A computer network management unit
The network management unit addresses the inefficiencies in data transfer between networks with differing security and integrity by using a controller to manage network parameter servers and switches, ensuring seamless and secure data transfer.
Patent Information
- Application Number
- GB2024008469
- Authority / Receiving Office
- GB · GB
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-06-13
- Publication Date
- 2026-01-28
AI Technical Summary
Existing methods for transferring data between separate computer networks with differing security and integrity requirements are laborious and inconvenient, often involving physical media like USB sticks, and lack efficient management of network connections.
A network management unit that temporarily connects and separates networks using a controller process to manage network parameter servers, shared memory, and network switches, enabling seamless data transfer while maintaining network integrity and security by dynamically assigning and managing network parameters.
Facilitates efficient, secure, and automated data transfer between separate networks by ensuring parameter consistency and isolation, reducing the risk of data clashes and unauthorized access.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
Introduction The present invention relates to a network management unit, specifically a network management unit for the management of separate computer networks, a combined computer network made from combining separate computer networks and separate computer networks made from separating a combined computer network into separate computer networks. Background An organisation may process data with different levels of security and integrity. Historically this data has been processed on one single large computer network. The differing security and integrity requirements place differing requirements on the design of one single computer network. One method to resolve these conflicting requirements is to create a number of separate networks each designed to address the security and integrity requirements of the data that each separate network processes. This however is inconvenient when data has to be passed from one separate network to the other separate network for processing. When data is processed within more than one separate network this process is historically achieved in a laborious manner such as attaching a USB memory stick to one separate network, storing data from the first separate network onto the USB memory stick, physically removing the USB memory stick from original separate network, attaching the USB memory stick into the second separate network and copying the data from the USB memory stick into the second separate network. This method additionally involves the management of the USB memory stick as this now has data on it which is associated with one of the networks. It is an object of the invention to address one or more of the above mentioned issues. In particular, it is desired to provide a method to temporarily connect separate computer networks together to create a combined network to allow data to flow between network sections and to then allow the combined network to divide and operate as separate computer networks. Summary Of The Invention According to an aspect of the present application, there is a network management unit for managing two or more separate networks to connect the separate networks into a combined network and a combined network into separate networks to allow the temporary transfer of data between the otherwise separate networks compromising any one or more of the following features: a computer hosting network parameter servers providing management of the networks comprising shared memory hosting a data store of parameters providing a means for the network parameter servers to communicate between themselves hosting a controller process configured to enable or disable a network parameter server or servers and also an open or close a network switch or switches network interfaces to allow the network parameter servers to be able to communicate with the separate networks switch interface or interfaces to allow connection to a network switch or network switches user input / output interface to allow configuration of the controlling process By providing the network management unit with two or more network parameter servers and a controller, the separate networks maybe disconnected from one another when the controller commands the network switch to be open to keep data, within one separate network, from passing to the other separate network. When data is required to be transferred from one separate network to the other separate network the separate network can be joined to create a singular combined network when the controller commands the network switch to be closed allowing data to flow between the otherwise separate networks. The computer hosts at least two network parameter servers and there may be two or more network connection interfaces. The shared memory is shared between the network parameter servers. The shared memory allows the network parameter servers to share network parameters as allocated within one separate network, to be prohibited from being allocated within another separate network. When the separate networks are merged by way of the network switch one network parameter server is disabled and management of the combined network is managed with the enabled network parameter server. When the networks are separated by way of the network switch the network parameter servers interrogate each separate network to determine which separate network, devices which have been added to the network whilst the network is combined, are in when separated. The network interface may comprise an Ethernet, USB, Fibre-Optic or other electrical interface. The network interface may comprise a wireless interface such as WiFi. The controller process may be arranged to open or close the network switch and enable or disable network parameter servers. The controller may operate the switch automatically or by being triggered by a user to change the state or by an external trigger. The controller process may be configured to open and close the network switch states and enable or disable network parameter servers according to one or more time parameters. The time parameters may define any one or more of a closing time of the network switch and disable network parameter servers, an opening time of the network switch and enable the network parameter servers or a time duration in which the switch is closed or open and disable or enable the network parameter servers. The time parameters may therefore define a time during which the network is a combined network and able to transfer data between from each otherwise separate network. The time parameter may be set according to another device which requires intermittent connection to the controller process e.g. a time when a data transfer or similar operation is to occur or does occur. The network management unit may comprise an internal network switch or a plurality of network switches. The network management unit may comprise one or a plurality of network management servers. Each