Network Security Intermediary for IoT Malware Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security measures for networked computing devices are inadequate against cyber-attacks, particularly in IoT networks, as they consume significant resources and are not cost-effective for large-scale implementation, and do not provide complete protection against malware and intrusion.
Innovation Solution
A system that secures communications by using non-public identification codes and application identifiers, with cryptographic keys and data model validation, to establish authorized communication pathways and encrypt data packets, ensuring only authorized data is transmitted and received.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional device-level protection (anti-malware software and intrusion detection technology) is installed, then security protection is improved, but computing resources are consumed significantly and Quality-of-Service is degraded
Solution Approach 1:
The patent introduces a network security system as an intermediary layer between network interfaces and internal networks. This mediator performs security functions at the network level rather than requiring heavy anti-malware software on each device, thus improving security protection while reducing computing resource consumption on individual devices.
Solution Approach 2:
The patent shifts the security protection dimension from device-level (individual computing resources) to network-level (centralized security infrastructure). By implementing security measures at the network infrastructure level rather than on each endpoint device, the system achieves comprehensive security without consuming significant resources on individual devices.
2Reliability
If conventional device-level protection is installed, then security protection is improved, but Quality-of-Service is degraded
Solution Approach 1:
The network security system acts as an intermediary that handles security inspection and authentication at the network level, allowing device-level applications to operate without the performance overhead of local security software. This mediator approach maintains security protection while preserving Quality-of-Service for legitimate traffic.
Solution Approach 2:
By moving security functions to the network infrastructure level, the patent eliminates the need for resource-intensive security software on each device. This dimensional shift from device-level to network-level security ensures that Quality-of-Service is not degraded, as security processing occurs centrally rather than on every endpoint device.
3Reliability
If conventional node protection tools are upgraded, then security protection is improved, but cost-effectiveness is reduced due to rapid increases in processing and memory requirements
Solution Approach 1:
The patent employs a network security system as an intermediary that centralizes security processing. Instead of requiring each node to maintain complex protection tools with increasing processing and memory requirements, the system uses a centralized infrastructure to handle security functions, reducing the complexity burden on individual devices while maintaining comprehensive protection.
Solution Approach 2:
The patent transitions security protection from a device-centric model requiring continuous hardware upgrades to a network-infrastructure model. By implementing security at the network level with centralized management, the system achieves improved protection without the escalating processing and memory requirements that plague conventional node protection tools.
Data Source
AI summary
The present disclosure relates to network security software cooperatively configured on plural nodes to authenticate and authorize devices, applications, users, and data protocol in network communications by exchanging nonpublic identification codes, application identifiers, and data type identifiers via pre-established communication pathways and comparing against pre-established values to provide authorized communication and prevent compromised nodes from spreading malware to other nodes.


