Hardware one-way security data ferry storage device and method thereof
By using a hardware-based unidirectional secure data transfer storage device and utilizing an optocoupler or high-speed data isolation chip to achieve unidirectional data transmission, the security and convenience issues of data exchange under physically isolated networks are solved, and efficient and secure data transmission is realized.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- 王莎莎
- Filing Date
- 2026-01-19
- Publication Date
- 2026-05-08
AI Technical Summary
In physically isolated network environments, existing technologies suffer from problems such as data leakage, virus transmission, and cumbersome operation in data exchange, and existing equipment cannot meet the requirements for portability, flexibility, and plug-and-play functionality.
A hardware-based unidirectional secure data transfer storage device is adopted. Through physically independent first and second host interfaces and control logic units, data can flow unidirectionally from the first storage space to the second storage space. Optical couplers or high-speed data isolation chips are used to ensure that data can only be transmitted in one direction. The control logic units are solidified and hardened through FPGA or ASIC.
It achieves absolute one-way secure transmission at the hardware level, eliminates the risk of data leakage and virus transmission, simplifies operation processes, improves data transfer efficiency, adapts to various device forms and scenarios, and enhances device reliability and security.
Smart Images

Figure CN121996162A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data storage and information security technology, specifically to a hardware-based one-way secure data transfer storage device and method. Background Technology
[0002] In highly sensitive sectors such as government, military, finance, energy, and critical infrastructure, physically isolated network architectures are typically employed to ensure the absolute security of core data. This architecture physically disconnects the internal "intranet" (high-security network) that processes sensitive information from the external "extranet" (low-security network) that has internet access, thus preventing malicious attacks from external networks and the leakage of internal data.
[0003] However, physical isolation also presents challenges for data exchange. In practice, it is often necessary to import publicly available information, updates, and data reports from the external network into the internal network for processing. Currently, the most common data exchange method is "physical ferrying," which uses standard portable storage media (such as USB flash drives and external hard drives) as the "ferry." The process typically involves manually switching storage media between computers on the internal and external networks and copying data. This traditional method presents numerous serious security risks and operational inconveniences, including: data leakage risks (operators may accidentally copy sensitive internal network data to the media, leading to leaks when connecting to the external network); virus or malware propagation risks (malicious programs infected on the external network may be transmitted to the internal network via the media); and cumbersome operation, low efficiency, and a lack of effective auditing and control.
[0004] To address the issue of unidirectional data transmission between networks, existing technologies have developed devices such as "network isolation gateways" or "data diodes," which ensure unidirectional data transmission through hardware technology. However, these devices are typically large-scale network equipment, expensive, complex to deploy, and suitable for fixed network nodes. They cannot meet the portable, flexible, plug-and-play secure data transfer needs of individual users or mobile office scenarios. Furthermore, some dual-system isolation solutions implemented through software or virtualization technologies rely heavily on the reliability of the software and the underlying operating system for security, failing to provide hardware-level physical isolation guarantees.
[0005] Therefore, the market urgently needs a new type of data transmission solution that can provide both the hardware-level unidirectional transmission security of a data diode and the portability and ease of use of a portable storage medium, in order to solve the pain points of data transfer in the current physically isolated environment. Summary of the Invention
[0006] The purpose of this invention is to provide a hardware-based unidirectional secure data transfer storage device and method. Through a hardware-implemented unidirectional data transmission module, physically independent first and second host interfaces, and a control logic unit, the device forces data to flow unidirectionally from the first storage space to the second storage space at the hardware level, effectively preventing data backflow and combining high security with ease of operation.
