TCP/UDP Security Flag Mechanism for Threat Adaptation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

TCP/UDP sessions are vulnerable to virus, malware, and spyware attacks due to a lack of awareness about the security status of connected devices, leading to potential exposure of confidential information, as transport protocols are not adaptive and do not adjust information exchange based on security levels.

Innovation Solution

A system and method that inform peers about security issues in TCP/UDP sessions through a security flag in the TCP header, allowing applications to limit information exchange based on the severity of the issue, enabling proactive measures to mitigate security threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If TCP/UDP sessions exchange confidential information without security awareness, then information exchange continues uninterrupted, but security vulnerability increases due to lack of awareness about virus, malware, or spyware attacks

Engineering Contradiction:
Improvesecurity of information exchangeVSAvoidcomplexity of security monitoring
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary security monitoring mechanism that operates between the application layer and transport layer. This intermediary monitors security status independently without disrupting the TCP/UDP session flow, allowing confidential information exchange to continue while providing real-time security awareness through socket option notifications.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security monitoring system performs self-service by automatically detecting security issues and notifying applications through socket options without requiring manual intervention. The transport protocol layer autonomously monitors security status and communicates findings to the application layer, enabling the system to protect itself against threats while maintaining normal operation.

Inventive Principle:
Principle #25Self-service

2Adaptability or versatility

If transport protocols are made adaptive to security levels, then security response capability improves, but protocol complexity increases beyond standard TCP/UDP specifications

Engineering Contradiction:
Improveadaptability to security levelsVSAvoidcomplexity of transport protocol
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by making security adaptability optional and localized to specific applications that need it. Rather than making all TCP/UDP sessions adaptive to security levels (which would universally increase complexity), the invention allows applications to opt-in to security monitoring through socket options, providing adaptability only where required while maintaining standard protocol behavior elsewhere.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The security monitoring mechanism is dynamic, allowing applications to enable or disable security awareness on-demand through socket options. The system can adapt its behavior based on application requirements, enabling security monitoring when needed and maintaining standard operation when not required, thus providing versatility without forcing complexity on all sessions.

Inventive Principle:
Principle #15Dynamics

3Reliability

If security monitoring is implemented in TCP/UDP sessions, then awareness of security issues improves, but performance overhead increases due to additional monitoring and notification mechanisms

Engineering Contradiction:
Improvesecurity awarenessVSAvoidtransaction performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements partial action by providing security monitoring only to the extent that applications request it through socket options. Rather than monitoring all TCP/UDP sessions universally (which would create excessive overhead), the system selectively monitors only those sessions where applications have opted-in, providing necessary security awareness while minimizing performance impact on unaffected sessions.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10027687B2Security level and status exchange between TCP/UDP client(s) and server(s) for secure transactions
Publication Date: 2018.07.17 KYNDRYL INC
  • US10027687B2 patent drawing
  • US10027687B2 patent drawing
  • US10027687B2 patent drawing

AI summary

According to one embodiment, a method includes informing a second peer about a security issue in one or more secure transmission control protocol/user datagram protocol (TCP/UDP) using a first peer of the one or more TCP/UDP sessions. The method also includes performing at least one action at the first peer in response to detecting the security issue. The at least one action resolves the security issue, avoids the security issue, or resolves and avoids the security issue. Also, the at least one action includes informing, via a socket call or an extension of a socket call on the one or more TCP/UDP sessions, one or more applications operating on the second peer to limit information exchange based on a severity of the security issue. Other systems, methods, and computer program products are described in accordance with more embodiments.