Re-configurable Data Communication Device for Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Standard electronic device architectures allow direct access to native resources, creating security vulnerabilities that can be exploited by cyberattacks, as they bypass operating system supervision and security mechanisms.

Innovation Solution

A safe case with a controller that manages both the control and data planes of data communication, re-configures operating parameters of a re-configurable data communication device to a trusted clean state by applying a trusted firmware image, thereby wiping out malicious codes and enhancing security and privacy protection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If direct access to native resources is allowed for performance consideration, then data communication speed is improved, but security mechanisms are bypassed creating security vulnerabilities

Engineering Contradiction:
Improvedata communication speedVSAvoidsecurity mechanism effectiveness
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent introduces a re-configurable data communication device as an intermediary layer between the application layer and native resources. This device provides DMA capabilities while maintaining security through configurable access control, thus resolving the contradiction by enabling fast data communication without directly bypassing security mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the data communication function into multiple layers: the re-configurable device handles high-speed DMA operations while the controller manages security policies and firmware configuration. This segmentation allows performance-critical functions to operate independently while security functions remain under supervision.

Inventive Principle:
Principle #1Segmentation

2Reliability

If re-configuration of data communication device is performed to restore trusted state, then security is improved, but device operational time is reduced due to re-configuration interruptions

Engineering Contradiction:
Improvesecurity trust stateVSAvoiddevice operational continuity
Core Design Contradiction:
ReliabilityVSDuration of action of stationary object

Solution Approach 1:

The system performs preliminary validation of firmware images before applying them, and maintains a ready-state trusted firmware image. This allows rapid re-configuration when security events are detected, minimizing operational interruption while ensuring security integrity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The re-configuration process changes the firmware image parameter of the data communication device, transitioning it from a potentially compromised state to a trusted state. This parameter change restores security without requiring complete device replacement or prolonged downtime.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11243783B2Device re-configuration for security
Publication Date: 2022.02.08 PPIP LLC
  • US11243783B2 patent drawing
  • US11243783B2 patent drawing
  • US11243783B2 patent drawing

AI summary

In accordance with some embodiments, an apparatus that controls device re-configuration for security is provided. The apparatus includes a storage storing a first firmware image for a re-configurable data communication device. In some embodiments, the first firmware image provides one or more operating parameter configurations for the re-configurable data communication device. The apparatus also includes a controller, which is coupled to the storage and the re-configurable data communication device and operable to manage transport of data by the re-configurable data communication device, including obtaining the first firmware image from the storage and loading the first firmware image to the re-configurable data communication device. The apparatus additionally includes a housing at least partially supporting the storage and the controller.