Out-of-Band Signaling for IoT Firewall Bypass

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

IoT devices face challenges in transmitting data across network firewalls due to stringent firewall policies, which can introduce risks and complicate simple tasks, especially when minimal data needs to be transferred across the firewall.

Innovation Solution

A method is introduced to generate a low data rate signal using an out-of-band communications channel, where the signal, comprising a single bit or multiple bits transmitted sporadically, bypasses the firewall, utilizing a random clock signal to prevent data leakage and exfiltration attempts, and includes an authentication protocol for additional security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If firewall policies are applied to protect network infrastructure, then network security is improved, but data transfer capability deteriorates

Engineering Contradiction:
Improvenetwork securityVSAvoiddata transfer capability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments data transfer into two distinct paths: a primary path through the firewall for normal data communication, and a secondary out-of-band path for status signaling. This segmentation allows the firewall to maintain security for bulk data while permitting minimal status signals through the alternative path, resolving the contradiction between security and data transfer capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary out-of-band communication channel that mediates between the firewalled network infrastructure and external services. This intermediary path carries only essential status signals (not full data) and bypasses the firewall's data transfer restrictions, enabling status monitoring while maintaining firewall security policies.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If firewall policies are made stringent to prevent data leakage, then security risk is reduced, but communication flexibility deteriorates

Engineering Contradiction:
Improvedata leakage riskVSAvoidcommunication flexibility
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic communication flexibility by allowing the out-of-band status signaling path to adapt to different operational states. The system can dynamically switch between using the firewalled path for normal communication and the out-of-band path for status reporting, providing versatility without compromising security. The signaling protocol can be activated or deactivated based on operational needs.

Inventive Principle:
Principle #15Dynamics

3Reliability

If complex authentication protocols are implemented to secure firewall exceptions, then security is improved, but operational complexity deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidoperational complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the authentication and security verification functions from the main data path and places them in the out-of-band signaling path. By separating security verification from data transfer, the system reduces operational complexity in the primary communication channel while maintaining robust security through dedicated authentication mechanisms in the signaling path.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11646999B2Low data rate signalling
Publication Date: 2023.05.09 HEWLETT PACKARD DEVELOPMENT COMPANY LP
  • US11646999B2 patent drawing
  • US11646999B2 patent drawing
  • US11646999B2 patent drawing

AI summary

In some examples, a method for generating a low data rate signal for transmission from a first network domain to a second network domain, the second network domain logically separated from the first network domain by a firewall, can include encoding a signal from a first device logically positioned within the first network domain to form a data signal, and transmitting the data signal over an out-of-band communications channel from the first network domain to the second network domain.