Network Security Input Output System with Heterogeneous Redundancy
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The network security defense system faces a challenge in improving the security of its input and output ends, which utilize single-point communication and are not suitable for the dynamically heterogeneous redundancy mechanism.
Innovation Solution
An input-output system is introduced, comprising a structural encoding unit with an input branching module and input proxy module, and an error correction decoding unit with an output selecting module, output proxy module, arbitration branching module, arbitration proxy module, and voting module. These modules are designed to replicate and distribute messages and data, perform voting, and select output results, all while ensuring no backdoors and implementing memory erasure functions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If single-point communication is used at input and output ends, then communication simplicity is maintained, but security is insufficient and vulnerable to backdoors
Solution Approach 1:
The patent divides the single-point communication structure into multiple parallel communication paths (input branching module creates multiple input channels, arbitration branching module creates multiple output channels). This segmentation allows the system to distribute traffic across multiple paths, preventing single-point vulnerabilities and enabling security mechanisms like voting and memory erasure on each path independently.
Solution Approach 2:
The patent introduces intermediary modules (input proxy module, output proxy module, arbitration proxy module) that act as mediators between the communication paths and the core processing units. These proxies implement security functions including memory erasure, voting, and backdoor verification, thereby enhancing security without requiring fundamental changes to the communication architecture.
2Reliability
If dynamically heterogeneous redundancy mechanism is applied, then security defense capability is improved, but it cannot be applied in single-point communication structure
Solution Approach 1:
The patent implements dynamic heterogeneity by allowing different communication paths to use different security mechanisms and redundancy levels. The system can dynamically adjust which paths are active, switch between different voting schemes, and apply memory erasure at different rates based on security requirements. This dynamic approach enables the redundancy mechanism to adapt to various communication scenarios.
Solution Approach 2:
The patent applies different security qualities to different parts of the communication system. Critical paths may have full voting and memory erasure, while less critical paths may have simplified mechanisms. The input and output proxies can apply different levels of security processing to different messages based on their sensitivity, thereby making the redundancy mechanism adaptable to various communication requirements.
3Object-affected harmful factors
If memory erasure function is implemented to erase impact from disturbance, then security against generalized disturbance is improved, but system complexity increases
Solution Approach 1:
The patent implements memory erasure as a preliminary action that occurs automatically at defined points in the communication flow (at the input proxy and output proxy modules). By pre-erasing memory contents at these strategic points, the system prevents accumulated disturbances from affecting subsequent operations, thereby enhancing resistance to generalized disturbance without requiring continuous complex monitoring throughout the entire system.
Data Source
AI summary
A structural encoding unit and an error correction decoding unit are divided. The structure encoding unit is divided into input branch processor and an input proxy processor; and the error correction decoding unit is divided into an output routing processor, an output proxy processor, an adjudication branch processor, an adjudication proxy processor and a voting processor. The input branch processor is used for duplicating and distributing messages, the arbitration branch processor is used for duplicating and distributing data, the voting processor is used for performing voting, and the output routing processor is used for selecting an output result from processing results of the output proxy processor according to a voting result of the voting processor.