network server maybe connected to one or a plurality of network interfaces. The user input / output interface maybe comprise a touch screen and / or a USB interface and / or an HDMI interface and / or Ethernet interface and / or other interface. Brief Description Of The Drawings Embodiments of the invention will now be described, by way of example only, with reference to the accompanying drawings, in which Figure 1 shows a schematic view of two networks separated by a network switch with a computer housing two network parameter server software processes sharing memory, with a store of parameters in a common data base of dynamically assigned parameters such as IP addresses, with the network switch connected between networks in the open state Figure 2 shows a schematic view of two networks separated by a network switch of Fig 1 with the network switch connected between networks in the closed state Figure 3 shows a schematic view of two networks separated by a network switch with one network parameter server software processes providing dynamically assigned parameters such as IP addresses which do not conflict between networks according to another embodiment. Figure 4 shows a schematic view of a four of networks separated by three network switches with four network parameter server software processes sharing a common data base of dynamically assigned parameters such as IP addresses according to another embodiment. Figure 5 shows a schematic view of two networks separated by switches with two network parameter server software processes sharing dynamically assigned parameters such as IP addresses which do not conflict through some communication link such as USB, Ethernet or other data link according to another embodiment. Detailed Description Figure 1 and 2 show a schematic illustration of a network management unit 100 according to an embodiment. The network management unit 100 is used for managing the separate networks 108 such that when the network connection switch 109 is closed to create a combined network the combined network operates seamlessly as a single network allowing data to flow within this combined network. The network management unit 100 may be used for combining networks 108 as part of a computer server system or the like In other embodiments the network management unit 100 may take the form of a consumer unit that can be used to connect separate home networks.. The network management unit 100 generally comprises; a server computer 101, network parameter server software processes 102; shared computer memory 103; a controller process 104; network connection interface 105; a network switch interface 106; a user input / output interface 107. The network connection interfaces 105 are arranged to connect the network management unit 100 to external separate networks. The network connection interfaces 105 provide a means of communication into the network management unit 100. The computer 101 has a number of network management server processes 102 running on it. The network management servers 102 manage the network(s) 108 by providing management tasks on each separate network 108 or combined network 108. Each network parameter server software processes 102 assigns dynamic parameters to the computer devices of each separate network 108. In one embodiment the network parameter server 102 may be a DHCP server and may assign IP addresses to computer devices within a computer network 108. In another embodiment the network parameter server 102 may be a different type of server and may assign other network parameters to computer devices within a computer network 108. The controller process 104 controls the network connection switch 109 which combines and separates the networks 108. In addition the controller process 104 controls the state of the network parameter servers 102. The network connection switch 109 connects the networks 108 in one state to create a single connected network or separates the networks 108 in the other state to create separated networks. When the controller process 104 sets the network switch 109 to open the network segments are separated. When the controller process 104 sets the network switch 109 to closed the network segments are connected to create a single connected network. When the switch is open each network parameter server software process 102 is enabled and manages network parameters of each separate network 108. The network parameter server software processes 102 have access to the shared memory 103. The shared memory 103 is able to be written to and read by each network parameter server software process 102. The shared memory 103 allows each network parameter server software process 102 to share the parameters that have been assigned to computer devices within each separate network with the other network parameter servers 102. By sharing network parameters, computer devices are inhibited from being assigned the same network parameters which would cause a clash between the computer devices when the networks 108 are combined. Shared parameters are inhibited from being assigned by other network parameter servers as a result of being shared within the shared memory 103. Network parameter server software process 102 read the shared memory 103 to ensure that prior to assigning network parameters to computer devices within the network 108, the parameters are not already assigned by other network parameter server software process 102 to computer devices within another separate network 108. When network parameter servers 102 detect that a computer device has left the network being managed by the network parameter server 102 the parameters are removed from the shared memory 103 and made available for allocation within any network 108. When the controller process 104 sets the network switch 109 to open the controller process 104 enables the disabled network parameter server software process 102. When the controller process 104 sets the network switch 109 to closed the controller process 104 disabled one of the network parameter server software process 102. When the network parameter servers 102 are enabled the network parameter servers or server 102 manage the separate networks or combined network 108. When the controller 104 requests the network switch 109 to be closed, and the network segments are connected into a single combined network, the controller disables one of the network parameter server software processes 102 to inhibit assigning of network parameters. When the controller 104 requests the network switch 109 to be closed, and the network segments are connected into a single combined network, the controller commands the enabled network parameter server software processes 102 to assign network parameters. When the controller 104 requests the network switch 109 to be closed, and the network segments are connected into a single combined network, the controller commands the enabled network parameter server software process 102 to access the assigned parameters stored in the shared memory 103 associated with the management of the combined network. When the controller 104 has requested the network switch 109 to be closed, and the network segments are connected into a single combined