High security bidirectional file transfer system
The bidirectional file transfer system with personalized access controls and security measures addresses data transfer challenges, enhancing security and compliance in OT-IT networks.
Patent Information
- Application Number
- PCT/TR2025/050321
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-03-28
- Publication Date
- 2025-10-02
AI Technical Summary
Existing file transfer systems between OT and IT networks face challenges in securely and efficiently managing data transfer, particularly in organizations with intense security requirements, leading to potential data leakage and impractical solutions like external memory or email sharing.
A bidirectional file transfer system is implemented with separate incoming and outgoing folders for each external user in both IT and OT networks, incorporating security measures and personalized access controls, ensuring data compliance and privacy through predetermined approval flows.
Enhances data security and control during transfer by reducing unnecessary copying and ensuring compliance with personal data rules, thereby improving operational effectiveness in secure data management.
Smart Images

Figure TR2025050321_02102025_PF_FP_ABST
Abstract
Description
[0001] HIGH SECURITY BIDIRECTIONAL FILE TRANSFER SYSTEM
[0002] Technological Field:
[0003] The present invention relates to a system to provide secure file transfer from the OT network within the institution to the outside of the institution and from the outside of the institution to the OT network, without causing any leakage in the IT network.
[0004] State of the Art:
[0005] OT and IT networks in organizations are networks used for internal company communication. The OT network (operational technologies) referred to here is the network, also known as closed network, black network or red network, where industrial control systems data used to control and maintain the continuity of industrial processes, to ensure functional and technical security, where industrial process communications are provided, where confidential files or data are stored. An IT network (information technology) is a system of computers, storage, networks and other physical devices, infrastructure and processes to create, process, store, secure and exchange all types of electronic data, known as an open network or blue network.
[0006] Intensive organizations with separate OT-IT structures and high security requirements, such as military institutions, have the advantage of keeping their sensitive data in secure areas closed to the internet. These types of organizations provide this advantage with systems established by separating OT-IT structures. However, when data in these secure areas is needed, some difficulties arise in the process of exporting and receiving this data in a controlled manner. In the current situation, in order to extract data from the systems, it must first be copied to an area with internet access within the secure area where this data is located. Then, this copied data is sent out. In this process, structures such as unnecessary copying and difficulties in tracking data emerge, which pose potential risks in terms of data security. In this context, the development of a more effective solution for the secure transfer and management of data could increase the security of these systems.
[0007] In the state of the art, files from the OT network to outside the organization are shared via external memory or e-mail by authorizing some people for the company, which paves the way for the files to be leaked by third parties. This situation also presents an impractical solution that is difficult to control.
[0008] In the patent document numbered US2023216831A1 , which was encountered in the literature research, a system is described in which access to an OT network where historical data is stored is provided through tunnels opened in real time. The relevant patent is designed to enable historical data to be shared securely among historians and to eliminate attacks on the OT network. The tunnels mentioned herein are not used in the invention described herein. In the present invention, incoming and outgoing file folders are created for external users on an environment provided in the IT and OT network, and file sharing is carried out in a planned manner in these secure areas.
[0009] Consequently, a new file transfer system is required in which the state of the art is exceeded, the disadvantages are eliminated.
[0010] Brief Description of the Invention:
[0011] The invention is a file transfer system which exceeds the state of the art, eliminates the disadvantages and has some additional features.
[0012] The object of the present invention is to provide a file transfer system to enable file sharing between the OT network and external users in a secure and planned manner. Said system offers a special approach to manage data to be sent outside the secure area in a more secure and controlled manner. In this context, the process of opening data to the outside world is carried out through predetermined approval flows and personal data rules. Data is sent out in accordance with these approval flows and subject to specified protocols and security standards. To achieve this in the system, separate incoming and outgoing file folders are created for each external user in both the IT network and the OT network. In this way, the system works bidirectionally. Files go through all kinds of security and approval processes in these folders.
[0013] This approach reduces unnecessary copying and provides greater control and security during the data transfer process. In addition, by ensuring full compliance with personal data rules, it creates a more solid foundation in data privacy and security issues. In this way, military systems and other systems with intense security requirements can transmit their sensitive data to where it is needed more effectively and securely. This solution increases the operational effectiveness of military systems and similar systems with intensive security requirements by providing a data management process that is security-focused and meets compliance requirements.
