Data transfer method with a media break between domains of different security levels, and associated system
Patent Information
- Application Number
- PCT/EP2026/057398
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2025-03-17
- Filing Date
- 2026-03-17
- Publication Date
- 2026-09-24
Smart Images

Figure EP2026057398_24092026_PF_FP_ABST
Abstract
Description
[0001] DESCRIPTION
[0002] TITLE: Data transfer method with media break between domains of different security levels and associated system
[0003] The invention relates to the technical field of data transfer between domains having different security levels.
[0004] We want to be able to manage the transfer of data from a workstation located in a high security domain to a workstation in a low security domain, or downward data transfer, so that data reserved for authorized or empowered users of the high security domain can, for example, be accessed in a controlled manner from the low security domain.
[0005] Similarly, we want to be able to manage the transfer of data from a workstation in the lower security domain to a workstation in the higher security domain, or upstream data transfer, so that, for example, malicious data is not introduced into the higher security domain.
[0006] Establishing a communication link, for example wired, between the two workstations for direct data transfer is strongly discouraged since such a link makes the high security domain vulnerable to attacks from the low security domain.
[0007] The best way to operate is to avoid any direct connection from one domain to another by using an intermediate station, or break station, which allows a break in the physical medium on which the data to be transferred is stored; that is to say, a station which allows the data carried by a first medium in the originating domain to be copied onto a second medium in the destination domain.
[0008] The object of the present invention is to provide an indirect method for bidirectional data transfer between a high-security domain and a low-security domain. To this end, the invention relates to a method for transferring data between a high-security domain and a low-security domain. For a downward data transfer from the high-security domain to the low-security domain, the method comprises the following steps: Connecting a first removable storage device to a port of a first workstation in the high-security domain; Copying a data file stored in the memory of the first workstation into the memory of the first removable storage device; Disconnecting the first removable storage device from the first workstation and connecting an intermediate station, acting as an interface between the high-security and low-security domains, to a first port of a first "white" station. The intermediate station provides a break in the data storage medium.Copying the data file stored in the memory of the first removable media into a buffer memory of the first white station; Disconnecting the first removable media and connecting a second removable media to a second port of the first white station; Copying the data file stored in the buffer memory of the first white station into the memory of the second removable media; Disconnecting the second removable media from the intermediate station and connecting it to a port of a second workstation in the low security domain; and, Copying the data file stored in the memory of the removable media into the memory of the second workstation, and the method comprising, for an upstream data transfer from the low security domain to the high security domain, the steps of: Connecting a third removable media to a port of the second workstation in the low security domain;Copying a data file stored in the memory of the second workstation to the memory of the third removable media; Disconnecting the third removable media from the second workstation and connecting it to a third port of a second workstation (white) in the intermediate station; Copying the data file stored in the memory of the third removable media to a buffer of the second workstation; Disconnecting the third removable media and connecting a fourth removable media to a fourth port of the second workstation; Copying the data file stored in the buffer of the second workstation to the memory of the fourth removable media; Disconnecting the fourth removable media from the intermediate station and connecting it to a port of the first workstation in the high security domain;and Copying the data file stored in the memory of the fourth removable media into a memory of the first workstation, the first, second, third and fourth removable media being distinct from each other, and the first and second blank workstations of the intermediate workstation being physically segregated.;
[0009] Depending on specific embodiments, the process comprises one or more of the following characteristics, taken individually or in all technically possible combinations:
[0010] Following the connection of the second removable media to the intermediate station, a memory of the second media is emptied and the second removable media is formatted; the step of copying the data file stored in the memory of the first removable media into the buffer memory of the first white station includes the following steps: authentication of a user of the intermediate station; selection by the authenticated user of a data file in the memory of the first removable media; validation of the selected data file in the memory of the first removable media; and, copying of the validated data file into the buffer memory of the first white station;
[0011] the first white station storing a table, the validation of the selected data file in the memory of the first removable media consists of filtering the selected folder by ensuring that a type of data file is associated with a user identifier of the authenticated user in said table and / or applying an antivirus software to the selected file;
[0012] the first white station storing a table, the selection by the authenticated user of a data file in the memory of the first removable medium is possible only when a medium identifier carried by the first removable medium is associated with a user identifier of the authenticated user in said table;
[0013] following the connection of the fourth removable media to the intermediate station, the memory of the fourth media is emptied and the fourth removable media is formatted;
[0014] The step of copying the data file stored in the memory of the third removable medium to the buffer memory of the second branch station includes the following steps: authentication of a user at the intermediate station; selection by the authenticated user of a data file in the memory of the third removable medium; validation of the data file selected in the memory of the third removable medium; and,
[0015] - copying the validated data file into the buffer memory of the second white station;
[0016] the second white station storing a table, the validation of the selected data file in the memory of the third removable media consists of filtering the selected data file by ensuring that a type of the data file is associated with a user identifier of the authenticated user in said table and / or applying an antivirus software to the selected file;
[0017] the second white station storing a table, the selection by the authenticated user of a data file in the memory of the third removable media is possible only when a media identifier carried by the third removable media is associated with a user identifier of the authenticated user in said table; the first and third removable media are read-only on the intermediate station;
[0018] including a logging step consisting of creating an entry in a log for any action performed on the intermediate station.