network, the controller 104 commands the enabled network parameter server software process 102 to identify parameters assigned whilst part of a combined network to enable these parameters to be assigned to the respective separate network at the point in time when the network switch 109 is commanded open. When the controller 104 has requested the network switch 109 to be closed, and the network segments are connected into a single combined network, and when the enabled network parameter server 102 detects that a computer device has left the network the parameters are made available to be allocated to other networks by way of the shared memory 103 When the controller 104 requests the network switch 109 to be open separating into separate networks the network parameter server software processes 102 associated with the separated network is enabled. When the controller 104 has requested the network switch 109 opened the newly enabled server will take control of the management of the separate network segment. When the controller 104 has requested the network switch 109 to be open the network parameter server software processes 102 interrogate the separate networks 108 to determine which separate network 108 the computer device added whilst part of a combined network 108 reside in. When the controller 104 has requested the network switch 109 to be open the network parameter server software process 102 which is controlling the network 108 in which the added computer device is discovered associates the parameters to the parameter server software process 102 associated with the management of that separate network 108. The user input / output interface 107 may comprise a USB interface, an HDMI interface, a touchscreen, Ethernet interface or other interface. The network connection interfaces 105 may be a wired network connection interface, or a wireless network interface. The first of these alternatives allows the network management unit 100 to be directly connected to a computer network 108 via a connecting cable to network devices such as computers, network attached storage such as NAS drives or printers. The second of these alternatives allows the network management unit 100 to be wirelessly connected to a network. In embodiments where the network connection interface 105 is a wired network connection interface, the network connection interface 105 may comprise a Fibre-Optic interface, or other suitable interface at which data is received from a wired network interface (e.g. via a cable). In these embodiments, the network connection interface 105 may comprise a fibre-optic cable connector socket arranged to connect to an optical fibre. Other types of wired data carrying network methods may also be used, with a corresponding network connection interface 105 chosen as appropriate. In embodiments where the network connection interface 105 is a wireless network connection interface, the network connection interface 105 may comprise a Wi-Fi interface, such as IEEE 802.11, or an interface using other wireless connection technologies known in the art (e.g. a cellular network interface). In some embodiments, the network management unit 100 may be formed by a self-contained unit as illustrated schematically in the Figures. It does not therefore require any operative connection to another remote device via which the network switch 109 can be operated and network parameter servers 102 enabled or disabled to allow unauthorised connection of networks 108. Another device may be connected for configuration only, and is disconnected during normal operation. In some embodiments, the network switch 109 may be operated only by the controller (e.g. based on locally stored parameters, locally automatically determined condition or via local interaction with the user). This means that the network management unit 100 is not susceptible to attack from malicious software that could close the network switch 109 and gain access to data in network segment 108 to which authorisation is not desired. The network management unit 100 may therefore be provided in some embodiments as a separate unit that can be connected between two or more networks 108 to isolate them from each other. In some embodiments, the network management unit is therefore formed from components mounted with a self-contained housing, or provided on a single server rack unit. The controller 104 is arranged to control operation of the network parameter servers 102 and network switch 109. The controller 104 may be implemented using any suitable hardware and software components, and may for example comprise one or more processors in communication with a computer readable / writeable memory 103. The computer readable / writeable memory 103 is configured to store one or more computer readable instructions or programs which may be read by the processors in order for the controller 104 to perform functions to control the network management unit 100. The controller 104 may be arranged to combine the network segments 108 and corresponding disabling of network parameter servers 102 according to one or more time parameters. The time parameters may define any one or more of: a connecting time of the network segments 108 and corresponding disabling of network parameter servers 102, an opening time of the network segments 108 and corresponding enabling of network parameter servers 102 or a time duration in which the are connected or separated and corresponding disabling or enabling of network parameter servers 102. The controller 104 may connect and disconnect the network segments 108 and corresponding disabling or enabling of network parameter servers 102 according to a time schedule. The network segments 108 may therefore be connected and corresponding disabling or enabling of network parameter servers 102 at a time when data transfer is required to take place, but is otherwise separated to maintain isolation. The time parameters may be synchronised with a data transfer schedule. The one or more time parameters may be stored by the controller 104 in the computer readable memory 103. This allows the time parameters to be stored locally to the controller 104 (e.g. locally within the network management unit) rather than being remotely accessed. This may reduce the risk of malicious software being able to combine the network segments 108 by interfering with the controller 104 operation. The controller 104 further comprises a user input / output interface 107. This may allow a user to set the time parameters, or provide other access or to set other functions of the isolation unit 100. The time parameters are set via the input / output interface, e.g. so that they can be programmed by the user. The input / output interface 107 may be any form of input / output interface, such as: a data connection port, e.g. a USB port or similar via which another device can be connected when required for configuration; a keyboard and screen interface; or a built in touch screen; or Ethernet or other interface. The user input / output interface 107 may be a wired connection to another device only, so that no unauthorised access to the controller 104 may occur by malicious software. The user input / output interface 107 may