[0007] To achieve the above objectives, the present invention provides the following technical solution: a hardware-based one-way secure data transfer storage device and method, comprising: a first storage space and a second storage space; a first host interface for connecting to a first network and a second host interface for connecting to a second network, wherein the first host interface and the second host interface are physically independent; a control logic unit; and a hardware-implemented one-way data transfer module. The control logic unit is configured to: when the storage device is connected to a computer in the first network via the first host interface, make the first storage space visible only to that computer; when the first storage space receives write data from the computer, instruct the one-way data transfer module to synchronize the write data to the second storage space in real time; when the storage device is connected to a computer in the second network via the second host interface, make the second storage space visible only to that computer; wherein, the one-way data transfer module ensures at the hardware level that data can only be transferred from the first storage space to the second storage space, and prevents any data backflow from the second storage space to the first storage space. This device, through its hardware-level enforced one-wayness, fundamentally solves the risks of data leakage and virus import in traditional transfer methods.
[0008] Furthermore, the first storage space and the second storage space are two independent partitions on the same physical storage medium, or two independent physical storage media. When the same physical storage medium is used, independent partition management is performed through a control logic unit to achieve logical isolation; when two independent physical storage media are used, complete physical isolation is achieved, and the implementation scheme can be flexibly selected according to different security level requirements.
[0009] Furthermore, the unidirectional data transmission module is implemented based on an optical coupler or a high-speed data isolation chip, completing unidirectional data transmission through optical signals or electromagnetic isolation. For example, when using an optical coupler, data is physically transmitted unidirectionally through an electro-optical-electro-electrical conversion; when using a high-speed data isolation chip, electromagnetic isolation is used to eliminate any possibility of signal backflow at the hardware level.
[0010] Furthermore, the control logic unit is a field-programmable gate array (FPGA) or an application-specific integrated circuit (ASIC). Using an FPGA or ASIC enables the solidification and hardening of the control logic, preventing software tampering, ensuring the security, reliability, and determinism of device behavior, and meeting the trusted computing requirements in high-security scenarios.
[0011] Furthermore, the storage device is a portable storage device, with the first host interface and the second host interface located on different sides or ends of the device casing. This physical layout design helps users intuitively distinguish between internal and external network interfaces, avoiding mis-plugging, while maintaining the device's compact and portable characteristics, similar to the form factor of a dual-interface USB flash drive or portable solid-state drive.
[0012] Furthermore, the storage device is an internal storage device, and the first host interface and the second host interface are two independent SATA interfaces or NVMe interfaces. This configuration is suitable for fixed workstation scenarios, integrating internal and external network data storage functions into a single hard drive and connecting to the corresponding network via different motherboard interfaces or expansion cables to achieve convenient and secure data exchange.
[0013] Furthermore, the first host interface is a USB interface, and the second host interface is a USB interface or other types of data interfaces. The USB interface has the advantages of strong versatility and plug-and-play functionality, and can also be combined with other interface types (such as Ethernet ports) according to specific needs to adapt to different host connection environments.
[0014] Furthermore, the storage device also includes an authentication module, wherein the second storage space is only visible to a computer connected to the second network and authenticated by the authentication module. This authentication module (such as a password, digital certificate, or biometrics) adds extra control over access to high-security networks (internal networks), further enhancing the device's security.
[0015] Furthermore, the first host interface and the second host interface adopt different physical forms or different color markings to facilitate user differentiation. For example, the external network interface can be marked in blue, and the internal network interface in red, or the interfaces themselves can adopt different physical forms such as Type-A and Type-C, reducing the risk of user operation errors through intuitive visual or tactile differences.
[0016] Further, the method includes the following steps: providing a storage device comprising a first storage space, a second storage space, a first host interface, a second host interface, and a hardware-implemented unidirectional data transmission module; connecting the storage device to a computer in a first network via the first host interface, and exposing the first storage space only to that computer; when the first storage space receives write data, automatically unidirectionally synchronizing the data from the first storage space to the second storage space in real time via the unidirectional data transmission module; connecting the storage device to a computer in a second network via the second host interface, and exposing the second storage space only to that computer for reading the synchronized data; wherein, the data synchronization process is forced to be unidirectional at the hardware level to prevent any data from flowing back from the second storage space to the first storage space. This method simplifies the complex transfer process to two steps: "external network write, internal network read," with data synchronization automatically completed by the device, balancing security and ease of use.
