Process for ensuring high availability and security of data exchanges between two networks of different criticality

The method employs a pair of counter servers connected via fiber optics to a data diode, configuring secure communication channels and firewall functions to address vulnerabilities in existing solutions, achieving high availability and security for data exchanges between networks of different criticality.

FR3157598A1Pending Publication Date: 2025-06-27LORIDON GILLES +1
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
FR2023015120
Authority / Receiving Office
FR · FR
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-12-22
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

Existing solutions for ensuring high availability and security of data exchanges between networks of different criticality are vulnerable to hacker attacks, complex to implement, and do not provide sufficient security to protect classified information or critical industrial networks.

Method used

A method utilizing a pair of upstream counter servers and a pair of downstream counter servers, connected via fiber optic connections to a data diode, which configures virtual and physical IP addresses, communication channels, and firewall functions to ensure secure and uninterrupted data transmission.

Benefits of technology

The solution achieves high availability and security by blocking unauthorized communications, enabling real-time data flow, and ensuring continuous data transmission even if a single element malfunctions, with automatic restart capabilities and robust cybersecurity measures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

The present invention describes a method for ensuring high availability and security of data exchanges between two networks of different criticality, respectively hosting a SOURCE (100) and a DESTINATION (200), each associated with an IP address and a TCP or UDP port. The method uses a pair of upstream counter servers (130, 140) and a pair of downstream counter servers (210, 220), connected by optical fiber connections to a data diode (150, 160). It comprises the following steps: Individual initialization: Defining the virtual and physical IP addresses of the counter interfaces connected to the upstream and downstream networks, as well as the profiles of the counter users.Individual configuration: Set up a communication channel by defining a unique identifier, the type of data or protocol used, the IP address and TCP or UDP port of the SOURCE and DESTINATION, any keys or accounts and passwords required for identifying the counters, as well as the paths of the directories hosting the data on the SOURCE and DESTINATION.
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: Method for ensuring high availability and security of data exchanges between two networks of different criticality Field of invention

[0001] The present invention relates to the field of cybersecurity of unidirectional communications in the context of communications between two networks of different levels of confidentiality or criticality and more precisely to the hardware and functional architectures of hybrid information systems.

[0002] In many contexts, related to security or industrial, several IT environments coexist with different levels of confidentiality or criticality. In government or private domains but dealing with classified information, it is common to have the need to import into a network dealing with classified data data coming from a network of a lower classification level. In the industrial domain, it is very often necessary to export data from the industrial network, critical in terms of production or the safety of people and / or the environment, to the company's office network.

[0003] In such hybrid environments, the problem of enabling users of the more confidential or less critical network to securely access data on the less confidential or more critical network is to protect the critical or confidential environment from attacks exploiting vulnerabilities and connectivity of the less sensitive computing.

[0004] To achieve this, network partitioning is generally sought to limit risks. Exchanges between networks are carried out, for example, using more or less secure protocols such as FTP, SFTP or FTPS. The software enabling these information transfers is vulnerable to remote code execution (RCE) cyberattacks, as well as configuration changes that circumvent access controls.

[0005] Generally, RCE attacks take place in three phases:

[0006] a) Cyber ​​hackers identify a vulnerability in a network's hardware or software.

[0007] b) They exploit this vulnerability to remotely infect a terminal with malicious code or software.

[0008] c) Once cyber hackers gain access to the network, they compromise user data or exploit the network to commit their crimes.

[0009] Other cyberattacks use the SQLi flaw, short for "SQL Injection." This security flaw affects an application interacting with a database. It allows a piece of the query to be injected into the current SQL query that is not provided by the system and could compromise its security. State of the art

[0010] To reduce the risk of compromise, it is known to organize access by the least sensitive environment to sensitive data through a demilitarized zone, with data replication. However, if the protocol used to "replicate" sensitive data to the server on the other side of the demilitarized zone (DMZ) has vulnerabilities, it will be possible to take control of the sensitive network. Furthermore, this solution requires real-time and continuous monitoring of the demilitarized zone to detect possible intrusions. A demilitarized zone (DMZ) is a subnetwork separated from the local network and isolated from it and from the Internet (or another network) by a firewall. This subnet contains machines that are likely to be accessed from the Internet, and which do not need to access the local network.

