Cloud Virtual Data Diode for Secure One-Way Network Traffic
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing hardware-based cross-domain solutions for secure network communication are difficult to maintain and operate, and are not feasible for cloud networks due to their unwieldy nature and high cost.
Innovation Solution
A software-implemented cloud-based cross-domain system that enables secure one-way traffic into a dedicated network using a network interface card (NIC) with configurable filters and protocols, allowing for flexible and adaptable security configurations without specialized hardware.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If hardware-based cross-domain solutions are used to control and inspect data entering a dedicated network, then security and data control are improved, but device complexity and ease of operation deteriorate
Solution Approach 1:
The patent replaces hardware-based cross-domain solutions with a software-implemented virtual data diode. The virtual data diode is implemented as a software component that runs on standard network infrastructure, eliminating the need for specialized hardware devices. This substitution maintains security functionality while significantly improving ease of operation and reducing device complexity.
Solution Approach 2:
The virtual data diode is implemented as a multi-functional component that can operate within existing network infrastructure. It provides data control and inspection capabilities while being compatible with standard network protocols and hardware, making it universally applicable without requiring dedicated hardware systems.
2Reliability
If hardware-based cross-domain solutions are used to control and inspect data entering a dedicated network, then security and data control are improved, but device complexity and maintenance difficulty worsen
Solution Approach 1:
The patent replaces complex hardware-based cross-domain solutions with a software-implemented virtual data diode. The virtual data diode is implemented as a software component that runs on standard network infrastructure, eliminating the need for specialized hardware devices. This substitution maintains security functionality while significantly reducing device complexity and maintenance difficulty.
Solution Approach 2:
The virtual data diode creates a software copy of the data control functionality that can be deployed without physical hardware. This virtual copy maintains the security functions of hardware-based solutions while being easier to deploy, manage, and maintain within cloud network environments.
3Reliability
If specialized hardware is used for cross-domain solutions, then security control is improved, but cost and adaptability worsen
Solution Approach 1:
The patent replaces specialized hardware with a software-implemented virtual data diode that can be deployed in various network configurations. The virtual data diode adapts to different network topologies and can be configured for various security requirements without requiring dedicated hardware for each scenario.
Solution Approach 2:
The virtual data diode provides dynamic adaptability through software configuration. Security control parameters, data flow rules, and inspection policies can be dynamically adjusted without hardware changes, allowing the system to adapt to evolving security requirements and network conditions.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
In some aspects, a network interface card (NIC) may receive, at a first node of a network interface card associated with a disconnected network, a message intended for the disconnected network and sent using a first communication protocol. The network interface card may send the message from the first node to a second node of the network interface card using a second communication protocol the second communication protocol being configured for unidirectional communication. The network interface card may receive the message at the second node. The network interface card may send, from the second node, the message to a destination node of the disconnected network using a third communication protocol. Numerous other aspects are described.