[0017] This invention provides a hardware-based one-way secure data transfer storage device and method, which has the following beneficial effects: Achieving absolute unidirectional secure transmission at the hardware level, completely eliminating the risk of data leakage: The core advantage of this invention lies in its hardware-implemented unidirectional data transmission module (such as an optocoupler or a high-speed data isolation chip), which physically forces data to flow only from the first storage space (connected to the external network) to the second storage space (connected to the internal network). This design blocks any possibility of data backflow at the lowest level of electronic or optical signal transmission, achieving a security level equivalent to professional data diode equipment. Compared to traditional solutions relying on software or operating systems, this invention fundamentally eliminates the risk of sensitive internal network data being leaked to the external network through storage devices due to malware, system vulnerabilities, or human error, providing extremely high-reliability data transfer security for physically isolated networks.
[0018] By employing physically isolated dual interfaces and partition control, this invention effectively prevents network cross-infection and misoperation: Through physically independent first host interface (external network interface) and second host interface (internal network interface), combined with intelligent configuration of the control logic unit, strict access isolation is achieved. When a device connects to the external network, only the first storage space is visible; when connected to the internal network, only the second storage space is visible. This design ensures that computers on both the internal and external networks cannot logically access each other's storage areas simultaneously. This not only effectively prevents external network viruses or malware from being activated and spreading when connected to the internal network, but also fundamentally prevents the operational risks of users mistakenly writing internal network data to the external network partition or misreading internal network data in an external network environment, achieving inherent security.
[0019] Simplified operation process, significantly improving data transfer efficiency and user experience: Compared to the cumbersome traditional transfer process of "manual copy-unplug-security check-manual copy again," this invention simplifies data transfer into two intuitive steps: "writing via external network interface" and "reading via internal network interface." The synchronization process of data from the first storage space to the second storage space is automatically and in real-time completed by the device's internal unidirectional data transfer module, requiring no manual intervention. This highly automated design greatly reduces operational complexity, decreases the probability of errors, and significantly improves data exchange efficiency, making secure data transfer as convenient as using a regular USB flash drive.
[0020] The technical solution is flexible and applicable to various device forms and a wide range of application scenarios: The claims of this invention cover various device forms, including portable (such as dual-interface USB flash drives) and built-in (such as dual SATA / NVMe interface hard drives). Storage space can be an independent partition or an independent physical medium, control logic can be implemented by FPGA or ASIC, and interface types can be flexibly selected. This modular and scalable design allows the invention to adapt to the needs of different users and scenarios. Whether it's a portable scenario requiring mobile office work or a high-performance built-in storage requirement for a fixed workstation, a suitable implementation solution can be found, demonstrating broad applicability and market potential.
[0021] To enhance device reliability and tamper resistance, an additional security authentication layer is provided: By employing fixed hardware such as FPGA or ASIC to implement the control logic unit, the stability and immutability of the device's operating logic are ensured, preventing security threats that could alter device behavior through software attacks. Furthermore, the claims include an authentication module that ensures the second storage space (internal network side) is only visible after authentication. This adds a security barrier to internal network data access, preventing unauthorized personnel from reading transfer data, further enhancing the overall security and controllability of the device, and meeting the stringent requirements of high-security environments. Attached Figure Description
[0022] To more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings in the following description are merely exemplary, and those skilled in the art can derive other embodiments based on the provided drawings without creative effort.
[0023] Figure 1 This is a flowchart illustrating the overall operation of the device of the present invention. Figure 2 This is a flowchart illustrating the workflow of the hardware unidirectional data transmission module of the present invention. Figure 3This is a flowchart illustrating the host interface and storage space management of the control logic unit of the present invention. Figure 4 This is a complete flowchart of the data transmission process from network A to network B in this invention. Figure 5 This is a flowchart of the secure data transmission method of the present invention. Detailed Implementation
[0024] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numerals in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this disclosure. Rather, they are merely examples of apparatuses consistent with some aspects of this disclosure as detailed in the appended claims.
