Cross-Domain Transfer Guard with Diode Modules

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Transferring content between networks with different security levels is challenging due to the risk of malware transmission, which can compromise higher security networks or nodes, and existing solutions fail to prevent improper information transfers effectively.

Innovation Solution

A cross-domain service architecture that includes a transfer guard module implementing two-way file transfer protocols over TCP/IP, diode modules for one-way transfers, and review modules for malware and permission analysis, ensuring only verified and permitted content is transferred between high and low security domains.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If content is transferred between networks with different security levels, then information exchange capability is improved, but the risk of malware transmission and security compromise increases

Engineering Contradiction:
Improveinformation exchange capabilityVSAvoidmalware transmission risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a cross-domain gateway as an intermediary system between high-security and low-security networks. This gateway includes inspection modules that analyze transferred content, data diodes that enforce one-way transfer, and policy enforcement mechanisms that mediate the exchange process. The intermediary prevents direct contact between the two networks, blocking malware transmission while allowing legitimate information exchange through controlled channels.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the content transfer process into multiple independent stages: content inspection, permission verification, malware scanning, and controlled delivery. Each stage is handled by separate modules (inspection module, data diode module, review module) that work in sequence. This segmentation allows thorough security checking without blocking legitimate transfers, resolving the contradiction between security and exchange capability.

Inventive Principle:
Principle #1Segmentation

2Reliability

If content transfer is restricted to prevent malware, then security protection is improved, but proper information transfer is blocked

Engineering Contradiction:
Improvesecurity protectionVSAvoidinformation transfer efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary security inspections, malware scans, and permission verifications on all content before it is allowed to transfer between domains. The inspection module analyzes content characteristics, the review module checks permissions and policies, and only pre-verified content is permitted through by the data diode. This preliminary action ensures security protection while allowing all legitimate transfers to proceed without delay.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The cross-domain gateway automatically performs security checks, malware detection, and permission verification without requiring manual intervention for each transfer. The system self-regulates the transfer process by automatically blocking malicious content and permitting legitimate content based on predefined policies, maintaining both security and transfer efficiency.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If multiple security checks are performed on transferred content, then malware detection capability is improved, but transfer process complexity increases

Engineering Contradiction:
Improvemalware detection capabilityVSAvoidtransfer process complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The complex security checking process is divided into separate functional modules: an inspection module that analyzes content characteristics, a review module that verifies permissions and policies, and a data diode module that enforces transfer rules. Each module performs a specific security function independently, making the overall complex process manageable and maintainable while achieving high malware detection capability through cumulative checks.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9762595B2Secure cross domain solution systems and methods
Publication Date: 2017.09.12 RAYTHEON CO
  • US9762595B2 patent drawing
  • US9762595B2 patent drawing
  • US9762595B2 patent drawing

AI summary

Generally discussed herein are systems, apparatuses, and methods for secure transfer of content across a security boundary. A system can include a high side domain communicatively coupled to a transfer guard module, the high side domain comprising a high side data repository, a first review module executable by processing circuitry to determine whether a permission level of first content violates a permission level of the high side domain, a second review module executable by the processing circuitry to determine whether second content from the high side data repository includes a permission level that violates a permission level of a low side domain, a first data diode module communicatively coupled between the first review module and the high side data repository, and a second data diode module communicatively coupled between the second review module and the high side data repository.