[0011] A derived solution, much more secure, consists of protecting the sensitive environment using a diode ("datadiode"). However, existing solutions tend to lose data and / or deliver corrupted data. Indeed, conventional solutions based on diodes do not support the availability problems of the destination network or of the systems receiving the data downstream of the diode. The window downstream of the diode can be compared to a bathtub filling with a constant flow but emptying with a flow of the same order but sometimes being interrupted completely or partially without the ability to interrupt the flow filling it. It therefore frequently happens that the bathtub overflows. For the window downstream of the diode, this results in data being partially or completely overwritten before being sent. This is a problem inherent to diodes.

[0012] Known in the prior art is patent application WO2019055948A1 presenting techniques that can be applied to a network orchestration and security platform for a network such as an industrial control system (ICS) network. These techniques include, for example, methods for characterizing and classifying networked industrial devices based on conversation patterns, generating security zones for ICS networked assets based on characteristics and conversation patterns, for identifying and registering ICS networked devices in a non-intrusive manner, for creating secure passages between security zones for ICS networked devices, without impacting flexible terminal devices and associated systems.

[0013] It describes a system comprising: - a network of industrial control systems (ICS); - a first security zone coupled with the ICS network; - a second security zone coupled with the ICS network; - a network orchestration and security platform coupled with the network ICS to generate a fingerprint to ensure that a source in the first security zone is authorized to send to a destination (200) in the second security zone;

[0014] The network orchestration and security platform initiates an operational connection from the source to the destination (200), the source then sends a clear message to a security zone exit port of the first security zone. The security zone exit port sends the message via a secure conduit to a security zone entry port of the second security zone and in return the security zone entry port sends the clear message to the destination (200). When the operational connection is reactivated, the destination (200) validates the identification fingerprint. Disadvantages of the prior art

[0015] Known software solutions remain highly vulnerable to hacker attacks. These software solutions in the field of management information technology, which ensure similar cyber security objectives, are also very complex to implement and do not provide a sufficient level of security to protect classified information or critical industrial networks.

[0016] As for current hardware solutions based on diodes (150, 160) and counters, they are complex to maintain, require manual interventions to restart the transfer of corrupted data or to reset them after faults such as the unavailability of one of the components of their solution, either one of the two counters or the diode, or the unavailability of the network or the systems receiving the data transmitted downstream of the diode. Solution provided by the invention

[0017] In order to overcome these drawbacks, the invention relates, in its most general sense, to computer equipment having the following characteristics.

[0018] The invention relates, in its most general sense, to a method for ensuring high availability and security of data exchanges between two networks of different criticality having the characteristics set out in claim 1.

[0019] This method implements a pair of upstream counter servers and a pair of downstream counter servers, each of said upstream counters connected to one of said downstream counters only via fiber optic connections to a data diode, in that it comprises the following steps: a. An individual initialization step for said upstream counters and said downstream counters consisting of defining the virtual IP address(es) and their types, and the physical IP addresses of the counter interfaces connected to the upstream and downstream networks, as well as the different user profiles b. a step of individual configuration of said upstream counters (130,140) and said downstream counters consisting of configuring a communication channel by defining a unique identifier, the type of data or protocol used by this channel, the IP address and the TCP or UDP port of the data SOURCE, any keys or account & password necessary for the identification of the upstream counters on the SOURCE and the possible path of the directories hosting the data on the SOURCE, then by defining on the downstream counters a communication channel with an identifier identical to that used for the channel on the upstream counters, the type of data or protocol used by this channel, the IP address and the TCP or UDP port of the data DESTINATION, any keys or account and password necessary for the identification of the downstream counters on the DESTINATION, and the possible path of the directories hosting the data on the DESTINATION.

[0020] Optionally, the method comprises an additional step of configuring said upstream counters and said downstream counters consisting of configuring firewall functions of said upstream and downstream counters to authorize only certain nodes of the SOURCE and DESTINATION networks to have access to said counters.

[0021] Advantageously, said additional step controls the configuration of a mechanism for automatically saving the configuration of the counters either locally or remotely.