[0019] The invention also relates to a system for implementing the previous method of transferring data between a high security domain and a low security domain, the system comprising: a first workstation in the high security domain; a second workstation in the low security domain; an intermediate station interfacing between the high and low security domains, the intermediate station ensuring a break in the data support and comprising, physically segregated, a first white station dedicated to the downward transfer of data and a second white station dedicated to the upward transfer of data;the first, second, third and fourth removable media being distinct from each other, the first removable media being used exclusively for the transfer of data from the first workstation to the first white station, the second removable media being used exclusively for the transfer of data from the first white station to the second workstation; the third removable media being used exclusively for the transfer of data from the second workstation to the second white station; and the fourth removable media being used exclusively for the transfer of data from the second white station to the first workstation.;
[0020] The invention and its advantages will be better understood upon reading the following detailed description of a particular embodiment, given solely by way of non-limiting example, this description being made with reference to the accompanying drawings in which:
[0021] - Figure 1 is a schematic representation of an infrastructure for implementing the data transfer process according to the invention;
[0022] - Figure 2 is a block representation of an embodiment of a downward data transfer method according to the invention;
[0023] - Figure 3 is a block representation of an embodiment of an upstream data transfer method according to the invention.
[0024] Figure 1 represents an infrastructure 1 for the implementation of the process according to the invention.
[0025] Infrastructure 1 comprises a high security domain 10 and a low security domain 20. A high security domain is defined as a domain with a higher security level than the low security domain, which is characterized by a lower security level. The high security domain 10 contains a workstation 11.
[0026] The workstation 11 is for example a computer whose hardware includes computing means, such as a processor 12, storage means, such as a memory 13, and interface means, such as an electronic card equipped with an external connector so as to constitute a port 14.
[0027] The software part of station 11 includes an operating system 15 and a data source application 16 and a data consumer application 17.
[0028] For the implementation of the steps of the process according to the invention which are carried out on the workstation 11, a control application 18 is executed on the station 11.
[0029] The control application 18 relies on a first table T1 indicating, for example: the identifiers of the users authorized to manipulate data on the workstation 11; for each user, the media identifiers of the removable media owned by that user and which are authorized to connect to port 14 to remove data from the workstation 11; for each user, the media identifiers of the removable media owned by that user and which are authorized to connect to port 14 to deposit data on the workstation 11; and, advantageously, for each user / removable media pair, the type or types of data files that that user can save on that removable media.
[0030] Similarly, the workstation 21 includes a processor 22, a memory 23, a port 24, an operating system 25, a data source application 26, a data consumer application 27, and a control application 28 for implementing the steps of the process according to the invention carried out on the workstation 21.
[0031] The control application 28 relies on a second table T2 indicating, for example: the usernames and passwords of the users authorized to manipulate data on the workstation 21; for each user, the usernames of the removable media that they own and that are authorized to connect to port 22 of the workstation 21 to deposit data; for each user, the usernames of the removable media that they own and that are authorized to connect to port 22 of the workstation 21 to remove data; and for each user / removable media pair the file types that can be moved.
[0032] Infrastructure 1 includes, at the interface between the high security domain 10 and low security domain 20, a data support break station 30.
