Secure Transfer Gateway
The forwarding device with a unique architecture and transfer controller enables secure, high-throughput data transfer between networks by ensuring complete separation and independent verification, addressing the limitations of existing security components.
Patent Information
- Application Number
- JP2024501134
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2021-07-07
- Filing Date
- 2022-07-07
- Publication Date
- 2025-09-24
- Estimated Expiration
- 2042-07-07
AI Technical Summary
Existing security components in digital data transfer systems, such as hardware firewalls and protocol-breaking gateways, are ineffective against sophisticated attacks and fail to provide complete separation and independent verification of data legitimacy between networks.
A forwarding device with a unique architecture that includes four communication interfaces and a transfer controller, allowing for independent data verification and transfer without physical connections between networks, using a transfer memory for temporary storage and sequential activation of transmission channels to ensure secure, bidirectional data exchange.
Ensures secure, high-throughput data transfer between networks with complete separation and independent verification, preventing unauthorized data transmission and maintaining network integrity even in the presence of corruption.
Smart Images

Figure 0007743601000001 
Figure 0007743601000002
Abstract
Description
[Technical Field]
[0001] The present invention relates to the field of information systems security. More particularly, the present invention relates to a device for transferring digital data. The present invention also relates, in a non-exhaustive manner, to a communication system comprising such a device, a method for transferring digital data using such a device in such a system, and a computer program designed to control such a device. [Background technology]
[0002] The development of cellular networks such as 5G, the increasing virtualization of computer networks, or the emergence and widespread adoption of the Internet of Things are all examples of the current general trend towards the decentralization of digital communication, both in the personal and professional spheres.
[0003] Inevitably, this movement is accompanied by an increase in the growth and complexity of security systems to address recurring issues such as the protection of industrial and commercial confidentiality or privacy.
[0004] Another ongoing challenge is maintaining the security of computer systems connected to hospitals or in the defense sector, or large networks and infrastructures, especially distributed control systems for the distribution or transportation of fluids (water, gas, etc.), which are subject to sophisticated attacks.
[0005] In this general context, in order to keep digital data transmissions secure, it is known to provide various security components in devices that interconnect computer networks, such as network gateways or routers.
[0006] An example of such a security component is the insertion of a hardware firewall. Such a device has at least two network interfaces and analyzes the data passing through it to see if this data corresponds to predefined rules. These rules can be of several types. For example, you can ask the firewall to systematically deny all requests from a certain domain, all requests using a certain protocol, or all requests related to this or that port number.
[0007] The drawback of hardware firewalls is that filtering is complex to implement, and malicious data may remain unfiltered because it is masked by encryption or presented in the same format as legitimate data.
[0008] Another example of a security component is a gateway that breaks protocols that utilize double transformation elements.
[0009] A protocol-breaking gateway has the effect of preventing the establishment of direct communication sessions between a client and a server, but, in contrast, intercepts such sessions. A protocol-breaking gateway comprises a "pseudo-server" module that communicates with a client using a protocol recognized by the client, a "pseudo-client" module that communicates with a server using a protocol recognized by the server, and a filter that integrates a double conversion element. The filter connects the pseudo-server module to the pseudo-client module and uses a restricted protocol, thus implementing two successive protocol conversions, i.e., between the client protocol and the restricted protocol on the one hand and between the server protocol and the restricted protocol on the other hand. Summary of the Invention [Problem to be solved by the invention]
[0010] Its purpose is two-fold: to prevent attacks related to specific protocols and to allow for inspection of communication content.
[0011] The drawback of protocol subversion is that it does not allow the transmission of all possible legal data, but only data that is compatible with the restricted protocol. Another drawback of protocol subversion is that some illegal data may get through via the restricted protocol.
[0012] Another example of a security component is a network diode. A network diode is unidirectional and receives digital data from an upstream window located on a source network and protects this digital data. Destination Network It transmits to the downstream window located above. Of course, it is also possible to place two diodes to enable bidirectional communication.