[0022] According to a variant, said security function is the sending of a syslog type message and logging of said message in an event log service of the computer systems of said SOURCE and DESTINATION networks.

[0023] According to another variant, said security function is the cutting of communication and the blocking of communications by the counters coming from the IP address / TCP PORT / MAC address except the authorized one

[0024] Preferably, said high availability of the upstream and downstream counter servers is based on virtual IP addresses, buffer databases distributed respectively on the pair of downstream and upstream counters, on the sending of a copy of the data by the Master upstream counter to the Slave upstream counter and by the Master downstream counter to the Slave downstream counter, mechanisms for monitoring the availability of each member counter of a pair by the other member of its pair triggering a switchover Master / Slave in certain cases, mechanisms for monitoring the respective availability of the SOURCE and DESTINATION of each data channel, and a mechanism for automatic resumption of communications in the event of total unavailability of the upstream and / or downstream networks, or of the SOURCE and / or DESTINATION of the data.

[0025] According to a variant, said high security of the most critical network is guaranteed by the property of the data diode which only allows information to be transmitted between the upstream network and the downstream network, and that this property is achieved by the physical device of the data diode not comprising any configuration, software or logic.

[0026] According to another variant, said high availability of the counter servers in terms of resistance to denials of service is achieved, among other things, by hardening the operating system of said counters to offer a very restricted attack surface, a strict policy of access control to the counter without a super user or administrator account available, and an integrated firewall.

[0027] Advantageously, said high availability of data transmission is ensured by data integrity control mechanisms at the level of the packets sent by multiplexing to the data diodes and at the level of the data itself.

[0028] The invention also relates to a secure computer system connected to a public data network to ensure high availability and security of data exchanges between two networks of different criticality respectively hosting a SOURCE and a DESTINATION of data, characterized in that it comprises a pair of upstream counter servers and a pair of downstream counter servers, each of said upstream counters connected to one of said downstream counters only by means of fiber optic connections to a data diode.

[0029] Each of said upstream counters and said downstream counters being configured to: a. define the virtual IP address(es) and their types, and the physical IP addresses of the counter interfaces connected to the upstream and downstream networks, as well as the different user profiles, b. configure a communication channel by defining a unique identifier, the type of data or protocol used by this channel, the IP address and TCP or UDP port of the data SOURCE, any keys or account & password required for identifying the upstream counters on the SOURCE, and the possible path of the directories hosting the data on the SOURCE, then by defining on the downstream counters a communication channel with an identifier identical to that used for the channel on the upstream counters, the type of data or protocol used by this channel, the IP address and TCP or UDP port of the data DESTINATION, any keys or account & password required for identification downstream counters on the Destination, and the possible path of the directory hosting the data on the DESTINATION.

[0030] Advantageously, the system comprises two sub-assemblies in parallel, each composed - an upstream counter associating an upstream channel number, a type of supported exchange protocol and a source identified by an IP address and a TCP / UDP port and comprising a buffer memory synchronized by a dedicated and direct network link between said two upstream counters - a diode (150, 160), - and a downstream counter, associating a downstream channel number, a type of supported exchange protocol and a destination identified by an IP address and a TCP / UDP port, and comprising a buffer memory synchronized by a dedicated and direct network link between said two downstream counters One of the said upstream counters is controlled, when the system starts, in “Master” mode to receive only the data transmitted by a connected source, - Then, episodically, • the Master counter is configured to verify that it is properly connected to the data source and • in case of loss of this connection, to query the other counter controlled in Slave mode to check if it has access to the source • and if yes, the state of the Master counter is changed to Slave and the state of the Slave counter is changed to Master thus ensuring the connection to the source - the Master counter and the Slave counter applying a marking process to each data packet received from said source consisting of adding a digital sequence comprising the number of the channel corresponding to their source and a sequential identification number - Each labeled packet being transmitted in parallel by the upstream Master counter and the upstream Slave counter on the corresponding diode Each of said downstream counters receives said unit data packets, verifies their integrity at the packet level and their unit sequence number, then transmits them to the DESTINATION (200) with the protocol associated with the channel in its configuration.