[0033] More specifically, the rupture station 30 comprises:
[0034] hardware and software resources in the high security domain 10 which constitute an elementary breaking station 31 dedicated to the transfer of data from the high security domain 10 to the low security domain 20 (downward flow of data identified by the arrow F1);
[0035] hardware and software resources in the lower security domain 20 which constitute a second elementary break station 331 dedicated to the transfer of data from the lower security domain 20 to the upper security domain 10 (upstream data flow identified by arrow F2); and,
[0036] a human-machine interface, HMI, 40 comprising for example a touch screen allowing a user to enter information and for information to be presented, in the form of a display adapted to that user.
[0037] The first and second elementary stations are physically segregated to guarantee control of data exchanges between domains and consequently the integrity of security on these domains.
[0038] The elementary station 31 is a computer comprising, in its hardware part, a computing means, such as a processor (not shown in Figure 1), storage means, such as a memory 33, as well as interface means, in particular a card with an external connector forming a port 32 on the upper security domain side 10 and a card with an external connector forming a port 34 on the lower security domain side 20.
[0039] The software component of elementary station 31 includes an operating system 35 and various data management applications. Specifically, elementary station 31 is designed to run an application 36 for authenticating the user of the break station, an application 37 for managing the HMI 40, an application 38 for verifying files to be transferred, and finally an application 39 for logging actions performed on the break station for the transfer of data from domain 10 to domain 20.
[0040] Application 36 relies on a third table T3 indicating: the identifiers of the users authorized to manipulate data on the first elementary station 31; for each user, the identifiers of the removable media they own and which are authorized to connect to port 32 to deposit data on the break station and those authorized to connect to port 34 to withdraw data from the break station; and for each user / removable media pair the or each type of data file that this user is authorized to move between this removable media and the break station.
[0041] Similarly, the elementary station 331 is a computer comprising, in its hardware part, a computing means, such as a processor (not shown in Figure 1), storage means, such as a memory 333, as well as interface means, in particular a card with an external connector forming a port 332 on the high security domain side 10 and a card with an external connector forming a port 334 on the low security domain side 20.
[0042] The software part of the elementary station 331 includes an operating system 335 and various data management applications: an application 336 for authenticating the user of the break station, an application 337 for managing the HMI 40, an application 338 for checking the files to be transferred, and finally an application 339 for logging the actions executed on the break station for the transfer of data from domain 20 to domain 10.
[0043] Application 336 relies on a fourth table T4 indicating, for example: the identifiers of the users authorized to manipulate data on the second elementary station 331 of the breaking station 30; for each user, the identifiers of the removable media they own that are authorized to connect to port 334 to deposit data on the breaking station and those authorized to connect to port 332 to withdraw data from the breaking station; and for each user / removable media pair the data file type that this user is authorized to move between that removable media and the breaking station.
[0044] Infrastructure 1 also includes:
[0045] - a first removable information support 50 in the high security domain 10 specifically allowing data transfer between station 11 and intermediate break station 30;
[0046] - a second removable information support 60 in the low security domain 20 allowing to specifically transfer data between the intermediate breaking station 30 and the station 21;
[0047] - a third removable 360 information carrier in the low security domain 20 allowing for the specific transfer of data between station 21 and the intermediate break station 30; and,
[0048] - a fourth removable information carrier 350 in the high security domain 10 allowing to specifically transfer data between the intermediate breaking station 30 and the station 11.
[0049] More specifically, the first media 50 is dedicated to the high security domain 10. The removable media 50 is designed to be connected only to port 14 of station 11 or to port 32 of the rupture station 30. The removable media 50 includes, for example, a memory 51 for storing data and a circuit 52 for access control to the contents of the memory 51, and has a connector paired with connectors 14 and 32. The circuit 52 stores, in particular, a removable media identifier characteristic of the first media 50. Similarly, the second media 60 is dedicated to the low security domain 20. The removable media 60 is designed to be connected only to port 22 of station 21, or to port 34 of the rupture station 30. The removable media 60 includes, for example, a memory 61 for storing data and a circuit 62 for access control to the contents of the memory 61, and has a connector paired with connectors 22 and 34.Circuit 62 stores, in particular, a removable media identifier characteristic of the second media 60.
[0050] The third 360 media is also dedicated to the low security domain 20. It is designed to be connected only to port 22 of station 21, or to port 334 of the break station 30. The removable media 360 includes, for example, a memory 361 for storing data and a circuit 362 for access control to the contents of memory 361, and carrying a conjugate connector for connectors 22 and 334. The circuit 362 notably stores a removable media identifier characteristic of the second 360 media.