[0014] Description of the Figures:
[0015] The present invention will be described with reference to the accompanying drawings, thus the characteristics of the invention will be understood clearly. However, the aim of this is not to limit the invention with such certain embodiments. On the contrary, it is aimed to cover all alternatives, amendments and equivalents which may be contained in the field defined by the accompanying claims. It is to be understood that the details shown are only shown for the sake of illustrating the preferred embodiments of the present invention and presented for both illustrating the methods and for providing description of the rules of the invention and the conceptual features of the invention to be easily understood. In these figures;
[0016] Figure- 1 Schematic view of the file transfer system which is the subject of the invention.
[0017] The figures which enable to clarify this invention are enumerated as mentioned in the attached figure and they are given with their names herein below.
[0018] Description of the References:
[0019] 10. OT network
[0020] 11. OT network user
[0021] 12.OT server
[0022] 13. Administrator
[0023] 14.OT team folder
[0024] 15.OT sent folder
[0025] 16.OT incoming folder
[0026] 17. File approval
[0027] 2O.Agent
[0028] 30. IT network
[0029] 31. IT server
[0030] 32. IT team folder
[0031] 33. IT sent folder
[0032] 34. IT incoming folder
[0033] 40. External user
[0034] Description of the Invention:
[0035] In this detailed description, the inventive file transfer system is described by means of examples only for clarifying the subject matter such that no limiting effect is created. The file transfer system, which is the subject of the invention, provides two-way file transfer from said OT network (10) to the external users (40) located outside the institution, and from said external users (40) to the OT network (10) in an institution comprising at least one OT network (10) and at least one IT network (30). The inventive system achieves this by creating two different environments in the OT network (10) and the IT network (30) and by creating independent incoming and outgoing file folders for each external user (40) in these environments. In this way, both the problem of the difficulty of file transfer tracking processes is eliminated and the files can be transferred securely without being leaked.
[0036] In the invention, the OT network (10) is the network in which the data of industrial control systems used to control and maintain the continuity of industrial processes, to ensure functional and technical security, industrial process communications are provided, and confidential files or data are stored. The IT network (30) used in the invention is a network of computers, storage, networks and other physical devices, infrastructure and processes to create, process, store, secure and exchange all kinds of electronic data.
[0037] In the invention, in the OT network (10), it is possible for at least one OT network user (11 ) who has access to the files in the OT network (10) to perform two-way file transfer with an external user (40) located outside the organization. For this purpose, there is an OT server (12) in the OT network (10). The OT server (12) creates an environment in the OT network (10) through the software it owns. In said environment, there is an OT team folder (14) used by OT network users (11 ), at least one OT incoming folder (16) and an OT sent folder (15) for each external user (40). The OT sent folder (15) is the folder where the file that the OT network user (11 ) wants to transfer to the external user (40) is waiting for approval to be transferred to the IT network (30). The OT incoming folder (16) is the section where files coming from external users (40) are received via the IT network (30). Files transferred to the OT incoming folder (16) can be retrieved by the OT network user (11 ) and saved to the hidden database in the OT network (10). There is at least one administrator (13) in the OT network (10) for file approval (17). Said file approval (17) can consist of variable rules. For example, if the file to be transferred from the OT network (10) to the external user (40) comprises personal data, the approval of person X in the organization may be required, otherwise the approval of person Y may be required. Such variable rules are controlled by the administrator (13). However, after file approval (17), file transfer can be made from the OT network (10) to the IT network (30) or from the IT network (30) to the OT network (10).
[0038] In the invention, the IT network (30) comprises an IT server (31). Said IT server
[0039] (31 ) creates an environment in the IT network (30) through a software it owns. In the mentioned environment, there is an IT team folder (32) used by IT users, at least one IT incoming folder (34) and an IT sent folder (33) for each external user (40). The IT sent folder (33) is the folder where the file that the OT network user (11 ) wants to transfer to the external user (40) is accessible by the external user (40). However, this access is limited to external users (40) by specific rules. The external user (40) may not be able to use one or more of the viewing, printing, downloading and editing features in the IT sent folder (33) opened specifically for him / her. For example, if a print blocking rule is assigned to the IT sent folder (33), the external user (40) cannot print the file shared with him / her in the IT sent folder (33). The IT incoming folder (34) is the section where files coming from external users (40) are kept waiting to be transmitted to the OT network (10) after passing through the security processes in the IT team folder
[0040] (32).