[0031] According to a variant, each of said labeled packets is transmitted in parallel by the Master upstream counter and the Slave upstream counter on the corresponding diode, and returned until the TX return from the diode is received before sending the next packet.

[0032] Detailed description of a non-limiting example of embodiment of the invention

[0033] The present invention will be better understood on reading the following description, concerning a non-limiting example of embodiment, illustrated by the appended figures, where:

[0034] [Fig-1] [Fig.l] represents a schematic view of the hardware architecture of a system according to the invention

[0035] [Fig.2] [Fig.2] represents a schematic view of the functional architecture of a system according to the invention. General principle of the invention

[0036] The equipment that is the subject of the present invention aims to ensure a very high level of cybersecurity, availability and integrity, for the most sensitive unidirectional connections between two networks with different levels of confidentiality or criticality. The objectives are fourfold: • Block all communications from the most confidential network to the least confidential network (to prevent leaks of confidential data) or from the least critical network to the most critical network (to prevent industrial incidents) • Enable real-time, high-speed data flow from the least confidential network to the most confidential network or from the most critical network to the least critical network. • Continue to transmit data without interruption or loss when a single element of the solution malfunctions. • Allow automatic restart of data transmission after unavailability of the source or destination (200) (200) without loss of data for a specified period.

[0037] The invention aims to provide an excellent level of cyber security and a high level of availability thanks to security implemented by a “hardware” diode without configuration or logic and by counter software which ensures very high level high availability without manual intervention.

[0038] The issue is critical because these interconnections are the main point of entry into the network for hackers.

[0039] The proposed solution consists of two parallel systems, each composed of upstream gate (130, 140) - diode (150, 160) - downstream gate (210, 220).

[0040] The upstream (130, 140) and downstream (210, 220) counters must be configured by a dedicated management port not connected to the data network. The upstream configuration is the association of an upstream channel number with, on the one hand, an exchange type among the supported types: FTP, SFTP, FTPS, SMTP, UDP, TCP streaming, Industrial protocols, and on the other hand a source (100) identified by an IP address and a TCP or UDP port. Optionally, application users on the source (100) and their access must also be configured, such as an FTP user account ID and password on the FTP source (100).

[0041] The downstream configuration is the association of a downstream channel number with on the one hand an exchange type among the supported types: FTP, SFTP, FTPS, SMTP, UDP, TCP streaming, Industrial protocols, and on the other hand a destination (200) identified by an IP address and a TCP or UDP port. Optionally, application users on the destination (200) and their access must also be configured, such as the identifier of an FTP user account and its password on the destination (200) of the FTP type.

[0042] One of the two upstream counters (130, 140) has the role of Master, noted 20 in [Fig.2], and the other that of Slave, noted 30 in [Fig.2]. Only the Master receives the data to be transmitted by the source (100). The Master counter periodically checks that it is properly connected to the source (100) of the data. If it loses this connection, it interrogates the Slave counter to check if it has access to the source (100). If so, the Master counter becomes Slave and the Slave counter becomes Master and thus ensures the connection to the source (100).

[0043] The data received by the source (100) on the Master are then tagged with a channel number that corresponds to their source (100), identified in the configuration of the counter by IP address and port, and a sequential identification number. They are transmitted to the upstream slave counter by a direct and dedicated connection (108) on [Fig.l].

[0044] The upstream counters (130, 140) support the storage of the data to be transmitted in a rotating FIFO buffer, First In First Out, noted 22 in [Fig.2]. This buffer is a database distributed between the two upstream counters.

[0045] The data stored in the FIFO buffer of the two downstream counters (210, 220) are synchronized by a dedicated and direct network link between the two counters, noted (107) in [Fig.l],

[0046] On each upstream counter, the tagged data are transmitted, in the order in which they arrive in their buffer, to a sending service on the unidirectional diode (150, 160). Depending on their type (file, TCP, UDP), the service uses CRC, Cyclic Redundancy Check and / or MD5 type hashing algorithms to calculate their signature, and sends, by multiplexing in elastic size internal multichannels, the data cut into unit packets of fixed size. A variable number of internal channels is associated with each type of data and can be configured to optimize sending on the diode depending on the spectrum of data received by type. For example, for a use requiring the sending of many small files, the sending service can use a thousand internal channels dedicated to files and two other internal channels respectively for UDP and TCP.