[0051] The fourth media 350 is dedicated to the high security domain 10. It is adapted to be connected only to port 14 of station 11 or to port 332 of the break station 30. The removable media 350 includes, for example, a memory 351 for storing data and a circuit 352 for access control to the contents of the memory 351 and carrying a conjugate connector of connectors 14 and 332. The circuit 352 notably stores a removable media identifier characteristic of the first media 350.
[0052] A removable information medium, such as 50, 60, 360 and 350 media, is a physical data storage medium such as a USB flash drive or a removable hard drive.
[0053] For example, in cases where removable media 50, 60, 360 and 350 are of the USB flash drive type, ports 14, 32, 34, 332, 334 and 22 are also of the USB type.
[0054] Figure 2 represents a preferred embodiment of a downstream data transfer method from the high security domain 10 to the low security domain 20 (i.e., according to the flow indicated by arrow F1 in Figure 1), using the first and second removable media 50 and 60 and the white station 31 of the media break station 30.
[0055] Process 100 begins with a step 120, during which a user uses the data generation application 16. During this use, data is generated and stored as a file in the memory 13 of the workstation 11.
[0056] After using application 16, in step 130, the user launches the execution of the control application 18 to transfer certain data from workstation 11 to workstation 21. More specifically, in step 131, the user is first prompted to authenticate using, for example, a username and password. Application 18 verifies that the user is authorized to manipulate data by checking that their username is present in table T1.
[0057] If so, in the following step 132, the first removable media 50 is connected to port 14 of workstation 11.
[0058] Application 18 verifies that the first removable media 50 is authorized to be used by this user to retrieve data, by reading the media identifier in the circuit 52 of the first removable media 50 and verifying, in table T1, that this media identifier is associated with the user identified in step 131.
[0059] If so, in step 134, the user, via the control application 18, accesses the operating system file manager 15 of the workstation 11 to select data files from memory 13 to transfer to memory 51 of the first removable media 50.
[0060] In step 136, the control application 18 validates the selection made in step 134. This validation consists, for example, of verifying that a selected file can indeed be transferred from the upper security domain to the lower security domain. To do this, application 18 consults table T1, which indicates, for each user / removable media pair, the types of data files that this user is authorized to move onto that removable media.
[0061] Finally, in step 138, the validated files are copied, by the control application 18, from memory 13 to memory 51 of the first removable media 50.
[0062] In step 140, the first removable support 50 is physically disconnected from port 14, transported from the location of workstation 11 to that of break station 30.
[0063] In a step 150, the break station 30 is used to copy the data files from the first removable media 50 to the second removable media 60, via the memory of the first white station 31 as a buffer memory.
[0064] More specifically, in step 151, the user of the break station 30 launches the execution of application 36.
[0065] The user is then prompted to identify themselves by entering their username and password using the HMI 40.
[0066] Application 36 verifies that the user is authorized to manipulate data on the first white station 31 by checking that his identifier is present in table T3.
[0067] If so, the first removable media 50 is connected to port 32. Application 36 then checks that the first removable media 50 is authorized to be used by this user to store data in the memory 33 of the first white station 31. To do this, application 36 accesses the circuit 52 of the first removable media 50 to read the media identifier, and checks, by consulting table T3, that this media identifier is associated with the user identified in step 151.
[0068] The first removable media 50 is then accessible, preferably in read-only mode. If so, in a step 152, the operating system 35 of the white station 31 is executed so that the user can select, via the HMI 40, files in the memory 51 of the first removable media 50, in order to transfer them to the memory 33.
[0069] Here again, a suitable menu presenting the contents of memory 51 is presented to the user on the human-machine interface 40 of the breaking station 30.
[0070] The user selects one or more files and then confirms their selection.
[0071] In step 153, the files are momentarily transferred into memory 33 of white station 30.
[0072] Then in step 154, application 38 is executed to check the files placed in memory 33. They are first filtered and then an antivirus is advantageously applied.
[0073] Filtering consists, for example, of comparing the selected files to a whitelist stored by station 30, for example in table T3.
[0074] This whitelist indicates the file types, including their extension, that are allowed to be transferred from the high security domain 10 to the low security domain 20. Preferably, this authorization is defined at the level of each user in the T3 table.