[0013] The drawback of network diodes is that the security of the switch depends on the integrity of the transmission windows placed on the protected network. In practice, corruption of the upstream window results in loss of control over data transmission and creates the risk of unauthorized transmission to the downstream window.
[0014] Generally, the higher the level of security provided by existing security components, the lower the possibility of replacement, but complete separation of the protected network cannot be achieved.
[0015] It would be desirable to overcome the above drawbacks in order to make the transfer of digital data between two separate computer networks more secure.
[0016] It would also be desirable to be able to verify the legitimacy of transfers between two computer networks, as well as the legitimacy of the digital data being transferred, in a manner that is independent of the networks involved. [Means for solving the problem]
[0017] This disclosure improves the situation.
[0018] According to one aspect of the invention, a forwarding device for forwarding digital data between a first network and a second network in a communication system is proposed, the device comprising: a first communication interface with a first network; a second communication interface with a second network; a third communication interface having a transfer controller for controlling the transfer of digital data through the transfer device; a fourth communication interface configured to be connected to the at least one transfer memory; Equipped with The transfer devices are mutually exclusive. a first transmission channel through the first and fourth communication interfaces; a second transmission channel through the third and fourth communication interfaces; The third transmission channel is transmitted through the second and fourth communication interfaces. It is configured for continuous activation.
[0019] Due to the special architecture of this transfer device for transferring digital data, a complete separation between the two networks is obtained in the sense that no physical connection is ever established between these two networks.
[0020] Furthermore, the special architecture of this transfer device for transferring digital data also allows for an independent transfer controller for controlling the transfer of digital data, eliminating any connection to the network being partitioned, regardless of the level of corruption.
[0021] It is possible that the device further comprises a transfer memory connected to the fourth communication interface, or possibly several transfer memories connected to the fourth communication interface.
[0022] The transfer memory is, for example, a digital data storage device such as random access memory (RAM), flash memory (SD card, USB stick), hard disk drive (HDD), or solid state disk (SSD). Such a transfer memory is connected to the fourth communication interface and serves as a medium for temporarily storing data to be transferred. This medium can be successively connected by the transfer device to the first network, then to the transfer controller, and finally to the second network in order to transfer data from the first network to the second network while intermediate verification is performed by the transfer controller. Symmetrically, this medium can be successively connected by the transfer device to the second network, then to the transfer controller, and finally to the first network in order to transfer data from the second network to the first network while intermediate verification is performed by the transfer controller.
[0023] For example, the transfer memory is a first partition dedicated to storing digital data to be transferred from the first network to the second network; and a second partition dedicated to storing digital data transferred from the second network to the first network.
[0024] Therefore, when a forwarding device successively activates a first transmission channel and then a second transmission channel, it is expected that only the first partition will contain data coming from the first network and being forwarded to the second network. Therefore, in such a situation, it is expected that the forwarding controller will automatically erase the contents of the second partition to avoid unauthorized forwarding to the second network.
[0025] According to another aspect of the present invention, there is provided a communication system between a first network and a second network, the system comprising: a transfer device as described above for transferring digital data; a transfer controller for controlling the transfer of digital data through the transfer device; Equipped with The forwarding controller is connected to a third communication interface of the forwarding device and is independent of both the first network and the second network.
[0026] "Independent from the first network and the second network" is understood to mean that the transfer controller has no physical data connection, bus, or network, even temporary, to these two networks. As a result, the transfer controller is less likely to receive instructions from a potentially corrupted entity on one of these two networks.
[0027] The combination of the forwarding device and the forwarding controller allows any form of data exchange between the first network and the second network to be managed end-to-end independently of the two networks, so that even if the source of the forwarded data in one of the two networks becomes corrupted, this source does not have direct or indirect control over the forwarding controller or the forwarding device.
[0028] For example, the transfer controller can be further configured to control the sequential activation of the transmission channel by the transfer device. For example, such control can be performed by an all-or-nothing signal that does not pass through the transmission channel. If the sequential activation of the transmission channel can be physically triggered only by the transfer controller, the operation of the transfer device is performed independently from the first network and the second network. As a result, it is physically impossible for a malicious attacker to control the transfer device using logical instructions from either of the two networks.
