Air-Gapped System Access via Simplex Encoded Messages

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Air-gapped computer systems face challenges in secure command execution due to the risk of remote attacks and data integrity issues, as they are designed to minimize network connections to prevent attacks, but this restricts administrative access, leading to potential data damage from errors or malicious activities.

Innovation Solution

Implementing a role-based access control system with a simplex communication method using encoded messages, such as QR codes, to allow authorized users to execute commands on air-gapped systems without closing the air gap, ensuring secure access through multi-factor authentication and limited-time access tokens.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the air gap is closed to allow remote access for command execution, then administrative functionality is improved, but security against remote attacks deteriorates

Engineering Contradiction:
Improveadministrative accessVSAvoidremote attack risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a message passing interface as an intermediary mechanism that allows commands to be transmitted to the air-gapped system without establishing traditional network connections. The encoded messages (e.g., QR codes) serve as intermediaries that carry authentication and command data, enabling administrative access while maintaining the air gap's protective isolation against remote attacks

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the traditional mechanical/network connection system with an optical/code-based transmission system. Instead of using network protocols and physical connections, the system uses encoded visual messages that can be captured and decoded, substituting the mechanical network interface with a non-network-based communication method that preserves security while enabling functionality

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If the air gap remains closed to maintain security, then protection against attacks is improved, but administrative control and monitoring deteriorate

Engineering Contradiction:
Improvesystem securityVSAvoidcommand execution capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements preliminary authentication and authorization actions before commands are executed. The system pre- validates user credentials, device identities, and command permissions through multi-factor authentication mechanisms. This preliminary verification ensures that only authorized commands are transmitted, maintaining security while enabling legitimate administrative control

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent establishes a feedback mechanism where the air-gapped system can send status information and command execution results back to the external system through encoded messages. This feedback loop allows administrators to monitor system state and verify command outcomes without maintaining continuous network connections, thus preserving security while enabling control

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If traditional network protocols are used for access, then communication functionality is improved, but vulnerability to protocol-based attacks increases

Engineering Contradiction:
Improvecommunication capabilityVSAvoidprotocol attack susceptibility
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent substitutes traditional network protocol-based communication with a custom encoded message transmission system. Instead of using TCP/IP stacks and network protocols that are susceptible to attacks, the system uses visually encoded messages (such as QR codes) that contain authentication and command data, eliminating protocol-based attack vectors while maintaining communication functionality

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The encoded message serves as an intermediary that carries communication data without requiring traditional network protocols. The message encapsulates all necessary information (authentication, commands, timestamps) in a self-contained format that can be transmitted through non-network channels, replacing protocol-based communication with a protocol-free intermediary system

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11960612B2Access control for air-gapped computer systems
Publication Date: 2024.04.16 DELL PROD LP
  • US11960612B2 patent drawing
  • US11960612B2 patent drawing
  • US11960612B2 patent drawing

AI summary

A system receives a request from a user to execute a command on an air-gapped computer system. If a role-based access control system permits the user to execute the command, the system prompts a number of approvers to determine whether to approve of the user executing the command. If a required number of approvers have approved of the user executing the command, the system encodes the command and incorporates the encoded command in an encoded message. The system uses a simplex communication output device to communicate the encoded message to a simplex communication input device for the air-gapped computer system. The system enables execution of the command by requesting the air-gapped computer system to execute the command, or by providing the user with an access token, received from the air-gapped computer system, which enables the user to physically access the air-gapped computer system and execute the command.