[0075] Applying an antivirus involves thoroughly analyzing the contents of a file in memory 33 to detect any potential malware.
[0076] In step 155, the first removable support 50 is disconnected from port 32.
[0077] In step 156, the second removable support 60 is connected to port 34.
[0078] The break station 30 checks that the deposit port 32 is free (that the first media 50 has actually been removed) before allowing the connection of the second media 60 to the data retrieval port 34.
[0079] Application 36 then checks that the second removable media 60 is authorized to be used by this user to retrieve data from the memory 33 of the first white station 31. To do this, application 36 accesses the circuit 62 of the second removable media 60 to read the media identifier, then verifies that this media identifier is associated with the user who identified themselves in step 151. This verification is carried out by consulting table T3. The second removable media 60 is then accessible, preferably in write-only mode.
[0080] If so, in step 157, the memory 61 of the second removable media 60 is completely emptied and the second removable media 60 is formatted by an appropriate process carried out by application 36 so as to delete all information on this media.
[0081] In a step 158, the files from memory 33 that have successfully passed the verification step are transferred from buffer memory 33 to memory 61 of the second removable media 60.
[0082] In a step 160, preferably carried out in parallel with step 150, application 39 is executed to create an entry in the log of actions carried out on station 30.
[0083] An entry includes, for example, the identifier of the user using the break station, the identifiers of the removable media used, the list of files transferred and some of their characteristics (such as their type, size, etc.), as well as information such as the date.
[0084] In a step 170, the second removable support 60 is disconnected from the port 34 of the breaking station 30, transported from the location of the intermediate station 30 to that of the work station 21 in the lower domain 20.
[0085] In step 180, the user launches the execution of the control application 28 on the workstation 21.
[0086] In step 181, the user is first prompted to log in, for example, using their username and password. Application 28 verifies that the user is authorized to manipulate data on workstation 21 by checking that their username is present in table T2.
[0087] If so, in step 182, the second removable support 60 is connected to port 22.
[0088] The application 28 checks that the second removable media 60 is authorized to be used by this user to deposit data on the workstation 21, by reading the media identifier indicated in the circuit 62 of the second removable media 60 and by verifying that this identifier is associated, in table T2, with the user who identified themselves in step 181.
[0089] If so, in step 184, the user, via the control application 28, accesses the operating system file manager 15 to select data files from the memory 61 of the second medium 60 to be transferred to the memory 23 of the station 21.
[0090] In step 186, the control application 28 validates the selection made in step 134. This validation can advantageously consist of verifying that a selected file can actually be transferred. To do this, the application 28 consults table T2, which indicates, for each user / removable media pair, the types of data files that this user is authorized to copy to station 21.
[0091] Finally, in step 188, the validated files are copied, by the control application 28, from memory 61 to memory 23.
[0092] In step 190, the data-consuming application 27 is executed on the workstation 21. It accesses the data which comes from the high security domain and which is now present in memory 23.
[0093] Figure 3 represents a method of transferring data from the low security domain 20 to the high security domain 10 using removable data media 360 and 350 and the white station 331 of the media break station 30.
[0094] Process 200 is substantially similar to process 100 but it allows an upstream transfer of data (according to the flow F2 in Figure 1) from the low security domain 20 to the high security domain 10, whereas process 100 allowed a downstream transfer of data from the high security domain 10 to the low security domain 20.
[0095] The process 200 begins with a step 220, during which a user uses the data generation application 26 on the workstation 21 of the low security domain 20. During this use, data is generated and stored as a file in the memory 23 of the station 21.
[0096] After using application 26, in step 230, the user launches the execution of the control application 28 in order to transfer data from workstation 21 to workstation 11 in the high security domain 10.
[0097] More specifically, in step 231, the user is first prompted to log in, for example, using a username and password. Application 28 verifies that the user is authorized to manipulate data by checking that their username is present in table T2.
[0098] If so, in the next step 232, the third removable 360 support is connected to port 22 of station 21.
[0099] Application 28 checks that the third removable media 360 is authorized to be used by this user to retrieve data in the low security domain 20, by reading the media identifier in the circuit 362 of the removable media 360 and verifying that this identifier is associated with the user identified in step 231 in table T2.
