Network Endpoint Security Layer for Legacy Device Integration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing electronic systems face challenges in flexibility and security due to application-specific requirements, leading to costly and difficult updates, especially in distributed systems where legacy devices may not be compatible with newer standards, and there is a need for secure communication and reconfigurability.

Innovation Solution

A network system with end-points and a controller that communicate using unique hardware identifiers and encryption keys, providing secure and adaptable communication by filtering and encrypting data, and translating protocols to ensure compatibility across different devices and software languages.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If custom connectors and cabling are used for distributed components, then secure communication and device compatibility are improved, but system cost, weight, size, and complexity increase

Engineering Contradiction:
Improvesecure communicationVSAvoidcustom connectors and cabling
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal endpoint interface that can communicate with multiple different device types using a single standardized connection. The endpoint device includes a communication interface that supports multiple protocols and a processing system that can translate between different device protocols, eliminating the need for custom connectors for each device type while maintaining secure communication capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The endpoint device acts as an intermediary between the network system and various legacy devices. It includes protocol translation functionality that converts between different communication protocols, allowing legacy devices to communicate securely through a standardized interface without requiring custom cabling or connectors.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If legacy devices are integrated into the network system, then system adaptability and flexibility are improved, but security consistency and protocol compatibility deteriorate

Engineering Contradiction:
Improvelegacy device integrationVSAvoidsecurity consistency
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The endpoint device serves as a security intermediary that all legacy devices must pass through to access the network. It implements encryption and authentication functions, ensuring that even devices with outdated security protocols communicate securely through the endpoint's modern security mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces physical security mechanisms (such as hardware-based authentication in legacy devices) with software-based security implemented at the endpoint. This includes encryption/decryption functions and authentication protocols that work across different device types, modernizing security without requiring legacy device hardware changes.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Adaptability or versatility

If redesign of legacy components is performed to meet new standards, then protocol compatibility and security are improved, but development cost and time increase

Engineering Contradiction:
Improveprotocol compatibilityVSAvoidredesign cost
Core Design Contradiction:
Adaptability or versatilityVSEase of manufacture

Solution Approach 1:

The patent extracts the protocol translation and security functions from the legacy devices themselves and places them in the endpoint device. This allows legacy devices to remain unchanged while still achieving protocol compatibility and security compliance through the endpoint's translation capabilities.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The endpoint device creates virtual representations of legacy device interfaces through software emulation. It can mimic the communication protocols and data formats of legacy devices, allowing modern network infrastructure to interact with legacy devices without physical redesign of the legacy components.

Inventive Principle:
Principle #26Copying

4Adaptability or versatility

If frequent updates and modifications are made to distributed components, then system flexibility and functionality are improved, but qualification testing requirements and deployment complexity worsen

Engineering Contradiction:
Improvesystem reconfigurabilityVSAvoidqualification testing
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The endpoint device is designed as a universal platform that can support multiple device types and protocols through software configuration rather than hardware changes. Updates to supported protocols or device types can be deployed as software updates without requiring physical requalification of hardware components.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system allows dynamic reconfiguration of endpoint capabilities through software updates. The processing system can load new protocol handlers, encryption algorithms, or device drivers without hardware modification, enabling frequent updates without triggering extensive requalification testing.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10693884B1Device agnostic security layer and system
Publication Date: 2020.06.23 L3 TECHNOLOGIES INC
  • US10693884B1 patent drawing
  • US10693884B1 patent drawing
  • US10693884B1 patent drawing

AI summary

A network end-point communicates, to a controller, a unique hardware identifier that is associated with a first end-point. The network end-point receives from the controller a first encryption key that is uniquely matched to a decryption key privately held by a second end-point. The network end-point then receives device data from a first device in direct communication with the first end-point. The network end-point communicates the device data to the second end-point, wherein the device data is encrypted using the first encryption key.