Bidirectional Gateway Low-Speed Link Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing gateways between high and low security communication networks lack sufficient security measures to ensure the integrity and authenticity of data flows from the low security network to the high security network, particularly in critical contexts like avionics where absolute security is required.
Innovation Solution
A bidirectional gateway with a low-speed return path using a unique communication protocol and cryptographic authentication, combined with a firewall for filtering and rate control, ensures secure data transmission from the low security network to the high security network by reducing data throughput and employing asymmetric key mechanisms for verification and encryption.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a bidirectional gateway is used to allow data transmission from low security network to high security network, then communication functionality is improved, but security level deteriorates
Solution Approach 1:
The gateway is divided into separate processing units: a first processing unit for receiving and authenticating data from the low-security network, and a second processing unit for forwarding authenticated data to the high-security network. This segmentation isolates security-critical functions from potential attack vectors, allowing bidirectional communication while maintaining security boundaries.
Solution Approach 2:
An authentication mechanism acts as an intermediary between the low-security and high-security networks. The first processing unit verifies data authenticity before forwarding to the second processing unit, which then transmits to the high-security network. This intermediary layer enables communication functionality while preventing unauthorized data from compromising the high-security network.
2Ease of operation
If traditional firewall filtering is used for data security, then ease of operation is improved, but security level deteriorates
Solution Approach 1:
The system changes the security parameter from simple packet filtering (traditional firewall) to cryptographic authentication verification. The processing units authenticate data based on security credentials and authentication tokens rather than relying solely on IP addresses and port numbers, significantly raising the security level while maintaining operational simplicity through automated authentication processes.
3Reliability
If data authentication and encryption mechanisms are implemented, then security level is improved, but device complexity deteriorates
Solution Approach 1:
The gateway processing units are designed to perform multiple functions: data reception, authentication verification, encryption/decryption, and forwarding. By consolidating these functions into unified processing units rather than separate dedicated components, the system achieves high security levels while controlling overall device complexity through functional integration.
Data Source
Figure 1~2
Figure 3~5
AI summary
A secure gateway allows bidirectional communication between two communication networks. A first high-security network and a second network whose security is lower. The gateway is bidirectional with enhanced security level between a high-security communication network and a low-security communication network. For this purpose, the return pathway from the low-security network to the high-security network comprises a low-speed link. The physical layer of this low-speed link differs from the physical layers involved both in the high-security network and in the low-security network. This low-speed link is endowed with a linking layer according to a protocol which differs from the protocols used on the linking layers used both on the high-security network and on the low-security network. Advantageously, the linking layer of the low-speed link is furnished with an authentication protocol making it possible to guarantee the origin of the data.