Data Diode Packet Relay for External Request Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Data diodes that physically limit communication to one direction restrict external requests to an internal network, limiting data transmission to predefined content and timing, preventing requests for actions like stopping data transmission due to external equipment failures or retransmitting failed data.
Innovation Solution
A data diode device with a specific packet relay function that includes a packet relay unit to authorize and relay only specific packets between networks, using a unidirectional transmission path and registration information to determine and restore authorized packets, allowing external requests to be transmitted while maintaining network security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a data diode completely blocks external communication toward the internal network to ensure security, then unauthorized access is prevented, but external requests cannot be transmitted to the internal network
Solution Approach 1:
The patent applies preliminary action by pre-registering specific packet types that are authorized for relay before the data diode operation begins. The registration information storage unit stores predefined packet identification information (such as protocol types, source/destination addresses, or packet formats) that are permitted to pass through the unidirectional transmission path. When a packet arrives from the internal network, the packet determination unit checks if it matches any pre-registered authorized packet type, allowing legitimate external requests to pass while maintaining security against unauthorized access.
Solution Approach 2:
The patent introduces intermediary components between the internal and external networks: the packet determination unit acts as a filter that identifies authorized packets, the registration information storage unit serves as a reference database, and the unidirectional transmission path functions as a controlled channel. These intermediaries enable selective packet relay by mediating between the security requirement (blocking all external access) and the functionality requirement (allowing specific external requests), thus resolving the contradiction between security and adaptability.
2Reliability
If a data diode is used to limit communication to one direction, then unauthorized access is prevented, but data transmission is limited to predefined content and timing
Solution Approach 1:
The patent applies dynamics by making the data transmission capability adaptive rather than static. While the physical transmission path remains unidirectional (from internal to external network), the system dynamically determines which packets are allowed to pass based on real-time packet identification and comparison with registered authorized packet types. This dynamic packet-level control enables flexible data transmission management without compromising the unidirectional security architecture, allowing external requests to be transmitted when they match authorized patterns while blocking unauthorized communications.
3Reliability
If a data diode blocks all external communication, then network security is maintained, but requests for actions like stopping data transmission or retransmitting data cannot be given
Solution Approach 1:
The system enables communication control capabilities by pre-registering specific packet types that correspond to control functions. The registration information storage unit can store authorization information for packets requesting actions such as stopping data transmission, retransmitting data, or modifying transmission parameters. When such control packets arrive from the external network, the packet determination unit identifies them as authorized based on their pre-registered characteristics, allowing external entities to control internal network operations while maintaining security through the unidirectional transmission constraint.
Data Source
AI summary
A data diode device with specific packet relay function (14) is connected between an external network and an internal network. The data diode device with specific packet relay function (14) includes a first unit (21) and a second unit (22) connected by a signal line (Q), and the first unit (21) connected with the external network (15) has a first reference table (T1) in which a plurality of pieces of packet registration information are registered to correspond to the signal lines (Q). The second unit (22) connected with the internal network (16) has a second reference table (T2) content of which is the same as the first reference table (T1). By activating the signal line corresponding to the packet registration information including a source IP address, a destination IP address and application data which are included in a packet received by the first unit (21), the content of the packet and that the packet to be transmitted to the internal network (16) is received are conveyed to the second unit (22). The second unit (22) generates the packet based on the packet registration information to deliver to the second network. The data diode device with specific packet relay function (14) relays the packet from the internal computer (12) to the external computer (11) by use of a unidirectional transmission path S for transmitting data in one direction.