[0100] If so, in step 234, the user, via the control application 28, accesses the file manager of the operating system 25 of station 21 to select data files from the memory 23 of station 21 to be transferred to the memory 361 of removable media 360. In step 236, the control application 28 validates the selection made in step 234, the validation advantageously consisting of verifying that a selected file can indeed be transferred from the low security domain 10 to the low security domain 20. To do this, the application 28 consults table T2 which indicates, for each user / removable media pair, the type of data files that this user is authorized to move onto this third removable media 360.
[0101] Finally, in step 238, the validated files are copied, by the control application 28, from memory 23 to memory 361 of the third removable media 360.
[0102] In step 140, the third removable support 360 is physically disconnected from port 22, then transported from the location of workstation 21 to that of break station 30.
[0103] In a step 250, the break station 30 is used to copy the data files from the third removable media 360 to the fourth removable media 350, via the memory of the second white station 331 as a buffer memory.
[0104] More specifically, in step 251, the user of break station 30 launches the execution of application 336.
[0105] The user is then prompted to identify themselves by entering, using the HMI 40, for example their username and password.
[0106] Application 336 verifies that the user is authorized to manipulate data on the second white station 331 by checking that their identifier is present in table T4.
[0107] If so, the third removable 360 support is connected to port 334 of the break station 30.
[0108] The application 336 then checks that the third removable media 360 is authorized to be used by this user to deposit data into the memory 333 of the second white station 331. To do this, the application 336 accesses the circuit 362 of the removable media 360 to read the media identifier, then verifies that this identifier is associated, according to table T4, with the user identified in step 251.
[0109] The removable 360 support is then accessible, preferably in read-only mode.
[0110] If so, in a step 252, the operating system 335 of the white station 31 is executed so that the user can select files in the memory 361 of the third removable media 360, in order to transfer them into the memory 333.
[0111] Here again, a suitable menu presenting the contents of memory 361 is presented to the user on the human-machine interface 40 of the breaking station 30.
[0112] The user selects one or more files and then confirms their selection. In step 253, the files are temporarily transferred to the memory 333 of the second white station 331.
[0113] Then, in step 254, application 338 is executed to check the files placed in memory 333. They are first filtered and then an antivirus is advantageously applied.
[0114] Filtering consists, for example, of comparing the selected files to a whitelist stored by the break station 30, for example in table T4.
[0115] This whitelist indicates the types of files, including their extension, that are allowed to be transferred from the low security domain 20 to the high security domain 10.
[0116] Applying an antivirus involves thoroughly analyzing the contents of a file in memory 333 to detect any potential malware.
[0117] In step 255, the third removable media 360 is disconnected from port 334. In step 256, the fourth removable media 350 is connected to port 332. The break station 30 verifies that the deposit port 334 is free (that the third removable media 360 has actually been removed) before allowing the connection of the fourth media 350 to the removal port 334.
[0118] The application 336 then checks that the fourth removable media 350 is authorized to be used by this user to retrieve data from the memory 333 of the second white station 331. To do this, the application 336 accesses the circuit 352 of the fourth removable media 360 to read the media identifier, then verifies that this identifier is associated, according to table T4, with the user identified in step 251.
[0119] The 350 support is then accessible, preferably in write-only mode.
[0120] If so, in step 257, the memory 361 of the fourth removable media 350 is then completely emptied and the fourth removable media 350 is formatted by a suitable process carried out by the application 336 so as to delete all information on this media.
[0121] In a step 258, the files from memory 333 that have successfully passed the verification step are transferred from buffer memory 333 to memory 351 of the fourth removable media 350.
[0122] In a step 1260, preferably carried out in parallel with step 250, application 339 is executed to create an entry in the log of actions carried out on the breaking station 30.
[0123] An entry includes, for example, the identifier of the user using the break station, the identifiers of the 360 and 350 removable media used, the list of files transferred and some of their characteristics (such as their type, size, etc.), as well as information such as the date.
[0124] In a step 270, the fourth removable support 350 is disconnected from the port 332 of the break station 30, and then transported from the location of the break station 30 to that of the work station 11 of the high security domain 10.
[0125] In step 280, the user launches the execution of the control application 18 on the workstation 11.
[0126] More specifically, in step 181, the user is first prompted to authenticate themselves using, for example, a username and password. Application 18 verifies that the user is authorized to manipulate data by checking that their username is present in table T1.
[0127] If so, in step 282, the fourth removable support 250 is connected to port 22.
