Network Security Input Output System with Heterogeneous Redundancy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The network security defense system faces a challenge in improving the security of its input and output ends, which utilize single-point communication and are not suitable for the dynamically heterogeneous redundancy mechanism.

Innovation Solution

An input-output system is introduced, comprising a structural encoding unit with an input branching module and input proxy module, and an error correction decoding unit with an output selecting module, output proxy module, arbitration branching module, arbitration proxy module, and voting module. These modules are designed to replicate and distribute messages and data, perform voting, and select output results, all while ensuring no backdoors and implementing memory erasure functions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If single-point communication is used at input and output ends, then communication simplicity is maintained, but security is insufficient and vulnerable to backdoors

Engineering Contradiction:
ImprovesecurityVSAvoidcommunication structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the single-point communication structure into multiple parallel communication paths (input branching module creates multiple input channels, arbitration branching module creates multiple output channels). This segmentation allows the system to distribute traffic across multiple paths, preventing single-point vulnerabilities and enabling security mechanisms like voting and memory erasure on each path independently.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary modules (input proxy module, output proxy module, arbitration proxy module) that act as mediators between the communication paths and the core processing units. These proxies implement security functions including memory erasure, voting, and backdoor verification, thereby enhancing security without requiring fundamental changes to the communication architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If dynamically heterogeneous redundancy mechanism is applied, then security defense capability is improved, but it cannot be applied in single-point communication structure

Engineering Contradiction:
Improvesecurity defense capabilityVSAvoidapplicability to communication structure
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic heterogeneity by allowing different communication paths to use different security mechanisms and redundancy levels. The system can dynamically adjust which paths are active, switch between different voting schemes, and apply memory erasure at different rates based on security requirements. This dynamic approach enables the redundancy mechanism to adapt to various communication scenarios.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent applies different security qualities to different parts of the communication system. Critical paths may have full voting and memory erasure, while less critical paths may have simplified mechanisms. The input and output proxies can apply different levels of security processing to different messages based on their sensitivity, thereby making the redundancy mechanism adaptable to various communication requirements.

Inventive Principle:
Principle #3Local quality

3Object-affected harmful factors

If memory erasure function is implemented to erase impact from disturbance, then security against generalized disturbance is improved, but system complexity increases

Engineering Contradiction:
Improveresistance to generalized disturbanceVSAvoidsystem structure
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent implements memory erasure as a preliminary action that occurs automatically at defined points in the communication flow (at the input proxy and output proxy modules). By pre-erasing memory contents at these strategic points, the system prevents accumulated disturbances from affecting subsequent operations, thereby enhancing resistance to generalized disturbance without requiring continuous complex monitoring throughout the entire system.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12267303B2Input/output system applied to network security defense system
Publication Date: 2025.04.01 CHINA NAT DIGITAL SWITCHING SYST ENG & TECH R&D CENT
  • US12267303B2 patent drawing
  • US12267303B2 patent drawing
  • US12267303B2 patent drawing

AI summary

A structural encoding unit and an error correction decoding unit are divided. The structure encoding unit is divided into input branch processor and an input proxy processor; and the error correction decoding unit is divided into an output routing processor, an output proxy processor, an adjudication branch processor, an adjudication proxy processor and a voting processor. The input branch processor is used for duplicating and distributing messages, the arbitration branch processor is used for duplicating and distributing data, the voting processor is used for performing voting, and the output routing processor is used for selecting an output result from processing results of the output proxy processor according to a voting result of the voting processor.