Network Security Content Checker Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security systems face risks of data damage and information leaks due to component failures that can cause data to bypass content checkers, leading to potential attacks or unauthorized data transmission.

Innovation Solution

Implementing an encryption method between the network interface card and the content checker using a key agreement protocol, such as Diffie-Hellman, and employing symmetric or asymmetric encryption to ensure that mis-delivered data is rendered unintelligible, thereby preventing damage or leaks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data is transmitted in a format that is invalid with respect to other software or peripheral firmware, then the risk of damage from misdelivered data is reduced, but the complexity of the system increases due to format validation requirements

Engineering Contradiction:
Improvedata integrityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies parameter changes by transforming data into a specific invalid format (changing the parameters of data representation) that is deliberately incompatible with standard software interpretations. This format transformation ensures that misdelivered data cannot be executed or processed harmfully by other system components, while the content checker can still validate and process the transformed data correctly.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If encryption is applied to data transmitted between network interface card and content checker, then protection against misdelivered data is improved, but processing time and computational resources increase

Engineering Contradiction:
Improvedata protectionVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by performing encryption on data before transmission between the network interface card and content checker. This advance encryption ensures that even if data is misdelivered or intercepted, it remains protected and unintelligible to unauthorized components. The encryption is performed proactively as part of the data transmission protocol rather than reactively after potential threats are detected.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2577548B1Network security content checking
Publication Date: 2020.07.08 QINETIQ LTD
  • EP2577548B1 patent drawingFigure 1
  • EP2577548B1 patent drawingFigure 2
  • EP2577548B1 patent drawingFigure 3

AI summary

Methods, apparatus, and programs for a computer for network security content checking: in particular ones which simplify the critical element of a content checker so it can be trusted and implemented in logic.