MOB Hub Network Router Isolating Embedded Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current embedded system protection techniques, such as 'protect and patch,' leave parts of embedded systems accessible to wider networks, creating direct attack surfaces that are costly and inefficient to secure.

Innovation Solution

A multilayered obstructed brokered (MOB) cyber security architecture that isolates and obstructs direct communication paths between embedded systems and wider networks, using limited processing and communication components with integrated encryption modules to ensure data security and reduce attack surfaces.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If embedded systems are directly connected to wider networks for communication and data transfer, then network functionality and data accessibility are improved, but attack surfaces increase and security costs rise

Engineering Contradiction:
Improvenetwork functionalityVSAvoidattack surfaces
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a network router as an intermediary device between embedded systems and wider networks. The router receives data from embedded systems, repackages it into appropriate network protocols, and forwards it to destination networks. This mediator approach allows embedded systems to communicate with external networks without direct connections, thereby maintaining network functionality while reducing attack surfaces by isolating embedded systems from direct network exposure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the network architecture into distinct layers: embedded systems, network routers, and external networks. Each layer operates independently with defined interfaces. The router acts as a separate segment that handles protocol translation and data repackaging, preventing direct attack paths from external networks to embedded systems while preserving communication capabilities through structured data flow.

Inventive Principle:
Principle #1Segmentation

2Reliability

If comprehensive security measures are implemented to protect embedded systems from network attacks, then security reliability is improved, but system complexity and implementation costs increase

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The network router serves as a security intermediary that implements security functions externally to embedded systems. The router handles protocol translation, data validation, and secure forwarding without requiring complex security implementations within the embedded systems themselves. This approach improves security reliability by centralizing security functions while reducing system complexity by keeping embedded systems simple and focused on their core functions.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Speed

If direct communication protocols are used between embedded systems and external networks, then communication efficiency is improved, but vulnerability to network attacks increases

Engineering Contradiction:
Improvecommunication efficiencyVSAvoidnetwork vulnerability
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The network router acts as a communication intermediary that maintains efficiency while reducing vulnerability. It receives data from embedded systems using their native protocols, repackages it into appropriate external network protocols, and forwards it efficiently to destination networks. This process preserves communication speed and efficiency while the router's protocol translation capability prevents direct exposure of embedded systems to external network attacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes communication protocol parameters through the router intermediary. The router transforms data from embedded system protocols into external network protocols, altering communication parameters such as data format, transmission rules, and protocol structure. This parameter transformation enables efficient communication while the protocol conversion process itself acts as a security barrier, preventing direct vulnerability exploitation.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10502572B1System and methods for network routing and data repackaging
Publication Date: 2019.12.10 THE UNITED STATES OF AMERICA AS REPRESENTED BY THE SECRETARY OF THE NAVY
  • US10502572B1 patent drawing
  • US10502572B1 patent drawing
  • US10502572B1 patent drawing

AI summary

Embodiments of the invention are directed a network routing and data repackaging system. The system pairs a multilayered obstructed brokered network routing and data repackaging system, sometimes referred to as a MOB HUB, with a cyber kneeboard. Both the MOB HUB and cyber kneeboard communicate with a mobile computer removably-attached to the cyber kneeboard.