[0029] For example, the transfer controller may be further configured to control a first slave controller connected to the first network to transmit a first set of incoming digital data coming from the first network to the transfer memory via a first transmission channel, and store the first set of incoming data as a first set of data to be transferred. For example, the transfer controller may signal the first slave controller whether the first transmission channel is active. This allows triggering data exchange between the first network and the transfer memory as soon as the first transmission channel becomes active and stopping such data exchange as soon as the first transmission channel becomes inactive. In this example, the transfer controller acts as a coordinator of the intermittent exchange of digital data with the second network from the perspective of the first network.
[0030] For example, the transfer controller may be further configured to obtain the first set of data to be transferred via a second transmission channel to perform a verification of the first set of data to be transferred, the verification providing a first result indicative of compliance with or violation of at least one security rule for the first set of data to be transferred. The security rule may be guided by a predetermined security policy and may relate, for example, to confidentiality and / or integrity of the digital data to be transferred. The verification of the data to be transferred may comprise, for example, running an antivirus program or verifying transfer authorization.
[0031] For example, the transfer controller may be further configured to control a second slave controller connected to the second network to transmit the first set of data to be transferred as a first set of outgoing digital data to the second network via the third transmission channel only if the first result does not indicate a security rule violation, which indicates that the transfer of the first set of data to the second network is permitted by the transfer controller.
[0032] For example, the transfer controller may be further configured to erase the data of the first set of data to be transferred from the transfer memory without further transmission via the third transmission channel if the first result for the data of the first set of data to be transferred indicates a violation of at least one security rule. For example, at a given time, the transfer controller may detect a violation of a security rule associated with the first set of data to be transferred. At this given time, the second transmission channel is active, and thus the transfer memory is not connected to either the first network or the second network, but is connected to the transfer controller. Thus, the transfer controller may specifically erase some or all of the data in the first set of data to be transferred, or may erase the entire contents of the transfer memory. If the transfer memory includes several partitions, including a partition dedicated to transferring data from the first network to the second network, the entire contents of this partition may be erased.
[0033] For example, the present system controlling a second slave controller to transmit a second set of incoming digital data coming from a second network via a third transmission channel to a transfer memory and to store said second set of incoming data as a second set of data to be transferred; obtaining a second set of data to be transferred via a second transmission channel for the purpose of performing a verification of the second set of data to be transferred, said verification providing a second result indicative of compliance with or violation of at least one security rule associated with the second set of data to be transferred; controlling the first slave controller to transmit, via the first transmission channel, the second set of data to be transferred as a second set of outgoing digital data to the first network only if the second result does not indicate a security rule violation; If the second result for the data of the second set of data to be transferred indicates a violation of at least one security rule, erasing the data of the second set of data to be transferred from the transfer memory without first transmitting it over the first transmission channel.
[0034] The forwarding controller therefore verifies both data coming from the first network and destined for the second network, and data coming from the second network and destined for the first network. The forwarding controller therefore verifies all data exchanges between the first and second networks, as well as their contents, i.e., all data exchanged between the first and second networks in one direction or the other, before allowing or denying their actual forwarding.
[0035] According to another aspect of the present invention, in a communication system, between a first network and a second network, a first communication interface with a first network; a second communication interface with a second network; a third communication interface having a transfer controller for controlling the transfer of digital data through the transfer device; a fourth communication interface; and a transfer memory connected to a fourth communication interface; 1. A method for transferring digital data by a transfer device comprising: A method is proposed, comprising successively activating, in an exclusive manner, a first transmission channel through the first and fourth communication interfaces, a second transmission channel through the third and fourth communication interfaces, and a third transmission channel through the second and fourth communication interfaces.