[0025] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative effort are within the scope of protection of the present invention.
[0026] How to use Step 1: Prepare the equipment Ensure you possess the aforementioned secure storage device. This device has two physically independent host interfaces (a first host interface and a second host interface) and incorporates a hardware-implemented unidirectional data transfer module.
[0027] Step 2: Connect to the first network (external network) to write data. 1. Connect the first host interface of the storage device (e.g., the USB interface marked in blue) to a computer on the first network (i.e., the external network).
[0028] 2. After the device is powered on, its internal control logic unit automatically detects that the first host interface has been activated and then enters "external network mode".
[0029] 3. In this mode, the control logic unit makes only the first storage space visible to the connected computer. The computer operating system will recognize only one storage partition (corresponding to the first storage space).
[0030] 4. Users write the data to be transferred (such as documents, update packages, etc.) into the visible first storage space, and the operation is no different from using a regular USB flash drive.
[0031] Step 3: The device automatically performs one-way data synchronization. 1. While data is being written to the first storage space, the control logic unit instructs the hardware-implemented unidirectional data transmission module to start working.
[0032] 2. This module (which may be based on an optocoupler or a high-speed data isolation chip) automatically and in real time synchronizes the data just written to the first storage space to the second storage space at the hardware level.
[0033] 3. Key security features: The hardware design of the unidirectional data transmission module ensures that data can only flow from the first storage space to the second storage space, and physically prevents any data backflow from the second storage space to the first storage space.
[0034] Step 4: Connect to the second network (internal network) to read data. 1. Disconnect the first host interface of the storage device from the computer on the first network.
[0035] 2. Connect the storage device’s second host interface (e.g., the USB interface marked in red) to a computer in the second network (i.e., the intranet).
[0036] 3. After the device is powered on, the control logic unit detects that the second host interface is activated and automatically switches to "internal network mode".
[0037] 4. In this mode, the control logic unit makes the second storage space visible only to the connected computer. The computer operating system will only recognize the other storage partition (corresponding to the second storage space).
[0038] 5. Users can then safely read the data synchronized in step three from this visible second storage space.
[0039] Summary of core operating procedures: External network write (interface A) -> Device automatic one-way synchronization -> Internal network read (interface B) Precautions for use Interface Dedicatedness: The purpose of each interface must be strictly distinguished. The first host interface (external network interface) is only used to connect to external network computers and write data; the second host interface (internal network interface) is only used to connect to internal network computers and read data. Interfaces may be distinguished by physical shape or color, and care must be taken to identify them during use.
[0040] One-way guarantee: The entire data synchronization process is forced to proceed in one direction by hardware. Users cannot interfere with or reverse this direction, thus fundamentally preventing internal network data from being leaked to the external network through this device.
[0041] Spatial isolation: In any mode, a computer can only see and access its corresponding storage space (external network computers see area A, internal network computers see area B), and cannot perceive or access another storage space, thus achieving effective logical isolation.
[0042] Optional authentication: If the device includes an authentication module, after connecting the device to a computer on the intranet, a specific authentication process (such as a password, key, etc.) may be required before the second storage space can be made visible and readable.
