Hardware Isolator for IoT Malware Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity solutions for computer systems and IoT devices rely heavily on software, which can be compromised by new attack methods, leaving them vulnerable to malware and cyber-attacks, especially in industrial control systems where such breaches can cause significant financial losses or harm.

Innovation Solution

A hardware-based isolator system that combines firmware obfuscation, white lists, machine user IDs, token passwords, restricted commands, internal buffer controls, and encrypted protocols to secure IoT systems and computer networks, using a Cryptoprocessor and hardware accelerator to enhance security by limiting malware access and ensuring only valid encrypted messages are accepted.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If software-based security measures are used to protect computer systems, then security protection is provided, but the system remains vulnerable to new attack methods and malware that can confuse or corrupt the software

Engineering Contradiction:
Improvesecurity protectionVSAvoidvulnerability to malware
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a hardware-based isolator as an intermediary component positioned between the computer system and external communication interfaces. This isolator acts as a mediator that filters and controls all data traffic, allowing legitimate communication while blocking malware and attack vectors. The isolator's hardware enforcement of security policies creates a protective barrier that software alone cannot provide.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces software-based security mechanisms with hardware-based enforcement. Instead of relying on software firewalls, antivirus programs, and security protocols that can be corrupted or bypassed, the system uses dedicated hardware circuits and logical isolators that physically enforce security policies at the hardware level, making them resistant to software-based attacks and corruption.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If hardware-based isolator systems are implemented to block malware, then security against software intrusions is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity against malwareVSAvoidsystem structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the computer system into isolated segments or zones with controlled communication pathways. The isolator creates distinct security domains that can be independently managed and protected. This segmentation allows security policies to be applied at specific boundaries rather than requiring complex system-wide security mechanisms, simplifying the overall architecture while maintaining strong security.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10922427B2Systems and methods for cybersecurity
Publication Date: 2021.02.16 JPS ENGINEERING CORP
  • US10922427B2 patent drawing
  • US10922427B2 patent drawing
  • US10922427B2 patent drawing

AI summary

The disclosed embodiments provide a method and apparatus for protecting a critical computer system from malware intrusions. An isolator containing access approval features is disclosed. The isolator requires the approval of a Supervisor which can be a person with authority or an intelligent computer before a user can have access to the critical computer system. The isolator contains features used to facilitate cascaded encryption and decryption of messages which further enhances the security of the critical computer system. The isolator can greatly improve security of infrastructure such as industrial control systems, servers and workstations. The disclosed embodiments also provide a set of software and hardware features used to provide detection, prevention and recovery from a Cyber-attack in an Internet of Things installation.