Non-flashable Circuitry for Network Packet Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security measures relying on software are vulnerable to cyber-attacks, as they can be altered by hackers and may not effectively prevent unauthorized creation, insertion, deletion, update, or writing of files, and require constant updating to keep up with new malware.

Innovation Solution

Implementing non-flashable circuitry, such as Application-Specific Integrated Circuits (ASICs) or permanent Read-Only Memory (ROM) chips, to detect and block unauthorized data packets or frames by determining if they contain instructions for file-sharing protocols other than reading instructions and ensuring digital signatures from recognized sources, thereby preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If software is used for network security, then security functions can be implemented, but the security system becomes vulnerable to alteration by hackers and requires constant updating

Engineering Contradiction:
Improvesecurity function implementationVSAvoidsecurity system vulnerability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent replaces the software-based security system with a hardware-based security system using non-flashable circuitry. This substitution eliminates the vulnerability of software to remote alteration while maintaining security functions such as packet filtering and digital signature verification through hardware implementation.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent segments the security system into distinct functional modules implemented in hardware, including packet inspection units, digital signature verification units, and decision-making logic. This segmentation allows each component to perform its specific function reliably without being susceptible to software-based attacks.

Inventive Principle:
Principle #1Segmentation

2Object-affected harmful factors

If firewall software is used to detect and block malicious data packets, then some security protection is provided, but the system remains vulnerable and requires constant updating to keep up with new malware

Engineering Contradiction:
Improveprotection against cyber-attacksVSAvoidconstant updating requirement
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by pre-configuring the hardware security system with security rules, protocols, and digital signature verification mechanisms during manufacturing. This pre-configuration eliminates the need for constant updating, as the system is designed to recognize and block malicious patterns from the outset without requiring remote modifications.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces the update-dependent software firewall with a hardware-based system that has immutable security logic. This substitution eliminates the complexity of constant updating by embedding security rules directly in non-flashable circuitry that cannot be remotely modified.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If non-flashable circuitry is used for security, then protection against remote alteration is improved, but the ability to update security rules is reduced

Engineering Contradiction:
Improveprotection against remote alterationVSAvoidsecurity rules update capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent extracts the update capability from the main security processing circuitry and places it in a separate, controlled interface. This allows security rules to be updated through a secure local process rather than remote updates, maintaining protection against remote alteration while enabling necessary rule changes through authorized local intervention.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary secure interface that mediates between the need for rule updates and the requirement for protection against remote alteration. This intermediary allows authorized local updates while blocking unauthorized remote modifications, balancing adaptability with reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12088735B1Apparatus, systems, and methods relying on non-flashable circuitry for improving security on public or private networks
Publication Date: 2024.09.10 ZECURITY LLC
  • US12088735B1 patent drawing
  • US12088735B1 patent drawing

AI summary

A hardware unit relies on non-flashable circuitry for improving security on a public or private network. The hardware unit can be added to a network without substantial modifications to the other devices already connected to the network. The hardware unit detects and blocks or drops data packets or frames that contain an instruction of a known file-sharing protocol other than a reading instruction that are not digitally signed by a recognized source. Thus, a cyber attack may be prevented instantaneously by what it attempts to do, typically the creation, insertion, deletion, update, renaming, or writing of files to compromise code or data.