Data Storage Device for Secure Cross-Domain Exchange

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional cross-domain solutions for secure data exchange between different security zones, such as those used in industrial control networks and office networks, are complex and not practical for data exchange via multiple distributed interfaces, especially when high security and robustness against attacks are required.

Innovation Solution

A data storage device with a storage unit, data validation unit, and access control unit that allows only validated data elements to be written and read between security zones, ensuring secure and manipulation-protected data exchange through a simple and cost-effective hardware-based validation process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional cross-domain solutions (firewalls, virtualization) are used for secure data exchange between security zones, then data security and manipulation protection are improved, but device complexity and implementation cost increase significantly

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The data storage device is segmented into functionally independent units: a storage unit for data elements, a validation unit for pattern checking, and an access control unit for read/write permission management. This segmentation allows each unit to perform its specific function efficiently while reducing overall system complexity compared to integrated firewall or virtualization solutions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The data storage device acts as an intermediary component between security zones, providing a hardware-based validation layer that mediates data exchange. The validation unit checks data elements against predetermined patterns before allowing access, serving as a simple yet effective mediator that reduces complexity compared to software-based intermediaries like firewalls or virtual machines.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If hardware-based data validation is implemented, then validation reliability and manipulation protection are improved, but implementation cost and device complexity increase

Engineering Contradiction:
Improvevalidation reliabilityVSAvoidimplementation cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The validation unit, access control unit, and storage unit are merged into a single integrated data storage device that can be implemented as one hardware component. This merging reduces implementation cost compared to separate hardware validation systems while maintaining high validation reliability through hardware-based pattern matching and access control.

Inventive Principle:
Principle #5Merging (Combining)

3Adaptability or versatility

If data exchange is enabled between security zones, then data communication flexibility is improved, but security risks and vulnerability to attacks increase

Engineering Contradiction:
Improvedata exchange flexibilityVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The validation unit performs preliminary validation of data elements against predetermined patterns before they are made accessible to other security zones. This preliminary action ensures that only valid, authorized data elements are transferred, reducing security risks while maintaining data exchange flexibility. The access control unit further enforces read/write permissions based on validation results.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If complex cross-domain solutions are deployed, then security coverage is improved, but ease of operation and integration simplicity deteriorate

Engineering Contradiction:
Improvesecurity coverageVSAvoidintegration simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The data storage device is designed as a universal component that can be integrated between any security zones regardless of the specific security zone architecture. The device provides multiple functions (storage, validation, access control) in a single unit, making it easy to operate and integrate while maintaining comprehensive security coverage across different security zones.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2981926B1Data storage device for protected data exchange between different security zones
Publication Date: 2019.07.24 SIEMENS MOBILITY GMBH
  • EP2981926B1 patent drawingFigure 1
  • EP2981926B1 patent drawingFigure 2
  • EP2981926B1 patent drawingFigure 3

AI summary

The invention relates to a data storage device (10) for protected data exchange between different security zones (16, 17) comprising at least a storage unit (11), a data validation unit (12) and an access control unit (13). The storage unit (11) has a first interface (14) to a first security zone (16), via which the data elements (18) can only be written to the storage unit (11). The storage unit (11) also has a second interface (15) to a second security zone (17), via which data elements (18) can only be read from the storage unit (11). The validation unit (12) is equipped to check the data elements (18) written to the storage unit (11) for agreement with a predetermined pattern (22, 22', 22''). The access control unit (13) is set up to permit the data elements (18) to be read from the storage unit (11) only when the data elements (18) are found to be in agreement and are thus applicably validated.