[0043] Example 1: Portable Dual-Interface Secure USB Flash Drive Based on FPGA and Single NAND Flash This embodiment describes a portable secure storage device, resembling a dual-interface USB flash drive or portable solid-state drive. The device's casing has a first host interface (external network interface) and a second host interface (internal network interface) at both ends, both being USB Type-A or Type-C interfaces, but distinguished by different colors (e.g., blue for the external network interface, red for the internal network interface) or physical shapes to prevent user mis-plugging. The core control logic unit of the device is implemented by a Field-Programmable Gate Array (FPGA). This FPGA integrates two independent USB controller protocol stacks, a Flash Controller (FTL), and the core control logic. The storage section consists of a single NAND Flash physical storage chip, which is divided into two logically independent partitions by the control logic unit: a first storage space (Area A) and a second storage space (Area B). A unidirectional data transmission module is also integrated within the FPGA; it is a hardware-defined path (e.g., a unidirectional bus or FIFO) that allows only unidirectional data transfer. The workflow is as follows: When a user plugs the external network interface into an external network computer, the FPGA detects the activation of the external network interface and enters "external network mode," exposing only area A as a regular USB flash drive to the computer. When the user writes data to area A, the FPGA simultaneously controls the data writing to the physical address of area A and synchronizes the data block to the physical address of area B through an internal unidirectional data transmission module. This hardware path ensures that data can only flow from area A to area B. After completion, the user unplugs the device and then plugs the internal network interface into the internal network computer. The FPGA detects the activation of the internal network interface and switches to "internal network mode," exposing only area B to the internal network computer for reading. The internal network computer cannot write to area B and absolutely cannot access area A, thus achieving secure and convenient data transfer.
[0044] Example 2: Enhanced security portable hard drive using independent storage chips and optically isolated components. This embodiment, based on Embodiment 1, provides a higher level of physical isolation security, suitable for scenarios with extremely high security requirements. The main difference lies in the implementation of the storage medium and the unidirectional transmission module. First, the first and second storage spaces are no longer logical partitions on the same NAND Flash chip, but rather two physically independent NAND Flash chips. One chip is dedicated to area A (external network data writing area), and the other to area B (internal network data reading area), achieving physical isolation of the storage medium. Second, the unidirectional data transmission module no longer relies on the internal logic path of the FPGA, but is implemented using external hardware circuitry composed of a high-speed optocoupler array. Specifically, when data is written to the chip in area A through the external network interface, the control logic unit (which can still be implemented by an FPGA or ASIC) reads this data and drives the light-emitting end (LED) of the optocoupler array to generate a light signal. This light signal passes through a transparent insulating layer, is received by the phototransistor receiver on the other side, converted back into an electrical signal, and then written to the chip in area B by the control logic. Because of the physical properties of light, which dictate that it can only propagate in one direction, any action that prevents the reverse transmission of electrical signals from the B-region chip will not be able to drive the light-emitting end to generate light signals. This completely eliminates the possibility of any electrical signal backflow at the physical device level, achieving perfect electrical isolation and absolute unidirectional transmission. This design provides stronger security than logic isolation.
[0045] Example 3: Dual-interface internal solid-state drive (SSD) suitable for fixed workstations This embodiment applies the technical solution of the present invention to a computer-embedded storage device, which is a solid-state drive (SSD) with dual host interfaces, suitable for fixed workstations that need to frequently exchange data between internal and external networks. Instead of using a portable USB interface, the device designs the first and second host interfaces as two physically independent SATA or NVMe interfaces. One SATA / NVMe interface (e.g., labeled as the external network interface) is led to the outside via a special expansion cable or bracket in the chassis for connecting to a host or port in the external network environment; the other SATA / NVMe interface (internal network interface) is directly connected to the workstation motherboard, which is located in the internal network environment. The internal control logic unit, storage space (A and B areas can be independent partitions or independent chips), and unidirectional data transmission module (FPGA logic or optocouplers, etc.) are all integrated on the hard drive's PCB board. The working mode switching logic is the same: when connected to an external computer via an external cable, the control logic unit only exposes area A to the external computer for data writing and automatically synchronizes the data to area B in real time via the unidirectional transmission module. When the workstation starts up (i.e., connects to the intranet interface), the control logic unit only exposes partition B to the intranet system. Users can directly read data from partition B of the hard drive without using external portable devices. This approach integrates secure data transfer functionality into the computer's internal storage, simplifying the deployment of fixed workstations, providing a seamless and efficient data exchange experience, while maintaining hardware-level one-way security.
[0046] Example 4: Portable dual-interface security USB flash drive with hardware authentication function This embodiment discloses a portable secure storage device with enhanced security authentication function. Its appearance design is similar to that of an ordinary USB flash drive, but it integrates a hardware authentication mechanism to further prevent unauthorized access.