[0041] In the invention, there is an agent (20) between the IT network (30) and the OT network (10). Said agent (20) scans the incoming folders (16, 34) and the sent folders (15, 33) at certain frequencies. If a new file is detected as a result of the scan, the agent (20) is triggered and requests file approval (17) from the administrator (13) for the relevant file. When the administrator (13) approves the file, file transfers can occur bidirectionally. In the invention described herein, file transfer from the external user (40) to the OT network (10) is realized by taking the file from the external user (40) to the IT network (30) and transferring the same to the OT network (10), while file transfer to the external user (40) is realized by taking the file from the OT network (10) to the IT network (30) and transferring the same from the IT network (30) to the external user (40). The distinctive feature of the invention is that all these bidirectional file transfer processes take place within a certain organization and plan, comprise security processes, and go through approval stages.
[0042] The structure of the invention, which enables file transfer to be carried out within a certain organization and plan, with personalized access restrictions, comprises at least one incoming folder (16, 34) and at least one sent folder (15, 33) in both the IT network (30) and the OT network (10) for each external user (40). As can be seen in Figure 1 , there are three different external users (40), three IT incoming folders (34), and three OT incoming folders (16).
[0043] In the invention, files coming from external users (40) are first taken to the IT team folder (32) and passed through security measures within the IT team folder (32). Said security measures may be at least one of the security measures such as virus protection, sandbox, CDR, DLP, SIEM, SOAR, filewall or alternatives. If there is no security problem with the incoming file, the OT server (12) then creates an IT incoming folder (34) with specific authorization rules defined specifically for the external user (40) and transfers the incoming file to the IT incoming folder (34). The file transferred to the IT incoming folder (34) is noticed by the agent (20) positioned between the OT network (10) and the IT network (30), and the agent (20) is triggered to request file approval (17) from the administrator (13) in the OT network (10). After the file approval (17) is received, the file is transferred by the IT server (31 ) to the OT incoming folder (16) created specifically for the external user (40) by the OT server (12) located in the OT network (10). The file arriving in the OT incoming folder (16) is downloaded by the OT network user (11 ) and saved in the OT network (10) database.
[0044] As can be seen in Figure 1 , in the invention, the files to be sent from the OT network user (11 ) to the external user (40) are placed in the OT team folder (14). Although there is no need for any security procedure since the files in the OT network (10) are secure, it is possible to be subject to a security measure that comprises at least one or alternative security measures such as virus protection, sandbox, CDR, DLP, SIEM, SOAR, filewall. Afterwards, the OT server (12) creates the OT sent folder (15) with certain authorization rules defined specifically for the external user (40), and the file to be sent is transferred to the said OT sent folder (15). The file transferred to the OT sent folder (15) is noticed by the agent (20) positioned between the OT network (10) and the IT network (30), and the agent (20) is triggered to request file approval (17) from the administrator (13) in the OT network (10). After the file approval (17) is received, it is transferred to the IT sent folder (33) created specifically for the external user (40) by the IT server (31). The file sent to the IT sent folder (33) can be used by the external user (40) according to the authorization rules assigned to the IT sent folder (33).
[0045] In the invention, the OT sent folder (15) and the IT sent folder (33), which are created specifically for the external user (40), comprise certain authorization rules. For example, these rules can be view only, edit only, download or print permissions. In the invention, it has become possible to assign different authorization rules to different external users (40) by creating folders specifically for each external user.
Claims
CLAIMS1. A file transfer system for use in an organization having at least one OT network (10), at least one IT network (30), at least one administrator (13) in said OT network (10) and at least one OT network user (11 ), characterized by comprising;• At least one OT server (12) that creates at least one incoming folder and at least one sent folder specifically for the external user (40) in order to perform bidirectional file transfer with an external user (40) in the OT network (10),• At least one IT server (31 ) that creates at least one incoming folder and at least one sent folder specifically for the external user (40) in order to be able to perform bidirectional file transfer with an external user (40) in the IT network (30),• At least one agent (20) that periodically traverses the folders created by the aforementioned IT server (31 ) and OT server (12) and is triggered when it detects a new file, requesting file approval (17) from an administrator (13) on the OT network (10) about the relevant file.
