Cloud-Based Cross-Domain System Using Smart NIC
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing hardware-based cross-domain solutions for secure data transfer are difficult to maintain and operate, and are not feasible for cloud networks due to the need for specialized and expensive hardware.
Innovation Solution
A software-implemented cloud-based cross-domain system that allows secure one-way traffic into a dedicated network using a Smart NIC with UDP protocol, enabling unidirectional communication without the need for physical data diodes or air gaps, and employs AI/ML filters for adaptive security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If hardware-based cross-domain solutions (data diodes, air gaps) are used to control and inspect data entering a dedicated network, then security and reliability are improved, but device complexity and cost increase significantly
Solution Approach 1:
The patent replaces physical hardware mechanisms (data diodes, air gaps) with a software-based protocol implementation. The unidirectional communication is achieved through software control of network interface cards and protocol processing, eliminating the need for specialized physical hardware while maintaining security functions.
Solution Approach 2:
The patent changes the state of standard network interface cards from bidirectional to unidirectional mode through software configuration. By modifying the operational parameters of the NIC via the cloud-based system, the hardware is repurposed to provide one-way communication without requiring physical hardware changes or specialized components.
2Reliability
If hardware-based cross-domain solutions are deployed, then secure one-way traffic control is achieved, but ease of operation and maintenance deteriorates
Solution Approach 1:
The patent introduces a cloud-based intermediary system that mediates between the source network and the disconnected network. This intermediary handles all traffic control, inspection, and protocol conversion remotely, making the system easier to operate and maintain without requiring on-site hardware management or physical access to the dedicated network.
Solution Approach 2:
The patent creates a virtual copy of the cross-domain control functionality in the cloud, replacing the need for physical hardware at the network edge. The software-based proxy system replicates the security functions remotely, allowing operators to manage the system from anywhere without direct interaction with the dedicated network infrastructure.
3Reliability
If specialized hardware (data diodes, air gaps) is used for cross-domain communication, then secure data transfer is achieved, but cost increases
Solution Approach 1:
The patent replaces expensive, specialized hardware components (data diodes, air gap infrastructure) with standard, off-the-shelf network interface cards and software. The solution uses commodity hardware that can be easily replaced or upgraded without requiring expensive specialized components, significantly reducing both initial and ongoing costs.
Solution Approach 2:
The patent makes standard network interface cards universal by enabling them to perform multiple functions through software configuration, including unidirectional communication, traffic inspection, and protocol conversion. This eliminates the need for expensive specialized hardware by making general-purpose hardware capable of performing security-specific functions.
Data Source
AI summary
In some aspects, a network interface card (NIC) may receive, at a first node of a network interface card associated with a disconnected network, a message intended for the disconnected network and sent using a first communication protocol. The network interface card may send the message from the first node to a second node of the network interface card using a second communication protocol, the second communication protocol being configured for unidirectional communication. The network interface card may receive the message at the second node. The network interface card may send, from the second node, the message to a destination node of the disconnected network using a third communication protocol. Numerous other aspects are described.