[0047] The unit packets are only transmitted on the diode if the previous packet has been received by the RX port of the counter connected to the TX port of the incoming connection of the diode. Otherwise, the counter always returns to the diode the current unit packet until the TX return from the diode is correctly received. This makes it possible to stop the transmissions if the diode is not functional but in no way guarantees that the unit packet has been correctly received by the downstream counter (210, 220).

[0048] The previous operation being carried out in parallel on the upstream Master window (20) and on the Slave window (30), each data item is transmitted in parallel on each diode.

[0049] Each downstream counter (210, 220) receives the unit data packets, checks their integrity at the packet level and their unit sequence number, then demultiplexes them by introducing them in the correct order into the downstream internal channels which are the mirror of the upstream internal channels. In the event of an integrity or sequence error, the packet is not transmitted and all other unit packets linked to a single data item, such as a file, will not be transmitted and an error code is sent either by email or by Syslog identifying the original single data item.

[0050] Each downstream counter (210, 220) reassembles the unit packets to reconstitute the initial data sent upstream and verifies their integrity at the level of the reassembled data. In the event of an error, a message is sent by email or by Syslog.

[0051] The downstream slave counter (50) sends the initial data reconstituted and verified to the master downstream counter (40) by a direct and dedicated connection noted 216 in [Fig.l].

[0052] Each downstream counter (210, 220) copies the original data, the integrity of which has been verified, into the distributed buffer database (42, 52) between the two counters. The master downstream counter (40) identifies the IP address and the port of the destination (200) by the channel number tagged with the data. The channel is previously configured downstream in a mirror manner of the upstream configuration. After verifying that the destination (200) is accessible and in operation, the downstream master counter (40) sends the data to the destination (200). Once the data has been sent, if the distributed buffer database (42) has reached a certain size threshold, the oldest data of the same type will be deleted.

[0053] The data stored in the FIFO buffer of the two downstream counters (210, 220) are synchronized by a dedicated and direct network link between the two downstream counters, noted (215) in [Fig.l],

[0054] If the downstream master counter (40) cannot reach the destination (200), it checks that the downstream slave counter (50) has access to it via a dedicated and direct network link between the two downstream counters, noted (215) in [Fig.l]. If so, the downstream master counter (40) becomes slave and the slave one becomes master. If neither the downstream master counter nor the slave one has access to the destination (200), the master one remains master and periodically continues to try to send the data to the destination (200).

[0055] The two downstream counters (210, 220) are connected to the information destination (200) typically via two network switches (230, 240), or two firewalls, themselves connected to the destination (200). Each of the downstream counters (210, 220) is physically and directly connected to the hardware diode (150, 160) by a fiber optic connection with a single strand of optical fiber connected between the output TX port of the diode and the RX of the downstream counter (210, 220). Hardware architecture

[0056] The proposed solution consists of two parallel systems, each consisting of an upstream counter server (130, 140) connected to the data source (100) by the least classified or most critical network and directly and physically connected to the diode

[0057] - a “hardware” diode equipped with an incoming fiber optic port connected to the server upstream counter (130, 140) and an outgoing fiber optic port connected to the downstream counter (210, 220)

[0058] - a downstream counter server (210, 220) connected to the destination (200) of the data by the most classified or least critical network.

[0059] The data source (100) is connected to two network switches / routers or two firewalls by the cables (105) and (106).

[0060] The data destination (200) is connected to two network switches / routers or two firewalls by the cables (213, 214).

[0061] The two upstream counter servers (130, 140) are connected to the network equipment connected to the source (100) of information by the cables (101) and (102) and (103) and (104) in [Fig.l] respectively, typically via two network switches (110, 120), or two firewalls, themselves connected to the source (100). Each of the upstream counter servers (130, 140) is physically and directly connected to the hardware diode (150, 160) by its input port with a two-strand RX / TX fiber optic connection.