[0036] The method includes, for example: transmitting a first set of incoming digital data coming from a first network via a first transmission channel to a transfer memory for transfer as a first set of data to be transferred; communicating a first set of data to be transferred via a second transmission channel to a transfer controller for purposes of performing a validation of the first set of data to be transferred, the validation providing a first result indicative of compliance with or violation of at least one security rule with respect to the first set of data to be transferred; transmitting the first set of data to be transferred as a first set of outgoing digital data to the second network via the third transmission channel only if the first result does not indicate a security rule violation; If the first result indicates a violation of at least one security rule, erasing the first set of data to be transferred from the transfer memory.
[0037] The method may further comprise the following steps implemented, for example, by the transfer controller: a forwarding device triggering activation of a first transmission channel; a start of transmission signal is sent to a first slave controller connected to a first network; sending an end of transmission signal to the first slave controller after the allotted time has elapsed; Triggering activation of a second transmission channel; and the contents of the transfer memory are read and verified; Optionally, the contents of the transfer memory may be partially or completely erased; and Triggering activation of a third transmission channel.
[0038] According to another aspect of the invention, a computer program is proposed comprising one or more instructions for implementing the above method when said program is executed by a processor.
[0039] Other features, details, and advantages will become apparent from reading the following detailed description and examining the accompanying drawings. [Brief explanation of the drawings]
[0040] [Figure 1] 1 is a functional diagram of a communication system in an exemplary embodiment of the present invention; [Figure 2] 1 shows a general algorithm of an exemplary embodiment of the invention, for example a method for transferring digital data in such a communication system; DETAILED DESCRIPTION OF THE INVENTION
[0041] The object of the present invention is to ensure the transfer of digital data between different networks without establishing physical communications between them. Throughout this specification, the simplified term "data" will be understood to refer systematically to digital data.
[0042] Thus, data from the source network is transferred to a controller that is independent of the various networks, and then verification After this is done, the verified data is then forwarded to the destination network. The stream is forwarded intermittently in one direction at a time, but at high throughput without modifying the transmitted data, while ensuring physical separation between different networks.
[0043] Many applications are possible, especially in companies and organizations that have multiple information systems with different functions or different data sensitivity, that require high-speed transfers on a regular to near-continuous basis, and whose security goals require the highest level of partitioning with no network connections between these information systems or with external systems.
[0044] For example, in a hospital, the invention can be applied to managing data transfers between computer networks of medical devices and administrative computer networks; in a critical organization such as an energy producer or transportation manager, the invention can be applied to managing digital data transfers between networks hosting industrial equipment and networks for production control and office automation; and in organizations in the defense field, the invention can be applied to managing transfers between computer networks that host data of various confidentiality but still require exchange between the networks.
[0045] Reference is now made to FIG. 1, which illustrates functionally an example of a communication system, and to FIG. 2, which illustrates an example of an algorithm for transferring data between different networks, which algorithm is applicable to such a communication system.
[0046] A device for transferring digital data is shown, which has four communication interfaces 1, 2, 3, 4.
[0047] The first communication interface 1 is connected via a first data bus to a first controller 11. This first controller comprises a network link to a first network 10 and is connected to a first shared memory 12. The first controller 11 associated with the first shared memory 12 provides, from the point of view of the first network 10, two network shares for accommodating outgoing and incoming digital data (S1), respectively.
[0048] The second communication interface 2 is connected via a second data bus to a second controller 21. This second controller comprises a network link to a second network 20 and is connected to a second shared memory 22. The second controller 21 associated with the second shared memory 22 provides, from the point of view of the second network 20, a network share for accommodating outgoing and incoming digital data.
[0049] The third communication interface 3 is connected to a transfer controller 30 via a third data bus. This transfer controller functions as a master controller for the first controller 11 and the second controller 21, and also functions as a controller that controls the operation of the transfer device to transfer digital data.
[0050] The fourth communication interface 4 is connected to a transfer memory 40 for temporarily storing the data to be transferred. Optionally, the transfer memory 40 is removably connected to the fourth communication interface 4, which is for example the case with a USB key or an external hard drive.
[0051] In the digital data transfer device, the fourth communication interface 4 can be connected to only one other interface of the other three communication interfaces 1, 2, 3 at each instant, for example at the command of the transfer controller 30.
