Sentry Device for Local Security Data Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing facility security systems face risks due to the transmission of sensitive security data outside the facility through virtual private networks (VPNs), which can compromise security and data integrity.

Innovation Solution

A sentry device is implemented within the facility to monitor and analyze security data without transmitting it outside, using non-VPN communication paths and processing security monitoring and remediation functions locally, with only results being transmitted securely through a firewall-protected channel.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If security data is transmitted outside the facility through VPN, then remote monitoring capability is improved, but security risk increases

Engineering Contradiction:
Improveremote monitoring capabilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the sensitive security data from the transmission stream by processing it locally within the facility. Only non-sensitive monitoring results are transmitted outside through the VPN, while the sensitive raw data remains confined to the internal network, thus maintaining remote monitoring capability while eliminating security risks associated with data transmission

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary processing system (firewall and local processing device) between the security data source and the external network. This intermediary processes and filters the data, allowing remote monitoring through the VPN while blocking sensitive data from leaving the facility, thus resolving the contradiction between remote access and security

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If security data is transmitted outside the facility, then remote analysis capability is improved, but data integrity risk increases

Engineering Contradiction:
Improveremote analysis capabilityVSAvoiddata integrity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent extracts only the essential monitoring results (non-sensitive data) for external transmission, leaving the complete and intact sensitive data within the facility. This allows remote analysis of key findings while preserving the integrity of the original security data through local retention

Inventive Principle:
Principle #2Taking out (Extraction)

3Ease of operation

If VPN is used for data transmission, then remote access is enabled, but security vulnerability increases

Engineering Contradiction:
Improveremote accessVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent places a firewall as an intermediary between the VPN and the internal network. The firewall controls and filters all traffic, allowing authorized remote access while blocking unauthorized connections and potential attacks, thus enabling remote access functionality while mitigating security vulnerabilities of the VPN

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10515539B2Security-focused network monitoring system
Publication Date: 2019.12.24 KNIGHT SECURITY SYSTEMS LLC
  • US10515539B2 patent drawing
  • US10515539B2 patent drawing
  • US10515539B2 patent drawing

AI summary

In some implementations, data from security monitoring devices of a facility is collected and analyzed within the facility and the results of the analysis transmitted to another computer that is outside of the facility via a non-VPN communication path.