation executed by the microprocessor, core or processing unit, with secure control being provided through the private network to the private network connection through the secure control bus.