Physical Intrusion Detection and Alert System for Packet Switched Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security methods for packet/frame/cell (PFC) networks fail to provide immediate detection and response to physical intrusions, allowing unauthorized access and data compromise due to the lack of comprehensive solutions for rapid alert generation and remediation in PFC-based network systems.

Innovation Solution

A system comprising a detection device, alert generator, and security enforcer that identifies physical intrusions in data communication paths, generates alerts, and automatically takes corrective actions to prevent further compromise, including rerouting traffic and encrypting data, to protect PFC networks from unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of time

If conventional security methods (manual detection and response) are used in PFC networks, then device complexity is reduced, but response time to physical intrusions is excessively long allowing data compromise

Engineering Contradiction:
Improveresponse time to physical intrusionVSAvoiddetection and alert system complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by pre-configuring detection devices on network links and pre-establishing alert generation mechanisms. When a physical intrusion is detected, the system immediately generates and transmits alerts without requiring manual intervention, thus reducing response time while maintaining manageable complexity through automated preliminary setup

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary alert generation system that sits between the detection device and network users. This intermediary automatically processes detection signals, generates appropriate alerts, and transmits them to users, thereby reducing response time without significantly increasing overall system complexity by using a standardized mediation layer

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If discrete temporarily deployed detection devices are used, then device complexity is minimized, but detection coverage and continuous monitoring capability are insufficient

Engineering Contradiction:
Improvecontinuous detection capabilityVSAvoiddetection system structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The detection devices are designed with multi-functionality to serve multiple purposes: they can detect physical intrusions, generate alerts, and potentially interface with multiple network links. This universal design improves reliability by enabling continuous monitoring without requiring separate specialized devices for each function, thereby maintaining simpler system structure

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If manual intervention is required to close off compromised links, then device complexity is reduced, but productivity and rapid response capability deteriorate

Engineering Contradiction:
Improveintrusion remediation speedVSAvoidautomated remediation system
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system implements feedback by continuously monitoring network links for physical intrusions and automatically responding to detected threats. When an intrusion is detected, the system generates alerts and can automatically trigger remediation actions, creating a closed-loop feedback system that improves productivity by eliminating manual intervention while maintaining manageable complexity through automated decision rules

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS7881209B2Method and system for protecting communication networks from physically compromised communications
Publication Date: 2011.02.01 CISCO TECHNOLOGY INC
  • US7881209B2 patent drawing
  • US7881209B2 patent drawing
  • US7881209B2 patent drawing

AI summary

A method and system for protecting a packet switched network from compromised communications due to a physical intrusion in the network are disclosed. The network includes at least one network element having a detection device operable to detect a possible physical intrusion in a data communication path connected to the network element. The method includes receiving a notification from the detection device that the detection device has identified a physical intrusion in the data communication path, generating an alert, and transmitting the alert over the packet switched network. The alert may include instructions on how to remediate the physical intrusion that can be automatically implemented by a given network-connected device or manually addressed by a network user or network administrator.