Network Device APT Protection via Memory Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network-connected devices, such as bar code scanners and payment terminals, are vulnerable to Advanced Persistent Threats (APT) attacks, where malware or contaminated firmware can be loaded before shipment, allowing access to sensitive data once connected to a network.

Innovation Solution

A method and system that involves detecting rogue software in the memory instructions of network-connected devices by authenticating executable program instructions using checksum block routines and locking down communications if unauthorized instructions are found, utilizing public key and private key cryptography or two-factor authentication to protect against APT attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If network-connected devices are deployed with standard software and communication capabilities, then device functionality and connectivity are improved, but vulnerability to APT attacks increases

Engineering Contradiction:
Improvedevice functionalityVSAvoidAPT attack vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary authentication of memory instructions before execution by installing checksum block routines at a low level in the operating system. These routines generate checksums of memory instructions and compare them against expected values, preventing execution of unauthorized or malicious code. This preliminary security check is performed before APT attacks can compromise the device, thereby maintaining device functionality while preventing vulnerability exploitation.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If checksum authentication is performed on all memory instructions, then security against APT is improved, but device performance and execution speed deteriorate

Engineering Contradiction:
Improvesecurity authenticationVSAvoidexecution speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent performs checksum authentication in advance during system initialization and before memory instructions are executed. The checksum block routines are installed at a low level in the operating system and automatically authenticate memory instructions as they are loaded into memory, before malicious code can be injected or activated. This preliminary authentication approach ensures security without requiring continuous verification during execution, thus maintaining device performance.

Inventive Principle:
Principle #10Preliminary action

3Difficulty of detecting and measuring

If low-level routines are installed for instruction authentication, then detection capability is improved, but device complexity increases

Engineering Contradiction:
Improverogue software detectionVSAvoidsystem structure
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The patent implements a self-service security mechanism where the operating system itself provides authentication capabilities through checksum block routines installed at a low level. These routines are integrated into the OS kernel and automatically perform authentication of memory instructions without requiring external security software or complex additional components. The system serves its own security needs through built-in cryptographic verification, thereby improving detection capability while minimizing added complexity.

Inventive Principle:
Principle #25Self-service

4Reliability

If communications are locked down upon detecting rogue software, then network security is improved, but device usability deteriorates

Engineering Contradiction:
Improvenetwork securityVSAvoiddevice usability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements preliminary anti-action by preventing rogue software execution through checksum authentication before it can compromise network security. The checksum block routines detect unauthorized memory instructions and prevent their execution, thereby neutralizing potential APT threats before they can initiate malicious communications. This preventive approach maintains network security while avoiding the need to lock down communications, thus preserving device usability.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS10333955B2Method and system to protect software-based network-connected devices from advanced persistent threat
Publication Date: 2019.06.25 HAND HELD PRODS INC
  • US10333955B2 patent drawing
  • US10333955B2 patent drawing
  • US10333955B2 patent drawing

AI summary

A method of protecting a network-connected device from an advanced persistent threat cyber-attack is provided. A network-connected device having an operating system, a memory, memory instructions holding executable program instructions, and being communication enabled, is protected from an advanced persistent threat by steps of detecting the advanced persistent threat due to the presence of rogue software in the memory instructions of the network-connected device and locking-down the communications of the network-connected device. The network-connected device may be provided with low-level routines that are correlated to the memory instructions. Detecting the advanced persistent threat may be comprised of authenticating the memory instructions of the network-connected device by using the installed low-level routines.