Bridge Computer File System for Secure Network Data Exchange
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for exchanging information between computer networks, such as firewalls and tunnels, are either overly restrictive or compromise security, and are cumbersome to configure and maintain, especially in dynamic environments with varying security levels.
Innovation Solution
A network environment where two isolated networks share a common storage device, with bridge computers that map and manage a file system, allowing secure information exchange between workstations through a sharing file system service and security applications, enabling authorized access and authentication while maintaining security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a firewall is used to check all information entering or leaving the secure computer network, then security is improved, but device complexity and maintenance difficulty increase significantly
Solution Approach 1:
The patent introduces a gateway computer as an intermediary between the secure private network and the untrusted public network. The gateway runs a file sharing service that acts as a mediator, allowing controlled access to files without requiring individual firewall rules for each computer. This intermediary handles the security management centrally, reducing the complexity of configuring and maintaining firewalls across multiple computers.
2Reliability
If a firewall is used to control information transit, then security is improved, but information exchange performance deteriorates
Solution Approach 1:
The gateway computer serves as a mediator that handles file access requests efficiently. Instead of blocking and inspecting every information transit through a firewall, the gateway provides direct access to authorized files through a file sharing service, maintaining security while improving performance by eliminating the overhead of continuous firewall inspection.
3Reliability
If complete isolation is implemented to protect the computer network, then security is improved, but adaptability to practical situations deteriorates
Solution Approach 1:
The gateway computer acts as a controlled bridge between the isolated private network and the external public network. It provides adaptability by enabling necessary connections for Internet-based applications and interconnection of sub-networks while maintaining security through centralized access control and authentication mechanisms.
4Reliability
If individual authorization control is implemented on each computer, then security is improved, but ease of operation deteriorates due to tedious configuration
Solution Approach 1:
The patent merges the authorization control functionality from individual computers into a centralized gateway computer. The gateway runs a file sharing service that handles authentication and access control for all files, eliminating the need to configure authorization controls on each computer individually. This centralization dramatically simplifies configuration and maintenance operations.
5Adaptability or versatility
If tunnel connections are established between selected computers, then information exchange capability is improved, but security deteriorates
Solution Approach 1:
Instead of establishing direct tunnel connections between computers that may compromise security, the patent uses a gateway computer as an intermediary. The gateway provides controlled access points through its file sharing service, allowing information exchange while maintaining security through centralized authentication and access control policies.
Data Source
AI summary
A method for exchanging information between computers from different computer networks without any direct connection is disclosed. The two networks include corresponding bridge computers that which share a file system residing on a common storage device. Any computer of a network needing to transmit information to a computer on the other network can map the file system of the corresponding bridge computer. The computer authenticates itself on the bridge computer, and it is then allowed to write the information into a file residing on the shared memory device. Likewise, any computer on the other network can map the same file system of the corresponding bridge computer. The computer authenticates itself on the bridge computer, and it is then allowed to read the information from a mirror copy of the file on the shared memory device. As a result, any network that is isolated from the outside can send and receive information. Such operation is possible even in the presence of virus infections without any security exposure.