[0052] This means that transfer controller 30 must: a command to activate the first transmission channel C1 through the first and fourth communication interfaces, or a command to activate the second transmission channel C2 through the third and fourth communication interfaces, or This means that a command to activate the third transmission channel C3 can be sent to the forwarding device through the second and fourth communication interfaces.
[0053] When one of the transmission channels is activated, the other two transmission channels are simultaneously deactivated, in particular: A physical connection between the first network 10 and the second network 20 is never established, and Nor is a physical connection ever established between the first network 10 or the second network 20 on the one hand and the transfer controller 30 on the other hand.
[0054] Specifically, a command to activate a transmission channel can be simply associated with a signal that allows at least three possible values. For example, a default position can be defined in which the third channel is activated. The activation signal can thus be coded with two bits, allowing two possible values: "10" for activating the first transmission channel and "01" for activating the second transmission channel. Other codings, i.e., "00" and "11," correspond to the default position, i.e., activation of the third transmission channel. Therefore, such an activation command can be summarized as the control by transfer controller 30 of two all-or-nothing devices, i.e., two binary switches within a transfer device for transferring digital data. These all-or-nothing exchanges are denoted I / O in FIG. 1 and do not constitute a data link.
[0055] Once the first transmission channel C1 is activated (S2), data can be exchanged between the first shared memory 12 and the forwarding memory 40 (S4). In particular, outgoing digital data from the first network 10 that was previously stored in the first shared memory 12 can be transmitted to and stored in the forwarding memory 40. Inversely, incoming data that was previously stored in the forwarding memory 40 can also be transmitted to and stored in the first shared memory 12 for the purpose of being forwarded to the first network 10.
[0056] For example, incoming and outgoing data may be stored in different partitions of the transfer memory 40. In other words, a first partition may be dedicated to transferring digital data from the first network 10 to the second network 20, while a second partition may be dedicated to transferring digital data from the second network 20 to the first network 10.
[0057] These digital data transfers are initiated or triggered, for example, by the transmission of control signals by transfer controller 30 as the master controller to first controller 11 as the slave controller (S3). Such control signals may thus essentially indicate to first controller 11 that transfer memory 40 is connected and that a unidirectional or bidirectional transfer can begin. Given its simplicity, such control signals may be transmitted over a direct connection between transfer controller 30 and first controller 11 by activating a single all-or-nothing exchange, i.e., a single all-or-nothing device such as a switch.
[0058] When the transfer of the digital data between the first shared memory 12 and the transfer memory 40 is completed (S5), the first controller 11 may notify the transfer controller 30 in the form of a new all-or-nothing exchange. Following such an all-or-nothing exchange, or after a predetermined time allotted for the transfer of the digital data between the transfer memory 40 and the first shared memory 12 has elapsed, the transfer controller 30 may command the activation of the second transmission channel C2 by the transfer device for transferring the digital data (S6).
[0059] When the second transmission channel C2 is activated, as already indicated, the transfer memory 40 is connected to the transfer controller 30 and disconnected from the two controllers 11, 21 of the shared memories 12, 22 and therefore from each of the two networks 10, 20.
[0060] At this stage, the transfer memory 40 can store the data transferred from the first shared memory 12, possibly in a dedicated partition.
[0061] Transfer controller 30 may read the contents of transfer memory 40 for verification purposes (S7).
[0062] One purpose may be to verify the legitimacy of an ongoing exchange. For example, transferred data may be required to be accompanied by a signature authenticating the issuer. In other words, the transfer controller may only allow data to be transferred if such a signature is present.
[0063] Transfer controller 30 may also access a lookup table that associates different potential sources with their respective rights assigned to them. Transfer controller 30 can then verify the rights assigned to the source of the data to be transferred, the source authenticated by its signature, in order to allow or disallow the transfer of data stored in transfer memory 40.
