Network Stack Intermediary for IoT Malware Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security technologies are inadequate in protecting networked computing devices from malware attacks, particularly in IoT networks, as they consume significant resources and may degrade Quality-of-Service, making them impractical for lightweight edge appliances and failing to ensure secure communication of sensitive information.
Innovation Solution
A system that secures communications between networked computing devices by executing computer-readable program code to manage identification codes, application identifiers, and data types, using encryption and authentication to establish authorized communication pathways, ensuring only authorized devices can exchange data, and translating payloads to conform to pre-defined formats and models.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional device-level protection (anti-malware software and intrusion detection technology) is installed, then security against malware attacks is improved, but computing resources are consumed significantly and Quality-of-Service is degraded
Solution Approach 1:
The patent introduces a network stack intermediary layer that operates between the application layer and the physical network layer. This intermediary implements security functions (identification code exchange, authentication, encryption) at the network stack level rather than relying solely on device-level software. The network stack acts as a mediator that provides security services to multiple applications simultaneously, reducing the computational burden on individual devices while maintaining security effectiveness.
Solution Approach 2:
The patent segments security functions into distinct components: identification code exchange, authentication, and encryption are separated as distinct operations within the network stack. This segmentation allows each function to be optimized independently and enables lightweight implementation on resource-constrained devices. The segmentation also allows security operations to be performed at the network layer rather than requiring heavy device-level protection software.
2Reliability
If conventional device-level protection is installed, then security coverage is improved, but the solution becomes impractical for lightweight edge appliances in IoT networks
Solution Approach 1:
The patent replaces the mechanical approach of installing heavy device-level protection software with a network-layer mechanism. Instead of relying on complex anti-malware software and intrusion detection systems that run on device processors, the solution uses network stack commands and identification codes that operate at the network layer. This substitution eliminates the need for heavy device-level software while maintaining comprehensive security coverage through network-based authentication and encryption.
Solution Approach 2:
The patent changes the operational parameters of security from device-level processing to network-level processing. By moving security functions to the network stack, the solution changes the scale at which security operations occur, enabling lightweight implementation on edge devices. The network stack handles identification codes and authentication at a lower level, reducing the computational requirements on individual devices while maintaining security effectiveness.
3Reliability
If network stack commands are used to exchange identification codes and establish encrypted pathways, then security of sensitive information communication is improved, but implementation complexity increases
Solution Approach 1:
The patent implements a universal network stack command interface that can be used by multiple applications for identification code exchange and authentication. This multi-functional approach allows different applications to use the same security mechanisms without requiring application-specific implementation details. The network stack provides standardized commands for authentication and encryption, simplifying the implementation complexity while maintaining strong security for sensitive information communication.
Data Source
AI summary
The present disclosure relates to network security software cooperatively configured on plural nodes to authenticate and authorize devices, applications, users, and data protocol in network communications by exchanging nonpublic identification codes, application identifiers, and data type identifiers via pre-established communication pathways and comparing against pre-established values to provide authorized communication and prevent compromised nodes from spreading malware to other nodes.