[0062] The two downstream counter servers (210, 220) are connected to the network equipment connected to the information destination (200) by the cables (209) and (210) and (211) and (212) in [Fig.l] respectively, typically via two network switches (230, 240), or two firewalls, themselves connected to the destination (200). Each of the downstream counter servers is physically and directly connected to the hardware diode (150, 160) by its output port with a single-strand fiber optic connection TX on the diode side and RX on the downstream counter server side (210, 220).

[0063] Each element of each pair of counter servers is physically and directly interconnected by cables (107) and (108), (215) and (216) respectively, to synchronize the distributed buffer database upstream and downstream, and to provide Master / Slave switchover functions. Functional architecture

[0064] [Fig.2] illustrates the functional architecture of the system according to the invention. It comprises an upstream source server (10) and a downstream destination server (90).

[0065] The upstream destination server (10) comprises a data transmission module (11), which sends the data to the master upstream counter server (20).

[0066] The upstream counter servers (20, 30) each comprising a module (25, 35) for receiving data, distributing the received data in preconfigured channels and master / slave management, a module (24), on the master only, for storage on the distributed buffer base (22, 32), a module (26, 36) for sending data from the buffer base to the two modules (27, 37) for transmission to the “hardware” diode (150, 160) on the master and the slave simultaneously.

[0067] The modules (23, 35) ensure the upstream reception of data according to the protocols, the correct reception of data at the application or protocol level, the management of the master / slave switchover and the monitoring of the availability of the upstream network and the SOURCE (10).

[0068] On the master upstream counter (20), the module (25) transmits the application or protocol data, for example as an entire file, to the module (24) which ensures the tagging and distribution of the data in the channel corresponding to the preconfigured information (IP address, port, protocol). The module (24) sends the data from the channels to the upstream distributed buffer base, modules (22, 32).

[0069] The modules (22,32) manage the synchronization of data between the buffer bases on the two upstream counters (20,30) using a physical, direct and dedicated network connection. On the master upstream counter (20), the module (22) sends the data, arriving first channel by channel, to the module (26).

[0070] The module (26) simultaneously sends the data to the modules (27, 37) respectively on the master (20) and slave (30) upstream counter thanks to a physical, direct and dedicated network connection. The modules (27, 37) ensure the division of the data into unit packets, the addition of additional information ensuring their integrity and their unique sequence number, their multiplexing on internal channels of elastic size but of a number fixed beforehand as mentioned previously. The modules (27, 37) also ensure the sending of the packets on the “hardware” diodes (150, 160)

[0071] The downstream counter servers (40, 50) each comprising a module (47, 57) for receiving data from the “hardware” diode (150, 160), ensuring the reconstitution of the initial data from the unit packets received from the diode while verifying their integrity, and also sending a copy of the data from the master downstream counter (40) to the slave (50), from a module (44) on the master of distribution of the received data in preconfigured channels and writing on the distributed buffer base, a module (42, 52) for managing the distributed buffer base and its synchronization, storage on the distributed buffer base (22, 32), a module (45, 55) for sending data from the buffer base to the data reception module (91), hosted by the destination server (90), according to the protocol corresponding to the preconfigured channel.

[0072] As previously explained, in the event of a failure, the “master” and “slave” roles of the two downstream counter servers (40, 50) are automatically reversed by the module (45, 45).

[0073] Any detection by a module of an integrity error or any other availability errors or interruptions will result in the sending of a syslog type message and the recording of said message in an event log service.

[0074] Detailed description of an example of implementation of the method according to the invention

[0075] The very high level High Availability function will be achieved by the physical and logical redundancy of the counters, network links and diodes (150, 160) in active-active mode. In this example, consider that the source (100) sends a file to the upstream counter with FTP. A malfunction affects the master upstream counter which becomes unavailable. The virtual IP mechanism between the master counter and the slave counter allows the slave to appropriate 1 physical network TP linked to 1 virtual TP and it becomes master. There is no interruption of service because the TCP / IP layer will absorb the change of physical IP for 1 virtual TP and the FTP protocol will restart the transmission of the current file according to the sending script thanks to the module (11) if necessary.

[0076] The master upstream counter constantly tests its connectivity to the source (100), if it can no longer reach the source (100) in the event of a network malfunction with the source (100), it checks that the slave upstream counter can access the source (100), and if so, it switches the slave to master and it to slave. There is no interruption of service because the TCP / IP layer will absorb the change of physical IP for the virtual IP and the FTP protocol will restart the transmission of the current file according to the sending script.