[0128] Application 18 checks that the fourth removable media 350 is authorized to be used by this user to deposit data on the workstation 11, by reading the media identifier in the circuit 351 of the media 350, and then verifying that this identifier is associated, in table T1, with the user identified in step 281.
[0129] If so, in step 284, the user, via the control application 18, accesses the operating system file manager 15 to select data files from memory 351 of the fourth removable media 350 to transfer to memory 13 of the workstation 11.
[0130] In step 286, the control application 18 validates the selection made in step 284. This validation can advantageously consist of verifying that a selected file can actually be transferred. To do this, the application 18 consults table T1, which indicates, for each user / removable media pair, the types of data files that this user is authorized to copy to workstation 11.
[0131] Finally, in step 288, the validated files are copied, by the control application 18, from memory 251 to memory 13.
[0132] In step 290, the data-consuming application 17 is executed on the workstation 11. It accesses data from the low security domain 10 which is now present in the memory 13 of the workstation 11.
[0133] The process according to the invention has the following advantages:
[0134] File transfer with comprehensive visualization of the data to be transferred on the human-machine interface of the intermediate breaking station;
[0135] Segregation of upstream and downstream flows, thereby preventing data compromises; identification of users and logging of actions performed on the intermediate break station;
[0136] break in support for data transfer from one domain to another, preventing information leakage;
[0137] Antiviral analysis of transferred data and filtering of data according to its type;
[0138] unidirectional pairing of removable media allowing data to be moved from one domain to another.
Claims
DEMANDS 1. A method for transferring data between a high-security domain (10) and a low-security domain (20), the method comprising the steps of: for a downward data transfer (100) from the high-security domain to the low-security domain: Connection (132) of a first removable media (50) on a port (14) of a first workstation (11) of the high security domain (10); Copying a data file stored in a memory of the first workstation (11) into a memory of the first removable media (50); Disconnection of the first removable media (50) from the first workstation (11) and connection to a first port (32) of a first white station (31) of an intermediate station (30) interfacing between the high and low security domains, the intermediate station ensuring a break in data media; Copying the data file stored in the memory of the first removable media (50) into a buffer memory of the first branch station (31); Disconnecting the first removable media (50) and connecting a second removable media (60) to a second port (34) of the first white station (31); Copying the data file stored in the buffer memory of the first white station (31) into a memory of the second removable medium (60); Disconnection of the second removable media (60) from the intermediate station (30) and connection to a port (24) of a second workstation (21) in the low security domain (20); and, Copying the data file stored in the memory of the removable media (60) into a memory location on the second workstation (21), and for an upstream data transfer (200) from the lower security domain to the upper security domain: Connection (232) of a third removable media (360) to a port (14) of the second workstation (21) of the low security domain (20); Copying a data file stored in a memory of the second workstation (21) into a memory of the third removable media (360); Disconnecting the third removable support (360) from the second workstation (21) and connecting to a third port (334) of a second white station (331) of the intermediate station (30); Copying the data file stored on the memory of the third removable media (360) into a buffer memory of the second branch station (331); Disconnecting the third removable media (360) and connecting a fourth removable media (350) to a fourth port (332) of the second white station (331); Copying the data file stored in the buffer memory of the second white station (331) into a memory of the fourth removable medium (350); Disconnection of the fourth removable media (350) from the intermediate station (30) and connection to a port (24) of the first workstation (11) in the high security domain (10); and, Copying the data file stored in the memory of the fourth removable media (350) into a memory location on the first workstation (11), the first, second, third and fourth removable supports being distinct from each other, and the first and second white stations of the intermediate station being physically segregated.
2. Method according to claim 1, wherein, following the connection of the second removable medium to the intermediate station, a memory (61) of the second medium (60) is emptied and the second removable medium (60) is formatted.
3. Method according to claim 2, wherein the step of copying the data file stored in the memory of the first removable medium (50) into the buffer memory of the first branch station (31) comprises the steps of: - authentication of a user of the intermediate station (30); - selection by the authenticated user of a data file in the memory of the first removable media (50); 19 - validation of the selected data file in the memory of the first removable media (50); and, - copying the validated data file into the buffer memory of the first white station (31).
