Bidirectional Secure Exchange Gateway Using Arbitrated Reverse Channel

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure information technology systems that utilize unidirectional components face inflexibility in adapting to changing operational requirements or enterprise policies, as they are designed to only allow one-way data transmission, making it difficult to implement necessary changes without significant expense.

Innovation Solution

A system that enables bidirectional communication by using bi-directional small form-factor pluggable transceivers (BiDi SFPs) and a third server with a power switch, which arbitrates message traffic through an on-board security module and routing table, allowing secure reverse data traffic when needed, while ensuring fail-safe conditions by disabling the second data channel upon defects or failures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If unidirectional data transmission is used to secure high-security networks, then security is improved, but adaptability to changing operational requirements deteriorates

Engineering Contradiction:
Improvenetwork securityVSAvoidadaptability to changing operational requirements
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements a dynamic system where the data diode can operate in multiple modes: traditional unidirectional mode for maximum security, and bidirectional mode enabled through a second data channel when operational requirements demand flexibility. The system transitions between states based on security policies and operational needs, resolving the contradiction between fixed security posture and adaptive requirements.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

A third server acts as an intermediary component that enables bidirectional communication while maintaining security controls. This mediator arbitrates message traffic between the high-security network and external networks, allowing reverse data traffic when needed while preserving the core security architecture through controlled intermediation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If unidirectional components are used to prevent intrusions, then protection from attacks is improved, but flexibility in network evolution deteriorates

Engineering Contradiction:
Improveprotection from intrusions and attacksVSAvoidflexibility in network evolution
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The patent segments the data transmission path into multiple independent channels: a primary unidirectional data diode for secure outbound traffic, and a secondary bidirectional data channel for controlled reverse traffic. This segmentation allows the system to maintain strong protection through the primary channel while enabling evolutionary flexibility through the secondary channel when needed.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The data diode system is enhanced with multi-functionality by incorporating a second data channel that can operate in both directions. This universal approach allows the same infrastructure to serve dual purposes: maintaining security through unidirectional transmission while also supporting bidirectional communication for network evolution and operational flexibility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If manual handover processes are used to transfer data between disconnected systems, then physical isolation security is improved, but productivity deteriorates

Engineering Contradiction:
Improvephysical isolation securityVSAvoiddata transfer efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent replaces the mechanical manual handover process with an automated electronic data transmission system. The data diode and second data channel provide automated, controlled data transfer between isolated systems, eliminating the need for manual intervention while preserving security through technical controls rather than human procedures.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11095649B2Uni-directional and bi-directional cross-domain (secure exchange gateway) design
Publication Date: 2021.08.17 SAUDI ARABIAN OIL CO
  • US11095649B2 patent drawing
  • US11095649B2 patent drawing
  • US11095649B2 patent drawing

AI summary

A system for enabling secure bidirectional communications on a network is provided, wherein a first server having a first security rating is connected to a second server having a second security rating by a first data channel configured to establish one-way communication from the first server to the second server. A second data channel incorporating a third server is configured to establish one-way communication from the second server back to the first server. The third server has a power switch that controls third server on and off states. The second data channel is enabled when the power switch is turned on. The third server arbitrates the flow of message traffic from the second server back to the first server by applying an on-board security module's encoded set of rules to determine whether the message is permitted to proceed to the first server.