[0077] If the source (100) is unavailable or the network is completely unavailable, the transmission of files by FTP will resume automatically without manual intervention as soon as the source (100) reconnects to the FTP server hosted by the master upstream counter according to the sending script using the module (11).

[0078] If during the master / slave switchover occurs while some files, which are stored in the distributed buffer database, are waiting for transmission to the diode, as the slave become master has a copy of its files on its own distributed buffer database, the transmission of these pending files will resume automatically without interruption. If a file was being transmitted to the diode by the master, as the master has also sent a copy of this file to the slave for transmission to its diode, the slave will send a complete file to the diode and its downstream counter (210, 220). The slave downstream counter (220) will store this file in the distributed buffer database and therefore the master downstream counter (210) will ensure the transmission of this file without interruption and without manual intervention.

[0079] If the diode (150) connected to the master upstream counter (130) is unavailable, it does not work or the optical fiber is disconnected, the master downstream counter (210) no longer receives the files. But since the master upstream counter (130) has sent a copy of each file to the slave upstream counter (140), they will be sent to the slave downstream counter (220) which receives all the files and stores them in the distributed buffer database. The master downstream counter (210) therefore sends them to the destination (200) from the distributed database without interruption and without manual intervention.

[0080] If the master downstream window (210) is malfunctioning, it switches the slave downstream window (220) to master and initiates its restart. If a file was being transmitted by the diode from the master upstream window (130) to the master downstream window (210), a copy of the file has been sent by the slave upstream window (130) to the slave downstream window (220). The slave downstream window (220), after being switched to master, will transmit this file from the distributed buffer database to the destination (200) without interruption and without manual intervention.

[0081] If the downstream network is unavailable between the master downstream (210) and the destination (200), the master downstream (210) checks whether the slave downstream (220) has access to the FTP server of the destination (200), if so, the slave switches to master and the master to slave. If a file was being transmitted by FTP between the master downstream (210) and the FTP server of the destination (200), the FTP session will be interrupted. Then another FTP session between the new master downstream (220) and the FTP server of the destination (200) will be established and the file being transmitted will be transmitted by the new master downstream (220) without file loss and without manual intervention.

[0082] If the downstream network is completely unavailable between the downstream counters and the destination (200), or if the destination (200) is unavailable, the master downstream counter (210) checks if the slave downstream counter (220) has access to the FTP server of the destination (200), as the slave downstream counter (220) does not have access to the destination FTP server (200), the master downstream counter (210) remains the master. If a file is being transmitted by FTP, the FTP session will be interrupted. The master downstream counter (220) will continually try to establish a new FTP session with the destination (200) until the moment when the The destination FTP server (200) will be available again. There will therefore be no file loss and no manual intervention.

[0083] The ATMs themselves are protected against denial of service attacks, DoS, the only type of remote attack that can affect data transmission. Resistance to DoS is achieved by reducing the attack surface offered by possible vulnerabilities in the ATM software and operating systems by hardening the ATMs through recompilation of their operating system by selecting only the strictly necessary modules, services and drivers, by the absence of a super user or administrator account usable on the ATMs, and by a firewall on each ATM that blocks all communications except those authorized from network nodes defined by their IP address, MAC and TCP or UDP port, and by blocking ICMP (ping) communications.