[0047] The device also includes a first host interface (external network interface) 101-1, a second host interface (internal network interface) 101-2, a control logic unit 102, a first storage space (area A) 103, a second storage space (area B) 104, and a one-way data transmission module 105. In addition, this embodiment adds a hardware authentication module 107, which is tightly integrated with the control logic unit 102.
[0048] The first host interface 101-1 and the second host interface 101-2 both use USB Type-C interfaces, but they are physically independent and located at opposite ends of the device. The labels next to the interfaces not only use color (blue for external network, red for internal network) but also have raised "IN" and "OUT" symbols to help users distinguish them by touch in dark environments.
[0049] Control logic unit 102: In this embodiment, it is implemented using an application-specific integrated circuit (ASIC) designed for secure storage. Its logic is embedded in silicon circuits, which has higher anti-tampering capabilities and operating efficiency.
[0050] Storage spaces 103 and 104: Area A and Area B are two physically independent eMMC storage chips, which are soldered to different areas of the circuit board, achieving physical isolation of the storage media.
[0051] Unidirectional data transmission module 105: This module is implemented by both the hardware logic integrated within the ASIC and an external high-speed magnetic isolation chip. Data is transmitted via magnetic field coupling, and its unidirectional nature is guaranteed by the physical structure of the chip.
[0052] Hardware authentication module 107: The core enhancement of this embodiment. This module contains a secure encryption chip (such as a chip compliant with national cryptographic standards) with pre-installed key pairs for asymmetric encryption algorithms. The module is directly connected to the control circuit of the second host interface (internal network interface).
[0053] The workflow of this device adds an authentication step to the existing implementation example: When the device is connected via the external network interface (101-1), its behavior is exactly the same as in Example 1: it is only visible in area A, and the written data is unidirectionally synchronized to area B in real time.
[0054] When the device connects to an intranet computer via the intranet interface (101-2), the control logic unit 102 does not immediately expose area B. Instead, it initiates a challenge-response authentication process to the computer through the authentication module 107. The intranet computer needs to run dedicated client software, which signs the challenge information using an authorization certificate stored locally and returns it. Only after the authentication module 107 verifies the signature is valid will the control logic unit 102 grant read access to area B, making it visible to the operating system. If authentication fails (e.g., connection to an unauthorized computer), area B will remain hidden. This entire process is completed at the hardware level, independent of the operating system's security status, greatly enhancing the security of intranet data reading and preventing unauthorized reading of intranet data after device loss or theft.
[0055] Example 5: A dual-interface secure storage device in the form of a large-capacity portable hard drive This embodiment discloses a high-capacity, high-performance dual-interface secure portable hard drive, designed to meet business scenarios that require the transfer of large datasets (such as design drawings, database backups, video materials, etc.).
[0056] This device uses a portable solid-state drive (PSSD) form factor, with a robust casing and compact internal structure. Its main components include: First host interface 101-1 and second host interface 101-2: To meet the needs of high-speed data transmission, both interfaces adopt USB 3.2 Gen 2x2 Type-C interfaces, with a theoretical bandwidth of up to 20Gbps. The two interfaces are located on the two long sides of the hard drive casing, and have a clear anti-misinsertion design.
[0057] Control logic unit 102: Implemented using a high-performance field-programmable gate array (FPGA). This FPGA is responsible not only for interface protocol conversion and memory control, but also has a built-in data buffer and a high-efficiency DMA controller to optimize the transmission efficiency of large data blocks.
[0058] Storage spaces 103 and 104: Area A and Area B consist of two independent NVMe solid-state drive (SSD) chips, each with its own PCIe channel connected to the FPGA. This architecture provides extremely high storage bandwidth, ensuring high-speed writing to Area A over the external network while simultaneously enabling high-speed real-time synchronization to Area B via a unidirectional transmission module, thus avoiding becoming a performance bottleneck.