[0064] Another purpose that transfer controller 30 may achieve by reading the contents of transfer memory 40 is verification of the actual data being transferred. This verification may include verifying the innocence of the data, for example, through antivirus, and / or verifying the authenticity of the data, for example, through encryption techniques, and / or verifying the format, size, and integrity of the data.
[0065] Generally speaking, each data validation performed by transfer controller 30 returns a result indicating violation or compliance with predetermined security rules for that data.
[0066] The security rules may be differentiated depending on the target network, which means that a first set of security rules may be provided for any data intended to be transferred to the first network 10, and a second set of security rules may be provided for any data intended to be transferred to the second network 20.
[0067] If at least one predefined security rule is violated, for example if the transfer is illegal or if the data to be transferred coming from the first network 10 represent a security risk or are not authentic, it is appropriate that the transfer of these data is not allowed (S9), i.e. the data is not sent to the second network 20. To do this, the transfer controller 30 may order the erasure of said data (S10).
[0068] Conversely, if none of the predefined security rules are violated, i.e., for example, if the transfer controller considers that the transfer is legitimate and that the data coming from the first network 10 and being transferred is authentic and does not pose a security risk to the second network 20, the transfer controller 30 may allow the transfer (S8).
[0069] Transfer controller 30 may log the outcome of each verification or control action that results in either allowing a transfer or erasing data stored in transfer memory 40 .
[0070] Next, the device for transferring digital data may activate the third transmission channel C3, for example, by command of the transfer controller 30 (S11).
[0071] When the third transmission channel C3 is activated, as already indicated, the transfer memory 40 is connected to the second network 20 and disconnected from both the first network 10 and the transfer controller 30. At this stage, the data to be transferred that is stored in the transfer memory 40 was previously subject to transfer authorization by the transfer controller 30 and would otherwise have been erased.
[0072] Then, data exchange between the transfer memory 40 and the second shared memory 22 (S13) becomes possible.
[0073] This exchange can be performed by a second controller 21 which, from the point of view of the second network 20, is responsible for network sharing functions for accommodating incoming and outgoing data respectively.
[0074] Indeed, when the third transmission channel C3 is activated, the second controller 21 can move data from the transfer memory 40 to the second shared memory 22. In parallel, the second controller 21 can also move data coming from the second network 20 and previously stored in the second shared memory 22 to the transfer memory 40.
[0075] Communication between transfer controller 30 as a master controller and second controller 21 as a slave controller may be provided and performed in a similar manner as already described between transfer controller 30 and first controller 11.
[0076] An example of such communication is described below. First, following activation of third transmission channel C3, transfer controller 30 signals second controller 21 by an all-or-nothing exchange that the data transfer can begin (S12). In a second step, a unidirectional or bidirectional transfer of data occurs between second shared memory 22 and transfer memory 40 (S13), this transfer being controlled by second controller 21. Finally, in a third step, second controller 21 signals transfer controller 30 that the data transfer is finished (S14), also by an all-or-nothing exchange.
[0077] A general mechanism has been described for transferring a first set of data from a first shared memory 12 linked to a first network 10 to a second shared memory 22 linked to a second network 20. The data present in the second shared memory 22 may then be transmitted over the second network 20 (S15).
[0078] According to this mechanism, forwarding can be controlled end-to-end by a single master controller, i.e., forwarding controller 30, and its operation can be performed completely independently of the entities linked to one or the other of the two networks 10, 20. In particular, the second interface 2 cannot be physically connected to the first interface 1 or the third interface 3.
[0079] Furthermore, since no connection is ever established between the first interface 1 and the third interface 3, neither the transfer controller 30 nor the transfer device for transferring digital data can be physically bypassed.
[0080] The general mechanism for transferring the second set of data in the reverse direction, i.e., from the second shared memory 22 linked to the second network 20 to the first shared memory 12 linked to the first network 10, operates in a similar manner to the transfer just described.