Claims

1. Claims Method for ensuring high availability and security of data exchanges between two networks of different criticality respectively hosting a SOURCE (100) associated with an IP address and a TCP or UDP port, and a DESTINATION (200) associated with an IP address and a TCP or UDP data port, implementing a pair of upstream counter servers (130, 140) and a pair of downstream counter servers (210, 220), each of said upstream counters (130, 140) connected to one of said downstream counters (210, 220) only by means of fiber optic connections to a data diode (150, 160), in that it comprises the following steps: a. An individual initialization step of said upstream counters and said downstream counters consisting of defining one or more virtual IP addresses and their types, and physical IP addresses of the counter interfaces connected to upstream and downstream networks, as well as different user profiles of said upstream counters and said downstream counters b. a step of individual configuration of said upstream counters and said downstream counters consisting of configuring a communication channel using a data type or a protocol by defining a unique identifier, said data type or protocol used by said channel, said IP address and said TCP or UDP port of said data SOURCE (100), possible keys or account and password necessary for the identification of the upstream counters (130, 140) on the SOURCE (100), and a possible path of the directories hosting the data on the SOURCE (100), then by defining on said downstream counters (210, 220) a communication channel with an identifier identical to that used for the channel on the upstream counters (130, 140), the data type or protocol used by this channel, said IP address and said TCP or UDP port of said data DESTINATION (200),any keys or account & password required for the identification of downstream counters at the Destination (200), and a path, possible directory hosting the data on the DESTINATION (200).

2. Method for ensuring high availability and security of data exchanges between two networks of different criticality respectively hosting a SOURCE (100) and a DESTINATION (200) of data, according to claim 1 characterized in that it comprises an additional step of configuring said upstream counters and said downstream counters consisting of configuring firewall functions of said upstream counters (130, 140) and downstream counters (210, 220) to authorize only certain nodes of the SOURCE (100) and DESTINATION (200) networks to have access to said counters.

3. Method for ensuring high availability and security of data exchanges between two networks of different criticality respectively hosting a SOURCE (100) and a DESTINATION (200) of data, according to the preceding claim characterized in that said additional step controls the configuration of a mechanism for automatic backup of the configuration of the counters either locally or remotely.

4. Method for ensuring high availability and security of data exchanges between two networks of different criticality respectively hosting a SOURCE (100) and a DESTINATION (200) of data, according to claim 1 characterized in that it comprises a security function by sending a syslog type message and logging said message in an event log service of the computer systems of said SOURCE (100) and DESTINATION (200) networks.

5. Method for ensuring high availability and security of data exchanges between two networks of different criticality respectively hosting a SOURCE (100) and a DESTINATION (200) of data, according to claim 1 characterized in that it includes a security function by cutting off communication and blocking communications coming from the IP address / TCP PORT / MAC address except that authorized.

6. Method for ensuring high availability and security of data exchanges between two networks of different criticality respectively hosting a SOURCE (100) and a DESTINATION (200) of data, according to claim 1 characterized in that said high availability of the upstream (130, 140) and downstream (210, 220) counter servers provides virtual IP addresses, buffer databases distributed respectively on the pair of downstream and upstream counters, the sending of a copy of the data by an upstream Master counter to an upstream Slave counter and by a downstream Master counter to a downstream Slave counter, and mechanisms for monitoring the availability of each member counter of a pair by the other member of its pair triggering a Master / Slave switchover in certain cases, mechanisms for monitoring the respective availability of the SOURCE (100) and the DESTINATION (200) of each data channel, and a mechanism for automatic resumption of communications in the event of total unavailability of the upstream and / or downstream networks, or of the SOURCE (100) and / or the DESTINATION (200) of the data.

7. Method for ensuring high availability and security of data exchanges between two networks of different criticality respectively hosting a SOURCE (100) and a DESTINATION (200) of data, according to claim 1 characterized in that said high security of the most critical network is guaranteed by the property of the data diode which only allows information to be transmitted between the upstream network and the downstream network, and that this property is achieved by the physical device of the data diode not comprising any configuration, software or logic.

8. Method for ensuring high availability and security of data exchanges between two networks of different criticality respectively hosting a SOURCE (100) and a DESTINATION (200) of data, according to claim 1 characterized in that said high availability of data transmission is ensured by data integrity control mechanisms at the level of packets sent by multiplexing to the data diodes (150, 160) and at the level of the data itself.

Citation Information

Patent Citations

  • Network asset characterization, classification, grouping and control

    WO2019055948A1

  • Methods and apparatus for providing controlled unidirectional flow of data

    US20150163198A1

  • High assurance segregated gateway interconnecting different domains

    US20170070507A1

  • Method and apparatus for repercussion-free unidirectional transfer of data to a remote application server

    US20200120071A1

  • Uni-directional and bi-directional cross-domain (secure exchange gateway) design

    US20200412722A1