2. A file transfer system according to claim 1 , characterized in that; it comprises at least one IT team folder (32) in the IT network (30), where files from an external user (40) are uploaded, passed through at least one security measure.
3. A file transfer system according to claim 2, characterized in that; said IT team folder (32) comprises an IT incoming folder (34) specially created for each file sending external user (40), to which files that have undergone security steps are transferred.
4. A file transfer system according to claim 1 , characterized in that; it comprises at least one OT team folder (14) in the OT network (10) where thefile to be transferred from the OT network user (11 ) to external users (40) is kept.
5. A file transfer system according to claim 4, characterized in that; it comprises an OT sent folder (15) specially created for each external user (40), to which files held in said OT team folder (14) are transferred.
6. A file transfer system according to any one of the preceding claims, characterized in that; it comprises a specially created IT sent folder (33) for each external user (40) to which the files in said OT sent folder (15) are transferred to be made accessible to the external user (40) as a result of approval processes.
7. A file transfer system according to any one of the preceding claims, characterized in that; it comprises a specially created OT incoming folder (16) for each external user (40), to which the files in the mentioned IT incoming folder (34) are transferred through approval processes to be made available to the OT network user (11 ).
8. A file transfer system according to any one of the preceding claims, characterized in that; it comprises at least one rule for external user (40) access restrictions (download, print, view, edit) to the file in at least one of said OT sent folder (15) and IT sent folder (33).
9. A method of using a file transfer system in an organization having at least one OT network (10), at least one IT network (30), at least one administrator (13) in said OT network (10) and at least one OT network user (11 ), to transfer files from external users (40) located outside said organization to an OT network user (11 ) in said OT network (10), characterized by comprising the process steps of;• importing files from external users (40) into an IT team folder (32),• passing at least one security measure within said IT team folder (32),• then the OT server (12) creating an IT incoming folder (34), if there is no security problem with the incoming file,• transferring the incoming file to the IT incoming folder (34),• noticing file transferred to the IT incoming folder (34) by the agent (20) positioned between the OT network (10) and the IT network (30),• triggering said agent (20) and requesting file approval (17) from the administrator (13) in the OT network (10),• after receiving the file approval (17), transferring the file by the IT server (31) to the OT incoming folder (16) created by the OT server (12) located in the OT network (10),• downloading the file received in the OT incoming folder (16) by the OT network user (11 ) and saved in the OT network database (10).
10. A method according to claim 9, characterized in that; the created IT incoming folder (34) and the OT incoming folder (16) are specific to the external user (40) for each file transfer.
11. A method of using a file transfer system in an organization having at least one OT network (10), at least one IT network (30), at least one administrator (13) on said OT network (10), and at least one OT network user (11), to transfer files from an OT network user (11 ) on the OT network (10) to external users (40) located outside the organization, characterized by comprising the process steps of;• importing the files to be sent from the OT network user (11) to the external user (40) into the OT team folder (14),• creating the OT sent folder (15) by OT server (12) with specific authorization rules defined specifically for the external user (40),• transferring the file to be sent to said OT sent folder (15),• noticing file transferred to the OT sent folder (15) by the agent (20) positioned between the OT network (10) and the IT network (30),• triggering said agent (20) and requesting file approval (17) from the administrator (13) in the OT network (10),• after the file approval (17) is received, transferring the same to the IT sent folder (33) specially created for the external user (40) by the IT server (31 ),• Using the file sent to the IT sent folder (33) by the external user (40) according to the authorization rules assigned to the IT sent folder (33).
12. A method according to claim 11 , characterized in that; the created OT sent folder (15) and IT sent folder (33) are specific to the external user (40) for each file transfer.
13. A method according to claim 11 , characterized in that; the created OT sent folder (15) and IT sent folder (33) have access restrictions (download, print, view, edit) specific to the external user (40) for each file transfer.
Citation Information
Patent Citations
Policy based agentless file transfer in zero trust private networks
US11811855B1
Secure remote access to historical data
US20230216831A1
Trace context over file transfer communications
US20230247084A1