[0081] The transfer device for transferring digital data activates (S11) the third transmission channel C3, and a second set of data is considered to have been transferred (S13) from the second shared memory 22 to the transfer memory 40. The end of this transfer (S14) may be signaled by the second controller to the transfer controller 30, for example, by an all-or-nothing signal. Alternatively, the transfer controller 30 may predict the end of this transfer as corresponding to the expiration of a pre-established period of time, for example, starting from the moment of activation of the third transmission channel C3.
[0082] Therefore, transfer controller 30 can instruct the transfer device to transfer the digital data, which causes second transmission channel C2 to become active again (S6).
[0083] A verification may then be performed by the transfer controller 30 of the legitimacy of the new exchange in progress, as well as the integrity and authenticity of the data being transferred from the second shared memory 22 to the transfer memory 40 (S7). At the end of this verification, the transfer of said data to the first network 10 may be approved (S8) or rejected (S9).
[0084] Therefore, in the case of refusal, transfer controller 30 can erase the data being transferred from transfer memory 40 (S10).
[0085] After this verification, and if the transfer is rejected, after erasing the corresponding data, the transfer controller 30 can instruct the transfer device to transfer the digital data, such that the transfer device again activates (S2) the first transmission channel C1.
[0086] The second set of data may then be transferred (S4) from the transfer memory 40 to the first shared memory 12. This transfer of the second set of data may be controlled by the first controller 11, which is itself controlled by the transfer controller 30, as already described.
[0087] Thus, a transfer device for transferring digital data allows for bidirectional data transfer between two networks without ever establishing a physical connection between these two networks, and further, this bidirectional data transfer can be controlled by a transfer controller that can be completely independent and have no physical connection whatsoever with either of these two networks. [Explanation of symbols]
[0088] 1. First communication interface 2 Second communication interface 3. Third Communication Interface 4. The fourth communication interface 10. The First Network 11 First Controller 12 First Shared Memory 20 Second Network 21 Second Controller 22 Secondary Shared Memory 30 Transfer Controller 40 Transfer Memory
Claims
1. 1. In a communications system, a transfer device for transferring digital data between a first network and a second network, comprising: a first communication interface with the first network; a second communication interface with the second network; a third communication interface having a transfer controller for transferring digital data through the transfer device; a fourth communication interface configured to be connected to the at least one transfer memory; Equipped with The forwarding device: instructions for activating a first transmission channel through the first communication interface and the fourth communication interface; then, instructions for activating a second transmission channel through the third communication interface and the fourth communication interface; and finally configured to sequentially receive instructions to activate a third transmission channel via the second communication interface and the fourth communication interface; These instructions result from a transfer controller controlling two binary switches within the transfer device, The forwarding device: after receiving the instruction to activate the first transmission channel, simultaneously activating the first transmission channel and deactivating the second transmission channel and the third transmission channel; after receiving the instruction to activate the second transmission channel, simultaneously activating the second transmission channel and deactivating the first transmission channel and the third transmission channel; After receiving the instruction to activate the third transmission channel, simultaneously activate the third transmission channel and deactivate the first transmission channel and the second transmission channel. It is configured as follows: No physical connection is established between the first network and the second network, and no physical connection is established between the first network or the second network on the one hand and the transfer controller on the other hand.
2. The device of claim 1 , comprising at least one transfer memory connected to the fourth communication interface.
3. The transfer memory a first partition dedicated to storing digital data to be transferred from the first network to the second network; a second partition dedicated to storing digital data transferred from the second network to the first network; The device of claim 2, comprising:
4. 1. A communication system between a first network and a second network, comprising: A transfer device for transferring digital data according to claim 1; a transfer controller for controlling the transfer of digital data through the transfer device; Equipped with The system, wherein the forwarding controller is connected to the third communication interface of the forwarding device and is independent of both the first network and the second network.
5. The system of claim 4 , wherein the transfer controller is further configured to control the continuous activation of the transmission channel by the transfer device.
6. 5. The system of claim 4, wherein the transfer controller is further configured to control a first slave controller connected to the first network to transmit a first set of incoming digital data coming from the first network to the transfer memory via the first transmission channel, and store the first set of incoming data as a first set of data to be transferred.
