Transparent Security Appliance for High Availability Device Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

High availability devices in computer networks, such as those in wafer fabrication, banking, and medical applications, are vulnerable to virus attacks due to their inability to be taken offline for patch updates, leading to potential spread of malicious content within the network.

Innovation Solution

Deploying a low-cost, transparent security appliance with a scanning engine between high availability devices and network connections, which receives patch updates via removable storage or a secure server to block malicious content, allowing for continuous protection without requiring devices to be taken offline.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If high availability devices are kept online continuously, then device availability and operational continuity are improved, but vulnerability to virus attacks increases due to inability to apply patch updates

Engineering Contradiction:
Improvedevice availabilityVSAvoidvirus attack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a transparent security appliance as an intermediary device positioned between the high availability device and the network. This appliance performs virus scanning and filtering of network traffic without requiring the high availability device to be taken offline, thus maintaining device availability while protecting against virus attacks through the intermediary's independent patch update capability

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security functionality is segmented into a separate transparent appliance distinct from the high availability device. This segmentation allows the appliance to be updated independently while the high availability device remains operational, resolving the contradiction by separating the update requirement from the device operation requirement

Inventive Principle:
Principle #1Segmentation

2Object-affected harmful factors

If traditional virus protection software is installed on high availability devices, then protection capability is improved, but device complexity and maintenance difficulty increase

Engineering Contradiction:
Improveprotection capabilityVSAvoidsoftware maintenance complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

By moving the virus protection functionality to an external transparent appliance, the patent reduces the complexity on the high availability device while maintaining protection capability. The appliance handles all scanning and filtering operations independently, simplifying the overall system architecture and reducing maintenance burden on critical devices

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements a transparent copy of the network traffic that is scanned by the security appliance without modifying the original traffic flow to the high availability device. This copying approach allows virus detection and blocking without adding complexity to the device's operational software

Inventive Principle:
Principle #26Copying

3Object-affected harmful factors

If high availability devices are taken offline for patch updates, then virus protection effectiveness is improved, but device availability and operational continuity deteriorate

Engineering Contradiction:
Improveprotection effectivenessVSAvoidoperational continuity
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The transparent security appliance serves as a mediator that can be updated independently of the high availability device. Patch updates are applied to the appliance without affecting the operational status of the high availability device, thus maintaining both protection effectiveness and operational continuity simultaneously

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary virus signature updates in the transparent appliance before they are needed by the high availability device. The appliance proactively receives and applies patch updates in advance, ensuring protection is already in place when new threats emerge, without requiring the high availability device to be taken offline

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8667590B1Method and apparatus for protecting high availability devices from computer viruses and other malicious content
Publication Date: 2014.03.04 TREND MICRO INC
  • US8667590B1 patent drawing
  • US8667590B1 patent drawing
  • US8667590B1 patent drawing

AI summary

A technique for protecting a high availability device in a computer network includes deploying an appliance between the high availability device and a network connection. The high availability device may be a device configured for a manufacturing operation, such as wafer fabrication, for example. The appliance may be a transparent security appliance with a scanning engine for scanning packets for malicious content, such as computer viruses or worms, for example. Scanning control information can be supplied to the appliance by way of either a removable storage medium or a secure server coupled to the appliance, for example. The scanning control information can include a patch update, perhaps with signatures of viruses and associated control instructions. The appliance can then block any malicious content entering the appliance in response to the scanning control information. Among other advantages, the technique allows for low-cost, plug-and-play protection of high availability devices with good scalability to larger network configurations.