Network Device Weakness Detection via External Server Evaluation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing digitization and networking of devices, particularly in industrial environments, pose a challenge in ensuring the security of these devices against unauthorized manipulation, as they become accessible via the Internet, leading to potential weaknesses that need to be detected and addressed.

Innovation Solution

A method and apparatus that involve transmitting a first message from a device in one network to a second device in a separate network, evaluating the message for identification information, and sending a second message to indicate any detected weaknesses, allowing for the identification of permissible communication protocols and potential security vulnerabilities, enabling targeted security enhancements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If devices are made accessible via the Internet to enable communication and autonomous decision-making, then connectivity and functionality are improved, but security against unauthorized manipulation deteriorates

Engineering Contradiction:
ImproveconnectivityVSAvoidsecurity vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by proactively testing devices for security weaknesses before actual attacks occur. The manufacturer's server sends test messages to detect if devices can be accessed from outside the network, and only devices passing the security test are allowed to receive operational messages. This preventive approach identifies vulnerabilities before they can be exploited by unauthorized parties.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If security testing is performed by having the first device transmit messages outside the network, then detection reliability is improved, but network complexity increases

Engineering Contradiction:
Improvedetection reliabilityVSAvoidnetwork complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses an intermediary approach by introducing a manufacturer's server as a mediator between the first device and the external network. The server receives test messages from the first device, evaluates them for identification information, and sends response messages back. This intermediary structure simplifies the overall network architecture while maintaining reliable security detection, as the server handles the complexity of message evaluation and protocol testing.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If multiple transmission protocols are tested to identify permissible communication protocols, then adaptability is improved, but testing time increases

Engineering Contradiction:
Improveprotocol compatibilityVSAvoidtesting time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent applies continuity of useful action by having the first device continuously test multiple transmission protocols in an efficient manner. The device systematically evaluates different protocols to determine which ones are permissible for communication with the manufacturer's server. This continuous testing process ensures that the device identifies all compatible protocols without unnecessary delays, maintaining both adaptability and time efficiency.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS10805334B2Method and system for detection and avoidance of weaknesses in a network connected device
Publication Date: 2020.10.13 NETCONNECT WIRELESS LLC
  • US10805334B2 patent drawing

AI summary

A method and a system for identifying a weakness in a first device that is arranged in a first network, including transmission of a first message to a second device, wherein the second device is arranged in a second network outside the first network, including reception and evaluation of the first message by the second device for the purpose of providing a piece of identification information for the first device in the first network, including composition and transmission of a second message to the first device by the piece of identification information by the second device and including display of a weakness by the first device or second device if the second message is received by the first device. The method and a system can be used to check a secure network and/or device configuration in the industrial and private sectors.