7. 7. The system of claim 6, wherein the transfer controller is further configured to obtain the first set of data to be transferred via the second transmission channel to perform verification of the first set of data to be transferred, the verification providing a first result indicative of compliance with or violation of at least one security rule for the first set of data to be transferred.
8. 8. The system of claim 7, wherein the transfer controller is further configured to control a second slave controller connected to the second network to transmit the first set of data to be transferred as a first set of outgoing digital data to the second network via the third transmission channel only if the first result does not indicate a security rule violation.
9. 8. The system of claim 7, wherein the transfer controller is further configured to erase the data of the first set of data to be transferred from the transfer memory without onward transmission over the third transmission channel if the first result for the data of the first set of data to be transferred indicates a violation of at least one security rule.
10. controlling a second slave controller connected to the second network to transmit a second set of incoming digital data coming from the second network via the third transmission channel to the transfer memory and to store the second set of incoming data as a second set of data to be transferred; obtaining the second set of data to be transferred via the second transmission channel for the purpose of performing a verification of the second set of data to be transferred, the verification providing a second result indicative of compliance with or violation of at least one security rule associated with the second set of data to be transferred; controlling the first slave controller to transmit the second set of transferred data as a second set of outgoing digital data to the first network via the first transmission channel only if the second result does not indicate a security rule violation; erasing the data of the second set of data to be transferred from the transfer memory without prior transmission over the first transmission channel if the second result for the data of the second set of data to be transferred indicates a violation of at least one security rule; The system of claim 9 , further configured to:
11. In a communication system, between a first network and a second network, a first communication interface with the first network; a second communication interface with the second network; a third communication interface having a transfer controller for controlling the transfer of digital data through the transfer device; a fourth communication interface; and a transfer memory connected to the fourth communication interface; 1. A method for transferring digital data by a transfer device comprising: The method first includes: instructions for activating a first transmission channel through the first communication interface and the fourth communication interface; then, instructions for activating a second transmission channel through the third communication interface and the fourth communication interface; and finally, receiving sequentially through the second communication interface and the fourth communication interface instructions for activating a third transmission channel, the instructions resulting from a transfer controller controlling two binary switches within the transfer device; The method comprises: after receiving the instruction to activate the first transmission channel, simultaneously activating the first transmission channel and deactivating the second transmission channel and the third transmission channel; after receiving the instruction to activate the second transmission channel, simultaneously activating the second transmission channel and deactivating the first transmission channel and the third transmission channel; after receiving the instruction to activate the third transmission channel, simultaneously activating the third transmission channel and deactivating the first transmission channel and the second transmission channel; Equipped with wherein no physical connection is established between the first network and the second network, and no physical connection is established between the first network or the second network on the one hand and the transfer controller on the other hand.
12. transmitting a first set of incoming digital data coming from said first network via said first transmission channel to said transfer memory for transfer as a first set of data to be transferred; communicating the first set of data to be transferred via the second transmission channel to the transfer controller for purposes of performing a validation of the first set of data to be transferred, the validation providing a first result indicative of compliance with or violation of at least one security rule for the first set of data to be transferred; transmitting the first set of data to be transferred as a first set of outgoing digital data to the second network via the third transmission channel only if the first result does not indicate a security rule violation; erasing the data from the first set of data to be transferred from the transfer memory if the first result for the data from the first set of data to be transferred indicates a violation of at least one security rule; The method of claim 11 , comprising:
13. Implemented by the transfer controller, triggering activation of the first transmission channel; sending a start of transmission signal to a first slave controller connected to the first network; sending an end of transmission signal to the first slave controller after the allotted time has elapsed; triggering activation of the second transmission channel; reading and verifying some or all of the contents of said transfer memory; Optionally, erasing some or all of said contents of said transfer memory; triggering activation of the third transmission channel; The method of claim 11 , comprising:
14. 12. A non-transitory computer-readable storage medium storing one or more instructions for implementing the method of claim 11 when executed by a processor.
Citation Information
Patent Citations
Secure data storage, exchange and processing system
WO2019215442A1