[0059] Unidirectional data transmission module 105: In this embodiment, a multi-channel fiber optic transmission scheme is adopted to achieve reliable electrical isolation at high speeds. The FPGA converts the data to be transmitted into electrical signals in parallel, drives a miniature laser array, and the electrical signals are converted into multiple optical signals. The optical signals are transmitted to the receiving end through a short-distance fiber optic cable, received by a photodetector array and restored to electrical signals, and then transmitted to the FPGA logic responsible for area B. The circuit structure of the fiber optic transceiver module (i.e., only a transmitter is configured at one end and only a receiver is configured at the other end) fundamentally ensures the unidirectionality of the data, and the fiber optic cable is completely insulated, achieving the highest level of electrical isolation.
[0060] The device's workflow is consistent with basic methods, but its advantage lies in its superior performance when handling large files. When a user copies a large file of tens of gigabytes to the visible A zone on an external network computer, they will experience speeds approaching those of directly writing to a regular high-speed external hard drive. During the copying process, the FPGA-controlled unidirectional fiber optic transmission module synchronously writes the data to the B zone at near-line speed. When the user switches the device to the internal network interface, the large file can be read completely from the B zone immediately, without a long wait for data copying, significantly improving the efficiency of large data transfer, especially suitable for professional fields such as data centers and media production.
[0061] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.
Claims
1. A storage device for secure data transmission between physically isolated networks, characterized in that, include: A primary storage space and a secondary storage space; A first host interface for connecting to a first network and a second host interface for connecting to a second network, wherein the first host interface and the second host interface are physically independent of each other; A control logic unit; as well as A hardware-implemented unidirectional data transmission module; The control logic unit is configured as follows: When the storage device is connected to a computer in the first network through the first host interface, the first storage space is made visible only to that computer; When the first storage space receives write data from the computer, it instructs the one-way data transmission module to synchronize the write data to the second storage space in real time; When the storage device is connected to a computer in the second network via the second host interface, the second storage space is made visible only to that computer; The unidirectional data transmission module ensures at the hardware level that data can only be transmitted from the first storage space to the second storage space, and prevents any data backflow from the second storage space to the first storage space.
2. The storage device according to claim 1, characterized in that, The first storage space and the second storage space are two independent partitions on the same physical storage medium, or two independent physical storage media.
3. The storage device according to claim 1, characterized in that, The unidirectional data transmission module is based on an optical coupler or a high-speed data isolation chip, and completes unidirectional data transmission through optical signals or electromagnetic isolation.
4. The storage device according to claim 1, characterized in that, The control logic unit is a field-programmable gate array (FPGA) or an application-specific integrated circuit (ASIC).
5. The storage device according to claim 1, characterized in that, The storage device is a portable storage device, and the first host interface and the second host interface are located on different sides or different ends of the device casing.
6. The storage device according to claim 1, characterized in that, The storage device is an internal storage device, and the first host interface and the second host interface are two independent SATA interfaces or NVMe interfaces.
7. The storage device according to claim 1, characterized in that, The first host interface is a USB interface, and the second host interface is a USB interface or other types of data interface.
8. The storage device according to claim 1, characterized in that, The storage device also includes an authentication module, and the second storage space is only visible after a computer connected to the second network has been authenticated by the authentication module.
9. The storage device according to claim 1, characterized in that, The first host interface and the second host interface use different physical forms or different colors to distinguish them for users.
10. A method for secure data transmission between physically isolated networks, characterized in that, Includes the following steps: A storage device is provided that includes a first storage space, a second storage space, a first host interface, a second host interface, and a hardware-implemented unidirectional data transmission module; The storage device is connected to a computer in a first network via a first host interface, and the first storage space is exposed only to that computer; When the first storage space receives write data, the data is automatically synchronized unidirectionally from the first storage space to the second storage space through the unidirectional data transmission module. The storage device is connected to a computer in a second network via a second host interface, and the second storage space is exposed only to that computer for reading the synchronized data; In this process, the data synchronization process is forced to be unidirectional at the hardware level to prevent any data from flowing back from the second storage space to the first storage space.