allow the user to configure the controller 104 to connect and disconnect the network segments 108 according to a desired time schedule. By accessing the controller 104 via the input / output interface 107 it can remain isolated from other devices to prevent it from being attacked by malicious software. In some embodiments, the controller 104 may be arranged to determine when to connect and disconnect network segments 108 and associated disabling and enabling of network parameter servers 102. This may be done additionally or alternatively to operate via a time schedule. The controller 104 may be arranged to determine whether to connect and disconnect network segments 107 based on various conditions. These conditions may be set by the user and stored in the memory 103 of the controller 104. For example, the controller 104 may be arranged to actively determine when to connect and disconnect network segments 108 based on the current operation of the isolation unit, such as a data transfer state. The determination may be based on any one or more of if data transfer has been activated; if data transfer has been completed; if the data transfer has been ended. The determination may alternatively or additionally be based on any one of if a specific procedure has been complete (such as complied code transferred from network section 108 to network section 108) or if malware has been detected. For example, the controller 104 may be arranged to monitor the flow of data through or within a separate or combined network 107 and operate the network switch 109 and enable or disable the network management servers 102 according to when data transfer has started, finished (i.e. successfully completed) or is stopped. The controller 104 may determine whether data transfer was stopped abruptly (e.g. due to a power outage) rather than being completed successfully, and may open the network switch 109 and enable a network management server 102 in response. Any of the conditions in response to which the network switch 109 may be operated and corresponding enabling or disabling of the network parameter servers 102 may be determined automatically (e.g. in real time) by the controller 104, and the state of the network switch 109 and network parameter server 102 changed accordingly. In other embodiments, the controller 104 may be arranged to connect or disconnect the network segments 108 based on a manual input from the user. Such an input may be received via the user input / output interface 107. In another embodiment the controller 104 may connect the networks 108 according to a request. In another embodiment a different technique such as routing tables may be used to determine the separate network 108 of a computer device added whilst part of a combined network. In another embodiment the network parameter server software processes 102 could be a single process if the computer has a number of network interfaces 105 as shown in Fig 3 In another embodiment more than two separate networks 108 may be provided Fig 4 shows 4 separate networks. In another embodiment the network parameter server software process 102 could share parameters using a data connection between computers as shown in Fig 5 In another embodiment the controller 101 could be remote such as being a remote system such as within a cloud computer network. In another embodiment the shared memory 103 could be remotely based such as within remote system such as within a cloud computer network. In another embodiment each network parameter server software process 102 could be assigned parameters which do not overlap between networks 108. In another embodiment the network switch 109 could be integrated within the network management unit 100. The network management unit 100 of the present application may be implemented using any suitable hardware and software modules, or a mixture thereof. The management circuitry described and claimed herein may be formed by any set of hardware components that are used to combine and separate computer networks to allow data communication between them. The network management unit 100 may be provided by any suitable internal or externally connected power supply In the embodiments described herein, the processor and memory provided in the controller form a microcontroller (MCU) configured to carry out any of the functions of the controller described herein. In other embodiments, the controller may take different forms. The controller may comprise any combination of hardware and software that operates to control and process information and carry out programmed instructions. The controller may comprise any suitable processing circuitry including microprocessors, programmable logic devices, application specific integrated circuits (ASIC), application specific instruction set processors (ASIP) or the like. The controller may be any device suitable for controlling the operations of the control system according to the functions defined herein (or additional functions) by processing information (e.g. information received from sensors, stored in local memory or received from an external source) In some embodiments, the controller 104 may be formed from distributed components within the network management unit 100. Various modifications will be apparent to the skilled person without departing from the scope of the claims. Any feature disclosed in connection with one embodiment may be used in combination with the features of another embodiment. Although the appended claims are directed to particular combinations of features, it should be understood that the scope of the disclosure of the present invention also includes any novel feature or any novel combination of features disclosed herein either explicitly or implicitly or any generalisation thereof, whether or not it relates to the same invention as presently claimed in any claim and whether or not it mitigates any or all of the same technical problems as does the present invention. Features which are described in the context of separate embodiments may also be provided in combination in a single embodiment. Conversely, various features which are, for brevity, described in the context of a single embodiment, may also be provided separately or in any suitable sub combination. The applicant hereby gives notice that new claims may be formulated to such features and / or combinations of such features during the prosecution of the present application or of any further application derived therefrom. For the sake of completeness, it is also stated that the term "comprising" does not exclude other elements or steps, the term "a" or "an" does not exclude a plurality, a single processor or other unit may fulfil the functions of several means recited in the claims and any reference signs in the claims shall not be construed as limiting the scope of the claims.
Citation Information
Patent Citations
An isolation unit
GB2608662A
Management server, host gateway, host client, user gateway, user client, and network convergence and separation method
JP4627291B2
A DHCP server and program for controlling the address allocation capacity.
JP4974287B2
Highly available DHCP service by running DHCP servers on a blockchain network
US20190334859A1