4. Method according to claim 2 or claim 3, wherein the first white station stores a third table (T3), the validation of the data file selected in the memory of the first removable medium (50) consists of filtering the selected folder by ensuring that a type of data file is associated with a user identifier of the authenticated user in the third table and / or applying antivirus software to the selected file.
5. Method according to any one of claims 2 to 4, wherein the first white station memorizing a third table (T3), the selection by the authenticated user of a data file in the memory of the first removable medium (50) is possible only when a medium identifier carried by the first removable medium is associated with a user identifier of the authenticated user in the third table.
6. A method according to any one of claims 1 to 5, wherein following the connection of the fourth removable medium to the intermediate station, the memory of the fourth medium is emptied and the fourth removable medium is formatted.
7. Method according to claim 6, wherein the step of copying the data file stored in the memory of the third removable medium (360) into the buffer memory of the second branch station (331) comprises the steps of: - authentication of a user of the intermediate station (30); - selection by the authenticated user of a data file in the memory of the third removable media (360); - validation of the selected data file in the memory of the third removable storage device (360); and, - Copying the validated data file into the buffer memory of the second white station (331).20 8. Method according to claim 6 or claim 7, wherein, the second white station storing a fourth table (T4), the validation of the data file selected in the memory of the third removable medium (360) consists of filtering the selected data file by ensuring that a type of the data file is associated with a user identifier of the authenticated user in the fourth table and / or applying antivirus software to the selected file.
9. A method according to any one of claims 6 to 8, wherein, the second white station storing a fourth table (T3), the selection by the authenticated user of a data file in the memory of the third removable medium (360) is possible only when a medium identifier carried by the third removable medium is associated with a user identifier of the authenticated user in the fourth table.
10. Method according to any one of claims 1 to 7, wherein the first and third removable media are read-only on the intermediate station (30).
11. A method according to any one of claims 1 to 10, comprising a logging step consisting of creating an entry in a log for any action performed on the intermediate station (30).
12. System (1) for implementing a method of transferring data between a high security domain (10) and a low security domain (20) according to any one of claims 1 to 11, characterized in that the system comprises: - a first workstation (11) in the high security domain (10); - a second workstation (21) in the low security domain (20); - an intermediate station (30) as an interface between the high and low security domains, the intermediate station ensuring a break in data support and comprising, physically segregated, a first white station (31) dedicated to downstream data transfer and a second white station (331) dedicated to upstream data transfer; - the first, second, third and fourth removable media being distinct from one another, the first removable media (50) being used exclusively for the transfer of data from the first station of 21 work to the first white station, the second removable media (60) being used exclusively for data transfer from the first white station to the second workstation; the third removable media (360) being used exclusively for data transfer from the second workstation to the second white station; and the fourth removable media (350) being used exclusively for data transfer from the second white station to the first workstation, in that the system comprises, for a downward data transfer (100) from the upper security domain to the lower security domain: A means of connecting the first removable media (50) to a port (14) of the first workstation (11) of the high security domain (10); A means of copying a data file stored in a memory of the first workstation (11) into a memory of the first removable medium (50); A means of connecting to a first port (32) of the first white station (31) of an intermediate station (30) in interface between the high and low security domains; A means of copying the data file stored in the memory of the first removable medium (50) into a buffer memory of the first branch station (31); A means of connecting a second removable media (60) to a second port (34) of the first white station (31); A means of copying the data file stored in the buffer memory of the first white station (31) into a memory of the second removable medium (60); A means of connecting to a port (24) of a second workstation (21) in the low security domain (20); and, A means of copying the data file stored in the memory of the removable media (60) into a memory of the second workstation (21), and in that the system comprises, for an upstream data transfer (200) from the lower security domain to the upper security domain: A means of connecting (232) the third removable media (360) to a port (14) of the second workstation (21) of the low security domain (20); 22 A means of copying a data file stored in a memory of the second workstation (21) into a memory of the third removable media (360); A means of connection to a third port (334) of the second white station (331) of the intermediate station (30); A means of copying the data file stored on the memory of the third removable medium (360) into a buffer memory of the second branch station (331); A means of connecting a fourth removable media (350) to a fourth port (332) of the second white station (331); A means of copying the data file stored in the buffer memory of the second white station (331) into a memory of the fourth removable medium (350); A means of connecting to a port (24) of the first workstation (11) of the high security domain (10); and, A means of copying the data file stored in the memory of the fourth removable media (350) into a memory of the first workstation (11).