Data Forwarding Device for Secure IMS Communication via Physical Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing data communication across multiple IMS subsystems lacks security, as unauthorized outsiders can easily obtain IP addresses, compromising communication integrity.

Innovation Solution

A method and system that utilize a data forwarding device to receive and forward data through multiple physical interfaces, such as IP network and USB ports, while enforcing a preset communication rule like SIP, ensuring secure data transmission by physically isolating data and preconfiguring intercommunication relationships between IMS subsystems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If data is transmitted directly between IMS subsystems via IP network, then communication efficiency is improved, but security deteriorates as unauthorized outsiders can obtain IP addresses

Engineering Contradiction:
Improvecommunication efficiencyVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

A data forwarding device is introduced as an intermediary between the first and second IMS subsystems. The device receives data from the first subsystem via an IP network port, forwards it through a USB port to a communication rule determination device, and then transmits it to the second subsystem. This intermediary structure maintains communication efficiency while enhancing security by adding verification layers and isolating direct IP address exposure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The transmission path is segmented into multiple independent stages: IP network port reception, USB port forwarding, communication rule determination, and final transmission. Each segment performs a specific function, allowing security checks to be inserted between segments without compromising overall communication efficiency. The segmentation enables the system to verify data at multiple points while maintaining the flow of information.

Inventive Principle:
Principle #1Segmentation

2Reliability

If multiple physical interfaces are used for data transmission, then security is improved through physical isolation, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The data forwarding device is designed with multi-functionality, serving as both an IP network interface and a USB interface in sequence. This single device performs multiple functions (receiving via IP, forwarding via USB, determining communication rules) that would otherwise require separate specialized devices, thereby reducing overall system complexity while maintaining physical isolation benefits.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent combines the data forwarding function and communication rule determination function into a single integrated device rather than using separate devices. This merging reduces the number of components in the system while still achieving the security benefits of physical isolation through multiple interface types, thus lowering device complexity without compromising security.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11838268B2Method, device and system for data communication control
Publication Date: 2023.12.05 ANKANG HONGTIAN SCI & TECH DEV CO LTD
  • US11838268B2 patent drawing
  • US11838268B2 patent drawing
  • US11838268B2 patent drawing

AI summary

Disclosed are a method, a device and a system for data communication control. In the method for data communication control, data sent from a first communication device is received by a data forwarding device, where the data is transmitted through at least two types of physical interfaces in sequence. The data is then forwarded by the data forwarding device to a second communication device that is preconfigured. During the process of sending the data by the first communication device, the data is physically isolated by at least two types of physical interfaces, and then forwarded to the second communication device that is preconfigured. Even if the first communication device is illegally invaded by outsiders, the outsiders only know the IP address of the first communication device but fail to know the IP address of the destination of the physically isolated data.