Data Diode Network Architecture for Intrusion Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The architecture of data collection networks facilitates the propagation of intrusions, viruses, and malicious software, posing a threat to the protection of confidential information and the normal operation of connected devices.

Innovation Solution

Incorporating data-diode-type equipment items that render connections between devices and the collection apparatus unidirectional, preventing the propagation of intrusions and ensuring that data can only flow from devices to the collection apparatus.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If bidirectional connections are used between devices and collection apparatus, then data can be collected and devices can be controlled, but intrusions and viruses can propagate throughout the network

Engineering Contradiction:
Improvenetwork securityVSAvoidconnection architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The network connection is segmented into unidirectional data-diode components, where each device connects to the collection apparatus through separate unidirectional channels. This segmentation prevents bidirectional communication that would allow virus propagation, while maintaining the ability to collect data from all devices. The segmentation isolates potential intrusion points and limits the spread of malicious software.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Data-diode-type equipment items are introduced as intermediary components between devices and the collection apparatus. These intermediaries enforce unidirectional data flow, allowing data to pass from devices to the collection apparatus while blocking any reverse flow that could carry intrusions or viruses. The intermediaries act as security barriers that maintain network reliability without requiring complex centralized control.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If unidirectional data-diode connections are implemented, then intrusion propagation is prevented, but bidirectional communication and device control are limited

Engineering Contradiction:
Improveintrusion protectionVSAvoidcommunication flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system dynamically adapts to different communication needs by implementing unidirectional data collection while allowing for controlled bidirectional interactions when absolutely necessary. The data-diode architecture provides default unidirectional protection, but the system can be configured to allow specific bidirectional communications through proper authentication and authorization protocols, maintaining both security and adaptability.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The unidirectional data-diode connection serves multiple functions: it collects data from devices, prevents intrusion propagation, and maintains network security. Additionally, the system can accommodate various data collection protocols and device types through the universal unidirectional interface, providing versatility within the security constraints of the unidirectional architecture.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Loss of information

If data can flow bidirectionally, then devices can receive updates and control commands, but sensitive information can be transmitted back to compromised devices

Engineering Contradiction:
Improvedata protectionVSAvoiddata flow management
Core Design Contradiction:
Loss of informationVSEase of operation

Solution Approach 1:

Instead of allowing bidirectional flow and filtering outgoing data, the system inverts the approach by allowing only incoming data flow to devices. The data-diode architecture physically prevents sensitive information from flowing back to compromised devices, while still enabling necessary data collection and device monitoring functions. This inversion simplifies security management by eliminating the need for complex egress filtering.

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentUS12341826B2Protected data collection network
Publication Date: 2025.06.24 ORANGE SA
  • US12341826B2 patent drawing

AI summary

A data collection network is disclosed. The network includes a plurality of devices and a collection apparatus suitable for collecting data generated by the devices. The network further includes a plurality of data-diode-type equipment items respectively associated with the devices, each device being connected to the collection apparatus via the associated data-diode-type equipment item. Each data-diode-type equipment item is arranged to render unidirectional the connection between the associated device and the collection apparatus, in the direction from the device towards the collection apparatus. Such a network thus makes it possible, in the event of an intrusion into one of the devices or into the collection apparatus, to prevent the intrusion from spreading to other devices.