Non-Flashable Circuitry for Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security measures relying on software are vulnerable to cyber-attacks, as they can be altered by hackers and may not effectively prevent unauthorized creation, insertion, deletion, update, or writing of files, especially with the constant need for updates and the emergence of new malware.
Innovation Solution
Implementing non-flashable circuitry, such as Application-Specific Integrated Circuits (ASICs), Field-Programmable Gate Arrays (FPGAs), or permanent Read-Only Memory (ROM) chips, to detect and block data packets or frames that contain unauthorized instructions, ensuring that firmware cannot be updated remotely and only allowing digitally signed data from recognized sources to be processed.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If software-based security measures are used, then ease of operation and adaptability are improved, but reliability deteriorates due to vulnerability to hacking and unauthorized alterations
Solution Approach 1:
The patent segments the security system into two distinct parts: non-flashable circuitry (ROM/ASIC) containing critical security functions that cannot be altered, and flashable memory containing updateable firmware for non-critical functions. This segmentation allows the system to maintain high reliability for security operations while preserving adaptability for legitimate updates through controlled interfaces.
Solution Approach 2:
The patent applies local quality by making specific regions of the system immutable (non-flashable ROM containing security protocols and digital signature verification) while allowing other regions (flash memory) to be updateable. This creates localized immutability where it is most needed for security, while maintaining flexibility elsewhere in the system.
2Reliability
If software-based firewall is used, then ease of operation is improved, but reliability deteriorates due to constant need for updates and vulnerability to new malware
Solution Approach 1:
The patent implements preliminary action by pre-loading security protocols, digital signature verification mechanisms, and authorized source identifiers into non-flashable ROM memory during manufacturing. This preliminary configuration ensures that core security functions are immediately operational and cannot be compromised by runtime modifications, eliminating the need for frequent security updates.
Solution Approach 2:
The patent substitutes the mechanical/software-based firewall update system with a hardware-based immutable security layer. Instead of relying on software updates delivered through potentially compromised channels, the system uses hardwired security protocols and digital signature verification that physically prevent unauthorized changes, replacing the update mechanism with a verification mechanism.
3Reliability
If non-flashable circuitry is used, then reliability is improved by preventing remote alteration, but device complexity increases
Solution Approach 1:
The patent applies universality by designing the non-flashable circuitry to perform multiple security functions simultaneously: storing security protocols, verifying digital signatures, identifying authorized sources, and controlling data packet transmission. This multi-functionality consolidates what could be separate hardware components into a single integrated security module, reducing overall device complexity.
Solution Approach 2:
The patent merges the security protocol storage, digital signature verification, and authorized source identification functions into a single non-flashable circuitry unit. This consolidation integrates multiple security mechanisms that could otherwise require separate hardware components, thereby reducing device complexity while maintaining comprehensive security.
Data Source
AI summary
A hardware unit relies on non-flashable circuitry for improving security on a public or private network. The hardware unit can be added to a network without substantial modifications to the other devices already connected to the network. The hardware unit detects and blocks or drops data packets or frames that contain an instruction of a known file-sharing protocol other than a reading instruction that are not digitally signed by a recognized source. Thus, a cyber attack may be prevented instantaneously by what it attempts to do, typically the creation, insertion, deletion, update, renaming, or writing of files to compromise code or data.

